
Key takeaways
• 2020-era online proctoring is broken. Second-device ChatGPT, on-screen overlays like Cluely, AI glasses, and voice clones that need a few seconds of audio all post-date the camera-on-face vendors. Honorlock and Proctorio are patching, not rebuilding.
• Hybrid AI + human review is the defensible 2026 architecture. AI-only catches the obvious and false-flags everyone else. Live-human doesn’t scale past a few thousand sessions a month. Hybrid, where AI surfaces the top few percent of moments to a trained reviewer, is what the EU AI Act high-risk regime points you toward.
• Stop trying to detect AI text. It doesn’t work. A 2023 study across seven detectors found a mean ~61% false-positive rate on essays by non-native English writers. OpenAI retired its own detector. Shift to authorial attestation, draft history, and behavioural signals.
• The EU AI Act classifies proctoring as high-risk, and the clock moved. Annex III §3(d) names student-monitoring AI outright. The Digital Omnibus (agreed May 2026) pushed high-risk obligations to 2 December 2027; transparency duties still bite from August 2026. The duties weren’t simplified, and conformity work takes months.
• A custom proctoring MVP ships in 18–22 weeks at $260–$420k. Browser lockdown + WebRTC capture + an AI flagging pipeline + a reviewer queue + a court-ready audit trail. Vertical certification bodies (finance, health, language) are the highest-margin buyer.
Why Fora Soft wrote this playbook
Fora Soft builds video, real-time, and EdTech products, and has since 2005: 250+ projects, 50 in-house engineers, a 100% Upwork success score. Assessment and proctored-exam features run through a chunk of that work. BrainCert (an EdTech client at $3M ARR in 2024, 58% year-over-year, 100,000+ customers and 500M+ classroom minutes) runs proctored certification flows; Scholarly and the assessment engines behind our AI quiz-generation work fill out the picture. Our e-learning development team has shipped this category more than once.
Across 2024–2026 we audited two proctoring products in pre-acquisition diligence and built a custom proctoring stack for a financial-certification body. The patterns here come from those engagements plus primary sources: the EU AI Act Annex III text, the 2023 Honorlock and ProctorU filings, the peer-reviewed benchmarks of AI-text detectors, the WCAG accessibility floor, and the 2025–2026 wave of device-based cheating that the UK exam regulator has started reporting on.
If you’re a certification body modernising a remote-exam stack, an online university trying to escape Honorlock or Proctorio, or a corporate L&D team rolling out compliance training that has to survive an audit, this guide gives you the architecture, the failure modes, the privacy reality, and the shipping plan we use with our own clients. One scope note: proctoring protects the integrity of a student’s assessment, which is a different job from watching the teaching itself. That’s classroom observation software.
Building a proctoring platform that survives the EU AI Act?
Send your exam volume, jurisdictions, and current vendor (or none). We’ll return a one-page architecture, an EU AI Act gap analysis, and an 18-week shipping plan — free.
What is online proctoring
Online proctoring is software that supervises a remote exam to keep it honest: verifying who’s taking the test, watching or recording the session, locking down the device, and flagging behaviour that suggests cheating. It replaces the human invigilator walking a physical exam hall. Four shapes exist: a live human watching over video, AI-only automated review, browser lockdown with no camera, and a hybrid where AI flags moments and a person judges them.
The category matters because the credential matters. A CFA charter, a nursing licence, an IELTS-style language score, a university degree. Each is worth money and trust, so each attracts cheating, and each carries legal weight if the process is unfair. That double bind, catch the cheats and wrong nobody, is the whole design problem, and it got harder the moment a phone could answer any question in seconds.
The 2026 cheating crisis
From 2014 to 2022 proctoring was a stable oligopoly. Honorlock, Proctorio, ProctorU and Respondus owned higher-ed; ETS and Pearson VUE owned the high-stakes test-centre market. The architecture was simple: camera on face, screen recording, browser lockdown, post-hoc review of flagged moments. Then ChatGPT shipped in November 2022 and one assumption broke: that the work in front of the student was the student’s. Here’s what changed.
1. Generative AI on a second device. Proctored laptop in front, phone with ChatGPT under the desk. Eye-tracking catches a blatant look-down pattern; it doesn’t catch a student who memorises the question, glances down once, and types. Multi-device cheating became the default failure mode, and the camera never sees it.
