Is Your Hiring Process Ready for Deepfake Candidates?
Deepfake candidates & your hiring process.
It comes up in nearly every conversation we have with talent leaders right now, and it is prompting a genuinely useful rethink of how hiring processes are designed.
Here is what is actually happening. A candidate profile can be entirely fabricated. A person on a video interview can be real, but running software that puts someone else's face on the screen. Answers can be fed in from off camera, by a model or by another person. And in the cases with the biggest consequences, someone passes the interview, changes their shipping address at onboarding, and a company laptop ends up somewhere nobody intended.
None of it is everywhere yet. All of it is becoming more common. And whatever is true today will shift again as the tools improve.
Gartner has forecast that by 2028, one in four candidate profiles worldwide could be fake. Greenhouse reported in late 2025 that 65% of hiring managers had caught applicants using AI deceptively, with 18% citing deepfakes among the tactics encountered. And in Fabric's analysis of 19,368 AI-led interviews conducted between July 2025 and January 2026, 38.5% of candidates were flagged for behaviors the platform classified as AI-assisted cheating, with the rate rising sharply over the period.
The forecasts and the early vendor data point in the same direction: candidate identity fraud and AI-assisted interviewing are becoming more common, not less. Most talent functions were built for a world where the person on the video call was obviously a person. The question now is bigger than detection. It is whether your hiring infrastructure, your process, your tooling, and the way you build teams are ready for a world where identity has to be established rather than assumed.
This is not, at its core, a technology problem. It is a process design problem that technology is now being asked to compensate for.
That gap will not announce itself. Like most infrastructure gaps, it will show up as a security incident, a hire who cannot do what the interview suggested, or a role that quietly fails in month four.
What actually changed
The tools are really smart. A real-time face and voice swap no longer requires deep technical skill or expensive hardware. Neither does real-time answer coaching, where a candidate is fed responses during a live interview by someone or something off screen. One attacks identity. The other attacks capability.
The economics changed. Fraudulent candidates are no longer only individuals overstating experience. The Justice Department has prosecuted cases involving US-based facilitators who received company-issued equipment at US addresses, then enabled overseas workers to access those devices remotely and appear to be working from the United States. In one scheme sentenced in April 2026, North Korean IT workers obtained employment at more than 100 US companies using the compromised identities of US citizens. What those companies absorbed was not a bad hire. It was legal fees, network remediation, and exposure of internal systems, intellectual property and source code.
The assumptions underneath the process stopped holding. Interviews were built to assess & evaluate capability. Background and eligibility checks were built to confirm identity and history at the point of hire. Neither was designed to establish that the person being interviewed is real, unassisted, and the same person who will do the work.
That second point is why this is not only a talent problem. The highest-impact cases do not end with a disappointing hire. They create access control, data security, intellectual property, payroll, sanctions, and worker classification exposure. If your CISO and general counsel are not part of this conversation, the conversation is incomplete.
Three different things to verify
"Verification" is not one control. There are three, and they answer different questions.
Identity. Is this person who they are represented to be in the application and the interview, and at what point in the process is that established?
Capability. Can this person independently demonstrate the judgment, skills, and work they claim? This is what your interview and assessment design is for.
Eligibility and history. Can they legally work in the role, and does their stated employment history hold up to appropriate verification?
Background and employment eligibility checks answer the third and contribute to the first at the point of hire. They were never designed to establish interview authenticity, and they cannot resolve a scenario in which a real person passes onboarding with legitimate documents, receives company equipment, and then enables someone else to do the work.
None of this means the old controls were wrong. They were built for conditions that held for a long time, and they did their job. What changed is one assumption underneath them.
When a technology shift lands on a people process, the useful question is whether the infrastructure still does what it was designed to do. Sometimes the answer is a policy update. Sometimes an interview redesign or a new plug in technology.
Where the gaps actually sit
The issues we are hearing about and solving for right now are usually not because a company skipped verification or had a weak process. They happen because the structure didn’t hold up to the current risks, and an assumption that one control covered all three questions.
No verification checkpoint before offer. Identity is confirmed at time of background check and onboarding, which happens after the decision is made. By then the process has already invested substantial interviewer time.
Inconsistent interview formats. Some panels run camera on, some do not, some record a transcript, some do not. When the standard varies by interviewer, there is no baseline to compare against.
