Talview Podcast
Talview is a top-rated Gen AI-powered interviewing and proctoring platform. Talview podcasts help you to learn more about the evolving landscape of interview and proctoring, the latest trends and technologies.
Learn more about Talview at https://www.talview.com/en/
Talview Podcast
Why the Most Dangerous Cheating Now Hides Between Exams, Not Within Them | Exam Security Summit 2026 | Agentic AI Edition
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this podcast, you will explore why exam integrity can no longer be measured by a single testing session alone. The discussion examines how sophisticated cheating networks operate across multiple candidates, exams, devices, locations, and programs, often leaving few traces within an individual assessment.
The panel unpacks the shift from session-level monitoring to program-wide intelligence, highlighting the role of data forensics, pattern recognition, cross-session analysis, and ecosystem-wide signals in identifying organized misconduct. You will also hear why a clean proctoring session does not always guarantee a secure credential.
Beyond detection, the conversation tackles the ethical challenges of large-scale assessment intelligence, including privacy, transparency, candidate dignity, human accountability, and responsible data use. It is a thoughtful discussion on how the industry can strengthen trust in credentials while balancing security with fairness.
Panel details:
- Paul Muir (risr/)
- Liberty Munson (Microsoft)
- Isabelle Gonthier (PSI & ETS)
- Rajeev Menon (AI DOME)
Welcome to this panel. My name is Rajeev, and I'm a member of AI Dome, which is a coalition that we established a few months ago to bring together stakeholders and test security experts to further the idea of test integrity itself, especially in the age of agentic AI. This conversation is the AI DOMES panel at the 2026 Talvue Exam Security Summit. Let me just set a little bit of a context now. Online exams have significantly changed over the last five years. I think COVID drove us to this. It accelerated the push towards online. And there's a lot of development on the uh that's happened on the online exam itself. In parallel, there's also a bunch of development that's happened on the test security part of it. From being in-centered proctored examinations, we have progressed quite a bit and come to a situation where we have agent TKI proctors that do a lot of the signal reading, flagging, and provide a lot of insights to a human to finally then take a call about a candidate. In all this, it might seem that we've kind of sorted out the test security aspects from a session perspective. And examination bodies world across should actually feel very comfortable about it. But that's not, that doesn't seem to be the case. The worries seem to be increasing over a period of time. So what's really happening? And that when and that's what we're going to talk about in this panel. What's probably happened is, and and and I I wouldn't say probable, I think I'm I'm pretty sure what's happening here is that we focus so much on the session itself that we've kind of perfected the session. But what we've probably ignored is the fact that there's a lot of data and signal that exists across sessions, across candidates, across programs. Um, something that's used by collusion gangs, something that's used by bad actors to tap into the exam integrity itself. From uh content that gets stolen to impersonation rings that help that's sit into candidates and so on and so forth. There's a lot that's happening. And the point to notice here is that the collusion actors actually are leaving behind digital signatures, are leaving behind because they're going to be talking, they're going to do all this from the same system again and again and again. They have patterns that see that are very similar and so on and so forth. So I think what we are trying to, that what we are seeing here is that there is a there needs to be a shift from individual session focus to a much larger context in terms of across sessions, across candidates, and so on and so forth. Uh, to see the shift and to see the depth of how we go about navigating this, I'm joined on this panel by three very eminent uh uh people resources, people in the area of uh testing and security, people who don't need any introduction, to be honest. Uh Liberty from Microsoft, she's been at the forefront of how uh certifications in Microsoft have evolved over time and have really been, I've got the kind of value that it has uh in the world. Uh Paul from Riser, he's worked with a bunch of other organizations as well. He sits on the board of ATP, he's uh ATP chair this year, and therefore he comes to a vantage point of seeing this from multiple organizations' perspective all together under one roof. And Isabel from ETS and PSI, one of the largest deployers of online assessments, arguably globally. So we have a ton of experience here, and we are going to spend the next 30 minutes trying to figure out how this is the shift really happening at all? Uh, are we how and how if the shift is happening, how are we going to move and navigate across? So, without uh any further ado, let me quickly throw the question straight at SW. When a proctored session looks clean and all the data points for the session has actually gone off well, but the credential seems to have got uh uh you know issues of integrity and it comes across as the program or the say, or the entire credential has got some kind of an issue with it. Um what is really being lost there? What is the item that is getting lost there? And what would it take in terms of signals to catch it much before so that we can act on it much earlier? Yeah, no, that's a great question. The