Not with certainty, and don't expect a provider to tell you. What you can do is collect three kinds of evidence. Tells in what comes back — odd phrasing, confident specifics you never wrote, and the best pointer of all: your own hidden decoy values appearing in their “summary”. Per-copy marks that say which copy travelled, so you talk to the right person. And a tripwire: a hidden reference link that can fire when an AI tool follows it. Read the evidence the right way round — a hit is a clear signal; silence is never proof that nothing happened — and when you have a signal, open a conversation, not an accusation.
Tells in what comes back
Usually the first clue is the document that lands in your inbox a week later — the “internal version”, the template for another region, the board summary that reads like your report with the edges sanded off. Worth noticing:
- Phrasing patterns. Even-length paragraphs, tidy three-item lists, a “key takeaways” block nobody asked for. Suggestive, never conclusive — plenty of humans write like that, and plenty of AI output is edited until it doesn't.
- Confident specifics you never wrote. A date, a figure, a source stated with certainty and absent from your file. Summarisers fill gaps; people paraphrasing your work usually keep your numbers.
- Your decoy values. If you cloaked the file before sending, it carries look-alike decoys beside every real figure, name, email and link — “$4.2 million” travels with “$3.7 million” and “$5.1 million” that a human reading normally in Word does not see. A value from the hidden decoys turning up in their output is a good pointer that the file was machine-extracted (or that someone was reading with hidden text switched on). A look-alike value can also be a coincidence, so check for several. It is not proof of who did it, or which tool, or whether it was deliberate — the file may have been forwarded first.
Keep a copy of exactly what you sent. Without the original, every tell is an argument about memory.
AI-detector tools for text
It is tempting to paste their document into an “AI detector” and get a score. Don't lean on it. These tools judge writing style, and style is a weak signal: careful, plain human prose regularly scores as machine-written, and lightly edited machine output regularly passes as human. They also say nothing about which file or copy was involved. A detector score is at most a reason to look more closely; it is never a reason to accuse a client, and it will not carry weight if the conversation turns formal.
Per-copy marks: knowing which copy travelled
Knowing that something happened is only half useful if three people received the report. Marking each copy tells you which one to ask about.
- Low-tech. Give every recipient a slightly different copy: a reference code or date in the footer, a different version label. Note who got which. Cheap, and it works as long as the differences survive whatever they do with the file.
- Sunda’s invisible per-copy mark. Every file Sunda Cloak cloaks carries an invisible mark made of zero-width characters, unique to that copy. Unlike the decoys, it is designed to survive a copy-paste of the visible text, so it can still say “this came from the copy sent to X” after the hidden decoys are gone. Attribution, not prevention — watermarking vs cloaking explains the difference.
An invisible mark can very occasionally shift a line or page break. Proofread the cloaked copy like any other deliverable before it goes out.
Tripwires: hearing about it at the time
A tripwire is the one piece of evidence that arrives on its own. Sunda Cloak’s tripwire is an opt-in switch in the popup (off by default). With it on, each cloaked copy carries one hidden reference link, unique to that copy. If an AI tool — or someone’s own software — actually fetches that link, the hit appears in the dashboard inside the popup. How to read it:
- It fires only if the link is followed. Many AI tools never follow links inside uploaded files, and pipelines change. We don’t claim any particular tool does or doesn’t.
- A hit is a clear signal; silence is no information. A quiet tripwire does not mean nobody looked.
- It records time, network address (IP) and user-agent. Not who, and not which AI product. It tells you something fetched the link in copy X at this time, and no more.
- Turn it on before you cloak, so the copy carries its own link.
What to do with a signal
- Gather, don’t react. Put the copy you sent, the output you received and any tripwire hit in one place. Note which copy it was.
- Check the contract. Does it say anything about AI reuse, derivative work or confidentiality? If it does, you have footing; if not, add a line for next time — see the AI-clause guide.
- Open a conversation, not an accusation. “It looks as though the report was put through an AI tool — can we talk about how you’d like to use it?” Assume they didn’t know it mattered to you, and offer a plain copy and a price as the way forward. You are deciding scope and money, not guilt — how to stop clients reusing your work with AI covers that.
- Set the norm for next time. Say up front that files are protected and offer a plain copy on request — Telling your client has the wording.
Any contract wording on this site is a starting point to review with a lawyer, never legal advice. How much weight a decoy match or a tripwire hit carries in a real dispute depends on your contract and your jurisdiction.
What this evidence can’t do
- None of it identifies a person or an AI product. At best it tells you a particular copy was machine-extracted, or that a particular link was fetched, and when.
- Copy-paste out of Word, screenshots, OCR and PDF export strip the hidden decoys and the tripwire link; those paths leave only the per-copy mark, and only if the visible text was copied.
- Hidden is not secret: a recipient who turns on “show hidden text” sees the decoys and the link and can delete them.
- The tripwire fires only when a tool actually follows the link; many never do, and pipelines change within months. Silence proves nothing.
- AI-detector scores are unreliable and produce false positives; never accuse on their say-so.
- Cloaking, marks and tripwires are a deterrent, not a guarantee, and never a substitute for a contract.
Frequently asked
Not reliably. Text-based AI detectors score style, and plenty of careful human writing scores as machine-written while lightly edited machine output passes as human. They produce false positives, give no indication of which file or which copy was used, and are not something to accuse a client on. Treat a detector score as a prompt to look closer, never as evidence.
Don't expect it. There is no lookup an outsider can run against someone else's account; uploads are treated as the account holder's data. Data-handling policies differ by plan and change over time — check the provider's current data-controls page if you are curious what it keeps — but none of that gives you visibility into another person's account. Any signal has to come from the file itself.
When it fires, it records the time, the network address (IP) of whatever fetched the link, and the user-agent string it sent. That is all. It does not record who opened the file or which AI product was used, and it fires only if a tool actually follows the hidden reference link — many AI tools never follow links inside uploaded files. The dashboard in the extension popup shows hits per cloaked copy.
It is a good pointer that your cloaked file was machine-extracted (or that someone was reading with hidden text switched on), because those values live in the hidden decoys that a human reading normally in Word does not see. A look-alike value can also be a coincidence, so check for several. It is not proof of who did it, which tool was used, or whether it was deliberate — the file may have been forwarded. Handle it as a conversation opener, check what your contract says, and keep the original file and their output side by side.