BetaMaShop is in public beta. We improve it continuously, and your feedback shapes what comes next.
MaShop/Blog/Industry/AI Content Detection Just Got Harder to Fool
IndustryJuly 30, 2026
Read · 5 min
ai content detection · pangram

AI Content Detection Just Got Harder to Fool

A detector claiming one error per 24,000 documents now runs inside newsletters and browsers. What that changes for a business publishing its own copy.

A detection company most merchants have never heard of raised 9 million dollars this week and shipped a model it says misidentifies human writing about once in every 24,000 documents. The number is the vendor's own and worth treating carefully. What is not in dispute is where the software already runs, and that is the part a shop owner should care about.

AI content detection is not new. What is new is where it runs. It runs inside Substack. It runs on Quora. It runs as a browser extension that labels posts on X, LinkedIn, Reddit and Medium as a reader scrolls past them, and LinkedIn itself now feeds reader reports into ranking, which changes how a shop should use AI for social media posts. Which moves this out of the schools-and-cheating story it has been for two years and into the ordinary business of publishing marketing copy. It runs on music catalogues too, which is why discoverability rather than registrability is the binding constraint on a fully generated track. The classroom version has moved on too, toward AI grading that works for feedback and not for scores.

Key takeaways
  • Pangram raised 9 million dollars led by Menlo Ventures and released Pangram 4, claiming 99.66 percent detection of AI text at a 0.0041 percent false positive rate, about one error per 24,000 documents.
  • The company's own numbers do not agree with each other. Its founder told TechCrunch roughly one in 10,000 human documents gets mislabelled, and the homepage states the same one in 10,000, which is more than twice the new model's claimed rate.
  • The detector claims to catch AI text run through 13 common humanizer tools 98.83 percent of the time, which makes the rewrite-it-to-hide-it approach a poor bet.
  • API pricing moved to 0.05 dollars per 100 words, described as a two to tenfold increase depending on document length.
  • Usage grew from 2,700 monthly users in June 2025 to 120,000 in June 2026, which is the number that explains why this now touches merchants.
  • Google does not penalise AI-written content as such. Its published guidance targets scaled pages without value, so search is not the risk here, and the same guidance underpins what actually changes your citation rate in AI answers.
  • The real exposure is a reader labelling your post, a platform flagging your newsletter, or a client questioning work you actually wrote, and the fix for all three is keeping evidence rather than hiding authorship.

What was actually announced?

Two things on the same day, from a company founded roughly two years ago by two Stanford AI graduates, Max Spero and Bradley Emi.

The funding came first. TechCrunch reported the 9 million dollar round led by Menlo Ventures with Haystack, ScOp, Script Capital and Cadenza participating, alongside two model releases: Pangram 4 for text, and Pangram Image in research preview with a broader release planned within weeks. The same piece lists who is buying: Substack, which has integrated it to flag AI-written newsletters, Quora, schools and universities, publishers, literary agents and recruiters.

The technical claims came second. The Decoder's write-up of Pangram 4 reports a 99.66 percent detection rate on AI-generated text with a false positive rate of 0.0041 percent on human writing, which is the one-per-24,000 figure. The model is six times larger than its predecessor with, the company says, 14 times fewer false positives and six times fewer missed AI texts. It claims to identify text that has merely been polished by AI as distinct from text written by it, and to catch AI content pushed through 13 common humanizer tools 98.83 percent of the time. The API now costs 0.05 dollars per 100 words, a two to tenfold rise depending on document length, with the previous model available until 30 September 2026.

Do the accuracy numbers hold up?

They are consistent enough to take seriously and inconsistent enough that you should use the conservative one. Nobody outside the company has published a test of Pangram 4 yet.

Three figures circulated within a day of each other, all traceable to the vendor. The Decoder's report of the new model gives 0.0041 percent false positives, one in roughly 24,000. TechCrunch quotes Spero saying roughly one in 10,000 human documents are incorrectly labelled. And the company's own homepage states 99.98 percent accuracy with a false positive rate of 1 in 10,000, and cites verification by researchers at the University of Chicago and the University of Maryland.

The likeliest reading is mundane rather than sinister: the one-in-10,000 figure describes the product as it has been running, the one-in-24,000 is the new model's internal benchmark, and the homepage has not been updated. The third-party verification named on the homepage refers to earlier work, not to the model announced this week. TechCrunch's own hands-on testing found the system solid on fully AI-generated text but noted it occasionally flagged human-written sentences as AI-assisted.