proctoring session is one piece of information. There's lots of data being collected throughout the session, but there's so many other aspects that can contribute to uh create an issue from an exam integrity standpoint. So if uh integrity is at stake here, it was probably not lost in the proctoring window. It was lost around it. So you've mentioned it earlier in the introduction. It could be that content was leaked, uh, candidates are showing up with pre-knowledge. Uh it's kind of looking at uh identity verification. When was it done? At what point in time? Registration, was there multiple checks? So the data points are really, really critical to help identify what is happening. And again, taking all of those elements of information, bringing them in together to be able to have a better, fuller, more accurate picture of what's going on. So a clean session, back to uh your point, is not doesn't necessarily mean a secure program. There's just so many different elements there. And then um, as you think about data, and obviously, you know, being a psychometrician by trade, I also like to really look at there's as mentioned the uh the data points early on before the session. There's the flags and data points collected during the session, but it's also as you sort of look at how test takers are answering, are responding to the test to the test, leveraging that data, analyzing that data as much as possible on the fly, but also post-assessment to understand what are the trends, what are the forensic indications, signals that would provide uh information in terms of there's something going on here that we need to address and we need to work on to later on minimize the impact. But I think overall, it's all about the data that are surrounding the session that we need to we need to focus on. Right, right, absolutely. And I think I think there's we've we have undermined the data quite a bit for sure, as from what you said to me. Um, liberty from a certification perspective, what does mean for the credential itself? When the breach is not inside the session, but it's much it's outside. How do then stakeholders, the the employees, the employers who depend on the credential, how do they start looking at it? What is the messaging that we're giving them uh uh to the employees and the candidates when the entire program is compromised and it's not about that one session, which seems all fine? Well, it's probably not a message we want to send, but it doesn't matter where this happens, but what's lost is validity, right? A credential is a claim about capability. If the underlying evidence uh no longer reflects the candidate's true skills, the signal breaks. And once that signal breaks at scale, downstream trust erodes. Employers, educators, and even candidates can no longer rely on what that credential represents. What's changed is that we used to equate integrity with kind of this session control. Now we have to think about it in terms of evidence of integrity over time. If learning, the preparation, or collaboration environments are compromised, a perfectly proctored section can still produce an invalid inference. So the meaning of credential kind of shifts from what happened in this exam at this moment to how confident are we in the full chain of evidence behind this performance? Right, absolutely, absolutely. And and Paul, um given the unified view that the three of us are talking about here in terms of what's moving from just looking at the session to looking at a much larger scope, uh, is that something that you're seeing, especially from the viewpoint of ATP, are you seeing this right across? Is it table stakes for the so-called collusion mafia now that you use multiple uh breakpoints right across, or is it a one-off that's it's just a fad that's going to maybe know wean off overtime? I like the idea of the mafia as well. I think I have to watch out for any horse hats in my bed or something at the end of this. But um I think one of the things it's just now, I think we keep calling it an exception. And I think the the challenge we've got is I think it's what exception is a lot of the instruments we use, they need to look inside the session. So I think we keep calling it an exception almost as like a I think as a like comfort blanket, but it's not. I think we we measure what we can see, we mistake then, I think Isabel said we we mistake the lack of evidence or absence of evidence as everything's great, and everyone goes, that's wonderful, great. And it's like, well no, we're not looking at the right place, and you know you're you're using like a torch or flashlight in the US, and actually what the problem is you're looking for something, and the problem is the person outside is hacking the grid, and that's the problem. That's the thing we're not looking at, and the thing we we don't know maybe how to deal with at the moment. We we're very happy we're looking for the, I guess, the amateur who's out there just doing something. Actually, we'll we need to change it. Actually, it's the we we catch the amateur who's doing a one-off thing. What we're maybe not getting and seeing is the professional who's actually doing a much, much more damage. And I think that's that's the the biggest challenge of currently go. Yeah, yeah, absolutely. And and it's and it's something that's evolving at a rapid pace. I mean, uh, we've seen the kind of collusion, kind of uh things that that the larger connected world can do. I mean, you don't have to be right next to a candidate. The the colluder could be, you know, the mafia could be right across the ocean somewhere, and you could still interfere in the entire examination itself. That makes it very scary. Uh, but uh Isabel, just coming, extending that same question, are