Skip to main content

Contact

What are you interested in?

AI detection · state of play, August 2026

Detecting AI text.

How detectors measure machine-generated text, where their error rates lie, what the text watermarks introduced since August 2026 change — and which question actually matters for a business.

Have your content process reviewed

Detecting AI text means measuring the statistical traces of machine text production — and living with an uncertainty that cannot be calculated away. Tools such as GPTZero, Originality.ai or Copyleaks do not determine origin. They calculate a probability from perplexity, sentence-length variation and stylistic patterns. No widely used detector delivers proof, and every one of them errs in both directions: it misses AI text, and it flags human text as machine-written.

This page explains what these methods actually measure, how high the error rates are in published research, what the watermarks rolled out since August 2026 change — and what all of that means for companies using AI in their content process. Because the question that matters commercially is not whether a text is recognised as AI, but whether it is good enough. Google does not assess how a text was made; it assesses purpose and quality. The exact wording of its documentation is collected on our page about AI content and the Google guidelines.

How does AI text detection work technically?

Common detectors rely on two statistical measures and a classifier trained on top of them: perplexity, burstiness and a model that has seen labelled collections of text. All three measure the same thing indirectly — how predictable a text is.

  • Perplexity describes how surprised a language model is by each next word. A text whose words are exactly the ones a model would have chosen itself has low perplexity. Because language models prefer probable words when generating, their own output sits structurally at the low end.
  • Burstiness describes the spread at sentence level: how much do sentence length, structure and rhythm vary across a paragraph? People write unevenly — a subordinate clause of 38 words, then four words. Models settle into a very narrow band unless told otherwise.
  • Stylistic markers complete the picture: how often em dashes appear, lists of three, balancing constructions such as "not only … but also", transition phrases at the start of paragraphs, uniform bullet lists with exactly three items.

These signals do not produce a yes or a no. They produce a score, which providers present as a percentage. That presentation is the industry's real communication failure: "94% AI" reads like a measurement, but it is the output of a classifier whose training data, thresholds and model versions are not disclosed. How language models pick words in the first place is explained in our glossary entry on the large language model.

A cryptographic watermark is something else entirely. It does not guess — it checks for an embedded pattern. More on that further down.

How accurate are AI detectors?

The published error rates are high enough that a detector score on its own cannot carry a decision. Three documented data points put that in context.

First: OpenAI took its own AI Text Classifier offline on 20 July 2023 because of its low accuracy. In OpenAI's own evaluation, it correctly identified 26 per cent of AI texts and wrongly flagged 9 per cent of human texts as machine-written. In other words, the provider with the best possible access to its own model could not reliably recognise that model's output.

Second: a research team at Stanford University, writing in the journal Patterns, tested seven commercial detectors against two purely human collections of text. Essays by US school pupils were classified largely correctly. For TOEFL essays by non-native speakers, however, the average false-positive rate was 61.3 per cent. When the same essays were rewritten with more advanced vocabulary, the rate fell to 11.6 per cent. What was being measured was linguistic fluency, not origin.

Third: detectors contradict each other. The same paragraph regularly receives scores from different providers ranging from "almost certainly human" to "almost certainly AI". As long as no provider discloses its thresholds and test sets, comparing two percentages tells you nothing.

Two practical limits sit on top of these. Below roughly 250 words, neither measure has enough data to work with. And any human editing shifts the values, without the detector being able to tell whether a person reworked the text or wrote it from scratch.

Why is human writing wrongly flagged as AI?

Because the features being measured do not mean "machine-made" — they mean "even", and plenty of people write evenly for good reasons. The false positives follow a recognisable pattern.

  • Writing in a second language. Anyone writing in a learned language falls back on a smaller, safer vocabulary and on practised sentence patterns. That is precisely what produces low perplexity. For Switzerland, with its four national languages, this point is anything but academic.
  • Technical and administrative language. Technical documentation, legal texts, quality records and standards are deliberately formulaic. Deviating from the pattern would be a mistake there.
  • Careful editing. A text that has been sub-edited, cut and aligned with a style guide loses exactly the irregularities that count as "human". Good craft raises the risk of a false flag.
  • Short texts. Product descriptions, teasers or emails simply do not provide enough material for a meaningful measure of variation.
  • Translations. Translated text follows the structure of the original and therefore reads as smoothed out.

The practical consequence is uncomfortable but clear: a detector score is not a basis for a sanction, a reduced invoice or an accusation. At best, it is a reason to read a text more closely.

