rel=nofollow citations. The promoted call-to-action above is a StealthWriter affiliate placement carrying its own disclosure, and is unrelated to this review.Does QuillBot bypass GPTZero? It is the one tool here that says in writing that it is not trying to, and the evidence agrees with it.
The only tool that bypassed Pangram and Turnitin in 2026.
Most humanizers clear one detector and get caught by the other. StealthWriter is the one that gets past both — run Ghost 5.2 Pro at level 7–8, section by section, and re-check before you submit.
Try StealthWriter →Key Takeaways
- QuillBot is the only tool in this cluster that denies being a bypass tool in writing. Its humanizer page states: “The Humanizer improves how your writing reads — it isn’t a tool for evading AI detection.”
- GPTZero lists it as one anyway. Its February 2026 paper names nine bypass services, and QuillBot is among them, rated “Low”.
- It also sells a competing detector, advertising a “99% detection rate, according to independent evaluations from RAID.” It is the only vendor here that cites a named third-party benchmark for its own number.
- That benchmark is real — and its headline finding is a warning about exactly that number. RAID reports that detectors claiming “extremely high accuracy (99% or more)” are “easily fooled by adversarial attacks.”
- Pangram caught QuillBot output 100.0% of the time — joint-highest detection of twenty tools benchmarked. Every sample.
- That is because of output quality, not despite it. Pangram’s DAMAGE paper rates QuillBot L1, its top fluency tier, and notes fluent rewriting is easier to detect.
- Its own older guidance concedes the limit plainly: “we make no guarantees if someone uses QuillBot on text generated by a tool like ChatGPT.”
Does QuillBot bypass GPTZero?
This page is the inversion of every other one in the cluster. There is no bypass claim to test, because QuillBot refuses to make one.
Its AI humanizer page says it outright:
“The Humanizer improves how your writing reads — it isn’t a tool for evading AI detection.”quillbot.com/ai-humanizer, read 21 September 2026
Across nineteen other tools in this cluster, not one has printed a sentence like that. So the interesting question becomes a different one: why is QuillBot on GPTZero’s list of bypass services anyway?
This page reports no first-party test. Everything below was fetched on 21 September 2026.
Which side of the market is it on?
Both, which is what makes it unusual here.
| Product | What it does | Access |
|---|---|---|
| AI Humanizer | Smooths “stiff phrasing, repetitive rhythm, and awkward transitions” | Free to 125 words; unlimited on Premium |
| AI Detector | Claims a “99% detection rate” citing RAID | Free to 1,200 words, 6 scans daily |
| GPTZero’s 2026 paper | Lists QuillBot among nine bypass services, rated “Low” | — |
| Pangram’s Aug 2025 benchmark | Caught QuillBot output 100.0% of the time | — |
One product rewrites AI text. The other identifies it. A competitor’s paper files the company under tools that evade detection, while its own page says it is not one.
Is the 99% figure substantiated?
It is cited, and that alone puts it ahead of every other accuracy claim in this series. QuillBot attributes it to “independent evaluations from RAID” — not to unnamed internal testing, not to a backdated blog post.
RAID is real and serious: published at ACL 2024 by Dugan, Hwang, Trhlik and colleagues, covering over 6 million generations across 11 models, 8 domains, 11 adversarial attacks and 4 decoding strategies, evaluating twelve detectors.
To be fair on the other side: QuillBot disclaims its own detector more carefully than most. The same page states that “no AI Detector can provide 100% accuracy”, that results are “probability estimates, not verdicts”, and that users should apply judgment rather than rely on a score.
Can you check GPTZero yourself?
Turnitin sells no individual licences and shows students no AI report, so nobody outside an institution can produce a genuine Turnitin screenshot. GPTZero removes that excuse entirely. Anyone can paste up to 10,000 characters into gptzero.me right now with no account, no card and no signup; a free account raises the per-scan limit to 150,000 characters with a 10,000-word monthly quota, and paid tiers start at $9.99 a month.
So when a humanizer claims to beat GPTZero and shows you nothing, that is a choice, not a constraint.
It also means you can check your own text. A genuine current GPTZero result shows a three-class classification — human, AI or mixed — a confidence category rather than a bare percentage, a probability breakdown across all three classes, and sentence-by-sentence highlighting. An image showing only “X% AI”, or one displaying perplexity and burstiness, is either fabricated or dates to roughly 2023.
Why does Pangram catch it every single time?
Because it writes too well, which is the most counterintuitive finding in this whole cluster.
Pangram’s August 2025 benchmark scored twenty humanizers and put QuillBot at 100.0% detection accuracy — joint-highest of the twenty. Not most samples. Every sample.
Pangram’s DAMAGE paper explains the mechanism. It rates QuillBot L1, the top tier for faithfulness and fluency, and observes that fluent rewriting is more detectable, not less. A tool that produces clean, coherent, well-formed prose is producing exactly the kind of text a classifier trained on clean, coherent, well-formed AI output recognises.
Pangram also names QuillBot directly as a “word spinner”, a category it notes was used “even before AI to disguise plagiarism” — which is a reminder that the product predates this entire argument.
What does GPTZero’s own paper say?
GPTZero’s February 2026 paper names nine bypass services in an appendix table and rates QuillBot “Low”, alongside StealthGPT, StealthWriter, HIX and GPTinf. Grubby AI, TwainGPT and WriteHuman are “Medium”; only Undetectable is “High”.
Being categorised as a bypass service by a competitor is not the same as marketing yourself as one. QuillBot did not put itself on that list.
