ooligo
ENTRY TYPE · definition

AI interview fraud

By Marius Bughiu Last updated 2026-08-09 Recruiting & TA

AI interview fraud is one label stretched over three separate problems, and the control that fixes one does nothing for the other two. Identity substitution — someone other than the applicant sits the interview, either a human proxy or a real-time face-swap driven by the operator. Answer provenance — the applicant is who they claim to be, and an off-screen model is writing their answers. Persona fabrication — the name, the employment history, and the references were manufactured to fit the req. The short answer to how you stop it is that you do not detect your way out inside the interview. You bind identity at a gate you control, publish the AI-use rule before the loop so answer provenance becomes a policy question instead of a guess, and ask questions whose answers a model cannot supply.

What it is not. It is not a candidate using AI to write a resume or rehearse answers — that is preparation, and it is now the baseline. It is not proctoring, and it is not emotion, stress, or honesty detection: EU AI Act Article 5(1)(f) prohibits inferring emotions from biometric data in the workplace, and the Commission’s February 2025 guidance on prohibited practices reads “workplace” to cover candidates during selection. It is not the same problem as AI screening bias, which is about who your models reject, not about who is on the call. And it is not a media-forensics problem you solve by buying a detector.

The three classes, and what each one needs

ClassWhat is actually happeningThe control that holdsThe control that does not
Identity substitutionA proxy or a face-swap overlay sits the loop; the hired person is not the interviewed personGovernment-ID plus liveness check bound to a named gate; one synchronous in-person or supervised checkpointRecruiter judgment on video; a deepfake-detection score
Answer provenanceReal candidate, hidden model supplying answers in real timeA published AI-use rule, plus questions grounded in the candidate’s own artifacts and interrupted follow-upsScreen share; asking candidates to promise they are not using AI
Persona fabricationSynthetic or stolen identity, invented history, controlled referencesEmployment and identity verification at offer, reference calls to numbers you sourced yourselfAnything inside the interview — the loop is not where a fabricated history breaks

The reason this taxonomy matters is that most programs buy one control and believe they have covered all three. An identity check at offer does nothing about a real candidate reading from Cluely. A cheating-detection model does nothing about a laptop shipped to a re-shipper’s address.

What the evidence actually supports

Making a synthetic candidate is a lunch break’s work. Unit 42 published research on 21 April 2025 in which a researcher with no image-manipulation experience built a synthetic identity capable of passing a video interview in 70 minutes, on a five-year-old computer with a GTX 3070, using free tools and AI-generated faces. The same research names the failure modes of real-time face swaps: temporal consistency breaks on rapid head movement, occlusion handling breaks when a hand crosses the face, lighting adaptation breaks on sudden brightness changes, and audio-visual synchronization drifts.

Institutional buyers now treat it as a top-tier fraud vector. Experian’s fraud forecast, published 13 January 2026, named AI-generated candidates among its threats for the year, warning that employers will onboard people who are not who they say they are and give them access to sensitive systems.

Answer-provenance tooling is funded and mainstream. Cluely raised a $15M Series A led by Andreessen Horowitz on 20 June 2025, at roughly a $120M post-money valuation, after a $5.3M seed in April. Its founders were suspended from Columbia over Interview Coder, the predecessor built specifically to pass technical interviews undetected. This is not a fringe capability that a policy can wish away.

The prevalence numbers are directional, not measured. The most-cited figure of 2026 — 38.5% of 19,368 interviews flagged for AI-cheating behaviour between July 2025 and January 2026, with technical roles at 48% versus 12% for sales — comes from Fabric, a vendor selling interview software with cheating detection built in. A flag there is a model output above a 40% probability threshold, not an adjudicated finding, and no false-positive rate is published alongside it. Read it as evidence that the direction is up and the volume is non-trivial. Do not put it in a board deck as a measured rate.

Human review is not a control. iProov tested 2,000 UK and US consumers in February 2025; 0.1% correctly identified every real and synthetic item in the battery, and participants were 36% worse on synthetic video than on synthetic images. The honest reading is narrower than the headline: 0.1% is an all-correct rate across a full set, not the odds a given recruiter spots a given fake. It still rules out “train recruiters to watch for it” as your primary defence.

