Undetected.ai
All posts
Detectors

ChatGPT Watermark: Detectors and Removal

OpenAI built a text watermarking method and has not shipped it, in its own words. What that means for ChatGPT watermark detectors, and what there is to remove.

By the Undetected.ai team

August 2026 · 8 min read

The Humanizer

Try:
Tone
Strength:

2 free runs a day, up to 200 words each. We save your run so you can get back to it, and a delete button appears with the result. See privacy.

AI-pattern score

This is our own AI-pattern score, measured here on sentence rhythm, template phrases, vocabulary variety and passive voice. It is not a GPTZero, Turnitin, Originality.ai, Copyleaks or ZeroGPT result, and it does not predict one. Worth knowing: we also ask the rewrite to vary sentence length, drop template phrases and prefer the active voice, so some of the drop is built in. Read the two panels below, not just the number.

Before ·

After ·

·

ChatGPT does not watermark its text. OpenAI has built a text watermarking method and has not shipped it, saying on its own provenance page that its teams "have developed a text watermarking method that we continue to consider as we research alternatives" while prioritizing image, video and audio instead. Nothing is embedded in the words ChatGPT gives you, so there is no watermark in your document to find and nothing to remove. What flags AI writing is statistical: a detector guesses from how the prose is built.

This matters because two of the most searched questions in this area, how to remove a ChatGPT watermark and where to find a ChatGPT watermark detector, are both built on a premise that is not true. Answering them properly means saying what OpenAI actually built, what it publishes about why it has not deployed it, and which company does watermark its text output, because one of them does.

Does ChatGPT have a watermark?

No. As of August 2026, text produced by ChatGPT carries no hidden mark, no invisible character sequence, and no metadata that identifies it as machine written. Copy it into a plain text file and what you have is the words, nothing else. OpenAI's published provenance work covers images, video and audio, and its own page on the subject describes text watermarking as research rather than a shipped feature.

The confusion is understandable, because OpenAI does attach provenance information to other kinds of output. It joined the steering committee of C2PA, the content provenance standard, and began adding C2PA metadata to every image created or edited by DALL·E 3 in ChatGPT and through the API, with the same planned for its video model. It has also incorporated audio watermarking into Voice Engine, its custom voice model. Images and audio are marked. Text is not.

OpenAI is explicit about the ordering. Its teams, in its wording, "have prioritized launching audiovisual content provenance solutions, which are widely considered to present higher levels of risk at this stage of capabilities of our models". Fabricated video and cloned voices were judged the more urgent problem than an essay.

What OpenAI built, and why it has not shipped it

The interesting part is that the technology exists. OpenAI states plainly that it has developed a text watermarking method. It also publishes its reasoning for holding it back, and the reasoning is more revealing than the decision.

The first concern is a scale problem with false positives. In OpenAI's words, "while text watermarking has a low false positive rate, applying it to large volumes of text would lead to a large number of total false positives." A small percentage of an enormous number is still a lot of people wrongly accused.

The second concern is the one worth sitting with. OpenAI writes that its research suggests the text watermarking method "has the potential to disproportionately impact some groups. For example, it could stigmatize use of AI as a useful writing tool for non-native English speakers." That is the same population the peer-reviewed detector research keeps landing on. Liang and colleagues, publishing in Patterns in 2023, ran seven detectors over TOEFL essays written by human students and found an average misclassification rate of 61.3 percent. The company with the most to gain from a working text watermark declined to ship one partly because it would land hardest on the writers already most likely to be misread.

OpenAI's stated alternative is cryptographically signed metadata rather than a watermark, on the grounds that signed metadata produces no false positives at all. Metadata, unlike a watermark, does not survive being copied into a text box, which is a fair summary of why none of this reaches an essay.

Is there a ChatGPT watermark detector?

No, and the sites offering one cannot be doing what the name implies. A watermark detector needs a watermark to detect and a key to check it against. Neither exists for ChatGPT output.

What those tools actually run is a statistical classifier, the same category of software as GPTZero, Originality.ai or Copyleaks. It reads finished text and estimates how predictable the word choices are and how much the sentence rhythm varies, then returns a probability. That is a legitimate thing to build. Calling it watermark detection is not, because it implies a definitive signal is being read when the tool is in fact guessing from surface features, which is why these products disagree with each other on the same paragraph. We went through what the measured error rates actually are, including the study where detectors misread human work less often than human graders did, on the AI detector false positive rate page.

One test tells you which kind of tool you are looking at. A real watermark detector would return a yes or a no. A classifier returns a percentage. If you are being shown a percentage, no watermark is being read.

How to remove a ChatGPT watermark

There is nothing in the text to remove, so the honest instruction is to stop looking for one. The advice circulating on this question generally involves retyping the text by hand, pasting it through a plain text editor to strip formatting, or replacing supposedly suspicious invisible characters. None of that changes anything about how a detector reads your writing, because a detector is not looking at characters. It is looking at patterns.

That has not stopped a market forming around the idea. Tools are now sold specifically as watermark removers, and at least one humanizer leads its pricing page with a claim to remove all AI watermarks, which is a claim nobody can currently test in either direction. We went through what those products actually touch in ChatGPT watermark remover: what works.

