AI Interview Cheating Is Now the Norm. Here's the Fix

38.5% of candidates now cheat live interviews and 61% still pass. Here's how to redesign your hiring pipeline to verify who you're actually hiring in 2026.

Ernest Bursa

Ernest Bursa

Founder · · 13 min read
An engineering director alone at a glass co-working desk cross-checking a candidate's real GitHub commit history on his laptop against handwritten interview notes

AI interview cheating is the use of real-time AI assistants, voice-mode LLMs, or deepfakes to pass a live interview dishonestly. In a 2026 audit of 19,368 AI-conducted interviews, 38.5% of candidates were flagged for AI-assisted cheating and 61% of them still scored above the passing bar. The live interview alone no longer verifies skill, and increasingly it no longer verifies identity either.

That is the uncomfortable finding for anyone who treats “they passed the technical” as ground truth. The signal your whole pipeline leans on has quietly stopped separating real from fake. This guide covers how widespread the problem actually is, why your passing score has lost its meaning, the separate and scarier wave of candidates who are not real people at all, and the concrete process changes that restore trust without buying a single piece of proctoring spyware.

How Bad Is AI Interview Cheating in 2026?

Bad, and getting worse fast, especially in engineering. The clearest dataset comes from Fabric, an AI interview platform that audited 19,368 live interviews between July 2025 and January 2026 and flagged 38.5% of candidates for AI-assisted cheating behavior.

The trajectory is the alarming part. Fabric’s flag rate climbed from 9% in July 2025 to 45% by September 2025, then stayed elevated through January 2026. That is a fivefold jump in a single quarter, not the “tripling” some coverage reported. Whatever the exact multiple, cheating went from a rare edge case to a coin-flip likelihood in roughly ninety days.

Engineering is the epicenter. In the same dataset, software engineering interviews showed a 48% cheating rate versus 12% for sales. That gap is not a mystery. Coding questions have clean, checkable answers, which is exactly the output a real-time AI assistant produces well. A sales roleplay is messy and interpersonal; a data-structures problem is a prompt away from a correct solution.

Do not read the 48% as “only a junior-engineer problem” either. The tools that drive the number are role-agnostic and effortless: an overlay does not care whether the question is a LeetCode medium or a senior system-design prompt, and the same assistant that solves a binary-tree traversal will happily draft a plausible architecture answer. The higher the role, the more expensive the mistake, and the more polished an overlay-coached candidate looks on camera.

One honest caveat before we go further: Fabric sells both AI interviews and cheating detection, so it has a commercial interest in a scary number. Treat its figures as directional. The reason to trust the direction anyway is that independent anchors, which we get to below, tell the same story from completely different vantage points.

Why Your Passing Score No Longer Means Anything

The failure mode is not that cheaters bomb the interview. It is that they pass it. In Fabric’s audit, 61% of flagged cheaters still scored above the 7.0 out of 10 passing threshold and would have advanced with zero detection.

Sit with that for a second. The score your applicant tracking system records, the one a hiring manager reads as “verified competent,” passed a majority of the people it should have caught. The cheating did not degrade the signal at the margins. It inverted it. A high score on a real-time recall test now correlates with good tooling at least as much as good skills.

The methods explain why detection by gut feel fails. Fabric’s breakdown of how candidates cheated:

Method Share What it looks like
Dedicated interview assistants (Cluely, Interview Coder) ~45% Invisible on-screen overlay feeding answers, not visible on a screen share
Voice-mode LLMs (e.g. ChatGPT) ~34% Audio transcription and spoken answers via a second device
Tab-switching / second screen ~18% Reading answers off a display outside the call
Live human help ~3% A person off-camera coaching in real time

The top two categories, roughly four in five cases, leave no trace on a standard screen share. Interview-assistant tools like Cluely and Interview Coder are marketed openly as invisible overlays that feed answers during a live call without appearing when the candidate shares their screen. You are not going to spot this by watching someone’s eyes. The format itself is compromised.

For the record, Fabric also found that 83% of candidates said they would cheat if they knew they would not be caught. It is a self-reported attitude, not a behavior, so weight it lightly. But it reframes the problem correctly: this is not a few bad actors. It is the default response to a system that made cheating trivial and detection theatrical.