Interviewers were never trained for this. Until very recently, the job in an interview was to evaluate against the role, assess for the skills the business will need next, build enough rapport for a great candidate experience, plan interview questions that give the candidate the opportunity to show their skills and fit for the role and provide the interviewer enough insight to make a judgement call on the candidates capability, take usable notes, and sell the opportunity well enough to leave the candidate excited about the opportunity. That is already a full cognitive load.
Now there is a new layer running underneath it: noticing whether something about this conversation is off. This is a new ask of interviewers & recruiters, ensuring they are trained and know what to look for, how the deepfakes are advancing and how to handle without making assumptions or inadvertently making a false accusation that opens other discrimination risks. The cost of getting it wrong is high. A polished, well prepared candidate should never end up treated as a suspect. Recruiting just got considerably more nuanced.
No documented escalation path. A recruiter or interviewer who feels something is off often has nowhere formal to take it, or a clear set of guidelines to gut check their concerns against. Concerns that live in a Slack DM are concerns that disappear.
No read on channel. Different sourcing channels carry different risk profiles, and most funnels do not track where anomalies cluster.
Recruiter capacity. This is the one people skip. Verification instincts are pattern recognition, and pattern recognition degrades under volume.
What companies are actually doing
Some of it is surprisingly low-tech.
In-interview checks. Some interviewers use unscripted questions, changed constraints, or a short live walkthrough to test whether a candidate can independently explain their own thinking, which is often more revealing than anything visual. Others use ad hoc visual checks, asking a candidate to change angle or move a hand across the face, in an attempt to expose manipulated video.
Watching signals rather than faces. Response latency on unexpected questions, mechanical or oddly paced speech, comprehension that falls apart when the topic shifts. Technical signals such as location data, where lawfully collected and appropriately reviewed, may add context, but should not be treated as conclusive.
Automated detection in the background. Tools that analyze lip sync, eye movement, facial construction, and voice patterns during a live interview and flag anomalies to the recruiter rather than interrupting the conversation.
Structural moves. Some organizations are adding higher-assurance steps for high-risk roles, including in-person (even if it’s asking the candidate to either come to an office they may be local to, or fly to meet a hiring manager or team member for coffee or an informal meeting prior to offer.
A caution about visual tests. They are a temporary tactic, not a dependable control. The models evolve quickly, interviewers are not trained examiners, and research suggests people are only modestly better than chance at spotting manipulated faces. Use them, if at all, as one input into a documented escalation process, never as the basis for an adverse decision. Useful as a stopgap. A poor foundation for a program.
And recruiters should not be turned into amateur examiners. Their job is not to detect a deepfake. It is to recognize when something warrants escalation, and to have somewhere to take it.
The emerging vendor category
Start with your existing vendors. The background screening market consolidated hard over the past two years. Checkr acquired GoodHire, HireRight acquired ClearChecks, First Advantage acquired Sterling, and the survivors have been building identity verification into their existing products. HireRight in particular now positions around identity verification and hiring fraud rather than records checks alone.
That matters practically. Adding a capability to an incumbent contract is a fraction of the procurement effort of onboarding a new vendor, and your screening provider already holds your candidate data flows, your compliance posture, and your integrations. Ask them what they have before you look at anything else.
The honest limitation: screening vendors are built for records verification, not forensic document analysis. A fabricated diploma tends to land in an education-verification queue and get checked with the registrar, rather than being examined as a possible forgery. Know where your incumbent stops and what that leaves uncovered.
Candidate verification and interview integrity is an emerging category in hiring, and it is moving fast. None of it replaces the process work but it is worth knowing what exists before you need it.
Identity verification at the front of the funnel. Providers such as Sumsub combine document and face-match workflows with liveness and deepfake detection, an approach that comes out of financial services KYC.
Real-time detection during interviews. Providers such as Pindrop and Reality Defender offer tools intended to detect synthetic or manipulated audio and video. Sherlock AI and InteleScreen are newer entrants built for hiring rather than adapted from adjacent industries.
Detection embedded in interview platforms. Some organizations will want this built into tools they already use. Others will need something standalone that integrates with their stack. The market is moving quickly enough that either could be right.
These are illustrative rather than endorsements, and capabilities change fast. Verify directly.
Detection accuracy claims in this category are self-reported and largely unaudited. Treat them as marketing until you have run your own pilot. And be clear about what you are buying: these tools produce a signal, not a verdict. Someone on your team still has to decide what to do with it.