Note

Use one in 10,000. Not because the better number is untrue, but because it is the vendor's own conservative figure, it is the one their founder says out loud, and any decision you make should survive the pessimistic case. At one in 10,000, a shop publishing three pieces a week hits an expected false flag roughly once every sixty years. At one in 24,000 it barely matters at all. Both are fine. The reason to care is not your own error rate.

Diagram showing the places an AI content detector already runs between a small business and its readers

Why would a merchant care about a detector?

Because detection has quietly moved from something an institution does to you into something a reader does about you, and those are different problems with different fixes.

The institutional version is old news and mostly irrelevant to a shop. A university checking an essay has no bearing on your product pages. The reader version is new. A Chrome extension that labels posts in a feed means a customer can be looking at your LinkedIn post with a badge on it that you did not put there and cannot remove. The same suspicion attaches to testimonial text, which is why the FTC rule now names model written reviews directly and why reading your reviews with a model stays safe while writing them does not. A newsletter platform running detection means your marketing email can be flagged inside the tool you send it with, and the feeds have since joined in, which is why LinkedIn and Snapchat now demote machine written posts rather than merely labelling them.

Three specific exposures follow from that, and only one of them is about search, now that sponsored listings sit inside the AI shopping assistant answer.

Where it can biteWhat actually happensHow much it mattersWhat to do
A reader's browser extensionYour post carries an AI label in someone's feed. No appeal, no notification to youReal but modest. It affects trust on the margin, not reachWrite with specifics only you know. Generic copy is what gets flagged and also what fails to convert
A publishing platformA newsletter or answer is flagged or down-ranked inside the platform itselfMatters if that platform is a channel you depend onRead the platform's own policy rather than guessing. Most permit AI assistance and target undisclosed volume
A client or partnerSomeone runs your work through a checker and questions whether you wrote itThe highest stakes case, and the one where a false positive costs you moneyKeep drafts, briefs and version history. Evidence of process settles it, denials do not
Google searchNothing, on the basis of authorship aloneLowest of the four, despite being the one people worry aboutFocus on value per page. The policy targets scaled output, not machine writing

The fourth row is the one worth internalising, because the fear costs merchants real hours of hesitation. Google's guidance on generative AI content does not treat AI involvement as a violation. What it targets is generating many pages without adding value, and it holds AI-written titles, descriptions and alt text to the same standard as hand-written ones. A detector's verdict on your product page is not a ranking signal.

What does a false positive rate actually mean for you?

Almost nothing at your volume, and a lot at a platform's volume, and confusing the two is where the anxiety comes from.

Take the conservative one in 10,000 that the company quotes for its AI text detector. A shop publishing three pieces of writing a week produces around 150 documents a year, so an expected false flag arrives roughly once every sixty-something years. That is not a risk you should spend a Tuesday on.

Now take the newsletter platforms, with Substack named by both The Decoder and TechCrunch among the users. A platform scanning millions of newsletters at one in 10,000 generates thousands of false flags a month. That is why platform-side detection is almost always advisory rather than automatic: the volume makes hard enforcement on a probabilistic signal unworkable, and the platforms know it. When you read that a service has integrated detection, the accurate mental model is a label or a queue for human review, not a switch that deletes your post.

The asymmetry runs the other way for the segment-level claims. Pangram 4 says it can distinguish lightly polished text from fully generated text and spot AI mixed into human writing. Sentence-level judgements on short passages are inherently noisier than document-level ones, and TechCrunch's testing found exactly that, with individual human sentences occasionally flagged as AI-assisted. So a per-document verdict deserves more weight than a highlighted sentence, and anyone waving a highlighted paragraph at you is showing you the weakest part of the tool.

Should you use a humanizer to get around it?

No, and the reason is that the arms race has an obvious asymmetry rather than that it is unethical.

Pangram's claim is that it catches text put through 13 common humanizer tools 98.83 percent of the time. Treat the exact figure as a vendor number, but the direction is structurally sound: a humanizer has to fool a detector without knowing which detector, while the detector gets to train on the humanizer's output, which is abundant and cheap to obtain. That is a bad trade for the side doing the hiding, and it gets worse each time a humanizer becomes popular enough to be worth targeting.

