PRAPI Research · 2026-07-31
What Gets Your Outreach Flagged as AI, Even When You Wrote It: 76 Operators on the Detection Arms Race
AI-detection is now built into inboxes, editor workflows, and source-request platforms, and it keeps flagging humans. We asked 76 operators what specifically gets their outreach tagged as AI even when they wrote it, and what gets through clean. The verdict is overwhelming and consistent: detectors react to structure and rhythm, not vocabulary. Tidy three-part lists, polished openers, and symmetrical sentences get flagged regardless of who typed them, while concrete, verifiable specificity gets through. The recurring operator rule: use AI for research, never for the final voice.
14 contributors cited
The AI-detection arms race has a problem almost nobody planned for: it flags humans. Editors, inbox filters, and source-request platforms now score every pitch for AI, and the detectors are noisy enough that outreach written entirely by hand gets tagged as machine-generated. We asked 76 operators and PR practitioners what specifically got their outreach flagged even when a person wrote it, and what changed to get pitches through clean. The answers were consistent.
It is structure, not vocabulary
The single most repeated finding: detectors are not reacting to words, they are reacting to shape. Operator after operator reported that the sentences lighting up their detectors were not the ones with "delve" or "leverage" in them, but the tidy ones. John Surabian III of Clickable Impact watched a pitch he wrote by hand on a Sunday afternoon, with no assistance of any kind, come back flagged high enough that the editor never replied, because it had a three-part list sitting in the middle of it. Kiel Tredrea of RED27Creative found that structured, well-formatted human emails were flagged more often than messy, conversational ones. Donnie Strompf of Good At Marketing calls it a silhouette: a greeting with a colon, three tidy bullets, a summarizing paragraph that adds nothing, a shape that reads as generated even when a person typed every word.
Ryan Miller of Sundance Networks, who spent 17 years in IT security reading outreach the way he reads phishing email, named the exact pattern: perfectly parallel bullet points, a three-part framework intro, and a clean call to action that wraps everything up too neatly. Human professionals do not write like that.
The tells operators now kill
The specific structures they have learned to cut:
- The polite opener that references the recipient's recent work. Joe Troyer of Great Lakes Tiny Homes says it is the fastest way to get flagged, because it matches the template pattern too closely.
- The throat-clearing first line. Joe Spisak of Fulfill.com, who has sent over 10,000 cold emails, got auto-rejected with an AI score for opening "I wanted to reach out regarding your recent article." His verdict: perfect grammar killed him more than bad grammar ever did.
- The credential dump. Justin Reese, a litigator at Alexander Shunnarah Trial Attorneys, found templated legal pitches flagged whether or not a human wrote them, because the culprit was the structure: formal opener, bullet-pointed credentials, call to action.
- The rule of three. Stephen Taormino of CC&A Strategic Media avoids the balanced three-part sentence because it sounds assembled; he says the false positives come from perfectly reasonable marketing language that has no scar tissue in it.
- Generic abstraction. Jennifer Bagley of CI Web Group puts it simply: if a sentence could apply to a dentist, a roofer, and an HVAC contractor, it probably sounds AI-generated even if you wrote it yourself.
What gets through: specificity only you could write
The counter-move nearly every operator converged on was concrete, verifiable specificity. Thomas Oldham of WebMotion Media skips the greeting and opens with a blunt, specific observation about the recipient's own situation, and reports replies within hours. Narayan Prasath of Metaflow cut the essay-like connective tissue and led with a specific data point, dropping his flag rate from roughly 40% to under 10% after a fully human pitch had been flagged 92% AI by GPTZero. The shared principle: a detail a template generator cannot reach, a real number, a named place, a friction point you personally verified, reads as human because it is.
The flag often costs nothing, until it does
An important nuance came from Raul Menoyo of Citora, who ran his own experiment on Qwoted's AI check. A polished pitch scored 100% AI; a rewrite in his own voice scored 100% AI again. Yet the flagged pitches still got read, and one became a published, linked quote. His takeaway: what kills a pitch is having nothing specific in it, not the score sitting next to it. But that grace is not universal. Joe Spisak and others were auto-rejected by submission systems before any human saw the pitch, and the filter, not the editor, made the call.