How reliable are the numbers on either side?
GPTZero’s own FAQ concedes: “Our classifier is not trained to identify AI-generated text after it has been heavily modified after generation.” Its developers page simultaneously claims a “Paraphraser Shield” means “even if AI content has been altered to look more human-like, GPTZero can detect it.” Both statements are currently published.
The two leading detector vendors publish opposite numbers on the same question. GPTZero’s February 2026 paper reports 93.5% recall on 1,000 texts run through nine bypasser services, and puts Pangram at 49.7%. Pangram’s DAMAGE paper reports GPTZero at 60.04% on humanized text, and 34.53% at GPTZero’s own default threshold. Each benchmark shows its publisher winning, and neither is peer-reviewed.
On false positives, GPTZero was one of seven detectors in Liang et al. (2023), which reported a 61.22% average false positive rate across those seven on 91 TOEFL essays. No per-detector figure was ever published, so that number is not GPTZero’s. GPTZero now claims it has cut its own TOEFL false positive rate to 1.1% — a figure no third party has verified.
What should you take from this?
QuillBot is the control group for this entire series. It is a mainstream product from a real company that sells paraphrasing as paraphrasing, declines to promise invisibility, cites a named benchmark rather than an invented one, and disclaims its own detector’s infallibility.
It is also caught 100% of the time by the strongest detector that has tested it, listed as a bypass service by a second, and honest enough to have said years ago that it makes no guarantees about ChatGPT text.
Those two paragraphs are not in tension. A tool that improves your writing and a tool that hides its origin are different products, and most of this market sells the first while advertising the second. If detection is your actual worry, the free check settles it in a minute at gptzero.me — and keeping your drafting history protects you whichever way the number falls.
If your real worry is being wrongly flagged on your own writing, keep your drafting history — it costs nothing and it survives a detector being wrong. It matters most for the writers detectors treat worst: ESL writers and AI detection and false positives for neurodivergent students. Check before you submit with the best pre-submission check and the Turnitin self-check, and strip the obvious tells by hand first via what to remove before using an AI humanizer.
For the product itself see our QuillBot review, and the same question against Turnitin and Pangram. Also in this cluster: Phrasly, StealthWriter, Rephrasy.
Get the free prompt pack instead
The manual rewriting prompts that lower AI signals without a subscription — and without betting a submission on a number nobody has reproduced. Free, no card.
Frequently asked questions
Does QuillBot bypass GPTZero?
The company says it is not trying to, and the independent evidence says it does not. Its humanizer page states that the Humanizer is not a tool for evading AI detection. Pangram’s August 2025 benchmark caught QuillBot output 100.0% of the time, joint-highest of twenty tools. GPTZero’s own February 2026 paper lists QuillBot among nine bypass services and rates it Low. No published test shows QuillBot output passing GPTZero.
Why is QuillBot in this series at all?
Because it is one of the nine services GPTZero names by name in its 2026 paper, and because a very large number of students reach for it first. It belongs in the matrix for the same reason the others do. The difference is that every other vendor here claims a bypass and cannot support it, while QuillBot declines to claim one at all.
What does QuillBot actually sell?
Both sides of the market. It sells an AI humanizer, free up to 125 words and unlimited on Premium, described as smoothing stiff phrasing, repetitive rhythm and awkward transitions while preserving meaning. It also sells an AI detector, free up to 1,200 words per scan and six scans daily, advertising a 99% detection rate. One product rewrites AI text, the other identifies it.
Is the 99% detection claim substantiated?
It is cited, which is more than any other accuracy claim in this series. QuillBot attributes the figure to independent evaluations from RAID, a real benchmark published at ACL 2024 by Dugan, Hwang, Trhlik and colleagues, covering over 6 million generations across 11 models, 8 domains and 11 adversarial attacks. The caution is that RAID’s own headline finding is about claims like this one: it reports that detectors claiming extremely high accuracy of 99% or more are easily fooled by adversarial attacks, variations in sampling strategies and unseen models. QuillBot’s site links no specific RAID result, so we could not establish which slice of that benchmark produces 99%.
Does QuillBot disclaim its own detector?
Yes, and clearly. The page states that no AI Detector can provide 100% accuracy, describes its outputs as probability estimates, not verdicts, and recommends users apply judgment rather than rely on a detection score alone. That is a more careful framing than most detector vendors manage, and notably more careful than the humanizer vendors it shares this cluster with.
Why does Pangram catch it every time?
Because of how well it writes, not how badly. Pangram’s DAMAGE paper rates QuillBot L1, its top tier for faithfulness and fluency, and observes that fluent rewriting is more detectable rather than less. Pangram also names QuillBot directly as a word spinner, a category it notes was used even before AI to disguise plagiarism. Its August 2025 benchmark scored QuillBot at 100.0% detection accuracy, joint-highest of the twenty tools measured.
Does QuillBot say anything about ChatGPT text specifically?
Its older guidance concedes the limit without hedging: we make no guarantees if someone uses QuillBot on text generated by a tool like ChatGPT. Its help article titled Will Turnitin detect QuillBot runs to 61 words and never answers yes or no.
So should a student use it?
For what it says it does, paraphrasing and readability, it is a competent tool from a mainstream company with a real corporate owner. For evading a detector it is the wrong choice on the published evidence, and the company tells you so itself. If detection is the actual worry, the free check is the honest step: paste your own text into gptzero.me, no account, up to 10,000 characters, and read the result.
