RefolkCandidates
10 min read

The 20-Point Suspicion Tax: Passing the Hand-Wave Test

Somos, Nominal, and BrightHire now ask for hand-waves, camera pans, and screen shares. Here is how honest remote candidates pass without getting flagged.

If you are applying to a remote role right now, an interviewer is about to ask you to wave a hand in front of your face, pan the webcam around your room, or turn your head to profile. You did not create the fraud wave that caused this, but you are about to eat the tax anyway.

The Wall Street Journal reported that Somos, Nominal, and BrightHire are running some version of these checks on every remote candidate. This piece is about paying the smallest possible version of the tax, without tripping the false-flag detectors that now sit between honest engineers, analysts, and operators and a job offer.

Why the hand-wave test suddenly exists

The hand-wave exists because consumer face-swap models lose lock when a hand crosses the face, and because 41% of large organizations have already onboarded someone who was not who they claimed to be, according to a May 2026 enterprise study from Corsound. It is not security theater. It is a specific model-failure exploit that recruiters learned about the hard way.

The mechanical story is short. Most off-the-shelf deepfake tools are trained on frontal faces. A hand across the mouth or a head yaw past roughly 45 degrees breaks the projection and the fake face glitches. In February 2026, cybersecurity company Evoke AI nearly hired a deepfake candidate who had passed multiple rounds; the tell came only when the hiring team asked the candidate to turn their head to the side and the generated face fell apart. That single incident is now baked into every "prove you're human" checklist you will encounter this fall.

The base rate justifies the checks. Fabric analyzed 19,368 live interviews and flagged 38.5% of candidates for AI-cheating behavior, a rate that tripled from 9% to 45% in three months of late 2025. Okta has detected over 6,500 cases of North Korean IT workers using fake identities to get hired at Western companies, and HR Dive reports a convincing fake candidate can be spun up in 70 minutes. In early 2025, Pindrop posted one developer opening, received 827 applications, and roughly one in eight was fake, including a candidate whose video-call face had been stitched together by deepfake software.

The 20-point suspicion tax, quantified

The suspicion tax is the gap between how often recruiters suspect AI misrepresentation and how often it actually happens: 59% minus 38.5%, or about 20 points. That gap lands on honest candidates.

Checkr surveyed 3,000 managers and found 59% suspect candidates have used AI to misrepresent themselves. Fabric's forensic review of actual interviews puts the real number at 38.5%. The difference is not noise. It is a structural over-trigger, and the reason it exists is that humans identify deepfakes with only 55.54% accuracy, barely above a coin flip. Recruiters know their gut is unreliable, so they lean on the process, and the process fires too often.

20.5 pts
Gap between suspected AI cheating (59%) and detected AI cheating (38.5%)

Roughly one in five suspicion events now lands on an honest candidate.

MetricValueSource
US recruiters and TA pros running these checks~92,413Refolk index, US titles containing "Recruiter" or "Talent Acquisition"
Managers who suspect AI misrepresentation59%Checkr survey, 3,000 managers
Live interviews actually flagged for AI cheating38.5%Fabric, 19,368 interviews
Suspicion-to-detection gap20.5 pts (1.53x)Derived from above
Human deepfake-spotting accuracy55.54%The Interview Guys, 2026
Hiring managers doing more in-person rounds39%Greenhouse
Large orgs that have already onboarded an impostor41%Corsound enterprise study, May 2026

Roughly 92,413 US recruiters and talent-acquisition pros now hold titles that make them the people running these checks on you. That is the population setting the norms for the next 12 months of remote hiring.

What each new check actually looks for

Every check on the list is looking for a specific fraud signature. Knowing the signature tells you exactly how to comply without setting off adjacent alarms.

  • Hand-wave in front of the face. Somos asks for this because face-swap models cannot track occlusion. What passes: a slow, deliberate wave, palm open, close to the face. What flags: a fast blur that looks like you are trying to hide the exact frames the model would fail on.
  • Camera pan around the room. Somos wants to see there is no second person and no second monitor feeding you answers. What passes: a smooth 360, pausing on obvious blank areas. What flags: a pan that skips a corner, or hesitation before starting.
  • Drop the virtual background. Same intent: confirm you are where you claim to be. What passes: a real room, even a messy one. What flags: asking to "keep the background for privacy," which is now read as stalling.
  • Screen share on demand. Confirms you do not have a second window with a chatbot open. What passes: one browser, one IDE, nothing else. What flags: closing tabs in real time.
  • Head turn to profile. The Evoke AI test. What passes: turning your head fully to the side and holding for two seconds. What flags: a partial turn that keeps your face mostly frontal.
  • Silent IP check. Somos recently started verifying candidate IP addresses against claimed location. There is nothing to "pass" here except: do not interview from a VPN. Turn it off before the call.
  • Tab-switching monitors. BrightHire flags tab switches during the interview, with a human reviewing the signal rather than an automated reject. What passes: one tab, full-screen. What flags: alt-tabbing to check notes, even briefly.

The honest-candidate behaviors that now read as guilty

Several habits that used to be smart interview prep are now active red flags. Rewriting them is the actual work of passing the verification tax.