What you are actually allowed to collect
Before you design anything, know the constraints. They are jurisdictional and they will shape the design more than the technology will.
Biometric law in the US. Three states have standalone biometric statutes: Illinois (BIPA), Texas (CUBI), and Washington. Illinois matters most, because BIPA carries a private right of action, meaning individuals can sue without proving actual damages. A 2024 amendment limited damages to accrue per person rather than per violation, which reduced exposure without removing it. Roughly twenty more states treat biometric data as sensitive under broader consumer privacy laws. If your approach involves face matching or voice analysis, this is a design constraint, not a compliance afterthought.
The EU and UK. Biometric data is a special category under GDPR Article 9, requiring explicit consent or a national law exception. Regulators have been consistent that employers can rarely rely on legitimate interest for biometric authentication where a less intrusive method exists, and consent in an employment context is complicated by the power imbalance between employer and candidate. AI-assisted screening will generally trigger a Data Protection Impact Assessment under Article 35. In several member states, Germany chief among them, deploying biometrics in an employment context requires works council consultation before go-live. The EU AI Act now sits alongside all of it.
The practical implication is that a single global verification standard is unlikely to survive contact with your jurisdictions. Tier by geography as well as by role risk, and bring privacy counsel in at design rather than at rollout.
What we would actually build first
Name an owner. This work sits across talent acquisition, security, privacy, legal, and IT. Someone has to own the design and convene the rest. In our experience it works best when TA owns the process design and security owns the risk tiering, with legal and privacy consulted at design rather than at sign-off. Who holds the pen matters less than the fact that somebody does.
Before you buy anything, start here. The specific tools and tactics in this piece will age quickly. These will not. And for most organizations this is a quarter of focused work, not a transformation program.
If you only do one thing this quarter, tier your roles and write down your interview standard. Both cost attention rather than budget, and everything else gets easier once they exist.
Tier your controls by role risk. A role with no system access does not need the same design as one with production access, customer data, financial authority, or regulated information. Tiering is what stops this becoming a tax on every hire.
Set a consistent interview standard and write it down. Format, participation, accommodations, and documented exceptions. Consistency creates a baseline. Inconsistency is what makes anomalies impossible to read. Enable teams with the tools to easily assess candidates while being freed up to be present in the interview. When your heads down taking notes, or focused on reading the resume in the interview and trying to decide what to ask, it’s easier to miss something. Bonus points engaged interviewers can lead to better candidate experience, which we don’t want to lose sight of as we navigate the rise of deepfakes.
Build authenticity into the interview itself. This is the control that works whether or not you ever buy a tool. Role-relevant work samples, adaptive follow-ups rather than scripted ones, and candidates walking through their own decisions and responding when you change a constraint.
Put identity checks at a risk-appropriate point. For higher-risk roles, decide whether verification happens before a final decision, before equipment ships, or before access is granted. Design it with legal, privacy, and security.
Give recruiters an escalation path. How to document their flags, any tools that outline what to look for, and who to report it to when they feel something isn’t quite right even if an offer has already been sent. Define what happens next, what would lead to rescinding an offer, what are the candidate communications, what collaboration with legal to you want to have in place, and how to ensure fair process so that a candidate is treated fairly when the signal turns out to be nothing.
Tell candidates what to expect. Publish your process, including any verification steps and your position on AI use, before candidates encounter them. Nobody should meet a new requirement mid-process. Transparency is also a deterrent: a documented, clearly communicated process is a harder target than an ambiguous one, and it costs a legitimate candidate nothing.
Decide your policy on candidate AI use. Using AI to prepare is not the same as being fed answers in real time. A policy that fails to distinguish will punish honest people and miss the actual problem.
The part worth protecting
There is a version of this where hiring becomes an arms race, every interview becomes a security screening, and candidates walk into the process assuming they are suspects.
That version costs more than the fraud does.
The strongest hiring processes we have built ran on trust that was earned in both directions. Candidates were told what to expect and treated fairly. Recruiters had the tools & training to notice when something felt wrong, and the authority to say so. Verification was a quiet layer in the infrastructure, not a checkpoint the candidate experienced as an accusation.
Build the verification layer. Then keep building the human one, because the second is what makes the first tolerable, and a process that treats everyone as a threat will lose the people you most wanted to hire.
Last updated: August 2026. This is a fast-moving area and we update this piece as the picture changes. This article is educational and does not constitute legal, privacy, or security advice