Why detection-first fails

Three reasons, and they compound.

Base rates. A screen that catches 80% of fraudulent candidates at a 5% false-positive rate, against a 2% prior, produces a flag that is real about a quarter of the time. Three flags in four are innocent people. The arithmetic is worked through in the interview-fraud screening skill, and it is the reason a flag routes to verification and never to a rejection.

Detector generalization. Deepfake detectors collapse off their training distribution, and the adversary picks the generator. A score you cannot benchmark against the model actually in use is a number, not a control.

Legal exposure runs the wrong way. Analysing the video for face geometry or a voiceprint pulls you into Illinois BIPA and the AI Video Interview Act, with notice, consent, and deletion duties attached. Buying a third-party score about a candidate raises automated-decision questions under NYC Local Law 144. The heavier the detection stack, the more compliance surface you own — for a signal that does not survive its own base rate.

The controls that hold

  1. Bind identity at a named gate, not in the loop. Government ID plus liveness at offer or onboarding, checked against the name on the payroll record. Compare the identity-document address against the shipping address for company equipment; a divergence there is the cheapest signal available and almost nobody looks at it.
  2. Keep one synchronous checkpoint that a proxy cannot sit. Google, Cisco, and McKinsey all reinstated in-person rounds through 2025 for exactly this reason — Cisco’s VP of global talent acquisition, Scott McGuckin, tied the change directly to fake candidates infiltrating remote hiring. One round is enough; a full onsite loop is not the ask.
  3. Publish the AI-use rule before the first interview. Decide whether assistance is prohibited, permitted with disclosure, or permitted outright, then say so in the invite. If nothing is published, the honest default is permitted, and screening against an unstated rule is indefensible.
  4. Ask questions a model cannot answer for them. Their own commits, their own decisions, the tradeoff they regret. Interrupt. Follow up off-script. A hidden assistant handles the question it was given, not the third follow-up on a choice the candidate made in 2023.
  5. Use live challenges against the known failure modes, and do not overweight them. A profile turn, a hand passed across the face, a change in lighting — Unit 42’s own recommendation, targeting occlusion and temporal consistency. Failing one is a reason to verify. Passing all three proves nothing.
  6. Route every flag to a verification conversation. A structured 45-minute follow-up resolves most flags. The outcome of that conversation, not the score, reaches the hiring decision.
  7. Verify employment and identity at offer, independently of the loop. Fabricated histories break against payroll records and references you sourced yourself, never against a good interview performance.

Common pitfalls

Buying a deepfake detector and calling it a programme. The vendor benchmarks on its own distribution; your adversary picks a different generator. Guard: treat any detector score as a routing signal into step 6, and put your budget into the identity gate in step 1.

Rejecting on a flag. At realistic base rates, most flags name innocent candidates, and a file of unadjudicated accusations against named people is discoverable in any later charge. Guard: make rejection structurally impossible — the flag field routes to verification and has no reject path.

Screening against a rule you never published. Guard: the AI-use policy ships in the interview invite and the careers page before the first flag is raised.

Reading the iProov figure as “0.1% of people can spot a deepfake.” It is an all-correct rate across a battery of images and video. Guard: cite the study for the conclusion it supports — human review is not a control — and not as a per-item detection rate.

Treating the in-person round as the whole answer. It closes identity substitution and does nothing about a real employee handing credentials to someone else after day one, or about a fabricated employment history. Guard: pair it with verification at offer and with access controls that assume the insider case.

Challenge-response that penalizes disabled candidates. Movement challenges, gaze-based signals, and response-latency thresholds disadvantage candidates with motor, visual, or processing differences. Guard: publish an accommodation path with the AI-use policy, exclude gaze and affect signals entirely, and never let a latency threshold act alone.

Letting the fraud response degrade the loop for everyone. Adding four verification steps to a five-stage process costs you real candidates. Guard: scope the heavy controls to reqs with production access or fully-remote onboarding, and measure drop-off at each new step.