One Weird Trick for Opting Out of Pangram on Substack
I explain why the AI slop detector potentially violates Article 22 GDPR, and what you can (possibly) do about it if you're in the EU/UK.
So, I initially wasn’t going to weigh in on the Pangram announcement posted by Substack’s CEO Chris Best on Wednesday, because 1) everyone is talking about it, and 2) I didn’t have much to add.
If you have no idea what I’m talking about, the Tl;Dr is that Substack has now integrated Pangram’s AI-detection software directly into the Substack App. Now, if you ever want to tell if a post, note, reply, or comment is AI-generated, you can click a button and receive an automated assessment of human-ness vs. AI assistance.
Chris spent the majority of his post explaining why, and if you haven’t read it, it’s worth a skim.
As I said, many people weighed in, and the comments were almost uniformly negative. Maybe that’s just unique to my feed, but the general vibe I got was that everybody hates this, for about 50 different reasons.
As I read through though, my brain began vibrating in that way it does when I pattern-match ‘stupid business idea’ with ‘probably violates a law somewhere’. In this case, potentially two laws, at least over here in the EU.
Below, I’m going to briefly discuss them, and provide a quick suggestion on what you might be able to do if you are blessed to be located in a jurisdiction with actual privacy laws!
The Article 21 & 22 landmine
Some jurisdictions, notably the EU and UK, have rules around automated decision-making and profiling. Under the EU GDPR, for example, people (aka, ‘data subjects’) have a right
not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
To comply with Article 22, entities (referred to as ‘controllers’ in GDPR-speak) who use automated tools, e.g., AI detectors, to make decisions about people, must do a few things, unless an exception applies. Specifically, they must:
implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.
Article 21 of the GDPR also gives data subjects a right to object to processing, including profiling, where that processing is based on the controller’s legitimate interests—which is a fancy way of saying ‘where the controller might have a legitimate business need to process data in a certain way.’
Now, let’s look at Substack’s privacy policy notice. This is from May 2026, so it doesn’t mention the Pangram use-case, but based on my expert deductive processes,1 I think Substack’s lawyers would likely bucket AI detection into the legitimate interest category:
In particular, where we process your Personal Information on the basis of our legitimate interests — including where we profile you in order to personalise content recommendations — you have the right to object to such processing at any time on grounds relating to your particular situation. We will cease such processing unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims. To exercise this right, please contact us at privacy@substackinc.com.
In plain English: unless Substack can demonstrate and provide evidence that their legitimate business interests override our data protection rights to be free of profiling and automated decision-making, they need to stop using Pangram, at least on posts where an EU/UK data subject has objected.
Similarly significant effects
You might be asking (and the Substack team might be asking their lawyers right about now), whether or how Pangram’s AI detection produces ‘legal effects’ or ‘similarly significantly affects’ a creator.
Some of this depends on what Substack does with this tool. If, for example, Substack uses Pangram to shadow-ban, down-rank or otherwise penalize creators by surfacing their content less based on Pangram’s AI detection, this could have measurable economic consequences (thus, a ‘similarly significant affect’) on creator incomes. Given that Pangram still gets a false positive 1 out of every 10,000 analyzed posts (and as JHong notes, that’s in controlled lab conditions!), if there are say, 2 million posts a week, that’s 20,000 cases where someone’s content is labeled 100% AI-generated.
But there’s also what everyone else will do. We humans tend to be bad at applying judgment and healthy skepticism in the face of convincing evidence. Sure, we tell ourselves that the computer can be wrong, and that we’re critical thinkers and will apply our own reasoned judgment. The computer isn’t the boss of me, we tell ourselves. but that’s System 2 thinking. Automation bias, and automation-induced complacency (insufficient attention or monitoring of AI outputs deemed to be reliable) affect us all.
In practice, people will click ‘Scan for AI text’, Pangram will do it’s thing, and readers will make inferences based on those automated results. Not just of my writing, but also my behavior, reliability, and worthiness as a writer. This is the very definition of profiling under the GDPR.
The reality is that the people who are likely to end up suffering the most aren’t the AI slop peddlers. It’s the people who, for whatever reason, use AI as an assist, not a brain replacement. The non-native speaker. The person trying to find their voice, or communicate difficult or complex ideas into accessible language. Neurodivergent people. The poor bastards who actually kinda write like they’re AI already.2 But these are the very people who will most likely end up tagged by Pangram as creating AI-generated content, even when the substance and ideas are their own.
If Substack becomes a place where everyone can casually cast aspersions against one another, based on what Pangram says is the truth, this will also have significant and chilling effects on speech. This may be harder to prove in a court of law, but deeply impactful all the same.
Does Substack have a legitimate interest?
Now, Substack will reasonably counter that what they’re doing serves legitimate business interests:
When content made by no one takes over parts of the internet that are supposed to be human, it pollutes the commons and makes it hard to discover and hear human voices. When readers have to wonder if what they’re reading is real, it undermines trust in authorship and threatens the livelihood of writers—including those who use AI tools thoughtfully to produce work they believe in. Platforms that reward fakeness will create a race to the bottom. …
But one thing we do know is that we don’t want to wait until your Substack app turns into LinkedIn before we start to learn and make progress. So to start, we’re launching some new tools that we hope will increase transparency and give us a basis to ask for your feedback.
