Full disclosure: This post contains affiliate links. If you make a purchase through these links, 99signals may earn a commission at no additional cost to you.
There’s a loud argument happening about whether AI detectors work.
One camp says they’re a scam. A viral LinkedIn post called GPTZero a $30 million per year grift and noted that OpenAI quietly shut down its own detection efforts. Pangram and WIRED have been trading claims about bias and post-humanizer accuracy.
The argument is worth having. It’s also a distraction from enforcement that’s already running.
The Clearest Enforcement Data We Have
GMBapi analyzed 12,752 rejected Google Business Profile review replies, and the numbers are blunt.
Rejections ran at 354 in 2022 and 398 in 2023. In 2024 alone, 9,393. That spike tracks almost exactly with the mass adoption of AI reply tools.
Of those rejections, 92.6% were responses to 5-star reviews. Positive feedback generates the most rejections because that’s where businesses reach for enthusiastic templates.
Around 67% contained at least one detectable AI boilerplate phrase, up from roughly 35% in early 2024 to 85% by mid-2024.
Google isn’t flagging individual words. It’s flagging a structure: opener, reviewer name, compliment phrase, satisfaction line, forward-looking closer.
The recurring phrases are the ones unconfigured AI tools produce by default. “We’re thrilled to hear.” “Your kind words.” “Look forward to welcoming you back.”
If your reply tool writes those, audit it this week.
Nobody Gets a Notification
This is the part that should concern anyone running automated replies.
There’s no error message and no warning. The reply appears sent while sitting in a REJECTED state internally.
Without API-level visibility into ReviewReplyState, you’d never know. Businesses replying through the GBP interface, or through third-party tools that don’t surface that field, are flying blind.
A meaningful percentage of your existing replies may already be dead, meaning your side of those conversations never reached the public.
Two other patterns show up. Rejected replies were posted an average of 1,221 hours after the original review, roughly 50 days, with bulk-scheduled batches heavily overrepresented. And one account sent “Thank you!” verbatim to over 100 consecutive reviews. All rejected.
The practical fixes are unglamorous. Vary every reply rather than reusing a template. Strip embedded emails and phone CTAs. Spread replies across time instead of firing 200 on Monday morning. Aim to respond within 24 hours, since delay is itself a signal.
The filter also throws false positives, because it matches patterns rather than reading intent. A Dutch business replying “Beste Dick” gets caught on the reviewer’s legal name. A restaurant called Burger Bitch can’t sign off with its own name.
Detection Moved Inside the Models
The detector debate is becoming irrelevant because provenance has shifted upstream to the companies generating the text.
The mechanical difference matters. A third-party detector like GPTZero reads finished text and makes a statistical guess about whether a machine produced it. It has no access to the generation process, so it infers from surface patterns, which is why false positives hit non-native English writers hardest.
Watermarking works from the other end. The model embeds a signal during generation, so verification becomes a lookup rather than an inference.
Anthropic now watermarks Claude’s text output under the EU AI Act. Google has watermarked Gemini output since 2024 via SynthID.
Neither is perfect. Marks can be stripped by heavy editing, and absence of a mark proves nothing. But the direction is clear, and it’s not one that humanizers address.
Which means the defensive workflow that’s metastasized around detector evasion, running humanizers, deleting em dashes, scoring hooks, checking drafts against Pangram, is optimizing against the wrong threat. It bloats production and usually degrades the writing.
You Can’t Test Your Way Out of This
The deeper problem with pre-publication risk checks is timing.
John Mueller has confirmed that scaled AI spam triggers algorithmic penalties, and that recovery takes significant time and effort. Glenn Gabe has warned that short-term testing tells you nothing about spam update exposure.
Content can perform well for months before a core or spam update crushes it. Algorithmic demotions don’t reverse when you fix the content, because Google’s systems need to relearn compliance over a period measured in months.
That’s an untestable penalty. No detector check predicts it, and no dashboard shows it coming.
What’s Actually Being Punished
Worth being precise, because the distinction shapes where your budget goes.
Google’s guidance has been consistent that AI assistance isn’t the problem. LinkedIn’s crackdown targets generic, low-effort posts. The review filter catches templates, not automation.
What gets penalized is low effort, and AI is incidental to that.
Teams producing demand-validated, original work carry far less exposure than teams optimizing for detector scores, regardless of how much AI sits in either pipeline.
Building a Defense That Holds
The shift is replacing the humanizer-and-detector loop with validation before production and monitoring after.
Semrush’s Content Toolkit handles the front end. Topic Finder validates that every topic in a scaled program has real audience demand before anyone writes, which is the best guard against volume outrunning relevance.
That matters because scaled content usually fails on relevance before quality. Two hundred articles nobody searched for is the pattern that gets flagged, however the words were produced.
SEO Writing Assistant then works inside the editor, giving real-time originality, tone, and readability guidance during drafting. You meet a quality bar while writing rather than running a detector afterward and hoping.
The Content Toolkit runs $99 per month.
For the review reply problem specifically, the Local Toolkit is the relevant piece. Review Management centralizes monitoring and response so replies get drafted with oversight instead of bulk-generated in the batches Google’s filter is documented to catch.
Given that rejections are invisible, a managed workflow matters more here than almost anywhere else. You can’t fix what you never learn about.
GBP Optimization covers the adjacent risk as enforcement of AI-generated profile content tightens.
The Social Toolkit addresses LinkedIn, where slop reporting now extends to comments and feeds ranking. Social Content Insights shows which posts actually earn engagement, pushing optimization toward resonance rather than evasion. Social Tracker benchmarks competitors so you can see how the crackdown is reshaping your specific category.
Both run $49 per month, and all three offer free trials.
The Bottom Line
The detector accuracy fight will keep generating engagement and keep being the wrong conversation.
Third-party detection is unreliable and losing relevance. Model-level watermarking is reliable and expanding. Platform enforcement is already running, already silent, and already deleting work at volume.
None of that responds to humanizers or em-dash deletion.
What it responds to is content demonstrating genuine effort, validated demand, and quality that survives human review. That was the answer before AI detection became a product category.
Twelve thousand businesses learned it the hard way, and most still don’t know it happened.