Do AI texts now carry a watermark?

Partly yes — the situation has changed measurably since August 2026, and in a different way from the widespread idea of hidden special characters. The position as of 19 August 2026, provider by provider:

  • Anthropic (Claude): Anthropic announced on 11 August 2026 that Claude output carries a watermark based on Google DeepMind's SynthID-Text method, and described it in detail on 14 August 2026. Models released from 2 August 2026 ship with it; according to the provider, older models are being retrofitted over the following months. The method alters the source of randomness used for word choice during generation. Anthropic states explicitly that nothing is added to the text and that no hidden characters are created.
  • Google (Gemini): Gemini text has carried the SynthID-Text watermark since 2024. The reference implementation is available as open source, but reading the production watermark requires the provider's key.
  • OpenAI (ChatGPT): no watermark has been shipped for text to date. Images from ChatGPT and the API carry SynthID as well as C2PA content credentials, and so does speech output since July 2026.

The driver behind all this is regulation: Article 50(2) of the EU AI Act requires the output of generative systems to be marked in a machine-readable way as artificially generated and detectable as such, and has applied since 2 August 2026. Switzerland is not bound by it. Swiss companies that supply the EU market or serve EU customers effectively are.

Two points matter in practice. First, there is currently no freely available checking service for text. Anthropic has announced a detection API but has not opened it generally; Google's SynthID Detector portal launched at Google I/O in May 2025 and is still only accessible through a waiting list for journalists, media professionals and researchers — it does cover text, but recognises only content carrying Google's own SynthID key. Second, according to Anthropic's own account, light editing probably does not remove the watermark completely, whereas rewriting every word does — and detection confidence rises with the length of the text.

What people take for a watermark in day-to-day use is almost always a typographic artefact: narrow no-break spaces, em dashes, curly quotation marks. Those characters are not a watermark, but they can be replaced cleanly — the how is set out on cleaning up AI text.

What does AI detection mean for visibility in Google?

For rankings it makes no difference whether a detector fires — Google does not run AI detection as a ranking factor, it assesses purpose and quality. The relevant rule is called "scaled content abuse" and is defined in the spam policies as: "Scaled content abuse is when many pages are generated for the primary purpose of manipulating search rankings and not helping users." As an example, Google explicitly names "using generative AI tools or other similar tools to generate many pages without adding value".

The helpful-content guidance puts it even more directly: "If you use automation, including AI-generation, to produce content for the primary purpose of manipulating search rankings, that's a violation of our spam policies." The yardstick is therefore the motive, not the tool — and it catches purely human-made bulk content just as readily.

For companies, that means the question "will they be able to tell we used AI?" is the wrong one. The right one is: "is there anything in this text that would not exist online without us?" Concrete price ranges, your own measurements, experience from real projects, a reasoned opinion. Those same qualities decide whether a passage gets cited in AI answers, which we describe in detail under generative engine optimisation. The full reading of Google's documentation, including the criteria around E-E-A-T, is on AI content and the Google guidelines.

What should companies check instead of detector scores?

Check substance, evidence and accountability — those are the properties by which readers and search systems alike judge a text. An acceptance checklist that works in practice:

  • Figures and sources: does the text contain at least one verifiable number, date or source per section? Missing specificity is the most dependable warning sign there is — far more dependable than any percentage.
  • Fact-checking: do the cited studies, standards and companies exist? Language models invent evidence convincingly. A detector never catches this, because it measures style and not truth.
  • First-hand experience: is there anything in the text only your company could know? A process, a price range, a mistake from a real project.
  • Accountability: is it clear who is responsible for the text, and would that person be willing to defend it in a client meeting?
  • Agreed ground rules: put it in writing with agencies and freelancers — what AI may be used for, and where human review is mandatory. That is more effective than any measurement after the fact.

How this translates into a running editorial process is described in our knowledge article on AI content strategy for Swiss SMEs. If texts merely feel mechanical although the substance is there, the guidance on humanising AI text is the better starting point.

When AI detection is the wrong question

There are situations in which working on detectors demonstrably burns time — and we would rather name them upfront than afterwards.