Where AI actually helps
Nearly everyone drew the same line. AI earns its place upstream: research, finding the relevant conversation, scoring leads, drafting a first-pass scaffold, pressure-testing whether a pitch answers the request. It gets you caught the moment it writes the final voice. Magee Clegg of Cleartail Marketing said it plainly: AI gets you caught when you let it write the final pattern, the clean opener, symmetrical bullets, vague benefit, frictionless call to action. Thomas Oldham's rule was the common refrain: use AI for the data, write the pitch yourself.
The human cost
The arms race is also wearing down the writers it misfires on. Mia Morin, Editor-in-Chief at Intimeros, is blunt: the detectors punish people who actually know how to write, and a sentence that is free of errors is suspicious. She now runs everything through detectors before sending, which killed her natural flow, and found that humanizer tools turned her clear sentences stilted and worse.
The operator playbook
- Break symmetry on purpose. Cut three-item lists to two or pad them to four. Let one sentence run long and a little ugly, then follow it with a fragment.
- Kill the polite opener and the credential dump. Lead with one specific, verifiable observation about the recipient's actual situation.
- Ground every line in a detail only you could know: a real number, a named place, a friction point you checked yourself.
- Use industry-specific language, not safe generic business words. The awkward insider term is what reads human.
- Use AI upstream for research and scaffolding, never for the final voice. The moment an AI-written first pass ships unedited, you are producing exactly what the filters are built to catch.
- Do not lean on humanizers. Operators consistently found they optimize for the same evenness detectors punish, and often score worse than the original.
The detectors are pattern matchers, not intent readers. In 2026 the winning move is not to sound less like a machine by swapping words; it is to write with the specificity, friction, and idiosyncrasy a machine has no way to fake.
Contributors
Qwoted runs an AI check on pitches. I wrote a pitch for a HubSpot piece reviewing five AI visibility tools: five balanced reviews, the same shape each time, praise then caveat, em dashes, polished. It scored 100% AI, 0% human.
The false positive that actually cost me was a pitch I'd written by hand on a Sunday afternoon, no assistance of any kind, and it came back flagged high enough that the editor never replied. It had a three-part list sitting right in the middle of it.
The opener that gets flagged fastest is any sentence that references the journalist's recent work in a polite way. It matches the pattern too closely.
I skip the greeting entirely and open with a specific client reference or a blunt observation.
The culprit was usually the structure: formal opener, bullet-pointed credentials, call to action. That's exactly how AI writes, and detectors don't care who actually typed it.
It gets you caught when you let it write the final pattern: clean opener, symmetrical bullets, vague benefit, frictionless CTA.
We had a fully human-written pitch to a tech publication flagged as 92% AI by GPTZero. The fix: we now strip any connective tissue that sounds "essay-like," lead with a specific data point or observation in the first two sentences, and keep paragraphs to 2-3 lines max. Since adopting that structure, our flag rate dropped from roughly 40% to under 10%.
The tell I avoid now is abstraction without receipts. If a sentence could apply to a dentist, roofer, SaaS company, and HVAC contractor, it probably sounds AI-generated even if I wrote it myself.
The detectors punish people who actually know how to write. A sentence that is free of errors is suspicious.
That silhouette reads as generated even when a person typed every word of it, and I have watched perfectly human pitches get treated as machine output because they arrived in that shape.
structured, well-formatted emails written by humans were getting flagged more than messy, conversational ones. The culprit wasn't the words—it was the rhythm.
The false positives usually come from “perfectly reasonable” marketing language that has no scar tissue in it.
I've sent over 10,000 cold emails building businesses and running Fulfill.com, and here's what actually gets flagged now: perfect grammar killed me more than bad grammar ever did.
Perfectly parallel bullet points, a three-part framework intro, and a clean CTA that wraps everything up too neatly. Human security professionals don't write like that.