The Second Problem: Is the Candidate Even a Real Person?

Answer-cheating assumes a real candidate getting illicit help. The newer, scarier wave removes that assumption. In a growing share of cases, the person on the call is not who they claim to be, and sometimes is not a single real person at all.

The demonstration that should end the “our video interviews catch this” argument came from Palo Alto Networks’ Unit 42. A researcher with no image-manipulation experience, using a five-year-old consumer GPU, built a convincing synthetic video candidate in about 70 minutes. Not a nation-state lab. An afternoon and a gaming card. If that is the floor, a live video call is not identity verification.

The scale is corroborated by sources that do not sell interview software. GetReal Security’s 2026 report found that 41% of IT, cybersecurity, risk, and fraud leaders say their organization has hired and onboarded a fraudulent candidate, and 88% said they have encountered deepfake or impersonation attempts at least occasionally. Gartner, an analyst firm with no dog in the detection fight, predicts that by 2028, one in four job candidate profiles globally will be fake. Label that one as a forecast, but it points the same direction as everything else.

This is not hypothetical fraud waiting to happen. It is an active, industrialized pipeline. The U.S. Department of Justice has brought a string of actions against a systematic North Korean scheme that uses deepfakes and stolen identities to plant operatives in remote U.S. tech roles, and CNBC has reported tech CEOs describing fake job seekers flooding their remote-hiring funnels. Voice-analysis vendor Pindrop measured a 1,300% increase in deepfake fraud attempts in 2024. Read those specific vendor multiples as directional, but the convergence across law enforcement, analysts, and independent researchers is the point.

The canonical case is KnowBe4’s North Korean operative. In July 2024, the security-training company hired a “software engineer” who turned out to be a North Korean operative using a valid U.S. identity stolen from a real person, with a stock photo AI-augmented to match. The persona cleared a background check, verified references, and four separate video interviews. The moment the company-issued Mac arrived, it began loading malware; KnowBe4’s tooling caught the anomaly and locked the device within 25 minutes. No breach occurred, but the lesson is stark: four live video interviews are not identity verification, and this is now a documented, systematic operation, not a one-off.

Note that most of the punchiest identity statistics also come from vendors that sell deepfake detection. That is why the load-bearing claims here lean on the independent anchors: Gartner’s forecast, Unit 42’s hands-on demonstration, and the fully documented KnowBe4 incident. The vendor numbers are consistent with those anchors, not a substitute for them.

The live coding interview is uniquely exposed because it combines two things AI is good at: producing clean, checkable answers, and doing so invisibly. It is the highest-value target in your pipeline and the easiest to compromise.

Think about what a real-time coding round actually tests. It rewards fast recall of algorithmic patterns under observation, which is exactly the task a large language model excels at and a nervous human does not. A candidate running an overlay does not need to understand the solution. They need to read it off the screen while nodding. The interviewer sees a screen share that looks completely normal because the assistant renders outside the shared surface.

This is the same structural weakness that already killed the whiteboard as a standalone signal. As we argued in the case against whiteboard interviews, watched-puzzle formats measure performance under observation more than engineering judgment, and AI overlays finished the job by making the puzzles trivial to solve silently. The response that works is not surveillance software. It is a format shift toward assessments that test reasoning and communication, the two things an overlay still cannot fake in a live back-and-forth.

There is a tempting shortcut here, and it is worth naming so you can reject it. When teams realize the live round is compromised, the first instinct is usually to buy proctoring: keystroke logging, eye-tracking, browser lockdown, forced full-room camera pans. Resist it. It punishes honest candidates with an interrogation-grade experience, it does nothing against a deepfake that is happy to comply with every check, and the overlay vendors iterate faster than the detectors. You cannot surveil your way out of a format problem. You redesign the format.

Worth separating clearly: this is a different problem from AI bias in resume screening. That is about your algorithm being unfair to real candidates. This is about verifying that a candidate is who and what they claim. Both matter, and the fixes do not conflict, but do not confuse the two.

