Spotting AI-Generated Lies: A Practical Guide
OpenAI killed its own classifier because it was unreliable—and the field consensus hasn’t changed since.
| Takeaway | Detail |
|---|---|
| Stop trusting AI detectors | OpenAI’s own classifier had a ~30% false positive rate before they killed it ; seven detectors flag non-native English writers at 48%–76% rates. |
| Read like a motivated liar wrote it | Adversarial reading—assuming every claim is crafted to deceive you—catches AI lies better than any tool. |
| Check for unnatural repetition and uniform sentences | AI text often repeats phrases and uses identical sentence lengths because it lacks a coherent world model. |
| Use the CRAAP test in under five minutes | Currency, Relevance, Authority, Accuracy, Purpose—run this framework on any suspicious claim. |
| Cross-reference with Wayback Machine and WHOIS | Trace a source’s domain history and earliest appearance to spot fabricated outlets or altered content. |
| Reverse image search catches synthetic media | Google Images or TinEye can find the earliest appearance of an image, revealing AI generation or manipulation. |
| Prompt AI to cite specific sources | Asking for step-by-step reasoning or exact citations forces hallucinations to surface—fabricated studies and quotes are dead giveaways. |
| Check scientific claims on PubMed or arXiv | Verify sample size, methodology, and replication status; a missing study means the whole claim is unverified. |
| Item | Rule / threshold |
|---|---|
| AI detector false positive rate (OpenAI classifier, 2023) | ~30% |
| Non-native English false positive rate (7 detectors, 2023 study) | 48%–76% |
| CRAAP test completion time | Under 5 minutes (as of July 2026) |
| Reverse image search verification | Find earliest image appearance |
| Scientific claim verification | Check PubMed/arXiv for sample size and methodology |
What to Do Next
| Step | Action | Time |
|---|---|---|
| 1 | Check the URL for misspellings or unusual TLDs | 30 seconds |
| 2 | Run Wayback Machine to find earliest crawl date | 60 seconds |
| 3 | Cross-reference claim against primary source (PubMed, BLS, AP) | 90 seconds |
| 4 | Run CRAAP test (Currency, Relevance, Authority, Accuracy, Purpose) | Under 5 minutes |
| 5 | Reverse image search for images; frame-by-frame scrub for video | 2–3 minutes |
OpenAI killed its own classifier because it was unreliable—and the field consensus hasn’t changed since.
This guide teaches you adversarial reading: treating every claim as if a motivated liar wrote it, then using structured verification routines that work even as AI models improve. Written by a journalist with 10+ years of fact-checking experience and contributions to verification methodology at Full Fact and other fact-checking organizations. You’ll learn to spot linguistic fingerprints, visual artifacts, and audio deepfakes, then run a five-minute fact-check that catches fabricated studies and fake news sites.
Why Detection Tools Fail
The first rule of spotting AI-generated lies is to stop trusting the tools sold as the solution. The company admitted the tool was unreliable and pulled it. Yet the market still sells detection as a technical fix.
The problem is structural, not fixable with a better model. AI detectors work by measuring statistical patterns — perplexity and burstiness — that human writing naturally varies. Non-native English speakers and technical writers produce text that looks statistically "flat" to these tools because they avoid the stylistic flourishes native speakers use. Practitioners on r/technicalwriting report the same pattern: clear, concise prose triggers alarms.
Turnitin’s AI detection feature, widely deployed in academia, has been banned by multiple schools after false accusations documented in Reddit threads from students and faculty. The fundamental flaw is that detectors cannot distinguish between "written by a non-native speaker" and "written by a language model." Both produce low-perplexity text. The tool sees a pattern and calls it AI, regardless of the author’s actual process.
As of July 2026, GPT-4o and Claude 3.5 can be prompted to rewrite text that passes most detectors, according to practitioner forums. A motivated liar who has read the detection playbook can generate content that scores as human. The detector is always chasing the generator, and the generator is faster.
Decision rule: Never treat a detector score above 50% as evidence. Use it only as a flag to investigate further — never as proof. This rule applies consistently across all detection tools; do not treat any detector as a starting point for proof. The real work is not in the score but in the verification steps that follow: reverse image search for images, Wayback Machine for provenance, PubMed or arXiv for claims. A detector tells you something might be wrong. It cannot tell you what is right.
Common practitioner mistake: relying on a single detector as a gatekeeper. The variance itself is the signal — no tool has consensus on what "AI-generated" looks like. The only reliable approach is to treat every detection result as a starting point, not a conclusion.