2. On-screen AI overlays. Cluely launched in April 2025 — a startup founded by an ex-Columbia student, backed by roughly $15M from a16z — selling an on-screen assistant it markets as invisible to screen-share and screen recording. When the cheat lives in the same monitor the proctor watches through, screen capture stops being evidence. A cluster of counter-detection startups appeared within weeks.
3. AI glasses and invisible earpieces. Meta sold more than seven million smart glasses in 2025. The UK exam regulator Ofqual warned in June 2026 after 2,225 device-related malpractice cases in summer 2025 — 44.3% of all recorded misconduct. Vision-and-audio cheating moved onto the candidate’s face, where a webcam looking at that same face can’t distinguish glasses from glasses.
4. Real-time voice clones. In 2024 real-time cloning needed about 30 seconds of sample audio. By 2026 it needs three to fifteen seconds, often zero-shot, with sub-200-millisecond streaming replies. Audio-based detection has to assume the assistant is silent or sub-audible, not that it’s a second voice in the room.
5. AI-text detection collapsed. Liang and colleagues (Patterns, 2023) tested seven commercial detectors and found a mean ~61% false-positive rate on TOEFL essays by non-native English writers, versus near-zero for native writers. Turnitin said its score shouldn’t be the sole basis for an integrity finding. OpenAI retired its own classifier in July 2023 after it caught only 26% of AI text. The arms race is lost; stop fighting it.
6. Student trust collapsed. “How to defeat Proctorio” workflows are a search away. Once a generation has watched those videos, the deterrence value of camera-on-face is gone. The system buyers now want is one students don’t actively try to beat — which means redesigning the assessment, not just the surveillance.

Figure 1. The camera-on-face model never sees the phone, the overlay, the glasses, or the earpiece.
Four ways to proctor a remote exam
Every modern remote-proctoring deployment is one of four shapes, or a blend of them. Each trades cost against scale, deterrence, privacy exposure, and how cleanly it fits the EU AI Act. Read the shapes before you architect anything — the wrong one is expensive to unwind.

Figure 2. Same job, four cost, scale and compliance profiles. Pick by stakes and volume.
Approach 1: live human proctor
How it works. A trained proctor watches one to twelve test-takers in real time over WebRTC video, audio and shared screen. They can pause the exam, ask for a room re-scan, or intervene. This is ProctorU Live+ and most high-stakes professional-certification flows.
Strengths. Strongest deterrent. Court-ready trail with a named proctor. Flexes around accessibility accommodations and unusual environments without algorithmic bias.
Limits. Cost of $15–$40 per exam. Scheduling friction. It doesn’t scale past roughly 1,000 concurrent exams without a proctor workforce no startup can hire. Proctor consistency varies shift to shift.
Reach for live human proctor when: the exam is high-stakes (board licensure, financial certification, immigration language test), volume is under about 5,000 sessions a month, and the per-session cost fits inside the test fee.
Approach 2: AI-only automated
How it works. The session records. AI runs face-presence, gaze, audio, second-person and second-device detectors. Flags issue automatically, sometimes triggering a warning, a termination, or a post-hoc human look. No reviewer sits in the live loop.
Strengths. Cheap, around $5–$15 per exam. Scales to any volume. Available 24/7 with no staff scheduling. It was the default for LMS-integrated proctoring through 2020–2022.
Limits. False-positive rates of 15–30% are common. Documented bias against dark-skinned candidates, neurodivergent test-takers, and candidates in religious head coverings. And it’s the shape EU regulators single out: proctoring is high-risk under Annex III, and a system with no human in the loop that fires automated adverse actions is the hardest version to defend. The Digital Omnibus moved the compliance deadline; it didn’t bless AI-only adjudication.
Reach for AI-only when: stakes are low (formative quizzes, training-completion checks), the result is non-binding, and you can show a regulator the AI flag is informational only, with no automated adverse action.
Approach 3: browser lockdown only
How it works. A dedicated browser (Safe Exam Browser, Respondus LockDown Browser) takes over the OS for the exam — disabling alt-tab, screenshots, screen sharing, virtual machines and common bypass utilities. No camera, no microphone.
Strengths. Lowest privacy cost — zero biometric data collected. Cheap (well under a dollar per exam, mostly licensing). Works offline. Strong against copy-paste, screen recording and alt-tab cheating.
