If you run remote technical interviews at any scale, some share of your candidates have real-time AI assistance available, and your current process almost certainly cannot detect it.
Why your screen share shows nothing
This is the part that surprises people, and it is worth being precise about.
Operating systems provide a documented API that marks a window as excluded from screen capture. It exists for legitimate reasons — privacy overlays, presenter tools, password managers. Assistance applications use it.
The consequence: the window is fully visible to the person sitting at the machine, and entirely absent from any screen share, recording, or proctoring screenshot. The proctor is not missing it through inattention. The frame they receive genuinely does not contain it.
Meanwhile the application captures system audio — hearing your question directly from the speakers — transcribes it, generates an answer with the candidate's résumé and the job description as context, and renders it near the webcam so gaze looks natural.
Lockdown browsers cannot see this, because it is not in the browser. Browser extensions cannot see it, because they are sandboxed. Watching the candidate produces suspicion, not evidence.
Every widely-deployed assessment control was designed for a threat model where cheating meant opening another tab. That threat model is obsolete.
The full threat list
Beyond overlay assistance:
- Remote-access takeover — a confederate drives the machine while the candidate performs.
- Virtual machines — the assessment runs in a VM, assistance runs on the host.
- Second-voice coaching — someone off-camera supplying answers.
- Deepfaked candidates — real-time face replacement, so the interviewee is not the hire.
- A second device — low-tech, outside the camera frame, still effective.
Decide the policy before buying tooling
This is the step organizations skip, and it determines whether detection is even the right purchase.
Option A — permit AI, and assess for it. For many roles, skilled AI use is exactly the competency you want. Redesign the task: give a harder problem, allow the tools, and assess judgement, debugging, and the ability to evaluate what the model produced. This is a legitimate and increasingly common answer.
Option B — require unassisted work, and verify it. For roles where unaided ability genuinely matters, keep the assessment and instrument for integrity. This requires both a stated policy and technical detection.
Option C — move to work-sample and structured evidence. Weight verifiable artifacts and structured behavioural interviews more heavily, accepting that take-homes carry less signal than they used to.
The failure mode is having no policy and no detection — running an unassisted-skills assessment while it is quietly being assisted, which measures nothing and creates unfairness between candidates who use tools and those who do not.
What detection actually requires
If you choose Option B, detection has to operate where the assistance runs:
Operating-system level inspection — enumerating running processes and identifying windows marked excluded from screen capture. A capture-excluded window during an assessment is a specific, high-signal finding with very few innocent explanations.
Environment detection — remote-access sessions, virtual machines, machine fingerprinting.
Post-session analysis — deepfake and synthetic-content detection across video and audio, second-voice detection, attentiveness and secondary-device signals, identity verification against a reference.
Cohort outlier ranking — flagging candidates whose pattern is statistically unlike their peer group, to prioritize human review.
This is the problem ScreenComply.AI was built for — a desktop agent operating below the overlay layer plus browser-based post-session analysis, producing binary verdicts where the question is binary and clearly-labelled signals where it is not.
Evidence quality determines whether you can act
If you are going to withdraw an offer, the finding must survive challenge. "Behavioural anomaly score 0.72" will not. "This named process, with this hash, was running and rendering a capture-excluded window at these timestamps" will.
Keep verdicts and signals clearly separated, never act on a single weak signal, disclose monitoring before the assessment, and provide an appeals path with human review of the underlying evidence. Also build an accommodation path in advance for assistive technology, or your detection will produce discriminatory outcomes.
Frequently asked questions
Can I just watch for suspicious behaviour?
No. Gaze drift, pauses, and over-structured answers are suggestive and produce far too many false positives to support a decision, and candidates practise specifically to suppress them. Behaviour is useful as corroboration alongside technical detection, never as the basis for an accusation.
Will asking candidates to share their whole screen solve it?
No. Full-screen sharing delivers the same composited frame with capture-excluded windows already removed. You will see a clean desktop regardless of what is being displayed to the candidate.
Should we just go back to in-person interviews?
In-person removes remote-access and VM threats and narrows the others, but does not eliminate phones, watches, or earpieces. It also shrinks your candidate pool significantly. In-person on managed machines is the strongest configuration if the tradeoff is acceptable to you.
Is detecting running processes legally risky?
It depends on scope, jurisdiction, and disclosure. Signal-layer detection — which processes and windows exist, with no content capture — during a clearly bounded and previously disclosed assessment window is considerably less invasive than recording screen content. Get advice for your jurisdictions, and disclose clearly regardless.
What about take-home assignments?
Assume they are AI-assisted, because they are. Either design them so that is acceptable and assess the follow-up discussion instead, or replace them with supervised assessment. A take-home that assumes unassisted work no longer measures what it was designed to measure.
