AI watermarks and other detection tools: How to detect AI-generated text 

This article explores the limitations of AI detection tools, the significance of AI watermarks, legal responsibilities, practical review methods, and emerging court requirements. It highlights the importance of verification and provenance analysis when evaluating AI-generated content.

AI watermarks and other detection tools: How to detect AI-generated text 

Generative AI produces fluent, on-demand prose that is often, whether we want to admit it or not, placed directly into court filings. While using AI to help write text can be incredibly useful for establishing a starting point or conducting a grammar/spelling check, it can be risky in the legal sector, where authorship, accuracy, and provenance are central to credibility and admissibility. Determining if a document was created using AI is not about “catching” technology for its own sake; it is about protecting the integrity of the record, honoring ethical duty, and ensuring courts and clients can rely on what they read. 

Courts and authoritative bodies have emphasized that lawyers remain responsible for verifying material submitted to a court, including material prepared with AI assistance.[1]https://legalaigovernance.com/tracker/court-orders/ Lawyers also owe a duty of candor and cannot wholly outsource judgment to a system that has shown that it can fabricate citations or subtly misstate holdings. The best-known example is Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023), where counsel filed a brief citing decisions that did not exist.[2]https://www.jdsupra.com/legalnews/federal-court-turns-up-the-heat-on-1849454/ Rule 11, the duty of candor reflected in Model Rule 3.3, and courts’ inherent authority can expose attorneys to sanctions, discipline, or other consequences when filings contain AI-generated hallucinations, and some courts are asking attorneys to disclose when AI tools are used to help draft court filings. Even as AI tools evolve and become more accurate, they remain imperfect and prone to error.  

Limits of current detection tools

No single test can conclusively establish whether AI was used to produce text. Scores from AI detection tools such as GPTZero and Turnitin should not be treated as standalone proof of AI usage in court without qualified explanations. These tools can generate false positives and negatives and have been known to flag standardized legal drafting and legitimate boilerplate language as “AI,” while failing to detect lightly edited AI text. As AI models evolve, they may not use the same writing styles or word choices that today’s AI detection tools rely on. 

The error rates are also contested in a way that should give any lawyer pause. A 2023 Stanford University study of seven detectors found that the detectors wrongly flagged more than half of a set of TOEFL (Test of English as a Foreign Language) essays written by non-native English speakers, an average false-positive rate above 60%, while scoring near-perfectly on essays by American eighth graders.[3]https://www.cell.com/action/showPdf?pii=S2666-3899%2823%2900130-7 Turnitin disputes these findings. It published its own study claiming that its AI detection rates for English language learners and native speakers were not statistically significant.[4]https://www.turnitin.com/blog/new-research-turnitin-s-ai-detector-shows-no-statistically-significant-bias-against-english-language-learners The two studies, however, are not measuring the same thing. Turnitin’s numbers come from submissions of at least 300 words, while the Stanford sample was mostly much shorter. Both can be accurate, which actually points to one of the problems with AI detection. A score’s reliability depends on the length of the passage and who wrote it, and the number on the screen tells you neither. 

Beyond ensuring accuracy in court filings, false-positive rates in AI detection tools for text written by non-native English speakers can pose an employment issue. For instance, if a law firm leverages an AI detection tool to score filings written by non-native English-speaking associates, these employees may be subject to disproportionate scrutiny or unsupported conclusions about how their work was prepared. Other non-native English speakers may be screened out during the job application process, depending on an AI detection score.[5]https://arxiv.org/abs/2304.02819

More recently, Anthropic signed the European Union (EU) AI Act’s Article 50(2) Code of Practice on Transparency of AI-Generated Content and began marking Claude’s output.[6]https://www.forbes.com/sites/maryroeloffs/2026/08/11/claude-will-put-invisible-watermarks-on-ai-text-and-images-and-the-internet-isnt-happy/ Claude models launched on or after August 2, 2026, carry marks at launch, and Anthropic says it is working to add marking to models released before that date. The marking applies wherever Claude is offered, not only in the EU. 

