AI Governance and Responsible Leadership

Do AI Detectors Actually Work? What to Put in Your Policy

Commercial AI detectors are too unreliable to start a disciplinary process. The decision that matters is not which detector a school uses, but what a high score is allowed to trigger, and who decides.

A blue cut-paper sieve with a thick black rim and a black mesh beneath it, one black mark caught inside the bowl while three others fall away below, standing for a detection tool that lets most of what it is meant to catch pass straight through and holds on to something almost at random.

In brief

No. Commercial AI detectors are not accurate or robust enough to decide whether a particular student cheated. Independent testing presented at the 2026 IEEE Symposium on Security and Privacy found false positive rates across five commercial tools ranging from 0.05 percent to 68.6 percent, and found that asking the language model for more elaborate vocabulary defeated them. A detector score measures how predictable a piece of writing is, not who wrote it. It can reasonably prompt a teacher to look harder at work they already had questions about. It cannot serve as evidence. The decision leaders have to make is not which tool to use but what a high score is permitted to trigger, and who is accountable for what happens next.

Somewhere in your school this term, a teacher will paste a paragraph of a child's work into a detector, watch a number come back, and then have to decide what that number entitles them to do. Ask most leadership teams who made that decision and you find nobody did. The teacher is improvising, in the moment, about a child.

So: do AI detectors actually work? Not to the standard a school needs when the next step is an accusation. They are worth something as a prompt to look harder at work a teacher already had questions about. They are worth nothing as proof. The gap between those two sentences is where schools are currently getting hurt, and closing it is a leadership job, not a teacher's.

Do AI Detectors Actually Work?

The best available evidence says commercial detectors are too unreliable and too easily defeated to settle a question about a particular student. In May 2026, researchers at the University of Florida presented "AI Wrote My Paper and All I Got Was This False Negative" at the IEEE Symposium on Security and Privacy. Seth Layton, Bernardo Medeiros, Kevin Butler and Patrick Traynor tested five commercial detection tools against roughly 6,000 papers written before ChatGPT existed, alongside AI-written clones of them.

Two numbers from that work should end the argument in most schools. False positive rates across the five tools ranged from 0.05 percent to 68.6 percent. False negative rates ranged from 0.3 percent to 99.6 percent. Not a spread between good tools and bad ones so much as a spread between a tool that works and a coin.

Then the researchers did something a sixteen-year-old could do. They asked the language model to write the same essay again using more elaborate vocabulary, which the paper calls a lexical complexity attack. The detectors fell over. As Traynor put it, "These are not reliable or robust tools to use to measure the problem. We really can't use them to adjudicate these decisions. People's careers are on the line here."

He was talking about academics. In a school, it is a fifteen-year-old's record.

The people who run qualifications say something close to it. The Joint Council for Qualifications, in AI Use in Assessments (Revision Two, April 30, 2025), is explicit that detection tools "vary in accuracy depending on the AI tool and version used, the proportion of AI to human content, prompt types and other factors," and that their use "should form part of a holistic approach to considering the authenticity of students' work; all available information must be considered when reviewing any malpractice concerns." Teachers, JCQ says, "will know their students best and so are best placed to assess the authenticity of work."

Systems are converging on the same position from the other direction. Chalkbeat's Lily Altavena reported on September 2, 2026 that the District of Columbia and at least 37 US states have now issued AI guidance for schools, that more than a third of those states urge schools not to rely solely on detection tools, and that half of the ten largest districts explicitly discourage their use. The same piece notes that state guidance largely sidesteps cheating altogether, which leaves the question exactly where it has been all along: on your desk.

What a Detector Score Actually Measures

A detector does not estimate the probability that a student cheated. It estimates how predictable their sentences are. JCQ says so plainly: these tools "base their scores on the predictability of words," which is why, in its words, they "will give lower scores for AI-generated content which has been subsequently amended by students."

Read that twice, because two consequences follow and neither is obvious.

The first is that a student who edits AI output even lightly moves toward safety. The tool rewards tampering.

