If you suspect a candidate may be a deepfake during a video interview, you can start by asking them to turn their head slowly toward profile, wave a hand across their face, or change the lighting in the room. Real-time deepfakes struggle with all of that, and a synthetic face tends to slip or tear at the edges. Listen for lip-sync lag, and check identity again in later rounds, not just the first.
Quick checks during a video interview:
- Watch for lip-sync lag.
- Compare the face lighting with the room.
- Look for tearing around the face, ears, or glasses.
- Ask for a slow head turn.
- Ask the candidate to pass a hand across their face.
- Re-verify identity in later rounds.
Identity and document checks run before the conversation, and they catch what leaves a paper trail. A deepfake leaves nothing to check until the interview is underway, so it has to be caught inside the conversation itself. Our guide to detecting fake candidates covers how those two layers work together.
Why deepfake job interviews are increasing
Deepfake interviews are getting more common and easier to pull off. In a 2025 Greenhouse survey of 1,236 recruiters and hiring managers across the US, UK, Ireland, and Germany, 18% said they’d caught applicants using AI deceptively by showing up as deepfakes. It’s a vendor survey, not a census, so it should be read as what hiring teams report encountering, not a rate among applicants.
In addition, the cost of producing a deepfake has collapsed: Palo Alto’s Unit 42 had a researcher with no image-manipulation experience build a passable real-time interview deepfake in about 70 minutes on cheap, widely available consumer hardware.
What is a deepfake interview, and how it differs from a proxy
In a deepfake interview, software maps a synthetic face, and often a modified voice, onto a live video feed running on the candidate’s own machine. The operator speaks and moves normally. The face and voice are replaced on their machine, before the video ever reaches you.
That’s different from an AI-enhanced photograph on a profile or an identity document, which is a problem at the application and sourcing stage and is caught by document checks, reverse image searches, and monitoring for AI-modified profile pictures (per Google’s Mandiant team).
It’s also different from a proxy interview, where a second real person sits the call, either coaching from off camera or answering as the applicant. The outcome is the same — the person you assessed isn’t the person you’d hire — but the checks that catch them are different.
Current deepfakes tend to degrade under motion, occlusion (anything passing in front of the face), and changing light, so the tests below force those conditions. They are not reliable catches on their own. A well-built fake, or one running on better hardware, can survive all of them.
A proxy interview survives all of them, because there’s nothing synthetic to break. Passing these tests rules out an obvious fake, not a real person pretending to be someone else.
How to detect a deepfake in a video interview
Tell the candidate you’re checking for deepfakes and why. These checks look for signs of synthetic manipulation; they don’t confirm identity on their own. Run them consistently rather than singling anyone out, and pair them with identity verification against information already on file.
The most reliable approach is a set of challenge-response prompts: instead of watching and hoping to notice something, you ask the candidate to do something the software renders badly, and watch how it holds up.
Signs of a deepfake on camera
Microsoft’s threat-intelligence team (writing about the group it tracks as Jasper Sleet) and Palo Alto’s Unit 42 (who built a real-time fake themselves) arrived at the same set of visual tells:
- temporal inconsistency during rapid movement
- occlusion failures when an object passes over the face
- lighting that doesn’t match the scene
- exaggerated expressions
- edge artifacts such as tearing or pixelation around the face, eyes, ears, and glasses
Audio often drifts before video does. Microsoft’s list includes audio-visual sync lag, and documents operators using voice-changing software — so a voice that sounds slightly processed is easy to write off as a bad microphone.
A poor connection produces similar artifacts, and glasses and awkward lighting are ordinary features of ordinary interviews. Each signal is a reason to look closer, not grounds on its own for a decision.
Challenge-response prompts to use in the call
- Ask for a slow head turn toward profile. Real-time face replacement is trained mostly on front-facing views, so a near-profile angle is where it degrades first. Watch the hairline and jaw as they turn.
- Ask them to pass a hand in front of their face. The FBI recommends this one specifically in its guidance to employers, because it can trigger a malfunction in AI-generated video. Watch the overlap where the hand and face meet.
- Ask them to change the lighting, or move nearer a window. A sudden change in light is one of the conditions Unit 42 found most reliably stressed the fake it built.
- Ask them to hold something up beside their face, like a notebook or a mug. This is the occlusion test Microsoft describes, and the failure is easy to spot.
- Ask an unplanned follow-up about a detail from their claimed history. This tests identity rather than rendering; see our guide to detecting fake candidates.
None of these criteria is hard evidence. A candidate on a weak connection, or a nervous one, will produce something odd on at least one. A failed check means slowing down — a second interviewer on the next round, identity confirmed through a channel the candidate didn’t supply, a closer look at the recording — rather than rejection.
Can you detect a deepfake just by watching?
Not reliably, which is why the checks above ask the candidate to do something, rather than asking the interviewer to notice something. People are consistently poor at catching synthetic video by eye, and better at confirming something real than flagging something fake.
The studies say the same thing from different angles. Viewers shown a high-quality deepfake among real videos, with no warning, noticed something odd no more often than a control group who saw only real ones (32.9% vs 34.1%; Lewis et al., 2023). Asked to judge directly, 1,901 viewers correctly identified 75% of real videos but only 50% of the deepfakes (Pehlivanoglu et al., 2026). Groh et al. (2022) found the same asymmetry: 75% vs 57%.
