Ask people whether they can spot an AI comment in a feed and most say yes without hesitating. Then you test them, and the confidence turns out to be the least accurate thing in the room.
That’s roughly what a recent experiment found. In a timed study built with master’s students from Malmö University and covered by TechRadar, 710 participants were dropped into a simulated comment section and given two minutes to flag the bot-written comments. Only 53% identified more bots than they wrongly accused humans of being. Nearly half failed outright. This piece covers what the experiment revealed about who gets fooled and when, why emotion turned out to matter more than reading skill, where bot contact actually turns into a loss, and what helps once you accept that spotting them isn’t a plan.
|
47%
of participants failed the bot-detection test outright
|
23%
of political discourse on X during election seasons is attributed to bot-driven amplification
|
|
6.3bn
fake accounts removed by major platforms each year, roughly 47 times the number of babies born worldwide
|
42%
detection rate among players aged 41 to 50, against 65% for those under 20
|
What the experiment measured
Two separate skills sit inside “can you spot a bot,” and the study tracked them apart from each other, which is where the interesting part starts.
The first is detection: how many actual bots you catch. The second is accuracy: how often you’re right when you call something a bot. A low accuracy score means you’re flagging real people, which carries its own cost on platforms where users report and pile onto accounts they suspect. Across the full 710-player sample, average detection landed at 58% and average accuracy at 66%, so the typical participant missed four bots in ten and was wrong about a third of their accusations.
The cliff at 40
Age turned out to be one of the sharpest dividing lines in the data. Players under 20 caught nearly 65% of bots with accuracy above 71%, the strongest result of any age group. Performance held roughly steady through the 20s and 30s, then dropped hard: the 41 to 50 bracket caught just 42% of bots with 59% accuracy, and players over 50 did only marginally better. Older participants weren’t only missing more bots, they were also more likely to wrongly accuse real people.
Your main platform shows in the score
The researchers also asked participants which platform they used most, and the answers split the sample almost as cleanly as age did. Reddit and X users tied for the highest detection rate at 68%, with X users also posting strong accuracy at 71%. Both platforms run on long, argumentative text, which seems to build the reflex. TikTok-first users were the most cautious rather than the most perceptive: detection of 61% paired with the highest accuracy in the study at 72%, meaning they flagged less and were right more often when they did.
Facebook users struggled most among the major platforms, catching 47% of bots with 55% accuracy, the weakest accuracy figure anywhere in the data. Threads users landed lower still on detection at 40%. Frequency mattered too, though not in the direction you’d expect. People who checked social media a few times a day scored better than both those who avoided it and those who described themselves as on it almost constantly. Being chronically online produced more false accusations, not fewer misses.
Emotion beats reading skill
The most striking finding had nothing to do with demographics. The game rotated through four discussion topics, two deliberately low-stakes and two politically loaded, and the gap between them was wider than any age or platform divide in the study.
| Discussion topic | Bots caught | Accuracy |
|---|---|---|
| Data centres | 71% | 76% |
| Pineapple on pizza | 64% | 69% |
| Immigration | 54% | 63% |
| Women’s rights | 49% | 61% |
On a technical debate about data centres, players found 71% of the bots with 76% accuracy, their best performance anywhere in the study. The moment the topic shifted to women’s rights, detection fell to 49%, meaning participants missed more bots than they caught, while accuracy slid to 61%. Same people, same interface, same two-minute window. The only variable that changed was how much the subject mattered to them.
Surfshark’s research lead, Luís Costa, reads this as something other than a media-literacy problem. Heated debate hijacks the mental filter people rely on to flag suspicious content, and no amount of careful reading compensates once that’s happened. What users need, on his account, is a cooler head and better awareness of their own blind spots, not sharper textual analysis.
Why this is getting harder, not easier
The old advice for spotting bots was to watch for clumsy phrasing and robotic tone, which worked reasonably well right up until it didn’t.
Generative AI removed the tells. Automated accounts no longer produce the stilted, repetitive text that used to give them away, and the economics shifted alongside the capability: fake social accounts trade for as little as $0.08 on underground markets, which makes running thousands of them trivially cheap. The 6.3 billion accounts platforms delete each year are the ones that got caught, which says nothing reassuring about the ones still posting.
The practical consequence is that individual detection has stopped being a reliable defence. If half of a controlled test group can’t manage it in a setting designed to make them look for bots, nobody is catching them reliably while scrolling on a phone between meetings.
Where bot contact turns into an actual loss
A bot comment on its own costs you nothing. The damage comes later, in the two or three steps that follow.
Most bot operations run a funnel. Comment sections and replies are the top of it, where the account establishes itself as a plausible person with opinions. The middle is a direct message, an account follow, or a link, and that’s where the exchange stops being ambient and starts being aimed at you. The bottom is a page: a fake login screen that captures your credentials, a spoofed shop, an investment platform that exists only to take a deposit, or a download that installs something on your device.
