Can AI Detectors Tell A Human Draft From AI-Edited Text?
Sometimes—but a detector can identify machine-like revision patterns without proving who wrote the draft, how much AI changed, or whether a policy was violated.
Sometimes. An AI detector can sometimes distinguish a fully human draft from text that an AI rewrote, expanded, or polished—but the result is a probability about patterns in the final text, not proof of who wrote the original ideas or how much the model changed.
This hybrid case is harder than detecting a passage generated from scratch. Human facts, terminology, argument structure, and phrasing can remain in the document while the model adds its own word choices, sentence rhythms, transitions, and organization. A detector trained mostly on fully generated output may read the surviving human material as human. A detector tuned for machine-revised text may recover more signal, but it still cannot reconstruct the writing process from prose alone.
The practical rule is simple: use an AI-detector score as a reason to review evidence, never as a self-sufficient verdict about authorship, intent, or misconduct.
What Counts As Machine-Revised Text?
Machine-revised text begins with meaningful human-written content and then passes through an AI editing step. Common instructions include:
- “Polish this paragraph without changing the facts.”
- “Rewrite this in a professional tone.”
- “Expand this draft to 800 words.”
- “Fix the grammar and improve the transitions.”
- “Shorten this while preserving every argument.”
That is different from prompting a model with a topic and asking it to produce the whole document. It is also different from taking an AI-generated draft and editing it manually afterward.
These workflows can produce similar-looking final text, but their provenance is different:
| Final document | Human contribution | AI contribution | What prose-only detection cannot prove |
|---|---|---|---|
| Fully human draft | Ideas and wording | None | That no tool was ever used |
| Human draft, AI polished | Ideas, facts, much of the wording | Style and local edits | The exact percentage changed |
| Human outline, AI rewrite | Structure and source material | Much of the wording | Whether the human contribution was substantial |
| AI draft, human edited | Instructions and later edits | Initial wording and structure | Which remaining sentences came from which source |
A binary label such as “AI” or “human” compresses all four cases into a distinction the final text may not support.
What Is Confirmed
Ordinary Detectors Can Lose Accuracy On Machine-Revised Text
The AAAI research paper Imitate Before Detect directly studied human-written passages revised by language models. The authors tested rewriting, expansion, and polishing across news, Wikipedia-style context, creative writing, and biomedical question-answering material. The revising systems included GPT-3.5, GPT-4o, Qwen2, Llama 3, Mixtral, and DeepSeek model snapshots available in 2024.
The researchers found that methods designed around fully machine-generated text performed much worse when the model revised human material. On their combined task comparison, Fast-DetectGPT reached an average AUROC of 0.7338 across rewriting, expansion, polishing, and generation. Its result was strongest on fully generated text and weakest on rewriting. That gap supports the core problem: a detector can recognize a clean machine-generation pattern yet struggle when human content remains inside the passage.
AUROC measures how well a method ranks positive examples above negative examples across a test set. It is useful for comparing detectors. It is not the probability that one particular student, employee, or author used AI.
A Detector Tuned To Machine Style Can Perform Better In Controlled Tests
The same paper proposed a method called Imitate Before Detect, or ImBD. Instead of relying only on the probability patterns associated with raw model generation, it tunes a scoring model to recognize stylistic preferences in machine-revised writing and then calculates a style-conditioned probability score.
In the paper's controlled datasets, ImBD improved average AUROC over Fast-DetectGPT by about 13 percentage points for revisions from the tested open-source models. The reported improvement was about 15 points for GPT-3.5 and about 20 points for GPT-4o across the authors' comparisons. On the four-task XSum comparison, ImBD reached an average AUROC of 0.9550, including 0.8739 for rewriting and 0.9707 for polishing.
Those are meaningful research results. They show that machine revision is not necessarily invisible and that a detector designed for the hybrid task can outperform one designed around fully generated text.
They do not establish universal detection. The study used controlled revision prompts, selected datasets, six model snapshots, and a known experimental pipeline. The paper's GPTZero comparison covered GPT-3.5-polished text in selected domains; it was not an audit of every current commercial detector, model, language, assignment, or editing workflow.
More Text Usually Gives A Detector More Signal
The ImBD paper reports that its accuracy improved as passage length increased. This matches the basic statistical problem: a few sentences provide fewer word choices, transitions, and structural patterns from which to estimate a style distribution.
Short answers, bullet lists, formulas, code, quotations, and rigid templates can therefore be especially difficult to interpret. Turnitin's current AI Writing Report guide says its model may misidentify human, AI-generated, and AI-paraphrased text. It also says the system does not reliably detect non-prose such as poetry, scripts, or code, or short and unconventional writing such as tables, bullet points, and annotated bibliographies.
