The pressure to flag risky applications is real and growing. In a 2025 prediction, the analyst firm Gartner estimated that by 2028, one in four candidate profiles worldwide will be fake, driven by AI tools that make it cheap to fabricate experience, generate convincing resumes, and even stage deepfake interviews. In the same body of research, Gartner reported that 6 percent of the 3,000 job seekers it surveyed admitted to some form of interview fraud, such as posing as someone else or having a stand-in take an interview for them (Gartner, July 2025; see also HR Dive). Those numbers explain why vendors are tempted to ship a blunt "fraud detected" badge. The temptation is understandable. The product decision is still wrong.
The scale of the problem in 2025 and 2026
The numbers behind application fraud have moved faster than most hiring teams anticipated. Deepfake fraud attempts in hiring jumped 1,300 percent between 2023 and 2024, according to Pindrop's 2025 Voice Intelligence Report, and that trajectory has continued to accelerate. Research from Resume Genius found that 17 percent of hiring managers reported encountering a suspected deepfake interview by the end of 2024, up from 3 percent the previous year. Separately, GetReal Security found that 41 percent of organizations have hired a fraudulent candidate without knowing it.
The financial picture is equally stark. Reported losses from job-related fraud grew from $90 million in 2020 to over $501 million in 2024, and the broader category of recruitment fraud costs an estimated $2 billion annually worldwide, according to DISA's 2025 AI hiring fraud analysis. And in late 2025, Amazon's chief security officer disclosed that the company had blocked over 1,800 suspected North Korean applicants since April 2024, with attempts growing 27 percent quarter-over-quarter, illustrating that the threat is not limited to low-sophistication fraud rings.
What makes this landscape especially difficult for ATS vendors is that humans are unreliable detectors. Research on synthetic media shows that people identify AI-generated audio, video, and images with only around 53 percent accuracy, barely above chance. When a "fraud detected" badge carries the same visual weight as verified information, recruiters either over-rely on it or learn to ignore it. A clearly scoped integrity warning is calibrated to that reality: it prompts a human check precisely because the machine cannot be certain.
Why the language matters
Words like fake, fraud, and verified carry weight. If an ATS labels a candidate as fake, recruiters may treat that label as a decision rather than a signal. That creates legal, ethical, and candidate-experience risk, especially when the underlying evidence is probabilistic or incomplete.
Hiring data is messy. Candidates mistype profile links, change email addresses, update LinkedIn after applying, or use privacy-focused tools. A warning can be useful in those cases. A definitive fraud label is too strong.
There is also a trust cost. The same Gartner survey found that only 26 percent of job applicants trust AI to evaluate them fairly. A candidate who is wrongly stamped as fraudulent, then quietly filtered out, never learns why and never gets to respond. That is exactly the kind of opaque, machine-driven rejection that erodes confidence in an employer brand and, as the compliance section below explains, increasingly sits on the wrong side of the law.
What an integrity warning should do
A good warning answers three questions: what was noticed, why it may matter, and what the recruiter should review next. It does not replace judgment. It does not hide the reason. It does not automatically move or reject the candidate.
This makes the warning actionable. The recruiter can open the candidate profile, inspect the signal, and decide whether to ask a follow-up question, verify a profile, request a work sample, or proceed normally.
The signals that fit this model
Application integrity warnings work best for signals that are concrete and reviewable: disposable email domains, suspicious profile links, unsafe URLs, profile brand impersonation, repeated CV fingerprints, repeated application answer patterns, velocity from the same metadata, and mismatches between claimed profiles and application content.
The signal should be narrow enough to explain. "This link uses an unexpected LinkedIn-like domain" is useful. "This candidate is suspicious" is not. Specific signals make it possible for recruiters to verify or dismiss the warning quickly.
