Request a callbackBook a call
← All posts

How Candidates Cheat AI Interviews in 2026, and How to Detect Each Method

TL;DR
  • Candidates cheat AI interviews four ways: answer overlays hidden from screen capture, second devices and helpers, proxy or deepfake interviewees, and AI copilots that hear the question. Gartner found 6% of candidates admit interview fraud and predicts one in four candidate profiles will be fake by 2028.
  • Each method needs its own detector: a desktop check for windows excluded from capture, headphones verified by an echo test, identity checks at every stage, and follow-up questions a relay cannot keep up with.
  • Never infer emotion and never auto-reject. The EU AI Act has banned emotion recognition in hiring since February 2025, and Illinois BIPA sets damages of $1,000 to $5,000 per violation for biometric checks without written consent.
The five defence layers
1 · Identity

ID document and liveness check before the interview, the same face matched at assessment, interview and onboarding, and a check for virtual cameras.

stops proxies and face swaps
2 · Environment

A desktop app that lists windows hidden from capture, background processes and extra displays. A browser tab cannot see any of it.

catches overlays
3 · Audio

Questions delivered only through headphones, verified by an echo test, with diarization to flag a second voice.

breaks phone relays
4 · Conversation

Follow-ups on the candidate's own last answer, interruptions and explain-your-own-code probes that punish a relay's lag.

hardest to defeat
5 · Human review

Every signal becomes timestamped evidence for a person. No automatic rejection and no emotion scores.

keeps false flags from becoming decisions
No single layer is sufficient. Each closes a class of attack the others cannot see, and the last layer decides whether a false positive turns into a wrong decision.

How do candidates cheat AI interviews in 2026?

Four ways: an answer overlay that screen sharing cannot see, a second device or an off-camera helper, a proxy or deepfake sitting the interview for someone else, and an AI copilot that hears the question and drafts the answer. Most proctoring still watches the browser tab and the webcam, which misses three of the four.

The numbers are large enough to plan for. In Gartner's 2025 candidate surveys, 6% of candidates admitted to interview fraud, either posing as someone else or having someone pose as them, and Gartner predicts one in four candidate profiles worldwide will be fake by 2028. The tools are sold openly: Cluely's homepage says it 'never shows up in shared screens, recordings, or external meeting tools'.

The proxy problem has moved from theory to law enforcement. The FBI warned in 2022 of deepfakes and stolen identities used to apply for remote jobs, and in June 2025 the Justice Department announced coordinated action against North Korean IT worker schemes that had obtained work at more than 100 US companies using stolen and fake identities.

Each method needs a different detector, so the sections below take them one at a time. The signal streams and the questions to ask a vendor are in the AI interview proctoring guide.

Which control catches which method
 Screen share + webcamDesktop appHeadphones + echo testIdentity + livenessConversation design
Answer overlay hidden from capture✕✓✕✕partial
AI copilot on the same machine✕partial✕✕✓
Phone relay or second device✕✕✓✕✓
Off-camera human helperpartial✕✓✕✓
Second monitor✕✓✕✕✕
Proxy intervieweepartial✕✕✓partial
Real-time deepfake✕partial✕✓partial
The first column is what most remote interviews still rely on. Read across any row: no single control catches everything, which is why the defence is layered.
6%
of candidates admit interview fraud, Gartner surveys
1 in 4
candidate profiles fake by 2028, Gartner's prediction
100+
US companies where North Korean IT workers obtained jobs, per the DOJ
41%
of job seekers admit using prompt injections, Greenhouse survey
Gartner, July 2025; US Department of Justice, June 2025; Greenhouse, November 2025.

How do answer overlays hide from screen sharing, and how do you detect them?

On Windows, an app can mark its window as excluded from capture, so it shows on the candidate's monitor and nowhere in a screen share or recording. A desktop proctoring app can list every window and read that flag. A browser-based proctor cannot, which is why overlays defeat most web tools.

