Detection basics
These are the words you will run into on almost any page that talks about AI detection, and most of them get used loosely by the people who sell the software, so we have tried to say what each one means and what it does not tell you.
AI detector #
An AI detector is a program that looks at the statistical patterns in a text and gives you an estimate of how likely it is that a language model wrote it. What comes back is a probability with an error rate behind it, since every detector makes mistakes at a rate somebody counted on a test set, and a score on its own will never tell you who the author was. Cobalynx’s own error rates are on the evidence page.
AI checker #
An AI checker is an AI detector under a second name. The maths is the same, so what you get back is still a probability with an error rate attached to it, and a checker that says it is certain is overstating what it knows.
Perplexity #
Perplexity is a measure of how predictable a text is to a language model, and low perplexity means the model would most likely have picked the same words itself. Given “The sky was a brilliant shade of”, a model finds “blue” very easy to predict (low perplexity), “cerulean” a little surprising (medium), and “accountant” very surprising (high), so a text that stays in the easy-to-predict lane the whole way through reads as smooth in the way that a model’s output tends to be. A model’s text usually sits at lower perplexity than a person’s, which is what makes the signal useful, but formal and conventional human writing is also very predictable, so perplexity on its own will give you false positives.
Burstiness #
Burstiness is how much a text varies as you move through it, in its rhythm and in how predictable it is, so it covers how much the sentence lengths, the structure and the surprise of the word choices go up and down. A person’s writing tends to be bursty, with a short sentence sitting next to a long one and a plain phrase next to an odd one, and a model’s output tends to be more even. Like every other single signal it is weak on its own and only means something once it is added up with the rest.
AI-generated vs. AI-refined #
AI-generated text is text that a model wrote from a prompt, and AI-refined text is text that a person wrote and then had a model or a grammar tool polish for them. The difference matters, since the software is looking at where the text’s statistics came from, so writing you polished heavily has moved toward the patterns a machine would have produced, and that is one of the main reasons why real writers get false positives.
The statistics behind a verdict you can trust
Vendor glossaries tend to leave this group out, and once you know what these words mean you start asking the questions that are awkward for them to answer. If you read one group on this page, read this one.
Calibrated probability #
A calibrated probability is a score that means what it says on the population it was tested on, so that among the texts in our evaluation set that were given 80%, about 80% really were written by AI. Without that step an “83% AI” label is a raw score with a percent sign on it, and it tells you nothing about how often the tool was right when it said 83%. What a score means in your own situation also depends on the base rate, and how ours was produced is written up on the methodology page.
Calibration #
Calibration is the job of taking the raw scores that come out of the software and mapping them onto real-world probabilities, which you do by comparing the scores with outcomes that a person had already confirmed. Without it, two tools can give the same text 12% and 88% and both of them can say they were working as designed, so it is normal for tools to disagree with each other, since none of them were ever calibrated to each other in the first place.
False positive #
A false positive is a piece of writing that a person wrote and that a detector wrongly labeled as likely AI, and it is the most damaging mistake this kind of software can make. Formal structure, careful grammar and non-native English have all been documented as things that set it off. If a vendor will not publish its false-positive rate, you have no way of knowing how often its tool does this.
False negative #
A false negative is AI-generated text that a detector failed to flag, so it passed as if a person had written it. Short texts, output that a person edited afterwards and paraphrase attacks all push the false-negative rate up. Every tool misses some of them, and a vendor who says theirs never misses has not counted the ones it missed.
False-positive rate (FPR) #
The false-positive rate is the share of texts that people really wrote which the software wrongly flagged, and you count it on a test set where you already knew who wrote what. It is the single most important number a vendor can publish, since it is the probability of doing harm to a writer who did nothing wrong. Cobalynx’s is on the evidence page with the raw counts and the intervals.
Confidence interval #
A confidence interval is the range you put around a measured rate to show how sure you are of it, so “4% (95% CI 2–7%)” is a way of saying that the 4% came from a sample of limited size and the true rate could be anywhere in that range. If a vendor published an accuracy figure with no interval and no raw counts, there is no way for you to tell how solid it is, and we would not trust it.
Abstention (inconclusive verdict) #
Abstention is when the software declines to give you a verdict, and it does that when there is not enough in the text to call it, which is what we would want it to do with a text that is short, or mixed, or so borderline that a person would not want to call it either. A tool that never says inconclusive has not solved those cases, it has turned the ones it was not sure about into confident answers, and some of those answers will be wrong. Cobalynx treats the abstention band as part of how the tool is supposed to work.
Operating point (decision threshold) #
The operating point is the threshold where the software turns a score into a label, so it is the place where “likely AI” begins and “likely human” ends. An error rate only means something if you were told which operating point it was taken at, since a vendor that moves the threshold after the test was run can make a bad error rate look a lot better.
Base rate #
The base rate is how common AI text really is in the pile you are checking, and it changes what a flag means. Say only a few of the essays in a stack were written by AI. Then even a tool with a low false-positive rate is going to hand you a lot of flags that were wrong, since the few real AI essays are outnumbered by the mistakes it makes on the many human ones, and so we tell people a flag is a reason to ask questions, and our base-rate explainer works it through with the rates we published.
Non-native (ESL) false-positive bias #
Non-native false-positive bias is the name for what happens when AI detectors flag writing by people whose first language is not English far more often than they should, and it happens since prose that a person learned carefully and that sticks to the rules looks, to the software, a lot like what a machine would have written. This was documented in peer-reviewed research (a Stanford team, in 2023) and it is a fairness problem. We test Cobalynx on non-native writing separately and we put that error rate on the evidence page.
