Home › Resources › ChatGPT watermark detector

ChatGPT watermark detector: there is nothing to detect.

This is the rare search where the honest answer is that the thing you are looking for does not exist. ChatGPT output carries no watermark. OpenAI built a text watermarking system, reportedly had it ready for about a year, and internal documents put it at 99.9% effective given enough text. It was never released. There is therefore no ChatGPT watermark in your document, and nothing that claims to detect one is doing what it says.

The picture is genuinely more interesting than that flat no, and it is worth five minutes. One major lab did ship text watermarking: Google DeepMind's SynthID-Text runs in Gemini, was published in Nature, and was validated on roughly 20 million live responses. It also only works for text from providers who adopt that same scheme, and the detector for it is not something a third party can point at an arbitrary document. Below: what a text watermark actually is, what OpenAI built and shelved and why, where images differ, and what we do instead. We do not check watermarks, and we say so on this page rather than in a footnote.

Run a statistical check instead
3 checks/day free No watermark claims, ever Primary sources cited Last verified
The short answer

The short version, provider by provider.

Text and images are completely different situations, and almost every confusing article on this topic is quietly switching between them.

Where things actually stand

ContentWatermarked?Can you check it?
ChatGPT textNo. Built, never shipped.Nothing to check.
Gemini textYes, SynthID-Text.Not by an arbitrary third party.
ChatGPT and DALL·E imagesC2PA provenance metadata.Yes, if the metadata survived.

The four things to take away

  • No ChatGPT text watermark exists to detect. Any tool advertising a ChatGPT watermark check is either mislabelling a statistical detector or selling you nothing.
  • A watermark and a detector are not the same kind of thing. A watermark is a signal deliberately embedded at generation time by the provider. A detector guesses after the fact from statistical patterns. The first is near-certain when present; the second is a probability estimate, always.
  • Watermarking is not metadata and not hidden characters. It changes which words the model picks. More on the mechanism below, because this is the most common misunderstanding.
  • Images are the exception. OpenAI attaches C2PA provenance metadata to images, which you can genuinely verify, with one large caveat about how easily it is stripped.
The mechanism

What a text watermark actually is.

Worth getting right, because the popular mental model is wrong in a way that leads people to hunt for the wrong thing entirely.

It is a bias in word selection

When a language model writes, at every step it has a distribution over possible next tokens and samples one. Text watermarking intervenes precisely there. Using a secret key, the scheme scores the candidate tokens and nudges sampling toward some of them over others. Each individual choice stays plausible, so the text reads normally, but across a few hundred words a statistical fingerprint accumulates that someone holding the key can test for with very high confidence.

OpenAI's reported approach worked this way: slightly changing how ChatGPT selects the next word or word fragment, leaving a trace only OpenAI's own tool could read. Google's SynthID-Text assigns pseudorandom scores to candidate tokens and prefers higher-scoring ones, then detects by computing the text's overall score. It modifies only the sampling procedure, not training, and detection does not require running the underlying model.

What follows from that mechanism

  • It is invisible in the text itself. There is no character, no glyph, no metadata field, nothing you could find by inspecting the document. The signal is in the choices.
  • It requires the key. This is the decisive point for anyone searching for a detector. Only the party who embedded the watermark, or someone they give access to, can test for it. A third-party tool cannot check a watermark it has no key for.
  • It needs length. A sentence or two carries too little signal. The high confidence figures assume a decent volume of text.
  • It is fragile to rewriting. Paraphrasing, translation and heavy editing degrade it, because they replace the very token choices that carried the signal.

Why this matters if you were hoping to verify a document

Even in a world where ChatGPT watermarked everything, you personally still could not check it. You would be submitting text to OpenAI and trusting their answer. Watermarking is a provenance tool for platforms, not a verification tool for readers, and that distinction is usually lost in coverage of it.

Built, not shipped

What OpenAI built, and why it stayed in a drawer.

This is the substance of the story, and OpenAI's own stated reasons for holding it back are more reasonable than the cynical reading suggests.