The mechanism is a documented Windows API. SetWindowDisplayAffinity with WDA_EXCLUDEFROMCAPTURE, available since Windows 10 version 2004, shows a window on the monitor while it does not appear at all anywhere else. Microsoft's own example is keeping recording controls out of recordings; the same call hides an answer panel. On macOS the picture is less clean: Apple now calls the equivalent window setting a legacy constant that macOS no longer uses and tells developers not to rely on it to hide content, so results vary with the capture method.

Detection is the mirror image. The companion call, GetWindowDisplayAffinity, reads that setting for a window from any process, so a desktop app can enumerate visible windows and flag any that are excluded from capture, with the process that owns each one. Legitimate software can set the same flag, so a hit is evidence for review, not a verdict.

Behaviour backs the check up. Reading from an overlay tends to show as a pause, then fluent and evenly paced recitation, then trouble when the interviewer asks one level deeper about the answer just given. That is why conversation design, covered below, is the layer that still works when the environment check has been bypassed.

hidden_windows.py
# Windows only: list visible windows that are hidden from screen capture.
import ctypes
from ctypes import wintypes

user32 = ctypes.WinDLL("user32", use_last_error=True)
WDA_MONITOR, WDA_EXCLUDEFROMCAPTURE = 0x01, 0x11

EnumWindowsProc = ctypes.WINFUNCTYPE(wintypes.BOOL, wintypes.HWND, wintypes.LPARAM)
user32.EnumWindows.argtypes = [EnumWindowsProc, wintypes.LPARAM]
user32.IsWindowVisible.argtypes = [wintypes.HWND]
user32.GetWindowDisplayAffinity.argtypes = [wintypes.HWND, ctypes.POINTER(wintypes.DWORD)]
user32.GetWindowThreadProcessId.argtypes = [wintypes.HWND, ctypes.POINTER(wintypes.DWORD)]
user32.GetWindowTextW.argtypes = [wintypes.HWND, wintypes.LPWSTR, ctypes.c_int]


def windows_hidden_from_capture():
    flagged = []

    def check(hwnd, _lparam):
        affinity = wintypes.DWORD()
        if user32.IsWindowVisible(hwnd) and user32.GetWindowDisplayAffinity(
            hwnd, ctypes.byref(affinity)
        ):
            if affinity.value in (WDA_MONITOR, WDA_EXCLUDEFROMCAPTURE):
                pid = wintypes.DWORD()
                user32.GetWindowThreadProcessId(hwnd, ctypes.byref(pid))
                title = ctypes.create_unicode_buffer(256)
                user32.GetWindowTextW(hwnd, title, 256)
                flagged.append(
                    {"pid": pid.value, "title": title.value, "affinity": hex(affinity.value)}
                )
        return True

    user32.EnumWindows(EnumWindowsProc(check), 0)
    return flagged  # evidence for a reviewer, never an automatic rejection
A minimal Windows check for windows hidden from capture, using the two documented user32 calls. It returns the owning process and window title for a reviewer to look at, because legitimate software can set the same flag.

How do you catch a second device or an off-camera helper?

Through audio, not video. Every relay needs to hear the question, so deliver questions only through headphones and verify them with an echo test: play a tone and check whether the microphone picks it up. A phone on the desk or a helper across the room then hears half a conversation, which is useless to them.

Make the check continuous. Enumerate audio outputs at the start, run the echo test, then repeat it quietly mid-session with a near-inaudible tone, so a candidate cannot pass the check and then switch to speakers. Add diarization to flag a second voice or whispering in the room.

The one workaround is to repeat the question aloud so the relay can hear it, which is itself a signal: flag verbatim restatement of a question before an answer. Second monitors are an environment problem. A desktop app can count displays, and in browsers that support the Window Management API, Screen.isExtended reports multiple screens, though it is experimental, missing from several major browsers and reads false when the window-management permission is blocked.

