2 September 2026 · one URL, sourced, not polite

You now prove you’re human to a model trained on the books the labs ate

Here is the new homework. You wrote the essay. You did not open ChatGPT. The TA, the agent, the acquisitions editor still might paste it into Pangram, because Pangram is what schools and publishers bought, and a yellow highlight is cheaper than reading. So you open Pangram yourself first. You pay them a dollar a hundred words to find out whether you still look like a person.

If that sounds like a protection racket, wait until you see who trained the bouncer and who paid for the door.

They already published the recipe. People just didn’t read it.

Pangram is not a mysterious oracle. Bradley Emi and Max Spero wrote it down. Twice. arXiv 2402.14873, then Pangram 4 as 2607.27183. Spero said the same thing to TechCrunch the morning the $9 million landed.

Take a human document. Prompt several large language models to write the same topic at the same length. Sometimes start the model on the human’s first sentences so it has to impersonate the page. Train a classifier on the pair. They call the AI side a synthetic mirror.

We prompt an LLM by requesting a document on the same topic, of the same length. For a fraction of examples, we have the LLM start with the first sentence of the human document.

That is not “detect AI.” That is this book versus Claude doing this book. Pangram 4 still uses the mirrors, then adds token labels and “75 of the most popular models, including all presently available OpenAI and Anthropic models.” The detector is a student of the same labs that ate the libraries.

When naive training saturates, they hunt. Scan the leftover millions of human docs. Keep the ones the current model already calls AI. Mirror those. Retrain. Algorithm 1, “hard negative mining with synthetic mirrors.” The hard class is not a fake AI novel from a Kaggle dump. The hard class is a living human the referee already wanted to eject.

Seven million book examples. No bibliography.

Table 5 of the 2024 paper is the tell. About 28 million “confirmed human” documents, 2021 and earlier, “licensed for commercial use.” One row is not a rounding error.

DomainExamples
Reviews15,000,000
Books7,000,000
Scientific papers3,000,000
Wikipedia1,000,000
Student writing23,000
ESL165,000

They evaluate the books domain on Project Gutenberg. They do not name the catalog behind the seven million training rows.

Gutenberg, sliced into chapters, can get you into the millions. So can Books3. So can LibGen. So can Anna’s Archive. Those corpora share a grotesque amount of the same dead authors. Overlap is free. A receipt is not.

Pangram’s lawyers wrote the safe sentence: owned, commercially licensed, or openly licensed; no “unauthorized internet crawls.” Fine. Publish the bibliography. Until they do, the industry pattern is sitting there in the room: every lab that mattered had the dump, nobody wanted to say the filename, and a detector trained on “book versus LLM rewrite of book” is exactly what you build if that dump is already on a disk.

I will not write “Pangram torrented 81 terabytes.” That number is Meta’s, from the Kadrey filings, via Anna’s Archive. Anthropic has its own LibGen / PiLiMi story in Bartz. Pangram has a press release. Those are different objects. The method does not care. The method is the dump-shaped idea whether the files came from a librarian or a swarm.

The same firm got paid on the way in and the way out

29 July 2026: Pangram 4 ships. $9 million led by Menlo Ventures. Haystack, ScOp, Script, Cadenza. Total raised about $13 million. TechCrunch did the morning-of.

Menlo is not a random seed check. Anthropic was the firm’s bet-the-firm AI position: Series C in 2023, lead on the 2024 Series D, still on the cap table through E and F. That is the lab a federal judge said built a central library in part from torrented books, even while calling the training itself transformative. Meta’s authors got the 81.7 TB quote. The books left the building. The models shipped. The referee needed a Series A.

So the same class of capital that got paid if Claude swallowed the 20th century is now paid if a detector grades the wreckage. Nobody had to send a memo. The incentive is the term sheet.

Spero told TechCrunch the product is for people who want to know whether they should “jump in skeptically.” The API customers he named are Quora, schools, universities, publishers, agents, recruiters. Substack wired it in so readers can see which newsletter is a model. The Chrome extension grades your feed. The future he wants, in his words: “If we do not actively discriminate in favor of human content, then we’re just gonna see more and more AI.”

Discriminate in favor of human content. Then sell the human a scan, because the human now looks a little too even, a little too 2024, a little too much like the mirror you trained on.

1925 is human. 2026 is a suspect.

A detector trained on “pre-ChatGPT book / student / review prose” versus “75 models rewriting that prose” is not asking whether you sat at the keyboard. It is asking which 512-token window you resemble. Clean professional English after 2022 lives next to the rewrite. A Hemingway sentence from 1925 lives in the human bin. That is not a vibe. That is what the loss function was fed.

We scored our own text on the Pangram 4.0 dashboard on 2 September 2026. Leftover-free unused Gutenberg sentences, about a thousand words, fourteen writing types: entire-text Human, 14 for 14, once we stopped inserting generated asides. The same original story rewritten by Llama 3.3 70B, Qwen 2.5 72B, and Grok 4.5: 100% AI, every time. Celebrity “write like Baldwin” prompts did not matter. Pasting modern product names onto Gutenberg stems did not flip the document. The book rhythm stayed Human. The instruct-model cadence did not.

Their 2024 paper says hard-negative mining dropped book-domain holdout false positives to 0.01% — one in 10,000. Spero repeated the order of magnitude for Pangram 4. Teachers still treat a highlight like a body camera. One in 10,000 is a rounding error until it is your chapter, or your kid’s scholarship essay, or the only draft an agent will open this month.

Students are already in the published evals. PERSUADE. ELLIPSE. PELIC. ICNALE. Twenty-three thousand student documents in the 2024 pool. The people with the least power are both the training data and the customer.

Name the seven million rows

You can assume they used the same shadow library everyone else had. I do, privately. I will not print it as a fact. Gutenberg is enough to explain why our public-domain collages look “human.” A living undergraduate essay is the control that matters, and we have not spent those credits yet. If PERSUADE scores Human, the detector can see a person who is still alive. If it scores AI, the “one in 10,000” story and the inbox full of kids checking themselves are the same object.

What would end the dump argument in a thread is a bibliography. Seven million book examples. Names, licenses, years. If it is Gutenberg and a licensed catalog, say so. If it is something you would not put on a slide for Congress, that is the frown. The frown is the point. The frown is why nobody says the filename, and why the people who still write are the ones buying the alibi.

First the books train the generators. Then the books-versus-generators train the referee. Then you paste your own work into the referee so a stranger with a budget will not throw you out. That is the double collection. The torrent is the rumor. The papers, the cap table, and the homework are not.

The four-part series: the cleanup crew, the office IP, the writer tax, Claude’s watermark. Dry notes: how Pangram trains.

Sources: arXiv 2402.14873 (Table 5, Algorithm 1, §4.2); arXiv 2607.27183; Pangram, Feb 2024; Pangram 4 model card; TechCrunch, 29 Jul 2026; TechCrunch on Menlo / Anthropic; TorrentFreak / Kadrey; Bartz v. Anthropic.