Skip to main content
AI Watermark Removal

Provider tracker

ChatGPT Watermark: Text, Images, C2PA, and SynthID

OpenAI has already built a ChatGPT text watermark, reportedly about 99.9 percent effective, and chose not to ship it. Leaked internal documents described in Wall Street Journal reporting say the company held it back over circumvention risk and a disproportionate impact on non-native English writers, plus internal survey data suggesting roughly 30 percent of users would use ChatGPT less if it launched. Images and, since July 31, 2026, audio went the other way: OpenAI confirms C2PA metadata and a SynthID watermark for both, though independent testing has already found daylight between that claim and what survives in practice.

Published 2026-08-11Updated 2026-08-11Confirmed

Key takeaways

  • Confirmed: OpenAI says images generated with ChatGPT, Codex, and the API carry C2PA metadata and a SynthID watermark, and it extended the same approach to supported audio from ChatGPT Voice, GPT-Live, and the API on July 31, 2026, alongside a new Content Provenance API.
  • Reported, not confirmed as deployed: OpenAI built an internal ChatGPT text-watermarking system years ago, described as roughly 99.9 percent effective, and held it back over circumvention risk, false positives, and impact on non-native English writers.
  • Independent testing complicates OpenAI's own claims. A November 6, 2025 investigation found Sora 2 videos where the visible watermark and the detectable C2PA metadata did not line up the way OpenAI's public description says they should, and a June 28, 2026 OpenAI developer forum thread reports metadata vanishing on a simple re-upload.
  • OpenAI's public writing echoes the leaked account. It has separately discussed text-watermarking tradeoffs, including false positives, circumvention, and non-native-speaker impact, in its own posts on content provenance, so this is not only a leak, it is a pattern OpenAI itself has acknowledged.

Provider map

Text watermark status by provider

Detector guide
How to read this map

Confirmed means an official or primary source documents text watermarking. Contested means official sources disagree with each other. Watchlist means regulation, research, or provider behavior makes the topic worth tracking closely.

What OpenAI actually watermarks today

Confirmed

Here is the exact list of what carries a signal right now, and the limits OpenAI puts on it in its own words.

OpenAI joined the C2PA steering committee and reached "C2PA Conforming Generator Product" status on May 19, 2026, launching a public verification tool at openai.com/verify on the same day.

  • Images from ChatGPT, Codex, and the OpenAI API: C2PA Content Credentials metadata plus a SynthID watermark.
  • Supported audio from ChatGPT Voice, GPT-Live, and the API: the same approach, added July 31, 2026, two days before EU AI Act Article 50 obligations took effect.
  • A Content Provenance API, announced the same day, so third parties can check for these signals programmatically.
  • Ordinary chat text: nothing. OpenAI describes text marking as a goal, not a shipped feature.

Both image layers have been in place since that May 2026 rollout, and OpenAI frames them as complementary. C2PA carries detailed context when it survives, and SynthID is meant to preserve a signal when the metadata does not.

The caveats are worth repeating in OpenAI's own words. "No detection method is foolproof," C2PA metadata "can be stripped, lost through uploads and downloads, or broken by transformations," and the Verify tool deliberately avoids a definitive conclusion when it finds nothing.

So no signal detected is not proof that an image or clip was not made with ChatGPT. It often just means the file traveled.

The text watermark OpenAI built, then shelved

Reported

You will see the exact reasons OpenAI reportedly weighed, and why its own public writing backs the leak up rather than contradicting it.

Years before its 2026 image and audio work, OpenAI reportedly built an internal ChatGPT text-watermarking system. Leaked internal documents, reported by the Wall Street Journal and covered by Tom's Hardware on August 5, 2024, described it as roughly 99.9 percent effective at flagging ChatGPT-written text.

OpenAI chose not to release it. The reported reasons stack up like this.

  • Circumvention risk: a watermark that can be defeated invites a false sense of certainty.
  • False positives: 99.9 percent accurate still means a meaningful volume of wrongly flagged writing at ChatGPT's scale.
  • Disproportionate impact on non-native English writers, whose prose can read as more mechanical to these classifiers.
  • Internal survey data suggesting about 30 percent of users would use ChatGPT less if the feature shipped.

This is not only a leak. OpenAI has separately and publicly discussed text-watermarking research and its risks, naming false positives, circumvention, and disproportionate impact on non-native English speakers, in its own content-provenance posts.

Nothing published since 2024 changes the picture. OpenAI's 2026 provenance documentation still says the goal is to expand provenance signals to all modalities including text, which describes an intention rather than a status.

Where independent testing and OpenAI's claims diverge

Community discussion

Two dated findings from outside OpenAI, plus an honest read on what each one does and does not prove.

A November 6, 2025 investigation, published on LessWrong and cross-posted to the EA Forum, checked Sora 2 videos against both OpenAI's own Verify tool and the open-source c2pa-rs CLI. Some videos carrying the visible OpenAI watermark had no detectable C2PA metadata at all, while some Pro-tier videos without the visible watermark did carry it.

That is close to the reverse of OpenAI's public claim that every video generated with Sora includes both visible and invisible provenance signals. No OpenAI response to the finding has surfaced.

Separately, a thread on OpenAI's own Developer Community forum, dated June 28, 2026, found that a PNG carrying valid OpenAI C2PA metadata gets that metadata stripped down to bare PNG chunks the moment it is re-uploaded into a ChatGPT conversation. The original file still verifies fine on openai.com/verify. OpenAI staff had not addressed the thread as of this writing.

Neither finding means OpenAI's provenance system is broken. SynthID is a separate pixel-level mechanism from C2PA metadata, and the Sora investigator's own framing treats the practical risk as low, since metadata is trivially strippable anyway.

What they do show is concrete and dated: real daylight between "every image is watermarked" as a claim and what people find when they actually check.

FAQ

Does ChatGPT watermark images?

Yes. OpenAI says supported generated images include C2PA metadata and a SynthID watermark, and it extended the same approach to supported audio on July 31, 2026.

Does ChatGPT watermark ordinary text?

Not currently. OpenAI reportedly built a text-watermarking system internally, described as about 99.9 percent effective, then chose not to release it, and its 2026 provenance documentation still describes text marking as a future goal rather than something live in ordinary ChatGPT output.

Why hold back a text watermark that reportedly worked that well?

Because a system that is right 99.9 percent of the time is still wrong on a meaningful volume of text at ChatGPT's scale. The reported concern was that those errors would land disproportionately on non-native English writers, whose writing already tends to look more mechanical to these classifiers, on top of survey data suggesting a real share of users would react badly to the feature shipping at all.

Does independent testing support OpenAI's claim that every generated image or video is watermarked?

Not consistently. A November 2025 investigation found Sora 2 videos where the visible watermark and detectable C2PA metadata did not line up the way OpenAI's description says they should, and OpenAI has not publicly responded to that finding or to a separate developer forum report of metadata vanishing on a routine re-upload.

Next steps

  • Get the short answer on each modality, including which parts are confirmed and which are still reported. Is ChatGPT watermarked?
  • See why the two layers on a ChatGPT image fail in completely different ways before you trust either one. C2PA vs SynthID
  • Check what the EU actually requires of providers and deployers now that the transparency rules apply. EU AI Act and AI watermarking
  • Run a suspicious block of text through the free in-browser cleaner to see whether it carries hidden Unicode characters, which are not an OpenAI watermark but are worth knowing about. Hidden character cleaner

Sources and citation status