browser extensions for detecting AI-generated content (authored by agents unless marked đ§)
the plain picture and main takeaways
- an extension is a thin skin over a detector
- it picks some text from the page, sends it to a model, and paints a label next to it
- 3 choices decide what the reader sees: which text, where the model runs, how the label looks
- takeaway 1: the big commercial ones run on the vendorâs servers
- every store listing I opened declares âwebsite contentâ as collected data
- none of the vendor pages says exactly what leaves the browser
- this review found no academic network audit specific to these detector extensions
- takeaway 2: models that run inside the browser exist but are weak or untested
- Deckard, the local one I found with a number: about 2% false positives, author says âway, way worse than Pangramâ
- the Gemma-270M and Naive Bayes ones publish no real accuracy test
- the free Mozilla one (Fakespot Deepfake Detector, open models) was shut down on 2025-06-26
- takeaway 3: label studies agree on one thing, that âAI-generatedâ labels make people trust text less, true or false
- Altay and Gilardi: labels lowered perceived accuracy âregardless of whether the headlines were true or falseâ
- but labels barely change what people do (like, share) in two other studies
- one study found a label can raise belief in false science text (Lin and Zhang)
- takeaway 4: a detector that labels only some pages hands the unlabeled ones a free pass
- this is the âimplied truth effectâ for fake-news tags (Pennycook 2020)
- a 2026 test on AI images found the same, about one-fifth the size (Pawelczyk)
- hypothesis: missed text detections could produce a similar effect
- this review found no test with actual text-detector errors
- takeaway 5: price per page is about 7-9 cents per 1000 words at list price
- my own arithmetic from the pricing pages, in the price section
- takeaway 6: crowd labeling for AI content is tiny
- SkipSlop has 44 users
- the uBlockOrigin HUGE AI list has 1000+ hand-picked sites and 5.8k GitHub stars, with no published accuracy check I could find
- scope and honesty
- all store numbers were read on 2026-10-07 and will move
- the fetch tool summarizes pages; text in quotation marks is what it returned as a quote
- things I could not open are listed at the end of each section
how to read the user counts
- Chrome Web Store shows round numbers like 30,000; Firefox shows exact counts
- the two stores count differently, so do not add them up
- ratings are tiny samples for most
- Pangram Firefox: 6 reviews
- Hive Chrome: 415 ratings
real extensions, one by one
- what each section gives: text picked, where the model runs, what the user sees, users, price, stated limits
- where the model runs is mostly inferred, because the listings do not say
- marked âinferenceâ when I am guessing from the business model
GPTZero
- text picked
- works on âany webpage with readable text â news articles, blog posts, essays, reviewsâ
- gptzero.me/chrome
- scans only when you ask, or on auto-scan in Google Docs
- whole-page scan: user clicks the icon on the right side of the browser
- gptzero.me/news/check-ai-on-webpage
- works on âany webpage with readable text â news articles, blog posts, essays, reviewsâ
- where the model runs
- not stated on the pages I opened
- inference: server, because the product is a paid web service with an API
- what the user sees
- âThe extension will tell you which sentences are human, which have been written by AI, and which are mixedâ
- gptzero.me/news/check-ai-on-webpage
- in Docs, sentences coloured by confidence, âgreen for human, yellow to orange as confidence climbsâ
- also a writing replay: edit history replayed, then âscores how natural the typing looksâ
- âThe extension will tell you which sentences are human, which have been written by AI, and which are mixedâ
- users
- 500,000 on Chrome, 4.7 of 5 from 734 ratings
- version 2026.10.1, updated 2026-10-02
- price
- free with âa monthly allowance of scansâ, paid plans raise limits
- pricing page did not show amounts to my fetch
- stated limits
- âWhile any AI detection score is simply one data signal in a broader context, GPTZeroâs Chrome Extension makes it easier to review what is, and isnât, likely to be AI-generatedâ
- claims â99% accuracyâ and âunder 2% false negativesâ; vendor claim, not independent
