This is how you play the game...
 

The Cost of Security: When Anti-Cheat Starts Policing the PC

Anti-cheat Locks up the PC

Disclaimer: The views and opinions expressed in this article are solely those of the author. The mention of any products, services, or methods does not constitute an endorsement.

Competitive PC gaming has reached a point where anti-cheat software is no longer watching only the game process. It is increasingly judging the condition of the machine around it, including firmware settings, storage drivers, virtualization features, input software, kernel modules, and the path Windows followed before the game even launched. For legitimate players, that can turn a routine queue into a BIOS session, a driver replacement, or a support-ticket hunt for software that worked perfectly everywhere else.

The pressure behind that change is real. Cheat developers have moved well beyond crude DLL injection and obvious memory editors, with kernel drivers, Direct Memory Access hardware, spoofing tools, compromised drivers, and pre-boot techniques now part of the commercial cheating market. Anti-cheat teams have responded by moving deeper into Windows and demanding more proof that the operating system itself can be trusted. The result is stronger resistance to sophisticated cheating, but also a growing compatibility tax paid by players who may have done nothing more suspicious than keep an older storage driver, run a remapping tool, or build a PC several hardware generations ago.

The Anti-Cheat Fight Has Moved Below the Game

Kernel-level anti-cheat is controversial partly because the word “kernel” sounds like a boundary games should never need to cross. Technically, the reason is straightforward: if a cheat can operate with kernel privileges while the anti-cheat remains in user space, the cheat can potentially hide or manipulate information before the anti-cheat sees it. Riot, EA, FACEIT, Easy Anti-Cheat, BattlEye, and other systems have all had to deal with versions of that problem, although their architectures and policies differ.

The more difficult problem is the use of legitimate signed drivers as an entry point. Microsoft describes vulnerable signed drivers as a recurring way for attackers to gain kernel access, which is why Windows maintains its own vulnerable-driver blocklist. Microsoft also acknowledges that blocking those drivers can break devices or software and, in rare cases, cause system crashes. In April 2026, Windows security updates went further by blocking certain older or vulnerable kernel drivers, including versions used by some backup software, showing that this conflict is no longer limited to games.

That matters because “this driver came from a real hardware company” is no longer enough to establish trust. A driver can be authentic, signed, and completely legitimate in its intended use while still exposing a flaw that cheat developers or malware authors can abuse. From an anti-cheat perspective, an old driver that still works can be more dangerous than a broken driver because it quietly provides a path into privileged parts of the system.

Legitimate Drivers Are Already Getting Caught

FACEIT offers one of the clearest examples of how this affects ordinary systems. Its 2026 support documentation says its anti-cheat uses DMA Remapping to defend against hardware-based cheating, but certain manufacturer-specific storage drivers conflict with that protection. The listed cases include drivers associated with Samsung, Solidigm, and Micron storage controllers, with affected players instructed to move to standard Microsoft drivers or updated alternatives before they can continue playing.

Riot has implemented a similar line of enforcement in Vanguard. Its support material describes an “Incompatible OEM Driver” condition in which some third-party NVMe or SATA storage drivers do not meet Vanguard’s DMA Remapping requirements, even though those drivers may otherwise function normally. In those cases the issue is not that the player installed cheat software. Vanguard is refusing to trust the system state until the incompatible driver is replaced.

That distinction matters, but it does not erase the frustration. A player can have a stable PC, current GPU drivers, a clean account, and years of legitimate play, then discover that one storage or Wi-Fi component has become unacceptable to a competitive platform. To the anti-cheat team, this is system-integrity enforcement rather than an accusation. To the player trying to join a match, the practical result is still a locked door.

Standard Utilities Can Become Security Problems Overnight

Drivers are only part of the argument. Modern anti-cheat systems are also becoming more willing to block software whose normal features overlap with techniques used to automate input, alter presentation, inject overlays, or manipulate controls. EA’s recent Battlefield 6 anti-cheat update says some hardware and software products that had previously been allowed were reevaluated and moved onto prohibited lists, with its example warning naming AutoHotkey and its discussion referencing reWASD. EA also points to categories such as input remapping, crosshair overlays, screen magnification, and sound equalizers as areas where one product may be acceptable while another crosses its rules.

This is where intent becomes difficult to encode in software. AutoHotkey can automate desktop tasks, reWASD can solve controller-layout problems, audio tools can compensate for hearing preferences or weak headset tuning, and overlays can provide harmless information. The same categories can also be configured to automate recoil control, create macros, exaggerate positional sound, or provide competitive information a game was never designed to expose.

Anti-cheat software cannot reliably judge every user’s motive. It tends to judge capability, behavior, driver access, or known implementation methods instead. That is defensible from a security standpoint, but it creates a widening gray zone where a tool can be legitimate in Windows and unacceptable in a ranked match at the same time.

