Back to all posts

cat posts/openai-eu-text-watermark-azure-openai-not-covered-yet.md --category "Security & Compliance" --views 6

OpenAI's EU text watermark: Azure OpenAI is not covered yet

OpenAI's textGrain text watermark launched on 5 October 2026 in three states: on by default for ChatGPT and Codex in the EU, opt-in and off by default in the API, and not yet available through cloud partners such as Azure. Microsoft Foundry's provenance page lists only Claude models for text marking, so Azure OpenAI teams still own the Article 50(2) duty themselves, with the 2 December 2026 transitional deadline eight weeks away.

  • --author By Falak Mahmood
  • --date October 6, 2026
  • --read 12 min read
  • --views 6 views

On 5 October 2026 OpenAI published its approach to the EU AI Act's text marking rule. The system is called textGrain. It ships in three different states depending on where you buy: on by default for ChatGPT and Codex users in the EU within weeks, off by default and opt-in for API customers worldwide from today, and not yet available at all through "cloud partners", which OpenAI says will follow "in the coming weeks". Microsoft Foundry's own content provenance page, updated on 1 October, lists four Claude models under text watermarking and no OpenAI model. If you run a customer-facing text generator on Azure OpenAI, the marking obligation in Article 50(2) is still yours to meet by hand, and for systems that were already live before 2 August the transitional window closes on 2 December 2026. That is eight weeks from today.

What OpenAI announced, track by track

The announcement is deliberately phased, and the phasing is the news. OpenAI's own words: text watermarking and detection "remain early technologies with significant limitations", so the company is not making it a global default. The three tracks:

Surface Watermark state Who and where Timing
ChatGPT and CodexOn, for eligible text outputAll plans, EU only"Over the coming weeks"
OpenAI APIOff by default, opt-in for select modelsAPI customers worldwideFrom 5 October 2026
Cloud partners (Azure OpenAI and others)Not yet availableUnspecified"In the coming weeks"
Watermark detectorApplication only, case by caseApproved researchers and expert organisationsApplications open 5 October; no public tool at launch

Two details matter for enterprise buyers. First, the EU rollout covers "all plans", which means ChatGPT Business and Enterprise workspaces in Sweden will emit watermarked text once the rollout reaches them, with no admin toggle mentioned. Second, the detector is not for you. OpenAI will grant access "in accordance with the Code of Practice" to organisations that can help evaluate the technology, and the tool only reports whether an OpenAI watermark is present. It does not identify the user, the account, the prompt or the conversation.

How well textGrain works, by OpenAI's own numbers

textGrain nudges the model's word choices to leave a statistical fingerprint. OpenAI says it matched or exceeded Google's SynthID for text in internal evaluations, and a technical report plus an open-source release are promised. The published detection figures are honest about the ceiling:

  • Length matters. At a 1 percent false positive target, the detector caught about 80 percent of 200-token passages and about 95 percent of 400-token passages, measured on psychology questions from the ELI5 dataset. A 200-token passage is roughly 150 words, a typical customer-service reply.
  • Constrained text hides the mark. Detection was "substantially lower" for mathematics, where there is little freedom in word choice. Expect the same for code, structured data, legal boilerplate and anything with a fixed vocabulary.
  • Editing erases it. On 400-token passages, swapping 10 percent of words for synonyms cut detection from about 92 percent to 66 percent. Swapping 25 percent cut it to 17 percent. A human editor doing a normal pass over a draft will land somewhere in that range.

Output quality holds up. OpenAI compared watermarked and unwatermarked runs of its Astra frontier model across eight benchmarks and saw no meaningful difference: 49.57 versus 49.76 on the Artificial Analysis Intelligence Index, 72.80 versus 71.68 percent on DeepSWE v1.1, 53.90 versus 56.06 percent on Terminal-Bench 4.0. For API customers the cost of opting in is therefore close to zero in quality terms. No price change was announced.