Treat gaze as weak evidence. Looking away while thinking is normal, and candidates with a disclosed accommodation should have visual signals switched off entirely. A glance pattern is a reason to watch the clip, not a finding.

How a phone relay breaks
Phone relay attack against headphone enforcementInterviewerCandidatePhone relay
question asked
in-ear only
relay hears nothing
no answer available
attack fails here
candidate repeats question aloud
the only workaround
answer displayed
verbatim restatement flagged
detected
The relay is defeated twice: once by never hearing the question, and again because the only workaround is an obvious behavioural signal.

How do you spot a proxy or deepfake interviewee?

Verify identity at every stage, not once. Check a government ID with a liveness test before the interview, match the same face at assessment, interview and onboarding, and detect virtual cameras on the device. The FBI's own advice is identity verification during interviewing, onboarding and throughout employment.

The FBI has described the tells: lip movements that do not match the audio, and coughs or sneezes heard but not seen. In January 2025 it reported North Korean IT workers using AI and face-swapping technology during video interviews, and recommended cross-checking applicants who share resume content or contact details, and completing as much of hiring as possible in person.

Liveness checks ask for spontaneous actions, such as turning the head or holding the ID beside the face, because a pre-recorded or synthesised feed has to produce them live. Run them with consent, as a stated step, not as a hidden test a candidate can fail without knowing.

Placement matters more than cleverness. Identity checks belong before the interview and again before an offer, as their own step with their own consent screen. A harder interview does not catch a stand-in who knows the material, and a laptop shipped to an unverified address undoes every check before it.

Identity at every stage
  1. 1
    Applicationdedupe

    Flag applicants who share resume content, phone numbers or email addresses, as the FBI recommends.

  2. 2
    AssessmentID + liveness

    Document check and a live selfie, with a separate biometric consent and a stated retention period.

  3. 3
    Interviewsame person

    Face match against the assessment and a check for virtual camera drivers on the device.

  4. 4
    Offerverify again

    A second ID check, in person where possible, before anything is signed.

  5. 5
    Onboardingday one

    The same person on the first call, with equipment shipped only to a verified address.

Five cheap checkpoints. A stand-in has to beat all of them, and each one runs with the candidate's consent.

How do you detect AI copilots that listen and answer in real time?

Mostly by conversation design, because a copilot on the same machine can capture system audio even when the candidate wears headphones. It still needs time to transcribe, generate and be read, so questions that pivot on the candidate's own last answer, interruptions and requests to explain their own code expose the lag.

Design for latency. Ask for answers to begin within a few seconds, interrupt mid-answer with 'why not the other approach?', and ask the candidate to reconcile something they said two turns earlier. A relay is always one turn behind and cannot follow a conversation that keeps pivoting on its own content.

In coding rounds, have the candidate change their own code under a new constraint and explain why. Pasted or dictated code often comes with a confident account of the general approach and a weak account of the specific line the interviewer points at, which is exactly the gap to probe.

AI interviewers add one more attack: text aimed at the scoring model. Greenhouse's November 2025 survey found 41% of job seekers admit using prompt injections. Treat every transcript and document as data, never as instructions, and keep the rubric out of the candidate's reach. The architecture is in how to build an AI interviewer.

Interview design
Controls that survive a bypassed environment
  • Answers must begin within a few seconds
  • Interrupt mid-answer and ask 'why not the other approach?'
  • Reference the candidate's earlier statement and ask them to reconcile it
  • Flag verbatim restatement of the questionrelay tell
  • Ask for a change to their own code under a new constraint
  • Treat transcripts and uploads as data, never as instructionsprompt injection
  • Diarization for a second speaker or synthesised audio

What should you never do when detecting cheating?

Never infer emotion, never auto-reject, and never collect biometrics without consent. The EU AI Act has banned emotion recognition in workplace settings, which includes hiring, since 2 February 2025; GDPR restricts decisions based solely on automated processing; and Illinois BIPA requires a written release before collecting face geometry or voiceprints.

