AI writing

Can you bypass AI detection?

Sometimes, against a specific detector, with a rewrite that changes how the text is built. Here's what moved the score in our tests, what didn't, and why no one can promise it for every detector.

Updated October 1, 2026

How a detector decides

A detector gives your text a score, then compares it with a line. The line is set so that a chosen share of real human writing, often 1 in 100, is flagged by mistake. Anything above the line is called AI. Getting past detection means getting the score under that line without changing what the text says.

Tricks that don't work

The RAID benchmark applies the usual tricks to ChatGPT and GPT-4 text: lookalike letters from other alphabets, zero-width spaces, extra whitespace, odd capitalisation, synonym swaps, misspellings, dropped articles, inserted paragraph breaks, paraphrasing. At its 5% line, MELD caught 100% of the AI texts under every one of the 11 tricks (public_report.txt).

Character tricks also tend to backfire with people: a teacher or editor who finds Cyrillic letters or invisible characters in a document has stronger evidence than any detector score.

What moved the score, and what didn't

AI drafts, untouched (general web text)
Flagged as AI93.3%
Stock phrases removed, words swapped
Flagged as AI92.7%
Rewritten by a model shown two examples, one try
Flagged as AI60.7%
Same, best of four
Flagged as AI26.0%
Rewritten by our trained model, one try
Flagged as AI19.3%
Our trained model, best of four
Flagged as AI2.7%

Pilot set, report.txt: the same 300 drafts, the same detector (MELD) at its 1% line. The jump comes from rewriting sentences, not from editing words. Best of four is picked by the same detector that grades it, so treat the one-try rows as the honest ones.

What the research says about paraphrasing

Paraphrasing has beaten detectors before. In a 2023 study, a purpose-built paraphrasing model cut DetectGPT's detection rate from 70.3% to 4.6% while holding false alarms at 1% (Krishna et al.). The same paper proposed a defence: a provider keeps a record of what its model generated and checks new text against it.

Detectors trained since then include paraphrased text in their training data, which is part of why the RAID paraphrase trick above no longer worked against MELD. Expect the same cycle to repeat.

Passing one detector isn't passing them all

  • Of commercial humanizers' rewrites that MELD let through, GPTZero still flagged 33–36% and Originality 22–33% (about 2,400 rewrites from two public benchmarks).
  • Prompting alone can get past a detector on some kinds of writing. Asked to explain things simply and avoid AI habits, GLM 5.3's answers were caught 2% of the time at MELD's shipped line and GPT-5.6 Luna Pro's 7.5%. The same approach on advice-forum posts was caught 29–96% of the time, depending on the model.
  • Detectors flag some human writing too, so "never flagged" isn't a promise anyone can keep.
  • Detectors change. A rewrite that passes today can be flagged after an update.

When not to

If a school or employer bans AI help for a piece of work, getting past a detector doesn't make it allowed, and the version history of a document can show how it was written. Rewriting is for your own posts, emails and messages, where the problem is that an AI draft reads like AI.

Questions

Does paraphrasing bypass AI detection?+

A light paraphrase rarely does. In our tests, cleaning stock phrases and swapping words moved the flagged rate by less than one point. Sentence-level rewrites by a model trained on human writing moved it by about 74 points on one try.

Do tricks like special characters or invisible spaces work?+

Not against current detectors. Under all 11 RAID tricks, including lookalike letters and zero-width spaces, MELD caught 100% of the AI texts at its 5% line. People who find such characters also tend to treat them as evidence.

Does asking the AI to write like a human work?+

Sometimes, depending on the writing. Simple explanations from some models prompted to avoid AI habits were caught only 2–17% of the time by MELD; advice-forum posts from the same prompt were caught much more often.

Does it work on Turnitin or GPTZero?+

We haven't run our own rewrites through either yet. Public benchmark data show why it matters: of humanizer rewrites MELD let through, GPTZero still flagged about a third.

Can any tool guarantee undetectable AI text?+

No. Detectors disagree with each other, change over time and flag some human writing. A tool can show how it did against named detectors on named texts; a guarantee is a sales line.

Is bypassing AI detection cheating?+

It depends on the rules for the work. Where AI help is banned, yes. For your own posts and emails, there's no rule to break; the goal is text that sounds like you.

Sources and dates

Facts about other products come only from these pages, on the dates shown; prices are as published that day. Macaron's own details are as shipped on October 1, 2026. Products change, so check their sites for the latest.

Keep reading