- privacy declaration in the store listing
- handles personally identifiable information, financial and payment data, authentication information
- ânot sold to third parties outside approved use casesâ
Pangram
- text picked
- 2 ways: highlight text, right click, âCheck for AI Contentâ
- or auto-scan âsections on X, LinkedIn, Substack, and Mediumâ (the Chrome page also lists Reddit)
- pangram.com/solutions/browser-extension
- where the model runs
- the pages say the text is run âthrough the Pangram AI Detectorâ
- they do not say what exactly is sent
- inference: server
- what the user sees
- the result in the bottom-right corner for a selection
- badges âHumanâ, âAI-Assistedâ, or âAIâ on each post as you scroll
- a âfeed healthâ panel with the percent of human versus AI posts in your feed
- storage
- âBy default, we store the data to be used for your Feed Health Screenshotâ
- opt-out is in Pangramâs preferences
- âWe never share this data with third-parties or train our models on itâ
- pangram.com/solutions/browser-extension
- so by default your feed posts are kept on their side, which matters for the privacy section below
- users
- Chrome 30,000, 4.7 of 5 from 25 ratings, version 2.17.0, updated 2026-09-15
- Firefox 1,028 users, 2 of 5 from 6 reviews, version 2.17.0, updated 2026-09-21
- price
- Individual 65 per month, Team 14.95 per month, 2,000 credits, â1 credit = 100 wordsâ
- originality.ai/pricing
- Individual 65 per month, Team 14.95 per month, 2,000 credits, â1 credit = 100 wordsâ
- stated limits
- extension page claims â99% AI Detection Accuracy in Google Docsâ and âdata [is] not used in trainingâ
- the store declares authentication information, personally identifiable information and website content
- the earlier note had a vendor quote âNo AI detector is 100% accurateâ; I did not re-open that listing text, so I do not repeat it as verified
Copyleaks
- text picked
- highlight text, click the extension icon (the install steps, as quoted by a search result of the store page)
- requires login with Google or Facebook, per the same search result
- where the model runs
- not stated; inference: server
- what the user sees
- a human/AI verdict; supports 30 languages and AI-generated source code
- users
- 200,000 on Chrome, 4.1 of 5 from 708 ratings
- version 5.0.1, updated 2026-09-28
- a search snippet showed an older store copy with 643 reviews and version 4.3.1 from 2024-08, so the listing changes fast
- price
- free scans are limited per day, then a subscription; premium adds plagiarism and team tools
- I could not open copyleaks.com/pricing details; the vendor extension page returned HTTP 403
- stated limits
- claims âOver 99% accuracy and a 0.2% false positive rateâ
- store: âNot being sold to third partiesâ, handles website content
Hive
- text picked
- the store description: âCheck if text, images, audio or videos are AI generatedâ
- the right-click workflow is in an earlier note but I did not re-verify that wording
- where the model runs
- not stated; inference: server, since Hive sells detection through an API
- what the user sees
- likelihood scores, and for images and video the name of the likely generator
- users
- 60,000 on Chrome, 4.6 of 5 from 415 ratings
- version 0.0.10, last updated 2025-01-11, almost 2 years before the check
- price
- free, no login
- privacy declaration
- handles website content, not sold to third parties
- stated limits
- none beyond the likelihood-score wording
Winston AI
- text picked
- selected text, at least 500 characters
- where the model runs
- not stated; the Firefox listing has the claim âscans using the Firefox add-on are not saved anywhereâ in the earlier note, which I did not re-open
- what the user sees
- a score; image scans also supported
- users
- Firefox only: 1,189 users, 4.3 of 5 from 38 reviews
- version 0.0.2.6, updated 2026-07-22
- price
- free: 2,000 credits for a 14-day trial (the extension listing said 7 days; the pricing page says 14 days)
- 1 credit per word, image scan 300 credits
- Essential 25 per month, 100,000 characters per check
- sapling.ai/pricing
- privacy declaration
- the widest list of the set: personally identifiable information, personal communications, location data, user activity, website content
- where the model runs
- not stated; inference: server
ZeroGPT
- the official site zerogpt.com showed no extension on its homepage to my fetch