Detector Vendors Also Say A Score Is Not A Verdict
Turnitin says its AI writing result should not be the sole basis for adverse action against a student. Its guide suppresses numeric scores below 20% because it observed a higher incidence of false positives in that range.
GPTZero similarly tells educators that short or heavily edited passages are harder to classify and recommends using a result as a conversation starter. Its educator guidance suggests checking edit history, reviewing prior work, collecting drafts, and asking the writer to explain the process.
Vendor statements about their own accuracy should be read as vendor claims unless independently reproduced under the same conditions. Their caution about decision-making is still important: the companies selling the detectors do not describe a single score as conclusive authorship evidence.
Broader Benchmarks Show Performance Depends On The Generator And Detector
NIST's text-to-text GenAI pilot study evaluated generators and discriminators using human- and machine-generated summaries. NIST found that performance varied substantially by system: some generators deceived most discriminators, while some discriminators detected output from almost all tested generators.
That benchmark focused on generation rather than the exact human-draft-then-AI-revision workflow. Its broader lesson still applies. “AI detection accuracy” is not one stable property. It depends on the generating model, detector, domain, language, passage length, transformation, threshold, and test distribution.
What Is Still Unclear
A detector score cannot answer several questions that often matter more than the label:
- Did the person write the original draft?
- Did the AI correct punctuation, reorganize paragraphs, or replace most of the prose?
- Which exact sentences changed?
- Was the tool used before or after the submitted version was created?
- Did the writer follow the applicable classroom, workplace, journal, or client policy?
- Did the text pass through translation, accessibility, grammar, or style tools that use language models?
- Did a model watermark or signed file record survive copying, formatting, or later editing?
- Would the same text receive the same score after the detector is updated?
The final prose usually contains no complete, tamper-evident edit history. A detector estimates whether observed patterns resemble its learned categories. It does not replay the document's creation.
Absence of a flag is not proof that no AI was involved. A high score is not proof that a person cheated. Both conclusions require additional evidence.
Why Human Drafts Can Look Machine-Written After Editing
AI editing can change the features detectors inspect while leaving the substance intact.
Word Choice
A model may replace ordinary terms with words it favors, remove regional expressions, or standardize technical language. Repeated preferences can create a machine-like statistical pattern even when the ideas and many sentences began with a person.
Sentence Rhythm
Polishing can make sentence lengths more uniform, remove fragments, balance clauses, and smooth abrupt transitions. Those changes may reduce the irregularity some detectors associate with human writing.
Organization
A rewrite may add headings, topic sentences, parallel lists, summary paragraphs, or symmetrical section structures. These patterns are not uniquely artificial, but repeated regularity can influence a classifier.
Domain Language
Specialized terminology supplied by the human can pull the score in the opposite direction. The ImBD authors identify this as one reason ordinary generation detectors struggle: human-originated content remains even when the model changes the presentation.
This is why an AI-revised document can produce conflicting reports. One detector may focus on the retained human content, another on the introduced style, and a third on features that do not generalize to that domain.
Detection Is Not The Same As Provenance
Detection infers a likely origin from the artifact. Provenance records how the artifact was produced.
Useful provenance evidence can include:
- timestamped drafts;
- document version history;
- tracked changes;
- research notes and source annotations;
- prompt and response records that the writer is authorized to retain;
- a screen recording or writing-process report created under a disclosed policy;
- signed content credentials or model watermarks when the relevant system supports them; and
- an interview in which the writer explains choices, sources, revisions, and argument development.
None is perfect. Version history can be incomplete, records can be fabricated, and watermarks can disappear after transformation. But process evidence addresses the question more directly than a prose classifier.
This distinction also matters for Claude's current marking system. As explained in what a Claude watermark actually proves, Anthropic says a detectable mark can indicate that Claude processed text even when it only proofread, translated, summarized, or converted human-originated material. A processing signal does not by itself assign authorship.
The DRAFT Review For A Flagged Document
Use this five-part review before acting on an AI-detector result.
D — Define The Policy Question
Ask what conduct the policy actually governs. “No fully generated submission,” “disclose any AI assistance,” and “AI may be used for grammar but not drafting” are different rules. A classifier cannot decide whether an allowed use occurred unless the policy first defines it.
R — Retain And Review Process Evidence
Look for drafts, revision history, notes, sources, and prior writing. Compare chronology and substance, not just tone. A writer who can explain why each source was chosen and how the argument changed supplies evidence that a detector score cannot.
A — Audit The Detector's Scope
Record the detector version, supported languages, qualifying-text rules, minimum length, threshold, and whether it claims to detect paraphrased or machine-revised content. A result outside the documented scope should carry little weight.
F — Find Alternative Explanations
Consider grammar tools, translation, dictated text, templates, professional editing, accessibility software, technical conventions, and non-native-language writing. These do not automatically explain a flag, but they should be evaluated before inferring misconduct.