Even when people know fakes are present, it doesn’t help much. Köbis et al. (2021) told participants outright that half the videos were fake; they still answered “authentic” 67.4% of the time, and neither a warning about harms nor a cash bonus improved their accuracy.
Richer media does help. A 2024 study of political-speech deepfakes saw accuracy climb from 57% on a transcript to 85% with video and audio together, and a live two-way conversation is richer still. But no published study measures how a trained interviewer performs against a real-time deepfake in a hiring conversation. Every result above uses prerecorded clips, non-expert viewers, and an artificial 50/50 mix. A real interviewer faces far fewer fakes, no warning, and a conversation to run at the same time.
How reliable is deepfake detection software?
Software that watches a video call for signs of manipulation exists, it’s improving, and it catches things a person watching in real time won’t. It still hands you a signal, not an answer. Treat a deepfake flag as proof and an honest candidate gets rejected over a rendering artifact; ignore flags because the software is imperfect and a fraudulent candidate goes through.
Detection-accuracy figures in this market are self-reported by the companies selling the detection, and we haven’t found an independent evaluation supporting a market-wide accuracy claim.
A full stack of checks can still be beaten. KnowBe4 — a security-awareness training company — published an account of hiring a North Korean operator in 2024: résumé reviewed, four video interviews conducted, background and reference checks run, candidate hired, and malware on the workstation as soon as it arrived. The person used a real but stolen US identity and an AI-enhanced image.
How to build deepfake checks into your hiring process
What to watch for around the call
The signals around the call are often easier to catch than the ones in it. Mandiant’s guidance to employers covers checking whether a contact number is VoIP, confirming a candidate’s claimed location matches other evidence, and comparing what’s on screen against their online profiles and identity documents.
Australia’s government advisory on North Korean IT workers, updated February 2026, names fake personas, stolen identities, forged documents, and face-swap filters among its red flags. Answers that sound generated, long pauses, and eyes tracking something off screen are a different problem.
Where to focus first
Start where exposure is highest. Screening interviews carry the most risk: volume is high, scrutiny is thin, and it’s often one recruiter on a short call with many more booked behind it. Interview rounds come next. Identity is almost never re-checked after the first round, and the sunk cost by that point is largest.
Who decides when a flag fires
Decide in advance who reviews a flag and who makes the final call. That decision usually spans recruiting, security, and legal, and in most teams no one has written it down. Without that, the first real flag turns into a three-way call about who’s supposed to act, while the candidate moves to the next round.
Consent and compliance
Checking faces and voices raises consent and biometric questions, and several US states regulate it specifically. Tell candidates you’re running these checks, apply them consistently, and confirm what notice and consent your jurisdiction requires.
Detecting deepfakes in live interviews with BrightHire
One person watching one call in real time will miss things. Give them less to catch live and more to review afterward.
BrightHire surfaces candidate fraud signals directly from AI screening interviews and live interviews, with reviewable evidence attached — location mismatches, unusual answer patterns, and video inconsistencies. Deepfake detection is available directly inside live interviews on Zoom.
None of that makes an interview fraud-proof. A recorded, reviewable two-way conversation changes something narrower: the judgment no longer has to happen in real time, by one person, once. A second reviewer can go back to the moment a signal fired and look at it properly.
BrightHire’s AI surfaces signal, and people make the decision. A fraud flag never removes a candidate from consideration and never auto-rejects anyone. It’s a reason for a person to look at the evidence and decide.
Questions about deepfake candidates
Can a deepfake pass a job interview?
Yes — there’s a documented case. KnowBe4 conducted four video interviews, ran background and reference checks, and hired a North Korean operator using a stolen US identity and an AI-enhanced image.
What should you ask a candidate to do if you suspect a deepfake?
Use challenge-response prompts: a slow head turn toward profile, a hand passed in front of the face, and a change in lighting — see the checks above. The FBI recommends the hand test specifically. None is proof on its own.
Can you spot a deepfake just by watching the video?
Not reliably. With no warning, viewers notice something odd no more often than people watching only real videos (32.9% vs 34.1%, Lewis et al.); asked directly, they catch only 50% of deepfakes while clearing 75% of real videos (Pehlivanoglu et al.). No published study yet measures a trained interviewer against a real-time deepfake in a live hiring conversation.
If a different person shows up for a later round, would you catch it?
Only if you look. Identity is usually verified once, then assumed — exactly the gap a proxy or sustained deepfake exploits. Re-verify between rounds and compare behavior across them. A proxy passes all the motion tests, so it needs different checks.
Do you have to tell candidates you’re checking for deepfakes?
In several jurisdictions, yes, and disclosure is good practice everywhere. Rules on notice, consent, and biometric data vary by state and country.
Will you know during the interview, or only afterward?
Some signals surface during the call, some after. Relying on live alerts depends on one person catching one thing in one moment — what the research says people are worst at. A recorded conversation a second person can review is the more dependable control.
What do you do when a signal fires?
Slow down rather than stop. Confirm identity through a channel the candidate didn’t supply, put a second interviewer on the next round, and route it to whoever owns the decision.