OpenAI versus Anthropic: two readings of the same article

Anthropic signed the Code of Practice on Transparency of AI-Generated Content as both a model provider and a system provider, and switched marking on for new Claude models worldwide from 2 August 2026. We covered that decision when it was announced in Claude's text watermark: what it means for Article 50. OpenAI has now taken the opposite reading of the same obligation. Side by side:

Dimension Anthropic (Claude) OpenAI (textGrain)
Geographic scopeWorldwide, "wherever Claude is offered"EU only for ChatGPT and Codex; opt-in worldwide for API
Default in the APIOn, applied at model levelOff, customer opts in for select models
Cloud platformsLive on Microsoft Foundry, AWS Bedrock and Google Cloud"Working with cloud partners", coming weeks
Models listed in Foundry's text tableClaude Fable 5.1, Mythos 5.1, Opus 5, Opus 5.5None
Detector accessPrivate preview for eligible organisations (regulators, media, fact-checkers, researchers, education)Application, approved researchers and expert organisations
Stated limitsHeavily edited, excerpted or short text may carry no detectable markSame, with published numbers for length and edit rate

Neither vendor is wrong on the law. Article 50(2) binds the provider of a generative AI system, and both companies are providers of their own consumer apps. The difference is in how much of the burden each one lifts off the companies building on their APIs. Anthropic marks everything, so a Claude-based application inherits a machine-readable mark whether or not its builder thought about Article 50. OpenAI leaves the choice, and the responsibility, with the API customer. Both positions are defensible. Only one of them means your compliance posture changed on 5 October without you doing anything, and it is not the OpenAI one.

The Azure gap, read from Microsoft's own page

Microsoft Learn's content provenance page for Foundry is the document to read, because it is the one a Swedish auditor will read. Its text section says: "Text provenance support varies by model. Where available, the underlying model provides invisible watermarking and surfaces it through Microsoft Foundry." The table under it lists one provider, Anthropic, and four models. For image and audio the picture is better: Content Credentials and SynthID-style watermarks cover gpt-image-1-mini, gpt-image-1.5 and gpt-image-2, the MAI image models, Black Forest Labs Flux, the gpt-audio family and Azure AI Speech, with a public detection website and a Content Provenance Detection API for verification.

So an Azure OpenAI deployment of GPT-6 Astra, GPT-5.6 Sol or any other OpenAI text model has no vendor-supplied text mark today. OpenAI's "cloud partners in the coming weeks" almost certainly includes Microsoft, and the Foundry page says Microsoft "works closely with model providers to increase the availability of text provenance capabilities". But there is no date, no model list and no statement of whether it will arrive as an opt-in deployment setting, a per-request parameter or an always-on default. The same page closes with the sentence that decides who carries the risk in the meantime: "Customers are responsible for evaluating and meeting any transparency obligations that apply to their products and services."

Why that sentence lands on you

When you build a chatbot, a document generator or a content tool on an Azure OpenAI model and put it in front of users under your own name, you are the provider of that generative AI system under the Commission's Article 50 guidelines. The marking duty in Article 50(2) is yours, and the machine-readable mark must be present in the output your system emits. Our July guide, Article 50 compliance for Azure OpenAI apps, walks through the three patterns: chatbot disclosure, machine-readable marking and deployer labels. Pattern two was written on the assumption that a model-level watermark would arrive. For OpenAI models on Azure it has not, and the Code of Practice does not treat a single watermark as sufficient anyway. It asks providers for layered marking that combines metadata, watermarks and provenance mechanisms, because no single technique meets the Article's four tests of effectiveness, interoperability, robustness and reliability on its own.

Three options for an Azure OpenAI text workload

The decision depends on one date. If your system was placed on the market or put into service before 2 August 2026, the Digital Omnibus gave you a four-month transitional window for the Article 50(2) marking duty only, ending 2 December 2026. If it launched on or after 2 August, there was no window and the duty already applies. Everything else in Article 50 (chatbot disclosure, deepfake labels, public-interest text labels) applied from 2 August regardless.

Option What you do Fits when Risk
1. Wait for the Foundry toggleKeep the OpenAI model, add metadata marking now, switch on the vendor watermark when it landsPre-August system with the 2 December window; internal tooling with low exposure"Coming weeks" has no date. If it slips past December you are late on one layer
2. Route marked workloads to Claude in FoundryPoint the public-facing text path at Claude Opus 5.5 or Fable 5.1, keep OpenAI models for internal pathsMulti-model architecture already in place; output goes to the publicModel change needs regression testing; Claude's detector is also private preview
3. Build the provenance layer yourselfAttach signed metadata to every generated artefact, log model and timestamp, expose a verification endpointDocument and content generators where output is a file, not a chat bubbleMetadata is stripped on copy-paste; this is one layer, not two

Option 1 and option 3 are the same work with different end states. Metadata marking is needed under all three options because the Code expects layering, so build it first. Option 2 is the only one that gives you a model-level watermark on Azure today, and it costs a model swap. Whichever you pick, write down the choice, the date and the reasoning. An Article 50 question from a supervisory authority will be answered with your documentation, not with a vendor press release.