Limits. Useless against a second device, voice clones or AI glasses. The phone in the lap does whatever it wants. Lockdown stops local cheating, not the room.
Reach for browser lockdown only when: the assessment is closed-book and short, you want zero biometric collection, and you accept that second-device cheating will leak. Pair it with question-pool randomisation and time pressure to blunt a phone lookup.
Approach 4: hybrid AI and human review
How it works. The session records under lockdown. AI scans it near real time, ranks suspicious moments, and surfaces the top 3–8% to a trained reviewer queue. The reviewer marks each moment confirmed, dismissed, or inconclusive. A confirmed flag opens an institutional integrity process — never an automatic termination.
Strengths. EU AI Act high-risk fits by design, because the human-oversight loop is built in. False-positive cost drops toward zero because no automated adverse action ever fires. Cost of $10–$25 per exam sits between AI-only and live human, and it scales because reviewers see only a few percent of moments.
Limits. Highest engineering investment. Reviewer training never stops. Quality rides on ranking precision — if the AI surfaces junk, the queue becomes noise and reviewers tune out.
Reach for hybrid AI and human review when: stakes are medium-to-high, volume is over about 5,000 sessions a month, and you touch any EU jurisdiction. This is the architecture we recommend for nine of ten 2026 proctoring builds.
Escaping Honorlock or Proctorio?
We’ll audit your current vendor, list the EU AI Act gaps, and scope a migration that keeps your accreditation intact. Free 30-minute call.
AI cheating detection signals
The AI layer in a hybrid stack is a flagger, not a judge. Treat it as a search engine over the recording that surfaces the top suspicious moments to a human. These are the signals that earn their place in 2026.
1. Off-screen object detection. A YOLO-class detector on every Nth frame catches phones, second laptops, and paper notes entering view. A false positive on a hand resting on the desk is cheap; a missed phone is expensive. Tune for high recall, accept the false-positive rate, let the reviewer dismiss.
2. Multi-voice audio detection. Speaker-diarisation pipelines — pyannote.audio 3.1, NVIDIA NeMo — flag when a second voice appears for longer than a threshold. Transcription (Whisper, or NVIDIA Parakeet, which topped the open ASR leaderboard in 2025) lets the transcript itself flag phrases like “what’s question seven.” This is also where earpiece-assistant detection lives, since the assistant is occasionally semi-audible.
3. Gaze-pattern change. Head-pose plus gaze over time. Best practice in 2026 is not to flag individual glances (the bias risk is too high) but to flag pattern shifts: a candidate stable for ten minutes who suddenly develops a five-second downward look every thirty seconds is worth a reviewer’s time.
4. Keystroke and paste dynamics. Sudden changes in typing rhythm, paste events on essay questions, mouse movement that doesn’t match a human distribution. These are strongest on coding exams, where a paste of hundreds of tokens with no preceding typing is a bright line.
5. Network and device fingerprinting. The same physical device used by two test-takers an hour apart. Two simultaneous sessions from one IP. VPN or proxy signatures. These are cheap, accurate, and effectively impossible to bias against a protected group, so keep them on always. Building the AI layer well is where our AI integration team spends most of its time.

Figure 3. The AI layer ranks moments; a human makes every adverse decision. That rule keeps you out of court.
Stop detecting AI-written essays
AI-text detectors aren’t reliable enough to base an integrity finding on. The 2023 seven-detector study measured a ~61% false-positive rate against non-native English writers; Turnitin walked back its own claims; OpenAI shut its classifier. So don’t buy the arms race. Change the assessment. Five patterns actually defend integrity in 2026.
1. Authorial attestation with draft history. Students write inside a tracked editor that records keystrokes, pauses and revisions. Pasted blocks with no preceding edits get flagged. The audit trail is the evidence, not a probability score.
2. Oral defence of written work. A five-minute recorded follow-up where the student explains a section of their own essay. AI can’t do that on demand, and the cost of cheating jumps from “ten seconds of ChatGPT” to “weeks of impersonation practice.”
3. Personalised problem variants. Each student gets a unique parameterised version — student-specific numbers on a maths exam, student-specific datasets on a programming one. The cheating tool now has to be told the variant, which is friction.
