
A security analyst at a major platform told me something that stuck: “We stopped hunting for bots years ago. Now we hunt for anything that plays too well.” That single shift explains almost everything about modern online poker integrity systems work in 2026, and why they create as many headaches as they solve.
The old approach was straightforward. Bots left obvious fingerprints: identical timing on every decision, no deviation across thousands of hands, reaction times measured in milliseconds rather than seconds. According to Card Player Lifestyle, AI systems monitor reaction time consistency across thousands of hands because bots maintain unnaturally uniform response patterns that humans simply cannot replicate. Early detection caught these accounts easily. Outliers were visible to the naked eye in statistical analysis of hand histories.
Then cheaters adapted. Human-plus-AI hybrids emerged: a real person at the keyboard, consulting a solver between streets, feeding decisions back manually. The timing looked human. The decisions looked superhuman. Platforms needed a new architecture.
Layer One: Timing Analysis (And Why It No Longer Works Alone)
Timing analysis is still the first filter. Every click, fold, raise, and check is timestamped. The system builds a behavioral fingerprint: how long does this player take on a flop c-bet versus a river decision? Do they speed up under pressure or slow down? Do they show any variance at all?
A genuine human playing texas holdem shows messy, inconsistent timing. They tank on easy spots sometimes. They snap-fold when they should think. Bots don’t do this. Their standard deviation across decision types stays unnaturally narrow.
But timing alone stopped being sufficient once hybrid cheaters learned to inject artificial delays. A script that adds 8-22 seconds of random noise to every decision passes basic timing filters. This forced platforms to build the second layer.
Layer Two: Solver Deviation Scoring
This is where the architecture gets genuinely interesting, and genuinely problematic.
Modern platforms run every hand through a solver reference model in the background. They calculate the GTO-optimal action at each decision point, then score how closely the player’s actual choice matched that optimal line. One hand means nothing. Across 50,000 hands, a pattern emerges.
The threshold question is: at what deviation score does a player get flagged? A confirmed bot playing pure solver outputs will score near 100% accuracy. A recreational player might score 40-55%. An elite professional human player, someone who has spent years studying GTO theory, might score 72-81% on certain spot types.
This is the friction point. A hybrid cheater running real-time solver assistance might score 88-93%. But a legitimately excellent player who has deeply internalized solver logic on common spots can reach 83-87% on their best game. The gap between “world-class human” and “human using AI assistance” has narrowed to a range where statistical separation requires enormous sample sizes, and even then carries real uncertainty.
This is the gray zone. Platforms estimate that roughly 15-20% of flagged accounts sit in this ambiguous range, where the solver deviation score alone cannot confirm cheating. The detection system catches the obvious cases easily. The edge cases require the third layer.
Layer Three: Collusion Network Mapping
Machine learning algorithms scan for collusion by detecting unusual betting patterns that suggest coordinated play. But modern collusion mapping goes further than spotting two players who always fold to each other.
The system builds a graph of every account’s interaction history: who sits at the same table, how often, whether chip transfers flow in one direction over time, whether one player consistently makes exploitable folds only against a specific opponent. Isolated, each signal is ambiguous. Together, they reveal structures that no individual hand would expose.
This layer catches multi-accounting rings, chip-dumping operations, and soft-play agreements between friends. It also catches something unexpected: legitimate friend groups who play poker with friends regularly and have developed table tendencies that, statistically, resemble soft-play patterns. Two people who genuinely enjoy each other’s company at the table, who have played thousands of hands together in home games transferred online, can trigger collusion alerts through nothing but familiarity. Platforms have had to build manual review processes specifically for this scenario.
What to Do for Skilled Players Worried About False Positives
The gray zone is real, but it’s navigable. What actually matters:
- Vary your timing deliberately on spots where you’re confident. If you know your hand is a clear fold, don’t always snap it. The behavioral fingerprint benefits from noise that reflects genuine thought process variation.
- Respond promptly to platform inquiries. Accounts that cooperate with manual review, providing session logs or explaining study methods, resolve faster than those that go silent.
- Keep records of your study tools. If you use solver work offline to build your game, being able to describe your study process concretely helps security teams distinguish internalized skill from real-time assistance.
- Play on platforms with transparent review processes. GGPoker’s PokerCraft analytics system flags behavioral anomalies but routes ambiguous cases to human review teams rather than auto-banning, which matters enormously if you’re a strong player who happens to run hot on solver accuracy.
The arms race isn’t over. Platforms keep refining the thresholds; cheaters keep finding the edges of the gray zone. But understanding the three layers, timing, solver deviation, and network mapping, tells you exactly what the system is measuring and why even legitimate skill can occasionally look suspicious at scale. The best protection is still playing your game, staying consistent, and knowing what questions a security team might eventually ask.