you seeing this often enough in from from an ETS and PSI perspective? Are you seeing this emerging often enough uh in in in what you see? Yeah, no, we're saying what's interesting is that we're we're saying we're identifying like patterns and we're able to address the patterns in session when they we see them, when they happen. But when Paul just mentioned something that's really important is that you're gonna have those test takers that are gonna look for a way to gain in them fair advantage, but they're not necessarily gonna be super sophisticated about it. Uh, and those ones are easier to catch. But the ones that, you know, the the professional ones, the the you know, looking at the rings and the people that are doing this for a living, they basically have organized uh uh a way of taking examinations that barely leaves any trace in the moment. Um, that being said, though, those traits can be identified as you sort of step back and look at the program level. And that's where you can start seeing some patterns. You can try to look at the data across programs as well to help identify those signals that will lead to being able to uh connect with the document and identify a risk and address the risk. Um, and I'm gonna steal uh something from our chief uh security officer at ETS. He says that security does not come from tools, it comes from the orchestration. So you have multiple tools, multiple ways of addressing, of identifying, but how you put it all together is how you are able to really identify the risks and the actual signals and address them. I think that's the most important aspect, addressing the risk and protecting, adding the layers of protection to it. Oh, absolutely, absolutely. And just extending that context context, uh, I don't know if you all of you read uh very recently in India, just about a week ago, we had an entrance exam for the medical colleges, about two and a half million students who were taking the exam about three weeks ago. They've been told that the exam was completely invalid. Of course, it's a paper-based exam, the context is slightly different there, but it still involved all these collusion rings that we're talking about. People write across the chain trying to break it, to break the system. Uh it got caught, which is great, which means that the exam at the integrity of the exam itself is still managed, managed well. But imagine the pain for the test takers. They have to write the exam all over again, prepare for it all over again. It's and it breaks the trust of the candidates in the system itself. So it's very important that we identify some of these patterns and break these collusion rings because, as Paul and you say, the professional hacker is the one that we really need to work against. The individuals is still fine. I mean, I'm sure they keep getting caught because the systems are, uh session-based systems are quite good today. But the professional hackers are the ones that we really need to get into. Uh shifting gears a little bit, now that we've established that we've got to get this intelligence rather than just uh point-based session data that we're looking at. Paul, what does a program-wide intelligence really look like to you in practice? And what should the industry codify or mandate rather than just leave it to vendors and exam bodies to manage amongst themselves? Um, I think it's not a single proctoring feed. I think this is a thing. So we've talked already. It's about it's not a session, it's a cross-pattern layer, effectively. So looking at things like um items with showing abnormal response times, or where test centers or IP ranges are like potentially clustering together, we're starting to see um, you know, if candidate A or candidate B take two different exams and different centers, different days apart, but miss the same different miss the same things. It's what people always used to say to me when you know at school, it's not the cheats, the people who get the same things wrong, not the same things right. Right. And but how can we look at that across different different sessions across across the whole thing and and and and sharing those sort of impossible timelines, I guess. Um and potentially using how we can look at start building dashboards. And again, this is where it's uh this is the challenge where different programs potentially will some of these candidates could be appearing in different programs, run by different vendors, run by different owners, test owners. And I think at the moment I'm not aware of people who share data on that for many different reasons, whether that's technology or whether it's legal or that type of thing. But I think there's also another thing around with a lot how people are testing now and the amount of digital testing happening, can we share data across different testing programs, across different you know, candidate identifiers, that type of thing, to show patterns of cheating to help us try and build this, this, this, this, um, this image up for us. Um, because I think it is you're right, it's it's not just detecting it. I think detecting it is the easy part. I talked about it in Cambridge a few weeks ago that actually we've been we've been obsessed with detecting stuff. And that's not what it is anymore. We've gone beyond that. People have we can find what it's actually how we use the information we get and how we then apply that to um our test security and building that in from day one, um, not laying on laying more and more security on top of something that potentially is already broke. Right, right, right. And and and and from a if if if you were to sit in front, if if I were to make you sit in front of a dashboard for a particular credentialing program, what do you think the