humanflow

Copyleaks, reviewed

In the one peer-reviewed study that tested it, Copyleaks was the most accurate detector examined and produced the most false accusations of any tool in the set. Those sound contradictory. They are not, and understanding why explains most of what is wrong with how these scores get used.

Last reviewed 16 August 2026 · The HumanFlow team

What it is

Founded in 2015, before the generative-AI era, as a plagiarism-detection company — Copyleaks Technologies Ltd., with a New York office and development in Israel. Its co-founders, Alon Yamin and Yehonatan Bitton, met in the Israeli military’s Unit 8200. It has raised a modest $7.75 million across a 2018 seed and a 2022 Series A.

What matters for a student is who buys it. Copyleaks is one of the few detectors sold to institutions the way Turnitin is — priced on full-time student headcount, with integrations into Canvas, Moodle, D2L Brightspace, Blackboard, Schoology, Sakai and Edsby. If your university runs AI detection, this is a plausible candidate for the tool doing it, and you may never see its name.

The contradiction at the centre of it

Perkins et al. (2024) tested seven detectors across 805 tests. Copyleaks came out on top: 73.9% accuracy on unmanipulated AI text, against a seven-tool average of 39.5%. Apply simple adversarial techniques and it fell to 58.7% — still the best of the seven, and still a long way from reliable. The paper’s own summary is worth quoting: “even the highest-performing tool (Copyleaks) failing to identify 39% of AI-generated cases.”

And in the same study it recorded the highest false-accusation rate of all seven tools, at 50%.

Those two results are not in tension once you see what a detector is doing. A tool tuned to catch more AI text will, on the same threshold, also flag more human text. Copyleaks is aggressive; aggression buys you detection and costs you innocent people. Which of those two numbers matters depends entirely on whether you are the person running the scan or the person being scanned.

Its own numbers say something very different

To Copyleaks’ genuine credit, it publishes the most complete testing methodology of any detector we have looked at: model version V10, tested 16 October 2025, English only, texts over 350 characters, test data disjoint from training data, run by two independent internal teams.

The headline results: across 229,843 human texts, 99.97% accuracy with 60 false positives in total — including 10,000 student essays with just two. Across 18,712 AI texts, 99.2%. Three sensitivity levels are published with their own error rates, the default “Balanced” setting at 0.026% false positives and 0.79% false negatives.

So how does 0.026% sit alongside a 50% false-accusation rate? Because they measure different worlds. Copyleaks tested a newer model on its own corpus, choosing the texts and the conditions. Perkins tested an earlier version against material deliberately modified to evade it, and counted an accusation as false when a human-written control was flagged at all. Neither is dishonest. Neither is the number you should carry around alone.

One caveat we would apply to any vendor, including ourselves: Copyleaks maintains a page collecting third-party studies that rate it well, and the Perkins study — the one with the 50% false-accusation finding — is not among them.

Where the independent record is kinder

It would be easy to build a hit piece from the Perkins number alone, so here is the other side. Orenstrakh et al. (2023) tested eight detectors against human and AI-generated computer-science submissions and found Copyleaks the most accurate at 97.06%, with a single false positive across 114 human submissions. It degraded on code, on non-English text, and after QuillBot paraphrasing — but on straightforward English prose it performed well.

Do not believe any figure attributing Weber-Wulff, Liang or the NBER paper to Copyleaks. It was in none of those three. This gets miscited constantly, and the 61.22% non-native-writer false-positive figure in particular belongs to a seven-detector average in a study Copyleaks was not part of.

Separately, Bloomberg Businessweek ran 500 university application essays written before generative AI existed through GPTZero and Copyleaks, and found 1–2% falsely flagged across the two tools, “in some cases claiming near 100% certainty”. The figure is a combined range rather than a per-tool result, but the confidence is the part worth noticing: a detector can be wrong and certain at the same time.

Where your text goes

This is the section we would want a student to read. Copyleaks paid plans include the Shared Data Hub, which the company describes as letting you compare your scans against submissions uploaded by other users. Read the other direction, that means a document you submit can join a corpus that other customers’ work is checked against.

Its privacy policy also states that it uses this information to train its models, with opt-out available to direct customers on request. There is a deletion route for internal data, and enterprise data is deleted within 90 days of a contract ending.

None of that is unusual for the category and none of it is hidden — but if you are pasting an unsubmitted dissertation or unpublished client work into a checker, it is the difference between a tool that reads your text and a tool that keeps it.