The second is my own reading of the same mechanism rather than a finding of JCQ's, and I would want a school to test it on its own work before acting on it: if the score tracks ordinariness of phrasing, then the students most exposed are the ones who write plainly. Second-language writers. Students taught to a rigid structure. Students who used the writing frame the department handed out in September. The quiet, compliant, scaffolded writer is the one the machine finds suspicious.

There is a third thing worth noticing, and it belongs in a different policy from the one you are thinking of. Pasting a child's work into a detector sends that child's work to a third party. That is the same decision, with the same duties attached, as putting student data into ChatGPT, and most schools that have written a careful rule about the second have never noticed they routinely break it with the first.

The Arithmetic Behind an Accuracy Claim

A low false positive rate still produces a steady supply of wrongly flagged children, because schools run enormous numbers of submissions past these tools.

Take a hypothetical secondary school of 1,200 students, each submitting eight pieces of written work a year that pass through a detector. That is 9,600 checks. At a false positive rate of 1 percent, which sits comfortably inside the range of the well-behaved tools in the Florida study, the school generates 96 false flags a year. Two or three every week of term, each one a genuine piece of a child's own work carrying a number that says otherwise.

Ninety-nine percent accurate is the sort of figure that sounds like a settled matter in a governors' meeting. Run it through your own numbers before you accept it.

The Trigger Test

Before your school buys, keeps or renews any detection tool, answer one question, and answer it with what actually happens rather than what you intend to happen.

The Trigger Test. When this tool returns a high score on a piece of a child's work, what happens next in our school? Write down the actual next step. If the honest answer is that a teacher looks more closely at work they already had questions about, the tool is a prompt, and its error rate is survivable. If the honest answer is that the student is asked to account for themselves, a mark is withheld, or a record is made, the tool has become evidence, and no published detector meets the standard evidence has to meet. A school that cannot say which of the two it is does not have a detection policy. It has a subscription.

This is my suggested way of framing the decision rather than a tested method, and its value is entirely in the honesty of the answer. Most leadership teams I put it to reach for the first option and then, pressed on what a teacher does at four o'clock on a Thursday with a 94 percent score and thirty books to mark, arrive at the second.

The point of the test is that it moves the argument off the accuracy number, where it cannot be settled, and onto the consequence, where you have complete control.

The Conversation I Keep Having

The question schools bring me is almost always "which detector should we use," and it is almost always the wrong question.

I work with schools, trusts and districts in several countries, and the shape of this problem does not change much between them. What changes is how far the school has already gone before anyone senior looks at it. Usually a department bought something, or a teacher found a free one, and a practice grew without a decision underneath it. By the time it reaches a leadership meeting there is already a student, a parent and an unhappy head of year in the room.

The moment the conversation turns useful is when someone asks what we would say to a parent who denies it. Not what we believe. What we would say, out loud, when a parent asks what the evidence is. If the answer is a percentage from a product nobody in the room can explain, everyone can see the problem at once, and the meeting stops being about software.

That is the same test I would apply to any tool a school lets near a child, and it sits inside the wider question of what you require before approving an AI tool at all.

What Your Policy Should Say About Detection

Four lines are enough, and most school AI policies are missing all four.

A detector score alone never starts a formal process. Name what does: a teacher's professional judgment, drafting history, a conversation with the student, work that does not match what the school has seen from them before.

Name who may run a check and on what. If work goes to an external tool, the same rules apply as for any other student data leaving the school.

Say what a student is entitled to. At minimum: to know a concern exists, to be asked before conclusions are drawn, and not to be told a machine says they cheated.

Say who decides. One named person, not the teacher who ran the check. This is the same principle that governs every other decision AI should never make on its own, and the process a school follows once a student has been accused depends entirely on getting it right.

The Case for Keeping a Detector, and When It Holds

There is a reasonable argument for keeping one, and it is worth stating properly rather than dismissing.

A detector that nobody treats as proof still surfaces work a busy teacher would have passed over, and a school that runs no checks at all sends a signal to students about how much anyone is paying attention. Where a detector is used as a triage prompt, sits behind a named person, and never appears in a conversation with a student or a parent, it can do useful work.

That argument fails in two situations. It fails where the tool's output reaches the student, because the moment a child is shown a percentage the number has become the accusation. And it fails where the school cannot say who is accountable for what happens after a flag, because then the tool is making the decision by default.