dashboard should give you? We spoke about a lot of these points, you know, uh multiple points that that needs to come come in as feed. But what do you want, let's say, a system that is designed to provide you as the ultimate output that will help you say, yes, this is I I can surely bet my last dollar that or last pound that this program that we're running is completely free of any encroachments. I'm gonna I'm gonna duck that. And there's there's two psychometricians on the call. I'm gonna I'm gonna look at the two of them and say yeah, no, no, I think that's fair. That's totally fair. And and I I have a few a few elements, and I'm sure Liberty will have other aspects to add to that. But um, if I think of a dashboard, for me, from my perspective, like there would be information, um, yes, as I've mentioned, on the fly, but also post-exam, looking at pass rate changes and trends, uh, looking at add-on performance drifts, looking looking at error in commons, like to kind of identify that there's potentially content that has been leaked with incorrect information, timing and anomalies. So if you look at the timing of sessions, if test makers are completing the test super quickly, that indicates that there's potentially, potentially has been pre-knowledge. So it's kind of looking at those data points that help identify that there's something that might be going on at the time of the session, but post-session as well, looking at the groups, looking at the patterns and identifying what might be the impact of liberty, what else would you be looking for? Um looking for patterns that repeat, whether it's across like attempts, locations, devices, uh cohorts, however you want to look at it, but looking for those kinds of patterns that seem I think if you just looked at looked for patterns, uh, especially if they're unexpected, but even to some extent, just look for patterns and that can be insightful that something might be going on behind the scenes. I think the biggest part of this conversation though is it can't just be a single session. Yes, we can identify stuff in a single session. We have data forensics for that and it does great, but we have to look at the whole ecosystem around like not just your program, but I I think to Paul's point, it would be super great if we could figure out how different programs could talk because these people are not showing up just for Microsoft and they're not just showing up in IT certification, they're showing up everywhere. And so because if you are if they're really smart cheaters, and I granted they're teaching, so maybe they're not, but if they're really smart, they have to know that they can only do so much within a single program at any given time. And so they're gonna create a pattern of behavior that goes that you can't see if you're just looking at your own data and kind of catching those bigger uh the more professional, the mafia, as it were. Um so that I I do think that it's just looking for patterns across the entire ecosystem. One of the things Microsoft talked about doing, but we never actually did something, was to kind of create, I'm gonna call it a security credit score uh for each candidate. And so because we we can't right now we're defaulting to uh guilty until proven innocent. But wouldn't it be great if we could be innocent until proven guilty? So we don't have any evidence the first time you take an exam and we watch you and we look at your pattern of behavior across uh administrations, and you know, if you could do it across programs even better, but then you kind of build up that credit score. And so you have you get more uh careful uh consideration factoring during an exam if as your credit score gets lower, um, and you get like, I guess, more freedom to do to be you know as your credit score gets higher. So I think it's kind of something like that, but to think about that as at a from just not beyond the one session, but a bigger session, because that's the only way you could create that infrastructure of learning to trust the people you should trust and then not trusting those who have demonstrated you shouldn't trust them. Absolutely, absolutely on that point just to pick up so I was saying about Jeeves on the point Bob raised earlier on, and I think Liberty's saying as well. This idea of data across systems and that type of thing. And yeah, there's a danger with a dashboard that you aggregate lots of data up, but all you're doing is aggregating data. It's not necessarily it might not, it might tell you a few little bits, but what we I think we need to think about it differently is about how do you apply intelligence to that data? How can you can you look for trajectories in that data? How can you actually come to a conclusion from that rather than just saying these few things added up equal a score of you know Liberty's you know, credit score idea, you know, you you've got a score of 0.87. Okay, and what does that tell me? What does that mean for that cohort of candidates? What would that mean for this next group of candidates based on the similar types of data? So it's I think aggregation versus intelligence is a is a discussion as well, or a point I think we were drifting towards, um, that we need to start to really think about because that's otherwise you've got a dashboard of of historic data that may might be sort of helpful, but probably isn't for going forward. Sure, and I think uh yeah, yeah, Liberty, please go ahead. I I just wanted to add on to that. So I I completely agree the intelligence part of it is something I just kind of assumed, but it should be stated. So I appreciate that. But the other piece of that is to actually take action. I think there's a lot of programs that feel like they can't do anything. And