The system

Reporting in August 2024, based on internal documents, described a text watermarking method that had been ready for roughly a year. The figure attached to it was 99.9% effective at identifying ChatGPT-generated content when enough text was available. Set that beside what OpenAI had actually shipped publicly and the contrast is stark: its AI Text Classifier, a statistical detector, correctly identified 26% of AI-written text while wrongly flagging human text 9% of the time, and was withdrawn on 20 July 2023 with the notice that it was "no longer available due to its low rate of accuracy."

So OpenAI possessed something that worked far better than the tool it had retired, and did not release it. The reasons given fall into two groups.

The commercial reason

An internal survey reportedly found that nearly a third of loyal ChatGPT users said they would use the product less if OpenAI watermarked its output while competitors did not. That is a straightforward competitive problem, and it is the part of the story that gets the attention. A watermark only one provider applies is a unilateral disadvantage.

The reasons that are actually good

The technical objections deserve more credit than they usually get, because they are the same objections that undermine detection generally.

  • It is circumventable, cheaply. OpenAI's own stated concerns included defeating the watermark by running text through translation systems, rewording it with a different model, or asking the model to insert a special character between every word and then deleting those characters. None of that requires expertise.
  • It is unfair in a familiar direction. OpenAI cited "the potential to disproportionately impact groups like non-English speakers." That is the same bias documented across this field: Liang et al. (2023) found seven detectors flagging more than 61% of TOEFL essays by non-native English speakers on average, against near-zero for native-English US eighth-graders.

A watermark that the motivated defeat in one step, while the unaware are disproportionately caught by it, redistributes risk toward exactly the wrong people. That is a serious objection whatever you think of the commercial one sitting next to it.

What OpenAI still says publicly about text

Its retired classifier announcement continues to describe more effective provenance techniques for text as something the company is researching, and does not point to a replacement. That page was still framing it that way when we last checked it. For text, OpenAI's published position remains open research, not a shipped capability. Our full write-up of the retired classifier is at AI Text Classifier alternative.

Sources: OpenAI's classifier announcement of 31 January 2023 and its 20 July 2023 withdrawal notice, quoted figures OpenAI's own; press reporting of internal OpenAI documents, August 2024, for the watermarking system and the user survey; Liang et al., Patterns 2023. The watermarking details rest on reporting of internal documents rather than an OpenAI publication, and we flag that rather than presenting them as a company statement.

The one that shipped

The watermark that did ship: SynthID-Text.

Google DeepMind deployed text watermarking at scale and published the method. It is the proof that this is buildable, and also the proof that it does not solve your problem.

What it is

SynthID-Text was published in Nature under the title "Scalable watermarking for identifying large language model outputs" and is described as the first publicised large-scale deployment of an LLM watermarking algorithm. It runs in Gemini, and the accompanying model and code were open-sourced. A live experiment across nearly 20 million Gemini responses found no degradation in text quality, which is the result that made deployment defensible: the standard objection to watermarking is that constraining sampling makes the writing worse, and at that scale it did not.

Why it still does not give you a detector

Three limits, all acknowledged in the work itself.

  • It only covers providers who adopt the same scheme. Gemini text carries it. ChatGPT text does not. Nor does output from a locally run open-weight model, which anyone can download. A watermark check is therefore a check on one vendor's output, never a general test of whether text was generated.
  • It weakens under paraphrasing, translation and heavy edits. The same fragility that worried OpenAI. Anyone deliberately hiding provenance removes it in one pass; the person who pasted output verbatim is the one who gets caught.
  • You are not the one who gets to check. Verification sits with the provider. Independent researchers have probed the scheme from the outside, and a public general-purpose SynthID-Text checker for arbitrary documents is not what shipped.

The structural problem with watermarking as a whole

It is voluntary, per-provider, and defeated by rewriting. For it to function as the verification layer people imagine, every model provider would have to adopt a compatible scheme, keep it on by default, and expose verification, while open-weight models that anyone can run unwatermarked continue to exist. Nature itself published a comment arguing AI watermarking must be watertight to be effective. It is a useful provenance signal for a cooperating platform. It is not, and on current evidence will not become, a way for a teacher or an editor to test an arbitrary document.

Sources: "Scalable watermarking for identifying large language model outputs," Nature (doi 10.1038/s41586-024-08025-4); Google DeepMind SynthID documentation and the open-sourced implementation; Nature comment "AI watermarking must be watertight to be effective." Captured 29 September 2026.

