Can you bypass AI detection?
Sometimes, against a specific detector, with a rewrite that changes how the text is built. Here's what moved the score in our tests, what didn't, and why no one can promise it for every detector.
Updated October 1, 2026
How a detector decides
A detector gives your text a score, then compares it with a line. The line is set so that a chosen share of real human writing, often 1 in 100, is flagged by mistake. Anything above the line is called AI. Getting past detection means getting the score under that line without changing what the text says.
Tricks that don't work
The RAID benchmark applies the usual tricks to ChatGPT and GPT-4 text: lookalike letters from other alphabets, zero-width spaces, extra whitespace, odd capitalisation, synonym swaps, misspellings, dropped articles, inserted paragraph breaks, paraphrasing. At its 5% line, MELD caught 100% of the AI texts under every one of the 11 tricks (public_report.txt).
Character tricks also tend to backfire with people: a teacher or editor who finds Cyrillic letters or invisible characters in a document has stronger evidence than any detector score.
What moved the score, and what didn't
- AI drafts, untouched (general web text)
- Flagged as AI93.3%
- Stock phrases removed, words swapped
- Flagged as AI92.7%
- Rewritten by a model shown two examples, one try
- Flagged as AI60.7%
- Same, best of four
- Flagged as AI26.0%
- Rewritten by our trained model, one try
- Flagged as AI19.3%
- Our trained model, best of four
- Flagged as AI2.7%
| What we tried | Flagged as AI |
|---|---|
| AI drafts, untouched (general web text) | 93.3% |
| Stock phrases removed, words swapped | 92.7% |
| Rewritten by a model shown two examples, one try | 60.7% |
| Same, best of four | 26.0% |
| Rewritten by our trained model, one try | 19.3% |
| Our trained model, best of four | 2.7% |
Pilot set, report.txt: the same 300 drafts, the same detector (MELD) at its 1% line. The jump comes from rewriting sentences, not from editing words. Best of four is picked by the same detector that grades it, so treat the one-try rows as the honest ones.
What the research says about paraphrasing
Paraphrasing has beaten detectors before. In a 2023 study, a purpose-built paraphrasing model cut DetectGPT's detection rate from 70.3% to 4.6% while holding false alarms at 1% (Krishna et al.). The same paper proposed a defence: a provider keeps a record of what its model generated and checks new text against it.
Detectors trained since then include paraphrased text in their training data, which is part of why the RAID paraphrase trick above no longer worked against MELD. Expect the same cycle to repeat.
Passing one detector isn't passing them all
- Of commercial humanizers' rewrites that MELD let through, GPTZero still flagged 33–36% and Originality 22–33% (about 2,400 rewrites from two public benchmarks).
- Prompting alone can get past a detector on some kinds of writing. Asked to explain things simply and avoid AI habits, GLM 5.3's answers were caught 2% of the time at MELD's shipped line and GPT-5.6 Luna Pro's 7.5%. The same approach on advice-forum posts was caught 29–96% of the time, depending on the model.
- Detectors flag some human writing too, so "never flagged" isn't a promise anyone can keep.
- Detectors change. A rewrite that passes today can be flagged after an update.
When not to
If a school or employer bans AI help for a piece of work, getting past a detector doesn't make it allowed, and the version history of a document can show how it was written. Rewriting is for your own posts, emails and messages, where the problem is that an AI draft reads like AI.
Questions
Does paraphrasing bypass AI detection?+
A light paraphrase rarely does. In our tests, cleaning stock phrases and swapping words moved the flagged rate by less than one point. Sentence-level rewrites by a model trained on human writing moved it by about 74 points on one try.
Do tricks like special characters or invisible spaces work?+
Not against current detectors. Under all 11 RAID tricks, including lookalike letters and zero-width spaces, MELD caught 100% of the AI texts at its 5% line. People who find such characters also tend to treat them as evidence.
Does asking the AI to write like a human work?+
Sometimes, depending on the writing. Simple explanations from some models prompted to avoid AI habits were caught only 2–17% of the time by MELD; advice-forum posts from the same prompt were caught much more often.
Does it work on Turnitin or GPTZero?+
We haven't run our own rewrites through either yet. Public benchmark data show why it matters: of humanizer rewrites MELD let through, GPTZero still flagged about a third.
Can any tool guarantee undetectable AI text?+
No. Detectors disagree with each other, change over time and flag some human writing. A tool can show how it did against named detectors on named texts; a guarantee is a sales line.
Is bypassing AI detection cheating?+
It depends on the rules for the work. Where AI help is banned, yes. For your own posts and emails, there's no rule to break; the goal is text that sounds like you.
Sources and dates
- MELD, the open-source detector we test with (Hugging Face)huggingface.co
- PAN 2026 and RAID texts (Hugging Face)huggingface.co
- Krishna et al., Paraphrasing evades detectors of AI-generated text (arXiv, Mar 2023; NeurIPS 2023)arxiv.org
- HumanizerBench (Hugging Face)huggingface.co
- ai-humanizer-benchmark (Hugging Face)huggingface.co
- mild-rgb ELI5 and AITA human-vs-AI sets (Hugging Face)huggingface.co
Facts about other products come only from these pages, on the dates shown; prices are as published that day. Macaron's own details are as shipped on October 1, 2026. Products change, so check their sites for the latest.