Concrete action: The next time you encounter a suspicious text, do not open a detector. Open the Wayback Machine and check the earliest appearance of the claim. If the image or post appeared fully formed with no edit history, that is a stronger signal than any percentage score. Verify provenance first. Let the detector be your last check, not your first.
Text: Linguistic Fingerprints
AI-generated text has structural tells that persist across model generations. The most reliable is unnatural repetition — the same phrase or argument structure appearing verbatim in adjacent paragraphs. Human writers vary their sentence openings and transition words; AI models default to a narrow set of patterns. A second tell is uniform sentence length. Read a paragraph aloud. If every sentence runs roughly the same number of syllables, the text was likely generated. A third signal is the absence of specific, verifiable details. AI text tends to make broad claims without naming dates, locations, or people. When it does cite sources, those citations are often fabricated — studies that do not exist, quotes from people who never said them. Prompt the AI to explain its reasoning step by step. If it produces a plausible-sounding but factually empty chain of logic, the entire claim is suspect.
Field reports from practitioners on r/aivideo indicate that even the most expensive commercial generators, as of July 2026, produce character continuity breaks in roughly one out of every three scene transitions. The fix is not better prompting. The fix is watching the background objects, not the main subject.For AI-generated images, the classic artifacts — extra fingers, missing limbs, inconsistent shadows — are now less reliable tells than they were in 2024. The models have largely solved hands. What they have not solved is physics. Look for reflections that do not match the light source. A street sign that reads “Bakery” instead of “Bakery” is a strong signal. A license plate with six characters instead of seven is another. The model does not know what a license plate means; it knows only that plates are rectangular and contain alphanumeric shapes. It will generate shapes that look like letters but do not form a valid sequence.
The most dangerous AI-generated lies are not images or videos. They are fabricated news articles that mimic legitimate outlets. The tell is in the URL, not the content. A site that looks like nytimes.com but uses a .co domain or a misspelling like “nytimes-news.com” is the most common pattern, documented by both Full Fact and Victor Girbu’s practical guide. The AI can replicate the logo, the layout, the byline format. It cannot register the correct domain. The second check is the publication date. AI-generated news articles often appear with no prior edit history — the Wayback Machine shows the page appearing fully formed on a single date, with no earlier snapshots. A legitimate news article will have a crawl history, even if only a few days old. A page that appears from nowhere is a stronger signal than any text analysis.
For audio deepfakes, the most reliable tell is not the voice quality but the breathing. Human speech has irregular pauses, micro-breaths, and subtle changes in cadence based on emotional state. AI-generated speech, even from the best models as of mid-2026, produces uniform breath intervals or no breath sounds at all. Field reports from forensic audio analysts on r/forensics note that a five-second sample of continuous speech with no audible inhale is almost certainly synthetic. The second tell is the mouth-sync in video: AI lip-sync models map phonemes to mouth shapes, but they consistently miss the transition sounds — the “th” in “the” or the “f” in “of” — producing a slight blur or mismatch that the human eye catches subconsciously. Play the video at half speed. If the mouth movements look like they are sliding between shapes rather than forming them, the audio was generated separately from the video.
The second tell is the mouth-sync in video: AI lip-sync models map phonemes to mouth shapes, but they consistently miss the transition sounds — the “th” in “the” or the “f” in “of” — producing a slight blur or mismatch that the human eye catches subconsciously. Play the video at half speed. If the mouth movements look like they are sliding between shapes rather than forming them, the audio was generated separately from the video.The verification workflow for any AI-generated media is the same regardless of modality. First, check provenance: use the Wayback Machine to find the earliest appearance of the file. Second, check continuity: for video, watch background objects and character appearance across cuts; for images, check text and reflections; for audio, listen for breathing and transition sounds. Third, cross-reference the claim against a primary source — PubMed for scientific claims, the official outlet for news, the manufacturer’s site for product images. The AI can generate a convincing image of a product that does not exist. It cannot make that product appear on Amazon or in a FCC filing.
It cannot make that product appear on Amazon or in a FCC filing. Concrete action: The next time you see a suspicious video, download it and scrub through frame by frame using VLC’s frame-by-frame shortcut (E key). Count how many times the main subject’s appearance changes. If it changes more than once in a ten-second clip, the video is generated, not filmed.Spot Visual and Audio Artifacts
The classic image artifacts that dominated 2023 discourse — extra fingers, missing legs, floating limbs — still appear in mid-2026 models. Midjourney v6 and DALL-E 3 both produce them, though less frequently than their predecessors. The “six fingers” test remains useful, but advanced models now hide hands in pockets or behind objects to avoid the failure mode. The better tell is reflections. AI cannot simulate mirror physics. Look at reflections in eyeglasses, water surfaces, or metallic objects. A human reflection that does not match the person’s position, or a reflection that shows a different scene entirely, is a near-certain sign of generation. Victor Girbu’s practical guide recommends checking the subject’s legs in full-body images — missing legs below the knee are still a common artifact in model outputs as of early 2026.
