I Paraphrased AI Text With Another AI and Turnitin Still Flagged It
A second AI pass is a workflow Turnitin names in its own documentation and has dated release notes against. Here is what the score is actually computed over, what the report's colours can and cannot tell you now that Turnitin has merged two categories into one, and the one comparison you can run on your own two files.
HumanPen Team
· 22 min read
The short answer
Two separate things are going on, and they usually get collapsed into one. First, the percentage is not computed over the words that changed: Turnitin extracts sentences, groups them into overlapping segments, scores each segment between 0 and 1, and every qualifying sentence inherits the scores of the segments it sits in, pooled. A pass that returns the same sentences in the same order with the same paragraph breaks returns the same grouping. Second, this exact workflow is something Turnitin describes in its own documentation and has been shipping updates against since December 2023.
Which of the two is doing the work in your case is not readable off the percentage. The report's category used to be a partial answer, and on 4 August 2026 Turnitin merged the two categories into one, so on a freshly generated report it is not even that. What is left is a comparison you can run on your own two files without any detector at all. Both are below.
This article assumes the text started as AI output and you ran a paraphraser over it. If you wrote the thing yourself and got flagged anyway, the situation and the response are different, and we wrote that up in flagged, but you wrote it yourself.
What the score is attached to, and what your pass moved
Turnitin's capabilities FAQ describes the pipeline in one paragraph:
"When a paper is submitted to Turnitin, sentences from the submission are extracted and segmented into overlapping sections for prediction analysis. Each segment is classified by the AI detection model and given a value between 0 and 1, denoting the probability of the text being likely human or AI-generated. Each qualifying sentence within these segments inherits the segment's score. Since segments overlap, some sentences may have multiple scores, which are then pooled into a single score. These sentence scores are further aggregated and used to compute the overall document AI writing score."
The unit carrying the score is the segment, and a segment is a group of sentences. That is a statement about scope, not a verdict on any particular editing operation. Substitution inside a sentence is one operation among several a rewrite can perform; what it does to a segment score depends on how much of the segment moves with it, and Turnitin has published neither the pooling function nor the aggregation, so there is no published quantity to reason from. That gap is not one a vendor can close from the outside, ours included.
What you can say without guessing is narrower and still useful. If the paraphrased file has the same sentence count, the same sentence order and the same paragraph breaks, then the sentences that shared a segment before still share one now. Merging two sentences, splitting one, cutting a redundant clause or moving a claim to a different paragraph changes which sentences sit together. That distinction is visible in your own two files, which is more than can be said for most of what gets claimed about these reports.
The properties Turnitin has actually named in public are at that level too. In the same FAQ it says false positives "can include content without a lot of structural variation, text that literally repeats itself, or text that has been paraphrased without developing new ideas". That third item is a description of what a paraphrase pass produces, written by the vendor, in a list of text that gets flagged. The sentence immediately after it points the other way and belongs here too: "If our indicator shows a higher amount of AI writing in such text, we advise you to take that into consideration when looking at the percentage indicated." The manual edits that follow from all this are in how to humanize AI text without a tool.
The workflow has a name in the documentation, and dates
The second thing is not about your file at all. It is about what the detector was built to look for. Turnitin's FAQ states it directly:
"Furthermore, it can also identify instances where AI-generated text may have been modified by AI paraphraser or bypasser (also called humanizers) tools to evade detection."
The parenthesis is Turnitin's, not ours. Three release notes give the capability a timeline, and the most recent one changed what the report shows without changing what the model is looking for.
| Release note | What it says | What it means for a second pass |
|---|---|---|
| 6 December 2023 | "AI word spinners are sometimes used to avoid identification of AI-generated text. We now detect likely AI-generated text even if it may have been paraphrased using an AI word spinner." | The paraphrase step has been inside the model's stated scope for over two years. The same note adds that existing submissions must be resubmitted for the change to apply to them. |
| 27 August 2025 | "With this release, the 'AI-generated only' category in the AI writing report will now include the percentage of AI-generated text that may have been modified by an AI bypasser tool." | From that date, an `AI-generated only` highlight does not rule out a bypasser classification. There was never a separate third colour for it. |
| 4 August 2026 | "We've updated the AI Writing Report to combine the previous two categories blue and purple into a single blue category", and "purple highlights previously used for AI-paraphrased text will no longer be shown". The same note adds that the model "will continue to detect likely AI generated content that may have been further modified by AI paraphrasers or bypassers". | The report stopped separating the two. The detection did not stop. Turnitin says the new report reaches files submitted after that date, and that an older submission has to go through again before its report is rebuilt, so a report you are already holding can still show purple. |
Turnitin also says it will not publish which tools it has trained against: "Our AI writing detector has been trained and tested to detect leading paraphraser and bypasser tools. However, to safeguard the integrity of our solution and its effectiveness in maintaining academic honesty, we're unable to disclose the names of these tools." That is why nobody can give you a verifiable answer to "which paraphraser gets through", including anyone selling one. The list does not exist in public, and the model changes.