Sometimes Anti-Cheat Conflicts With Windows Security Itself

The compatibility problem becomes stranger when a security product collides with another security feature. Epic’s current support documentation notes that Windows 11 Kernel-mode Hardware-enforced Stack Protection can prevent some Easy Anti-Cheat games, including Fortnite and Rocket League, from launching correctly. Epic’s documented workaround may require disabling that Windows feature, while explicitly warning that doing so can reduce system security.

That is a bad experience even when every engineering decision has a reasonable explanation. Players are being asked to decide which security layer gets priority, often without enough technical information to judge the trade. A game protection system that requires disabling an operating-system protection may be temporary compatibility debt, but the user still has to absorb the risk and troubleshooting.

EA’s own September 2026 Javelin update indirectly shows how large these compatibility problems can become. EA says an October 2025 fix for an AMD Anti-Lag conflict resolved launch issues for 45,000 players within 48 hours, and it also cites work around NVIDIA features and driver updates. Those numbers are EA’s own reporting rather than independent measurement, but they demonstrate that anti-cheat compatibility is not limited to obscure custom builds.

Secure Boot and TPM Are Turning Into Competitive Requirements

The next stage is hardware-backed trust. Battlefield 6 requires Secure Boot on PC, while FACEIT requires Secure Boot and TPM 2.0 for players on Windows 10 and Windows 11 and can also require features such as IOMMU, virtualization, and Memory Integrity depending on the security condition. Riot has likewise expanded checks around Secure Boot, TPM, VBS, IOMMU, firmware, and pre-boot integrity.

These features exist for good reasons. Secure Boot helps verify the boot chain, TPM can provide hardware-backed measurements and identity, and IOMMU can restrict how PCIe devices access memory. Those protections make life harder for cheats that depend on loading before Windows, hiding in privileged code, or reading memory through DMA hardware.

They also move competitive compatibility away from pure performance. A system can still produce excellent frame rates and low input latency while failing a security requirement because Windows was installed in Legacy BIOS mode, the boot drive uses an older partition layout, the motherboard firmware is outdated, or the platform lacks a required security feature. EA’s own Secure Boot guidance notes that systems running in Legacy BIOS mode may need their Windows disk configuration addressed before Secure Boot can be enabled.

For veteran PC gamers, that is a meaningful shift. We spent years judging whether an older rig could still compete by measuring frame time, CPU limits, refresh rate, and network performance. Security posture is now becoming another hardware requirement, and it can retire a machine from certain competitive environments before its GPU or CPU becomes too slow.

Anti-Cheat Restrictions Are Not the Same as Cheating Convictions

Aggressive anti-cheat also creates a communication problem. If software blocks a driver or refuses to launch on a machine, players often interpret the event as a false positive, even when no ban has occurred. Vendors need to be much clearer about the difference between detecting cheating, detecting an unsafe configuration, and refusing to trust a system whose state cannot be verified.

Riot made that distinction directly in its December 2025 Vanguard security update. It said a VAN:Restriction condition does not necessarily mean the player is suspected of cheating, but can mean the current configuration resembles the insecure conditions cheaters use to bypass protections. That is a more accurate description of where high-end anti-cheat is heading: the system is increasingly asking whether the PC can prove it is trustworthy, rather than only asking whether a known cheat is running.

Better messaging would reduce a lot of unnecessary panic. A launch block should identify the exact driver, service, firmware condition, or setting whenever disclosure does not give cheat developers a useful bypass. “Security violation” is not enough when the cause is a normal storage driver, an outdated motherboard BIOS, or a Windows feature the player has never touched.

The Better Direction Is Strong Security With Smaller Footprints

There are signs that deeper security does not always have to mean more permanent intrusion. Riot’s 2026 Vanguard Pre-Check work allows qualifying Windows 11 25H2 systems to run Vanguard’s driver on demand instead of loading it at system startup, provided the PC meets newer hardware and Windows security requirements. Riot says newer Windows driver-attestation features can give Vanguard a trustworthy record of drivers that have loaded since boot, reducing the need for the anti-cheat driver to remain present continuously.

That approach points toward a more sustainable bargain between players and anti-cheat developers. Let the operating system and hardware prove as much system integrity as possible, keep game-specific privileged code active only when it is needed, and give players precise compatibility information when something fails. The catch is obvious: those gains are easiest to deliver on newer platforms, so older systems bear more of the cost.

Some games are also experimenting with security that changes with the mode being played. Rocket League’s 2026 Easy Anti-Cheat rollout requires EAC for online matches, private matches, and tournaments, while allowing it to be disabled for offline play, training, LAN matches, replay work, and certain modded use cases. That separation recognizes that a competitive queue and an offline workshop session do not have the same threat model.

The PC has always been gaming’s most flexible platform because players can choose hardware, drivers, utilities, mods, input devices, audio tools, and operating-system settings with far more freedom than a console allows. Anti-cheat is now testing the limits of that freedom. The strongest systems will be the ones that stop sophisticated cheating without treating every unusual configuration as hostile, and that means compatibility engineering has become part of competitive integrity itself.

Leave a Reply