Deepfake candidates: what Gartner expects by 2028 and what a verified session changes
Gartner expects one in four candidate profiles to be fake by 2028. How a deepfake candidate works, why a call can't tell, what a verified session checks.
One in four candidate profiles fake by 2028 (Gartner, 2025). Virtual cameras, virtual audio drivers and stand-ins get past a video call. A verified session checks the devices and liveness, with consent, and a person reads the report.
Gartner expects one in four candidate profiles worldwide to be fake by 2028, and in its survey of 3,000 job candidates 6% admitted to interview fraud: posing as someone else, or having someone else pose as them. A deepfake candidate is someone whose video, audio or identity in the interview is not their own: a generated stream, a replaced face, or another person answering. A video call can't tell the difference. A verified session can see the tools that make it possible.
What does Gartner expect?
Gartner's 2025 forecast is about scale. One in four candidate profiles worldwide fake by 2028 means that a recruiter screening a hundred applications will meet twenty-five that don't describe a real person, or don't describe the person who will show up to the interview. The 6% who admit to interview fraud is a floor, not a ceiling: it counts the ones willing to say so.
The numbers matter because hiring processes are built on two assumptions: the person on video is the person on the resume, and the person who passes the interview is the person who starts on Monday. A video call checks neither.
How does a deepfake candidate work?
There are three common shapes. The first is a virtual camera: software that replaces the webcam feed with a generated or altered video, so the face on screen isn't the face in the room. The second is a virtual audio driver, which does the same with the voice. The third needs no synthesis at all: a different person takes the interview, or answers off camera while the person on video moves their lips.
All three rely on the same fact: a video call takes the camera and microphone as given. It has no way to know whether the feed comes from a physical device or from a piece of software that calls itself one.
Why can't a video call tell?
A general-purpose call sees pixels and audio samples. It doesn't see the machine. It doesn't know which devices are physical, which windows are hidden from capture, or whether a second monitor is showing an answer to someone off camera. Add-ons that live inside the call, note-takers and recorders, inherit the same blindness. They are on the wrong side of the screen.
Interviewers try to compensate by watching for lag, for eyes that read, for a voice that doesn't match the mouth. That works sometimes, and it turns the interviewer into a detective, which is a bad use of the interview and unfair to the many honest candidates with a slow connection or a nervous delivery.
What does a verified session check?
Vettasy runs the interview in a desktop application, and that changes what can be seen. Verified Session checks five things at the level of the operating system, only between the start and the end of the interview, and only after the candidate has consented in the app:
- Virtual cameras and audio drivers, the tools behind most deepfake pipelines.
- Liveness: one unobtrusive check at the start that a live person is on camera, from lighting consistency, natural movement and a response to a prompt. It is not face recognition and keeps no face template.
- Windows hidden from screen capture, which is how overlay assistants work.
- Known AI copilot processes, from a signature list updated weekly.
- A second monitor: that one is connected, and for how long. Never what is on it.
The result is a report, not a verdict. Each signal comes with a level of note or attention and a plain-language explanation that includes the harmless reasons: a streamer's virtual camera, a designer's second monitor. There is no score and no threshold. Nothing appears on either screen during the interview. A person reads the report afterwards, and both sides get the same one.
What about false positives?
A signal is not cheating, and the report says so on every line. Virtual cameras have legitimate uses. Second monitors are normal. So the candidate can dispute any signal within 14 days, with an explanation, and a Vettasy reviewer looks at the underlying data, only within the dispute and with every access logged. The outcome, confirmed, withdrawn or inconclusive, is shown to both sides. While the review is open, the signal cannot be grounds for a decision.
Dispute outcomes and the false-positive rate are published quarterly in the Trust center. We do not claim 100%. A verified session raises the cost of cheating and makes the evaluation defensible, and the signature list and the signals are updated as new schemes appear.
What changes for the honest candidate?
Verification runs in both directions. Before an employer can invite anyone, it proves that it owns its domain and provides its legal entity documents, and a person checks them within one business day. The candidate sees the verified mark on the invitation and in the app, next to a named interviewer and a date. Fake recruiters and staged "HR interviews" are a common way to steal money and personal data, and this part of the design is there to stop them.
Inside the interview, the honest candidate gets what the deepfake candidate takes away: a field where answering as yourself is enough. And afterwards, a copy of the recording, the same report as the employer, and a dispute reviewed by a person. Both sides are checked, and neither checks the other alone.
Sources
- Gartner, 31 July 2025. Gartner survey shows just 26% of job applicants trust AI will fairly evaluate them. Survey of 3,000 job candidates, second quarter of 2025.
- Vettasy, Verified Session: signals, report format and disputes.
Written by the Vettasy teamVettasy is a desktop application for job interviews. Employers run structured, recorded interviews in it with verified participants. It is free for candidates. Windows and macOS.