that just makes the problem worse because we have all this data saying people are doing things they shouldn't be doing, and then nothing happens with that information. Yeah. Yeah. I think it's important to set examples as well. Yeah. Setting deterrents is all about setting examples. And once once the the actors know that there is action that's going to happen based on anything that gets found, I think they're going to stay back as well. Uh, which brings me to another uh connected point. Are we ready for all this? Uh, for example, we spoke about cross-program intelligence. I we spoke about cross-entity intelligence and stuff like that. Are we ready for sharing that? Or are we still in the formative steps of trying to figure out where are we going with this? What what are your views from what you get from talking to others in the in the industry? I think there's appetite for it for sure. Whether we're ready for it, whether the industry, the programs are ready for it, I think that that's the key question. And I'm I'm not sure they are because I'm not sure they are ready for the implications of sharing their data and their information and thinking about the value it's going to bring to them, to their program. I think there's a lot of consideration around data protection, privacy, and so on and so forth that kind of like um would prevent from more broader sharing of the information. And it's a balancing, it's absolutely a balancing act. So we need to make sure we have the layers of protections in place to allow for that, uh, but also understand how is that data being used, who is it shared with, how it's going to be used down the road, and what's the actual impact and outcomes of that. And I think that's that's the piece we don't necessarily have fully defined, which makes the argument a little harder to make in order. To say, hey, let's kind of get all together and figure it out together. Right. Absolutely. Absolutely. And I think that gives me the right segue into the last part of this conversation, which is all about ethics and privacy and the conversations that we've had in the past in terms of AI DOM, the framework that the white paper that we created on the trust first light framework. We spoke a lot about how we have to build the guardrails, as it were. And I'll pose this question to you, Liberty. When the unit of integrity now is not the session, but much larger across the program. And the data of the candidate is not just with this respect to the session, but in relation to data that we're collecting across the program. And you're going to look at the data for a much longer period of time now. Do some of the written um statements that you've made on ethics and privacy in the session kind of session-based assessments, do those change now? Are there any creaks? Do you think that we need to rewrite what you put in there? And if that if so, does this give us an opportunity now to not just draw the lines that we should not cross, but also to kind of write it in such a way that we focus it all on the genuine test take on the candidate? And I'm trying, and I am trying to pull back to that particular point that you spoke about the security credit score, which is a very interesting point that you said. If if the past data about me or about the test that I'm going to take or about the system that I'm going to use tells me, tells you, tells the test the administrating officer that I am a low-likely candidate for fraud, do you then go easy on me in my proctoring? So this is an interesting question because I would argue if you're proctoring people with the right kind of ethics and privacy and all that stuff in place, then thinking about it from a single session is no different than thinking about it from the whole ecosystem, right? You really should only be collecting the data that truly matters to support validity. You need to be able to explain how you're making decisions. You need to make sure individuals can contest or uh correct those decisions like there's some sort of appeal process that's built into it. And then you have to make sure you're applying it consistently in a fairly across all population. So it really is like you have to make sure that you're doing all those things, whether you're looking at a single section or if you're looking at the whole ecosystem in which that session is occurring. Because at the end of the day, that's the the only way you're going to have a program that matters is that people have to trust what you're doing. And to trust, you have to be transparent. You have to be making decisions that make sense for the validity of what you're trying to demonstrate, and you have to make sure you're only collecting what you need to make those decisions. Right. And and uh if you remember in one of our earlier conversations, we spoke about a few elements of this particular trust and privacy. We spoke about minimal footprint, we spoke about human accountability, we spoke about traceable traceable evidence, and finally we spoke about candidate dignity. Do these four continue to remain the main pillars on which we all these trust statements that we that that we make in the extended view that we're looking at? Should these four be the same points, or do we see some of these points changing as well? I think they're the same. I would love to know what Paul and Isabel think, but I think that you know, if we this those four that we've talked about, this minimization of the data we're collecting to be only just what we need, being transparent, being able to explain, giving people the right uh to challenge a decision, and then just making sure everything is fair and everyone's treated equitably. Seems like there are four kind of core con uh core concepts around