Updated: 2026-09-28
GuideHow AI Detectors Work: Perplexity, Burstiness & Limits (2026)
AI detectors don't read your writing the way a teacher does. They run statistics on it — measuring how predictable your word choices are and how uniform your sentences sound. Understand those two measurements and you understand every detector on the market, including why they all fail in the same ways.
The core idea: statistics, not understanding
A language model generates text by repeatedly picking likely next words. That leaves a statistical fingerprint: the output hugs the probable, avoids the surprising, and keeps a steady rhythm. Detectors invert the process — they score how “model-like” a text's statistics are. No comprehension is involved, which is both why detectors work at all and why they're so easy to fool: anything that disturbs the statistics disturbs the verdict.
Perplexity, explained simply
Perplexity measures how predictable word choices are. When a model writes, it favors the most likely next word — “the cat sat on the mat” rather than “the cat sat on the radish.” Sustained low perplexity (everything predictable) reads as AI; spikes of unpredictability read as human. Human writers surprise constantly — unusual metaphors, odd word choices, domain jargon used loosely. That's the signal.
The catch: plenty of human writing is low-perplexity too. Legal boilerplate, technical documentation, ESL writing with simple vocabulary, and the five-paragraph school essay all hug predictable patterns — which is why detectors disproportionately flag non-native writers and formulaic genres. Low perplexity means “predictable,” not “artificial,” and detectors can't tell the difference.
Burstiness, explained simply
Burstiness measures variation in sentence structure — length, complexity, rhythm. Human writing is bursty: a long winding sentence, then a fragment. Then another medium one. AI output tends toward metronomic uniformity: every sentence a comfortable medium length with similar construction. Detectors quantify that variance, and low variance scores as AI.
This is why the most effective humanizing technique is structural, not lexical. Swapping synonyms doesn't change sentence rhythm; breaking sentences up, merging them, and varying cadence does. It's also why genuinely rewriting in your own voice beats every tool — your natural rhythm is already bursty.
Other signals detectors use
- Repetitiveness: models repeat favored phrases and transitions (“delve,” “in today's fast-paced world”). Unusual repetition elevates AI scores.
- Lack of personal grounding: specific names, dates, quantities, and lived details are hard to fake fluently — their absence is a soft signal.
- Uniform paragraph structure: same-length paragraphs with parallel topic sentences look generated, because often they are.
- Watermarking (emerging): some model providers embed invisible statistical watermarks (like SynthID) in output. Detectors that check watermarks can be highly confident — but only for watermarked models, and watermarks don't survive heavy editing.
- Stylometric comparison: some systems compare a submission against your known writing style. A sudden style shift flags louder than any absolute score.
Why detectors fail: the five classic cases
- Paraphrased AI text: restructuring disturbs the statistical fingerprint. Every detector's accuracy drops here — it's the fundamental arms race of the category.
- Short texts: under ~150 words there isn't enough signal for reliable statistics. Scores on short passages are noise; serious tools warn about this.
- ESL and non-native writing: simpler, more predictable phrasing mimics low perplexity. Independent tests consistently show elevated false-positive rates — a fairness problem the industry hasn't solved.
- Formulaic genres: legal, technical, and template-driven writing is uniform by convention. The detector sees the genre, not the author.
- Heavily edited AI text: human revision injects real irregularity. Enough genuine editing and the fingerprint is gone — which is also why “write it yourself” is the ultimate bypass.
Can detectors be trusted?
As screening signals, yes — with the right tool, the right content type, and sensible thresholds, they catch plenty of raw AI output. As proof, no — and no serious vendor claims otherwise. The responsible pattern: high thresholds, agreement across two tools, and human judgment before any accusation. Schools that skip those steps manufacture false accusations; publishers that skip them burn freelancer relationships.
What this means for you
- Writing with AI assistance? Rewrite in your voice and vary your rhythm — our bypass guide has the full workflow.
- Checking others' writing? Pick the right tool in our detector ranking, and never act on a single score.
- A student? Our student guide covers pre-submission checks and what to do if you're flagged unfairly.
- Choosing a humanizer? Now you know what to demand: structural rewriting, not synonym-swapping. See the humanizer ranking.
What is perplexity in simple terms?
