
A competitive ladder only works if players believe the result on the screen came from the match they just played. Once that trust starts slipping, every suspicious prefire, impossible tracking sequence, or perfectly timed flank becomes part of a larger credibility problem. The technical fight behind that trust has moved far beyond scanning a game folder for obvious cheat programs.
By 2026, major PC anti-cheat systems increasingly operate alongside Windows security features such as Secure Boot, TPM 2.0, virtualization-based security, memory integrity, and IOMMU protections. Riot Vanguard, EA Javelin Anticheat, Call of Duty’s RICOCHET Anti-Cheat, and FACEIT’s anti-cheat all reflect the same basic reality: modern cheats can operate below the level where a normal desktop application can reliably see them. That pushes anti-cheat software deeper into the operating system, which also pushes the privacy and security debate into territory that competitive players cannot reasonably ignore.
Why the Fight Moved Into the Kernel
Windows separates ordinary applications from the operating system kernel, where the most privileged parts of the system run. A normal game client operates in user mode. A kernel driver operates with far greater authority, close to the same layer used by hardware drivers, security products, and core operating system components.
That difference matters because cheat developers learned long ago that staying outside the game process can make detection harder. A cheat with kernel access can attempt to hide activity, manipulate memory access, or interfere with what a user-mode anti-cheat is able to observe. EA explicitly describes this as one reason Javelin operates in the kernel, arguing that an anti-cheat confined to user mode can be blinded by software operating beneath it.
Riot has made the same case in greater technical detail. Its June 2026 Vanguard update described kernel cheats, vulnerable signed drivers, boot-time attacks, hypervisor abuse, and hardware-assisted methods as parts of the current threat model. Riot’s argument is straightforward: if hostile code can establish itself before or beneath the anti-cheat, then the defender needs stronger evidence that Windows has remained trustworthy from boot through game launch.
This is why the phrase “kernel-level anti-cheat” can be misleading if it is treated as one technology. The driver itself is only one piece. Modern systems combine local monitoring, server-side detection, hardware attestation, account enforcement, behavioral analysis, signed-driver policies, and increasingly the security features already built into Windows and modern PC firmware.
The Privacy Concern Is About Authority, Not Automatically About Spying
Players are justified in treating kernel software differently from a normal launcher or overlay. Microsoft describes drivers as software with sensitive system access, and Windows applies special signing and integrity rules to kernel-mode code for exactly that reason. A faulty or compromised kernel driver can create security and stability risks that ordinary applications generally cannot.
That does not mean every kernel anti-cheat is reading personal documents, browser history, or unrelated communications. The important distinction is between what software technically has the privilege to do and what its vendor says it is designed, permitted, and audited to do. Those are different questions, and responsible scrutiny has to keep them separate.
Call of Duty states that the RICOCHET kernel driver runs only while a protected Call of Duty title is running and monitors software interacting with the game. EA says Javelin likewise runs only while a protected title is active and shuts down with the game. FACEIT says its driver loads at boot, but its anti-cheat only activates and collects game and anti-cheat data while Counter-Strike is running, and it allows players to disable the driver until the next reboot.
Riot historically drew more attention because Vanguard’s driver started with Windows. That model was intended to solve the “who loads first” problem, where a cheat could establish kernel access before the anti-cheat appeared. In June 2026, however, Riot introduced Vanguard On-Demand for PCs that pass its Vanguard Pre-Check security requirements. On those sufficiently secured systems, the driver no longer needs to launch at startup, because Riot can rely more heavily on Secure Boot, TPM-backed measurements, virtualization-based protections, and Windows runtime driver attestation.
That change is significant because it shows the privacy discussion is not frozen in the architecture of 2020. Better operating-system security can reduce how long an anti-cheat needs to remain resident while preserving evidence about what happened before the game launched.
Secure Boot and TPM Are Becoming Part of Match Integrity
For years, PC competitive integrity was mostly discussed as a software problem. In 2026 it increasingly begins before Windows has fully started.
Secure Boot verifies trusted components during the boot process. TPM 2.0 can support measured boot and attestation, creating cryptographic evidence about the state of the system. Memory Integrity, also known as HVCI, uses virtualization-based security to help prevent untrusted kernel code from executing. IOMMU protections can restrict how peripheral devices access system memory, which matters because Direct Memory Access hardware has become part of the modern cheating problem.
Riot now lists TPM 2.0, Secure Boot, Memory Integrity or VBS, and IOMMU among the security features Vanguard may require. FACEIT similarly requires or checks several of these protections, and its current documentation explains that TPM and Secure Boot can provide attestation about whether the boot chain remained clean. FACEIT also describes IOMMU as a defense against DMA hardware reading game memory outside normal software paths.
Call of Duty has also moved in this direction. RICOCHET now pairs its runtime kernel driver with TPM 2.0 and Secure Boot protections for Black Ops 7, describing the hardware-backed checks as complementary rather than replacements for live anti-cheat monitoring.