What Replaces Detection

The durable answer is to make the work harder to fake rather than easier to catch, which is a question about assessment design and not about software.

Schools getting this right are collecting evidence of process rather than judging the artifact alone: drafting visible over time, a short conversation where a student explains a choice they made, a piece of work started and finished in the room. None of it is new. All of it was good practice before any of this, and it has the advantage of being defensible to a parent, which no detector score is. That shift, and what it does to the meaning of a grade, is the larger question underneath what happens to assessment when AI can produce excellent work.

What to Do Next

Take the Trigger Test to your next leadership meeting and answer it about the arrangement you already have, because you almost certainly have one whether or not you chose it. Then write the four lines.

If your leadership team is working through where AI decisions like this one actually sit, and who owns them, that is the kind of work I support through AI strategy sessions and advisory work with schools and trusts. I also write about this most weeks in the newsletter.

Sources and Further Reading

Dan Fitzpatrick is the founder of The AI Educator and a bestselling author on AI in education. He works with schools, trusts and districts internationally on AI strategy, governance and leadership.

Key takeaways

  • AI detectors are not reliable enough to decide whether an individual student used AI: testing of five commercial tools presented at the 2026 IEEE Symposium on Security and Privacy found false positive rates from 0.05 percent to 68.6 percent and false negative rates from 0.3 percent to 99.6 percent.
  • The same researchers defeated the detectors by asking the language model to rewrite the work using more elaborate vocabulary, an attack any student could reproduce.
  • A detector score measures the predictability of the words, not the authorship of the work, which is why the Joint Council for Qualifications notes that scores fall once a student edits AI output.
  • The decision that matters is not which detector a school uses but what a high score is allowed to trigger: a closer look is survivable, an accusation is not.
  • Even a well-behaved 1 percent false positive rate produces roughly 96 wrongly flagged pieces a year in a hypothetical school running 9,600 checks, which is two or three genuine pieces of student work every week of term.
  • Pasting a child's work into an external detector sends that work to a third party, and carries the same duties as any other student data leaving the school.
  • More than a third of US states now urge schools not to rely solely on detection tools, and half of the ten largest districts explicitly discourage them, according to Chalkbeat's September 2, 2026 review of state guidance.

Frequently Asked Questions

Do AI detectors actually work?

Not to the standard a school needs before accusing a student. Testing of five commercial detectors presented at the 2026 IEEE Symposium on Security and Privacy found false positive rates ranging from 0.05 percent to 68.6 percent. Detectors are defensible as a prompt to look harder at work, and indefensible as proof.

Can a school discipline a student based on a Turnitin or GPTZero score?

No school should let a detector score alone start a formal process. The Joint Council for Qualifications says detection tools should form part of a holistic approach in which all available information is considered, and that teachers who know their students are best placed to judge authenticity. A score is a prompt, not evidence.

Why do AI detectors flag work that a student genuinely wrote?

Because they score how predictable the words are rather than who produced them. Plain, well-structured, formulaic writing looks predictable to the tool. That makes second-language writers and students taught to a rigid structure more exposed, which is an interpretation of the mechanism worth testing on your own students' work.

What should a school AI policy say about detection?

Four things. That a detector score alone never starts a formal process. Who may run a check and on what. What a student is entitled to, including being asked before conclusions are drawn. And which named person decides, rather than the teacher who ran the check.

Is it safe to paste student work into an AI detector?

Treat it as student data leaving the school, because it is. The same rules that govern putting student information into a general AI tool apply to an external detector. Many schools that have written a careful rule about one have never noticed they routinely break it with the other.

What should schools do instead of using AI detectors?

Collect evidence of process rather than judging the finished artifact alone: drafting visible over time, short conversations where a student explains a choice they made, and work started and finished in the room. It is older practice than the technology, and it is defensible to a parent in a way no score is.

If your leadership team is working through these questions, this is the kind of work I support through AI strategy sessions and advisory work.

Learn more about working together
D
Dan Fitzpatrick

Delivered training to 150K+ educators | Founder of The AI Educator and AI Educator Tools | Forbes Contributor | International Keynote Speaker | 4 x #1 Bestselling Author