AI-assisted misrepresentation, proxy candidates and synthetic identities are forcing enterprise talent acquisition teams to rethink how they establish identity, ability and trust – without turning every candidate into a suspect.


Candidate fraud used to mean an inflated resume, a suspicious reference or a candidate overstating their experience. In 2026, enterprise hiring teams face something broader: AI-generated applications, live interview assistance, proxy candidates, synthetic identities and, in the most serious cases, attempts to gain access to company systems and data.

The shift has happened fast. In GoodTime’s 2026 Hiring Insights Report, 23% of talent acquisition leaders said fake or AI-assisted candidates had been a major challenge in 2025. Looking ahead, 27% named fraudulent candidates as a top challenge for 2026 – enough to rank it number one, ahead of the 26% who cited a lack of qualified talent.

Fake or AI-assisted candidates are now TA’s #1 anticipated hiring challenge.

The study surveyed 504 senior U.S. talent acquisition leaders at organizations with at least 1,000 employees. That enterprise context matters. At scale, candidate fraud is not simply a resume-screening problem. It can affect hiring quality, recruiter capacity, candidate trust, information security, compliance and, once someone is hired, access to equipment, systems and sensitive data.

As Recruiting Brainfood founder Hung Lee put it: “ID verification, background checks, fraud detection and cybersecurity are now becoming much more important elements of a recruiter’s job.”

But the answer is not to treat every use of AI as deception, add the same identity check to every stage or automatically reject anyone who triggers a fraud score. Leading enterprise teams are taking a more disciplined approach. They are clarifying what acceptable AI use looks like, collecting stronger evidence of skills and identity across the hiring lifecycle, keeping humans accountable for decisions and defining how TA, Security, Legal, Compliance and IT will respond when concerns emerge.

The central lesson is simple: candidate fraud is a lifecycle and governance problem. It cannot be solved by one more screening tool.

What is candidate fraud in the age of AI?

Candidate fraud is deliberate misrepresentation intended to gain an unfair advantage or conceal a material fact during hiring. AI has widened the range of tactics available, but AI use itself is not the dividing line.

A candidate might use an AI assistant to research an employer, practice likely interview questions, check grammar or improve the structure of a resume. Those uses may be entirely legitimate. Employers use similar tools to write job descriptions, generate interview questions, summarize feedback and automate hiring workflows.

The concern begins when a tool no longer helps a candidate present their real ability, but instead manufactures evidence of an ability or identity they do not have. That spectrum includes:

  • Generally acceptable assistance: Researching a company, practicing responses, organizing ideas or editing application materials without inventing facts.
  • Potentially misleading assistance: Generating accomplishments, answers, code or work samples that the candidate cannot explain, reproduce or perform independently.
  • Clearly fraudulent behavior: Using a proxy test-taker or interviewee, a false or stolen identity, fabricated employment history, coordinated references, a deepfake overlay or an identity handoff after hire.

This distinction protects legitimate candidates as much as it protects employers. If organizations fail to define their boundaries, individual recruiters and interviewers are left to make inconsistent judgment calls based on instinct. Candidates also have no reliable way to know what assistance is permitted.

In a GoodTime fireside chat on the 2026 findings, Miro people leader Manjuri Sinha argued that “organizations, number one, have to start defining what is acceptable.” A clear candidate-AI policy turns an ambiguous cultural expectation into a rule that can be communicated, applied consistently and reviewed when the technology changes.

Why traditional hiring signals are breaking down

For years, resumes, portfolios and written application answers acted as shorthand for capability. Generative AI has made each of those artifacts easier to polish, tailor and produce at scale.

That does not make the artifacts useless. It does make them weaker as standalone evidence.

“Generative AI has turned signals into noise,” said GoodTime CEO and co-founder Ahryun Moon. A candidate’s materials can now look more specific to a role, more confident and more complete without becoming more accurate. Recruiters must sort through a larger volume of highly optimized applications while determining which claims reflect the person behind them.

The practical response is not to focus on whether AI touched a document. AI detectors are imperfect, and a polished sentence says little about whether the underlying claim is true. The better question is whether the hiring process produces enough job-relevant, observable and consistent evidence to validate that claim.

That pushes enterprise teams toward:

  • Structured questions tied to predetermined competencies
  • Job-relevant work samples and scenario walkthroughs
  • Live problem-solving that reveals how a candidate thinks
  • Follow-up questions about decisions, trade-offs and outcomes
  • Consistent scoring criteria across candidates and interviewers
  • Evidence collected and compared across multiple stages

This is one reason interviewer training and standardization matter more in the AI era. A conversational interview can reward fluency, confidence and preparation. A structured interview is better positioned to test whether the candidate can explain their reasoning, adapt when conditions change and connect a polished answer to real experience.

The goal is not to catch candidates in a contradiction. It is to replace weak proxies with stronger evidence.

