How do you make AI-generated text undetectable?
Raising perplexity defeats text detectors — Stanford researchers bypassed seven of them with a single prompt asking for more literary language. But undetectable isn't the same as safe: detectors aren't what catch people. Missing draft history, fabricated citations, and being unable to explain your own argument are.
Why — the first-principles explanation
Understand the mechanism and the answer is almost boring. Text carries no origin signal — nothing is embedded in words. So detectors score perplexity: how surprising each word is, given the words before it. Language models are built to pick high-probability words, so raw output is unusually unsurprising. Detectors flag that, plus low burstiness (sentences of monotonously similar length and complexity).
So anything that raises perplexity lowers the score. Unusual word choices. Varied sentence lengths. Digressions. Small imperfections. This is what "humanizer" tools sell, and it's why they work at all. Stanford's team demonstrated the whole thing with one prompt: asking a model to rewrite text "employing literary language" was enough to evade the seven detectors they tested. There's no secret. The lock is a proxy, and the proxy has an obvious dial.
But here's the trap in the question, and it's the reason this page exists. Detectors are not what catch people. They're unreliable in both directions and increasingly known to be — Vanderbilt disabled Turnitin's AI detector in August 2023, and the FTC took action against a vendor whose advertised 98% accuracy tested at roughly 53%. What actually catches people is everything the detector never looks at: a document whose version history shows 900 finished words pasted at 11:52 p.m. with no typing; three citations that don't resolve; a quote that doesn't appear in the source it's attributed to; work that doesn't sound like anything you've written before; and the two-minute conversation where you're asked to explain your own third paragraph. Beating the detector improves your score on the one test nobody's grade depends on.
And the same mechanism runs in reverse, which is the part worth knowing regardless of why you're here. If plain writing scores as AI — and it does, at 61.22% for TOEFL essays in the Stanford study — then rewording can't clear you either. The people searching this question split roughly into two groups: those trying to hide AI, and those who wrote every word themselves and got flagged anyway. Both are reaching for style. Both should be reaching for provenance. A revision history is evidence. A perplexity score, in either direction, is a guess.
An example that makes it click
Think of a metal detector at a beach. Someone tells you it beeps at metal, so you wrap your keys in cloth and walk through silently. Clever. You beat the machine.
Now the lifeguard asks where you got the watch on your wrist. The metal detector was never the thing standing between you and trouble — it was a gadget on the way in. The actual test is a person asking a question you can't answer. Meanwhile a kid with braces gets beeped at every single time, wraps nothing, hides nothing, and still gets stopped daily. That's the whole picture: the machine is easy to fool and impossible to escape, depending entirely on which side of it you're standing.
How to do it
- Understand the dial before touching it: detectors score predictability, so unusual words and uneven sentence lengths lower the score while plain, careful prose raises it — regardless of who wrote it.
- Know what humanizers actually do. They mechanically raise perplexity. Turnitin's February 2026 model update specifically targets content modified by humanizer tools, so any given tool's success rate drifts as vendors retrain.
- Know what paraphrasing does. Turnitin reports AI-generated-then-AI-paraphrased text as its own category in a separate highlight color, so paraphrasing changes what the report says rather than silencing it.
- Weigh the real exposure. Detector scores rarely stand alone in a misconduct case; missing draft history, unresolvable citations, and an inability to discuss your own work are what turn a flag into a finding.
- If you're falsely flagged, don't reword — document. Write in Google Docs or Word on the web with version history on from the first sentence, and keep your outline and notes in the same file.
- If you're falsely flagged, ask for specifics: the exact score, the word count, and the highlighted passages. Turnitin needs 300+ words and asterisks anything from 0 to 20% as unreliable by its own admission.
- Cite the vendor's own limits in your defense. Turnitin states its detection may misidentify human-written text and must not be the sole basis for adverse action against a student.
- If AI use is permitted where you are, disclose and cite it. Vanderbilt's guidance to instructors recommends exactly this — permitted-and-cited carries no detection risk at all.
Key facts
- Stanford researchers found that simple prompting strategies — including asking a model to rewrite text using more literary language — both mitigated detector bias and effectively bypassed the seven GPT detectors tested (Liang et al., Patterns, 2023).
- The same study found seven detectors flagged 61.22% of TOEFL essays by non-native English speakers as AI-generated, 19% unanimously, while classifying U.S.-born eighth graders' essays near-perfectly.
- Turnitin reports AI-generated text and AI-generated text that was subsequently AI-paraphrased as two separate categories, highlighted cyan and purple respectively in the Submission Breakdown.
- The FTC alleged Workado advertised its AI Content Detector as 98% accurate when independent testing showed roughly 53% accuracy on general-purpose content; final order approved August 2025.
- Vanderbilt University disabled Turnitin's AI detector on August 16, 2023, calculating that a 1% false positive rate against its 75,000 papers submitted in 2022 would wrongly flag about 750 papers.
- Turnitin requires at least 300 words of prose, asterisks scores from 0 to 20% due to elevated false positives, and states its detection must not be the sole basis for adverse action against a student.
▶ The 60-second explainer (script)
How do you make AI text undetectable? Mechanically, it's not a secret. Text carries no origin signal — nothing is embedded in words. So detectors measure one thing: predictability. AI picks the expected word almost every time, so its writing has very few surprises. Raise the surprises and the score drops. That's it. Stanford proved it with a single prompt — asking the model to rewrite the text using more literary language was enough to bypass all seven detectors they tested. That's what humanizer tools sell. The lock is a proxy, and the proxy has an obvious dial. But here's the trap in the question. Detectors aren't what catch people. Vanderbilt turned Turnitin's off in 2023. The FTC went after a vendor whose ninety-eight percent accuracy claim tested at about fifty-three. What actually catches people is everything the detector never looks at: version history showing nine hundred finished words pasted at 11:52 PM with zero typing. Three citations that don't resolve. A quote that isn't in the source. Work that sounds nothing like what you wrote in March. And the two-minute conversation where someone asks you to explain your own third paragraph. Beating the detector wins you the one test nobody's grade depends on. And run it backwards, because half the people asking this question wrote every word themselves and got flagged anyway — sixty-one percent of essays by non-native English speakers do. If plain writing scores as AI, rewording can't clear you either. Both groups are reaching for style. Both should be reaching for provenance. A revision history is evidence. A score is a guess.
What authoritative sources say
People also ask
Do AI humanizers work?
Partially and temporarily. They raise perplexity, which is the exact signal detectors measure, so scores drop. But vendors retrain against popular humanizers — Turnitin's February 2026 model update specifically targets humanizer-modified text — so effectiveness drifts constantly.
Does paraphrasing AI text hide it?
Not cleanly. Turnitin reports AI-generated-then-AI-paraphrased text as a separate category in a different highlight color. Paraphrasing changes what the report says about the text, not whether it says anything.
I wrote it myself. How do I make it stop getting flagged?
You largely can't, by editing. Detectors flag plainness, and 61.22% of TOEFL essays got flagged in Stanford's testing. Instead, produce evidence: version history from Google Docs or Word, and the vendor's own admission that the score can't be the sole basis for action.
Will a teacher notice AI even if the detector doesn't?
Frequently, through signals the detector can't see — invented citations, a style break from your prior work, or being unable to explain your own argument when asked. Those, not scores, are what typically escalate.
Is using a humanizer against the rules?
Where AI use is prohibited, disguising it is generally treated as an aggravating factor rather than a defense. Where AI use is permitted with disclosure — which Vanderbilt's guidance recommends — there's nothing to hide in the first place.