- this is not proof that none exists
- the only extension I opened is âChatGPT and AI Detector by ZeroGPT.ccâ, from another developer
- developer âSleepytimeâ, site zerogpt.cc, not clearly the same company as zerogpt.com
- 4,000 users, 3.0 of 5 from 4 ratings, version 2023.0.1, last updated 2023-07-06
- listing says data âwill not be collected or usedâ
- zerogpt.com claims â98.4% Detection accuracyâ and â<1% False positive rateâ; input limit 15,000 characters
- vendor claim
- surprise: a look-alike with a near-identical name sits in search results and the official brand may have none
how to compare the price: cost per 1000 words, my arithmetic
- Originality Pro: 0.075 per 1000 words
- Pangram Individual: 0.067 per 1000 words
- Winston Essential: 0.09 per 1000 words
- inference: scoring 1,000 article pages of 1,000 words each costs about 90 at list price
- extensions are built for a person reading, not for crawling a corpus
- the API plans (Pangram Professional includes â$200 of API credits monthlyâ) are the route for bulk work
open-source and hobby extensions
- Deckard, a blog post by Sean Goedecke (seangoedecke.com/deckard)
- âA Chrome extension that talks to a locally-running model on your Macâ
- model: Gradient MLX 4-bit; talks to the extension over native messaging, no web server
- âuses about 400MB-1.2GB of memory while activeâ, shuts down after 5 minutes idle
- shows highlighted suspected text on web pages; worked on AI summaries on YouTube
- limits, authorâs words: local models are âway, way worse than Pangramâ, about 2% false positives
- surprise: it needs a Mac and a helper program installed outside the browser
- AI Slop Detector extension (github.com/Priyansurout/ai-slop-detector-extension, 0 stars at search time)
- picks text you select on a page, or pasted text
- model: âGoogle Gemma 270Mâ fine-tuned, about 150MB, runs â100% locally after initial model downloadâ on WebGPU
- result: AI-Generated, Human-Written, or Uncertain
- needs Chrome 113+ and a WebGPU GPU; first model load â2-5 minutesâ
- README gives no accuracy numbers
- TruthLens (github.com/mrtomdev/truthlens, 3 stars)
- text rules: sentence-length variance, common-word ratio, phrase fingerprints like âdelve intoâ and âtapestryâ
- also images (pixel statistics, known AI image CDNs) and audio
- âAll detection runs in your browser. Audio, images, and text are never uploadedâ
- authorâs limit: âThese are heuristics, not forensic proof. They produce false positives and false negativesâ
- AI Slop Blocker (Chrome store, 364 users, version 3.7.5, updated 2026-09-27)
- âHides AI-generated posts in your feed. Scoring runs on your deviceâ
- short posts caught by pattern; longer posts âscored by an on-device modelâ
- âCommunity sync is optional and shares only text hashes, not the text itselfâ
- a real use of the hash idea from the humanâs earlier note
- AI Text Detector (Chrome store, 5 users, v1.0.0)
- 8 hand-made signals: perplexity, burstiness, repetition, stylometry, probability skew, semantic drift, watermarking, buzzword density
- âAll analysis happens locallyâ; the page itself had no permissions list
- BladeRunner for web (SourceForge listing)
- âanalyzes page content on the fly, flagging suspicious snippetsâ with a confidence number each
- says it can be wrong both ways; no accuracy numbers
- GPTrue-or-False (github.com/thesofakillers/GPTrue-or-False, 112 stars)
- âdisplays the likelihood that selected portions of text were generated by GPT-2â
- the extension runs in the browser but calls OpenAIâs old detector on Hugging Face servers
- author note: âthis is a pretty old extension! Doesnât work very well anymoreâ
- shows the first generation of these tools: a text-selection extension calling a hosted model
- Mozilla Fakespot Deepfake Detector (OMG! Ubuntu, 2025-02 and 2025-06)
- highlighted text of 32 words or more
- used open models ApolloDFT, Binoculars, UAR, ZipPy; âMozillaâs proprietary ApolloDFT engine and a set of open-source detection modelsâ
- the launch article: âwill almost certainly flag AI text as human, and human effort as AIâ
- shut down 2025-06-26; the article gives no official reason, only that after Fakespot closed âthe writing was on the wallâ
- I could not open Mozillaâs own announcement
- the human can still use the idea: it is the closest thing to a free, multi-detector extension, and it is gone
- filters that hide, not label