Two of those steps are worth doing for unrelated reasons. Pasting through a plain text editor removes the formatting and any tracking that came with copied rich text, which is good hygiene when you are moving text between applications. Retyping forces you to read every sentence, which catches invented citations. Neither is watermark removal.

If the underlying goal is text that does not read as machine written, the thing to change is the prose. AI drafts share three properties: sentences that all land at roughly the same length, a narrow set of recurring connectives, and paragraphs built to the same three-part template. Rebuilding those is what a ChatGPT humanizer does, and it is a genuine operation on the text rather than a search for a mark that is not there.

Which AI models do watermark their text?

Google does. SynthID, developed by Google DeepMind, "embeds digital watermarks directly into AI-generated images, audio, text or video", and the text version is deployed across Google's consumer AI products, including Gemini. It works by nudging the model's token choices with a keyed function, so each individual word reads naturally while the pattern across a passage encodes a signature. DeepMind open sourced the method, SynthID-Text, in October 2024.

ModelText watermarkCan you check it yourself
ChatGPT (OpenAI)No. Method developed, not deployedNothing to check
Gemini (Google)Yes, SynthID-TextNo. Verification needs Google's key
Claude (Anthropic)Yes, since August 2026, on models launched on or after August 2No. Anthropic has not published the detection tool yet
DALL·E 3 images (OpenAI)C2PA metadata, not a text watermarkYes, if the metadata survived
Voice Engine audio (OpenAI)Audio watermarkingNo public tool

Anthropic is the newest entry, and it changed in the middle of August 2026. Under the EU AI Act's Article 50(2) transparency code, Claude models "launched on or after August 2, 2026 support marking at launch", and Anthropic is applying that worldwide rather than only in Europe. In its own description, a supported Claude model "weaves an imperceptible watermark directly into the text itself", and because the mark is part of the text "it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing". Anthropic has not released the reader, saying it will "share details on detection mechanisms in forthcoming technical documentation", so nobody outside Anthropic can currently check a passage. What that does and does not prove is set out on the Claude AI detector page.

The Gemini row is the one people misread. Open sourcing SynthID-Text lets other developers watermark their own models using their own keys. It does not let anyone verify Google's production Gemini output, because that verification requires Google's key. So even for the one major model that genuinely watermarks its text, you cannot check a document yourself, and neither can your professor or your client. The practical situation is the same for Claude and for ChatGPT: whatever anyone concludes about your writing today, they concluded it statistically.

What actually flags your text, since it is not a watermark

Detectors measure two things. The first is how predictable each word is given the words before it, which is low in AI writing because models are trained to pick likely continuations. The second is how much that predictability varies across a passage, which is also low, because a model holds a steady register where a person does not. Human writing is lumpy. It has a nine-word sentence next to a forty-word one, an aside that goes nowhere useful, and a paragraph that ends on the evidence instead of a tidy summary.

Everything else follows from those two measurements. It explains why paraphrasing often fails to move a score: swapping synonyms leaves the rhythm and the paragraph architecture untouched, and those are what is being measured. Turnitin lists "text that has been paraphrased without developing new ideas" among the writing most likely to be misread, which is the same observation from the other direction.

It also explains a problem writers hit outside education entirely. The flatness that a detector picks up is the same flatness a reader feels, and it compounds when one draft gets reworked into a newsletter, a blog post and half a dozen social posts, since every version inherits the parent's rhythm. Teams who turn a single piece into every channel tend to notice it as a brand voice problem long before anyone runs a detector over it. The fix in both cases is the same: vary the structure, and add something specific that a model could not have known.

That last part is the one no tool does for you. A rewrite changes how the prose moves. It does not add evidence, and it does not repair an argument that was thin when the model produced it. If you are writing for submission, the more durable protection is a drafting history that shows the document developing, which is the point we make at length in how to prove you did not use AI. Detectors infer from finished text. Version histories record process, and process is the only thing that answers the question properly.

The short version

ChatGPT does not watermark its text, so there is no ChatGPT watermark to detect and none to remove. OpenAI has built a text watermarking method and has not deployed it, citing the volume of false positives it would generate and the risk that it would stigmatize non-native English speakers who use AI as a writing aid, and it has prioritized image, video and audio provenance instead. Sites advertising a ChatGPT watermark detector are running statistical classifiers, which you can tell because they return a percentage rather than a yes or a no. Google's Gemini does watermark its text with SynthID, and even there verification needs Google's key, so nobody outside Google can check. Everything anyone concludes about whether your writing is AI generated is a guess made from the shape of the prose, which means the prose is the only part worth changing.

Let Undetected.ai clear the flag for you

Paste your own text and watch our AI-pattern gauge sweep from the score on your draft to the score on the rewrite, meaning kept intact.

Make your next draft read like you wrote it

Paste your text and Undetected.ai rewrites the robotic patterns into natural prose, keeps your meaning, and scores the result on our own AI-pattern measure.

Meaning kept · Your own text rewritten · Saved to your history, delete any time

Humanize my text