RefolkCandidates
10 min read

Flagged for AI Cheating: How Honest Candidates Get Swept Up

Fabric flags 35% of candidates for AI cheating and 48% in technical roles. Here is what honest job seekers trigger and how to defuse it.

Fabric's own dataset says more than one in three candidates now trips an AI-cheating flag in a live interview, and closer to one in two if the role is technical. The detectors driving those numbers run at 80 to 90% accuracy, not 99%, which means a real and growing group of honest candidates is getting bucketed with actual cheaters. If you are interviewing this quarter, you need to know exactly which signals fire and how to defuse them before "under review" becomes a silent rejection.

Why the flag rate jumped from 15% to 35% in six months

Fabric tracked over 50,000 candidates and watched its AI-cheating flag rate more than double, from 15% in June 2025 to 35% by December 2025. A follow-up study of 19,368 interviews between July 2025 and January 2026 pushed the number to 38.5% overall, with technical roles hitting 48% and sales sitting at 12%. That 4x delta by function is the shape of the story.

The mechanism is not that candidates suddenly got dishonest. Three things happened at once:

  • Cluely, Interview Coder, and other invisible overlays became genuinely undetectable on most video platforms by late 2025. Cluely quietly rebranded from "cheat on everything" to a general meeting assistant in November 2025 without changing the underlying overlay.
  • Voice-mode LLMs (ChatGPT, Gemini) crossed the latency threshold where they can answer in real time.
  • Vendors responded by stacking more signals (gaze, timing, second-screen, language) and lowering their thresholds.

The last point is where honest candidates get hurt. When a vendor tunes for the 45% of cheating that runs through dedicated tools like Cluely and Interview Coder, it also sweeps up the 18% "tab-switching" bucket, which is where a lot of legitimate behavior lives. Voice-mode LLMs account for another 34%, and live human help sits at just 3%.

35%
Candidates flagged for AI cheating by December 2025

Up from 15% in June 2025 across Fabric's 50,000-interview dataset.

What the "20+ signals" actually are, in plain English

Fabric analyzes more than 20 behavioral signals during a live interview and combines them into a cheating probability score, with anything above 40% treated as a flag. The signals fall into four buckets, and each has an honest analog that fires the same detector.

Signal bucketWhat it catches (real cheating)Honest behavior that looks identical
Gaze / eye movementReading a rendered overlay to the sideRe-reading the prompt, note-taking on paper, glancing at a second monitor
Response timingConsistent delay regardless of question difficultyTrained "take a beat" pacing, stutter, ESL processing
Second screen / tab switchingAlt-Tab to Cluely or a code editorChecking a calendar notification, opening the JD, muting Slack
Language patternsGPT-shaped phrasing, unnatural fluencyOver-prepared answers, coached vocabulary, technical jargon

Two details matter. Proctorio's own FAQ states its gaze detection only checks whether you are "looking away from the screen for an extended period of time" and explicitly does "not track precise eye movement." That is a coarse signal that misfires on anyone who thinks with their eyes off camera or takes notes on paper. Second, Fabric explicitly cites "artificial smoothness" as a tell, because a candidate reading answers off a screen skips the stutters that mark genuine thinking. Naturally fluent, over-prepared candidates now read the same as cheaters.

One vendor already saw this coming and walked away. AutoProctor built eyeball tracking into early versions, then abandoned it after concluding it "wasn't as effective as it seemed in theory" and produced a frustrating experience for honest test-takers. Fabric and Talview lead with the same signal anyway.

The junior penalty: why entry-level candidates get flagged more

Candidates with 0 to 5 years of experience cheat at nearly double the senior rate, and that base rate gets baked into the detectors, which makes an honest junior more likely to be false-positive-flagged than an honest senior. This is a Bayesian trap and worth spelling out.