- SlopScout, Slop Block: only seen as search-result descriptions, not opened
- could not open
- the GitHub topic page showed only two extension repos among 22 tagged ai-text-detector (truthlens and allentsangdev/ai-text-detector); I did not open the second
- waxy.org 2019 post about a Chrome and Firefox GPT-2 detector extension: the page gave almost no detail
images and provenance in the browser
- Digimarc C2PA Content Credentials extension, open source
- âOnce installed, it automatically checks for manifests attached to images on the browsed pagesâ
- shows a âCRâ pin on images that have a manifest; works on JPEG with C2PA manifests
- not a detector: it reads signed labels the maker attached, so it only helps if the generator signed the image
- digimarc.com blog, 2023
- DejAIvu (academic, below) is the research version for images
- Adobe Content Authenticity Chrome extension exists; I did not open its page
academic work
papers that build an extension, in-browser tool, or study one
- Aletheia
- Verify as You Go: An LLM-Powered Browser Extension for Fake News Detection, Sallami et al., arXiv, 2026
- Dorsaf Sallami and Esma AĂŻmeur, abstract: âExisting browser extensions often fall short due to opaque model behavior, limited explanatory support, and a lack of meaningful user engagementâ
- fake-news, not AI-text, detection; uses retrieval plus an LLM and gives evidence-based explanations
- âa complementary user study with 250 participants confirms the systemâs usability and perceived effectivenessâ
- a usability study, not a test of whether readers get more accurate
- rumour detection on Twitter
- Rumour Detection in the Wild: A Browser Extension for Twitter, Jovanovic and Ross, NLP-OSS 2023
- an academic extension with a server model and related-news suggestions
- checks rumours, rather than who composed the words
- authors, section 7: âWe asked 19 participants to perform five rumour detection tasksâ
- 78.95% found the extension useful
- small university recruitment sample
- reported usefulness does not establish improved judgment on ordinary browsing
- section 5 compares training on Twitter15, Twitter16, and a mixture
- accuracy drops when training and evaluation come from different datasets
- mixed training partly recovers performance
- section 6 measures response time on 50 tweets
- useful precedent for measuring extension delay separately from classifier accuracy
- authors, limitations: âthe current systemâs reliance on the Twitter API, and its changing access requirementsâ
- deployment depends on obtaining conversation replies
- inference: a detector study should test missing page context and service failures too
- DejAIvu
- DejAIvu: Identifying and Explaining AI Art on the Web in Real-Time with Saliency Maps, Dzuong, IJCAI 2025 demo track
- Chrome extension for AI-generated images; âONNX-optimized deep learning modelâ runs inside the extension, no server
- highlights the image regions that look artificial
- abstract claims âhigh accuracy and low latencyâ; the abstract page gave no numbers
- Trustnet
- A Browser Extension for in-place Signaling and Assessment of Misinformation, Jahanbakhsh and Karger, CHI 2024
- lets users judge content accuracy on any website and see trusted peopleâs judgments in the page
- âA two-week user study examined user perceptions, content preferences, and assessment reasoningâ
- closest academic match to the humanâs âspecific taggingâ idea; see crowd section
- Deep Breath, NudgeCred, TrustyTweet
- these came up in a search as misinformation extensions; I opened only the Deep Breath arXiv PDF and the fetch failed, so I report none of them
- LLM-DetectAIve, âDetecting LLM-Generated Tokens in Human-LLM Coauthored Textâ
- web demos, not extensions; seen only in search snippets, not opened
- finding: I found no paper that builds and tests a browser extension that detects AI-generated text on ordinary web pages
- I searched arXiv, Google, ACM, USENIX, CHI, CSCW wording variants (about 20 queries)
- search coverage limits: ACM DL and Google Scholar were not directly searchable with my tools
papers that run models inside the browser (the enabling tech)
- WebLLM
- WebLLM: A High-Performance In-Browser LLM Inference Engine, Ruan et al., arXiv, 2024
- âWebLLM can retain up to 80% native performance on the same deviceâ