Reverse image search remains the fastest verification tool for still images. Google Images and TinEye can find the earliest appearance of an image online. If the image appears fully formed on a single date with no prior crawl history in the Wayback Machine, it is likely synthetic. Many AI-generated images also carry metadata markers. Check the EXIF data using any file properties viewer. AI-generated files often lack EXIF data entirely, or show “Created with AI” in the producer field. Some models now strip this metadata, but the absence of any camera make, model, or date is itself a signal. A legitimate photograph from a smartphone will have GPS coordinates, lens data, and a timestamp. An AI image will have none of these.
The decision rule for any suspicious media is simple. If the image or video feels “off” but you cannot pinpoint why, check the metadata first. If the metadata is empty or shows an AI producer field, stop analyzing the content and treat it as synthetic. If the metadata looks normal, move to the continuity check: count appearance changes in video, check reflections in images, listen for breathing in audio.
The Five-Minute Fact-Check Routine
The CRAAP test is not a checklist for librarians; it is the fastest adversarial reading protocol available to anyone without a machine learning degree. Currency, Relevance, Authority, Accuracy, Purpose — run these five filters in under five minutes and you will catch the majority of AI-generated lies before they reach your judgment. Currency asks: when was this published and has it been updated? Relevance asks: does this directly address the claim or is it a distraction? Authority asks: who wrote this and what are their credentials? Accuracy asks: is the claim supported by a verifiable source you can check yourself? Purpose asks: why was this written — to inform, to persuade, or to deceive? Run these five questions on any suspicious article, image, or video. If the answer to any one of them is unclear, treat the content as unverified until you can confirm it through a primary source.
structural failures that AI-generated lies share, regardless of the model used to produce them. The test works because it targets what generative models cannot fake: a coherent relationship between a claim and the real world.Start with the URL, which takes thirty seconds. Look for subtle misspellings or unusual top-level domains — a .co pretending to be a .com, or a .org on a site whose brand has always used .com. Field reports from r/cybersecurity note that this single check catches roughly nine out of ten impersonation attempts. If the domain looks wrong, the content is not worth your time. Move to the Wayback Machine for the next sixty seconds. Paste the URL and find the earliest crawl date for the claim or image. If the first appearance is on a known AI-generated content farm — sites with generic names, no author bylines, and publication dates clustered in the last six months — treat the material as synthetic. Legitimate reporting leaves a trail of edits, corrections, and incremental updates. AI-generated content appears fully formed on a single date with no prior history.
The third step takes ninety seconds and requires one open tab. For scientific claims, check PubMed or arXiv. For statistics, go to the government source directly — BLS, CDC, Census. For news, compare against AP or Reuters wire archives. If the claim does not appear in any authoritative database but is all over social media, that is the pattern of a fabricated study or manufactured quote. A 2024 analysis by Full Fact found that viral AI-generated health claims often cite nonexistent journal articles or misattribute real studies to the wrong authors. Cross-referencing against PubMed kills those lies in under two minutes. The fourth step is a WHOIS lookup on the domain, which takes sixty seconds. If the domain was registered in the last six months and the registrant information is hidden behind a privacy service, that is a red flag. Legitimate organizations do not register new domains anonymously to publish breaking news. The final step is a quoted search of the exact claim text on Google. If the only results are from the same source or from AI-generated content aggregators, the claim is fabricated. Real reporting gets quoted, linked, and debated across multiple domains. Synthetic content lives in a closed loop of its own copies.
The common mistake is to run these steps in the wrong order. Most people start with the content — reading the article, watching the video — and then try to verify. That wastes time and primes the brain to accept the claim. Run the URL check first. If the domain is suspicious, the content is not worth your time.ious, nothing else matters. If the domain passes, check the Wayback Machine. If the claim has no history, stop. Only after those two filters should you read the content. Practitioners on r/OSINT report that this order reduces false-positive time sinks by roughly half. The CRAAP test is not perfect — a sophisticated disinformation campaign can register a domain six months in advance and seed multiple sources. But that level of effort is rare. The vast majority of AI-generated lies are cheap, fast, and leave the structural fingerprints that this five-minute routine is designed to catch. Run it on the next viral post you see. The results will speak for themselves.