Two different mechanisms are involved, and the difference matters more than the announcement does. Generated text carries a watermark woven into the words themselves, so it survives copying and pasting and may survive some editing. Generated files, such as .svg, .png, and .jpg, carry signed provenance metadata under the Coalition for Content Provenance and Authenticity (C2PA) standard, which is much easier to strip through format conversion, resaving, or a screenshot. Treating both as metadata gets the durability question backward.[7]https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content

A mark shows processing, not authorship

This is the part most likely to get lost, and it is the part that matters in practice. Anthropic’s own guidance says a detected mark shows only that content may have been processed by Claude.[8]Ibid. It does not say who wrote it. People use these tools to proofread, translate, and summarize, so a brief that a partner drafted and then ran through Claude for a grammar check will carry a mark. This is the same low risk use this article endorses. 

The inference fails in the other direction, too. The absence of a mark proves nothing. The text may have come from an older model, a different vendor, or a marked model that was edited so extensively that the signal was lost. A short passage may not carry a reliable mark at all. 

Anthropic has not yet published its detection method, so there is currently no tool a lawyer can run against a filing. Beyond Anthropic, OpenAI, Google, and other companies with AI tools have also signed the aforementioned EU article. Google has implemented watermarking in text generated by Gemini using its own “SynthID” technology;[9]https://deepmind.google/models/synthid/ however, OpenAI has yet to implement watermarking in AI-generated text.[10]https://www.smithstephen.com/p/the-claude-watermark-is-real-the; https://openai.com/index/supporting-eu-trustworthy-ai-ecosystem/

Some tools, such as Watermark Detector (watermarkdetector.com), have been launched that examine text for AI watermarks and hidden Unicode characters.[11]https://watermarkdetector.com/ While using this tool or others like it could identify instances where AI tools inserted watermarks, false positives still occur.[12]https://openreview.net/forum?id=WB3T9mkf8F Plus, the same tool offers “cleaning” services that purport to remove the watermarks from the generated text. 

Where the rules are headed

The Advisory Committee on Evidence Rules has proposed a new Federal Rule of Evidence 707. This rule would treat machine-generated evidence offered without a supporting expert similarly to expert testimony under Rule 702, requiring the proponent to show that the output is based on sufficient data and reliable methods. Simple scientific instruments would be excluded. 

The proposal was published for comment in August 2025, but the committee declined to advance the draft in May 2026, with plans to revise it at a mini conference in October 2026.[13]https://cdt.org/insights/changing-course-to-get-it-right-the-advisory-committee-reviews-its-ai-evidence-rule/ A companion proposal, Rule 901(c), addresses the authentication of electronic evidence that may be fabricated.[14]https://www.reuters.com/legal/legalindustry/daubert-digital-age-proposed-fed-r-evid-707–pracin-2026-06-24/ 

The point for our purposes is narrow. A detector score offered to a court without an expert to explain its methodology and error rate is exactly the kind of output at which Rule 707 is aimed. 

Practical considerations and limitations

A sound approach combines provenance checks, linguistic and formatting analysis, and rigorous verification. Where authorship or provenance is disputed, information concerning a document’s development may provide useful context. Some attorneys or courts may ask for draft histories, version control, or tracked changes that show human drafting over time, or may review file metadata for authorship, creation and modification times, and the software used. These details would then be compared to representations of who wrote the document and when. A complex brief produced unusually quickly, or a mismatch between the named author and the document properties, may warrant deeper scrutiny.  

A linguistic review can add probabilistic signals. Machine-generated text is often read as hyper-fluent yet impersonal, with a steady, evenly formal tone that lacks human-level variations in word choice. Repetition in structure, generic transitions, and a tendency to hedge with safe qualifiers are common. Of course, these styles also occur in human writing and do not prove that AI was used.  

Researchers have found that some AI tools tend to rely more heavily on certain words than human writers do.[15]https://www.sciencedirect.com/science/article/pii/S2666920X2500147X; https://www.scientificamerican.com/article/chatgpt-is-changing-the-words-we-use-in-conversation/ These words include, but are not limited to, crucial, comprehensive, intricate, pivotal, delve, underscore, utilize, and align. They have also determined that AI-generated text more frequently uses certain punctuation and rhetorical patterns, including em dashes, colons, semicolons, and the “rule of three” (as in this sentence).[16]https://www.cmu.edu/dietrich/news/news-stories/2025/large-language-models-writing-text; … Continue reading When these appear alongside other recognized characteristics of AI-generated content, they may serve as potential indicators of AI use.   

