The short answer: no single tool can prevent AI-assisted cheating. In 2026, the most defensible approach combines assessment design, clear AI-use rules, identity verification, device and environment controls, multi-signal monitoring, human review, and a fair appeals process. A lockdown browser can protect one device, but it cannot see a second phone, a hidden earpiece, a virtual camera, or an accomplice outside the webcam frame.

This guide gives universities, certification bodies, testing centers, and public-sector exam owners a practical control model. The goal is not maximum surveillance. It is proportionate security: stronger controls where a result carries greater consequences, lighter controls where accessibility and low friction matter more.

What counts as AI-assisted cheating in an online exam?

AI-assisted cheating means using a generative AI system or an AI-enabled helper in a way that violates the assessment rules and makes the submitted performance an unreliable measure of the candidate’s own knowledge or skill. The AI does not have to run on the exam computer.

  • Second-device prompting: a phone or tablet photographs questions and returns generated answers.

  • Hidden audio assistance: an earpiece relays AI-generated or human-generated answers.

  • Remote-control workflows: an accomplice or automation interacts with the exam through remote access or a virtual environment.

  • Content leakage: screen mirroring, capture hardware, or an external display exposes live exam content.

  • Undisclosed AI use: a candidate uses an allowed application or browser feature for a prohibited purpose.

  • Synthetic identity attacks: virtual cameras, replayed video, or manipulated media are used during identity checks.

Why a lockdown browser is no longer enough

A secure or lockdown browser remains useful. It can restrict tabs, shortcuts, clipboard actions, screen sharing, and prohibited applications on the managed device. But its coverage ends at the boundary of that device. Modern exam security therefore needs to distinguish between the application layer, the operating-system layer, the hardware layer, and the physical environment.

Official assessment guidance published by Ofqual in 2026 makes the same broader point from a policy perspective: vulnerability depends on task design, the assessed output, timing, supervision, and access to digital devices. Technology should support a valid assessment design rather than substitute for one.

The seven-layer security model

1. Start with assessment design and explicit AI rules

Define what AI use is permitted before choosing detection tools. A policy should answer whether candidates may use grammar tools, coding assistants, calculators, search, translation, or generative AI, and whether disclosure is required. Design tasks around the evidence you need: specific contexts, original data, intermediate work, short oral follow-ups, or supervised checkpoints can make competence easier to verify.

2. Verify identity at the right assurance level

Identity controls should match the consequence of a false result. Low-stakes practice may need only account authentication. Admissions, licensing, and professional certification may require document validation, face matching, liveness checks, and a reviewer workflow. For longer exams, verify continuity during the session instead of treating login as permanent proof that the same person remains present.

3. Protect the device and operating environment

Use a secure exam browser where appropriate, but add checks for virtual machines, remote desktop tools, prohibited processes, screen sharing, external monitors, and abnormal display paths. Hardware bypasses such as HDMI splitters can duplicate content after it leaves the operating system, which is why software-only display checks create a blind spot.

4. Cover the physical environment and second devices

A second camera can expand visibility beyond the laptop webcam. Bluetooth and peripheral signals can add context about nearby phones, smartwatches, and earpieces, but they should be interpreted as risk signals rather than automatic proof of misconduct. Strong programs correlate proximity, timing, video, audio, and device events before escalating a case.

5. Monitor multiple signals during the session

Useful signals include face presence, additional people, phone or object detection, audio anomalies, focus loss, prohibited applications, device changes, and unusual response timing. No single signal is reliable enough to decide an outcome. The value comes from a synchronized timeline that shows what happened before and after each event.

6. Keep humans responsible for consequential decisions

Automation should prioritize review, not issue a final accusation. Reviewers need access to the relevant evidence, the exam rule that may have been violated, and the context required to distinguish misconduct from poor connectivity, disability-related movement, background activity, or a technical failure. Clear thresholds and reviewer training reduce inconsistent decisions.

7. Build privacy, retention, and appeals into the workflow

Tell candidates what is collected, why it is needed, who can access it, how long it is retained, and how they can challenge a decision. Collect only the signals justified by the exam’s risk level. A defensible integrity program protects both the credential and the candidate.

A practical pre-exam checklist

  • Classify the exam as low, medium, or high stakes.

  • Publish a plain-language policy for permitted and prohibited AI use.

  • Map each integrity risk to a specific control instead of enabling every feature.

  • Test identity, camera, microphone, screen, bandwidth, and accessibility accommodations before exam day.

  • Define which events create a flag and which require human review.

  • Prepare an exception path for technical failures and candidates who cannot complete the standard workflow.

  • Set evidence access, retention, deletion, and appeals rules.

  • Run a pilot and measure false positives, support volume, completion rates, and reviewer agreement.

How TrustExam supports a layered model

TrustExam combines identity verification, AI behavioral monitoring, screen and device controls, multi-camera coverage, environment protection, and audit-ready reports. Exam owners can configure the controls by risk level and keep humans in the decision loop. Existing LMS and testing platforms can remain the primary exam interface while TrustExam provides the integrity layer.

Frequently asked questions

Can online proctoring detect ChatGPT use?

It can detect some paths used to access AI, such as prohibited applications, tab switching, remote access, a visible phone, or correlated second-device signals. It cannot prove every instance of AI use from one behavior. The most reliable approach combines preventive controls, task design, multiple signals, and human review.

Does a lockdown browser stop a second phone?

No. A lockdown browser controls the exam computer, not an independent phone or tablet. Second-camera coverage, environmental checks, Bluetooth or peripheral signals, and exam design are needed to address that risk.

Should every exam use the strictest controls?

No. Controls should be proportionate to the stakes, threat model, candidate population, legal context, and accessibility requirements. Excessive friction can reduce completion and create unfair outcomes without materially improving integrity.

Can an AI flag automatically invalidate an exam?

It should not. A flag is evidence for review, not a final verdict. Consequential decisions should be made by trained people under a documented policy with an appeal route.

Sources and further reading

Orken Rakhmatulla

Head of Education

Share