Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Anti-cheat in 2026 is a layered contest, not a race that AI is either winning or losing. Machine learning scores play for signs of cheating, but the publishers describing their systems in detail are also restricting how third-party software can reach game memory, running kernel-level components, checking boot and firmware settings, and screening input devices. Riot Games says AI-assisted reverse engineering has widened the number of people building cheats. Electronic Arts describes machine-learning and behavioral systems as one part of its defenses. Each company publishes its own results, and those results cover different games, periods and definitions, so they cannot be ranked against each other.
This article draws on Riot and EA statements from 2020 through October 2026, plus one academic preprint tested on Counter-Strike 2 data. We did not find a current first-party Valve description of its anti-cheat machine-learning approach, so Valve’s system is not covered here.
What changed in 2026
Riot cuts unapproved apps off from game memory
Riot’s support notice, “Game Memory Access Removed for Third Party Apps,” sets the start date: “Starting October 6, 2026, Riot will begin proactively preventing game memory access by default for all unknown third-party applications, for all titles, including League, TFT, and VALORANT.”
The word “unknown” is the key. Tools Riot has not approved are blocked by default. Tools that were already approved get an extended grace period through April 2027, after which they must use official APIs. Riot says it had allowed memory access for trackers, overlays and mods, and that AI-assisted reverse engineering has expanded the ranks of would-be hackers and is being used to build cheats, bot farms and attacks on in-game experiences. Those are Riot’s stated reasons. Its expectation of fewer cheats and fewer crashes is a projection; no independent measurement is cited for it.
#1 Best Overall
For players who rely on a stat tracker or overlay, the practical question is whether that tool’s developer is moving to official APIs before the April 2027 deadline.
Riot’s case for trust-based segmentation
In “Vanguard On-Demand,” Phillip Koskinas, whom Riot identifies as managing its competitive integrity portfolio, argues that as AI lowers the barrier to botting, the security bar for entering competitive play has to rise. He puts the principle this way: “Ultimately, for competitive online spaces to persevere, it is necessary that we be able to trust the endpoints that the games are played on.”
The approach Riot describes is segmented rather than universal. Riot says it prefers incentives to blanket requirements, and it reserves additional checks for highly competitive segments, unusual devices and high ranks. The likely effect is that security demands differ from one part of the player base to another. That is an inference from the segmentation Riot describes, not a rule Riot has quoted.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteEA’s year-in-review for Javelin
EA’s September 10, 2026 update, “Raising the Bar: A Year of Progress for EA Javelin Anticheat,” summarizes a year of detection work: anti-DMA protection, defenses against malicious input devices, measures against macro software and synthetic input, seven major upgrades and hundreds of smaller improvements. EA says it continues to invest in machine-learning models, behavioral analysis and hardware-level defenses.
Rank #2
EA reports 277,649 attempts to cheat or tamper prevented before they affected matches through July 2026. It attributes that count to Battlefield 6 and Javelin AntiCheat.
Where AI fits, and where it stops
Riot: models that score likelihood, limited by server data
Riot says it uses machine models to estimate how likely it is that a player is cheating. Its limit is the data available to those models. In its “/dev: Vanguard x LoL” article, Riot writes: “We do use machine models to predict the likelihood that a player is cheating, but using only data the game server receives does not currently afford us the granularity necessary to detect ‘informational’ cheats that do not modify player input—ESPs, FoW leaks, and radar hacks are almost totally undetectable.”
The gap is structural. An informational cheat reveals information the game meant to hide, but it does not change the inputs the server records, so a model that sees only those inputs has little to work with. Riot estimates that the best models using only server-side player input identify around 30–50% of aimbots, and it considers that recall insufficient for its free competitive games. That is Riot’s own estimate from the article, not a field-wide independent measurement. It is a large part of why Riot’s defenses reach into the client and operating system, covered below.
EA: a new Apex model for newer bots
EA says it built a new machine-learning model for Apex Legends to handle a newer generation of bots, and that the model is designed to cope with future variants. An earlier EA update described initial reviews as accurate with low false negatives but gave no percentage. Treat this as a description of EA’s own system for one game. It is not a measured comparison with Riot’s approach.
An academic test on Counter-Strike 2 data
AntiCheatPT_256 is a transformer model described in a 2025 preprint and evaluated on Counter-Strike 2 gameplay. The dataset contains 795 labeled matches and 90,707 context windows. On an unaugmented test set, the result is reported as 89.17% accuracy and 93.36% AUC — AntiCheatPT_256 paper authors, 2025. That is a study result on the paper’s own data, not a deployed anti-cheat product, and it should not be placed beside Riot’s or EA’s operational claims as if they measured the same thing.
Beyond aimbots: accounts, bots and boosting
Riot: account sharing and rank boosting
Riot describes classifying account sharing and rank boosting as part of its competitive integrity work. These problems involve people, not game software, so they are handled differently from memory or input manipulation. The public material reviewed does not describe the detection methods for these cases.
EA: bots, teaming and Apex enforcement
EA reports bot and teaming enforcement in Apex Legends, including around 1,200 accounts actioned and around 17.4 million ranked points removed. EA’s page for that update does not give a date that can be confirmed, so no year is attached to these figures here.
