NotBot
GuideAI detectionevidenceacademic integrityhearing

How to Gather Evidence When Accused of Using AI on an Essay

August 1, 2026  ·  7 min read

If you have been accused of using AI on an essay, the single most useful thing you can do in the first 48 hours is preserve evidence of how you wrote it. Detector scores are contested, but process evidence (drafts, version history, notes, browser records) is concrete and hard to argue with. The problem is that most of it can be overwritten, expired, or deleted quickly if you do not act fast.

Why process evidence matters more than the detector score

A detector score is a probabilistic classification. In case after case, what actually reverses an AI accusation is not an argument about the detector: it is a set of artifacts that show a human writing a document over time. Google Docs version history, Word autosave, browser search records, library checkouts, and handwritten notes all tell a story a probabilistic classifier cannot rebut.

Institutions vary in how much weight they give this evidence, but the pattern across documented dismissals is consistent: when a student produces a credible reconstruction of their process, cases tend to close. The UC Davis handwritten-draft case and the UCSB retraction after version history are two documented examples of the same dynamic.

Important
Do not edit, re-open, or "clean up" the flagged document. Every save can overwrite version history and change file metadata. Preserve first, argue second.

What to preserve in the first 48 hours

The order matters. Start with the evidence most likely to disappear: cloud version history that rolls off after a set retention period, browser history that clears automatically, and cached search results. Do the following in sequence:

  1. Stop editing the document. Do not open it to "look" at it. Every open can trigger an autosave that changes timestamps.
  2. Export a copy of the version history. In Google Docs, use File → Version history → See version history, then take dated screenshots of every named or timestamped version. In Word, check File → Info → Version History (Microsoft 365) or the AutoRecover folder for older versions.
  3. Download the file in its original format and as a PDF. Store both in a folder you will not modify.
  4. Export browser history for the drafting period. Chrome, Safari, and Firefox all allow this. Do it before the retention window closes (Chrome defaults to 90 days).
  5. Screenshot any research tabs, ChatGPT logs (if you used AI for permitted tasks like brainstorming), citation manager entries, and library database access logs.
  6. Photograph handwritten notes and annotated printouts with a clear timestamp on the phone photo.

Evidence by source: what each artifact actually proves

Not all process evidence is equally persuasive. A reviewer wants to see continuity: ideas showing up in notes, being drafted, being revised, and ending up in the final document. Here is what each common source demonstrates.

SourceWhat it provesHow to preserve it
Google Docs version historyIncremental editing over time, not a single pasteScreenshots of the version timeline; download of named revisions
Word AutoRecover / OneDrive versionsSame, for Microsoft workflowsExport each version file; screenshot the Version History panel
Browser historyResearch pattern consistent with the essay's sourcesExport as HTML/CSV before the retention window expires
Library database access logsYou accessed the sources you citedRequest a copy from the library or take screenshots of your database account
Handwritten notes, outlines, annotated readingsIdeas existed on paper before the document didTimestamped photos; keep the originals
Citation manager entries (Zotero, Mendeley, EndNote)Sources were collected and organized over timeExport the library with dated entries
Email or LMS submissions of earlier draftsThird-party timestamp on prior versionsSave the emails; download LMS submission receipts
Messages with classmates or tutors about the assignmentContemporaneous engagement with the topicScreenshot with dates visible

If you have no drafts or version history

Many students wrote directly into a single document without a Google or OneDrive account that preserves versions. This is common, and it is not fatal. Reviewers know that not every student uses cloud drafting. Focus on secondary evidence:

  • Browser history showing research on the essay's topics and sources
  • Library records showing you accessed the cited materials
  • Screenshots of any notes, outlines, or reading annotations, even informal ones
  • A written reconstruction of your process: when you started, where you worked, what you consulted, in what order
  • Offering to write a comparable piece under observation, which some instructors accept as informal proof

A written process narrative on its own is weaker than artifacts, but combined with even one piece of external evidence (a library log, a browser export, a photo of scratch notes) it becomes meaningfully harder to dismiss.

Tip
Write your process reconstruction before you read the full accusation letter's specifics. That way it reads as genuine recall, not as a response tailored to the allegations. Save it with a timestamp.

Chain of custody: how to store evidence so it holds up

A reviewer or hearing panel will take evidence more seriously if it looks preserved rather than manufactured. A few practical rules:

  • Put all evidence in one folder, organized by source, and do not modify the files after saving them.
  • Keep a plain-text index file listing each artifact, where it came from, and the date you preserved it.
  • Do not rename original exports. If you need a friendlier name for a submission copy, keep the original alongside it.
  • Where possible, send a copy of the evidence folder to yourself by email so there is a third-party timestamp on the collection date.
  • If you use Google Drive or OneDrive to store the folder, note that these systems record upload timestamps, which is useful.

What to submit, and when

Do not send everything you have. Send what directly rebuts the specific allegation. If the accusation is that the essay was generated in a single session, version history is the most relevant artifact. If the accusation is that sources were fabricated by AI, library records and citation manager exports are the strongest response. Match evidence to claim.

Attach evidence to your written response, not before it. A cover letter that walks the reviewer through what each artifact shows is more effective than a folder of files with no explanation. Our procedural rights FAQ covers what you can request from the institution (the detector name, the score, human review notes) that will help you know what evidence to prioritize.

If you are drafting the written response now, NotBot's defense package generates a personalized response letter, an evidence collection guide tailored to your writing tools, and a hearing preparation brief in about a minute. If you are past the initial finding and preparing an appeal, the appeal package is built around the procedural grounds that matter at that stage.

If the potential sanction is suspension, expulsion, or visa consequences, preserve everything now and consult an education law attorney before you submit anything. Evidence you fail to preserve cannot be recovered later, but evidence you submit prematurely can be used against you.

Build your defense package

A personalized response letter and evidence guide tailored to your writing tools, ready in minutes.

Get your defense package

$49 one-time · Generated in 60 seconds

Related articles