anything that we do when it comes to delivering an exam, uh, regardless of the program or the outcome. Right. Paul, Isabel, any views? Uh any any new additional names or new additional pillars that we need to start building for for integrity? And I would I would agree, I would agree with with what Liberty has just said, and because in the end, yes, we need to protect the integrity, but we need to make sure we have the proper guardrails around it. Uh, there's elements of fairness uh and and and uh and protection that needs to apply every step of the way. Paul, any views? Yeah, I I think it's I think having a session-wide thing help potentially helps is more ethical as well. You're building a bigger picture of someone and it's not a one-off decision. And actually, what we're starting to do is actually you're building maybe a more a balanced score or to back to back to Liberty's um you know um credit security score again. But you know, 99.9% of the candidates who do this are are ethically doing this, they're they're working hard, they're trying to get the test score for the right reason, everything. So I think having a session-wide thing wide approach to it will give the majority of test takers who are trying to do the right thing uh more comfort and probably feel less intrusive because it's not about that single moment or that two hours where you've been you feel you're being watched and everything. Actually, it's about building a program across your whole um a program of evidence across your whole work. And I think that's it's that. And I think one of the things we've talked about before, and I think we're going to be talking about at the E-Assessment Association conference in June as well, is thinking around transparency and trust around and explain and audit around how we use these things is really important now. And I think as long as you can whatever you do, whether it's session-based or s or across the whole program, how do you show that you're doing the right thing? How can you explain it? How is it auditable? How can you that's really, really important as we go. Because the perception is if you say to someone, I'm gonna watch you across your whole program, that to me actually sounds more in sounds more threatening. Actually, it's not, it's actually probably better for you that we're doing that. But that that's gonna take some careful management, I think, in terms of the industry, if we uh if we can figure out how to get that way and share this information across sessions and programs. Right. So it looks like I think we need to probably also start a bunch of educational initiatives talking about this to the industry and saying that how this is beneficial to each stakeholder there, the test taker, the uh person who's coding the exam, and so on and so forth. But uh Isabel, do you see this being difficult to operationalize? Stuff like minimal footprint. I mean, we are we now all I think it's that balance that we need to strike between what you collect from an examination and across sessions to what you really need. And uh to a to uh to an inexperienced person, it might seem that the more the merrier, the more data we have, the more analysis we can provide. But that's not necessarily the case here because there are other considerations. We need to look at the dignity of the candidate, we need to look at accountability and so on and so forth. But given given these conflicting, appearing to be conflicting points, how easy is it to implement these four things? Minimal footprint, human accountability, traceable evidence, and uh candidate dignity, how easy is it to implement that? Yeah, I think I think from our perspective, it's very easy as long as you've been consistent about it. So I think one of the things that can get in the way is like uh customization, program by program, and making sure you know everybody gets what they need. So you want a certain level of flexibility, don't get me wrong, absolutely, but the consistency of the layers and the elements you put in place helps provide um an easier way to implement, to consider, and to explain it. I think you've mentioned, I really want to highlight that, the the education, the awareness, why are we do are we collecting this information? How are we using it? What are the benefits to the program, to the test taker? How is it protecting the integrity of the process of the assessment? Because in the end, I think what you know we always always need to remember is that uh it's all about the validity of the score that is provided. Everything links back to that. Right. And and how much of this do you think should be should should should there be an industry standard for this? Or are we okay just every every awarding body trying to build this framework for their own exams? Liberty, what are your views? Is should there be an industry standard and then maybe Paul as well? I I think that's a really good question. Uh the the my brain immediately went to Microsoft's gonna want to do something different. That's the way Microsoft roles. So I think so I'm hard pressed to say like an industry standard, maybe. Uh, but it I think maybe it might be more better positioned as guidelines or something like that, just because I know Microsoft will inevitably do something that feels better that we feel is better for our candidates. And I am not in uh like so, yes, we're certifications and yes, bad things can happen if somebody uh doesn't install Azure correctly or whatever it is, a security entre, whatever. Um, but this is not a medical, like my life and death is very different than life and death for somebody who's in medical field, which is why I think that it's more guidelines than standards, because I have a lot more, I have more tolerance for risk