What Actually Verifies a Candidate: Three Checkpoints

The evidence supports three structural moves, none of which require a deepfake detector. The goal is to make legitimacy a property of your pipeline rather than a guess a tired interviewer makes on a Friday afternoon.

1. Tie the assessment to a verified identity

Anonymous video calls are the weak link because nothing binds the person to a stable, auditable identity across your process. Replace the ad-hoc call link with a candidate-portal login, so every submission and every stage is tied to the same authenticated session. That does not, by itself, prove someone is not a proxy. What it does is create one continuous identity thread you can reason about, and it gives you the natural place to add a hard identity checkpoint (a government-ID check at offer stage, for instance) where the stakes justify it.

2. Shift weight from real-time recall to work samples

Real-time recall is the format AI feeds best. A reviewed work sample, a job-relevant task the candidate completes and then defends, is far harder to fake convincingly at depth. It also predicts performance better than a whiteboard sprint. The evidence here needs a caveat: older meta-analyses put work-sample validity around 0.54, but a 2022 reanalysis by Sackett and colleagues revised many of these estimates downward, placing work samples near 0.33 (structured interviews around 0.42). Even at the conservative figure, a work sample is a strong, legally defensible signal because it directly samples the job. Pair it with a live defense where the candidate explains and changes their own decisions, and the overlay has nothing to feed.

3. Keep a stage-level audit trail

When a hire’s legitimacy is questioned six months later, “I remember they interviewed well” is not an answer. You need a reconstructable trail: who assessed the candidate at each stage, when, on what artifact, and what score they gave. An audit trail does not prevent fraud on its own, but it turns an unanswerable question into a documented timeline, and it is what auditors, security teams, and your own future self will ask for.

How to Redesign Your Interview Stages Around Verification

Here is the shift in mindset: verification is not a tool you bolt on. It is a property of a pipeline where each stage and assignment is a first-class object tied to one authenticated candidate identity. When your ATS models the process that way, the three checkpoints above stop being manual discipline and become how the system already works.

This is exactly why Kit treats the interview-stage lifecycle as structured data rather than a folder of notes. A few concrete primitives map directly onto the checkpoints:

  • Identity-linked candidate portal. Kit uses magic-link authentication, so every candidate action happens inside the same authenticated session rather than an anonymous call. Work is bound to a stable identity thread across every stage, which is the foundation any verification story needs.
  • Code assignments as async work samples. Kit’s code assignments are GitHub-integrated and reviewed asynchronously, which is precisely the format shift the evidence recommends: away from real-time recall an overlay can feed, toward a defended work sample it cannot.
  • Team review and scorecards. Structured, collaborative scoring is where anomalies surface: a live answer that contradicts the work sample, a score that does not match the resume, a submission that “felt too clean.” This is a process your team runs on Kit’s existing review and voting, not an automated fraud detector.
  • Stage-level history as audit trail. Because stages and assignments are modeled objects with timestamps and ownership, you get the reconstructable trail for free. Legitimacy becomes something you can point to later, not something you hope you remember.

To be clear about what this is not: Kit does not ship deepfake detection, biometric verification, or video proctoring, and you should be wary of any vendor promising a magic lie detector. The durable fix is structural. Identity verification proper, where you truly need it, is a checkpoint you add at high-stakes stages, layered on top of a pipeline that already knows who did what and when.

The Takeaway

The live interview stopped being proof. With 38.5% of candidates flagged for cheating, 61% of them passing anyway, and a synthetic candidate buildable in 70 minutes, “they passed the technical” is no longer a fact you can bank. The instinct to fight this with more surveillance is a trap; overlays are invisible and deepfakes are cheap, so detection will always lag.

The move that holds is structural. Tie assessments to a verified identity, weight your loop toward defended work samples over real-time recall, and keep an audit trail so any hire’s legitimacy can be reconstructed. Do that, and verification stops being a separate tool you buy and starts being a property of how your pipeline works. If you want a hiring process built that way from the first stage, see how Kit models the interview lifecycle.

Related articles

Ready to hire smarter?

Start free. No credit card required. Set up your first hiring pipeline in minutes.

Start hiring free