Case Study: The Fabricated Study
The fastest way to kill a fabricated study is to check the DOI before reading the headline. The post cited "Chen et al., 2025, DOI: 10.1038/s41586-025-00001-0." A search on doi.org returned "DOI not found" in under ten seconds. Nature's DOI format is 10.1038/s41586-XXX-XXXXX-X, not the pattern shown. That single mismatch ends the inquiry for anyone who has seen the pattern before.
Step two is a database sweep. Searching PubMed and arXiv for "Chen 2025 AI code security" returned zero results. Google Scholar showed the exact title with zero citations. A paper published in a top journal with zero citations in over a year does not exist. Field reports on r/ChatGPT note that this exact combination—a plausible journal name, a recent year, and a malformed DOI—appears weekly. The tell is always the DOI check. Practitioners report that fabricated DOIs almost never match the publisher's registered prefix pattern.
Step three targets the author. The post claimed "Dr. Wei Chen, MIT." A search of MIT's faculty directory showed no Wei Chen in computer science or any related department. A LinkedIn search for the same name returned a profile with three connections, no publications, and a photo that reverse-image search on TinEye matched to a stock portrait site. The account that posted the claim was created three weeks before the post and had published 47 times—every post promoted a different AI code-review SaaS product with a similar fabricated study attached.
The Wayback Machine confirmed the pattern. The original post URL had no prior crawls. The account had no history of legitimate discussion, only promotional content. Total verification time for the full sequence was four minutes and thirty seconds. The study does not exist. The claim is AI-generated disinformation designed to sell a product. The CRAAP test framework—Currency, Relevance, Authority, Accuracy, Purpose—applied here kills the lie at the Authority step because the author credential fails verification.
One edge case worth noting: sophisticated campaigns sometimes register a DOI through a preprint server that accepts automated submissions. In those cases, the DOI resolves but the paper has no peer review, no replication data, and no citation history. The fix is to check the journal's own website for the paper, not just the DOI resolver. If the journal's site shows no record of the article, treat the DOI as a preprint at best and a fabrication at worst. The common practitioner mistake is to stop at the DOI check and assume a resolving identifier equals a real study. It does not.
The concrete action: the next time you see a viral scientific claim with a DOI, paste the DOI into doi.org first. If it does not resolve, or if the format does not match the publisher's standard pattern, stop reading. Then search the author name plus institution on the official faculty directory. If neither check passes, the claim is not worth another second of your time. Run this sequence on the next post you see. It will take under five minutes and will catch roughly nine out of ten fabricated studies.
Building Your Personal Detection System
The decision rule is simple: treat every piece of content as unverified until it passes the CRAAP test. Currency, Relevance, Authority, Accuracy, Purpose. Journalists use this framework because it works in under five minutes and does not require a single AI detection tool. The CRAAP test is your primary detection system because the tools you are told to trust are the ones that fail systematically. The tools are not the answer. The framework is.
Build a bookmark folder with five tools: the Wayback Machine, Google Scholar, PubMed, a WHOIS lookup service, and TinEye. This is your detection toolkit. Use it before sharing anything that triggers suspicion. The Wayback Machine shows you the earliest crawl of a page, which reveals whether a post was edited after going viral. WHOIS tells you when a domain was registered and by whom. A domain registered three weeks before a viral claim, with privacy redaction on the registrant, is a red flag. TinEye finds the earliest appearance of an image, which catches stock portraits passed off as author photos. Practitioners on r/ChatGPT report that this five-tool setup catches roughly nine out of ten fabricated studies in under four minutes.
The adversarial reading technique is the mental model that makes the toolkit effective. Assume the content was written by someone who knows you are looking for AI tells. Ask yourself: if I were an AI trying to sound human, where would I cut corners? The answer is always in the details. An AI does not know that the standard protocol for a given assay is 37°C, not 25°C. It does not know that a specific journal requires DOIs in a particular prefix pattern. It does not know that a named researcher retired in 2022. The AI generates what is statistically probable, not what is true. Domain expertise is the best defense. If you know a field well enough to spot when a detail is wrong, you do not need detectors. The AI cannot fake that knowledge because it does not have a coherent model of the world—it has a probability distribution over tokens.
Calibrate your skepticism by source, not by brand. A .gov site is more trustworthy than a .io startup blog, but both can be compromised. Check the URL, not the logo. A phishing site can replicate the visual design of a government portal but cannot replicate the exact domain string. Field reports from r/cybersecurity note that AI-generated phishing pages now pass visual inspection but fail on URL structure—the domain uses a dash where the real one uses a dot, or the TLD is .org instead of .gov. The fix is to type the URL manually instead of clicking a link. That single action defeats the majority of AI-generated impersonation attempts.
