it's interesting how in security, the attacker almost always moves second, and thus have an advantage by adapting the attack to a given system.
in detecting AI-generated text, however, the *defender* moves second! i.e., even if the attacker bypasses all current AI detectors, the next version of, say, Pangram will almost surely be trained with texts from new LLMs, new humanizers, etc.
this enables post-hoc detection: if you used AI to generate/edit, say, a paper, it will be sooner or later known. intuitively, this gives defenders a solid chance!