Almost every assumption baked into modern online training was made before generative AI existed. The SCORM specification, which still underpins the majority of corporate e-learning, was finalized in the early 2000s. The xAPI standard that succeeded it was designed in the early 2010s. Video-based courseware, click-through quizzes, completion certificates, the entire LMS architecture — all of it was built around a quiet, unspoken premise: a human being is sitting at the screen. In 2026, that premise no longer holds. AI agents can log in, watch videos at 10x speed, answer multiple-choice questions with near-perfect accuracy, generate plausible free-text responses, and produce a clean completion record indistinguishable from one a real employee would generate. The infrastructure of online training was designed for a world that does not exist anymore.
The Pre-AI Assumptions Hiding in Plain Sight
Open any LMS admin panel and you'll find an architecture built on three load-bearing assumptions that all predate generative AI. First: a login event corresponds to a human. Second: time-on-page is a reasonable proxy for attention. Third: passing a quiz is evidence that learning occurred. None of this was ever truly secure — it was tolerated. In 2005, no one really knew who was sitting at the keyboard either. But the tools to exploit that gap at scale didn't exist. Committing training fraud meant finding a human willing to sit through hours of content for someone else — slow, expensive, and hard to industrialize. The identity gap was a latent weakness, not a systemic one. Generative AI changed that overnight. A bot can produce a login event. An AI agent can hold a tab open for the prescribed duration. A large language model can pass almost any compliance quiz on the first attempt without ever processing the underlying material. The standards weren't wrong when they were written — they were written for a threat model where industrial-scale fraud was impractical. That threat model is gone. The standards haven't caught up.
SCORM and xAPI: Beautiful Specs for the Wrong Era
SCORM 2004 and xAPI are remarkable engineering achievements. They standardized how courseware reports progress, how learning records are stored, how training content moves between systems. But read the specifications carefully and you'll notice what they do not specify: any mechanism whatsoever for verifying that the entity producing the learning record is human. The completion code, the suspend data, the statement actor — all of it assumes good faith. SCORM was designed for a world where the cost of cheating was high (you had to physically find a co-worker to take your course) and the value was modest (an hour saved). Generative AI inverts both sides of that equation: cheating is now free, and at scale it can save organizations thousands of hours of payroll. The spec never anticipated that asymmetry.
Video Courses Were Built to Be Watched, Not Verified
The dominant content format in corporate compliance training is the narrated video module. It exists because in the pre-AI era, sitting through a video was a reasonable proxy for engagement — a human paying enough attention to absorb the message. Today that proxy is meaningless. An AI agent can play the video in a hidden tab while the employee does something else. A browser script can mark the video as watched without playing it at all. More fundamentally, even when a human does sit through the video, there is no mechanism inside the video player itself that verifies which human is watching. The format was never designed to answer that question because in 2008, no one needed to ask it.
Click-Through Compliance and the Death of the Quiz
The multiple-choice quiz at the end of a compliance module is the last line of defense in most online training. It was supposed to confirm comprehension. In practice, it confirms nothing. Modern LLMs score above 90% on virtually every commercially available compliance quiz on the first attempt — without ever being shown the course content. They infer the answer from the question itself, from the structure of regulated language, from millions of similar examples in their training data. The quiz, as a verification mechanism, is dead. It worked when the only entity capable of answering the question was a human who had either learned the material or guessed lucky. Neither condition is necessary anymore.
The LMS Was Designed to Track Activity, Not Identity
Step back from any individual format and you'll see the deeper problem. The Learning Management System — the architectural center of corporate training — was built as an activity tracker. It logs enrollments, completions, quiz scores, time-on-task. It was never built as an identity verification system. There is no learner-verification layer. No continuous presence check. No tamper-proof session evidence. The LMS trusts the session token and reports what the session token does. In 2010, that was sufficient because the cost of compromising a session token was higher than the value of a fake completion. In 2026, that calculation has flipped completely. The LMS is now an honest reporter of dishonest data.
Why the Industry Hasn't Caught Up
If the architecture is so clearly broken, why hasn't it been replaced? Three reasons. First, switching costs. Organizations have decades of SCORM content, integrations, and reporting workflows built around the existing model. Second, the incentive misalignment. Training vendors are paid for completions, not for verification — every additional integrity check is a friction point that depresses the metric they're measured on. Third, plausible deniability. As long as the completion record exists, organizations can demonstrate to regulators that training 'happened.' The new ANSI/ASSP Z490.1-2024 standard, with its explicit Section 4.4.2 requirement for learner authentication, is the first major signal that this deniability is running out. Other regulators will follow.
What Post-AI Training Integrity Actually Looks Like
Training built for the AI era starts from a different premise: assume the session is hostile until proven otherwise. That means continuous biometric identity verification — not a single check at login, but ongoing confirmation that the same human is present throughout the session. It means liveness detection that can distinguish a real face from a recording, a deepfake, or a virtual camera. It means tamper-proof session records that capture the actual evidence of human participation, not just a completion flag. And it means defensible records — artifacts that can stand up in a regulatory audit or a courtroom by showing exactly who completed what, when, and how their identity was verified at every step. None of this is exotic technology. It exists today. What's been missing is the industry will to admit that the old model is structurally insufficient.
The Path Forward
The honest version of the story is this: online training as currently practiced is the right product for a world that ended around 2023. The standards, the formats, the quizzes, the LMS architecture — all of it was thoughtfully designed for human-only sessions and reasonable cheating costs. Generative AI has dissolved both assumptions. Continuing to issue completion certificates from systems that cannot tell a human from a model is not a compliance program; it is a paperwork ritual. The organizations that recognize this first — and rebuild their training stack around verified human presence rather than tracked activity — will be the only ones with defensible records when the next wave of regulation, litigation, or public incident forces the question. The pre-AI era of online training is over. The infrastructure just hasn't been told yet.
Authoritative Sources & Further Reading
- OSHA Training Requirements— Official OSHA guidelines for workplace safety training
- ANSI Standards— American National Standards Institute
Writing on training integrity, learner verification and compliance record-keeping for Asgard Authenticate.
Ready to Issue Credentials You Can Defend?
Join organizations worldwide that trust Asgard for online training credential integrity. Start your free trial today—no credit card required.
Start Free Trial