One limit on all of this, in the vendor's own words. A documented capability is a description of what a model was trained to do, not evidence that a specific passage went through that workflow. Turnitin's own guidance says its model "may not always be accurate (it may misidentify human-written, AI-generated, and AI-paraphrased text), so it should not be used as the sole basis for adverse actions against a student", and that determining misconduct "takes further scrutiny and human judgment in conjunction with an organization's application of its specific academic policies".
Language matters here as well: one Turnitin help article states that "only our English AI detector includes AI paraphrasing and AI bypasser detection capabilities", and adds that the Spanish and Japanese detectors do not.
What the report's colour tells you, now that there is only one
Until 4 August 2026 the standard AI Writing Report had two visible categories. `AI-generated only` was one of them, and since the August 2025 update it could also contain text the model considers possibly modified by a bypasser. The other was `AI-generated text that was AI-paraphrased`, shown in purple, a further inference applied to text already judged likely AI-generated. On 4 August 2026 Turnitin folded the second into the first and said the purple highlights would no longer be shown.
So what the colour is worth depends on which report you are holding. On one generated before that date, purple says the model reached a paraphrasing classification on top of the AI-generated one, while the other category, after August 2025, says nothing either way about a paraphrasing step. On one generated after it there is a single category, and no answer at that level at all. What did not change is the detection: the same release note says the model will continue to detect AI-generated content that may have been further modified by paraphrasers or bypassers. Neither state names a tool, an account, a device or a prompt, and the two old categories are worth reading properly before you build a story on an old report: we took them apart in what Turnitin's AI-paraphrased and AI-bypasser labels actually mean.
There is a second reason not to read too much into a category change between your two reports. These changes are not applied retroactively: Turnitin says the August 2026 one reaches only what you send it afterwards, and that anything already in the system keeps the report it has until you send it again. Two reports generated on either side of an update are not measuring the same thing, and a category can switch without your text being the cause. If you are holding two reports and trying to work out what your revision did, the comparison has more moving parts than it looks like, and comparing two reports rather than two scores is the longer version of that argument.
The comparison you can run without a detector
You almost certainly cannot measure the effect of the pass, for two documented reasons that stack. Turnitin displays no number and no highlights for scores above 0% and below 20%, only an asterisk, so a real move from 19% to 3% and no move at all look identical. And in most configurations the indicator is not yours to look at: Turnitin says the report is not visible to students, though instructors can download the PDF and share it.
What you can do is open your pre-paraphrase and post-paraphrase files side by side and answer four questions. None of them needs the detector, and all four take about five minutes on a chapter.
| What to compare | How to check it | What it tells you |
|---|---|---|
| Sentence count per paragraph | Count the terminal punctuation in three or four flagged paragraphs, in both files | If the counts match, the sentences that shared a segment before still share one |
| Paragraph breaks and the order of claims | Read both at 50% zoom, looking at the shape rather than the words | Merging, splitting and reordering change which sentences sit together. Replacements inside a sentence leave that arrangement where it was |
| Passages the first report never highlighted | Mark them in the report, then check whether the pass rewrote them anyway | A pass with no report in front of it treats flagged and unflagged prose the same way. Everything it touched is prose you now have to re-read |
| Quoted material, numbers and in-text citations | Search for quotation marks, then for each citation | A paraphraser has no way to know which sentence is a direct quote from a source you are obliged to reproduce exactly |
One trap specific to this workflow: if you tested the paraphraser on a short extract, the result told you very little. Turnitin says that in documents of only a few hundred words "the prediction will be mostly 'all or nothing' because we're predicting on a single segment without the opportunity to overlap", and that as a result text mixing AI-generated and original content can be reported as entirely AI-generated.
The fourth row is the one that costs people marks rather than percentage points. It is also the one nobody checks, because the file came back looking finished.
What the blind pass did to the rest of the document
A paraphraser run over a whole file has no report and therefore no scope. It rewrites the introduction you were happy with, the methods paragraph you spent a week on, and the sentence containing the figure your supervisor queried. None of those were flagged. All of them are now prose you have not read in its current form.
