# A $2M Book Deal, an AI Detector, and the Real Way to Prove Something Is Authentic

> A $2M book deal was pulled after an AI detector flagged the manuscript. It's a lesson in why a single AI-probability score isn't proof - and what verifying authenticity actually takes in 2026.

*Published 2026-08-05 · 8 min read · TamperCheck.ai*

Canonical: https://tampercheck.ai/blog/how-to-prove-a-document-is-authentic

---
A debut crime novelist's **$2 million book deal** - won in a 14-way auction - was withdrawn by his own agents after an editor's concern led them to run the manuscript through an AI-detection tool. The author disputes the finding, has taken legal advice, and points to earlier drafts of the book plus concerns about bias in how the suspicion was raised ([as reported](https://post.substack.com/p/an-authors-2-million-book-deal-was)).

We're not here to decide whether that manuscript was written by a human. We can't, and neither, with certainty, could the tool. That's exactly the point. Strip away the specifics and this story is about a question every business now faces in some form: **when the stakes are high, how do you actually prove something is authentic - rather than just act on a machine's guess?**

> **INFO:** A note on scope: this post is about the *principle* of verifying authenticity. Detecting AI-written prose (what happened above) is a genuinely hard, error-prone problem. Verifying documents - statements, IDs, receipts - is a different and far more tractable one, for reasons we'll get to. We'll be clear about which is which.

## The trap: mistaking a score for proof

An AI detector returns a number - "97% likely AI." It feels authoritative. But a probability is not evidence. It's an opinion with a confidence interval, and it can be wrong in both directions:

- **False positives** wrongly flag genuine work. Text detectors are notorious for it, and the harm isn't evenly distributed - they've been shown to misfire more often on non-native English writing, which is why bias concerns follow them everywhere.
- **False negatives** wave through the real fakes, because whoever made them optimised specifically to beat the detector.

When you hang a life-changing decision - a book deal, a loan, a job, an insurance payout - on a single opaque number, you inherit both failure modes at once. You accuse the innocent *and* you miss the guilty. The number gave you confidence, not correctness.

> **WARNING:** The problem isn't that detection tools exist. It's using one score, in isolation, with no evidence behind it, as if it settled the question. A score should *start* an investigation, not end one.

## The better question

"Is this AI?" is the wrong question for a high-stakes decision, because it demands a yes/no from a tool that can only offer a maybe.

The better question is: **"What's the evidence, and can a person check it?"**

That reframing changes everything. Instead of one probability, you gather independent signals, each of which points to something concrete a human can verify. No single signal decides the case; together they build - or fail to build - a defensible conclusion. That's how forensics has always worked, and it's the opposite of "trust the score."

## What proving authenticity actually looks like in 2026

Authenticity shows up in three very different arenas, and they're not equally solvable.

### Writing: provenance beats detection

For prose, the detectors are the weak link. The strong evidence is **provenance** - the trail of how the work came to exist. Draft history, version timestamps, research notes, the messy human record of revision. Notably, the author in the book-deal story reached for exactly this: he pointed to drafts predating the tools he's accused of using. A document's *history* is far harder to fake than its surface, which is why provenance, not a detector's verdict, is the real proof.

### Identity documents: forensics, not vibes

A passport or driver's licence can't be judged authentic by how confident a model feels about it. It's judged on physical and structural signals - security features, the machine-readable zone, generation artefacts, internal consistency. This is a domain where evidence is concrete and checkable, and where AI-generated fakes leave signatures the eye misses. (More on that in [deepfake document fraud in KYC](https://tampercheck.ai/blog/deepfake-document-fraud-kyc) and [fake passport detection](https://tampercheck.ai/blog/fake-passport-detection-forensic-signals).)