That structure explains why detection at the comment stage matters less than it feels like it should. You don’t lose anything by reading a bot’s take on immigration policy. You lose something when a link two steps later loads a page designed to look like a service you already use. Coordinated amplification works the same way at scale, shifting what looks popular or widely believed until a claim feels settled enough to act on.
Both ends of that funnel live outside your judgment. The first depends on data collected about you, which shapes what reaches you and how well it’s targeted. The second depends on a domain loading in your browser. Neither is a question of whether you read the comment carefully.
Where a VPN fits into this
Worth saying plainly: no VPN will help you identify an AI-written comment. That’s a judgment problem, not a network one.
What a VPN addresses is the layer underneath, and specifically both ends of the funnel above. ZoogVPN’s Shield feature filters ads, trackers, and known malicious domains at the DNS level, which means a link that leads somewhere dangerous fails to resolve rather than rendering a convincing fake login page. That intercept happens before the page draws anything on your screen, so it doesn’t depend on you noticing a misspelled domain in the address bar while you’re already halfway convinced.
The tracker side of the same feature works on the other end. Targeted bot activity performs better with data behind it, and much of that data comes from trackers following you between sites and feeding data brokers who sell the result. Blocking those trackers and masking your IP address gives that pipeline less to work with. ZoogVPN routes your traffic through its own servers with AES-256 encryption, keeps no logs of what you do while connected, and operates under Greek jurisdiction rather than a country with mandatory data retention. A built-in kill switch cuts the connection if the tunnel drops, so a brief disconnect doesn’t quietly expose traffic you assumed was covered.
None of that makes you better at spotting a bot in the wild. It reduces what happens after one succeeds in getting your attention, which is the part of the problem the study suggests you can actually control.
Worth knowing: ZoogVPN’s free plan covers 10 GB a month with no credit card, and a paid plan runs on up to ten devices at once. Given how much of this lands on older relatives, covering their phones costs about as much as covering your own.
Stop the link before you have to judge it.
Habits that hold up better than instinct
If detection is unreliable, the useful response is changing how you react rather than trying harder to identify what you’re reacting to.
Notice the feeling before the content. The study’s clearest finding is that anger and urgency are where detection collapses. A post engineered to enrage you deserves a pause on that basis alone, regardless of whether you can tell who wrote it.
Treat unsolicited DMs as a category, not individual cases. A stranger opening with romance, an investment tip, or a push to move the conversation to WhatsApp or Telegram is the most common bot scam pattern there is. The opener is the tell, not the writing quality.
Verify unusual requests through a different channel. If a friend, a public figure, or an official account contacts you with something out of character, confirm it somewhere else before acting. Call them, check a verified profile, or ask something only the real person would know.
Keep personal details out of DMs. Your phone number, address, ID details, and anything financial have no business in a conversation with someone you’ve only met online, however long you’ve been talking.
Check the source before resharing. Content designed to be shared immediately, without verification, is doing exactly what coordinated amplification is built for. Thirty seconds spent on where it originated defeats most of it.
Lock down the entry points. Two-factor authentication, restricted DM settings, and current app versions remove the easy paths bot-driven scams rely on once they have your attention.
Frequently asked questions
A few questions come up often enough to answer directly.
How can you tell if an account is a bot?
The structural signals still help: very high posting frequency, repetitive or generic content, an incomplete profile, odd follower ratios, and sudden bursts of activity after long dormancy. Text quality is no longer one of them, which is precisely why the test in this study was so hard.
Are social media bots illegal?
It depends on the platform’s terms and what the bot does. Automation itself generally isn’t illegal, but most platforms prohibit accounts that mislead users, spread misinformation, spam, or harass, and malicious activity can carry legal consequences beyond suspension.
Does spending more time online make you better at spotting bots?
Only up to a point. In the study, people who checked social media a few times a day outperformed both those who avoided it entirely and, on accuracy, those who were on it almost constantly. Heavy users were more prone to wrongly flagging real people.
Which platform’s users spot bots best?
Reddit and X users tied for the highest detection rate at 68%, with X users also scoring 71% on accuracy. TikTok users were the most accurate overall at 72% while flagging less often. Facebook and Threads users performed worst on both measures.
Can a VPN block bots?
Not on social platforms, no. A VPN with DNS-level filtering blocks the malicious domains bot-driven scams direct people toward, and encryption plus tracker blocking limits the profiling data that makes targeting effective. It has no visibility into who wrote a comment in your feed.
Why do bots do better on political topics?
Because emotional investment interferes with scrutiny. Detection dropped roughly 20 percentage points between the study’s least and most charged topics, with the same participants performing well on a technical debate and poorly on a political one minutes later.
You can’t spot every bot. You can close the door they’re steering you toward.







