A Brief History of AI Text Detection: From GLTR to Watermarks (2019–2026)

Table of Contents
- Key Pointers
- What “AI detection” actually means in 2026
- The timeline at a glance
- 2019: detection started in a lab, not a classroom
- Late 2022 to 2023: detection becomes an industry
- GPTZero and the perplexity era
- Copyleaks, Winston, and the detector pile-up
- OpenAI tried, and quit
- Turnitin flips the switch
- 2023 to 2024: the accuracy backlash
- 2023 to 2025: watermarking moves from paper to product
- 2026: regulation arrives, and the labs move
- Anthropic went first
- OpenAI reversed course on 5 October 2026
- Google opened its detector, and left text out
- Does ChatGPT, Claude or Gemini watermark text?
- What this means for your classroom this semester
- Four things people get wrong about AI watermarks
- Frequently asked questions
- More from our history series
- Sign Up for Quetext Today!
Key Pointers
- AI text detection has run through three eras: statistical research tools (2019), commercial classifiers (2022–2023), and provenance marking built into the models themselves (2024–2026).
- The first AI detectors weren’t products. GLTR arrived in June 2019 from Harvard NLP and the MIT-IBM Watson AI Lab, followed by OpenAI’s GPT-2 Output Detector that November.
- Detection became a business in late 2022, months before most people noticed. Originality.ai launched 26 November 2022, four days before ChatGPT.
- A 2023 Stanford-led study found seven detectors falsely flagged over 61% of genuine TOEFL essays by non-native English writers as AI-generated. That finding reshaped the whole category.
- All three major labs now mark their text. Google’s SynthID-Text went public in October 2024, Anthropic began watermarking Claude in August 2026, and OpenAI launched textGrain on 5 October 2026.
- Here’s the part that matters this semester: no public detector for AI text watermarks exists for any lab. Google opened its SynthID Detector to everyone on 6 October 2026, but only for images, video and audio. Text is not included.
What “AI detection” actually means in 2026
Two different technologies now share one name, and conflating them causes most of the confusion you’ll see online.
Statistical AI detection analyses text after the fact. A detector reads your writing, measures how predictable the word choices are, and returns a probability score. It has no inside knowledge of who or what wrote the text. This is what Turnitin, GPTZero, Copyleaks and Quetext’s AI content detector do. It’s what schools actually use, and it’s the source of every false-accusation story you’ve read.
Watermarking works the other way around. The model embeds a hidden statistical signal while it generates the text, keyed to a secret the lab holds. A detector with that key can check for the signal later. It’s far more reliable in principle, because it isn’t guessing. It’s reading a mark that was deliberately placed.
One reads tea leaves. The other checks a signature.
Both are called “AI detection,” and in 2026 they finally split apart in a way that changes what teachers, students and editors should actually do.
The timeline at a glance
| Date | Milestone | Why it mattered |
|---|---|---|
| May 2019 | GROVER (University of Washington / Allen Institute for AI) | Built a fake-news generator first, then used it to catch its own output |
| June 2019 | GLTR released (Harvard NLP + MIT-IBM Watson AI Lab) | First widely used detector; raised human accuracy at spotting fake text from 54% to 72% |
| November 2019 | OpenAI GPT-2 Output Detector | A lab shipped a detector for its own model, free and open |
| 26 November 2022 | Originality.ai launches | First dedicated commercial AI detector — four days before ChatGPT |
| 30 November 2022 | ChatGPT launches | Demand for detection goes from niche to universal |
| Early Jan 2023 | GPTZero launches | Princeton student Edward Tian popularises perplexity and burstiness |
| 24 January 2023 | Kirchenbauer et al., "A Watermark for Large Language Models" | The green-list method that every text watermark since is built on |
| 31 January 2023 | OpenAI AI Text Classifier | Caught 26% of AI text, false-flagged 9% of human text |
| 5 April 2023 | Turnitin switches on AI detection | Detection reaches 10,700+ institutions at once |
| 20 July 2023 | OpenAI retires its classifier | Withdrawn "due to its low rate of accuracy" |
| July 2023 | Liang et al. published in Patterns | Mean false positive rate just over 61% on non-native English essays |
| 23 October 2024 | SynthID-Text published in Nature and open-sourced | Watermarking moves from paper to live product across Gemini |
| 2 August 2026 | EU AI Act Article 50 becomes enforceable | Marking synthetic output becomes a legal duty, not a choice |
| 11 August 2026 | Anthropic begins watermarking Claude text | First lab to mark text at the model level, worldwide |
| 5 October 2026 | OpenAI launches textGrain | ChatGPT and Codex text watermarked in the EU |
| 6 October 2026 | Google opens SynthID Detector to the public | Images, video and audio only — text excluded |
2019: detection started in a lab, not a classroom
Nobody built the first AI detectors to catch students. They were built because researchers were nervous about what they’d just made.