I agree with Chris on one thing—I also don’t want Substack to turn into LinkedIn. The company isn’t wrong, but that doesn’t make the approach they’re taking here the right one. Means, ends, etc.
Yes, Pangram will be useful for detecting AI slop and LinkedIn-style spam, and that may be a valid reason for enabling it. But this concern doesn’t override the harms that using Pangram indiscriminately, and very publicly, will impose on people, disproportionately, without their consent, and absent any suitable measures to safeguard the creator’s own rights, freedoms, and legitimate interests.
Dear Substack: I object!
Remember how I mentioned the right to object (Article 21 GDPR) above? Well, I plan to exercise that right. Here’s a template you can use—Don’t send this verbatim. There are a number of sections you’ll need to customize, which I’ve highlighted below.
From: [Your full name] [Your Substack publication name and URL] [Email address associated with your Substack account]
To: privacy@substackinc.com CC: Bird & Bird GDPR Representative Services (EU Representative of Substack Inc. under Article 27 GDPR), Zuid-Hollandplein 22, 2596 AW The Hague, Netherlands (EUrepresentative.Substack@twobirds.com)
Date: [Date]
Subject: Objection under Article 21(1) GDPR to processing of my personal data via AI-detection scanning (Pangram), and request for information under Articles 13–15 GDPR
Dear Substack privacy team,
I am a Substack writer residing in the European Union. I write to (1) object under Article 21(1) GDPR to your processing of my personal data through the “Scan for AI text” feature powered by Pangram, (2) require you to demonstrate the compelling legitimate grounds and balancing assessment on which this processing relies, and (3) request specific information about automated decision-making connected to this feature.
As Substack offers its services to individuals in the EU and monitors their behavior within the EU, this processing falls within the territorial scope of the GDPR under Article 3(2), as reflected by your designation of an EU representative under Article 27.
1. The processing I am objecting to
On or around 21 July 2026, Substack enabled a feature allowing any reader to run an AI-detection scan, powered by Pangram, against posts, notes, and comments I publish. The scan produces and displays a percentage assessment of whether my writing is human-authored or AI-generated.
This is processing of my personal data. The content I publish under my name is personal data relating to me (Article 4(1)), and the Pangram output is a further item of personal data: an inference about my conduct, working methods, and authorship, generated and displayed to third parties. Because the feature uses automated processing to evaluate personal aspects of my behavior and reliability as a writer, it constitutes profiling within the meaning of Article 4(4).
This processing was enabled by default, without my consent, and without any prior, specific notice to me as required by Articles 13(3) and 14. I was not informed of my right to object “explicitly and separately from any other information” as Article 21(4) requires. Although not explicitly mentioned in the privacy notice, as I understand it, Substack is relying on legitimate interests (Article 6(1)(f)) for this processing; if you rely on a different legal basis, identify it precisely in your response, per Article 13(1)(c).
2. Objection under Article 21(1)
I object to this processing, including the profiling it involves, on grounds relating to my particular situation, including:
[Reputational and economic harm: My writing is my livelihood / a significant source of income. An erroneous “AI-generated” score displayed to my readers and prospective subscribers directly damages my professional reputation and income, with no meaningful way for me to correct the public impression it creates.]
[Known unreliability of AI detectors: AI-detection tools produce false positives at material rates, and published research shows they disproportionately misclassify text by non-native English speakers, neurodivergent writers, and writers with formal or formulaic styles. Describe here if any of these apply to you.]
[Chilling effect on expression: The prospect of being publicly scored on every post, note, and comment alters what and how I write, interfering with my freedom of expression under Article 11 of the Charter of Fundamental Rights.]
[Penalty for exercising controls: Disabling detection on a post causes readers to be shown an “AI detection unavailable” notice — a conspicuous signal that itself invites suspicion. I should not suffer a detriment for exercising a data protection control.]
[Add your own particular circumstances.]
Under Article 21(1), upon receipt of this objection you must cease this processing of my personal data — including scanning my content, generating AI-likelihood scores about my writing, and displaying such scores — unless you demonstrate compelling legitimate grounds for the processing which override my interests, rights and freedoms. A generalized interest in “trust” or “transparency” or avoiding the platform turning into LinkedIn is not, without more, a compelling ground that overrides the specific harms identified above.
Pending resolution of this objection, I also request restriction of processing under Article 18(1)(d): suspend all scanning and display of AI-detection results on my content until you have verified whether your grounds override mine.
3. Disclosure of your legitimate interests assessment
Since you rely on Article 6(1)(f) GDPR, you were required to identify the legitimate interest pursued, establish that the processing is necessary for that interest, and balance it against the interests, rights, and freedoms of the data subjects concerned. As your current notice (last updated: May 14, 2026) does not mention Pangram or your lawful basis for this processing activity, I request the following:
The legitimate interests assessment (LIA/balancing test) conducted for the Pangram integration, or a meaningful summary of it, including the date it was completed and whether it was completed before the 21 July 2026 launch.