4. Mastery-based progression instead of point-in-time exams. If the credential reflects ten interactions over six weeks, no single ChatGPT session fakes it. That’s the mastery-learning thesis applied to credentialing — see our AI tutor and adaptive-learning playbook for the model that supports it, and the wider e-learning platform it slots into.
5. Honour codes plus narrow detection. Students cheat less when the policy is explicit, the assessment feels fair, and the surveillance is light but credible. A 2024 University of Maryland study found honour-code campuses with hybrid proctoring saw less cheating than camera-only campuses with no honour code. Trust, oddly, out-performs the microscope.
Privacy and the EU AI Act
Privacy stopped being a soft constraint on proctoring; it’s the gate for market access. Five regimes apply in parallel, and the first one is the reason so many vendors are scrambling.
1. EU AI Act high-risk (Annex III, Article 6). Annex III §3(d) names “AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests.” That’s proctoring, explicitly. The Digital Omnibus — agreed by the Council and Parliament on 7 May 2026 — pushed high-risk Annex III obligations from 2 August 2026 to 2 December 2027 (embedded Annex I systems move to August 2028). But the Article 50 transparency duties still apply from August 2026 (the Article 4 AI-literacy duty has applied since February 2025), and the obligations themselves weren’t simplified: risk-management system, data governance, technical documentation, human oversight, accuracy and resilience testing, cybersecurity, conformity assessment, post-market monitoring, and a Fundamental Rights Impact Assessment where required. The deadline moved; the work didn’t shrink. Conformity takes months, so treat it as a fixed line item, not an afterthought.
2. GDPR special-category data. Face and voice are biometric data under Article 9. Lawful basis is consent or substantial public interest. Keep data in the EU. Honour erasure within 30 days. A Data Protection Impact Assessment is mandatory before launch — the same discipline we walk through for regulated video in our HIPAA and SOC 2 guide.
3. US state biometric laws. Illinois BIPA is the dangerous one: statutory damages of $1,000 (negligent) and $5,000 (intentional) per violation, plus a private right of action. Illinois SB2979 (August 2024) changed accrual to a single per-person recovery, curbing the per-scan theory from Cothron v. White Castle (2023) — but the exposure is still real. ProctorU, after a 2020 breach of roughly 444,000 users, and Respondus have both faced BIPA suits. Get explicit informed consent at registration, not at exam start.
4. The Fourth Amendment and room scans. In Ogletree v. Cleveland State University (N.D. Ohio, August 2022) a judge ruled a pre-exam room scan violated the Fourth Amendment; the vendors were Respondus and Honorlock. The ruling was vacated on appeal in 2023 on procedural grounds, so it’s not binding precedent — but it tells you exactly where the next plaintiff aims. Design the room-scan flow as consented, minimal, and reviewable.
5. FERPA and accessibility. Under FERPA the institution is the controller and the vendor is a school official: no advertising use, no third-party sharing without parent consent for under-18s. And accessibility is law, not polish. WCAG 2.2 AA is the latest version (2023), though the EU’s EN 301 549 and the US ADA Title II rule still cite 2.1 AA, and the European Accessibility Act took effect on 28 June 2025. Keyboard navigation across the lockdown shell, a screen-reader-compatible reviewer console, and an accommodation flow that never discloses a disability to the AI flagger. Our NFR checklist maps the full surface.

Figure 4. Classification is settled; the Digital Omnibus moved the deadline to December 2027, not the duty.
Reference architecture
A hybrid AI and human-review stack has six layers, each with a clear failure mode and a clear owner, all sitting under one compliance umbrella.

Figure 5. The six-layer hybrid stack we ship, with EU AI Act, GDPR, BIPA, FERPA and WCAG as one umbrella.
Lockdown shell. Safe Exam Browser for the open-source path; a custom Electron shell when you need deep OS hooks (USB device blocking, virtual-machine detection). Disable alt-tab, screenshots, screen sharing, parallel windows and common bypass utilities.
Live capture. A WebRTC SFU (mediasoup or LiveKit) ingests camera, mic and screen. Recording is server-side, a single canonical artefact, not browser-side, which is a tampering risk. AV1 for storage efficiency at scale, H.264 as fallback; the trade-offs are in our AV1 production playbook, and the SFU patterns in our WebRTC architecture guide. This is the layer our video engineering team lives in.
