New to Marqeable? See how it generates leads and wins customers. See the platform

Does ChatGPT Watermark Its Text? What “AI Watermark” Actually Means in 2026

Someone on your team pastes a draft into a detector, it comes back “92% AI-generated,” and the meeting turns into a debate about whether ChatGPT secretly tags everything it writes. It does not - not in the way people usually mean when they say “AI watermark.” But there is real technology behind the phrase, and it pays to know which part is real, which part is research, and which part is a guess dressed up as a percentage.

Three different concepts get blended together in that conversation. Pull them apart and most of the confusion goes away.

1. Embedded provenance: real, but for images and audio

This is the closest thing to what people imagine: a signal attached to a file that says where it came from.

OpenAI does this today - for images and audio, not text. Supported outputs carry C2PA Content Credentials (an open metadata standard that records which tool made the file) and, since 2026, a SynthID watermark that is baked into the pixels or the audio itself rather than sitting in metadata, so it is designed to survive cropping, filters, and lossy compression. OpenAI’s public verification tool checks whether a file carries those signals. As of this writing it accepts images and audio. Not a ChatGPT paragraph.

Two honest caveats even for media:

2. Text watermarking: real research, not deployed in ChatGPT

Text is harder. There are no pixels to hide a signal in - only word choices.

Researchers have shown that a language model can be steered to pick tokens according to a hidden statistical pattern (a “green list” of preferred words seeded by the previous words, in the best-known 2023 scheme). Human readers see normal prose. Someone holding the matching detector can run the text through it and count how often the hidden pattern shows up. Over enough words, the count either looks like chance or it does not.

Google DeepMind put a version of this into production for Gemini as SynthID-Text and published the method. Anthropic followed in August 2026, announcing that Claude models released from August 2 onward carry a SynthID-style text watermark, driven by the EU Code of Practice on Transparency of AI-Generated Content. OpenAI signed that same code and has researched text watermarking for years, but as of this writing has not shipped one for ChatGPT - and it has been unusually candid about why: the signal degrades under translation, rewriting with another model, or even trivial transformations like inserting and deleting characters; it risks disproportionately flagging groups such as non-native English writers; and a watermark that only one vendor’s models carry does nothing about text from any other model.

The follow-up research on how robust these schemes really are (On the Reliability of Watermarks for Large Language Models) is worth reading in full if you care about this. The short version: watermarks can survive light paraphrasing if you have a lot of text to look at, and they get much weaker under heavy rewriting or human editing. Which brings us to the workflow problem in section 4.

Key point: a text watermark only exists if the model provider embedded it and only works if you have that provider’s key. Gemini and newer Claude models carry one; ChatGPT text, as of this writing, does not. There is no universal invisible tag in AI text, and generic detector tools cannot read the vendor watermarks that do exist.

3. AI-text detection: what the “92%” tools actually do

When a tool says a document is “92% AI,” it is not finding a secret ChatGPT signature. It is doing statistics on the writing itself.

Detectors look at features like how predictable each next word is (perplexity), how much sentence length and structure vary (burstiness), vocabulary distribution, transition patterns, and stylistic uniformity. Human writing tends to be lumpier - odd word choices, uneven rhythm, the occasional ugly sentence. Model output, especially unedited output, tends to be smooth. The detector learns what “smooth” looks like and scores against it.

That approach has a track record, and it is not a good one:

None of this means detectors are useless as a signal. It means the number they produce implies a precision the underlying method does not have.

4. Why length helps but the workflow problem does not go away

A 3,000-word article gives a detector - or a person - far more evidence than a 30-word email. You can look at consistency of voice, vocabulary spread, repeated structures, and whether one section suddenly reads differently from the rest. Longer text makes directional judgments more defensible.

But there is a fundamental ambiguity that more words do not fix. In 2026, real writing looks like this:

AI draft → human edits → AI tightens → human edits again

and that is extremely difficult to distinguish from:

Human draft → AI proofreads

Both leave the fingerprints of both. Add the fact that a modern model asked to write in a specific, well-documented voice will produce far less stereotypically “AI-looking” prose, and the clean binary of “human or machine” stops describing what actually happened to the document.