than other programs might. So you're saying create a base minimum kind of a guideline and then allow each exam to adopt based on their uh requirements, is what you say. Yeah. Right, right. Great, great. Awesome. Paul, any final comments? Yeah. Yeah, I was gonna I was gonna is it challenge the right word slightly, but I I think it's whether um there's a danger that obviously each security, let's say a security vendor, you know, someone's got s has got a got a program to sell or software to sell, potentially define a threat very differently. So depending on who you are, they will define it. So actually, do we actually if we're gonna get anywhere, we need to maybe actually come to maybe this is where ATP's role comes in or somewhat similar body is to say what stop allowing vendors to define the threat differently or between each other, because actually then all you're doing is creating loopholes potentially for people to actually exploit. So can we come up with something actually um we can agree that you know a threat to I don't know eye movement or a threat from certain other things around in things, actually, this is what it looks like. This is this is what the standard or guideline at this point looks like, rather than letting each vendor say this is what a threat should look like, because otherwise then you're just you're you're using security as a as a um almost like a as a tool of competition. And I don't think that's right because they'll say, Oh, you know, X program lets you do this, but Y program it doesn't pick up on that. It's like okay, well so I think that's a that's a big thing to if we're gonna start going this road of program-wide, it's we have to start looking at actually what is a threat and what do we believe a threat looks like. And there's lots of people I think we have the opportunity within places like ATP and other organizations where we can actually have that discussion openly because we do that, we have those in this and and say, is that something we want to do? Is that something we want to progress? And because a lot of the people who do these have these discussions, have their own software, are members of organizations like that. Let's have the discussion. Right, right, absolutely. And I think the more clear we are, the less confusion there is, and less confusion there is, the more trust in the system, actually. So I think that from that perspective, creating that the broad guidelines, as Liberty said, is something that we should probably try to attempt. Great. Now that you've established that, and we I know we come to the end of this session, we established that moving from a session-based focus to a program-wide focus is very, very critical. Uh, one statement from each of you. Uh what should the industry or or the key stakeholders not do in 2026? Uh, considering the seriousness of how we want to change from a single session to a program-wide focus. What should they not be doing? Who wants to go first? I would say don't look at data in isolation. It's all about the trance, it's all about the connecting pieces. And if you want to get the best picture possible, make the connections, use the information you have, uh, and don't isolate. So don't look at data in isolation. Great, great point. Paul, what what is your edict? Um mine wasn't be around, it's sort of session and thing, but it's sort of stop trust stop treating a clean session as proof of integrity, we said earlier on. And and it's and not just because it sounds like a we've talked about it and we said why, but actually it's what the ad it's what our I'll call it enemies are looking for us to do. They're looking it's easy for them to defend and to work around a single point or a session, but if we can stop doing that and stop treating a session as a single as a clean session as a proof of integrity, then it's not half the battle one, but we're we're we're going in the right right direction. So that would be my point. Absolutely, absolutely. Liberty, what is your one leg? Uh don't trade transparency for sophistication. I think we uh have a tendency to over-engineer solutions, especially in this space. And we do that at the risk of transparency and really understanding the decisions we're making and why we made them. If we can't explain it, we've kind of done damage. We've done we've done more bad than good. Great, wonderful, wonderful. Great insights from all the three of you. And I'm happy that we had this 30-minute quick session. What's clearly established is that we we are moving from a session-based focus to a program-based focus. Uh, there's a bunch of stuff that we need to do in the assessment world. And AI Dome kind of bodies like AIDOM actually help you to kind of build the basic bulwark for uh some of these things to move forward. What I also want to leave the audience here is the fact that this is not just theory that we're talking. There are organizations, for example, Talvue that's already built something called AIOP, the uh intelligence operations platform, assessment intelligence operations platform, which looks at multiple, which is beginning to look at multi-session intelligence. And it's not just Talvue, there are other bodies as well building it, but it's still a few. We need more uh awarding bodies, more vendors to start building these frameworks and move the focus from single session to the larger program at focus to ensure that the larger collision rings, that's the starting premise that we had. We need to break those collision rings. We need to make the test-taking experience secure, safe for organizations and for the stakeholders. Uh, thank you so much for this particular time. This is our AI DOME's presentation at the at the Talview Exam Security Summit. Thank you so much.