AI flagging. The recording streams into a worker pool. Object detection on every Nth frame, diarisation on the audio, gaze analysis. Each detector emits timestamped moments with confidence scores, and a ranker produces the top-N suspicious moments per session.
Reviewer queue. Trained reviewers watch the 30–90 seconds around each surfaced moment with the AI’s reasoning visible, and mark it confirmed, dismissed, or inconclusive. Target productivity is 60–90 reviewed moments per reviewer-hour.
Audit trail. Every flag, dismissal and decision is logged with a cryptographic hash chain. The artefact has to hold up in a university hearing, an immigration appeal, or a certification-body review — plan for at least seven years of retention.
Integrity workflow. A confirmed flag triggers the institutional process — instructor notice, a student response window, an appeal. Never an automated termination, never an automated zero. The system surfaces evidence; humans adjudicate.
Honorlock vs Proctorio vs Respondus vs custom
The vendor market is also consolidating: Meazure Learning (ProctorU plus Yardstick) acquired Examity in September 2023, so “independent” choice is thinner than the logos suggest. Prices below are per-exam retail estimates for 2026; the custom row is your own operate cost per exam-hour, which is a different unit; see the cost section.
| Vendor / approach | Approach | EU AI Act fit | Typical cost | When to pick |
|---|---|---|---|---|
| Honorlock | AI plus on-demand human | Retrofit needed | $8–$15 / exam | US higher-ed, no EU exposure |
| Proctorio | AI-only Chrome extension | Hard — no human loop | $5–$12 / exam | Low-stakes formative quizzes |
| ProctorU Live+ | Live human | Compliant | $15–$40 / exam | High-stakes, low volume |
| Respondus LockDown | Browser lockdown only | No biometrics, low risk | Under $1 / exam | Low-stakes plus question-pool |
| Safe Exam Browser (OSS) | Open-source lockdown | Compliant baseline | $0 | Build-your-own foundation |
| Custom (hybrid AI + human) | Full hybrid stack | Compliant by design | $2–$4 / exam-hr to operate | Cert bodies, EU exposure, high volume |
What it costs to build and run
Two numbers decide build-versus-buy: the one-time build and the per-exam-hour operate cost. Keep them separate from vendor retail pricing, which bundles margin.
Build — an 18–22 week MVP. A team of five: senior backend, senior video/WebRTC, ML engineer, frontend/lockdown-shell, product designer. Weeks 1–4, lockdown shell (SEB integration or custom Electron). Weeks 5–9, WebRTC capture, server-side recording, the audit-trail spine. Weeks 10–14, the AI flagging pipeline, ranker and reviewer console. Weeks 15–18, integrity workflow, EU AI Act documentation, accessibility, beta. Weeks 19–22, conformity assessment, hardening, GA. Total $260–$420k depending on geography and seniority; with pattern reuse and agent-assisted engineering we usually land nearer the lower end.
Operate — per exam-hour. AI-flagging compute on Hetzner GPU instances runs roughly $0.40–$0.80. Seven-year recording storage on S3-compatible object storage amortises to $0.20–$0.50. Reviewer cost, assuming 8% of moments surfaced and 60–90 reviews per reviewer-hour at $25 fully loaded, is $0.40–$1.20. SFU and bandwidth add $0.10–$0.30. Total: $1.50–$4 per exam-hour.
Worked example. Take a certification body running 30,000 proctored exams a year, two hours each — 60,000 exam-hours. Licensing a hybrid vendor at $12 per exam is 30,000 × $12 = $360,000 a year. Operating your own hybrid stack at $2.10 per exam-hour is 60,000 × $2.10 = $126,000 a year. The $234,000 annual gap pays back a $300,000 build in about 15 months, and every year after is margin. Below roughly 10,000 exams a year the maths flips and you should license, not build.
Mini case: a certification body
A financial-certification body came to us in 2024 running 30,000 proctored exams a year on Honorlock. Two problems pressed at once: candidate complaints about false flags were eating their ombudsman’s budget, and a planned EU launch meant the AI Act high-risk regime was coming for them. Their internal audit had found a 12% verified-cheating rate in 2023, which they suspected undercounted badly, because AI-only flagging missed the multi-device pattern that had become dominant.
