Same frame as the last two recaps before we get into it, because this is running on our public site and not everyone reading it is inside the panel.
CXR runs research panels a few times a year that is run as a small group with a closed forum over several weeks of structured async discussion on one topic, then wrapped with a closing call. This one is on candidate fraud in hiring - roughly two dozen TA leaders and heads of talent, plus a handful of identity and verification specialists to keep us honest on the tech side.
Co-facilitating with me is CXR member @Alex Murphy, CEO of JobSync, who has shaped the weekly prompts alongside me from the start. Full disclosure the same way I'd give it inside the forum: Alex and JobSync helped frame this panel, and JobSync sits in the talent tech market. Nobody on this panel is paid to participate, and in all the years CXR has run research like this, nobody ever has been. If you're interested in more on this panel and other research we've conducted, you can find the details at www.cxr.works/research.
Week 1 defined the problem (recap here). Week 2 covered detection and the gap between the tools and the playbook (recap here). Week 3 took on The AI Complication, and the biggest thing I think that it complicated was an assumption many of us carried in ourselves.
The arms race is mostly a myth
Some of us assumed this week would be about AI detectors squaring off against AI candidates. Deepfake detection versus deepfakes, bot versus bot, escalating forever.
As it turns out, that fight barely exists inside real programs today. What we heard instead, from companies at very different maturity levels, was the same lesson learned by different routes: detection tools built for this problem don't hand you verdicts, they hand you clues.
Alex has experimented with the thing everyone imagines buying, and his early findings are a useful reality check. AI designed to detect AI seems to work best on its own kind - Gemini is good at catching Gemini - and a candidate with decent editing skills and a few strict rules can fool the detector easily. His conclusion from that experimentation is that the more durable investment is a library of signals mixing AI and non-AI assessments, which his team is now taking into consideration. Slowly, and on purpose, to get it right.
The practitioners running live fraud-detection programs described the same reality from the other direction, however. The clean, automatable fraud indicator everybody wants doesn't survive contact with an actual applicant flow. An IP address pinging off a different continent could be a bad actor, a vacation, or a work eligibility question, and the sophisticated bad actors mask with VPNs anyway. What these systems produce is a pile of puzzle pieces, and somebody with judgment still has to assemble them.
Read that as bad news and you've completely missed the panel's finding. The companies furthest along have stopped asking their tools for verdicts and reorganized around the clues, routing flagged cases to a small team built for investigation while recruiters get back to recruiting. Their recruiters no longer burn hours playing detective over three applicants sharing a phone number. The system catches it, the right people run it down, and the funnel keeps moving.
If Week 2's big finding was that the tools are ahead of the playbook, Week 3 has explained to us why the playbook has to be written around people. And the realization for some that there was never a version of this where it wasn't.
Two strategies, and both of them are deliberate
The philosophical split I flagged after Week 2 came into sharper focus this week as we dug in, and the panel gave us improved language for it.
What looked at first like one camp adopting AI and another camp refusing it turns out to be a choice between two control strategies. One of our leaders described her team's position as purposely choosing a different one: they won't answer every AI risk with another AI tool, because that road ends with a second black box evaluating the output of the first, and inexplainability is a real problem when livelihoods are at stake. Their organization will build AI into its hiring system deliberately, as design, on its own timeline. The arms race is the part they're skipping.
Another leader reported that they are running the other strategy with just as much intent, deploying every approved tool she can get in what she calls a battle for quality signal. A week of direct questioning moved neither position, and I've stopped expecting it to. These are two very defensible bets. Which one fits your organization will completely depend on your risk profile, your regulatory exposure, and how much trust your TA team has already banked with legal.
That last variable turned out to be the story of the week.
The question for legal changed
Ask a room of TA leaders what legal is telling them about AI and identity tools right now and you'll get every answer at once. And @Jessica Gray at GDIT compressed it into six words: "Yes, No, and not right now." Proven tools with big customer bases get the yes. Newer tools with unknown risk get the no. Everything else waits.
But sitting with all three threads this week, the pattern that emerged wasn't about legal's answers. It was about which question the fastest-moving teams have learned to ask.
The teams stuck in place are still asking legal for permission. The teams moving are asking legal to help them build something defensible - and they're widening the room so legal isn't weighing risk alone. @Amy Ho at Adobe shared the version of this I'd encourage every TA leader to study: their AI debates kept stalling until security joined the conversation and put the other side of the ledger on the table, the risk of NOT using these tools against a threat that's already industrialized. Rather, that's what finally moved the decision.
@Sarah Smart at Appian has turned the same idea into a repeatable formula. Human-in-the-loop decision-making, a documented escalation process, auditable reporting, and a policy - when she can prove those four things, initiatives that looked stuck start getting approved. @Linellis Santiago at Land O'Lakes opens with the question itself: how can we use AI responsibly, ethically, and compliantly, rather than can we use it at all. And from the vendor we heard confirmation that the pattern holds across hundreds of enterprise deals. The buyers who get to yes work with legal on the how, and the vendors who survive that scrutiny are the ones offering candidate-controlled data, in-person off-ramps for people without smartphones, and real certifications rather than promises.
Two cautions from the week deserve a place in your notes as they came up more than a few times. First, legal may not even be your toughest reviewer - one panelist's AI-ranking evaluation ended not because legal objected but because the data protection team did, a stakeholder most TA teams haven't thought to brief. Second, if your program is global, plan on your controls not being uniform. Several companies on this panel run photo capture and identity verification on candidate consent across most regions and hit a wall in Europe, and the ones handling it well found that out during planning instead of mid-rollout.
The policies are getting written. TA isn't always holding the pen.
The third thread asked who has an actual written policy on AI use in hiring, covering candidates and their own teams. More companies have one than I expected, and that's genuinely good news across the board.
The caution however, is who's writing them. At several organizations these policies came primarily out of IT, with legal advising, and TA never had a meaningful voice - which is how you end up governed by rules like a blanket prohibition on using AI to filter or analyze resumes, written by people who've never sat in your funnel. Maybe that's the right rule in the long-run but I suspect that it isn't. Either way, if your company is drafting this policy right now, go establish a voice in those conversations. Today.
The model to study belongs to @Tom Young at IEM, and what makes it the model is that it has teeth. Their Responsible Use of AI policy routes every planned HR use through legal review, allows AI-drafted materials only when a qualified human validates the output and takes full accountability, and bars AI from making or substantially determining any final employment decision. When it launched, it paused an AI interview-recording tool his own team liked using, purely because the tool hadn't been through review yet. They ate their own cooking. I trust a policy like that.
And the best single sentence of the week came from a job posting, believe it or not. @Ryann Wingeier shared the line Assurant now puts in front of candidates: "Assurant supports the responsible use of Artificial Intelligence (AI), but we want to know the real you."
Assurant supports the responsible use of Artificial Intelligence (AI), but we want to know the real you.
Sit with how much work that one line does. It welcomes the candidate using Claude to polish a resume built on real experience, and it draws the line at fabricating a work history tailored to the job description. That's the distinction this panel landed on in Week 1 (the tool versus the misrepresentation - go back and read it) showing up three weeks later as the backbone of how companies write the actual rules. The panel called it early and it sticks.
Where Week 4 goes
What Needs to Change. Prompts are up.
We've spent three weeks on what fraud is, what you're doing about it, and how AI complicates both. Week 4 turns the panel loose on the fix - process, technology, ownership, and where responsibility should live. I'll say this much for now: some of the early responses are already poking at hiring paperwork most of us have treated as settled for decades, and that recap is going to be a fun one to write.
#CandidateFraud#leadership#Operations#solutions