How to Prepare for AI Text Watermarking Under the EU AI Act
If you publish or process AI-generated text for European audiences, you need to know how to prepare for AI text watermarking, because OpenAI has announced it will start watermarking ChatGPT’s text output for users in the EU.
The move ties into the transparency duties of the EU AI Act, which expects synthetic content to be identifiable. Providers are now building the marks into their tools, and businesses that use those tools will feel the effects: detection, labelling questions, and customers who ask where your content came from. You can get ahead of all of it with a few practical steps. The original report is on TechCrunch.
What You Need Before You Start
You need three things. A list of every place your organisation uses generative AI to produce text, including marketing, support replies, reports and code comments. Access to whoever owns legal or compliance, even if that is one part-time adviser. And a copy of the official text of the regulation, which you can read on artificialintelligenceact.eu or on the EU’s own AI regulatory framework page.
A quick note. This guide is practical information, not legal advice. Which obligations apply to you depends on whether you are a provider or a deployer of AI systems and on your use cases, so confirm the details with a qualified lawyer.
Step 1: Map Where AI Text Enters Your Business
Run a short internal survey. Ask each team: which AI tools do you use, for what, and what happens to the output? Build a simple register with columns for tool, vendor, use case, who sees the output, and whether it reaches customers or the public.
You will almost always find tools nobody told IT about. Marketing may use one chatbot, support another, and a developer a third. Shadow AI is the biggest gap in most compliance efforts, so give people an amnesty: list it now, no blame.
Mark each use as internal only or externally published. Watermarking and labelling questions matter most for the second group.
Step 2: Understand What the Watermark Does and Does Not Do
A text watermark is a statistical pattern added during generation. It is usually invisible to readers, and a detector can estimate whether text came from a particular model. It is not a visible stamp, and it is not perfect. Heavy editing, translation or paraphrasing can weaken or remove the signal, and short snippets give detectors very little to work with.
That has two consequences for you. First, do not promise customers or regulators that watermarking alone proves provenance. Second, do not assume your edited drafts are “clean”. If a detector flags content you believe was human-edited, you want records showing how it was produced. This is why Step 4 matters.
Step 3: Set Disclosure and Labelling Rules
Decide, in writing, when your organisation tells people that content is AI-generated. The AI Act’s transparency provisions address situations such as people interacting with an AI system and the publication of AI-generated text on matters of public interest, with exceptions for content that has gone through human review and editorial responsibility. Check how those provisions apply to your case.
A workable policy usually has three tiers:
- Fully AI-generated, published as is: label it clearly, for example “This article was generated with AI.”
- AI-assisted, human-edited: keep an internal record of the review, and label according to your legal advice.
- Internal drafts and notes: no public label, but keep the register entry.
Put the label where readers will see it, not in a footer nobody opens. For chatbots, tell users at the start of the conversation that they are talking to an AI.
Step 4: Document Your Review Process
Documentation is your best defence. For content that reaches the public, record who reviewed it, when, which AI tool produced the draft, and what was changed. A simple spreadsheet or a field in your content management system is enough.
Add an approval step to your publishing workflow so no AI draft goes live without a named person signing off. This supports the editorial responsibility argument, and it also catches factual errors, which are a bigger practical risk than any watermark.
Step 5: Update Vendor Contracts and Technical Controls
Read the terms of every AI tool on your register. Ask vendors three questions: do you watermark or mark outputs, how can we detect or verify those marks, and what are your obligations and ours under the AI Act? Get answers in writing, and make sure data processing terms line up with GDPR if personal data goes into prompts.
On the technical side, avoid stripping metadata or marks from AI outputs in your pipelines, since removing them may undermine your compliance position. If you build your own AI features, plan for marking outputs as part of the design. Retrofitting later costs more.
Common Mistakes to Avoid
Treating it as a vendor problem only. Providers add the watermark, but disclosure and governance inside your organisation are yours.
Trying to defeat detection. Running text through “humaniser” tools to hide AI use is a risky habit, and it can contradict transparency expectations. Be open instead.
Waiting for perfect guidance. Standards and codes of practice will keep evolving. A register, a policy and a review log are useful now and easy to adjust later.
Forgetting non-EU teams. If your content reaches European readers, the rules may reach you even if your office is elsewhere.
Key Takeaways
- Inventory first: you cannot manage AI text you do not know you have.
- Know the limits: watermarks are statistical signals, not proof, and edits can weaken them.
- Write the policy: clear tiers for labelling remove guesswork for your team.
- Keep records: review logs show editorial responsibility and protect you in disputes.
- Talk to vendors: get their marking and compliance position in writing.
Need Expert Help?
If this feels like a lot to manage alone, TecniForge can handle the heavy lifting. Our team specializes in custom software development and AI integration, including review workflows and content pipelines built with compliance in mind. Get in touch with our experts.
Also read: ChatGPT Watermarking in the EU, our earlier coverage on why this matters today.
Your challenge: set aside thirty minutes this week and start the AI register. Even ten rows is enough to show you where your real exposure sits.
Discover more from TecniForge
Subscribe to get the latest posts sent to your email.