Enterprise scale amplifies both the risk and the noise

Enterprise hiring creates a distinctive mix of vulnerabilities. Applicant volumes are high. Hiring spans business units, regions and systems. Thousands of interviewers may apply policies differently. Multiple vendors create handoffs and visibility gaps. Remote processes remove some of the identity cues that once came with an office visit.

Volume itself can become an attack on the process. Kyle & Co.’s State of Candidate Fraud Detection & Prevention describes a TA leader receiving approximately 1,500 applications overnight for a single engineering role. Meaningful manual review became impossible.

The immediate risk is not only that a fraudulent candidate advances. It is that qualified, legitimate applicants disappear inside synthetic volume. Recruiters spend more time adjudicating suspicious signals, candidate response times worsen and the funnel becomes less useful to everyone.

The consequences also change as a candidate moves forward. At the top of the funnel, the chief risk is usually operational: automated applications create noise and absorb review capacity. In the middle, the concern shifts toward whether the person interviewing or completing an assessment is who they claim to be and can perform the work. After offer acceptance, the stakes can include equipment, credentials, confidential information and access to internal systems.

That is why no single checkpoint can answer every question. A background check may validate records associated with an identity without proving that the interview participant is the person those records describe. An identity check early in the process does not prove the same individual completed a later assessment. And even a legitimate hire can create risk if credentials or work are handed off after onboarding.

Candidate fraud can surface across the full lifecycle:

  1. Application intake: Automated or synthetic applications overwhelm the funnel.
  2. Resume screening: Fabricated or AI-polished experience is presented as fact.
  3. Identity verification: A stolen or synthetic identity is used.
  4. Assessments: A proxy test-taker or unauthorized AI assistance completes the work.
  5. Interviews: A proxy interviewee, deepfake or real-time coaching obscures actual ability.
  6. References: Fabricated or coordinated reference networks reinforce false claims.
  7. Background checks: Valid records are connected to the wrong person.
  8. Onboarding: A different individual receives equipment or access.
  9. Post-hire: Credentials, identity or work are handed off.

The Kyle & Co. research captures the pattern: fraud changes form at each stage, defenses are unevenly distributed and some of the highest-impact risks appear after an organization believes verification is complete.

In the webinar, Moon made the operational implication explicit: teams need to maintain confidence in identity throughout the pipeline, not perform one isolated check. That does not mean applying the heaviest verification to every applicant. It means matching confidence measures to rising risk and consequence.

How leading enterprise TA teams are responding

The strongest response is not a wall of new controls. It is an operating model that makes expectations, evidence, escalation and accountability clear.

1. Establish a clear candidate-AI policy

Start by defining what candidates may and may not do during applications, assessments and interviews. The policy should answer practical questions: Can candidates use AI to edit written responses? Must an assessment be completed without outside tools? Is live interview assistance prohibited? When will identity verification occur? What may trigger additional review?

Communicate those expectations before the relevant stage, not after a concern arises. A concise disclosure creates a fairer process and gives the organization a more defensible basis for responding when a boundary is crossed.

The policy should also distinguish between roles and stages. An early application may reasonably allow broad assistance. A live skills assessment for a security-sensitive role may require tighter controls. Review the policy with Legal, Compliance and accessibility partners, then update it as tools and candidate norms evolve.

2. Replace conversational confidence with structured evidence

Structured interviewing is both a quality practice and an integrity practice. Begin with the competencies needed for the role. Ask every candidate a consistent core of job-relevant questions, use anchored scoring criteria and train interviewers to document evidence rather than impressions.

Then design opportunities for candidates to demonstrate how they work. Ask them to walk through trade-offs, adapt an answer when new information appears, explain a previous decision or complete a realistic task. The exercise should resemble the job closely enough to produce useful evidence without demanding excessive unpaid labor.

The best verification is often built into good assessment design. A candidate who understands their work can usually explain it from multiple angles. A candidate who has borrowed an answer may struggle when the problem changes.

3. Treat identity as something to maintain, not check once

Use risk-based verification across the lifecycle. Lower-friction controls can establish continuity early, while stronger checks may be appropriate as candidates advance, when conflicting signals appear or when a role carries significant access to data, funds or critical systems.

Map what each control actually proves. Identity verification, assessment proctoring, reference checks, background checks and device or network signals answer different questions. None should be mistaken for a universal verdict.

The aim is proportional confidence, not maximum friction. Teams should know why a check exists, when it fires and what happens if it produces an uncertain result.

4. Keep humans responsible for employment decisions

Technology can compare information, surface inconsistencies and explain why an interaction was flagged. It should not make an opaque determination that a person is fraudulent.

That is especially important in an immature market. Kyle & Co. notes that vendor accuracy figures often rely on different populations, definitions and self-reported methodologies. A fraud rate from one vendor cannot be treated as a market-wide benchmark or compared directly with another vendor’s number.

Vendors with different technical approaches are nevertheless converging on a sound set of principles: surface signals rather than verdicts, explain the signals and do not automatically reject candidates. Human review protects candidates from false positives and gives the organization room to consider context, accessibility, data quality and alternative explanations.