That is a proofreading job the size of the document, and it lands at the point in a submission cycle when there is least time for it. The specific things that break are boring and consequential: a direct quotation quietly reworded, a hedge dropped so a claim states more than your data supports, a term of art swapped for a near-synonym halfway through so the same concept now has two names, a number rounded. Reference lists, tables and equations have their own failure modes, which we listed in what happens to citations, tables and equations.
The alternative is not "do nothing". It is to make the report decide the scope, so the paragraphs you re-verify are the paragraphs something was actually said about. That is what rewriting only the paragraphs a report flagged means in practice, and most of the difficulty in it is matching a highlight that starts mid-clause back to a paragraph in your source file.
What to do with the report you already have
You have something more useful than a percentage: a set of marked passages. Work from those.
- Keep every file, in order. The original draft, the paraphrased version and both reports. That sequence is the only thing here that answers "how was this written", and it keeps answering it whatever the number does.
- Do not run a second blind pass over the whole thing. It doubles the re-verification job and removes your ability to tell which change did what, since you will have two rounds of edits mixed together in prose you no longer recognise.
- Re-read the four rows in the table above before anything else. Quotations and citations first. Those are marking criteria, not detector output.
- Decide scope from the report, not from the score. A passage nobody highlighted is a passage with no evidence attached to it.
- Check your institution's rule before you rewrite anything. There is no published threshold, and what counts as acceptable assistance is set locally rather than by the vendor. Why the widely-quoted 20% is not that rule is in is 20% AI too high.
We build a tool for the fourth item. HumanPen takes the AI Writing Report as a PDF, matches its highlighted passages back to your uploaded document, and shows you the scope before anything runs. A paragraph is the smallest unit it will rewrite, so a highlight covering half a paragraph is widened to the whole one and shown that way for you to confirm. It bills the words it actually rewrites, so a job scoped to four paragraphs is priced as four paragraphs.
What it does not do is give you a predicted score, because that number is not available to anyone outside Turnitin. What we can say is that eligible results can continue lowering AI for free.
Frequently asked questions
Would a third paraphrasing pass help? There is no published quantity that would let anyone answer that, and each pass adds a round of edits to prose you then have to re-verify. The vendor's own false-positive list names "text that has been paraphrased without developing new ideas" as a property of text that gets flagged, which is worth reading before adding a third round of exactly that.
There is purple in my report. Does that prove I used a paraphrasing tool? No, and check the date on the report first. Purple was a classification the model reached from the final prose, not a record of how the document was produced, and Turnitin says the model may misidentify human-written, AI-generated and AI-paraphrased text and that the score should not be the sole basis for action against a student. Since 4 August 2026 that category is not shown separately, so purple on the page means you are looking at a report generated before then, or at a submission that has not been resubmitted since.
I paraphrased a 300-word extract to test it and the whole extract came back flagged. Why? Turnitin says that in documents of only a few hundred words the prediction is mostly all or nothing, because there is a single segment and no opportunity to overlap, and that mixed content can therefore be reported as entirely AI-generated. A short extract is close to the worst possible test bed.
Does any of this apply to my Spanish or Japanese submission? Not the paraphrasing part. One Turnitin help article states that only the English detector includes AI paraphrasing and AI bypasser detection capabilities, and that the Spanish and Japanese detectors do not.
Can I just check the score between passes? Usually not. Anything above 0% and below 20% shows as an asterisk with no number and no highlights, and in most setups the indicator and report are visible to instructors and administrators rather than to you. That is the main reason this whole area runs on claims rather than measurements, and it is also why different detectors give you different answers, which we covered in why the same text scores differently on every detector.
Sources: Turnitin's [AI writing detection capabilities FAQs](https://guides.turnitin.com/hc/en-us/articles/28477544839821-Turnitin-s-AI-writing-detection-capabilities-FAQs), [Using the AI Writing Report](https://guides.turnitin.com/hc/en-us/articles/22774058814093-Using-the-AI-Writing-Report), and the [AI writing detection model release notes](https://guides.turnitin.com/hc/en-us/articles/28294949544717-AI-writing-detection-model). Quotations checked against those pages on 14 August 2026, and the 4 August 2026 entry in Turnitin's release notes checked on 18 August 2026. This is published on the blog of a company that sells a document rewriting tool, which is worth knowing while reading the section about what a blind pass costs.
KEEP READING