For competitive communities, this changes what it means to have a “clean machine.” A player can have no obvious cheat application running and still fail an integrity check because firmware is outdated, Secure Boot is disabled, virtualization protections are unavailable, or a vulnerable driver has weakened the trust chain. The anti-cheat is no longer asking only what the game process is doing. It is asking whether the PC can prove that the environment around the game has remained trustworthy.
Better Security Also Creates More Compatibility Friction
The cost of stronger enforcement is visible the moment anti-cheat begins requiring firmware settings instead of merely installing a background service. Secure Boot, TPM, IOMMU, UEFI mode, virtualization, and memory integrity can expose old hardware, outdated BIOS versions, incompatible drivers, or unusual system configurations.
FACEIT’s support documentation openly warns that enabling these protections can require BIOS changes, converting older systems from legacy boot modes, troubleshooting driver conflicts, or in some cases replacing outdated hardware. Riot’s late-2025 Vanguard work went even deeper after it identified motherboard firmware conditions that could leave a pre-boot DMA protection gap despite security settings appearing to be enabled. Riot coordinated with motherboard vendors on firmware fixes and began restricting affected configurations when it could not establish sufficient trust.
Microsoft is tightening the same part of the PC stack for broader security reasons. Beginning with April 2026 updates, Windows stopped trusting the deprecated cross-signed kernel-driver program by default in covered configurations, pushing new kernel drivers toward Microsoft’s Hardware Compatibility Program signing process. Microsoft also continues to maintain a vulnerable-driver blocklist intended to stop known-abusable drivers from loading.
The overlap is telling. Anti-cheat vendors and operating-system security teams are increasingly trying to close many of the same doors because cheat developers and malware authors both benefit from weak driver controls, vulnerable kernel components, and compromised boot chains. A protection that frustrates a cheat loader may also block a rootkit technique. The downside is that legitimate users can get caught in the compatibility cleanup when old drivers or firmware no longer meet the new baseline.
Clean Ladders Require More Than a Kernel Driver
Kernel access can make certain forms of cheating harder to hide, but it does not magically solve competitive integrity. External hardware, computer-vision systems, synthetic input, account boosting, collusion, smurfing, match fixing, and human-assisted information sharing do not all present themselves as a suspicious process inside Windows.
That is why the strongest anti-cheat programs have become layered systems. EA says its 2026 Javelin work includes anti-DMA protections and defenses against malicious input devices and synthetic input. Riot separately uses server-side behavioral systems and in September 2026 detailed additional Vanguard systems aimed at rank manipulation and boosting. Those approaches matter because some forms of unfair play are better identified through match behavior, account relationships, or statistical patterns than through memory inspection.
The same lesson applies to community ladders. A clean competitive system needs technical anti-cheat, sensible identity controls, match records, dispute procedures, ban appeals, server-side evidence, and administrators who understand the difference between suspicious play and proof. Kernel software can protect the endpoint, but competitive credibility is built across the whole system.
False positives also deserve serious attention because an anti-cheat penalty can affect purchased games, tournament access, rankings, and player reputation. EA reported in September 2026 that Javelin protected 20 titles and blocked 26.7 million cheat attempts during the preceding year, while claiming detection accuracy above 99 percent and a false-positive rate below 1 percent. Those are EA’s own figures, not an independent audit, but they illustrate the scale at which even a small error rate becomes important.
The Real Trade-Off Is Trust for Trust
Competitive players are being asked to grant anti-cheat vendors unusually deep access to their PCs because those vendors are trying to establish something players also want: confidence that the person on the other side of the server is competing under the same rules. That bargain is easier to accept when the software runs only during protected games, publishes clear technical explanations, supports appeals, undergoes external review, minimizes collected data, and can be disabled or removed without ambiguity.
It becomes harder to accept when documentation is vague, telemetry boundaries are unclear, updates arrive without explanation, or the player has no practical way to understand why a machine has been blocked. Kernel privilege raises the standard the vendor should be expected to meet. A company asking for that level of system trust has to earn it continuously through engineering discipline, transparency, security review, and restrained data collection.
The most interesting direction in 2026 is the movement away from making the anti-cheat driver carry the entire burden. Riot’s on-demand model, FACEIT’s hardware security requirements, RICOCHET’s Secure Boot and TPM integration, EA’s anti-DMA work, and Microsoft’s tighter driver policies all point toward a PC where competitive integrity is increasingly backed by the operating system and hardware itself. That does not remove the need for kernel anti-cheat, but it can narrow the job that proprietary software has to perform.
For ladder players, that may be the healthier long-term arrangement. The cleaner path is not giving one game company limitless responsibility for policing an entire PC. It is building enough verifiable security into the platform that anti-cheat can focus on the match, while Windows and the hardware establish whether the machine beneath it can be trusted.
