TL;DR. Throw out the guides. Seriously, delete them. The ones about “identical timing” or “silence in chat” are dead weight. It’s 2026. You sit at a table and you cannot tell a top-tier bot from a live player. Not by eye. Not anymore. Modern engines randomize their pauses — and not dumb randomization, the pauses scale with how complex the spot is. They mimic reg bet sizings. They answer in chat, and the answer comes either from an LLM or from a live operator. Does that make bots invulnerable? No. The catching happens on the room’s server now, away from your table. And not every room does this equally well. Some do it properly. Some — we’ll get there.
Every couple of weeks I get the same DM, different wording: “look, I spotted a bot — all his pauses are identical.” Or: “caught one, didn’t respond to my chat jab.”
I’ve spent the last few years working on the architecture of detection systems, not on playing strategy, so every time I end up explaining the same thing. The heuristics that worked around 2018? Dead. I wrote about this back in “Ghosts at the Table” — and since then it only got worse.
WHAT’S WRONG WITH THE BEHAVIORAL-TELL GUIDES
Everybody links the same guide. The poker bot detection guide from Upswing Poker, August 2021 — probably the most cited one in the industry. Four working signals it gives you: consistent timing, no reaction to a moderator alert, sessions of 12+ hours, 25+ tables at once. (Bet sizing and silence in chat — to their credit, they admit those are unreliable.) Fine. Except five years passed since 2021. And in 2026 not one of those four delivers what it promised. Not one.
Timing first. People imagine old bots clicked at exactly 2.4 seconds on every decision. Nonsense. Even the OpenHoldem generation, the early Shanky Poker Bot stuff — randomization was already there. Crude, yes, identical for every situation, but there. Aggregate statistics across volume were what actually busted those bots. No hero with a stopwatch on a single hand. Today the range is context-aware. Garbage preflop hand — instant fold. Tough river all-in — nine seconds of “thinking.” They even fake tilt: loses a big pot, snap-calls right after. Like a human steaming. Cute.
The moderator test doesn’t work anymore either. Direct message with a notification — a modern bot answers just as convincingly as a human. The difference is the cost of the solution. Cheap option: an LLM answering autonomously, no human in the loop, and it slips on stuff unrelated to the game — recent news, local language nuances, the model starts to drift. Expensive option, the one serious farms use: a sniffer catches the system notification and forwards it instantly to an operator in Telegram. Guy replies from his phone. Good luck jab-testing that.
The 14-hour marathon was too obvious a tell on its own. So farms dropped it. Modern table-selection code hunts weak lineups by itself, and sessions cut off on a time cap or a win-rate threshold.
Same story with 25+ tables. Today that’s standard practice for professional mass-multitablers. Humans. The sheer table count gives a bot away about as much as wearing a hoodie does.
WHAT ACTUALLY HIDES THE BOT FROM THE ROOM
First, one question needs clearing up, otherwise it gets in the way: why does the anti-fraud system even let the bot in?
Here’s the thing. The technical perimeter isn’t aimed at you. It’s built to defeat the room’s anti-fraud system, and it stays active the entire time the game is running — at login and through the whole session. The standard setup is an Android emulator running a modified APK client of the room: a sniffer intercepts the game packets — cards, stacks, positions — before they’re even rendered on screen, forwards them to a remote decision server, and then the emulator taps the screen with the ready-made action. That’s the working mechanism. Nothing magical. And what hides it? Residential proxies instead of a data-center IP, plus FakeGPS with a realistic margin of error. To the room this player looks like an ordinary student on a smartphone in Lisbon. Not a VM in a data center. A student.
“LIQUIDITY BOTS”: WHY CLUB OWNERS RUN A BOT AT ZERO EV
Now an argument against manual detection that almost nobody brings up. Bots deliberately not programmed to win.
In WePoker, ClubGG, PPPoker there’s a practice called “liquidity bots.” They’re tuned to play at zero or a slight loss — 0 or −2 bb/100. Beating the regs isn’t the job. Keeping the illusion of a live game running 24/7 and generating rake for the club owner is. These bots make “human” mistakes. They toss emoji into chat. Tell me how you distinguish that script from a tipsy fish at the table. You can’t. There’s no way. The bot isn’t trying to play optimally. Optimal play is exactly what would give it away.