The exception

Images are different, and this part works.

If what you actually have is an image rather than text, there is something real to check. It comes with one caveat that undoes it in most practical cases.

C2PA provenance metadata

OpenAI adds C2PA metadata to images created and edited by DALL·E 3 in ChatGPT and through its API, and joined the C2PA steering committee. C2PA is an open standard for embedding verifiable provenance into a media file: which application generated it, what actions were taken on it, and what was edited. Public verification services exist, so you can take an image and check for a credential. This is the one branch of this topic where a "detector" in the everyday sense genuinely exists.

The caveat that matters more than the feature

Metadata is trivially removed, and most platforms remove it for you. Accidentally or deliberately, C2PA credentials come off: a screenshot has none, a re-encode usually drops them, and the majority of social platforms strip metadata from uploads as a matter of routine. So the absence of a credential tells you almost nothing, because the overwhelmingly common case for an ordinary image is that it never had one or lost it in transit. Only the presence of a valid credential is informative.

That asymmetry is the whole practical story of provenance metadata. It can confirm; it cannot refute. We cover the standard in more depth in our C2PA content credentials guide, and our separate image detector is a statistical tool for images, not a credential reader.

Sources: OpenAI provenance documentation and its C2PA steering committee membership; C2PA specification materials; OpenAI began adding C2PA metadata to DALL·E 3 images in February 2024. Captured 29 September 2026.

What people find instead

The invisible-character theory, and why it is not this.

A persistent belief holds that ChatGPT hides special characters in its output as a secret marker. It is worth separating what is true from what is being claimed.

What is actually true about odd characters

Model output does sometimes contain unusual Unicode: non-breaking spaces, narrow no-break spaces, curly quotation marks, and the em dash appearing far more often than most people use it. These are real and you can find them. They are artefacts of training data and tokenisation, not a designed marker, and they are trivially removed by a find and replace or by pasting through a plain text editor. Anything that can be stripped by accident, by a copy and paste into a different editor, is not functioning as a watermark.

Why it could not work as one anyway

A watermark has to survive ordinary handling and has to be hard to forge. Invisible characters fail both tests. They vanish in normal editing pipelines, and anyone can insert the same characters into human-written text, which would let you make genuine writing look generated. A signal that is both fragile and forgeable is worse than none, because it produces confident wrong answers in both directions.

There is a nice irony in OpenAI's own stated circumvention concern here: one of the ways to defeat its real watermark was to have the model insert a special character between every word and then delete them. Special characters are the attack in that story, not the mark.

The other claims worth ignoring

  • "Ask ChatGPT whether it wrote this." It has no memory of other conversations and no ability to recognise its own output. It will answer confidently either way. This is not a check.
  • "Detects the ChatGPT watermark" as a product feature. There is no ChatGPT watermark. Whatever the tool is doing, it is not that, and the mislabel is a reason to distrust the rest of its claims.
  • Em dash counting as proof. Punctuation habits are a weak hint at best. Our own detector reads em dashes in a way that surprises people, which is a good illustration of why single surface features are not evidence.
The realistic option

What actually works instead, and what it costs you.

Statistical detection is the only tool that applies to arbitrary text from any provider. Here is an honest account of what it buys and what it does not.

How it differs from a watermark

A statistical detector reads properties of the finished text: how predictable the word choices are, and how much that varies. It needs no key, no cooperation from the provider and no prior arrangement, which is why it works on anything. The price is that it is inference rather than confirmation. A watermark present is near-certain. A detector score is a probability about a document, and it is wrong a measurable fraction of the time.

That trade is the whole subject. People search for a watermark detector because they want certainty. Certainty is exactly the thing that is not on offer, from us or anyone.

What we actually do

  • Statistical detection on English text, with sentence-level highlights so you see which passages drive the reading rather than only a single number.
  • Published bands, not a headline figure. 88% to 92% on long-form English of 300 words or more across 15 model families, 70% to 78% under about 100 words. Short text is where every detector is weakest and we would rather publish that than hide it.
  • A false-positive benchmark with the data attached. 1,180 academic papers, 5.85%, downloadable per document at our benchmark.