Watermarks and provenance
Watermarks and provenance get mixed up with detection all the time, and they are not the same thing at all. Detection is a guess made from the writing. A watermark or a credential is something that was put into the text or the file on purpose, and you either find it or you do not.
AI text watermark #
An AI text watermark is a statistical pattern that gets hidden in the word choices a model makes while it is writing, so the mark lives in the word picks themselves, which were nudged in a way the model’s operator can test for later, and there is no metadata tag in the file. Only whoever holds the key can test for it, and editing or paraphrasing the text wears it away. How text watermarks work goes into the detail.
SynthID-class keyed watermark #
A keyed watermark (Google’s SynthID-Text is the best-known one) shapes a model’s word choices with a secret key, so that only whoever holds that key can test for the mark. That was done on purpose, since if the public could test for the mark the public could also strip it out. It is also why no third-party tool, and that includes Cobalynx, can tell you it has read a rival company’s text watermark.
C2PA / Content Credentials #
C2PA Content Credentials are a note that sits inside a picture or a video file and says who or what made it and what was done to it since. The note was signed with cryptography, so you can tell if a person changed it, and the camera makers and the big AI labs all got behind it as an open standard. A valid manifest from an AI generator is close to conclusive evidence of where a file came from, but a missing one proves nothing, since most files never had credentials in the first place. You can read a file’s credentials here.
Provenance #
Provenance is what you know about where a file came from when you read it out of the file itself, from things like signed manifests, tool records and edit chains, and not from guessing at what the content looks like. Detection is statistical and provenance is not, so when provenance is there it is strong evidence, and when it is missing the right answer is “unknown”, since a missing credential does not mean a person made the file.
Machine-readable marking #
Machine-readable marking means putting a label on AI output that software can read as well as people, which usually means a credential written into the file, a watermark in the text, or a bit of structured data that says where the thing came from. The EU’s law now asks AI providers to do this for the content their models produce (Article 50, in force since August 2, 2026), and it is why provenance standards keep moving out of photography and into the tools people use for text and video, which had never had them.
The law
Two terms from the law, and both of them are European, since that is where the rules that have teeth came in first. Each one links the page that goes through the rest.
EU AI Act — Article 50 #
Article 50 of the EU AI Act is the transparency rule, and since August 2, 2026 it has required providers to mark AI-generated content in a machine-readable way, chatbots to tell you they are not human, and deepfakes to be labeled. The duty sits on the providers and the deployers, and not on you as a reader. What the law actually says will take you through the deadlines, the penalties and who is bound by it.
AI disclosure #
AI disclosure is when a company tells you that a piece of content, or the thing you are talking to, is AI, whether the reason is a company policy, a platform rule or a law. In the EU it is now a legal right when you are talking to a chatbot, and in most other places it is still a norm that is only starting to take hold. The duty to tell you sits with whoever put the AI there, so a detector can back up your suspicion but it cannot stand in for that duty.
Evasion and the business around it
There is a small industry built around getting AI text past AI detectors, and we think you should know its vocabulary, if only so that you know what you are looking at when a salesman tries to sell you a way around a tool like Cobalynx.
Humanizer #
A “humanizer” is a rewriting tool that a vendor sells you to get AI text past AI detectors. Independent testing has shown that they lower the recall of every detector, and that includes Cobalynx, which is why we publish those adversarial numbers and do not claim immunity. We do not build or sell evasion tools, and we would be wary of a vendor that sells you both the detector and the tool for getting past it, since it makes money from both sides.
Paraphrase attack #
A paraphrase attack is when a person takes text that a model wrote and rewords it, either by hand or by running it through a second model, so that the statistical fingerprint a detector would have picked up on gets blurred. Of all the ways people have found to get past a detector, this is the one that works best, and an evaluation worth reading will have a section on it. Ours does, and you can see how the detector did under it on the evidence page.
AI slop #
AI slop is a term for low-effort AI-generated content published with little checking or original value. It can include articles, reviews and images. Repetition can prompt a closer look, but an AI score does not establish whether content is useful, true or fraudulent. See the practical review checks.
General AI terms, in plain words
And finally a few general terms about the models themselves, which you will see on this site and everywhere else, in the plainest words we could find for them.
Large language model (LLM) #
A large language model is a neural network that was trained on a very large amount of text to predict the next token, and it turned out that this was enough for it to write, summarize, translate and hold a conversation with you. LLMs are what write the text that AI detectors try to recognize, and the detectors themselves use the same statistical regularities that make an LLM’s output read so smoothly.
Token #
A token is the unit that a language model reads and writes in, and most of the time it is a piece of a word a few letters long and not a whole word. A model picks one token at a time, and it picks by probability, and that is the reason statistical detection is possible at all, since writing text one likely piece at a time leaves a trail of typical choices behind it that you can count.
Training data #
Training data is the pile of text that a model’s makers gave it to learn from. For a detector it cuts both ways, since what the detector saw while it was being trained sets the limit on what it can recognize later, and whatever it never saw is where it will fail, and it will not warn you when that happens. Cobalynx never uses the text you submit as training data, and the promise and the way we enforce it are both on the privacy page.
Hallucination #
A hallucination is when a language model says something false and says it fluently and with complete confidence, so it covers made-up citations, facts that were never true, and nonsense that sounds fine until you go and look it up. It matters on this site since a verdict only tells you where the words probably came from, and it says nothing about how true they are. A person can write something false and a model can write something true, and a detector does not look at that at all.
Zero retention #
Zero retention means that a service handles what you gave it in memory and keeps nothing once it has answered you, so there are no stored copies, nothing gets reused for training, and there is nothing left over to leak later. The claim is only as good as whatever enforces it, and in Cobalynx’s case that is an automated no-persistence test that runs on every release, which we describe on the privacy page.