It helps to be honest about what each signal actually proves, because almost none of them prove fraud on their own:
- Disposable email domain. An address from a throwaway mail service is a recognised abuse indicator, and fraud teams treat it as a low-quality signal across sign-up flows. But it is only a signal. Plenty of legitimate, privacy-conscious people use forwarding or alias addresses, and roughly half of risky disposable domains are short-lived and cycle in and out quickly, so blocklists are never complete (analysis of 1.5M disposable-email messages). The right response is to ask for a stable contact method, not to reject.
- Look-alike profile links. A link that imitates a real LinkedIn or GitHub URL on a near-miss domain is worth a closer look, but it can also be a tracking redirect or a typo. Verify where the link actually resolves before drawing a conclusion.
- Repeated CV or answer fingerprints. The same document hash or the same free-text answers appearing across many applications can indicate a templated submission farm. It can equally be one person applying to several roles, or a popular interview-prep template. Quantity is a prompt to read, not a verdict.
- Velocity from shared metadata. A burst of applications from the same device or network fingerprint is a classic automation pattern, yet it also describes a university careers lab, a shared office, or a referral campaign. Context decides.
The pattern across all of these is the same: each signal narrows where a human should look. None of them is strong enough to substitute for that look. A warning that says exactly what was noticed lets a recruiter resolve it in seconds; a black-box "fraud score" forces them to either trust a number they cannot inspect or ignore it entirely.
How recruiters should respond
The first step is to treat the warning as a prompt, not a conclusion. Review the candidate card, open the details panel, and read the explanation. Then check the underlying material. If a link looks wrong, verify the URL. If application answers appear copied, ask for concrete examples. If the profile is inconsistent, ask the candidate to clarify the discrepancy.
Document what happened. If the warning was a false positive, the candidate should continue normally. If the verification reveals material misrepresentation, the decision should be based on the verified misrepresentation, not the warning itself.
A practical verification protocol
The training guidance from Gem and the broader industry consensus on recruiter workflows converge on a consistent sequence. It takes most recruiters under ten minutes per flagged application when the warning is specific enough to act on.
- Read the warning reason before touching anything else. Every integrity warning should state the specific signal, not a generic score. "Email domain is a known disposable service" tells a recruiter exactly where to start. A number like "fraud risk: 74" does not.
- Cross-check the candidate's stated profiles independently. Open LinkedIn, GitHub, a portfolio site, or any claimed credential in a separate browser session, not via the link in the application. Verify that the profile name, headline, and work history match what was submitted. Recently created profiles with sparse connections are a secondary signal worth noting alongside the original warning.
- Compare the resume against the application form answers. AI-generated applications often produce plausible but internally inconsistent narratives. Job titles, employment dates, and company names that differ between the resume and the form answers are a stronger indicator of synthetic content than either document alone.
- Ask one targeted clarifying question before making any decision. The Kira AI 2026 candidate screening checklist recommends framing this as a routine follow-up rather than an accusation. "Can you tell me more about your role at [Company X] and what you were responsible for day to day?" surfaces fabricated experience quickly without creating legal exposure or damaging the candidate relationship if the warning was a false positive.
- Record your decision and the reason, not just the outcome. Whether you proceed or withdraw, log the specific observation and the action taken. This audit trail is what satisfies the EU AI Act's transparency obligation and provides the documented human decision that the EEOC expects to see if a selection procedure is ever challenged.
Roles with elevated access or remote-only work arrangements warrant a higher verification threshold. The HYPR 2026 onboarding fraud guide recommends segmenting roles into trust tiers, with the highest-sensitivity positions triggering identity verification steps before an offer is extended, not after. An integrity warning on an application for a remote senior engineer role should move through a more thorough check than the same warning on an in-office junior coordinator role.
Why this is safer for compliance
Many recruiting teams are already cautious about automated decision-making. Integrity warnings fit that caution because they are advisory and reviewable. They support human oversight, provide explainable context, and avoid presenting a machine-generated signal as a final employment decision.
This is not just good manners. Three overlapping legal regimes push hiring software toward the warning-only model, and away from automated rejection.
