Reference guide
Interview Cheating: What It Looks Like and How to Stop It
Interview cheating today means AI assistance running on the candidate's own machine: copilot applications that listen and answer, overlay windows hidden from screen share, coding assistants, remote-control software, and proxy candidates. Because these run outside the browser and outside the video call, they are invisible to standard interview tooling. Stopping them requires detection at the device level plus a consistent, documented review process.
The categories of interview cheating
It helps to separate the problem into distinct categories, because each one is defeated by a different control. Grouping them all as 'cheating' leads teams to buy a tool that addresses one category and assume the rest are covered.
- Real-time answer generation: a desktop copilot transcribes the interview and displays answers on screen.
- Coding assistance: AI coding tools produce solutions during technical assessments.
- Impersonation: a proxy candidate performs the interview, in person or through remote control.
- Media manipulation: pre-recorded, deepfaked, or altered video in asynchronous interviews.
- Environmental assistance: a second device, a second monitor, or a person off camera.
Why browser-based proctoring misses modern AI assistants
Most proctoring tools are built as browser extensions or lockdown browsers. They can see the tab, the page, and sometimes the webcam, but their visibility ends at the edge of the browser process. Modern AI assistance does not live inside the browser.
Tools such as invisible interview copilots and always-on-top answer overlays run as native desktop applications. They render above every other window, are frequently excluded from screen capture and screen share, and never touch the exam tab. A lockdown browser can be perfectly locked down while an assistant quietly reads the question and displays an answer on the same screen.
The same gap applies to remote-control software, virtual machines, injected keyboard input, and a second device sitting off camera. None of these leave a trace inside the browser, which is why a session can look clean in a browser-only tool and still be assisted end to end.
- Native overlay applications draw above the browser and are often invisible to screen sharing and screen recording.
- Remote-access tools let another person drive the machine without any browser-visible signal.
- Virtual machines and sandboxes let a candidate run the assessment in a controlled environment with helpers outside it.
- Synthesized or injected keyboard input can type answers that were never physically typed.
- A second phone, tablet, or monitor off camera leaves nothing at all in the browser.
What device-level detection actually sees
Detecting AI assistance reliably requires observation at the layer where the assistance runs: the operating system. ScreenComply pairs a browser-based API with an optional desktop agent that inspects the environment around the assessment rather than only the page inside it.
The agent enumerates running processes and browser extensions against a continuously updated list of AI assistants, answer overlays, and interview-copilot tools. It looks for always-on-top and transparent windows, remote-access sessions, virtualization, screen-capture drivers, additional connected displays, and USB storage events. It checks whether keyboard input originates from local physical hardware, and it records focus changes, clipboard events, and typing cadence patterns that distinguish composition from paste-and-modify behavior.
No detection system is perfect, and ScreenComply does not claim to catch every form of assistance. The goal is different and more useful: gather corroborating, timestamped signals so a human reviewer can make an informed, defensible decision instead of guessing from a webcam thumbnail.
- Process and extension enumeration against a maintained AI-assistant list.
- Overlay and always-on-top window detection, including windows excluded from screen share.
- Remote access, virtual machine, and screen-capture detection.
- Multi-monitor enumeration queried from the operating system, not inferred from gaze alone.
- Input-source integrity, clipboard and paste events, and typing-cadence analysis.
- Network and secondary-device signals on the local network.
Detect mode and Prevent mode
Not every stage of a hiring funnel warrants the same intensity. Detect mode observes quietly, logs signals, and produces a report — appropriate for early screens where friction matters more than enforcement. Prevent mode goes further and blocks restricted applications from launching for the duration of the session, which suits final-round technical assessments and regulated hiring.
Running Detect broadly and Prevent narrowly gives most teams coverage without turning every conversation into an examination.
How audit-ready integrity reports work
A detection is only useful if it can be explained to someone who was not in the room. Every ScreenComply session produces a structured integrity report: an executive verdict with a risk level, a chronological evidence timeline, and the underlying signal detail behind each entry.
Each entry is timestamped and tied to the specific observation that produced it, so a reviewer can see what was detected, when it happened, and how strong the signal was. Reports are written in non-accusatory, factual language, because the institution or employer makes the decision, not the software.
Reports can be exported to PDF and shared with a secure link, which is what makes them usable in academic-integrity hearings, HR reviews, and compliance audits. Retention is configurable, including tiers that minimize or eliminate stored artifacts for privacy-sensitive programs.
- Executive verdict with a graded risk level rather than a pass/fail guess.
- Chronological, timestamped evidence timeline linked to underlying signals.
- Human-review-by-design framing: factual observations, not accusations.
- PDF export and secure sharing for hearings, HR files, and audits.
- Configurable retention, up to zero-retention operating modes.
Building a policy that holds up
The organizations that handle this well write the policy before the first flag, not after. Disclose monitoring in advance, apply the same configuration to every candidate at a stage, define who reviews flags and against what criteria, and set a retention period that matches your obligations.
ScreenComply supports that operating model with configurable retention tiers, role-scoped access to reports, exportable documentation, and a SOC 2 Type 2 examination in progress. ScreenComply is under contract with the State of Montana.
Where to go next
Frequently asked questions
How common is AI-assisted interview cheating?
Purpose-built interview copilot tools are openly marketed and widely available, and hiring teams increasingly encounter them in remote technical interviews. Rather than quoting a figure, the practical assumption is that the tooling is accessible to any candidate who wants it.
What is an invisible interview copilot?
A desktop application that listens to the interview, generates answers with a language model, and renders them in an always-on-top window designed to be excluded from screen sharing and screen recording.
Do coding platforms already detect this?
Most coding assessment platforms run in the browser and can observe paste events and tab focus within their own page. They generally cannot see native desktop applications, overlay windows, or remote-control software running alongside the assessment.
Does ScreenComply need to be installed by the candidate?
The browser-based API requires no installation. The desktop agent is required for Prevent mode and for the deepest device-level signals; the candidate launches it for the session.
What does an integrity report contain?
An executive verdict with a graded risk level, a chronological evidence timeline of timestamped observations, and the supporting signal detail — exportable to PDF and shareable through a secure link.
ScreenComply is under contract with the State of Montana. SOC 2 Type 2 examination in progress.
See a session, a detection, and a report
A short walkthrough of live detection, Detect versus Prevent mode, and the integrity report your reviewers would actually receive.