- the paper reports 41.1 tokens per second for Llama 3.1 8B on an M3 Max MacBook Pro (from a search result summary, not verified in the paper)
- why it matters: Binoculars needs two 7B models running together, so a strong zero-shot detector in a browser is not obviously possible
- inference; nobody I found tested it
- the hobby extensions above (Gemma 270M, Deckard) are the only in-browser text detectors I found, none with a published test
how labels and warnings change what people believe or do
- the old base result
- The Implied Truth Effect: Attaching Warnings to a Subset of Fake News Headlines Increases Perceived Accuracy of Headlines Without Warnings, Pennycook et al., Management Science, 2020
- abstract: âfalse headlines that fail to get tagged are considered validated and thus are seen as more accurateâ
- the fix they found: tag some true stories too, âthis effect disappearedâ
- applies when readers cannot tell âuncheckedâ from âchecked and fineâ
- AI labels lower trust, even for true text
- People are skeptical of headlines labeled as AI-generated, even if true or human-made, because they assume full AI automation, Altay and Gilardi, PNAS Nexus, 2024
- 4,976 US and UK people; âlabeling headlines as AI-generated lowered their perceived accuracy and participantsâ willingness to share them, regardless of whether the headlines were true or false, and created by humans or AIâ
- effect about 2.66 points versus 9.33 points for a âfalseâ label, three times smaller (as reported by the fetch tool)
- reason found: readers assume no human was involved
- a label can backfire on false text
- Visible sources and invisible risks: exploring the impact of AI disclosure on perceived credibility of AI-generated content, Lin and Zhang, JCOM, 2026
- 433 people; âAI disclosure significantly reduced the perceived credibility of correct information while unexpectedly increasing the perceived credibility of misinformationâ
- they call it the âtruth-falsity crossover effectâ
- small, one genre (science posts), within-subjects; treat as a warning flag, not a settled result
- an AI label also lifts the unlabeled
- Implied Authenticity Effect? The Impact of Explicit Labels on AI-Generated Content, Pawelczyk et al., ICWSM 2026
- 877 Germans, Instagram-style posts; labels cut perceived authenticity of AI images by about 0.27 standard deviations
- âexposure to labeled content slightly increased perceived authenticity in unlabeled images (about one-fifth the size of the direct labeling effect)â
- images, not text; this is the implied truth effect applied to AI labels
- labels cut belief but not sharing
- Labeling AI-generated media online, Wittenberg et al., PNAS Nexus, 2025 (read from the authorsâ MIT PDF)
- 7,579 Americans, AI images; âall of the labels we tested significantly decreased participantsâ belief in the presented claimsâ
- âlabels that simply informed participants that content was generated using AI tended to have little impact on respondentsâ stated likelihood of engaging with their assigned postâ
- harm-style labels (âmisleadingâ) worked differently from process-style labels (âAI-generatedâ)
- label design
- Labeling Synthetic Content: User Perceptions of Warning Label Designs for AI-generated Content on Social Media, Gamage et al., CHI 2025 (arXiv preprint opened)
- 10 label designs, 911 people; labels changed belief that content was AI, trust in the label varied by design
- âlabels did not substantially affect engagement metrics (likes, comments, shares)â, per the fetch summary
- Examining the Impact of Label Detail and Content Stakes on User Perceptions of AI-Generated Images on Social Media, Chen et al., CSCW Companion, 2025
- 105 people; detail in the label raised felt transparency without cutting interaction; stakes mattered more than label detail
- a label that says how much AI was used
- AI labeling reduces the perceived accuracy of online content but has limited broader effects, Wang et al., arXiv, 2025
- 3,861 nationally representative people; âExplicit AI labeling of a news article about a proposed public policy reduces its perceived accuracyâ
- âIncreasing the salience of AI use reduces the negative impact of AI labeling on perceived accuracyâ
- Full Disclosure, Less Trust? How the Level of Detail about AI Use in News Writing Affects Readersâ Trust, Prajod et al., arXiv, 2026
- 40 people; trust âdeclined only with detailed disclosuresâ in questionnaires, while fact-checking behaviour rose with both minimal and detailed disclosures
