OpenAI has begun deploying textGrain, an invisible statistical signal designed to help approved investigators assess whether text may have been generated by certain OpenAI models. The company made the signal available as an opt-in for selected API models on 5 October and said it would roll it out to selected ChatGPT and Codex outputs in the European Union over the coming weeks.

The release is explicitly limited. OpenAI says access to its detector will be restricted to vetted researchers and other approved experts. It also warns that the signal does not establish authorship, ownership, accuracy or the identity of the person who produced a document. The absence of a detectable signal does not prove that text was written by a human.

OpenAI reports a target false-positive rate of 1 per cent and detection of about 80 per cent for 200-token passages, rising to about 95 per cent at 400 tokens in one psychology-oriented evaluation. The company also says editing weakens detection: replacing 25 per cent of the words in a 400-token passage reduced detection in its test from 92 per cent to 17 per cent.

For regulated organisations, the practical lesson is that watermarking can support investigations but cannot carry a disciplinary, compliance or fraud decision on its own. It should sit alongside access logs, document history, identity evidence and human review.


Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.
Share this post
The link has been copied!