What it costs

Personal: $16.99/month for 100 credits, or $13.99/month billed annually for 1,200 credits a year. Pro: $99.99/month for 1,000 credits, or $74.99/month annually. One credit covers up to 250 words or one image — so 100 credits is around 25,000 words, roughly a hundred pages. Enterprise and Education are quote-only.

Two terms worth knowing before you subscribe: plans do not stack, so switching plans overrides your current one including any remaining credits; and refunds are available only within the first ten days and only if you have used no credits at all.

Where we stand

We sell a detector and a humanizer, so we are competing with this company. We have published no measured pass rate against Copyleaks and will not claim one before our benchmark produces it.

The honest summary is that Copyleaks is at the better end of a field whose better end is still not good enough to convict anyone. If you have been flagged by it, the 50% false-accusation finding is a legitimate thing to raise, and what to do next is the same as for any other tool: preserve your draft history, and ask what evidence exists beyond the score.

Compared against

  • Turnitin vs Copyleaks Copyleaks against Turnitin on what independent testing found, who each is sold to, and what happens to the text you submit.
  • SafeAssign vs Copyleaks Copyleaks against SafeAssign on what independent testing found, who each is sold to, and what happens to the text you submit.
  • GPTZero vs Copyleaks Copyleaks against GPTZero on what independent testing found, who each is sold to, and what happens to the text you submit.
  • Copyleaks vs QuillBot Copyleaks against QuillBot on what independent testing found, who each is sold to, and what happens to the text you submit.

Related

Also on Copyleaks: our longer review, and what the detectors charge, where their published pricing sits beside three others read on the same day.

Common questions

Is Copyleaks accurate?
It is the best-performing of the tools that have been independently tested — and it still failed to identify 39% of AI-generated cases in that test, and produced the highest false-accusation rate of the seven tools examined. Its own testing tells a very different story: 99.97% accuracy and a 0.026% false-positive rate on its V10 model. Both are real measurements of different things, and the gap between them is the most useful thing on this page.
How much does Copyleaks cost?
Personal is $16.99 a month for 100 credits, or $13.99 a month billed annually for 1,200 credits a year. Pro is $99.99 a month for 1,000 credits, or $74.99 a month billed annually. One credit covers up to 250 words or one image, so 100 credits is roughly 25,000 words. Enterprise and Education are quote-only, with Education priced on your institution's full-time student count.
Does Copyleaks keep what I submit?
Yes, and this is a product feature rather than a footnote. Paid plans include the Shared Data Hub, which Copyleaks describes as a library of user-submitted documents that scans are compared against — so a document you submit can become part of a corpus other customers are checked against. Its privacy policy also states it uses this information to train its models, with opt-out available to direct customers by contacting support.
Does Copyleaks detect humanized or paraphrased text?
It claims to — its highest sensitivity setting is explicitly described as designed to flag AI text put through a humanizer or text spinner. The independent evidence is less flattering: in peer-reviewed testing its accuracy fell from 73.9% to 58.7% once simple adversarial techniques were applied, and a separate study found it degraded notably after QuillBot paraphrasing.
Is Copyleaks used by universities?
Yes. Along with Turnitin it is one of the few detectors genuinely sold to institutions rather than individuals — priced per full-time student, with integrations for Canvas, Moodle, D2L Brightspace, Blackboard, Schoology, Sakai and Edsby. If your institution runs AI detection at all, Copyleaks is a realistic candidate for the tool doing it.
Is Copyleaks better than Turnitin?
They have not been tested head to head in a study covering both, so anyone giving you a straight answer is guessing. Turnitin scored highest of fourteen tools in Weber-Wulff et al. (2023), which did not include Copyleaks; Copyleaks scored highest of seven in Perkins et al. (2024), which did not include Turnitin in the same configuration. The honest answer is that both are at the better end of a field where the better end still means missing a third or more of AI text.

Sources

  1. 1.Simple techniques to bypass GenAI text detectors: implications for inclusive education Perkins, Roe, Vu, Postma, Hickerson, McGaughran & Khuat — Int. J. of Educational Technology in Higher Education 21:53, 2024
  2. 2.Detecting LLM-Generated Text in Computing Education Orenstrakh, Karnalim, Suarez & Liut — arXiv:2307.07411, 2023
  3. 3.AI content detector testing methodology (model V10, tested 16 Oct 2025) Copyleaks, 2025
  4. 4.Do AI Detectors Work? Students Face False Cheating Accusations Bloomberg Businessweek, 2024
  5. 5.Testing of detection tools for AI-generated text Weber-Wulff et al. — International Journal for Educational Integrity 19:26, 2023