How to

How to use AI in recruiting responsibly: a working policy for recruiters

On this page
  1. Map where AI already touches your hiring
  2. Sort every use by risk
  3. Keep a human decision where it counts
  4. Check AI output before you rely on it
  5. Control what candidate data goes where
  6. Test for bias, and keep testing
  7. Tell candidates, and give them a route
  8. Write it down: an AI register and a one-page policy
  9. Questions people ask

To use AI in recruiting responsibly, list every place AI touches your hiring process, sort each use by how close it comes to a decision about a person, keep a trained human making and explaining those decisions, check AI output against the source before relying on it, control what candidate data goes into which tool, and tell candidates what you use. Drafting a job ad is low risk; ranking or rejecting candidates is high risk and, in a growing number of places, regulated.

This page is a working method you can turn into a team policy. For what the laws say, see AI hiring laws by state, which is dated and linked to the statutes, and the EU AI Act for recruiting.

This is general guidance, not legal advice. AI rules in hiring are changing quickly and depend on where the job and the candidate are. Confirm the rules for your situation with counsel before deploying a tool that screens, scores or ranks candidates.

Map where AI already touches your hiring

Most teams use more AI than they realize, because it arrives inside tools they already had. Before writing any policy, list every use. Ask each recruiter and hiring manager, and check the release notes of your ATS, sourcing and scheduling tools.

StageCommon AI uses
Planning and adsDrafting job descriptions, suggesting titles, rewriting for inclusive language
SourcingSearch suggestions, profile matching, outreach drafting
ScreeningResume parsing, match scores, knockout question filtering, chatbots
InterviewsTranscription, summaries, question suggestions, scoring or "insights" on answers
Decision and offerCandidate comparisons, recommendations, offer drafting
CommunicationScheduling assistants, status updates, rejection drafting

Sort every use by risk

The question that matters is how directly the output affects whether a particular person moves forward. Three tiers are enough for most teams.

TierWhat the AI doesExamplesMinimum controls
1: AssistHelps a person write or organize; no output about a specific candidateJob ad drafts, email templates, interview question ideasHuman edit before use; no candidate data in the prompt
2: Record and summarizeCaptures or condenses what a candidate said or submittedInterview transcripts, call summaries, resume parsingCandidate told; output checked against source; data kept per your retention rules
3: EvaluateScores, ranks, filters, recommends or rejects candidatesMatch scores, automated knockouts, AI interview ratings, video analysisLegal review; bias testing; human decision with authority to overrule; notices; appeal route; vendor audit evidence

Be honest about tier 3. A "match score" that recruiters sort by is evaluation even if the vendor calls it a suggestion, because it decides who gets looked at first and who never gets looked at. The New York City Local Law 144 guide walks through how one law draws that line.

Keep a human decision where it counts

"Human in the loop" means little if the human approves every recommendation in two seconds. For tier 3 uses, a meaningful human review has four parts:

  • Authority. The reviewer can overrule the tool without justifying themselves to it or to a manager.
  • Information. They see the underlying evidence, such as the resume or the answer, not only the score.
  • Time. The volume assigned to them allows real review. If one person is "reviewing" hundreds of auto-rejections a day, nobody is.
  • Accountability. The decision is recorded under their name with a reason a candidate or regulator could understand.

A simple test: pick five candidates the tool screened out last month. Could the reviewer explain, from the record, why each was not progressed? If not, the tool made the decision.

Check AI output before you rely on it

Generative tools produce fluent text that can be wrong. In recruiting, the errors that do the most harm are the ones that sound plausible in a candidate's file.

RiskWhat it looks likeCheck
Invented quotesA summary puts words in the candidate's mouthEvery quote traced to the transcript or recording
Merged detailsTwo candidates' experience blended in one summaryOne candidate per session; review names and employers
Inflated or deflated claims"Led the migration" when the candidate said "supported"Compare verbs against the source
Protected informationA summary mentions age, health, family or religion the candidate mentioned in passingRemove before sharing; see what not to write in interview notes
Biased draftingJob ads with language that narrows who appliesHuman edit against the actual requirements

Tools can make checking easier or harder. Interview Signal, for example, checks each evidence quote on a scorecard against the transcript, and leaves the score and the decision with the interviewer. Whatever you use, the standard is the same: nothing goes to a client or into a decision that you could not show came from the candidate.

