How to use AI in recruiting responsibly: a working policy for recruiters
On this page
- Map where AI already touches your hiring
- Sort every use by risk
- Keep a human decision where it counts
- Check AI output before you rely on it
- Control what candidate data goes where
- Test for bias, and keep testing
- Tell candidates, and give them a route
- Write it down: an AI register and a one-page policy
- Questions people ask
To use AI in recruiting responsibly, list every place AI touches your hiring process, sort each use by how close it comes to a decision about a person, keep a trained human making and explaining those decisions, check AI output against the source before relying on it, control what candidate data goes into which tool, and tell candidates what you use. Drafting a job ad is low risk; ranking or rejecting candidates is high risk and, in a growing number of places, regulated.
This page is a working method you can turn into a team policy. For what the laws say, see AI hiring laws by state, which is dated and linked to the statutes, and the EU AI Act for recruiting.
This is general guidance, not legal advice. AI rules in hiring are changing quickly and depend on where the job and the candidate are. Confirm the rules for your situation with counsel before deploying a tool that screens, scores or ranks candidates.
Map where AI already touches your hiring
Most teams use more AI than they realize, because it arrives inside tools they already had. Before writing any policy, list every use. Ask each recruiter and hiring manager, and check the release notes of your ATS, sourcing and scheduling tools.
| Stage | Common AI uses |
|---|---|
| Planning and ads | Drafting job descriptions, suggesting titles, rewriting for inclusive language |
| Sourcing | Search suggestions, profile matching, outreach drafting |
| Screening | Resume parsing, match scores, knockout question filtering, chatbots |
| Interviews | Transcription, summaries, question suggestions, scoring or "insights" on answers |
| Decision and offer | Candidate comparisons, recommendations, offer drafting |
| Communication | Scheduling assistants, status updates, rejection drafting |
Sort every use by risk
The question that matters is how directly the output affects whether a particular person moves forward. Three tiers are enough for most teams.
| Tier | What the AI does | Examples | Minimum controls |
|---|---|---|---|
| 1: Assist | Helps a person write or organize; no output about a specific candidate | Job ad drafts, email templates, interview question ideas | Human edit before use; no candidate data in the prompt |
| 2: Record and summarize | Captures or condenses what a candidate said or submitted | Interview transcripts, call summaries, resume parsing | Candidate told; output checked against source; data kept per your retention rules |
| 3: Evaluate | Scores, ranks, filters, recommends or rejects candidates | Match scores, automated knockouts, AI interview ratings, video analysis | Legal review; bias testing; human decision with authority to overrule; notices; appeal route; vendor audit evidence |
Be honest about tier 3. A "match score" that recruiters sort by is evaluation even if the vendor calls it a suggestion, because it decides who gets looked at first and who never gets looked at. The New York City Local Law 144 guide walks through how one law draws that line.
Keep a human decision where it counts
"Human in the loop" means little if the human approves every recommendation in two seconds. For tier 3 uses, a meaningful human review has four parts:
- Authority. The reviewer can overrule the tool without justifying themselves to it or to a manager.
- Information. They see the underlying evidence, such as the resume or the answer, not only the score.
- Time. The volume assigned to them allows real review. If one person is "reviewing" hundreds of auto-rejections a day, nobody is.
- Accountability. The decision is recorded under their name with a reason a candidate or regulator could understand.
A simple test: pick five candidates the tool screened out last month. Could the reviewer explain, from the record, why each was not progressed? If not, the tool made the decision.
Check AI output before you rely on it
Generative tools produce fluent text that can be wrong. In recruiting, the errors that do the most harm are the ones that sound plausible in a candidate's file.
| Risk | What it looks like | Check |
|---|---|---|
| Invented quotes | A summary puts words in the candidate's mouth | Every quote traced to the transcript or recording |
| Merged details | Two candidates' experience blended in one summary | One candidate per session; review names and employers |
| Inflated or deflated claims | "Led the migration" when the candidate said "supported" | Compare verbs against the source |
| Protected information | A summary mentions age, health, family or religion the candidate mentioned in passing | Remove before sharing; see what not to write in interview notes |
| Biased drafting | Job ads with language that narrows who applies | Human edit against the actual requirements |
Tools can make checking easier or harder. Interview Signal, for example, checks each evidence quote on a scorecard against the transcript, and leaves the score and the decision with the interviewer. Whatever you use, the standard is the same: nothing goes to a client or into a decision that you could not show came from the candidate.
Control what candidate data goes where
Candidate data is personal data. Before any tool receives it, answer these questions and write the answers down:
- Is this tool approved by the organization for candidate data, or is it a personal account?