T — Treat The Score As One Signal
Use the result to guide a fair follow-up. Do not convert “the text resembles a learned machine-revision category” into “the system proved this person did not write the work.” Document contrary evidence and allow the writer to respond.
How Writers Can Document Legitimate AI Editing
If a school, employer, journal, or client permits some AI assistance, the safest approach is transparency and process documentation—not trying to manipulate a detector.
- Read the policy before using the tool.
- Keep the original human draft.
- Save the instruction given to the editor when policy and confidentiality allow.
- Review every change instead of accepting a full rewrite blindly.
- Preserve tracked changes or a version history.
- Verify facts, citations, quotations, and calculations independently.
- Disclose the assistance in the required format.
- Keep sensitive or regulated information out of unapproved AI systems.
These steps do not guarantee a low detector score. They create better evidence of what actually happened.
For legitimate privacy work, the objective should not be to “beat” a detector. It should be to minimize unnecessary data exposure, follow the applicable policy, and preserve an honest record of human and machine contributions.
Where OpenVeil Fits
OpenVeil is a privacy-focused hosted AI workspace for chat, files, search, voice, images, and video. Normal private-chat history is stored in the browser rather than as a normal server-side chat-history record, and OpenVeil says prompts, uploads, media, and outputs are not used to train foundation models.
OpenVeil is not fully offline or anonymous. Active requests still require processing by OpenVeil and necessary providers, and limited operational, billing, security, and abuse-prevention records can exist. OpenVeil does not claim to make AI-edited text undetectable, remove model style, erase watermarks, certify human authorship, or protect against an unrelated academic or workplace policy violation.
If you are using permitted AI editing on a sensitive draft, OpenVeil's documented data boundaries may fit better than a tool that creates a long cloud-chat archive or uses submitted content for model training. Review the applicable policy first, minimize the text you send, and retain your original draft and revision evidence separately.
You can try OpenVeil after reviewing its hosted-processing boundaries and privacy policy.
Frequently Asked Questions
Can Turnitin Detect A Human Essay Polished By AI?
Turnitin says its system can identify text that may be AI-generated or AI-paraphrased, but it also says the model can misidentify human, generated, and paraphrased text and should not be the sole basis for adverse action. Whether it flags one essay depends on the text, supported language and format, length, detector version, and amount and type of revision.
Can GPTZero Detect AI-Edited Human Writing?
GPTZero says it evaluates mixed and modified writing and offers paraphrase-focused detection. Its own educator guidance also says highly edited and short passages are harder, recommends reviewing process evidence, and describes the result as a conversation starter rather than a verdict.
Does A High AI Score Prove The Whole Document Was Generated?
No. A document-level score does not reconstruct which phrases came from a person, which were revised, or whether the writer used an allowed tool. Review sentence-level signals cautiously and compare them with drafts and revision history.
Can Grammar Correction Trigger An AI Detector?
It can change word choice and sentence structure in ways that affect a score, especially when the correction tool performs substantial rewriting rather than narrow spelling or punctuation fixes. A flag still does not prove what tool was used or whether the use violated a policy.
Is Machine-Revised Text Easier To Detect Than Fully Generated Text?
Usually not for detectors built around fully generated output. In the ImBD experiments, conventional methods generally performed worse on rewriting and polishing than on full generation. A detector tuned specifically to machine-revised style performed much better in those controlled tests.
Does A Detector Know Which AI Model Edited The Draft?
Not from a generic AI score. Model attribution is a separate task and remains probabilistic. It depends on the candidate models, versions, prompts, editing, domain, and amount of text. Read more about how AI rewriting can add a recognizable model style.
Is An AI Watermark Better Evidence Than A Detector Score?
A verified watermark can provide a more direct signal that a supporting model processed the text, but its scope matters. It may indicate proofreading or translation rather than full authorship, and it may not survive heavy editing or transformation. Absence of a detectable mark does not prove that AI was not used.
What Is The Best Evidence That A Human Wrote The Original Draft?
A consistent body of process evidence: dated notes, sources, drafts, version history, tracked changes, and the writer's ability to explain the work. No single artifact is perfect, but that evidence addresses authorship more directly than a classifier operating only on final prose.
Bottom Line
AI detectors can sometimes tell a fully human draft from machine-revised text, and research shows that detectors tuned to machine style can outperform methods designed for fully generated output.
But detectable machine influence is not the same as proof of machine authorship. A final document can preserve human ideas and language while carrying AI-introduced style. Detector performance also changes with the model, domain, language, passage length, editing workflow, threshold, and detector version.
Use a score to start a careful review. Define the policy, inspect the detector's scope, preserve drafts and version history, consider alternative explanations, and give process evidence more weight than a standalone probability.