And here’s the part that stings. If you consistently run good against weak opponents at limits where the room earns on rake, don’t rush to thank luck. The bot is losing on purpose — but every pot you drag pays rake to the house. The club’s economy is fine. You’re the customer. You aren’t the beneficiary.
HOW BOTS GET CAUGHT
So if a person can’t spot a bot with their eyes — bots are invulnerable? No. They just get caught in places an ordinary player has no access to.
What happens on the room’s server
At the table you see a hundred hands against one suspicious opponent. The room sees every hand that player ever played, on every table. Plus IP, device telemetry, links to other accounts. Different game entirely.
Rooms themselves rarely disclose the details of their systems, so we go by their contractors. GeoComply, for instance — builds anti-fraud systems for rooms. It checks three things at once. First, what’s happening on the device itself: foreign code hooked into the game client, a solver renamed to look like a system utility, whether the whole thing is an emulator under the hood. Second, whether the physical location is real — it checks more than IP, including what GeoComply calls “impossible movement patterns.” An account was on GPS in Lisbon a minute ago and is now writing from a mobile network in Manila — that’s not a human, that’s a plane that doesn’t exist. Third, links between accounts: identical device fingerprints, a shared Wi-Fi point across supposedly different players. By their own description, that’s how they once caught 2,000 “unique” accounts physically sitting in a single location. Two thousand.
Of the rooms themselves, only partypoker has publicly disclosed the mechanics — on their Game Integrity team’s blog. Two mechanisms. The first is whole-pool comparison: the system matches every player against every other and calculates how similar their styles are; reports are generated automatically. The second is fingerprints. Once a bot has been identified, its profile is captured from the stats, and from then on the system fires a signal in real time as soon as anyone’s stats match it. Then a live analyst takes the account from there.
PokerStars keeps a dedicated Game Integrity team — data scientists, analysts, former pros — and states that 95% of caught bots are found by the team itself, with only 5% coming from player reports. Think about that next time you fire off an angry email to support. Their procedure is a cross-check: one analyst makes a call, a second one independently makes theirs. They disagree — a third joins in and they decide together. Why the paranoia? Because the actions are irreversible. Fund seizure. Insurance against a single analyst’s error, that’s what this is.
GGPoker, via its Poker Integrity Council, banned 42 accounts in a single 2026 investigation and seized $1.2M from those playing with AI. Partypoker’s numbers are more modest but published steadily, year after year: 291 accounts and $71,771 returned to players in 2024, and since 2018 — more than 2,540 accounts and over $2M.
And none of this is a fresh idea, by the way. Back in 2015, a master’s thesis at the University of Ottawa (“Hiding Behind Cards: Identifying Bots and Humans in Online Poker”) summarized earlier results on detection through server logs, timing, and network traffic — earlier work reported around 90% accuracy from traffic analysis and around 95% from decision logs. Catching a bot with statistics at scale isn’t new. Engineers have been systematically grinding this problem for more than a decade.
The same logic works against farms — only there, the target is coordination between accounts rather than a single bot. A 2022 paper catches that coordination with the Isolation Forest algorithm. Without labels. Without a pre-defined image of collusion. Just statistical outliers. Tested on 170,000+ players and 100,000+ matches.

An insider’s leak
Sometimes it isn’t a system that catches the bot. It’s chance. That’s what happened with Martin Zamani. On January 17, 2026, the poker pro published a 36-second video on X: rows of computers playing tables on Ignition and Bovada, not a single human at any keyboard. Zamani didn’t shoot the video — he got it from someone on the outside and posted it. Ignition claimed the footage was old, from 2022, and that all the accounts had long been closed. Zamani disagreed and showed a screenshot from the same source, this time from a 2024 tournament. Same farm.
Who’s right? From open data, you can’t tell. And that’s the point. Leaks aren’t a detection method. They’re luck plus somebody’s insider access, and even then they don’t give a definitive answer. Only grounds for an argument.

