Blog

The Disease and the Cure: Technology and Academic Fraud in the Generative Age

a staff member reviews information on her computer at her desk
interoperability_3.jpg

Table of Contents

Reflections following the UNESCO capacity-building webinar "Combatting academic fraud through technology and international cooperation," under the Global Convention on the Recognition of Qualifications concerning Higher Education.

Marshall McLuhan warned that we shape our tools, and thereafter our tools shape us. Fifteen years ago, digital technology was the cure for diploma fraud. Today it's also the disease—and, built carefully, the cure again.

That spiral framed UNESCO's recent webinar on academic fraud, which brought together perspectives from the Groningen Declaration Network, the Norwegian Directorate for Higher Education and Skills, and the technology and standards community. The occasion was serious: estimates cited by UNESCO put the fake degree market at more than $22 billion (University World News, 2023). Behind that figure sits an industry now estimated to generate $7 billion a year—in one recent US federal case alone, three schools sold more than 7,600 fake nursing diplomas, and some 2,800 buyers went on to pass national licensing exams—and the human cost the panel insisted on naming, real learners, employers, and patients absorbing the consequences.

 

The war on paper is over but the battle on digital is still on

The original work of credential evaluation was forensic. Evaluators examined paper under magnifying glasses and blue light, hunting for inconsistent fonts, blurred seals, and missing signatures. Digital issuance was supposed to end that war, and for a while it did.

Then the tools turned. Generative AI now produces forged documents of a fidelity no lightbox can catch, at a cost approaching zero, at a scale no evaluator's office can match. Industry telemetry tells the story plainly: digital forgeries have overtaken physical counterfeits as the leading form of document fraud. The scan and the PDF, which are the primary formats much of the world's recognition machinery still runs on, are precisely where the new fraud thrives.

Yet there is a twist that should give the sector confidence rather than despair. The technologies built over the past decade, such as cryptographic signatures, independent verification, revocation, and verifiable credentials, carried features that were ahead of their time. They were harder to implement than the moment seemed to require. That moment has arrived. The features once difficult to justify are now exactly what the sector needs.

 

Three generations of trust

It helps to see verification as a sequence of paradigms, each removing a dependency that the last one couldn't shake.

Generation one: phoning home. The verifier contacts the issuing institution, whether by post, phone, or email. It works when the institution answers. The arithmetic is unforgiving: Norway's recognition authority alone assesses some 30,000 foreign qualifications a year, and verifying each at source is impossible. Generation one depends entirely on someone picking up the phone, and much of the world still lives here.

Generation two: trusted depositories and networks of networks. Instead of calling the institution, the verifier checks against a trusted hub—a national database, a sector-owned network, a hub-and-spoke federation of the kind the Groningen Declaration Network convenes. The logic, as the Norwegian experience shows, is precise: what a verifier actually needs is not the diploma but the connection between a serial number, an identity, and a result in an authoritative record. The document becomes almost incidental.

This generation is not theoretical. Canada's MyCreds, the sector-owned national network, has reached majority adoption across the country's public institutions—and, as its founding leadership recounted in the session, five years of operation without a single case of fraud passing through the network. Across the world, My eQuals connects all 47 universities of Australia and New Zealand, with some ten million credentials issued and records shared into more than 130 countries; documents that once took over a month to deliver now reach learners in 24 to 48 hours. Generation two is today's workhorse, and it works.

Generation three: the learner as the source of truth. The emerging paradigm inverts the architecture. The learner holds their credentials in a digital wallet and shares them directly with whoever needs to verify—no phone call, no central database query. The trust travels inside the credential itself: cryptographically signed by the issuer, tamper-evident, machine-verifiable in seconds. This is sovereignty in the fullest sense—personal agency over one's own record, trust established peer to peer rather than brokered through an intermediary. The standards are the same ones generation two already runs on, which means the handover requires no rebuild. When the sector is ready to trust the holder as the source of truth—and the technology increasingly warrants it—the rails are already laid.

The tense matters. Generation three is motion, not arrival. The networks connecting national information centers, depositories, and evaluators remain the most efficient verification instrument the world has today. But the direction is set.

 

Leave no one behind (including the paper)

A caution, before the technology runs ahead of the world it serves. Institutions sit on a wide spectrum of readiness. Some are moving from paper to PDF; some from PDF to structured data; some are aligning to competence frameworks. No single technology dropped uniformly across that spectrum will serve everyone, and in parts of the world, the digital divide is not a metaphor but a bandwidth reading.

The elegant answer is that generation-three trust doesn't require generation-three infrastructure. A cryptographically signed QR code printed on a paper document—not the decorative QR scanned for menus, but one embedding a verifiable signature—lets a paper credential be checked offline, in low-bandwidth and no-bandwidth contexts. It is the newest trust technology carried by the oldest medium: the digital and the physical closing the loop. Equity is not what gets added after the architecture is finished. It is a design requirement of the architecture.

 

Prepared to be hacked

The session closed with a prediction that deserves to be wrong: diploma fraud will not keep looking like fake institutions. People will fake themselves. Instead of forged certificates, verifiers will receive generated applications, synthetic portfolios, and inflated representations of real people—plausible, polished, and hollow. That will be the new normal.

Cryptography answers part of this. What it cannot answer is the question that follows: once a credential is provably real, what is it actually telling us? The center of gravity in a credential is moving from authenticity to four harder properties—equivalence, transparency, expressiveness, and actionability. Equivalence: what is this qualification worth against that one, across borders and systems? Transparency: what learning actually sits beneath the label? Expressiveness: does the credential say enough about itself—skills, context, evidence—to be interpreted at all? Actionability: Can an admissions officer, a licensing board, or an employer make a defensible decision on it? Authenticity is becoming the floor. The judgment work above that floor—the work credential evaluators, national information centers, and recognition authorities have always done—is becoming the whole game.

 

The move

This is why the Global Convention on Higher Education matters, and why it's not primarily a technology instrument. Fraud is a coordination problem wearing a technology costume. The concrete steps are known: establish national information centers where none exist, so there is someone to answer when the world calls; connect them across regions through the convention's networks; treat verification as shared public infrastructure rather than each country's private burden; and keep educating across borders, because a network no one understands is a network no one trusts.

We shaped these tools. They are shaping us back. The task of the next fifteen years is to make sure that what they shape is a system where every learner's record is verifiable, every verifier's judgment is informed, and no one—no institution, no country, no learner—is left on the wrong side of trust.

About the Author

Principal, Global Learning Ecosystem

Simone Ravaioli is a Recognition Technologist and Credentials Cartographer working across education, technology, and global policy. As Senior Director of Global Learning Innovation at Instructure, he leads strategic initiatives that advance learner-centric recognition systems, credential portability, and data interoperability. He works with global partners to translate complex challenges into practical solutions that connect education and employment through innovation and aligned strategy. He currently serves as Co-chair of the W3C Verifiable Credentials for Education Task Force and Chairperson of the Credential Engine Advisory Group. These roles let him contribute to open standards and infrastructure that make recognition more transparent, portable, and meaningful. He's a strong advocate for framing micro-credentialing through the lens of "Policy as Data." The approach bridges the gap between frameworks and practice, helping learners and workers navigate these systems more easily and equitably.

Like what you learned?

Stay in the know by subscribing to monthly recaps of our news feed.

CAPTCHA
Enter the characters shown in the image.