- Where is the data stored, and in which country?
- Does the vendor use inputs to train its models, and can that be switched off in the contract?
- How long is the data kept, and can you delete a candidate's data on request?
- Who at the vendor can access it, and is there a data processing agreement?
- Does the tool record audio or video, and have candidates been told and, where required, asked for consent? The consent guide covers recording.
A rule most teams can adopt immediately: no resumes, transcripts or interview notes in personal AI accounts. Retention periods for notes are covered in how long to keep interview notes.
Test for bias, and keep testing
Any tool that screens or scores can produce different outcomes for different groups, even when nobody intended it. Federal anti-discrimination law applies to a selection procedure whether a person or software runs it. The Uniform Guidelines describe a rule of thumb for spotting adverse impact: a selection rate for any race, sex or ethnic group that is less than four-fifths of the rate for the group with the highest rate is generally regarded by federal enforcement agencies as evidence of adverse impact (29 C.F.R. § 1607.4(D)). It is a screening signal, not a legal safe harbor.
An invented example of the arithmetic:
A screening tool advances 60 of 100 applicants in group A (60%) and 40 of 100 in group B (40%).
40% divided by 60% is about 0.67, which is below 0.8. That result calls for investigation: what the tool is weighting, whether those factors are job-related, and whether a less discriminatory alternative exists.
Ask vendors for their own testing, including any independent bias audit, the date it was run and the data it used. In New York City, an independent bias audit is required before using a covered tool; the city's DCWP page sets out the requirements. Then test on your own outcomes, because a tool audited on another employer's applicants may behave differently on yours.
Tell candidates, and give them a route
Some jurisdictions require notice and, in some cases, consent. Where no rule applies, telling candidates is still what builds trust. Keep it plain:
How we use technology in hiring
We use [tool type, e.g. "software that transcribes interviews and
drafts a summary"] to help our interviewers take accurate notes.
Interviewers read every summary against the transcript and make
all hiring decisions themselves. The software does not score or
reject candidates.
We use [tool type, e.g. "an application system that sorts
applications by keywords from the job description"]. A recruiter
reviews every application that meets the minimum requirements.
If you would like an alternative, or have questions about how your
information is used, contact [name, email]. You can ask us to
delete your data at any time, subject to legal retention periods.
Only write what is true. A notice that says a human reviews every application, when a filter removes most of them before anyone looks, is worse than no notice.
Write it down: an AI register and a one-page policy
Keep one row per tool. It becomes the answer when a candidate, a client or a regulator asks what you use, and it is what most AI hiring rules effectively ask you to be able to produce.
| Field | Example entry |
|---|---|
| Tool and vendor | ATS match score, [vendor] |
| What it does | Scores applications 0 to 100 against the job description |
| Risk tier | 3: Evaluate |
| Where used | All US roles; not used for New York City roles pending audit |
| Human review | Recruiter reviews every application above minimum requirements, regardless of score |
| Candidate notice | Careers page notice, linked from application form |
| Bias testing | Vendor audit dated [date]; internal selection-rate check quarterly |
| Data | Stored in the US; not used for training per contract; deleted with the ATS record |
| Owner and review date | [Name], next review [date] |
The policy itself can fit on a page: the three tiers, which tools are approved for each, the rule about personal accounts, who approves a new tool, and who candidates contact. Review it when you add a tool, when a law changes, and at least once a year.
Questions people ask
Is it safe to paste resumes into a general AI chatbot?
Only if your organization has approved that tool for candidate data and its terms say inputs are not used to train models or retained longer than you allow. A personal account on a consumer chatbot usually fails both tests. Remove names and contact details if you are unsure.
Can AI reject candidates automatically?
Technically, yes. Responsibly, it should not be the only thing standing between a candidate and a human review, and in several places automated decisions trigger notice, audit or appeal duties. Use AI to organize and summarize, and keep the reject decision with a person who can explain it.
Do I need to tell candidates that I use AI?
In some places the law requires it, for example for automated employment decision tools in New York City and AI analysis of video interviews in Illinois. Everywhere else, telling candidates what the tool does and does not do is still good practice, and it costs one sentence.
Does using AI note-taking count as automated decision-making?
A tool that only transcribes and summarizes is generally treated differently from one that scores or ranks candidates. The line depends on the specific law and on how the output is used, so check the definition in the rule that applies to you.
What should I do if a candidate asks not to be assessed by AI?
Have an answer ready before anyone asks: an alternative route, such as a human review of the application or an interview without a transcription tool, and a named person who handles the request. Record the request and what you offered.