The 22-week build. Weeks 1–4, a custom Electron lockdown shell with USB monitoring and virtual-machine detection that SEB didn’t cover for their legacy clients. Weeks 5–9, WebRTC ingestion on mediasoup, server-side recording in AV1, a hash-chained audit log. Weeks 10–14, five detectors (object, multi-voice, gaze, keystroke, network) feeding a ranker that surfaced the top 5% of moments. Weeks 15–18, a reviewer console with an EU-resident review pool wired into their case-management system. Weeks 19–22, EU AI Act technical documentation, a conformity dry-run, an accessibility audit, and a two-cohort soft launch.
Outcome. In the first quarter of operation the verified-cheating catch rate rose from 12% to 30% (+18 points), driven by the multi-voice and network-fingerprint detectors Honorlock didn’t offer. False-positive load, measured by ombudsman complaints, fell 64%, because the human-review loop sanity-checked every flag before a candidate saw an adverse action. Per-exam operate cost landed at $2.10, well under the break-even from their existing fee schedule. Book a 30-min call for a similar audit of your stack.
A decision framework in five questions
Q1. What are the stakes? A formative quiz with no consequences? AI-only or lockdown is fine. Licensure, certification, an immigration language test? Hybrid AI and human review, or live human only.
Q2. Any EU exposure? One candidate resident in an EU member state and Annex III high-risk applies. Budget the conformity work and the Fundamental Rights Impact Assessment as fixed line items, and start early. December 2027 sounds far away until you cost the documentation.
Q3. What volume? Under about 5,000 sessions a month, live human is viable. Past that, hybrid is effectively mandatory because reviewer headcount becomes the bottleneck.
Q4. Can the assessment be redesigned? Authorial attestation, oral defence, mastery progression and personalised variants cut cheating at the design level. The cheapest defence is a smarter assessment, not more surveillance.
Q5. What’s your trust posture? A university with a vocal student body? Pure AI-only will trigger backlash whatever its accuracy. Hybrid plus a transparent appeal repairs the trust camera-only spent.
Pitfalls to avoid
1. Trusting AI-text detectors. They aren’t reliable enough to be the basis for any integrity finding. Stop, and restructure the assessment instead.
2. Automated adverse action from an AI flag. The fastest route to a class action is auto-terminating an exam on an AI signal. Every adverse action goes through a human reviewer and an institutional process. No exceptions.
3. Skipping bias testing. Run the flaggers against a test set covering skin tone, head coverings, neurodivergent patterns and low-bandwidth environments, and document the results. The EU AI Act requires it, ethics requires it, and litigation will eventually require it.
4. Browser-side recording. The canonical artefact has to be produced server-side. A candidate-controlled recording is tampering-vulnerable and won’t survive a hearing.
5. Bolting on accessibility late. WCAG 2.2 AA across the lockdown shell, the candidate flow and the reviewer console, with an accommodation path that never discloses a disability to the AI. Retrofitting it after launch costs more than building it in.
When not to build custom
Custom is the wrong call more often than vendors admit. Build only when the economics or the compliance surface justify it. Skip it in these cases.
Low stakes, low volume. A few thousand low-consequence exams a year? Respondus LockDown or Safe Exam Browser plus question randomisation is cheaper and faster than anything custom, and nobody will sue you over a formative quiz.
No EU exposure and a short runway. Every candidate US-based and you need to ship this quarter? An off-the-shelf US vendor gets you live faster. Revisit custom when EU jurisdictions or high-stakes volume actually arrive.
No reviewer capacity. Hybrid only works if you can staff and train a review pool. Without it you fall back to AI-only — and you should buy that, not build it.
The real problem is assessment design. If your exam is a closed-book recall test any phone defeats, no surveillance stack fixes it. Redesign the assessment first; it’s cheaper than any proctoring build, and it’s the one fix cheating tools can’t route around. If you’re unsure which camp you’re in, that’s a good thing to spend 30 minutes on with someone who’s shipped both.
KPIs to measure
Quality KPIs. Verified-cheating catch rate on a known-positive control set (target at least 25%). False-positive rate by reviewer dismissals (under 10% of surfaced flags). Bias delta across protected groups under 3 points. Reviewer adjudication time per moment under 90 seconds.
Business KPIs. Operate cost per exam-hour under $4. Candidate NPS above 25 (proctoring is a hated category; positive is a win). Institutional renewal above 90%. Time from suspected violation to resolution under 14 days.