That said, caution is warranted in legal writing because many, if not all, of these words are commonly found in briefs and other legal documents. In fact, lawyers have been using em dashes, colons, semicolons, and the rule of three long before generative AI existed. After all, AI models learned these patterns and vocabulary choices from the corpus of text they were trained on.  

Comparative authorship analysis offers another angle. By comparing a document to a baseline corpus from the same author, looking at sentence length variance, function word distribution, preferred rhetorical moves, and distinctive vocabulary, you can spot deviations that merit follow-up questions. As described previously, watermarking is no longer an experiment; audit logs may be requested by some courts or attorneys, and platform-level attestations are available from some vendors. Where available, these artifacts can support or rebut claims about drafting methods. In many legal settings, a clear disclosure or sworn attestation about how a document was prepared will be more practical and easier to defend than an online AI detector score. 

What can lawyers do?

Some legal teams may choose to lean on provenance over perfection and document a consistent review process. They may request draft histories, maintain their own version logs, and review notes. Because judges have taken very different positions on AI disclosure and certification, their views will largely determine the obligations that apply in a given matter.  

Firms should confirm what happens to client material entered into a hosted AI tool, which, for many organizations, presents a greater risk exposure than anything related to AI detection. When an author’s voice matters, such as in affidavits, expert reports, and executive statements, compare the submission against known writing samples to identify unexplained stylistic drift.  

More broadly, rely on multiple indicators rather than a single tool or score, and document the steps you took, the thresholds you applied, information considered (and its limitations), and any follow-up performed so that your methods can withstand scrutiny. Finally, establish clear policies, required disclosures, and training on permissible AI use, along with verification procedures aligned with court rules and client expectations. 

What if you believe opposing counsel filed a brief or other document that was prepared with undisclosed AI assistance or contains AI-generated errors? After all, French legal researcher Damien Charlotin has identified more than 1,200 US cases involving AI hallucinations in court filings or proceedings.[17]https://www.damiencharlotin.com/hallucinations/?graphs=0&q=&sort_by=-date&states=USA&period_idx=0&legal_fields= And given the growing adoption of AI tools such as ChatGPT, Claude, and Harvey within law firms, it is reasonable to assume that at least some filings have involved the use of nondisclosed AI.  

Where AI-generated errors are identified, counsel may oppose the filing on the merits, move to strike the offending portions, seek leave to submit corrective briefing, or, in particularly egregious cases, pursue sanctions based on opposing counsel’s failure to conduct a reasonable inquiry before filing. If evidence shows that opposing counsel used AI despite certifying otherwise, you may motion to strike, request sanctions, pursue disciplinary remedies, or otherwise challenge the submission on the grounds that opposing counsel made a false representation to the court.  

Although most courts have stopped short of banning AI outright, some judges’ standing orders prohibit AI-assisted preparation of filings or impose restrictions on or require certifications for AI use for certain tasks. Table 1 provides examples of standing orders issued by federal judges in various US jurisdictions.[18]https://legalaigovernance.com/tracker/court-orders/

Table 1: Standing orders on the use of generative AI in US courts

Court Judge Type What the order requires 
N.D. Ohio Christopher A. Boyko Ban, with exceptions No attorney or pro-se party may use AI in preparing any filing. Does not apply to legal search engines, such as Westlaw or LexisNexis, or Internet search engines, such as Google or Bing. Parties and counsel must immediately inform the court if they discover the use of AI in any filed document. Violations may draw sanctions, including striking the pleading, economic sanctions, or contempt, and dismissal. 
S.D. Ohio Michael J. Newman Ban, with exceptions Same core prohibition, effective August 27, 2025. Carve out for information gathered from legal and Internet search engines. Same duty to inform the court. 
S.D. Ohio Jeffery P. Hopkins Disclosure Separate declaration required if any portion of a filing was generated with generative AI, certifying review of source material and verification of accuracy. 
S.D.N.Y. Dale E. Ho Disclosure Any party using generative AI to generate a court document must file a separate declaration disclosing the use. 
US Court of International Trade Stephen Alexander Vaden Disclosure Any submission containing text drafted with a generative AI program must include a disclosure notice identifying the program and the specific portions so drafted. 
N.Y. County Supreme Court Tandra L. Dawson Disclosure If AI is used for substantive legal research and writing, counsel or a pro se litigant must submit an affirmation at the end of the document stating AI was used. 