If detectors are calibrated to a population where 48% of technical candidates cheat, the prior working against any given technical candidate is high. When a junior triggers a gaze anomaly, the system asks "given that half of this pool cheats, how likely is this a real signal?" The answer is: quite likely, even when the specific candidate is innocent. Karat separately estimates 80% of candidates use LLMs during code tests even when explicitly banned, and CodeSignal data shows technical assessment cheating climbed from 16% to 35% of attempts in a single year. Those numbers keep the prior high.

That matters because the entry-level software cohort is where the most desperate applicants sit. In Refolk's index, there are roughly 346,000 US software engineers on the market right now, and juniors are the group most likely to be interviewing and most likely to trip a flag they cannot see.

How many honest engineers get mis-flagged

Applying Fabric's own 3 to 5% false positive rate to a technical interview population produces the scale of the collateral damage: roughly 5,000 to 8,600 honest US software engineers get mis-flagged per 100,000 technical interviews conducted under Fabric-style detection.

Here is the math anchored on Refolk's index and Fabric's published rates:

SegmentNumberSource
US software engineers on the market~346,000Refolk index
US data analysts on the market~62,000Refolk index
US account executives / sales reps~447,000Refolk index
Technical role flag rate48%Fabric 19,368-interview study
Sales role flag rate12%Fabric 19,368-interview study
False positives per ~20K technical interviews~580 to 970 honest candidatesDerived from Fabric's 3 to 5% FPR
Sunday vs. weekday flag rate47.1% vs. 35 to 40%Fabric

The Sunday number is small but real: candidates who interview on Sundays get flagged more, possibly because home setups on weekends produce more ambient movement, worse camera angles, and more tab-switching to personal apps. If you can pick your slot, pick a weekday.

The four false-positive traps and how to defuse each one

Four honest behaviors reliably trigger AI cheating detection, and each has a specific counter-move you can rehearse before the interview. Do not wing this.

1. The gaze trap

Looking away from the camera to think is the single most common false-positive trigger. Reading text produces horizontal saccades; thinking produces inward focus, upward drift, or brief defocusing. Detectors read horizontal saccades as "reading text," which is exactly what re-reading a prompt on the same screen also looks like.

Counter-moves:

  • Position your camera dead center, not to the side. Fabric documents that side-angle cameras cause the system to misread normal movement as suspicious.
  • If you need to think, close your eyes briefly or look up, not sideways. Upward drift reads as thinking; sideways reads as reading.
  • Announce paper notes at the start: "I have a notebook to my right if I need to jot anything down." This creates a documented reason for the off-screen glance.

2. The timing flatline

Fabric's strongest tell is a consistent response delay regardless of question difficulty. If you pause 4 seconds before every answer, the detector concludes you are waiting for an LLM. Candidates trained to "take a beat before every answer" (a standard coaching tip for the last decade) now produce exactly this signature.

Counter-moves:

  • Vary your pace deliberately. Answer easy questions fast. Take longer on hard ones.
  • When you need to think, say so out loud: "Let me think through this for a second." Verbal filler breaks the flatline.
  • If you have a natural stutter or ESL processing lag, mention it up front. It becomes documented context, not an anomaly.

3. The second-screen sweep

The 18% "tab switching" bucket is where innocent people live. Checking a calendar notification, opening the job description, or Alt-Tabbing to a code editor for a live-coding question all trigger the same signal that Cluely does.

Counter-moves:

  • Full-screen the interview window. Close Slack, email, calendar, and any browser tab that will fire a notification.
  • If the interview requires a code editor, ask the interviewer explicitly: "Should I share my screen and code here, or open my local editor?" Get the answer on record.
  • Turn off dual monitors if you are not using them. A detected second display is a flag even if you never look at it.

4. The polish paradox

Being too fluent now reads as cheating. Fabric cites "artificial smoothness" as a signal, because candidates with an LLM on-screen skip the stutters and false starts that mark genuine thinking.

Counter-moves:

  • Do not memorize your STAR stories word for word. Rehearse the beats, not the script.
  • Leave in the small hesitations. "Hmm, the way I would frame that..." is a feature, not a bug.
  • If you have prepared extensively (you should), signal it: "I actually thought about this exact scenario when I prepped for the role."
The advice to interview naturally now conflicts with the advice to appear thoughtful, and the detector cannot tell them apart.