Reliability KPIs. 99.95% session-completion during peak windows. Recording success above 99.9%. Audit-trail integrity verified by hash-chain validation on every release. Reviewer-queue median latency under 15 minutes from flag to first review.
FAQ
Is Honorlock or Proctorio still safe to use in 2026?
In US-only, low-stakes deployments, yes, if you accept the false-positive overhead. For high-stakes exams or any EU exposure, both need a human-review loop retrofitted onto architectures that weren’t designed for one. The Digital Omnibus bought time to December 2027, but it’s a deadline shift, not a pass.
Can AI reliably detect ChatGPT-written essays?
No. A 2023 study across seven detectors found a mean ~61% false-positive rate on essays by non-native English writers, and OpenAI retired its own classifier after it caught just 26% of AI text. Use authorial attestation, draft history, oral defence, or mastery-based progression instead.
What does EU AI Act high-risk classification require, and when?
Proctoring is high-risk under Annex III §3(d). The obligations — risk-management system, data governance, technical documentation, human oversight, conformity assessment, post-market monitoring, and a Fundamental Rights Impact Assessment where required — now apply from 2 December 2027 after the Digital Omnibus, while transparency duties apply from August 2026. The duties weren’t simplified, so start the documentation early.
How do you stop second-device and AI-glasses cheating?
No single signal does it. Combine gaze-pattern flagging, network and device fingerprinting, a consented room-scan at start, and assessment redesign (personalised variants, time pressure on closed-book sections, oral defence on essays). Glasses and earpieces are the 2026 frontier: treat them as an audio and behavioural problem, not a webcam one.
How long does a custom proctoring MVP take to ship?
18–22 weeks at $260–$420k with a team of five: senior backend, senior video/WebRTC, ML engineer, frontend/lockdown-shell, product designer. That covers browser lockdown, WebRTC capture, the AI flagging pipeline, reviewer console, audit trail, EU AI Act documentation, and a two-cohort beta.
Safe Exam Browser or a custom lockdown shell?
Safe Exam Browser is the right baseline for around 80% of deployments: open source, mature, cross-OS. Build a custom Electron shell when you need OS-level features SEB lacks (USB blocking, deeper VM detection, DRM hooks for licensed content) or a single-installer footprint with your brand.
How do we avoid biometric-privacy lawsuits?
Bias-test every flagger across skin tone, head coverings, neurodivergent patterns and low-bandwidth environments before launch, and republish annually. Never auto-action on an AI signal alone. Provide an explicit appeal. Get informed consent at registration with the biometric-processing scope listed — under Illinois BIPA the damages are $1,000 to $5,000 per violation.
How long must we retain proctoring recordings?
It depends on jurisdiction and credential type. US higher-ed is typically 5–7 years per academic-integrity policy; professional certifications 7–10 years. GDPR’s right to erasure interacts with this — document the legal basis for retention and answer deletion requests within 30 days unless a litigation hold overrides.
What to read next
E-learning
E-Learning Platform Pillar
The platform layer this proctoring slots into.
AI Tutor
AI Tutors and Adaptive Learning
Mastery-based progression as an integrity strategy.
Compliance
HIPAA + SOC 2 Compliance
The compliance discipline in regulated video.
NFR
NFR Checklist
Accessibility, audit and retention requirements.
Codec
AV1 in Production
Storage-efficient recording for long audit retention.
Ready to ship 2026-grade proctoring?
The 2020-era vendors were architected before ChatGPT, before on-screen overlays and AI glasses, before the EU AI Act named proctoring high-risk, before the lawsuits forced a rethink of camera-only surveillance. Retrofitting human review onto a Chrome extension isn’t the same as designing for hybrid AI and human review from the first commit. Custom is on the table for buyers who refuse to ship a stack that only catches yesterday’s cheating.
A custom MVP ships in 18–22 weeks at $260–$420k: six layers — lockdown shell, WebRTC capture, AI flagging, reviewer queue, tamper-evident audit, integrity workflow — under one compliance umbrella, with EU AI Act documentation as a line item, not an afterthought. Vertical certification bodies are the highest-margin buyer, and that’s where we’ve shipped the most.
Want a 22-week proctoring shipping plan?
Send your exam volume, jurisdictions, and current vendor (or none). We’ll return an architecture, an EU AI Act gap analysis, and a cost forecast in 48 hours — free.
