← All guides Recruitment

AI photos on LinkedIn profiles

Generated headshots are ordinary now and say nothing about a candidate. A fabricated professional identity is the real problem, and the photo is not how you catch it.

· 9 min read · Best AI Image Detector

An AI headshot is not a warning sign. A fabricated professional identity is, and the photograph is the least useful part of detecting one: employment history, connection graph and account age carry far more signal.

Why generated headshots became normal

A professional portrait used to cost a few hundred in currency and half a day. Services that turn a handful of selfies into studio-quality headshots cost the price of a coffee and take ten minutes, and they are advertised directly to jobseekers.

The result is that a generated or heavily enhanced headshot now correlates with budget rather than with honesty. Screening on it filters for people who could afford a photographer, which is not a quality anybody intends to select for.

It also filters unevenly. Early-career candidates, people changing industries and people in countries where a studio session is expensive relative to income are exactly the group most likely to use a generated portrait, and least likely to be committing fraud.

Treating the photograph as a signal therefore fails twice: it flags a large group of legitimate people and misses the fabricated profiles that use a stolen photograph of a real person, which scores as the genuine photograph it is.

What a fabricated profile actually looks like

Recruitment fraud, credential fraud and the various forms of impersonation all share a structural weakness, and it is not the picture. It is that a professional history takes years to accumulate and cannot be generated.

Stronger signals than the headshot
  • Account age and activity A profile created last month with a decade of claimed experience.
  • Who endorses them Connections that are all recent, mutual and equally thin.
  • Employer overlap Nobody who worked at the same place at the same time is connected.
  • Written voice A summary that could describe anybody in the role.
  • External corroboration No conference talk, publication, company page or press mention anywhere.
Where the signal actually lives. The photograph is the weakest column and the one people check first.

The second row is the strongest of the five. Fabricated accounts connect to each other, so a profile whose entire network was created in the same short window is describing a cluster rather than a career.

None of this requires any image analysis at all, which is the point. A check on the headshot is a cheap addition to that work, not a substitute for it.

Where an image check does belong

Move the check from the profile photo to the documents, and it becomes genuinely useful. Right-to-work checks, proof of address and qualification certificates are all images used as evidence, and all are worth more to a fraudster than a headshot.

The pattern to look for there is a real document with one field changed, which is a region-map finding rather than a score. A wholly fabricated certificate reads hot across the whole grid; an altered name or date produces one hot tile in an otherwise cool frame.

Doing this locally matters more here than almost anywhere else on the site. Identity documents are among the most sensitive personal data an employer handles, and sending one to a third-party scoring service creates a processing relationship with its own contract and retention obligations.

Where a check is defensible in a hiring process
StageCheck the image?Why
Sourcing and outreachNoScreening on presentation, applied unevenly
Application reviewNoSame, and it affects a protected decision
ShortlistingNoNothing about the photo predicts the work
Right-to-work checkYesA recognised control, applied to everyone
Remote onboardingYesDocuments used as evidence of identity
Ongoing employmentWith careOnly where a specific concern already exists

If your own headshot gets questioned

This is becoming a real problem for people who did nothing wrong. A retouched studio portrait, a photograph taken on a recent phone in portrait mode, or an enhanced headshot can all score high, and being asked about it is uncomfortable.

The answer is the same as for any provenance question: keep the original. A camera file with intact metadata, or the receipt and the raw selfies from the service that produced the portrait, settles it faster than any argument about how detectors work.

It is also reasonable to say plainly that you used a headshot service. There is nothing to defend, and an employer who treats that as disqualifying has told you something useful about how they make decisions.

Building a policy your team can apply

The teams that handle this well have written the rule down rather than leaving it to whoever opens the application. Three decisions cover almost every case, and each takes a sentence.

Decide the stage. Image checks belong at identity verification, not at application review. Applying them earlier converts a fraud control into a screening filter, which is where both the fairness problem and the legal exposure come from.

Decide the response. A flagged document means request a better copy or move to a short video check, never a rejection. Writing that down protects the process from an individual recruiter improvising under time pressure.

Decide what is kept. The outcome of a check belongs with the right-to-work record under the same retention period. A separate log of scores against named applicants is a profiling exercise that needs its own justification and rarely has one.

The scam that targets recruiters

It is worth naming the inverse case, because it is growing. Fabricated recruiter profiles, complete with plausible headshots and company pages, are used to extract personal data and payment details from jobseekers.

The same rule applies in reverse. The photograph is not the tell; the tell is a company page created recently, a role that does not appear on the employer own careers site, and a process that asks for identity documents before any interview has happened.

The asymmetry is worth naming. A jobseeker who is wrong about a recruiter loses an opportunity. A jobseeker who is right and ignores it loses their identity documents, so the sensible default for anyone applying is to verify the employer through its own website rather than through the message that arrived.

Questions people ask

Should I be suspicious of an AI headshot?
No. Generated and enhanced professional portraits are ordinary now and cost almost nothing, so using one indicates a budget rather than a character. Screening on it penalises candidates unevenly and catches none of the fabricated profiles that use a stolen photograph of a real person.
How do I spot a fake LinkedIn profile then?
Look at the history rather than the picture. Account age against claimed experience, whether the connection graph was built in one short window, whether anybody who worked at the same employer at the same time is connected, and whether the person exists anywhere else online.
Is it legal to run detection on candidate photos?
In most jurisdictions yes, but legality is not the issue. Applying it at application stage is a screening filter with uneven effects; applying it at identity verification is a recognised control applied to everyone. Ask your own legal team about automated decision-making rules where you operate.
What about verifying identity documents?
That is where a check belongs, and the region map matters more than the score. A genuine document with one altered field shows as a single hot tile in a cool grid, while the whole-frame number stays low because most of the document is real.
My own headshot was flagged. What should I do?
Offer the original file. A camera photograph with intact metadata, or the source selfies and receipt from a headshot service, settles it directly. It is also fine to say you used a portrait service; that is ordinary and nothing to explain away.
Do recruitment scams use generated photos?
Sometimes, though stolen photographs of real people are more common because they survive a reverse image search less obviously than a generated face survives inspection. Either way the photograph is the last thing to check, well after account age and connection history.