---
title: "How candidates cheat with AI in 2026, and what actually stops them"
url: https://tatvaone.ai/how-candidates-cheat-with-ai/
date: 2026-10-02
modified: 2026-10-07
lang: en
author: "lineesh.kumar"
description: "Webcam-only proctoring was built for a world of notes under the desk. Here are the ten methods we see today, and the controls that catch them."
categories:
  - "Exam integrity"
tags:
  - "AI cheating"
  - "Exam security"
  - "Online proctoring"
image: https://tatvaone.ai/wp-content/uploads/2026/10/cover-ai-cheating-1-1024x576.webp
word_count: 407
---

# How candidates cheat with AI in 2026, and what actually stops them

Five years ago, the threats an online exam had to handle were mostly physical: a phone in the lap, a friend in the room, notes taped to the wall. A webcam and a careful invigilator caught most of it. That is no longer the main problem.

Today the most common attempts never appear on camera. An AI assistant reads the question and drafts an answer. An overlay window sits invisibly on top of the exam. A virtual machine runs the test while help runs outside it. The candidate looks calm and focused the whole time.

## The ten threats we design for

- **AI agents** that read the screen and answer for the candidate.- **Cheatbots** that feed answers into a second window in real time.- **Browser extensions** that read and answer questions inside the page.- **Overlay apps** that draw invisible windows over the exam.- **Virtual machines** that isolate the exam from tools running outside.- **Screen manipulation**: mirrored, cast or shared screens.- **Multiple devices**: a second phone or laptop out of view.- **Identity fraud**: a proxy sits the exam.- **Behavior manipulation**: scripted movement to fool monitoring.- **Remote assistance**: someone else controls the machine.

## Why a webcam is not enough

Half of that list is invisible to a camera. Detecting it means looking at the device as well as the person: what is running, what is drawn on screen, whether the session is inside a virtual machine, and whether input is coming from somewhere else. Camera signals still matter for identity, second devices and people in the room, but they are one layer, not the whole answer.

## Detection is only half the job

Every automated detector produces false positives. A candidate looks away to think. A neighbor's television is loud. If the AI decides, honest candidates get penalized and the institution ends up defending decisions it cannot explain.

That is why we treat every AI signal as a *flag*, not a verdict. A trained proctor reviews each flag with the clip and snapshots in front of them, confirms or dismisses it, and records why. The institution receives an integrity report per candidate and makes the final call.

## What to ask any proctoring vendor

- Which of the ten threats above do you detect on the device, not just on camera?- Who reviews AI flags, and how quickly?- What evidence do we receive for each candidate, and can we use it in an appeal?- Who makes the final decision?
If the answers are vague, the results will be too. See how [Proctorly](%%TATVA_URL:proctorly%%) handles each threat.