Emotion inference fails on science as well as law. A 2019 review in Psychological Science in the Public Interest found that the way people express emotion varies substantially across cultures, situations and individuals, and that a scowl often communicates something other than an emotional state. Nervousness is not a cheating signal, and in the EU, inferring it from a face or voice at work is prohibited under Article 5(1)(f).

Identity checks are biometric processing. Under Illinois BIPA, a face scan or voiceprint needs written notice of the purpose and retention period and a written release, with liquidated damages of $1,000 per negligent and $5,000 per intentional or reckless violation; a 2024 amendment limits repeated identical violations to one recovery per person. Under GDPR Article 9, biometric data used to identify someone is a special category that generally needs explicit consent.

Keep a person on every decision. GDPR Article 22 restricts solely automated decisions with significant effects, NYC Local Law 144 requires an independent bias audit before an automated employment decision tool is used, and the EU AI Act lists recruitment AI as high-risk under Annex III, with those obligations applying from 2 December 2027 under the Digital Omnibus.

RuleAppliesWhat it requiresWhat it means for proctoring
EU AI Act, Article 5(1)(f)Since 2 February 2025No emotion recognition in the workplace, which the Commission's guidelines read as including hiringNo nervousness, confidence or stress scores from face or voice
EU AI Act, Annex III point 4From 2 December 2027Recruitment and selection AI is high-risk: risk management, logging and human oversightLog every integrity flag and keep a human reviewer on it
GDPR Articles 9 and 22In forceExplicit consent for biometric identification; limits on solely automated decisions with significant effectsA consent screen before face matching; no automatic rejection
Illinois BIPA (740 ILCS 14)In forceWritten notice and release before face or voice biometrics; $1,000 or $5,000 per violationA separate biometric consent and a published retention schedule
Illinois AI Video Interview Act (820 ILCS 42)Since 1 January 2020Notice, an explanation and consent before AI analyses a video interviewExplain what the integrity checks look at, before the interview
NYC Local Law 144Enforced since 5 July 2023An independent bias audit within a year before use, and candidate noticeAudit the whole scoring pipeline, integrity signals included

Should you go back to in-person interviews to stop cheating?

For the final round of a remote role with access to sensitive systems, often yes; for every round, no. The FBI recommends completing as much of hiring as possible in person, and in Gartner's surveys 62% of candidates said they were more likely to apply where in-person interviews are required. The cost is reach, travel and time.

The practical split is by risk. Screening rounds stay remote and layered, because that is where the volume sits and where an AI interviewer saves the most time. The last conversation before an offer moves in person, or to a supervised location, for roles that touch production systems, customer data or money, which are the kinds of roles the FBI's 2022 warning named.

Where in person is impossible, a verified video call with the identity checks above, a live change to the candidate's own earlier work and a second interviewer gets most of the benefit. What does not work is a longer remote interview with the same controls: a relay does not get tired.

Remote or in person?
Where should this round happen?
Screening and first technical rounds
Remote, with the layered checks

The volume sits here, and an AI interviewer saves the most time.

Final round for a role with production, data or payment access
In person or at a supervised location

The FBI recommends completing as much of hiring as possible in person.

In person is impossible
Verified video with a second interviewer

Identity checks, a live change to the candidate's own work, and two people on the call.

What does a layered defence look like in practice?

Five layers, each closing a class of attack the others miss: identity before and during the process, a desktop environment check, headphone-only audio verified by an echo test, a conversation designed to punish latency, and a person reviewing timestamped evidence. Skip any one and a known method walks through the gap.

The layers are not equally expensive. Conversation design costs nothing but interviewer discipline and catches the widest range of methods. Headphone enforcement is a small piece of client code. The desktop app is the heaviest lift and asks the most of candidates, so reserve it for high-stakes rounds. Identity checks belong at the edges of the process, where a stand-in is cheapest to stop.