In May 2019, a team from the University of Washington and the Allen Institute for AI released GROVER on a bet: the best way to catch machine-written text is to build the machine that writes it. Train a model to generate fake news, and it recognizes its own fingerprints better than anything else can.
A month later came the tool that actually caught on. GLTR, the Giant Language model Test Room, was published on 10 June 2019 by Sebastian Gehrmann, Hendrik Strobelt and Alexander Rush, out of Harvard NLP and the MIT-IBM Watson AI Lab. It worked by colour-coding every word in a passage according to how predictable that word was to a language model. Green for the obvious next word, red for the surprising one. A machine-written passage lit up almost entirely green.
The paper reported something more useful than any accuracy score: with GLTR’s colouring in front of them, untrained humans went from spotting fake text 54% of the time to 72%.
That November, OpenAI released its GPT-2 Output Detector alongside the full 1.5-billion-parameter model. A RoBERTa classifier, free on Hugging Face, aimed at researchers.
None of this was a product. Nobody was charging for it. There was no market, because almost nobody outside research labs was generating text at scale yet.
That lasted about three years.
Late 2022 to 2023: detection becomes an industry
The commercial era started slightly before the moment everyone remembers.
Writer.com added a free AI content checker to its platform in October 2022. Originality.ai launched a dedicated paid detector on 26 November 2022. ChatGPT arrived on 30 November 2022. Within weeks, “AI detector” went from a term almost nobody searched to one of the fastest-rising queries in education.
Then the rush.
GPTZero and the perplexity era
In the first days of January 2023, Princeton undergraduate Edward Tian launched GPTZero, built with co-founder Alex Cui. It scored text on two measures: perplexity, how surprising the word choices are to a language model, and burstiness, how much sentence length and structure vary across a passage. Human writing is lumpy. Model writing is smooth.
About 30,000 people used it in the first week. It crashed.
Those two concepts became the public’s mental model of how detection works, and they’re still roughly how statistical detectors operate. Our GPTZero accuracy review goes deeper on where that approach holds up.
Copyleaks, Winston, and the detector pile-up
Copyleaks announced its detector on 12 January 2023. Winston AI followed on 28 January, built specifically for schools. Every plagiarism tool on the market was adding AI detection, including Quetext.
OpenAI tried, and quit
On 31 January 2023, OpenAI released its AI Text Classifier. The numbers in its own announcement were not reassuring: it correctly flagged 26% of AI-written text, and wrongly flagged 9% of human-written text as AI.
It lasted under six months. On 20 July 2023, OpenAI pulled it with a one-line note. No longer available “due to its low rate of accuracy.” Our breakdown of OpenAI’s retired AI Text Classifier covers what went wrong.
Turnitin flips the switch
On 5 April 2023, Turnitin activated AI writing detection across its existing products, reaching more than 10,700 institutions and 2.1 million educators overnight. No opt-in. No pilot.
Turnitin said it flagged text only at 98% confidence, keeping false positives under 1%. That claim became the most argued-over number in education technology, and our Turnitin AI checker review looks at how it has held up.
2023 to 2024: the accuracy backlash
Detection scaled faster than its evidence base, and the correction arrived quickly.
The study that did the damage was led by James Zou’s group at Stanford and published in Patterns in 2023. Researchers ran 91 genuine TOEFL essays, written by human students who were all non-native English speakers, through seven widely used detectors.
The mean false positive rate was just over 61%. Eighteen of the 91 essays were flagged as AI by all seven detectors. Eighty-nine of 91 were flagged by at least one.
The same detectors were near-perfect on 88 essays written by US eighth-graders.