Control what candidate data goes where

Candidate data is personal data. Before any tool receives it, answer these questions and write the answers down:

  1. Is this tool approved by the organization for candidate data, or is it a personal account?
  2. Where is the data stored, and in which country?
  3. Does the vendor use inputs to train its models, and can that be switched off in the contract?
  4. How long is the data kept, and can you delete a candidate's data on request?
  5. Who at the vendor can access it, and is there a data processing agreement?
  6. Does the tool record audio or video, and have candidates been told and, where required, asked for consent? The consent guide covers recording.

A rule most teams can adopt immediately: no resumes, transcripts or interview notes in personal AI accounts. Retention periods for notes are covered in how long to keep interview notes.

Test for bias, and keep testing

Any tool that screens or scores can produce different outcomes for different groups, even when nobody intended it. Federal anti-discrimination law applies to a selection procedure whether a person or software runs it. The Uniform Guidelines describe a rule of thumb for spotting adverse impact: a selection rate for any race, sex or ethnic group that is less than four-fifths of the rate for the group with the highest rate is generally regarded by federal enforcement agencies as evidence of adverse impact (29 C.F.R. § 1607.4(D)). It is a screening signal, not a legal safe harbor.

An invented example of the arithmetic:

A screening tool advances 60 of 100 applicants in group A (60%) and 40 of 100 in group B (40%).

40% divided by 60% is about 0.67, which is below 0.8. That result calls for investigation: what the tool is weighting, whether those factors are job-related, and whether a less discriminatory alternative exists.

Ask vendors for their own testing, including any independent bias audit, the date it was run and the data it used. In New York City, an independent bias audit is required before using a covered tool; the city's DCWP page sets out the requirements. Then test on your own outcomes, because a tool audited on another employer's applicants may behave differently on yours.

Tell candidates, and give them a route

Some jurisdictions require notice and, in some cases, consent. Where no rule applies, telling candidates is still what builds trust. Keep it plain:

How we use technology in hiring

We use [tool type, e.g. "software that transcribes interviews and
drafts a summary"] to help our interviewers take accurate notes.
Interviewers read every summary against the transcript and make
all hiring decisions themselves. The software does not score or
reject candidates.

We use [tool type, e.g. "an application system that sorts
applications by keywords from the job description"]. A recruiter
reviews every application that meets the minimum requirements.

If you would like an alternative, or have questions about how your
information is used, contact [name, email]. You can ask us to
delete your data at any time, subject to legal retention periods.

Only write what is true. A notice that says a human reviews every application, when a filter removes most of them before anyone looks, is worse than no notice.

Write it down: an AI register and a one-page policy

Keep one row per tool. It becomes the answer when a candidate, a client or a regulator asks what you use, and it is what most AI hiring rules effectively ask you to be able to produce.

FieldExample entry
Tool and vendorATS match score, [vendor]
What it doesScores applications 0 to 100 against the job description
Risk tier3: Evaluate
Where usedAll US roles; not used for New York City roles pending audit
Human reviewRecruiter reviews every application above minimum requirements, regardless of score
Candidate noticeCareers page notice, linked from application form
Bias testingVendor audit dated [date]; internal selection-rate check quarterly
DataStored in the US; not used for training per contract; deleted with the ATS record
Owner and review date[Name], next review [date]

The policy itself can fit on a page: the three tiers, which tools are approved for each, the rule about personal accounts, who approves a new tool, and who candidates contact. Review it when you add a tool, when a law changes, and at least once a year.

Questions people ask

Is it safe to paste resumes into a general AI chatbot?

Only if your organization has approved that tool for candidate data and its terms say inputs are not used to train models or retained longer than you allow. A personal account on a consumer chatbot usually fails both tests. Remove names and contact details if you are unsure.

Can AI reject candidates automatically?

Technically, yes. Responsibly, it should not be the only thing standing between a candidate and a human review, and in several places automated decisions trigger notice, audit or appeal duties. Use AI to organize and summarize, and keep the reject decision with a person who can explain it.

Do I need to tell candidates that I use AI?

In some places the law requires it, for example for automated employment decision tools in New York City and AI analysis of video interviews in Illinois. Everywhere else, telling candidates what the tool does and does not do is still good practice, and it costs one sentence.

Does using AI note-taking count as automated decision-making?

A tool that only transcribes and summarizes is generally treated differently from one that scores or ranks candidates. The line depends on the specific law and on how the output is used, so check the definition in the rule that applies to you.

What should I do if a candidate asks not to be assessed by AI?

Have an answer ready before anyone asks: an alternative route, such as a human review of the application or an interview without a transcription tool, and a named person who handles the request. Record the request and what you offered.