AI Pulse by Inblix

OpenAI joins C2PA steering committee, admits text watermarking flaws

OpenAI Blog · Jul 17, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: OpenAI joins C2PA steering committee, admits text watermarking flaws

OpenAI is making a significant pivot in its content authenticity strategy, acknowledging that watermarking AI-generated text remains too easy to circumvent while doubling down on a metadata standard for images. The company announced it has joined the steering committee of the Coalition for Content Provenance and Authenticity (C2PA), a standards body that also counts Adobe and Microsoft among its members. The move signals a preference for cryptographically signed metadata over other provenance methods that have proven fragile in practice.

In a candid update, OpenAI researchers revealed that their text watermarking method, while highly accurate against localized tampering like paraphrasing, crumbles against globalized attacks. Bad actors can easily strip the watermark by running text through a translation system, having another generative model reword it, or simply instructing the model to insert a special character between every word and then deleting that character. “It is trivial to circumvent,” the company’s update noted, without sugarcoating the defeat.

There’s another wrinkle OpenAI is weighing carefully: the watermarking approach could disproportionately stigmatize specific user groups. The company’s research suggests it might unfairly flag AI-assisted writing by non-native English speakers, people who often lean on tools like ChatGPT precisely to level the playing field in professional communication. That ethical risk, combined with the technical shortcomings, has pushed the company to explore metadata as an alternative for text provenance. Unlike watermarking, cryptographically signed metadata produces zero false positives—a characteristic OpenAI expects will matter more as generated text floods the internet. Even a low false positive rate becomes a torrent of false flags at scale.

On the image front, the company is making more immediate progress. DALL-E 3 images edited within ChatGPT now carry updated C2PA credentials that track the entire edit history, right down to the tool used and the specific action taken. In a demo, OpenAI showed a caterpillar image edited to wear a Santa hat, with the credential transparently reflecting both the original generation and the subsequent modification. The broader vision, according to OpenAI, is a world where anyone encountering digital content can verify its origins through an open standard—whether that content came from a camera or a diffusion model.

💡 Key Takeaways

  1. OpenAI has joined the C2PA steering committee, signaling a strategic bet on cryptographically signed metadata over in-house watermarking for content provenance.
  2. The company's own text watermarking method is easily defeated by globalized attacks like translation systems or character insertion tricks, making it effectively useless against determined adversaries.
  3. OpenAI's research found that text watermarking could disproportionately harm non-native English speakers, who frequently use AI writing tools for legitimate assistance.
  4. DALL-E 3 images edited in ChatGPT now carry updated C2PA credentials that log the full edit history, including specific tools and actions applied to the image.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

← Back to all articles