← Blog
1 September 2026 · 10 min read · Know Nota

Copyleaks AI Detector Review: Claims, Evidence, and Where Know Nota Differs

Copyleaks markets 99% accuracy. The research says detectors as a class are neither accurate nor reliable on edited text. Here is what the numbers say, what Nota prints about itself, and which tool fits which job.

reviewsai detectioncopyleaks

In August 2023, Vanderbilt University's Center for Teaching turned off Turnitin's AI writing detector for its entire campus. Their public explanation did the math nobody in the detection industry wanted printed: at Vanderbilt's volume of roughly 75,000 papers a year, even a 1% false-positive rate means 750 students wrongly flagged. That single paragraph reframed the whole category. The question stopped being "which AI content detector is most accurate?" and became "which one tells you how often it's wrong, and in what direction?"

Full disclosure before we go further: we build Know Nota, and Nota ships an AI detector. So treat every number we report about our own model as interested-party data and check it against the method page, where the same figures are published with the size of the test behind each one. What we can offer that a neutral reviewer usually can't is the exact numbers our own model is held to — including the gaps we have chosen to print rather than paper over.

Illustration of a document with a probability gauge whose needle sits in an ambiguous middle zone
The middle of the gauge is where most real documents land — and where a percentage tells you least.

How the Copyleaks AI content detector actually works

Copyleaks started in 2015 as a plagiarism-detection company selling into universities and publishers, and its AI detector is best understood as an extension of that business rather than a research project. That lineage explains most of its design choices.

The core mechanism is a supervised classifier. Copyleaks trained a model on large paired sets of human-written and machine-generated text and learned the statistical fingerprints that separate them. This is the dominant approach in the field, and it differs from the older zero-shot methods that scored text purely on how perplexity and burstiness behave under a reference language model — the approach behind Stanford's DetectGPT and behind the original GPTZero. Supervised classifiers generally beat zero-shot scoring on text that looks like their training data. They also degrade less gracefully when the input looks like nothing in the training set.

Copyleaks publicly markets accuracy above 99% with a false-positive rate around 0.2%, and it publishes model-specific claims about identifying output from particular generators. It sells LMS integrations (Canvas, Moodle, Blackboard, Google Classroom), an API, a Chrome extension, and enterprise features aimed at compliance teams: audit trails, admin dashboards, organization-wide reporting, SOC 2 and GDPR posture. If you run a 40,000-student university or a content operation with 200 freelancers, that surrounding infrastructure is genuinely the product. The detector is one component of a governance system.

The independent evidence is more mixed than the marketing. The most-cited third-party evaluation is Weber-Wulff et al., "Testing of Detection Tools for AI-Generated Text" (International Journal for Educational Integrity, 2023), which tested fourteen tools including Copyleaks across human text, raw machine text, machine text with human edits, and machine-translated text. Copyleaks placed among the stronger performers. The paper's overall conclusion was still that the tools "are neither accurate nor reliable" as a class, and that accuracy collapses once text is paraphrased or lightly edited. Krishna et al. demonstrated the mechanism directly in "Paraphrasing Evades Detectors of AI-Generated Text", and Sadasivan et al. argued in "Can AI-Generated Text Be Reliably Detected?" that as language models approach human text distributions, the theoretical ceiling on any detector's performance falls toward chance.

None of that is a knock on Copyleaks specifically. It's the physics of the problem. The differentiator that matters is how a vendor communicates under that constraint.

What the numbers actually say

The question a dean or a managing editor actually asks is not "what's your accuracy" but "if I act on this score, how often do I ruin someone's week?" Two kinds of numbers answer it: what the published research found across the category, and what a vendor is willing to print about its own model.

The research. Liang et al., "GPT Detectors Are Biased Against Non-Native English Writers" (Patterns, 2023), found that seven widely used detectors misclassified more than half of TOEFL essays written by non-native speakers as AI-generated, while near-perfectly classifying essays by native-speaking US eighth-graders. The mechanism is simple: if a detector penalizes constrained vocabulary and regular syntax, it penalizes second-language writers, because those are the features of second-language writing. Weber-Wulff et al. found accuracy falling apart on edited and paraphrased text. Neither finding has been overturned by newer models; the gap narrows, it does not close.

What Nota prints about itself. Our current model was held to a frozen exam on 29 August 2026: 104,692 real human documents of 250 words or more, none of them seen in training. At the line where a text is called AI-like, the model wrongly flagged 1.28% of them — about 1 in 78 — while catching 99.0% of machine text. That pooled number hides a spread by length, so every result shows the rate for the document's own length: 2.28% at 250–400 words (11,658 documents), 1.34% at 400–800 words (80,098), and none of the 12,936 documents at 800+ words. A measured zero is the exam's resolution at that length, not a promise. Between 100 and 250 words the model still scores but publishes no rate, because the exam starts at 250 and we would rather say so than borrow the longer documents' number.

Three limits shaped Know Nota's product more than anything else.

The non-native penalty. We have not measured a false-positive rate on non-native English writing, so we do not sell one — and the result page says exactly that. A single headline accuracy figure averaged across a mostly-native corpus hides the harm that matters most in a university with a large international cohort. Until a vendor can show you that segment measured on the model you'd be running, assume the Liang finding applies.

Short text collapses. Below roughly 100 words there is not enough statistical signal for any detector to support a claim in either direction. This is not a training problem; it is a sample-size problem. So Nota gives no score under 100 words — a refusal with a reason, not a number. Vendors who return a confident percentage on a two-sentence input are, in the most charitable reading, reporting a number their own validation data cannot support.