The mechanism is almost banal. Detectors read low vocabulary variety and simple sentence structure as machine-like. Those are exactly the markers of someone writing competently in a second language. We’ve written separately on AI detector bias against ESL students.
What followed was predictable. Vanderbilt, Northwestern and others switched Turnitin’s AI detection off. We track the pattern in universities restricting AI detectors.
There’s a newer chapter worth knowing about. In February 2026, researchers at Charles University and the University of Oslo revisited the bias question in Czech and found no systematic penalty against non-native writers. When they re-ran a commercial detector against the original Liang TOEFL set, the false positive rate had dropped to 23.1%.
Better. Not fixed. A 23% false positive rate still means roughly one in four honest students gets flagged.
The lesson that survived both studies: a detection score is a reason to look closer, never a verdict on its own. That’s the position we take on AI detector false positives.
2023 to 2025: watermarking moves from paper to product
While classifiers were losing credibility, a different approach was maturing.
On 24 January 2023, John Kirchenbauer and colleagues at the University of Maryland published A Watermark for Large Language Models. The idea is elegant. Before the model picks each word, a secret key pseudo-randomly marks part of the vocabulary as “green.” The model gets nudged toward green words without being forced. Over a few hundred words, green tokens show up far more often than chance allows, and a statistical test can say so with a p-value, without needing access to the model at all.
Nobody needs to see the text being generated. The mark is in the word choices themselves.
Zero-shot detection advanced alongside it: DetectGPT (ICML 2023), Fast-DetectGPT (ICLR 2024), and Binoculars (2024), each squeezing more signal out of probability curvature without training a classifier.
Then Google shipped it. On 23 October 2024, DeepMind published SynthID-Text in Nature and open-sourced it the same week. It had already been running live across Gemini, and the team validated it against roughly 20 million real Gemini responses. Users didn’t notice a quality difference.
Google also flagged the limits honestly: it works best on longer, open-ended text, less well on short factual answers, and it degrades when text is heavily rewritten or translated.
In August 2024, OpenAI confirmed it had built a text watermark and chosen not to ship it. Its stated reasons: the method was trivial for bad actors to circumvent via translation, and it risked stigmatising AI use among non-native English speakers.
That position held for two years.
2026: regulation arrives, and the labs move
The EU AI Act forced the issue
As of August 2nd, 2026, Article 50 of the EU AI Act has come into action requiring those in the field of generative AI technology to watermark images, audio, video, and text produced. The marking needs to be machine-readable, and detection interface must be provided for free.
The three sections of the Act specify the following:
- On August 2nd, 2026, new obligations come into force
- On December 2nd, 2026 products that are in use since before August need to comply with the marking requirements
- On February 2nd, 2027 providers of generative AI technology need to determine various solutions for interoperability in terms of watermark detection
The final Code of Practice was released on June 10th, 2026 and confirmed by the Commission in July, requiring a digitally signed meta-tagging and subtle watermarking technologies. The code includes simplified requirements for free text with no embedded metadata.
Anthropic went first
On 11 August 2026, Anthropic began embedding an imperceptible watermark in Claude’s text output. Per Anthropic’s own documentation, Claude models launched on or after 2 August 2026 support machine-readable marking at launch. It’s applied at the model level, worldwide. Not an EU-only feature, and not something a user can switch off.
Anthropic is unusually candid about what the mark proves. A detected watermark is “a signal that content was processed by Claude, but is not fully conclusive.” Claude may only have proofread or translated someone else’s writing. And a missing mark proves nothing either: the passage may be too short, heavily edited, translated, or from an older model.
Detection sits in private preview, open to regulators, researchers, media, fact-checkers and educational organisations by application.
OpenAI reversed course on 5 October 2026
Three days before this post went up, OpenAI announced textGrain, an invisible statistical watermark added to the model’s word choices.
The rollout is narrower than the headlines suggest:
- ChatGPT and Codex: eligible text output in the European Union only, across all plans, rolling out over the coming weeks
- API: opt-in, available worldwide from 5 October, and off by default
So a student in Dublin gets watermarked ChatGPT output. A student in Boston does not.
OpenAI published detection figures that are worth quoting exactly, because almost nobody else has them. At a 1% false positive rate, the detector caught about 80% of 200-token passages and about 95% of 400-token passages of psychology text. Detection was substantially worse on mathematics.