There is also a business reason that has nothing to do with detection. A humanizer's job is to scramble surface features while preserving the text, which means it removes nothing generic and adds nothing specific. You end up paying a second subscription to make weak copy less legible. The thing that makes copy read as human is the presence of facts a machine could not have known, which is also the thing that makes it sell. We work through that in the piece on how much editing AI written shop copy needs before it ships, and the answer never involves a laundering step.

What arrives on 2 August?

Marking obligations, from the other direction, and the timing of these two stories in the same week is the part nobody has connected.

The European Commission's summary of the AI Act transparency rules puts Article 50 into effect on 2 August 2026. Providers of generative systems must apply machine-readable marks to synthetic text, images, audio and video and enable detection, unless the system is performing an assistive function for standard editing or does not substantially alter the input or its semantics. Deployers must clearly label content that falsely appears authentic, and AI-generated text on matters of public interest published without human review. Systems already on the market get until December 2026 for the marking obligations, and penalties run to 15 million euros or 3 percent of worldwide turnover.

So detection is getting better at inferring origin in the same month that origin starts being declared at the source, and Anthropic has since begun watermarking the text Claude writes so the mark survives copy and paste. For a small shop the practical consequence is narrow and specific: the assistive-editing exemption covers most of what you do, and product descriptions you drafted with a model and then corrected are not deepfakes and not public-interest text. But the direction of travel is clear enough to plan around, and the plan is the same in both cases, which is to know and be able to show how your own content was made.

Card listing the three practical steps a small business should take in response to improved AI content detection

One more thing worth saying because it cuts against the panic. Nothing about this week changes what a customer wants from your writing. A reader who feels a product page was written by nobody in particular was already leaving that page. A detector puts a badge on a problem you could measure in your conversion rate before any of this shipped, which means the tool is a new way of observing an old failure rather than a new failure.

What the growth numbers really say

The detail that makes this a story rather than a product launch is the usage curve. Monthly users went from 2,700 in June 2025 to 120,000 in June 2026, with annual revenue up 35 times year over year according to The Decoder's report.

A tool used by 2,700 people a month is an academic integrity product. A tool used by 120,000 people a month, distributed as a browser extension and embedded in publishing platforms, is infrastructure. That transition is what changes the calculation for someone selling things online, and it happened in twelve months without most merchants noticing.

It also explains the pricing move. Raising API prices two to tenfold while shipping a better model is what a company does when demand is outrunning supply rather than when it is chasing customers. Whether the accuracy claims survive independent testing is a separate question, and one that will be answered by researchers rather than by press releases.

The counterargument deserves an airing, because there is a version of this that does hurt honest people. Detection at scale creates a category of accusation that is hard to rebut and easy to make. A writer whose style happens to be plain, or who works in a second language, or who uses an assistant for spelling and structure, can end up defending work they did. The number of people affected is small in percentage terms and large in absolute terms once the scanning volume is in the millions, and the burden falls on the accused rather than the accuser. Keeping your drafts is not paranoia in that world, it is the cheap form of insurance, and it is why the first item on the list below is a filing habit rather than a writing habit.

The practical response

Three things, none of which involve buying anything.

  1. Keep your working papers. Briefs, outlines, drafts, the notes with your product specifications in them. If a client or platform ever queries a piece, a version history is a complete answer and a denial is not. This costs nothing and it is the only real insurance against a false positive.
  2. Read the policy of each platform you publish on. Not the discourse about it, the policy. Most permit AI assistance and act against undisclosed scaled output, which is a bar you clear without changing anything.
  3. Fix the copy rather than the fingerprint. Add the specifics only you have. That improves conversion, satisfies every published policy, and happens to be the one thing no detector flags, in that order of importance.

The uncomfortable version of this news is that a detector is now a reasonably good instrument for spotting text with nothing in it. The comfortable version is that this describes the same failure your customers were already noticing without software, which is why the response is editorial rather than technical. Our wider look at which AI tools earn a place in a small business scores every tool on whether its output ships unedited, and generated copy that would trip a detector is generated copy you should have edited anyway.

For merchants building the pages themselves, the same logic applies one level down. A storefront whose product data holds real specifications gives every generated description something true to say, which is the durable answer to all of this. That is the case for an AI built shop that owns its own product data, and the credit costs of running one are a smaller line than a detection subscription plus a humanizer plus the copy you would have rewritten regardless.

Comments 0

0 / 4000Your email stays private.
No comments yet. Be the first.

Keep reading picked for you.

Describe it. MaShop builds it.

Commerce apps and websites from one sentence. No card to start.

Start building