### Financial documents: structure tells the truth

A bank statement, payslip, or receipt carries something a novel doesn't: **structure**. Balances must reconcile, totals must add up, metadata must match the claimed source, and the pixels must look captured rather than generated. Those are testable facts, not impressions - which is why a fabricated statement or an [AI-generated receipt](https://tampercheck.ai/blog/how-to-spot-ai-generated-fake-receipts) can look flawless and still fail on evidence.

> **TIP:** This is why documents are more tractable than prose. A page of writing is just words - there's nothing underneath to check. A document has structure, arithmetic, metadata, and a capture history, all of which either hold together or don't. Verification has something to grip.

## The principle that unifies them

Across all three arenas, responsible authenticity verification looks the same, and it's the exact opposite of a black-box score:

- **Multiple independent signals**, not one number.
- **Each finding tied to concrete evidence** a human can inspect - "this balance doesn't reconcile," not "risk: 0.82."
- **A human in the loop** on anything consequential, with enough context to overrule the machine.
- **A durable, reviewable record** of what was checked and why.

If that list sounds familiar, it's because it's also what regulators are now demanding. The EU AI Act's high-risk rules - live since August 2026 - require exactly this kind of explainable, logged, human-supervised decision-making for identity verification, credit, and insurance. A single opaque score doesn't just risk being wrong; it's increasingly hard to defend. (We covered that in [what the EU AI Act means for document verification](https://tampercheck.ai/blog/eu-ai-act-document-verification-high-risk).)

This is the honest place to say what TamperCheck does and doesn't do. We don't judge whether a novel was written by a human - that's the fragile, bias-prone problem the book-deal story is stuck in. We verify **documents and images**: whether a statement, ID, or receipt was authentically produced or tampered with, forged, or AI-generated. We do it the forensic way - many signals, plain-English findings tied to specific regions of the document, built to be reviewed rather than blindly trusted. It's [document fraud detection](https://tampercheck.ai/blog/document-tampering-detection-vs-ocr), not a verdict on someone's writing.

**See evidence, not just a score** — Upload a document and get plain-English forensic findings tied to what's actually on the page - the kind of evidence you can stand behind. $5 in free credits. (https://tampercheck.ai)

## The takeaway

The book-deal story will resolve however it resolves. But the lesson for anyone making authenticity decisions at scale is already clear: **don't let a probability masquerade as proof.** A score can point you somewhere worth looking. It can't stand in for the evidence, the human judgment, and the record that a fair, defensible decision requires - whether you're a publisher, a lender, or an onboarding team.

Ask for the evidence. Make sure a person can check it. That's the difference between a guess and a decision you can defend.

## FAQ

### How do you prove a document is authentic?

Not with a single AI-probability score. You gather independent, checkable signals: provenance and capture history, structural and metadata consistency, arithmetic that reconciles, and generation artefacts - each tied to concrete evidence a human can inspect. Authenticity is established by evidence that holds together, not by how confident one detector feels.

### Are AI content detectors reliable?

For text, not reliably enough to base a high-stakes decision on alone. They're probabilistic, can be beaten by anyone optimising against them, and produce false positives - with documented bias against non-native English writing. Treat a detector's score as a prompt to investigate, never as proof on its own.

### Why are documents easier to verify than AI-written text?

Because documents have structure to check. A bank statement has balances that must reconcile, metadata that must match its source, and pixels that were either captured or generated. A page of prose is just words, with nothing underneath to test. Forensic verification needs something concrete to grip, and documents provide it.

### What's wrong with using a risk score to make decisions?

Nothing, as a starting point. The problem is treating one opaque score as the decision. It offers confidence without evidence, so you can't explain or defend the outcome - and you inherit both false positives (accusing the innocent) and false negatives (missing real fakes). Regulations like the EU AI Act now expect explainable, human-supervised decisions instead.

### Does TamperCheck detect AI-written text like a novel?

No. TamperCheck verifies documents and images - bank statements, IDs, payslips, receipts - for tampering, forgery, and AI generation, using forensic signals you can inspect. Judging whether prose was written by a human is a separate and far less reliable problem, and not one we claim to solve.