  • No detector works as evidence. Neither with employees nor with suppliers can you defend a percentage whose threshold the provider does not disclose and whose false-positive rate is in double digits in published research.
  • For short texts the measurement is worthless. Below roughly 250 words there is no statistical basis. Product descriptions, ad copy and meta descriptions cannot be assessed this way.
  • Detectors do not find wrong facts. The most expensive mistake in AI-assisted content is the invented figure, not the mechanical tone. Only a human fact-check helps against that.
  • Optimising for "unflagged" misses the point. A text that loses precision through synonym swaps and artificial sentence-length variation sells less well — and a statistical watermark will not reliably go away either.
  • Applications, academic work and exams follow their own rules. There the issue is not detectability but the agreed duty to declare. That question belongs with the institution concerned, not with a tool.

At DLM Digital we use AI in our own content process — for research, structure and first drafts — and we check every figure, every source and every statement about our own work by hand. That is not a statement of principle, simply the way of working that has proven to hold up.

Statistical detector and watermark compared

AI detector (GPTZero, Originality.ai and others)Watermark (SynthID-Text method)
BasisEstimate from perplexity, burstiness, style markersPattern embedded in word choice during generation
ResultProbability value in per centDetected, not detected or inconclusive
False positivesDouble-digit, far higher for second-language writingVery low by design
CoverageIn principle any textOnly output from participating providers
Effect of editingEvery revision shifts the scoreLight editing usually harmless, a full rewrite removes it
Short textsUnusable below roughly 250 wordsConfidence rises with text length
Publicly checkableYes, many providersFor text, not generally available at present

Frequently asked questions about detecting AI text

Reliable enough to raise a question, not reliable enough to act on. OpenAI withdrew its own AI Text Classifier in July 2023 and published the numbers from its own evaluation: 26 per cent of AI texts were correctly identified, while 9 per cent of human texts were wrongly flagged as machine-written. Commercial providers do better today, but published comparisons still show double-digit false-positive rates. Two tools regularly give the same paragraph completely different percentages. A detector score is a probability estimate, not proof.

Because detectors measure style, not origin. They react to text that is evenly built: short sentences of similar length, a clear structure, few outliers in vocabulary. That is exactly how trained specialist writers, technical editors and anyone following a style guide write. People writing in a second language are hit hardest. A Stanford team writing in the journal Patterns tested TOEFL essays by non-native speakers across seven detectors and found an average false-positive rate of 61.3 per cent.

Since August 2026, partly yes — and not in the way most people assume. Anthropic announced on 11 August 2026 that Claude responses carry a watermark based on the SynthID-Text method, and explained how it works on 14 August 2026; models released from 2 August 2026 ship with it, older ones are being retrofitted. It sits in the choice of words, not in special characters: according to Anthropic, nothing is added to the text and no hidden characters are created. Google has watermarked Gemini text with SynthID since 2024. OpenAI has still not shipped a watermark for ChatGPT text.

For text, not publicly at the moment. Reading a SynthID-Text watermark requires the key held by the provider that generated the text. Anthropic has announced a detection API but has not opened it generally. Google's SynthID Detector portal launched at Google I/O in May 2025 and runs on a waiting list for journalists, media professionals and researchers; it covers image, audio, video and text, but only recognises content carrying Google's own SynthID key — so not Claude text. Any freely available "watermark checker" you find online is almost always checking special characters, not the statistical watermark.

No, not for how it was produced. Google's spam policies target scaled content abuse, defined as generating many pages for the primary purpose of manipulating search rankings rather than helping users. The documentation explicitly names the use of generative AI tools to produce many pages without adding value as an example. The yardstick is therefore purpose and outcome, not the tool. A carefully researched text written with AI support does not fall under the rule; a hundred thin pages out of a generator do.

Check them, yes — but check the right things. A detector score says nothing about whether the numbers are right, whether the sources exist, whether the expertise holds up and whether the claims fit your company. A short acceptance checklist works better: are concrete figures and sources given? Are there claims nobody can substantiate? Is there real experience in the text? Is authorship clear? Also agree in writing whether and how AI may be used. That is more dependable than any percentage.

Commercially, hardly. You are then optimising for a tool nobody in your sales process uses, and the text usually gets worse rather than better: swapping in synonyms and artificially varying sentence length costs precision. A statistical watermark will not reliably disappear either, because it sits in the word choice across longer passages. It is more productive to load the text with your own knowledge, concrete figures and a clear position. That solves the detection question as a side effect and improves the reading experience at the same time.

Not sure your content process holds up?

We review your existing content and tell you where substance is missing, where evidence is missing, and where AI genuinely takes work off your hands — without putting visibility at risk.

Have your content process reviewed