NOT ALL BOTS AND NOT ALL ROOMS ARE EQUAL
Behind all this engineering it’s easy to miss something simple: the majority of bots on the market aren’t the polished setup I described. Not even close. Building an undetectable system is expensive — development, infrastructure, keeping the thing alive through every room-client update. A significant share of bots would get caught on careful review. That’s my assessment based on such reviews — not hard numbers, I won’t pretend otherwise, but the kind of pattern you learn to see after enough of them. Either the mechanism through which the bot talks to the poker client lets them down. Or the operator does: broken schedule, an off-topic chat reply, a dropped proxy. Something always slips.
And the heavy tooling — style comparison, device telemetry — that’s mostly a thing at large public rooms. In closed club apps like WePoker, ClubGG, and PPPoker it’s different: the platform provides some tools, IP and geolocation restrictions and the like, but tracking games is up to the club itself. No unified system at the app level. Every club sorts it out on its own. And it’s not just a tools problem — the decision stays with the club owner, and he can turn a blind eye to a suspicious player as long as they bring in rake reliably. Server-side anti-fraud neural nets and cluster analysis? Only at the biggest rooms. The rest get by on player complaints and manual hand history reviews. Detection doesn’t disappear because of this. It’s just uneven. Strong in some places, nearly absent in others.
What the club owner is actually left with
If you play in the club apps, this section matters to you too — how the club owner handles this problem is what determines the quality of the pool you’re sitting in.
Here’s the honest picture: club owners aren’t looking for an absolutely bot-free room. That isn’t the goal. Often not even desirable. Bots — including a share of their own liquidity bots — mean around-the-clock action and traffic, which brings in real players and generates rake. The real threat is somebody else’s farm parking on the club without permission and quietly bleeding the regs dry. When that happens, the regs eventually notice, feel like they’re being farmed (because they are), and leave. Loyal regs gone — the recreational pool follows, and the rake dies. So what the club actually needs is control over external bot farms, with its own liquidity setup staying intact. Sterility isn’t the point.
The problem: a modern bot from an external farm mimics a live reg well enough that the club dashboard doesn’t distinguish it. Sizings normal. Timing looks emotional. Chat alive. Stats sit within the pool. By the built-in metrics — everything looks clean.
Which leaves the owner with two real options. Two.
The first is manual verification of suspicious players: ID request, gameplay video, a live voice check. It works. Technically. But using it on a real pool is problematic — every such check is friction with a player who may not turn out to be a bot at all, and a string of checks scares off loyal regs. And it’s the regs who bring in the rake. You see the trap.
The second is external analytics built specifically for the club’s job. Effectively the club needs its own miniature Game Integrity team. Building one from scratch is unrealistic, so the practical route is to rent that function as a service. That’s the model behind the poker bot detection service at pokerbot.com (I’m part of the team that builds it — judge accordingly): statistical analysis of the whole pool over long distance, hunting for teamplay patterns between accounts (joint play, coordinated lines of collusion), plus scoring based on the combined weight of statistically significant signals. What the club owner gets goes beyond a single “this player is suspicious” flag. It’s the whole pool annotated with review priorities — precisely the gap that internal platform tools can’t fill.
One honest caveat about this class of solution, because I keep my credibility by saying it out loud: statistical analysis catches external farms, coordinated groups, and profit-oriented bots because they leave a fingerprint at scale. It does not catch liquidity bots the club runs on itself. That’s a feature, not a bug — liquidity bots are, by design, statistically indistinguishable from a tipsy fish, and detection isn’t the layer where that decision belongs. That’s a business call for the owner. It isn’t a signal for a model.
What does all this mean for the ordinary reg? You may still notice something suspicious at the table, but reliably catching a top-tier bot with your eyes is out in 2026 — attention at the table is better spent on EV calculations, ranges, and the real weaknesses of the opponent. Suspicions are serious? Collect hand histories and file a report with the room’s or club’s support: security engineers have access to logs, telemetry, and cluster analysis you don’t. The hunt for the invisible in 2026 happens on the server, away from the table — and there, at best, you’re a signal source. Not the hunter.