Now the part that answers the question everyone asks. Replace 10% of the words with synonyms and detection on a 400-token passage falls from about 92% to 66%. Replace 25% and it drops to 17%.
OpenAI’s own summary: “Strong performance under ideal conditions does not guarantee reliable detection in everyday use.”
Google opened its detector, and left text out
On 6 October 2026, Google made its SynthID Detector portal publicly available. Anyone can sign in and upload a file to check for a SynthID watermark.
Twenty file formats are supported: 11 image, 3 video, 6 audio.
No text.
Does ChatGPT, Claude or Gemini watermark text?
Status as of 8 October 2026:
| Provider | Text watermark? | Where it applies | Can you check it? |
|---|---|---|---|
| OpenAI (ChatGPT, Codex) | Yes, textGrain, from 5 Oct 2026 | EU only for ChatGPT/Codex; API opt-in worldwide, off by default | No. Detector access is by application, for approved researchers and expert organisations |
| Anthropic (Claude) | Yes, from 11 Aug 2026 | Worldwide, model level, models launched on/after 2 Aug 2026 | No. Private preview for eligible organisations, by request |
| Google (Gemini) | Yes, SynthID-Text, live since 2024 | Gemini outputs | Not for text. The public SynthID Detector covers images, video and audio only |
| Meta, xAI, open-source models | No published text watermark | — | No |
Read that last column again. Every lab now marks its text. Not one of them lets a teacher, editor or employer check it.
What this means for your classroom this semester
If you expect that watermarking will settle the dispute regarding authorship, rest assured that it has not and will probably not ever resolve it.
Four things are true simultaneously:
Coverage is riddled with gaps. US ChatGPT results are not subject to watermarking. API results are by default not watermarked, and older models are unmarked. No one will ever watermark open-source models that run on a laptop.
Brief text cannot be watermarked reliably. Statistical watermarking requires space; a 100-word discussion post cannot provide space for a watermark.
Paraphrasing is effective. This is confirmed by the figures from OpenAI: 25% of synonyms will reduce the detectability to 17%. All “humanizing” tools use this approach.
You will not be able to check it anyway. Public tools for detecting text do not exist, neither for ChatGPT nor for Claude or Gemini.
Thus, the content-based detection and evidential process still mean something. Work drafts, version history in Google Docs, outline, in-class writing, and a two-minute discussion with the student about the argument he made are the most reliable clues available to the teacher in 2026.
If you want a pre-submission check on your own work, run it through our free AI detector and pair it with a plagiarism check before you hand it in. Treat the score as information, not a verdict. Ours included.
Four things people get wrong about AI watermarks
“The watermark comprises covert Unicode characters, which can be deleted using Notepad.” Nopes! The watermark used in both TextGrain and Claude is based on statistics. It skews what words the AI chooses based on a hidden key. No character is added. Copying into a plain text editor does not take anything away.
“ChatGPT has been marking its texts all along.” Not true! OpenAI admitted in August 2024 that it created a marker and did not make it public. TextGrain went live on October 5, 2026.
“SynthID works the same way for text and images.” Wrong! SynthID operates independently in both cases. Google’s public detector works with SynthID in images and video, but the text version is different and is not present on the portal.
“The presence of em dash in a text is a clear indication it was written by AI.” Em dashes, as well as words like “dink” and parallel structure are just parts of the style that were adopted when training the model. The detector score does not prove anything either!
Where this goes next
Three things to watch, all grounded in commitments already on paper.
February 2027 is the significant date. The European Union is requiring interoperable watermark detection by February 2nd, 2027. This means that instead of relying on one portal for each lab, detection will become possible with one tool before the suppliers. This is the change that would have an actual impact on teachers’ workflow.
Detector access will broaden progressively. According to both OpenAI and Anthropic, detector access will be expanded beyond the application-only preview stage. Both of them explain that a reason for such action is the risk of false positive, which is a problem faced in statistical detection in 2023.
The two methods will merge rather than compete. Watermarks will indicate that a section is associated with a specific text-generating algorithm. A statistical detector will also show that a passage is machine-generated or machine-like in nature, irrespective of the algorithm from which it came. The two technologies do not compete with each other but are separately useful yet both used at the same time.