  1. Looking down at notes off-camera. Eye-tracking flags downward glances. Paper notes below the webcam are no longer safe. Put notes in frame, on a single sheet, and briefly show it to the camera at the start of the call. "I have a page of notes here, wanted to flag it up front."
  2. A cheap webcam in low light. Compression artifacts and low-light noise look like generative-video artifacts. If your face has visible banding or frame-rate drops, a deepfake detector treats those as signal. Fix: a $30 clip light, a window behind the laptop, and no ceiling fan in frame.
  3. Virtual backgrounds, even branded ones. They obscure the wall behind you, which is exactly what a green-screened deepfake operator would do. Drop the background before the call starts, not when asked.
  4. Answers that are too polished. With 62% of hiring pros reporting candidates are better at faking than recruiters are at catching them, an answer that lands too cleanly raises the ceiling on suspicion. Pausing, saying "let me think," and correcting yourself mid-sentence now reads as human.
  5. Hesitating on any verification request. Somos reports candidates hanging up when asked to pan the camera, and that behavior now correlates with fraud in their internal data. Pre-decide you will comply with every reasonable check, and rehearse the motions once before the call.
  6. Interviewing from a coffee shop or coworking space. Background voices and a shared public IP address both trigger flags. If you cannot interview from home, do not interview.
The old advice was keep a cheat sheet off camera. In 2026 that cheat sheet is what gets you rejected.

The pre-interview checklist that keeps you out of the false-flag pile

Do these seven things in the ten minutes before every remote interview this fall. Every item maps to a specific detector on the other side of the call.

  1. Turn off your VPN. Confirm your IP resolves to the city on your resume.
  2. Close every browser window except the interview tab. Quit Slack, Discord, and any note app.
  3. Drop any virtual background. Tidy the visible wall behind you.
  4. Put a single sheet of paper notes in frame, upper right of the desk. Plan to show it in the first 30 seconds.
  5. Test a slow hand-wave in front of your face on the webcam preview. If it blurs badly, add light.
  6. Test a full head turn to profile. Same test: does the video hold up.
  7. Open your resume and the job description in one tab, side by side, so a screen-share request finds a tidy workspace.

That last item is where preparation compounds. Walking into a screen-share check with the exact tailored resume for the role already open, matched line by line to the posting, signals seriousness the way nothing else does. That is the work Refolk takes off you: paste the posting, get your own resume back rewritten for that specific role, with a fit score that tells you where you are actually weak before the interviewer finds it.

The in-person rollback and its geographic tax

39% of US hiring managers are now doing more in-person rounds, per Greenhouse, and that shift disproportionately taxes candidates in secondary metros. It is the hidden cost of the fraud wave nobody is naming yet.

Google, Cisco, McKinsey, and Nominal have all added or restored on-site stages. Nominal, which builds software for hardware-engineering teams and has around 220 in-office employees, will not hire until you come in person; coding tests happen on their laptop, in their office. If you live in Austin and the final round is in San Francisco, you now pay the unreimbursed travel cost that did not exist in the 2021 to 2024 remote market.

The strategic response is to be ruthless earlier in the funnel. If a company's final round requires travel you cannot afford, do not spend three weeks on their take-home. Read the interview process on the careers page before you apply, and tailor your applications toward companies whose loops actually match your geography.

Volunteer the motion before you are asked

The single best move in a 2026 remote interview is to run the verification rituals yourself, in the first 60 seconds, before anyone asks. It converts a suspicion event into a rapport event.

Try this opening: "Before we start, I know verification is a thing right now, so let me just get it out of the way." Then wave a hand in front of your face, turn your head fully to profile and back, and briefly pan the webcam across your desk. It takes eight seconds. It signals you have done this before, you are not hiding anything, and the interviewer can now spend the hour on your actual work.

Nominal co-founder Bryce Strauss framed the moment well: "The way to stand out in this moment is to be fundamentally human." The fundamentally human move is to acknowledge the elephant, do the checks, and get on with the conversation. The candidates who get flagged are the ones who treat every request as an insult. The candidates who get hired treat the ritual as routine: quick, done, back to the work.

FAQ

Should I refuse a camera pan request on privacy grounds?

No. In the current environment, refusal is treated as a positive fraud signal. Somos specifically noted that some candidates hang up when asked to pan the camera, and that behavior now correlates with fraud in their internal data. If you genuinely cannot show the room (roommate on a call, kids sleeping), say so in one sentence, offer a specific alternative like "I can show the desk and the wall behind me right now, and pan the rest after we hang up on video," and move on. Do not stall.

Are my paper notes going to get me flagged?

Only if they are off-camera. BrightHire's tools monitor tab-switching, and eye-tracking software flags repeated downward glances during answers. The workaround is to put a single page of notes in the webcam frame, on the desk, and briefly show it to the interviewer in the first minute. Once the interviewer has seen the paper, glancing at it reads as normal, not as reading answers off a hidden second monitor.

What if I have a cheap webcam and my video looks glitchy?

Fix the lighting before you replace the webcam. Compression artifacts and low-light noise are the exact signatures deepfake detectors are trained on, and humans only spot real deepfakes with 55.54% accuracy, so they lean hard on the automated flags. A $30 clip-on light in front of your face and a window behind your laptop will do more for your pass rate than a new camera. Also disable any "beauty" or "background blur" filter in Zoom, Meet, or Teams. Those filters modify your face in ways detectors flag.

How do I know if a company is running these checks before I apply?

You usually cannot, but you can infer. Companies that publish detailed interview-process pages, mention "in-person final rounds," or list vendors like Somos or BrightHire on the careers page are almost certainly running some version of this stack. Assume every remote interview at a company larger than 200 people has at least tab-switching monitoring and screen-share on demand. Prepare once, and the prep transfers to every subsequent loop.

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Keep reading