CV fraud in 2026: how AI-written CVs broke hiring and how to verify skills again
Mike (KimonRecruit founder)
Published
AI-polished CVs have made paper screening unreliable, and outright CV fraud is industrialising. How employers can verify skills again with CV-personalised assessment.

The CV stopped being reliable evidence some time ago. In 2026 it is barely evidence at all, and the teams still screening on paper alone are making decisions on the weakest signal in their entire process. This article looks at how we got here, what CV fraud actually looks like now, and what verification has to look like to work again.
The polish problem
Start with the legal end of the spectrum, because it is the bigger one. Most CVs that reach a pipeline today have been drafted, rewritten or targeted with AI assistance. That is not cheating; candidates are using the tools available to them, and a well-written CV was always partly a writing exercise.
But it changes what a CV measures. When every application is fluent, keyword-matched to the job description and structured the way screening software likes, the differences you used to read between the lines disappear. Writing quality used to be a weak proxy for diligence. Now it is a proxy for having used the same tools as everyone else. Two CVs that read identically can sit on top of wildly different capabilities, and nothing on the page tells you which is which.
The volume effect makes it worse. Because applying is nearly free, every posted role receives more applications, each individually polished. Screening teams respond by skimming faster or by automating the skim, which rewards exactly the optimisation that created the problem.
The fraud problem
Beyond polish sits deliberate misrepresentation, and it has industrialised. The patterns employers report in 2026 include:
- Invented experience, with plausible project histories generated to match a job description, sometimes backed by coached referees.
- Credential inflation, from upgraded degree classifications to certificates from institutions that exist only as websites.
- Outsourced assessment, where the person who sits a remote test is not the person who turns up to work, or where banked test answers are simply looked up.
- Identity gaps, up to and including entirely fabricated candidates as a vector for payroll fraud or security compromise. Several security vendors and national agencies have published warnings about organised versions of this aimed at remote roles.
Each of these defeats a different traditional control. Invented experience defeats the CV read. Credential inflation defeats the certificate check. Outsourced testing defeats the generic assessment. The common thread is that every control built on documents and shared tests can be prepared against, because the artefact being checked is separable from the person being hired.
Why generic testing does not close the gap
The instinctive fix is "add a skills test", and it is half right. The problem is which test. An assessment drawn from a shared question bank inherits the same weakness as the CV: it can be prepared against, because the questions exist before the candidate does. Popular banked tests have answer communities and prep services. A candidate who memorises the bank passes the test without the skill, and a fraudulent applicant with a coached test-sitter passes it without even that.
A shared test also cannot interrogate the CV in front of it. It tells you the candidate knows the subject in general. It cannot tell you whether the specific claims you are about to pay for, the years of experience, the systems they say they ran, the level they say they operated at, are true.
Verification that starts from the claim
The way to make verification work again is to tie the test to the claim. That is the design behind CV-personalised assessment, and it is the core of how KimonRecruit works.
When a candidate applies, the platform reads their CV and generates a unique assessment probing the specific skills and experience that CV asserts, at the seniority it asserts. There is no bank to leak, no prep course to take and nothing to coach against, because the questions did not exist until the CV arrived. The output is a CV Confidence Score: a direct measure of how well the candidate's performance backs what their CV claims.
Against the fraud patterns above, this changes the economics:
- Invented experience has to survive questions generated from itself. A fabricated project history invites specific probing the author never lived through, and the gaps are visible and specific.
- Practised candidates lose their edge, because there is nothing to practise. Exposure controls and retake cooldowns limit repeat-attempt games.
- Inconsistency surfaces. When claims and performance diverge, fraud signals are flagged for human review rather than averaged into a bland overall score.
Keep a human making the call
One caution, and it is a legal one as much as an ethical one. Verification evidence is decision support, not a verdict. A fraud flag can be a misunderstanding, a nervous candidate or a reasonable-adjustment need, and treating any automated signal as an automatic gate is exactly the posture the EU AI Act, enforced for hiring systems from August 2026, and UK equality law are aimed at.
KimonRecruit is built so that cannot happen by construction. No candidate leaves a pipeline without a human recruiter making the call. Every score is replayable from the prompt, model and version that produced it, so a reviewer who doubts a result can interrogate it. Adverse-impact monitoring runs across Equality Act 2010 characteristics continuously, so the verification layer itself is watched for group-level skew. The fraud problem does not justify an unfair process; it makes a fair, evidence-based one more valuable.
What to do this quarter
If your screening still rests on CVs and a generic test, three moves close most of the gap:
- Treat the CV as a set of claims to verify, not a record to trust.
- Make the assessment bespoke to each candidate's claims, so preparation and outsourcing stop paying.
- Keep humans deciding, with evidence they can replay and monitoring that proves the process stays fair.
The CV is not coming back as evidence. The claims on it can still be tested, one candidate at a time, against the one thing that cannot be outsourced: what they can actually do.
Found this useful? Share via email. · Read more →