AI-generated text is here to stay, and when used responsibly, it can enhance efficiencies in legal practice. However, authenticity, accuracy, and ethical compliance must remain paramount. Detection tools can play a role in the review process, but they have clear limitations that make them difficult to use as a definitive measure of authorship. 

Ultimately, the responsible use of AI in law hinges on transparency and consistent documentation. By combining provenance checks, careful review, and clear disclosures, lawyers can meet evolving court expectations and maintain the integrity of their filings. This approach ensures that clients and courts can rely on both the content and the manner in which legal documents are prepared. 

This article provides general information concerning AI watermarking and detection tools. It does not provide legal advice, establish a methodology for determining authorship, or offer conclusions about how a court may treat a particular document, pleading, watermark detector tool result, or other evidence concerning the use of AI. Those issues depend on the specific circumstances of the matter and relevant legal requirements. 

Portions of this article were written using generative AI models. In fact, some of the sentences written by AI models for this article include the very writing styles we mention, such as the rule of three, where arguments are made with three distinct points in the same sentence. 

About the authors

  Richard Peters, Partner

   Noah Genovesi, Manager

This article presents views, thoughts, or opinions that are provided for general information purposes only. It does not represent the views of, or constitute advice of any form (legal, professional or otherwise) from, HKA or any of its affiliates. While HKA takes reasonable care to ensure the accuracy of its contents at the time of publication, the article does not deal with all aspects of the referenced subject matter and may not be relied upon as a substitute for professional judgment or independent analysis. Accordingly, neither HKA nor the author accepts liability for any use of, or reliance on, the information presented in the article. This article is protected by copyright © 2026 HKA Global, LLC/© 2026 HKA Global Ltd. All rights reserved. 

References

References
1 https://legalaigovernance.com/tracker/court-orders/
2 https://www.jdsupra.com/legalnews/federal-court-turns-up-the-heat-on-1849454/
3 https://www.cell.com/action/showPdf?pii=S2666-3899%2823%2900130-7
4 https://www.turnitin.com/blog/new-research-turnitin-s-ai-detector-shows-no-statistically-significant-bias-against-english-language-learners
5 https://arxiv.org/abs/2304.02819
6 https://www.forbes.com/sites/maryroeloffs/2026/08/11/claude-will-put-invisible-watermarks-on-ai-text-and-images-and-the-internet-isnt-happy/
7 https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
8 Ibid.
9 https://deepmind.google/models/synthid/
10 https://www.smithstephen.com/p/the-claude-watermark-is-real-the; https://openai.com/index/supporting-eu-trustworthy-ai-ecosystem/
11 https://watermarkdetector.com/
12 https://openreview.net/forum?id=WB3T9mkf8F
13 https://cdt.org/insights/changing-course-to-get-it-right-the-advisory-committee-reviews-its-ai-evidence-rule/
14 https://www.reuters.com/legal/legalindustry/daubert-digital-age-proposed-fed-r-evid-707–pracin-2026-06-24/
15 https://www.sciencedirect.com/science/article/pii/S2666920X2500147X; https://www.scientificamerican.com/article/chatgpt-is-changing-the-words-we-use-in-conversation/
16 https://www.cmu.edu/dietrich/news/news-stories/2025/large-language-models-writing-text; https://www.mcgill.ca/oss/article/critical-thinking-student-contributors-technology/why-did-llms-steal-our-em-dashes; https://blog.aare.edu.au/2025/08/07/stop-policing-punctuation-now-why-ai-detection-needs-a-rethink/; https://www.mozillafoundation.org/en/nothing-personal/superficial-intelligence-ai-writing/
17 https://www.damiencharlotin.com/hallucinations/?graphs=0&q=&sort_by=-date&states=USA&period_idx=0&legal_fields=
18 https://legalaigovernance.com/tracker/court-orders/
X

Follow HKA on WeChat

关注我们的官方微信公众号

HKA WeChat