What you cannot do with any of this

Both vendors are blunt about what a text watermark does not prove, and the list should be pinned to the wall of every HR, procurement and legal team that has been hoping for an "is this AI" button. OpenAI's version: a watermark does not measure human contribution, does not establish ownership or responsibility, does not identify the user, does not verify accuracy, and its absence does not prove human authorship.

For Swedish organisations this cuts two ways. You cannot run a supplier's tender response or a candidate's cover letter through a detector, because neither OpenAI's nor Anthropic's detector is available to ordinary companies, and a 25 percent edit defeats OpenAI's anyway. In the other direction, your consultants' and communicators' drafts written in ChatGPT Business from a Stockholm office will carry an OpenAI mark once the EU rollout lands. Only approved organisations can read it, and a normal editorial pass will largely remove it. Neither fact is a reason to panic. Both are reasons to update the internal AI usage policy so it stops promising things the technology cannot deliver.

The Swedish and EU angle

The deadline is real and the fine is specific. Breaches of Article 50 fall under Article 99(4): up to EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher. Sweden's supervisory structure under the AI Act is still being assembled; the national inquiry on the AI regulation has delivered its report to the government and IMY has been given extra funding for its coming AI duties, including its regulatory sandbox for public-sector AI. Do not read the slow Swedish set-up as slack in the rule. The obligation applies from the EU dates, and a complaint can come from a competitor, a journalist or a customer long before a Swedish authority sends its first letter.

Public sector buyers will ask about it in procurement. Swedish municipalities and agencies writing requirements for AI-assisted citizen services now have a concrete question for every bidder: how does your system meet Article 50(2) marking, and which layers does it use? "The model does it" is a wrong answer for any OpenAI model on Azure today. The answer that survives evaluation names its layers: signed metadata on every artefact, a vendor watermark when Foundry exposes one, and visible disclosure in the interface. Put the question in your upphandling template this month.

The EU-only ChatGPT default is a data point for the sovereignty debate. OpenAI chose to confine the consumer watermark to the EU and to keep it off elsewhere. That is the same pattern as the Dots launch, where EU rules shaped a product boundary (see OpenAI Dots and the EU: Pro is blocked, Business is not). Anthropic took the other route and applied one standard globally. For a Swedish CIO weighing which vendor's roadmap is easier to govern, a vendor that treats EU rules as the global baseline produces fewer region-specific surprises than one that fences them off.

Checklist for this week

  • 1. Date every generative text system. For each Azure OpenAI or ChatGPT-based system, record whether it was in service before 2 August 2026. That decides whether your marking deadline is 2 December or already passed.
  • 2. Check the Foundry provenance page weekly. The text table is the signal that OpenAI's cloud-partner rollout has reached Azure. Note the model names and whether it is default-on or opt-in the day it changes.
  • 3. Ship metadata marking now. Model name, deployment, timestamp and a signed manifest on every generated document, email or export. This is the layer you need regardless of what the vendor ships.
  • 4. Decide the public-facing path. If users read generated text directly, decide between waiting for the OpenAI watermark on Azure and routing that path to a Claude model in Foundry that is already marked.
  • 5. Revise the internal AI policy. Remove any claim that AI text can be detected on demand. Replace it with disclosure rules for staff and a statement of which outputs carry vendor marks.
  • 6. Brief the ChatGPT Business admins. EU workspaces will start emitting watermarked text in the coming weeks, with no opt-out announced. Communicate it before users notice it in a news article.
  • 7. Add the Article 50(2) question to procurement. Ask every AI vendor which marking layers their system uses on text and how a third party can verify them.

OpenAI has done the technically honest thing and published the detector's failure modes alongside the launch. That honesty is useful to you only if you act on it: the watermark is one layer, it is not on Azure yet, and your marking duty did not move.

subscribe # the AI news that matters, minus the noise

Book a Call

Sources

Tags

Related posts