How predictable the word choices are. AI picks likely words, so its text has low perplexity; humans surprise more. Detectors flag sustained low perplexity — which also catches predictable human writing.
What is burstiness?
How much sentence length and structure vary. Humans mix long sentences, short ones, and fragments; AI tends toward uniform medium sentences. Low variation scores as AI.
Can detectors tell which AI model wrote something?
Some claim model attribution, but reliability is low — especially after editing. Treat attribution claims skeptically.
Do detectors work on short text like tweets?
Poorly. Under ~150 words there isn't enough statistical signal, and scores become unreliable. Don't trust short-text verdicts.
Why was my human writing flagged as AI?
Most likely: it's short, formulaic, or uses simple predictable phrasing — all of which mimic AI statistics. It's a false positive, and it's common. Keep your drafts as evidence and dispute it.
Will detectors get better?
They retrain constantly, and each generation closes some gaps — while humanizers open new ones. Expect the arms race to continue, not a final winner.
A brief history of AI detection
Detection started as a curiosity in the GPT-2 era (2019), when OpenAI itself released a detector for its own model — it worked because one lab controlled the generator. The ChatGPT explosion of late 2022 changed everything: suddenly everyone could generate fluent text, dozens of detectors launched within months, and accuracy claims got wild. 2023–2024 brought the education panic — schools banning, then un-banning, then regulating AI — and detectors became disciplinary infrastructure before the science was ready. 2025 was the counter-offensive: Turnitin's model update specifically targeted humanizer evasion, humanizer vendors answered with structural rewriting, and the “99% accuracy” marketing era quietly ended as false-positive scandals piled up. 2026: the mature arms race — no settled winner, process-based verification rising, and policy finally catching up to technology.
The lesson of that history: every confident claim about detection has eventually been humbled by the next model generation — on both sides. Treat current capabilities as temporary.
Glossary: detection terms in plain English
- Perplexity — how predictable word choices are. The core signal: low perplexity reads as AI.
- Burstiness — variation in sentence length and structure. Humans vary; models don't.
- False positive / false negative — human flagged as AI / AI missed as human. The two error types every detector trades off.
- Watermarking — invisible statistical signatures embedded by some model providers (e.g. SynthID). Powerful when present; absent in most text you'll encounter.
- Stylometry — comparing a text against a known author's style. Stronger than absolute scoring when reference samples exist.
- Adversarial evasion — techniques (humanizers, paraphrasing) designed to defeat detectors. The other half of the arms race.
What's the difference between AI detection and plagiarism detection?
Plagiarism detection matches text against existing sources — it's lookup. AI detection guesses at statistical origin — it's inference. A text can be 100% original and still flag as AI, or plagiarized yet score 'human.' They're different tools for different questions.
Are detectors biased against non-native speakers?
Effectively, yes — not by intent but by statistics. Simpler, more predictable phrasing (common in ESL writing) mimics the low-perplexity patterns detectors flag. Independent tests consistently show elevated false-positive rates. It's the industry's most serious fairness problem.
What detectors can't do (and won't soon)
- Prove authorship. Statistics describe resemblance, not origin. Proof requires process evidence.
- Handle short texts reliably. Below ~150 words there isn't enough signal; scores are noise.
- Survive heavy human editing. A genuinely revised draft defeats every statistical detector — which is also why editing is the honest answer.
- Stay current alone. Every model generation shifts the statistical landscape; detectors need constant retraining.
- Replace judgment. The final call on authenticity is human, contextual, and procedural. Tools inform it; they don't make it.
Internalize that list and you'll read detector marketing — and detector scores — with appropriately calibrated skepticism. The technology is useful the way a smoke alarm is useful: good at alerting, terrible at convicting.
Can AI detect its own writing reliably?
Ironically, models are mediocre at recognizing their own outputs — detection models are trained separately on human-vs-AI classification, and self-recognition isn't a designed capability. Don't ask a chatbot 'did you write this' and trust the answer.
Will quantum computing change detection?
No — detection is a statistics and data problem, not a compute problem. The arms race will be decided by training data and model design, not raw hardware.
What's the single best defense against false accusation?
Process evidence: drafts, version history, notes. Statistical arguments about scores are weak; a document history showing the work being written is strong.