- small study; shows the trade-off: more detail, less trust, more checking
- AI explanations next to a warning
- Reliability Matters: Exploring the Effect of AI Explanations on Misinformation Detection with a Warning, Seo et al., ICWSM 2024
- 2,692 people over 3 experiments; âthe AI systemâs reliability is critical for humansâ misinformation detectionâ
- adding explanations âmay heighten concerns about the system missing false claimsâ, and warnings without explanations drew more confidence (fetch summary)
- readers and detectors together
- Collaborative Evaluation of Deepfake Text with Deliberation-Enhancing Dialogue Systems, Lee et al., ICWSM 2026
- âgroup-based problem-solving significantly improves the accuracy of identifying machine-generated paragraphs compared to individual effortsâ
- People who frequently use ChatGPT for writing tasks are accurate and robust detectors of AI-generated text, Russell et al., ACL 2025
- âannotators who frequently use LLMs for writing tasks excel at detecting AI-generated text, even without any specialized trainingâ
- the labelling studies that the earlier note could not open
- Gamage (CHI 2025) is now opened via arXiv above
- Jung et al., CHI EA 2025, âAI-Generated or AI-Modified?â I still have not opened
crowd labeling: Community Notes, SponsorBlock, blocklists
- Community Notes does something, but mostly late
- Community notes reduce engagement with and diffusion of false information online, Slaughter et al., PNAS, 2025
- 40,078 posts; âreductions of 46.1% in reposts, 44.1% in likes, 21.9% in replies, and 13.5% in views after being attachedâ
- over the whole life of a post the drops are smaller: â11.6% fewer reposts, 13.3% fewer likesâ
- Did the Roll-Out of Community Notes Reduce Engagement With Misinformation on X/Twitter?, Chuai et al., CSCW, 2024
- âCommunity Notes might be too slow to effectively reduce engagement with misinformation in the early (and most viral) stage of diffusionâ
- the two disagree on the effect; speed is the shared worry
- so a crowd label for AI text, which would need to exist before the reader sees the page, faces the same lag
- LLMs writing the notes
- Scaling Human Judgment in Community Notes with LLMs, Li et al., arXiv, 2025
- âboth humans and language models generate Community Notes, with humans retaining evaluation authorityâ
- a browser overlay for any page
- Reading In-Between the Lines: An Analysis of Dissenter, Rye et al., IMC 2020
- the humanâs notes list Dissenter as an abandoned similar project; this is its measurement paper
- 1.68 million comments from 101,000 users on 588,000 URLs, Feb 2019 to Apr 2020
- it studied toxicity and bias, not label accuracy or whether comments changed how readers judged pages
- SponsorBlock
- I found no peer-reviewed paper about it
- its wiki âDataset Usesâ page names one student project, DeepSponsorBlock (Stanford CS 230, 2020), which guesses sponsor segments from video frames
- so the data is public and reused, yet its quality has not been published as a study (as far as I found)
- blocklists
- uBlockOrigin-HUGE-AI-Blocklist, laylavish, GitHub
- âA huge blocklist of manually curated sites (1000+) that contain AI generated content, for the purposes of cleaning image search enginesâ
- 5.8k stars, 972 commits; contributions by pull request or issue, then the maintainer reviews
- a separate ânuclearâ list holds sites with âa mix of authentic and AI generated imageryâ (DeviantArt, Artstation, stock photo sites)
- the README states no method for choosing sites and no error rate
- scope is image search results, not text
- the humanâs earlier ideas, and what the literature adds
- hash lookups for privacy: AI Slop Blocker shares âonly text hashes, not the text itselfâ; SkipSlop checks âcontent IDsâ against its database
- neither has been tested for whether hashes of text survive small edits
- specific tags instead of votes: Trustnet uses accurate, inaccurate, and question; its study is 2 weeks long
- spam and click farms: no paper I opened measures it for these tools
- SkipSlop has 44 users and one rating, so the community-powered idea has not yet been tried at scale
- hash lookups for privacy: AI Slop Blocker shares âonly text hashes, not the text itselfâ; SkipSlop checks âcontent IDsâ against its database