I built AccioMatrix, an AI assessment and interview platform that now serves 20+ enterprise clients, so this is the problem I work on. The integrity result I can point to is published: a Retell AI case study reports 70% fewer false-positive assessments, from 50% to 15%.

Price the layers before you build them. The desktop app, the identity step and the review tooling are separate lines, and the AI product cost estimator shows what each adds to the build and to the monthly bill.

Browser proctoring against a layered defence
Browser proctor only
Sees the tab and the face, and little else
  • Cannot see windows excluded from capture
  • Cannot hear a phone relay or see a helper out of frame
  • Tempted to read emotion from faces, which is banned in EU hiring
  • Produces flags without the evidence a reviewer needs
pick
Layered defence
Each layer closes a method the others miss
  • Identity checked at assessment, interview, offer and onboarding
  • Desktop check for hidden windows, extra displays and virtual cameras
  • Headphone-only audio verified by an echo test
  • Follow-ups on the candidate's own answers, with a person deciding on the evidence
The layered version costs more to build and far less to operate, because reviewers stop chasing flags they cannot verify.

How do you keep false positives down?

Score evidence, not suspicion. Every signal becomes a timestamped clip with a stated reason, several weak signals must agree before a flag, visual signals are switched off for disclosed accommodations, and a person decides. A system that flags a large share of honest candidates is not rigorous; it is unusable, and it trains recruiters to ignore it.

Calibrate on real sessions before launch. Have two reviewers label a sample blind, measure how often the system agrees with them, and raise thresholds wherever it flags innocent behaviour. Then tell candidates what is checked and why, before the interview starts; in Illinois and the EU that disclosure is a legal duty, not a courtesy.

If you want the layered checks built into your own interview flow, an AI interviewer is built at $0: the work is split into checkpoints with acceptance criteria agreed before it starts, and each one is invoiced only after you have seen it and accepted it. If you would rather hand over the whole hiring drive, that is engineering hiring.

Frequently asked questions

→Can screen sharing detect interview cheating?

Increasingly not. On Windows an app can exclude its window from capture with a documented API, so an answer overlay shows on the candidate's monitor and nowhere in the share. Phone relays and off-camera helpers never touch the screen at all. Screen sharing still has a place, but only as one signal among several.

→How do you detect an invisible answer overlay?

With a desktop app, not a browser. On Windows, GetWindowDisplayAffinity reads whether a window is excluded from capture, from any process, so the app can list hidden windows and the processes that own them. Legitimate software can set the same flag, so treat a hit as evidence for a reviewer, not as an automatic rejection.

→What is the single most effective anti-cheating control?

Headphone-only audio verified by an echo test, because every relay has to hear the question. If questions are audible only in-ear, a phone on the desk or a helper across the room hears half a conversation. Pair it with follow-up questions on the candidate's own answers, which defeat copilots that can still capture system audio.

→How do you detect a deepfake or proxy candidate?

Verify identity at every stage: an ID and liveness check before the interview, a face match between assessment, interview and onboarding, and a check for virtual cameras. The FBI lists lip movements out of sync with the audio and coughs heard but not seen as tells, and recommends completing as much of hiring in person as possible.

→Is it legal to use emotion detection in interviews?

Not in the EU, where the AI Act has prohibited emotion recognition in workplace settings, including hiring, since 2 February 2025. Elsewhere it is still a bad idea: a 2019 scientific review found that emotional expression varies too much across cultures, situations and people to read reliably. Score what candidates say and do, never how they look.

→Should candidates be told they are being monitored?

Yes. Illinois requires notice, an explanation and consent before AI analyses a video interview, BIPA requires a written release before face or voice biometrics, and the EU AI Act requires telling people they are dealing with an AI. Disclosure also makes the evidence defensible when a flagged candidate challenges a decision.

Take this into your own chat

Open the article in your assistant with one click and ask it how this applies to your product.

Keep reading

See it in production: 70% fewer false positives in AI interviews

Ready to talk numbers?

Twenty minutes, straight to the engineer. No sales rep, no deck.