Your analysis of necessity, specifically: why default-on, reader-triggered scanning of all eligible content was necessary, and which less intrusive alternatives you considered and rejected—for example: an opt-in model for writers; voluntary self-disclosure (which you already offer via “How I make this” statements); provenance metadata; or complaint-driven review of suspected inauthentic content. AI-detection scanning is plainly not essential to operating a publishing platform, so I expect this analysis to be substantive.
How the default-on design is compatible with data protection by design and by default under Article 25.
Whether a data protection impact assessment under Article 35 was carried out, as this feature involves novel, highly-contested technology and systematic, large-scale evaluation of personal aspects of individuals. If no DPIA was undertaken, please explain why Substack felt this was not required.
4. Automated decision-making and the use of Pangram results
Substack has stated publicly that the tool is “not designed to prohibit or penalize AI-assisted writing.” That statement addresses design intent, not actual or planned use. Under Articles 13(2)(f), 14(2)(g), and 15(1)(h), I am entitled to know about the existence of automated decision-making, including profiling, and to meaningful information about the logic involved and the significance and envisaged consequences of such processing for me. Please answer specifically:
Are Pangram scores or derived signals used now or under any current plan as an input to content ranking, recommendations, feed placement, or search visibility (including downranking or reduced distribution of flagged content or flagged authors)?
Are they used in monetization decisions: eligibility for or removal from monetization features, payment processing, revenue shares, or promotional programs?
Are they used in moderation, enforcement, or account-level actions, including any cumulative “repeat flag” scoring of authors?
Are any such decisions taken solely by automated means, or is there a meaningful human review process in place?
Describe the safeguards in place under Article 22(3), including the right to obtain human intervention, express my point of view, and contest the decision.
I reserve my position under Article 22 pending your answers. If visibility of my content is restricted on the basis of these scores, I also draw your attention to the statement-of-reasons obligation under Article 17 of Regulation (EU) 2022/2065 (Digital Services Act).
5. Accuracy, human oversight, and controls
The accuracy principle (Article 5(1)(d)) applies to the inferences you generate about me, not only to the data I supply. Please provide details on the following:
Any pre-release testing that measured the false positive rate of the Pangram classifier on Substack content, including performance for non-native English speakers and across languages, and any validation or bias testing you performed before launch. Note: I am not asking for Pangram’s published results.
What human review exists at any point: is any human involved before a score is displayed to readers, or is the “Report detection error” button the only recourse? Describe the process, timelines, and outcomes when a writer reports an error, and how a correction is communicated to readers who already saw the erroneous score.
What controls are or will be available to writers? Specifically, whether a global, account- or publication-level opt-out exists, or will exist at a future date. My understanding is that it does not, and that detection must be disabled post-by-post after first running a scan and sharing my content with Pangram.
Why opting out results in an “AI detection unavailable” notice being displayed to readers rather than a neutral absence of the feature.
Whether scans are performed on demand only or content is pre-scanned; how long scan results and scores are retained; whether Substack or Pangram use the content for model training or further processing purposes, and whether the results are stored in, or linked to my account.
6. Pangram Labs: processor, transfers, and further use
Confirm the role of Pangram Labs, Inc. in this processing (processor under Article 28 or independent controller) and that a compliant data processing agreement is in place.
Identify the transfer mechanism under Chapter V relied on for transfers of EU users’ data to the United States in connection with this feature.
Confirm whether my content or scan results are used to train, improve, or evaluate Pangram’s models, and if so, on what legal basis; I object to that processing on the same grounds as above.
7. Response
Please respond within one month of receipt as required by Article 12(3). If you reject my objection, you must specify the compelling legitimate grounds you claim override my interests, rights, and freedoms.
If I do not receive a satisfactory response, I will lodge a complaint with [your relevant EU supervisory authority]. For reference, as Substack Inc. has no establishment in the Union, the one-stop-shop mechanism does not apply.
Sincerely,
[Full name] [Substack publication URL] [Country of residence]
Note for users of this template: this is a template for exercising your own GDPR rights and is not legal advice. UK writers: the UK GDPR contains equivalent provisions (Articles 21, 22, etc.); address your letter to the UK representative listed above and refer to the ICO instead of an EU supervisory authority.
There may be similar rights in your jurisdiction, but this form template is only applicable to the EU/UK. Sorry :(
Of the six lawful bases available, there are only three viable options that Substack has at its disposal for this case: a) user consent; b) performance of a contract; or c) legitimate interests. Since nobody consented to this before they rolled it out, and it’s clear that Pangram AI detection is not necessary to use the platform (as evidenced by the fact that it was not a thing prior to July 21), that leaves legitimate interests.
This is the modern-day version of the guy or gal with that really annoying laugh that everyone hates. It’s not their fault that they have a hideous laugh, but that also doesn’t make the laugh less annoying.