So for anything consequential - a hiring decision, a plagiarism accusation, a performance review, a legal dispute - a detector score or a chatbot’s opinion is not proof of authorship, and treating it as proof is where people get hurt. What you can responsibly get is a qualitative read: “strong AI characteristics,” “ambiguous,” “strong human characteristics,” with the specific signals listed. That is useful. A percentage is theatre.

5. Where this leaves anyone who publishes for a living

Here is the reframing that saves marketing and content teams a lot of anxiety: detection is the wrong question.

Nobody buys, subscribes, or books because your blog post scored “human” on a detector. Search engines have said for years that they reward helpful content regardless of how it was produced and penalize scaled, low-value content regardless of who or what wrote it. Readers do not run detectors either. They notice, in about two sentences, whether a piece is specific - whether it knows their problem, uses their vocabulary, and says something the last ten articles did not.

That is a quality bar, not a provenance bar, and it is worth being clear about which one you are actually enforcing:

The questionWho caresWhat answers it
Was a model involved?Almost no reader; some regulators, for mediaProvenance signals (images/audio); disclosure policies
Does it read as generic?Every readerSpecific brief, documented brand voice, real details
Is it correct and on-brand?Your customers and your legal teamReview against the brief and the voice, by specialists and by a person
Who approved it?You, when something goes wrongA human approval step in the workflow, recorded

The teams that get the most out of AI drafting treat those last three rows as the job. They write a brand voice document the model can actually follow, they feed a real brief instead of a one-line prompt (the fix for why AI content sounds generic), they review before publishing for language, voice, and accuracy rather than for “AI-ness,” and they keep a person on the approve button. Do that and the detector conversation becomes irrelevant, because the content passes the only tests that were ever going to matter.

One place provenance genuinely does matter for marketers: images and audio. If you generate campaign visuals or voice clips with AI tools, know that some carry Content Credentials and invisible watermarks by design. That is fine - and increasingly expected under transparency rules such as the EU AI Act’s Article 50 obligations, which began applying in August 2026 - but it is a reason to keep your image sources and edits documented rather than a reason to avoid the tools.

Frequently asked questions

Does ChatGPT add a watermark to the text it writes?

Not a readable one. OpenAI embeds C2PA credentials and SynthID watermarks in supported images and audio, and its verification tool covers those media only. ChatGPT text carries no hidden tag you or anyone else can read back.

What is text watermarking, then?

A technique where the model biases its word choices toward a hidden statistical pattern that a keyed detector can look for. Google has deployed a version in Gemini and Anthropic in newer Claude models; OpenAI has researched it and documented why it has not shipped one for ChatGPT. Translation, paraphrasing, and human editing weaken it.

So how do detectors produce “92% AI”?

By scoring statistical features of the writing - predictability, uniformity, vocabulary spread - not by finding a signature. They have documented false positives (especially for non-native writers) and false negatives (especially after paraphrasing).

Should I run my marketing content through a detector?

It will not tell you anything your readers care about. Check instead whether the piece is specific, on-brand, correct, and approved by a person. Those are the tests that determine whether it works.

The bottom line

“AI watermark” is three things wearing one name. Embedded provenance is real and useful for images and audio. Text watermarking is real, shipping in Gemini and newer Claude models, has known weaknesses under editing, and for ChatGPT does not exist yet. AI-text detection is statistical inference that produces confident-looking numbers it cannot back up. If you publish for a living, none of them are the bar your work is judged against. Specificity, voice, accuracy, and a named human who said “ship it” are.

If you want that bar built into how campaigns get made: Marqeable’s agents draft campaigns from a real brief and your brand voice, run specialist review before you see the draft, and hold every send behind your approval.


Marqeable runs your campaigns, answers every visitor, text, and email in seconds, and turns them into booked jobs and meetings - even at 9pm on a Saturday. We’re in private beta with a small early cohort. Get early access

Marqeable
© 2026 Marqeable. All rights reserved.