Hybrid text is the real world, and it is the hardest case. A human draft polished by a model and a machine draft revised by a person are close to indistinguishable to every classifier, ours included. That is also the most common real workflow in 2026. We have not published a hybrid-text figure yet, and any accuracy claim that doesn't disclose one is describing a world that no longer exists.

Six things Know Nota does differently

These aren't features in the marketing sense. Most of them make our headline numbers look worse. That's the point.

1. Every score ships with how often the model is wrong — measured on the model version that produced it, at the document's length. Not a rate from a previous version, not a benchmark run once in a good quarter. The result shows the model version and the false-positive rate measured on that version against held-out human writing of the same length band. Where no rate exists — under 250 words — the result says so instead of borrowing one. If you're going to make a decision about a person, you need to know the base rate of the instrument's error.

2. It gives no score under 100 words. No gauge, no "leaning AI." Just an explanation of why the input is too short for a supportable inference. We lose demos over this. We've kept it anyway, because the alternative is manufacturing evidence.

3. It never says "written by AI." A classifier cannot observe authorship. It observes statistical properties and compares them to distributions it learned. So Nota's language is calibrated to what the model can actually support: a text looks like AI writing to this model, or looks like human writing. That phrasing is deliberately less satisfying than a verdict. It's also the only phrasing that survives an appeal hearing or a defamation review.

4. It never names a specific generator. No "this was written by ChatGPT" or "this looks like Claude." Attributing text to a named commercial product implies a discriminative capability that no published research supports at deployable accuracy, especially across model versions, system prompts, and paraphrasing. It's a compelling claim. It's also the single easiest claim in this industry to falsify in front of a hearing panel, and once it's falsified, every other finding in your report loses credibility with it.

5. Pasted text is discarded by default. Text you submit is not retained, not logged for training, not held for review. If you need an artifact — and academic-integrity offices and HR investigations often do — you choose to keep it inside a signed record: a tamper-evident receipt with the document's fingerprint, timestamp, model version, and result, that anyone with the link can check. Retention is a choice you make per document, not a term buried in a data-processing addendum.

6. Model version and word count print on every result. Detection scores are not stable across model versions. A screenshot from a March run and a screenshot from a September run are not comparable evidence, and treating them as comparable is how institutions build inconsistent case histories. Version and length stamps make a result auditable six months later, which is roughly when appeals actually get heard.

Comparison by use case

Decision tree infographic mapping four use cases to different AI detection tool choices
Which tool fits depends on what you need the number to do.

Universities that need one vendor for plagiarism and AI detection inside the LMS. Copyleaks is the stronger fit today, and we'd say that in front of a procurement committee. Its plagiarism corpus, its Canvas and Moodle integrations, and its admin reporting are mature in a way a detection-only product isn't. What we'd insist on adding: written policy that no score alone triggers an academic-integrity charge, and a request that the vendor supply false-positive rates segmented by English-language-learner status. If a vendor can't produce that segmentation — and we can't either, yet — your international students are absorbing an error rate nobody has measured.

Academic-integrity offices building cases that get appealed. This is where Nota's design earns its keep. "Looks like AI writing to this model — high band. On 80,098 real human texts of this length the model was wrong 1.34% of the time, about 1 in 75. Model nota-v0.1, 1,240 words." is a defensible sentence. "99.7% AI, written by ChatGPT" is not, and a competent student advocate will take it apart in ten minutes. The signed record matters here too, because appeals happen months after the original run — and a student who wrote the essay in Google Docs can bring a signed record of how it was written, which is stronger evidence than any score, ours included.

Editorial and publishing teams screening freelance submissions. Both tools function as triage. Neither should function as a rejection rule. A lightly AI-polished human draft and a lightly human-edited AI draft are close to indistinguishable at current detection accuracy, and your contributor agreement probably permits the first. Use detection to decide which submissions get a closer read, then read them. Nota's refusal to score short text is more useful than it sounds when your inbox is full of 300-word pitches.

Hiring teams screening written assessments. Honest answer: mostly don't. The non-native penalty maps directly onto employment discrimination exposure, and a take-home writing sample is exactly the artifact a candidate is most likely to polish with a model. If you must, use detection to trigger a live follow-up conversation about the work — never as a filter. Nota's refusal to name a generator and refusal to score short text both reduce the odds of a score becoming an adverse action.

Developers integrating via API. Copyleaks has broader API surface area because it bundles plagiarism, similarity, and detection. Nota returns a narrower, more structured object: the reading (band and a 0–100 AI-likeness), the false-positive rate measured for the document's length band — or null with a note saying why — the model version, the word count, and an explicit abstained state your code has to handle. That last field is the design difference. Most detection APIs make it easy to build a product that renders a confident verdict on 40 words of text. Ours makes it awkward.

What to do with this

The useful question when evaluating any AI content detector in 2026 isn't which vendor claims the higher accuracy number. Vendors control their own test sets. The useful question is: what does this tool do when it doesn't know?

Ask each vendor on your shortlist four things. What is your false-positive rate on human text written by non-native English speakers, measured on the model I'd be running? What's your minimum supported input length, and what happens below it? What exact sentence appears in the user interface next to a high score? And is submitted text retained by default?

You can test the fourth one yourself in about ninety seconds. The first three tell you whether the vendor has done the measurement at all.

If you want to see calibrated output side by side with whatever you're using now, run the same document through both at /verify. No account needed, nothing retained unless you choose to keep it in a signed record. Bring a piece of writing you know the provenance of — ideally something a second-language writer wrote before 2022. That's the test that tells you the most.

Try it

Paste a draft and see how it reads — with how often the model is wrong beside the score. Or bring the document and get a signed record of how it was written.