Why anti-cheat reaches below the game window
Vanguard’s three parts
Riot’s 2020 security explanation describes Vanguard as three components: a user-mode client, a kernel-mode driver and a platform. The client handles detections while a game is running. The driver validates memory and system state and starts with the computer, so it can block cheats from loading before the client is running. The explanation says Vanguard’s design was coordinated with Riot’s Security and Data Privacy teams and that the driver does not send computer information back to Riot. These are Riot’s own descriptions from 2020. They are not an independent audit, and later versions of the software may differ.
Why kernel access
Riot’s explanation ties kernel-level access to cheats that run at higher privilege, including DMA methods that relay a game’s memory to a second machine. A DMA cheat reads memory through hardware rather than through code running inside the game, so detection that sits only inside the game process has nothing to inspect.
The trade-off is intrusiveness. Kernel-level software runs with the highest system privileges, and players must decide whether they accept that. EA’s Javelin design takes a narrower route. According to EA’s September 2026 update, Javelin runs at kernel level only while a protected game is running and shuts down when the game closes.
Hardware, firmware and boot requirements
Here the defense reaches into system settings. Riot’s motherboard security update says restrictions can stop VALORANT from launching when system security features are disabled or when a system’s behavior resembles suspicious hardware configurations. Riot states that a restriction does not necessarily mean it suspects the player of cheating. In some cases it points players to enable a feature or to update motherboard firmware using the manufacturer’s official guidance.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →EA has moved in a similar direction with Secure Boot. Secure Boot is a firmware setting that checks the software loaded when a PC starts. EA introduced configurable Secure Boot requirements, and it reports that over 4.8 million players enabled Secure Boot afterward (EA, 2026 update).
Best Value
If a game won’t launch because of a security check
- Check whether Secure Boot and related security features are enabled in your motherboard’s firmware settings (UEFI or BIOS). Menu names differ by manufacturer, so use the maker’s manual to find them.
- Check the motherboard manufacturer’s support page for a firmware update, and follow its instructions exactly. Do not install firmware files from unofficial sources.
- Restart the PC and try the game again.
Input devices and accessibility
EA lists XIM, Cronus, Strike Pack and similar hardware as cheating when it is used to automate actions, modify recoil, alter input behavior or simulate unintended controls for advantage. These are examples of prohibited tools, not recommendations, and EA says confirmed cheating will receive permanent bans.
The harder problem is accessibility. Some assistive hardware also sits between the player and the game and changes how input reaches it, so a detection system has to separate it from cheating hardware. EA says Apex’s planned multi-layer detection is designed to make that distinction. EA’s published material does not give a separate error rate for accessibility cases, so whether the distinction works in practice cannot be verified from these statements.
Errors, appeals and compatibility
EA’s stated principle is: “We balance detection speed with accuracy.” In its Javelin update, EA reports a false-positive rate below 1% and presents that figure as its own measure. EA says it maintains an appeals process but withholds the specifics of its reviews to reduce exploitation. That is a real trade-off: less disclosure makes the system harder to game, and gives players less insight into why a decision was made.
Free tools Windows power users keep installed
One-click scans. No signup required.
Riot’s published material on these topics does not state a false-positive rate. Its hardware-restriction guidance, described above, is the closest it comes to explaining how an error should be read.
Compatibility is the other cost. EA says an October 2025 compatibility fix for AMD Anti-Lag resolved launch issues for 45,000 players within 48 hours. That is a launch-time fix, not a detection result, but it shows that system-level components can conflict with other software and need quick patches.
How the two approaches compare
Riot and EA cover overlapping problems with different tools. The table compares what each describes in its own material. “Not stated” means the cited material does not describe that point, which is not the same as saying the company lacks the feature.
| Question | Riot Games (League of Legends, TFT, VALORANT) | Electronic Arts (Apex Legends, Javelin AntiCheat) |
|---|---|---|
| Main detection signals | Machine models on server data, client detections, driver and system-state checks | Machine learning, behavioral analysis, anti-DMA protection, input-device defenses, hardware-level defenses |
| Threats named | Informational cheats (ESPs, fog-of-war leaks, radar hacks), aimbots, account sharing, rank boosting | Bots and teaming (Apex), DMA hardware, XIM, Cronus and Strike Pack-type devices, macro software and synthetic input |
| Kernel-level component | Vanguard kernel-mode driver that starts with the computer (2020 explanation) | Javelin runs at kernel level only while a protected game is running |
| Player-side requirements | Launch restrictions when security features are disabled or hardware looks suspicious; unknown third-party apps blocked from game memory by default from October 6, 2026 | Configurable Secure Boot requirements |
| Third-party tools | Approved tools must move to official APIs by April 2027 | Not stated in the cited EA material |
| Appeals and error handling | Hardware restrictions are not presumed to be cheating; appeals process not stated in the cited Riot material | Appeals process exists; review specifics withheld; self-reported false-positive rate |
| Accessibility devices | Not stated | Planned multi-layer detection designed to separate cheating devices from accessibility tools |
| Type of evidence | Company statements, a 2020 security explanation, and a Riot estimate for server-side models | Company update statements and company-reported counts and rates |
Why the published numbers don’t line up
The figures in this article come from different games, time periods and definitions, and each is reported by the company that benefits from it. EA’s prevention count covers Battlefield 6 and Javelin AntiCheat through July 2026. Riot’s recall estimate describes server-only aimbot models. The AntiCheatPT_256 result is accuracy and AUC on a single test set. EA’s false-positive rate is a self-reported rate for its own system. None of these is an industry-wide detection rate, and none can be averaged or ranked against the others. Read each one on its own terms, and treat any single figure as the publisher’s account of its own system.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