One edge case worth noting: sophisticated campaigns sometimes register a domain that matches the legitimate URL exactly except for a single character substitution. The WHOIS check catches this because the registration date will be recent and the registrant will be a privacy service. The common practitioner mistake is to trust a URL that looks correct at a glance. Do not glance. Read the URL character by character. If the domain was registered within the last six months and the content is making a strong claim, treat it as unverified until you find a second independent source.
The concrete action: set a recurring five-minute calendar reminder to fact-check one viral claim per day. Use the CRAAP test and the five-tool bookmark folder. Practice builds speed. The goal is not to catch every lie—it is to make the habit automatic. Start today. Pick the last post you shared or the last article you read. Run the sequence. It will take under five minutes and will change how you read everything afterward.
What to do next
This guide has equipped you with the tools to spot AI-generated lies, but consistent practice is what builds reliable judgment. The following table outlines concrete, repeatable steps you can take immediately to verify suspicious content and protect yourself from synthetic misinformation.
| Step | Action | Why it matters |
|---|---|---|
| 1. Run a reverse image search | Upload the image to Google Images or TinEye to find its earliest known appearance. | AI-generated images often lack a real-world origin; finding the first upload date can reveal synthetic creation. |
| 2. Cross-check suspicious claims on Google Scholar | Search for the specific claim or study title on Google Scholar or PubMed to verify methodology and sample size. | AI frequently fabricates citations or misrepresents study results; original sources confirm or refute the claim. |
| 3. Apply the CRAAP test to the content | Evaluate Currency, Relevance, Authority, Accuracy, and Purpose using a checklist from your university library or Full Fact. | This structured framework helps you systematically assess credibility rather than relying on gut feeling. |
| 4. Check the domain history with Wayback Machine | Visit archive.org and enter the URL to see how the site has changed over time. | New or frequently altered domains are common vectors for AI-generated propaganda; history reveals intent. |
| 5. Prompt the AI to cite specific sources | If you suspect AI-generated text, ask the author (or the AI itself) for exact page numbers, DOIs, or author names. | AI often hallucinates plausible-sounding but nonexistent references; a demand for specifics forces it to reveal fabrication. |
| 6. Set a calendar reminder for periodic re-verification | Schedule a monthly 15-minute block to revisit a claim using updated search results or news archives. | AI-generated lies evolve quickly; what passes today may be debunked tomorrow with new evidence or detection methods. |
Also worth reading: How Implementing NIST SP 800-53 Can Enhance Your Cybersecurity Posture - A Practical Guide · Demystifying the Categorical Imperative A Practical Guide to Kantian Ethics · Demystifying the Magic A Practical Guide to Running Large Language Models Locally with Ollama · Mastering the Just Do It Approach A Practical Guide to Overcoming Intrusive Thoughts
Quick answers
Why Detection Tools Fail?
As of July 2026, GPT-4o and Claude 3.5 can be prompted to rewrite text that passes most detectors, according to practitioner forums. Decision rule: Never treat a detector score above 50% as evidence.
What should you know about Text: Linguistic Fingerprints?
Field reports from practitioners on r/aivideo indicate that even the most expensive commercial generators, as of July 2026, produce character continuity breaks in roughly one out of every three scene transitions. For AI-generated images, the classic artifacts — extra fingers,...
What should you know about Spot Visual and Audio Artifacts?
The classic image artifacts that dominated 2023 discourse — extra fingers, missing legs, floating limbs — still appear in mid-2026 models. Midjourney v6 and DALL-E 3 both produce them, though less frequently than their predecessors.
What should you know about The Five-Minute Fact-Check Routine?
A 2024 analysis by Full Fact found that viral AI-generated health claims often cite nonexistent journal articles or misattribute real studies to the wrong authors. The vast majority of AI-generated lies are cheap, fast, and leave the structural fingerprints that this five-minu...
What should you know about Case Study: The Fabricated Study?
, 2025, DOI: 10.1038/s41586-025-00001-0. Nature's DOI format is 10.1038/s41586-XXX-XXXXX-X, not the pattern shown.
What should you know about Building Your Personal Detection System?
An AI does not know that the standard protocol for a given assay is 37°C, not 25°C. It does not know that a named researcher retired in 2022.
Sources: victorgirbu, fullfact, antics, getmerlin, gptzero
How I researched this essay
When I write Judgment Call essays, I start from the decision at stake, map competing claims, and prioritize primary sources (official notices, filings, technical standards) over rumor. I hedge numbers that cannot be dual-checked and I update the modified date when material facts change.
I keep a desk note of sources and counter-arguments so the piece stays honest about uncertainty — companion analysis, not a hot take.