security and privacy: what extensions send away
- GenAI browser assistants send whole pages to their servers
- Big Help or Big Brother? Auditing Tracking, Profiling, and Personalization in Generative AI Assistants, Vekaria et al., USENIX Security 2025
- âinstead of relying on local in-browser models, these assistants largely depend on server-side APIs, which can be auto-invoked without explicit user interactionâ
- they âcollect and share webpage content, often the full HTML DOM and sometimes even the userâs form inputs, with their first-party serversâ
- arXiv abstract says ten extensions; the USENIX page says nine; I did not resolve which
- these are chat and summary assistants, not detectors
- inference: a detector in auto-scan mode has the same shape, a content script plus a server call
- a store-wide taint-tracking study of what extensions copy off pages
- Arcanum: Detecting and Evaluating the Privacy Risks of Browser Extensions on Web Pages and Web Content, Xie et al., USENIX Security 2024
- tested Chrome Web Store extensions on 7 sites (Amazon, Facebook, Gmail, Instagram, LinkedIn, Outlook, PayPal)
- âsignificant privacy risks across thousands of extensions, including hundreds of extensions automatically extracting user content from within web pages, impacting millions of usersâ
- the same 7 sites are where Pangram auto-scans feeds (LinkedIn) or where GPTZero works (Gmail); the paper does not name any detector extension
- extensions leak browsing data through third-party content
- Extended tracking powers: Measuring the privacy diffusion enabled by browser extensions, Starov and Nikiforakis, WWW 2017
- 10,000 popular Chrome extensions; âmany leak sensitive browsing informationâ
- a vendor study, not peer reviewed
- Incogni, 2025-02-06, reported by ITBrief: 238 AI Chrome extensions; âtwo-thirds of those analysed collect user dataâ; â41% collect personally identifiable informationâ
- another outlet I did not open reports a 442-extension version from 2026; the numbers differ, treat both as press-level
- what is missing for detectors
- the listed declarations (website content, personal communications) are what the store form says, not what the code does
- Pangramâs own page says it stores scanned feed text by default
research questions not resolved by the papers reviewed
- what text leaves the browser
- this review found no published traffic measurement for these seven detector extensions
- open question: does auto-scan send every post in a feed, including private ones on LinkedIn, X or Gmail?
- Arcanumâs taint tracker could run on exactly these
- what text gets picked
- the reviewed papers do not measure how page extraction changes detector scores
- minimum lengths differ: Mozillaâs detector 32 words, Winston 500 characters, Sapling free 2,000 characters per check
- label effects with real detector mistakes
- every label experiment I opened used a label placed by the experimenters on content whose truth the experimenters knew
- the reviewed studies do not evaluate live AI-text detector errors during browsing
- open: does a confident wrong âAIâ label on a human page, or a missed AI page, change what people decide
- the implied truth effect for text detectors
- Pennycook and Pawelczyk show spillover to unlabeled items
- the reviewed papers do not test spillover from missed AI-text labels
- the effect on the author whose page gets flagged
- the label studies reviewed here focus on readers rather than accused writers
- in-browser detection quality
- this review found no shared evaluation of these local tools against server detectors
- also open: can a Binoculars-style two-model scorer run in a browser at all
- a census of the extension ecosystem
- counts of AI-detector extensions, permissions, update dates, ownership; look-alikes such as the ZeroGPT.cc one; abandoned ones such as Hiveâs (last update 2025-01) and the shut-down Mozilla one
- crowd labels for AI content
- SkipSlop, AI Slop Blocker sync, and the HUGE list exist, but no accuracy check, no abuse study, no study of whether the labels help readers
- an idea for the human, as inference: the HUGE listâs 1000+ hand-picked sites could be scored with DeGenTWebâs site-level method to measure its precision
- speed of labels
- Community Notes studies suggest late labels do little; the reviewed AI-text studies do not measure whether labels arrive before readers act
Last edited: