The New Era of RPO: Why Candidate Fraud is Reshaping Hiring Contracts.
How deepfake interviews and synthetic candidates are reshaping the trust equation between employers and their recruiting partners

For years, the RPO conversation has centered on speed, cost, and scale. But a new, less comfortable topic has moved to the top of the agenda in boardrooms and on LinkedIn feeds alike: can you trust the person on the other side of the interview screen?
As AI adoption accelerates across talent acquisition, so does a very real counter-narrative — AI is not just improving hiring; it's also being weaponized to defeat it. Deepfake interviews, synthetic identities, and proxy candidates are no longer edge cases. They are becoming a mainstream risk category that is actively reshaping how RPO contracts are written for 2026 and 2027.
The Numbers Are Bigger Than Most Employers Realize
The data emerging over the past year paints a stark picture:
Deepfake fraud attempts in hiring jumped roughly 1,300% year-over-year, according to Pindrop and Sherlock AI research cited across multiple 2026 industry reports.
An analysis of over 19,000 AI-powered interviews found that 38.5% of candidates were flagged for AI-cheating behavior, with the flag rate tripling from 9% to 45% in a single three-month stretch in late 2025 (Fabric, 2026).
98% of HR executives say they have encountered candidate fraud, yet automated security controls routinely fail to catch it — 68% of fraudulent hires are only uncovered through human observation and intuition, according to new HYPR Identity Assurance research released this month.
For 42% of organizations, hiring fraud isn't caught until after day one of employment, and by then, most fake hires have already received active corporate credentials and network access.
Gartner has projected that 1 in 4 job candidates worldwide could be fake by 2028 — a number that seemed alarmist a year ago and now reads as conservative given current trend lines.
On the financial side, nearly a quarter of companies report losing more than $50,000 USD to hiring fraud in a single year, with some losses exceeding $100,000 USD (Checkr, 2026).
A once fringe IT security problem is now a talent acquisition problem, and it sits squarely in RPO territory because RPO providers are the ones running the pipelines where this fraud enters.
Regulation Is Catching Up, Fast
Regulators are moving quickly to demand transparency in both directions — protecting candidates from opaque AI decision-making and protecting employers from AI-enabled deception.
Key developments shaping 2026-2027 contracts include:
The EU AI Act (Annex III) classifies hiring algorithms as "high-risk," with obligations — risk assessments, technical documentation, bias testing, human oversight, and transparency disclosures — phasing in through August 2026, backed by penalties of up to €15M or 3% of global annual turnover.
New York City's Local Law 144 requires annual bias audits and candidate notices before automated employment decision tools are used.
California and Colorado have introduced their own AI hiring rules effective in 2026.
New disclosure laws increasingly require employers to tell applicants before automated technology helps decide on them — and to explain, in plain language, what role that technology played if a candidate is rejected.
The upshot: RPO providers can no longer treat AI tooling as a black box. Clients are demanding to know exactly what AI is doing in their pipeline, why, and who is accountable when it gets something wrong — or gets fooled.
What This Means for RPO Contracts Going Forward
Industry researchers, including the RPO Association's own buyer trends reporting, note that "candidate fraud has become a material risk" and that "employer expectations around AI have grown more specific and more demanding." In practice, that's translating into a new generation of RPO contract language:
1. Identity verification as a contractual requirement, not an add-on.
Liveness detection, document authentication, and multi-point identity checks are moving from optional vendor features to baseline expectations, integrated at the application stage rather than just before onboarding.
2. Explicit AI use disclosure clauses.
Clients want to know which AI tools are touching candidate data, how, and where — mirroring the broader enterprise AI procurement trend toward disclosure obligations, audit rights, and sub-processor transparency.
3. Clear ownership of fraud detection and escalation.
Contracts increasingly specify who is responsible for flagging suspected synthetic candidates, how evidence is preserved, and which party (RPO provider, client HR, client security/legal) owns the final call — closing the "ownership void" that current research shows leaves 53% of pre-hire identity risk sitting with HR teams who often lack the tools to manage it.
4. Human-in-the-loop accountability.
Given that the majority of fraud is still caught by human intuition rather than automated systems, RPO agreements are building in mandatory human review checkpoints at key stages — not just AI-driven screening — with documented rationale for hiring decisions.
5. Liability and indemnification language for AI-driven errors.
As with broader enterprise AI contracting trends, RPO agreements are starting to explicitly allocate responsibility when AI tools produce biased outcomes, miss fraud, or make decisions that trigger regulatory scrutiny.
Why This Matters More for RPO Than In-House Teams
When an RPO provider owns the hiring pipeline, it inherits the risk that comes with it. A synthetic candidate who slips through an RPO-managed process doesn't just become an internal HR embarrassment — it becomes a contractual, reputational, and potentially legal exposure for the client who trusted their recruiting function to an outside partner.
That's exactly why sophisticated buyers are pushing this level of specificity into their RPO agreements now, rather than waiting for a costly incident to force the issue.
Building Fraud-Aware, Accountable Recruiting Into the Partnership
The organizations getting this right aren't the ones bolting on a single deepfake-detection tool and calling it solved. They're the ones building fraud awareness and AI accountability into the architecture of the recruiting process itself — identity verification at intake, documented human oversight at every critical decision point, transparent AI use across the candidate journey, and clear lines of ownership when something looks wrong.
That's the standard we hold ourselves to at Emerge Talent. Our RPO partnerships are built around rigorous verification protocols, transparent use of AI in sourcing and screening, and human accountability at the decision points that matter most — so our clients get the speed and scale RPO promises without inheriting the risks that come with an unaccountable process.
Not sure where your current pipeline is exposed? Book a 15-minute compliance review with our team, and we'll walk through your specific risks and needs. Start at emergetalent.com/rpo.
Sources referenced: HYPR Identity Assurance research (2026), Checkr State of Screening Compliance Report (2026), Fabric candidate fraud analysis (2026), Gartner candidate fraud projections, Pindrop/Sherlock AI deepfake fraud data, EU AI Act Annex III requirements, NYC Local Law 144, and RPO Association 2026 Buyer Trends Report.