GDPR Article 22. Under the EU and UK General Data Protection Regulation, a person has the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and the right to obtain human intervention, to express their point of view, and to contest the decision (Article 22, GDPR). Filtering out a job applicant clearly qualifies as a significant effect. Critically, a human who merely rubber-stamps the system's output does not satisfy the rule. The review has to be meaningful. An integrity warning that hands the recruiter the specific reason and leaves the decision open is built for exactly that standard; an auto-reject on a "fraud" flag is the thing the article restricts.
EU AI Act. The AI Act classifies systems used to recruit, filter applications, and evaluate candidates as high-risk under Annex III, point 4 (Annex III, EU AI Act). High-risk systems must be designed so that a person can understand, oversee, and override them, and can detect and correct errors including discriminatory patterns, under the Article 14 human-oversight requirements. The original deadline for these obligations is 2 August 2026. Note that in November 2025 the European Commission published the Digital Omnibus proposal, which would defer the high-risk compliance deadline to 2 December 2027; however, as DLA Piper's analysis of the Omnibus confirms, if that proposal is not formally adopted before 2 August 2026, the original obligations apply from that date as written. Designing for compliance now rather than betting on the deferral is the lower-risk position. A warning that explains its reasoning and keeps a human in control is aligned with that oversight duty by design.
US anti-discrimination law. In the United States, the Equal Employment Opportunity Commission has made clear that an algorithmic screening tool is a selection procedure under Title VII, and that an employer remains responsible for adverse impact even when a vendor built the tool. The EEOC also points to the four-fifths rule as a general rule of thumb for spotting adverse impact (analysis of the EEOC Title VII guidance). A "fraud detection" feature that silently removes candidates is precisely the kind of opaque selection step that invites a disparate-impact claim, because no one can show why each candidate was dropped. A logged, reviewable warning, paired with a documented human decision, is far easier to defend.
That legal direction also fits the broader pattern Treegarden uses for AI in recruitment: advisory scores, manual review, auditability, and clear language. The product helps recruiters decide where to spend attention without pretending that automation can judge candidate honesty on its own. None of the above is legal advice, and obligations vary by jurisdiction and role, so confirm specifics with your own counsel.
Sources and further reading
- Gartner: just 26% of job applicants trust AI to fairly evaluate them; 1 in 4 candidate profiles projected fake by 2028 (July 2025)
- HR Dive: By 2028, 1 in 4 candidate profiles will be fake, Gartner predicts
- Pindrop 2025 Voice Intelligence Report: deepfake fraud attempts in hiring up 1,300% from 2023 to 2024
- DISA: AI hiring fraud detection and prevention guide; recruitment fraud costs $2 billion annually worldwide
- HYPR: HR 2026 guide to identity verification and trust-tier segmentation in onboarding
- Gem: training recruiters to spot application fraud
- DLA Piper: Digital AI Omnibus - proposed deferral of high-risk AI Act obligations and current timeline
- GDPR Article 22: automated individual decision-making and the right to human intervention
- EU AI Act, Annex III: recruitment and employment systems classified as high-risk
- Mayer Brown: EEOC Title VII guidance on AI and algorithmic decision-making tools
Review applications with context
Treegarden helps recruiters manage high-volume pipelines with advisory AI, application integrity warnings, and human review built into the hiring workflow. Book a demo
Frequently Asked Questions
Why not call it fraud detection?
Because most signals are indicators, not proof. Fraud detection language can overstate certainty and create poor decisions. Integrity warning is more accurate.
Can an integrity warning reject a candidate automatically?
It should not. The safer model is warning-only, with a recruiter reviewing the signal before any decision is made.
What should be shown to recruiters?
Show a clear warning icon, a short label, and an explanation of the specific signal so the recruiter knows what to verify next.
Does auto-rejecting on a fraud flag create legal risk?
It can. GDPR Article 22 gives people the right not to be subject to a solely automated decision with significant effects and the right to human intervention, the EU AI Act treats application filtering as high-risk and requires meaningful human oversight, and the EEOC holds employers responsible for adverse impact from algorithmic selection tools. A reviewable warning with a documented human decision fits all three far better than silent automated rejection.