Overview: Most organizations that run computer-based exams still rely on a lockdown browser. Here is why that tool was built for a different problem, what it actually misses, and how to write an assessment policy that holds up.
Summarise this page with your favorite AI assistant

Battling academic dishonesty in the AI era

I spend most of my week talking to people who run assessments for a living: provosts, certification directors, and HR teams that screen thousands of applicants a year. Almost every one of them has a lockdown browser in place. Almost every one of them also suspects it is no longer doing the job. They are right, and the reason is not a flaw in any particular product. The tool was designed for a problem that stopped being the main problem about three years ago.

What a lockdown browser was built to stop

The lockdown browser emerged in the mid-2000s to address a specific and reasonable concern. A student sitting at a computer could open a second tab, search for the answer, and paste it in. So the browser was locked. No new tabs, no address bar, no copy and paste, and no switching to another window without the exam ending. Add a webcam, and you could also see whether the person at the keyboard was the person who registered.

That design assumed the threat lived inside the browser. For a long time, it did. Google was the cheating tool, and Google runs in a tab.

Where the threat lives now

AI assistance does not run in a tab. The common tools people use to cheat on an exam today run as separate applications on the same computer or on a different device entirely, and none of them ever touch the locked browser.

A candidate can run an assistant that reads what is on screen and shows answers in a small window that sits on top of everything else. To the lockdown browser, nothing has changed. No tab was opened. No window was switched. The exam is still full screen and still has focus. The overlay is drawn by the operating system, above the browser, and the browser has no way of knowing it is there.

The same is true of remote access. A second person can connect to the candidate's machine from another location, watch the screen, and type answers, while the browser reports a perfectly normal session. It is true of a virtual machine, where the entire locked environment runs inside a window on a computer that the examiner never sees. And it is true of the oldest trick of all: a phone or a second laptop sitting just out of the webcam's view. That one needs no technical skill.

I am deliberately not describing how any of this is set up. The point is not the mechanics. The point is that each of these methods shares one property: it never triggers a tab switch, a window change, or any of the events that a lockdown browser was built to catch. The browser is doing exactly what it was asked to do. It is simply looking in the wrong place.

Why the webcam only partly closes the gap

The usual response is to add video proctoring, either live or recorded with automated flags. This helps, and I would not tell anyone to remove it. But it has two limits worth being honest about.

First, a webcam sees a face and a room. It does not see software. An overlay assistant, a remote session, or a virtual machine produces no visible change in the candidate's behavior. They look at the screen. They type. A reviewer watching the recording sees a person taking an exam.

Second, the signals video can catch, such as eyes moving off screen or a head turning, are exactly the signals a prepared candidate learns to avoid. Modern assistants are designed to sit in the candidate's line of sight for that reason. The video flags that remain useful are those that catch a second device or a second person; those are real, but they are only a fraction of the problem.

What organizations can actually do

There is no single fix, and anyone who tells you there is has something to sell. But there are four approaches that work, and most organizations should be using more than one.

The first is to move high-stakes assessments back to a controlled setting. An in-person exam or a proctored testing center removes the device problem entirely. This is expensive and does not scale, which is why remote testing exists, but for the handful of assessments where the outcome carries the most weight, such as licensure, final certification, or a pre-hire technical screen that determines an offer, it is still the most reliable option available.

The second is to change what is being assessed. An exam that asks for a recall of facts is the easiest kind to outsource to an assistant. An exam that asks a candidate to reason through a scenario specific to your organization, defend a decision in their own words, or complete a task that requires context an assistant cannot have is much harder to fake. Many L&D teams have found that a short oral follow-up, even a 10-minute video call about the answers a candidate submitted, catches more than any monitoring tool, because someone who did not do the work cannot talk about it.

The third is device-level monitoring. This is a category of tools, and I run a company in it, so take that into account. The idea is to look at what is happening on the operating system during the exam, not just inside the browser: which applications are running, whether a remote session is active, whether a screen overlay is present, and whether the environment is a virtual machine. It closes the specific gap described above. It also comes with a real trade-off: the candidate has to install something, and some populations and institutions will not accept it. Therefore, it is a decision to make with eyes open, not a default.

The fourth is the one most organizations skip, and it costs nothing. Tell candidates, in plain language and in advance, what is and is not permitted, what will be monitored, and what happens if a violation is found. A large share of AI use in assessments occurs in a gray area, where the candidate is unsure whether it is allowed and decides that if no one said no, it must be fine. Clear rules, stated before the exam and acknowledged by the candidate, remove that ambiguity and, in my experience, remove a good part of the behavior.

Writing a policy that can actually be enforced

A policy is only useful if a reviewer can point to it after the fact and say, "This is what you agreed to, and this is what you did." Most assessment AI policies I read fail that test. They say something like "the use of unauthorized AI tools is prohibited," which sounds firm and means nothing, because it does not say which tools, does not say how anyone would know, and leaves "unauthorized" for a hearing panel to argue about later.

A policy that holds up does four things. It names the behavior rather than the technology: "You may not receive answers or assistance from any person, application, or device other than the exam platform during the assessment." Also, it states what is monitored, specifically, so that the monitoring is not a surprise and cannot be challenged as such. It tells the candidate what evidence would be reviewed and by whom, so the process is understood to involve a human decision rather than an automated verdict. And it requires the candidate to acknowledge all of this before the exam starts, not buried in a terms-of-service checkbox but as a distinct step.

That last point matters more than it seems. The organizations I see handle integrity cases well are not the ones with the most sophisticated detection. They are the ones where the candidate was told clearly, agreed clearly, and cannot later claim confusion. Detection tells you something happened. A good policy is one you can act on.

The honest bottom line

A lockdown browser is not broken. It still fails to prevent the thing it was built to prevent. But the thing it was built to prevent is no longer how people cheat, and continuing to treat it as the primary safeguard means the assessments an organization relies on for grades, credentials, and hiring are being protected against a threat from 2010.

The better question to ask is not "which tool should we buy" but "for each assessment we run, what is the outcome worth, and what combination of setting, design, monitoring, and policy is proportionate to that." Some exams deserve an in-person room. Others deserve a redesign. Some deserve device-level visibility. All of them deserve a policy that the candidate actually read.

About the author

Free trial
F S/M L

ScreenComply

Exam and assessment integrity software that detects AI assistants, hidden overlays, remote-access tools and second devices at the operating-system level, the layer lockdown browsers cannot see. Runs alongside your existing proctoring and LMS.

Change your privacy settings to see the content.
In order write or read comments you need to have functional cookies enabled.
You can adjust your cookie preferences here.
Share