What we explicitly do not do

We do not check watermarks. Not OpenAI's, because there is none to check. Not SynthID, because reading it requires access we do not have. Not C2PA credentials in text, because text has no such field. If a competitor tells you it checks a ChatGPT watermark, that claim is false regardless of who makes it, and we would rather lose the comparison than match it.

We also do not treat our own score as proof. It is a reason to look closer: at version history, at drafts, at a conversation with the author. Our limitations page sets out where the detector fails, and the methodology explains how the bands were measured.

FAQ

ChatGPT watermarks: the common questions.

Short answers, and the first one is the whole page.

Does ChatGPT watermark its text?

No. OpenAI built a text watermarking method and never released it. Reporting based on internal documents in August 2024 described a system that had been ready for about a year and was 99.9% effective given enough text, held back over circumvention risk, the potential to disproportionately impact non-English speakers, and a survey finding nearly a third of loyal users would use ChatGPT less if it watermarked output while rivals did not. OpenAI still publicly describes text provenance as something it is researching.

Is there any tool that detects a ChatGPT watermark?

No, because there is no watermark in ChatGPT text to detect. Any product advertising a ChatGPT watermark check is either relabelling an ordinary statistical detector or selling nothing at all. That mislabel is a good reason to distrust its other claims. Statistical detection is the only thing that applies to arbitrary text, and it estimates a probability rather than confirming an embedded signal.

What is a text watermark, technically?

A deliberate bias in word selection applied at generation time using a secret key. At each step the model scores candidate tokens and nudges sampling toward some of them, so each choice stays plausible but a statistical fingerprint accumulates over a few hundred words. It is not metadata and not hidden characters, there is nothing in the document you could inspect, and only the party holding the key can test for it. It also needs a decent length of text and degrades under paraphrasing or translation.

Does Gemini watermark text, and can I check it?

Gemini does carry SynthID-Text, published in Nature and validated across nearly 20 million live responses without measurable quality loss, with the method open-sourced. You cannot generally check it yourself. Verification sits with the provider, it only covers text from providers using the same scheme so it says nothing about ChatGPT or a locally run open-weight model, and it weakens under paraphrasing, translation and heavy editing.

Are the invisible characters in ChatGPT output a watermark?

No. Model output does sometimes contain unusual Unicode such as non-breaking spaces, narrow no-break spaces and curly quotes, and em dashes appear more often than most people use them. Those are artefacts of training data and tokenisation, removable by a find and replace or by pasting into a plain text editor. Anything strippable by accident cannot function as a watermark, and since anyone can insert the same characters into human writing it would also be forgeable in the other direction.

Do ChatGPT images carry a watermark?

Images are the one case where something real exists. OpenAI attaches C2PA provenance metadata to images created and edited by DALL-E 3 in ChatGPT and its API, and public verification services can read it. The caveat undoes most practical uses: metadata is trivially removed, a screenshot has none, re-encoding usually drops it, and most social platforms strip metadata from uploads. A valid credential can confirm origin; its absence proves nothing.

Can I just ask ChatGPT whether it wrote something?

No. It has no memory of other conversations and no ability to recognise its own output, and it will answer confidently in either direction. Screenshots of ChatGPT confirming or denying authorship are worthless as evidence, and have been used in real academic misconduct cases to the serious detriment of the person accused.

Does TextSight check for watermarks?

No, and we would rather state that plainly than imply a capability we lack. We run statistical detection on English text with sentence-level highlights, publish accuracy as bands rather than a headline figure (88% to 92% on long-form English of 300 words or more, 70% to 78% under about 100 words), and publish our false-positive rate of 5.85% over 1,180 academic papers with the per-document data downloadable. We do not read OpenAI watermarks, SynthID, or C2PA credentials in text.

Related

More on provenance and what detection can do.

Further reading

No watermark to find. Here is what can be measured.

Statistical detection on English text, with sentence-level highlights, published accuracy bands instead of a headline number, and a false-positive benchmark you can download. 3 checks a day, no account. We do not claim to read watermarks.

Run a check free Read the limitations first
No watermark claims · Sentence-level highlights · Bands, not a headline figure · Benchmark data downloadable