It has been seven years since GLTR first colored words green, and the answer is still the same: we can tell how a text is produced, but we cannot determine who wrote it.
What changed in 2026 is that the research was finally made to do its own work and verify its own results. Start with a free ai detection scan.
Frequently asked questions
When were AI detectors invented?
In 2019, AI text detectors were developed as products of research studies. University of Washington along with Allen Institute for AI introduced GROVER in May. GLTR of Harvard NLP and the MIT-IBM Watson AI Lab appeared in June, while OpenAI’s GPT-2 Output Detector was launched in November. Writer.com came with the very first commercial text detection software in late 2022, followed later by Originality.ai and a massive inflow of companies using this technology after ChatGPT shook the market of AI applications.
- Research phase: 2019
- World’s 1st dedicated commercial text detector: November 2022
- Critical mass: January – April 2023
Does ChatGPT have a watermark?
Yes, starting from the fifth of October of the year 2026, but not anywhere. OpenAI is introducing an invisible watermark to any of its eligible outputs generated by both ChatGPT and Codex in the European Union, as the process of introduction begins. The API access will be available to people worldwide and will be only activated upon request. No watermarks will be present on ChatGPT generated outputs produced outside the EU.
- ChatGPT and Codex outputs in the EU will be watermarked.
- ChatGPT and Codex outputs outside the EU will not be watermarked.
- Detector access will be possible only through an application.
Can AI watermarks be removed?
The effectiveness of the detection consistently diminishes. OpenAI reports that when a text passage with 400 tokens has 10% of its words replaced with synonyms, the detection declines from around 92% to 66%, and at a 25% word substitution, it drops to 17%. The translation and heavy editing contribute to further weakening of the original signal. The translated text does not contain any signal for detection of marks because of the very short length of the text. Google reported similar findings regarding SynthID-Text in 2024.
- Detection goes down to about 66% with 10% word replacement
- Detection decreases to about 17% with 25% word replacement
- Text of a very short size does not stay detectable for marks
Do AI detectors still matter if text is watermarked?
At present, yes. Watermarks are present on a limited set of models and in a limited set of regions and can currently only be read by approved research institutions. On the other hand, statistical detectors work with any written text, from any source, including open-source models with no watermarks. In practice, one should use both types of detection as complementary means of assessing the results.
- Watermarks: limited coverage, no public detectors
- Statistical detection: wide coverage, probabilistic but not definitive
Who can check Claude’s watermark?
Anthropic is operating watermark detection in a private preview. Regulating authorities, law enforcement agencies, media organizations, independent researchers, fact-checkers, educational institutions, as well as civil society groups, and companies (which have their own compliance responsibilities under the AI Act) may apply for access. Anthropic will grant access upon request and has plans to open it widely in the future. There is a Content Checker available for free, working separately with Claude’s file-level Content Credentials.
- Access: available by application
- Eligible applicants list includes educators
- File-level Content Credentials are checked for free
Are AI detectors accurate for non-native English speakers?
In the past, it had not managed to make a name for itself. According to the 2023 Stanford research conducted in Patterns, the detectors preceding this experiment produced false results for over 61% of real TOEFL texts produced by non-native speakers. The replication experiment conducted in February 2026 has established that this figure has dropped to 23.1% for one of the detectors on the same set of texts. Documentation proves that no systematic bias was observed in Czech.
- 2023: the mean false positive rate is right above 61%
- 2026: 23.1% is reported for the same essays.
- Do not rely on the score as proof.
Can Google’s SynthID Detector check AI text?
Incorrect. The SynthID Detector portal was released to the public by Google on 6 October 2026 and allows for the use of 20 different file formats: 11 for images, 3 for videos and 6 for audio files. Although Synth-Text has been operational since 2024, the text file formats continue to remain unsupported. The portal requires users to sign in, has limitations on the daily number of uploads and does not allow programmatic access.
- Released on 6 October 2026
- Only for images and audio
- No text checking available
More from our history series
If dated, sourced histories are your thing, we’ve done this before:
- A short history of academic plagiarism: how the idea of stealing words became an offence worth punishing
- A brief history of the footnote: the citation format that made modern scholarship auditable
Teachers managing a whole class can also look at AI detection for teachers, and students checking their own drafts at AI detection for students.