Build that review into the process. A flag should have an owner, an evidence standard, a documented decision and a path for escalation or reconsideration.

5. Create cross-functional ownership before an incident

TA may encounter the first suspicious signal, but it cannot carry the entire response. Candidate fraud can touch identity and access management, privacy, employment law, compliance, security operations and business leadership.

Define in advance:

  • Who performs the initial review
  • When Security becomes involved
  • Who makes the candidacy decision
  • How Legal or Compliance is consulted
  • What evidence is retained and for how long
  • How the candidate is informed
  • What happens if concerns emerge after hire

This is the organizational seam at the center of the problem: TA owns the hiring experience, while Security typically owns identity and access risk. Without an accountable owner and a documented protocol, a detection tool can create a queue of unresolved flags rather than a stronger defense.

Kyle & Co. found no broadly adopted, vendor-neutral response playbook and concluded: “Recruiters carry the floor. They cannot carry the ceiling.” Enterprise leadership must decide who owns the ceiling.

6. Protect the experience of legitimate candidates

Fraud prevention should not make every candidate prove their innocence. Controls should be proportionate to risk, communicated in advance, accessible across demographic groups, applied consistently and reviewed for false positives.

Give candidates a clear explanation of what is being verified and why. Offer an alternative process when a control creates an accessibility issue. Avoid collecting more personal data than the process requires. Measure delays and complaints created by verification, not just the number of flags it generates.

Enterprise teams also need to protect speed. In the webinar, Kyle Lagunas said, “We still have to continue to find the balance.” Friction affects employers too. A process that is slow, invasive or unpredictable can drive qualified people away while consuming the capacity teams need to investigate real concerns.

This is where disciplined automation helps. When scheduling, reminders, interviewer coordination and candidate communication run consistently, recruiters have more time for judgment, relationship-building and careful evaluation. Top-performing TA teams do not create rigor by making every task manual. They standardize and automate repeatable work so humans can focus on the moments that require context.

Traditional TA metrics may reward the wrong behavior

A serious fraud response can make a responsible TA team look less efficient on a conventional dashboard. Additional review may increase time to fill, cost per hire, candidate drop-off and the number of applications requiring intervention. Those same movements can also indicate an underperforming process.

Kyle & Co. found that none of the practitioners interviewed for its research had a TA scorecard that explicitly accounted for fraud prevention. That creates a dangerous incentive: teams can be penalized for applying appropriate scrutiny, while leaders lack the measures needed to tell whether the program is working.

Speed and cost still matter, but they need context. Add measures that show integrity, decision quality and downstream outcomes, including:

  • Confirmed fraud incidents and where they were detected
  • False-positive rates
  • Time required to adjudicate flags
  • Candidate complaints related to verification
  • Assessment integrity and process adherence
  • Misrepresentation-related terminations
  • Early-tenure performance and quality of hire

This aligns with the broader shift in enterprise talent acquisition priorities. GoodTime found that 42% of organizations now track quality of hire, while 22% name it their top success measure. Hiring integrity belongs in that same conversation. The purpose is not merely to identify more suspicious applications. It is to make better, more defensible hiring decisions and improve the outcomes of the people ultimately hired.

The defining question comes after detection

The market will continue to produce new fraud signals, identity tools and interview controls. Some will become important parts of the hiring stack. None can resolve the organizational question on their own.

The defining question for enterprise TA is not whether another tool can produce a fraud flag. It is whether the organization knows what to do when that flag appears.

Resilient hiring requires both speed and scrutiny. It requires clear boundaries for candidate AI use, stronger evidence of capability, risk-based identity continuity, accountable human review and a response model shared across TA and Security. It also requires enough operational capacity to apply those practices without leaving legitimate candidates waiting.

Enterprise teams do not have to choose between candidate trust and hiring integrity. The goal is to build a process strong enough to protect both.


Want the broader data behind the shift? Explore GoodTime’s 2026 Hiring Insights Report for more on candidate authenticity, AI adoption, hiring quality and the operating models separating top-performing teams from the rest. Then watch the on-demand fireside chat, How Top TA Teams Get Faster – and Hit Their Goals – in 2026, for the panel’s full discussion of trust, resilience and candidate fraud.

Unlock 2026’s top hiring strategies: Insights from 500+ TA leaders

Be the first to uncover deep hiring insights specific to your sector — straight from the highest-performing TA teams.

About the Author

Jake Link

Jake Link is a business process automation expert and Director of Content for GoodTime. He draws on over 10 years of experience in research and writing to create best-in-class resources for recruitment professionals. Since 2018, Jake's focus has been on helping businesses leverage the right mix of expert advice, process optimization, and technology to hit their goals. He is particularly knowledgeable about the use of automation and AI in enterprise talent acquisition. He regularly engages with top-tier recruitment professionals, distilling the latest trends and crafting actionable advice for TA leaders. He has advised companies in the tech, legal, healthcare, biosciences, manufacturing, and professional services sectors. Outside of work, you can find Jake exploring the coastline of Massachusetts' North Shore with his dog, Charlie.