The written application is the one place you can still control

Before you ever hit the live interview, your resume and cover letter are pre-screening you into or out of the flagged pool, and that is the one part of the process where AI use is not just tolerated, it is expected. The trap is that most candidates now paste job descriptions into ChatGPT, produce a generic tailored resume, and submit something that reads exactly like every other GPT-shaped resume in the pile.

This is the specific friction Refolk takes off you. Refolk writes your resume from your actual history rather than a template, tailors it to each posting you apply to, drafts the cover letter, and scores how well you actually fit the role before you spend a week prepping for an interview you will not pass. Because the output starts from your own work history rather than generating claims from a prompt, it does not read as GPT-shaped filler.

The scoring piece matters especially for the junior software cohort. If Refolk tells you the fit is 62% and flags three weak spots, you can either fix them before applying or spend that hour on a role where you score 85%. That triage is what saves you from walking into a technical interview where the detector's prior is already stacked against you.

What to do if you have already been flagged

If you suspect you were flagged in a recent interview, the answer is not to email the recruiter demanding to see the score. You will not get it, and the request itself sounds defensive. The better move is to preempt the doubt in your follow-up.

  • Send a same-day thank-you that references two specific technical details from the conversation. This is hard to fake with an LLM in real time.
  • Offer a short, unproctored take-home or a live pairing session on a shared screen. "Happy to walk through my approach on a shared editor if that would help."
  • If you know you glanced off-camera to check notes, name it: "I referenced my notebook a couple of times, I take handwritten notes when I think through tradeoffs."

The goal is not to prove innocence, which is impossible against a black-box score. The goal is to give the hiring manager one specific reason to override the flag when they review the transcript.

48%
Flag rate in technical role interviews

Vs. 12% in sales roles, a 4x delta across Fabric's 19,368-interview study.

FAQ

How do I know if I was flagged for AI use in an interview?

You almost never will, directly. Vendors like Fabric produce a probability score with timestamped evidence that goes to the employer, not the candidate. The tells are indirect: a fast rejection with no feedback, a request for a second live technical round when one was not scheduled, or a sudden shift to a proctored take-home. If any of those happen after a live AI interview, assume the score was borderline and use the follow-up moves above.

Can I refuse to be recorded or proctored?

Practically, refusing usually ends the process. A better play is to ask up front what signals are being measured ("Is this interview using gaze or timing detection?") and adjust your setup accordingly. Knowing the system is watching for off-screen glances lets you position your notes correctly and announce them, which is a stronger move than opting out entirely.

Should I disclose that I used AI to prepare my resume or cover letter?

Only if asked, and only in the framing that AI helped you tailor and format, not write. AI-assisted preparation is expected now; AI-generated slop is not. Because Refolk builds from your actual history rather than inventing content from a prompt, the honest disclosure is straightforward: "I used a tool to tailor my resume to this posting, but the experience and results are mine." That is defensible in a way that "I asked ChatGPT to write it" is not.

Is it worth interviewing at companies that use Fabric or similar detectors?

For most candidates, yes, because you often will not know until you are in the flow. Assume any live remote interview at a tech company in 2026 is running some form of detection, and prep your setup (centered camera, closed tabs, verbalized thinking, announced notes) as a default. The candidates who lose to false positives are almost always the ones who did not know the signals existed. You now do.

Put this to work

Reading about the job search is not the job search.

Paste your career in once. I write the resume, then every week I rank the live openings against your history, tailor a resume and a cover letter to the best of them, fill in the forms if you ask me to, and keep going until you land. Your part is deciding what goes out.

  • 140+ curated roles a week, found, written, and scored for you.
  • Every bullet stays inside what your history actually supports.
  • Queued, submitted, interviewing, offer, all in one place instead of a spreadsheet.

500 free credits on sign-up. No card.

Keep reading