Policy
Do You Allow a Candidate's AI Agent to Apply and Schedule?
When a candidate's AI agent fills out the application, books the screen and answers scheduling email, allow the logistics and require the person. A filled form or a booked slot is delegation, and nothing in your stack reliably separates that traffic from a candidate typing fast, so a ban would land on whoever looked suspicious. Require the person for the assessment, the interview, and every authorization carrying a signature, since federal law puts those signatures on the candidate personally. Put both halves in the invite before anyone applies.
The takeThe line here was drawn by Congress before anyone shipped an agent. The FCRA disclosure and the work authorization attestation sit on a natural person because a signature is how the law finds someone to hold responsible, and no policy you write moves that. Everything outside those acts is preference, and preference dressed as principle is what a candidate ends up appealing. Employers keep arguing this as an ethics question. On what is public so far, the ones who lose the argument will lose it on a record they cannot produce, not on a candidate who used a tool.
Where Olive fits
Open a role and see what the work shows
If the assessment is the step you require the person for, the link matters: Olive mints an invite that belongs to one candidate, and the first session it opens is the one it keeps, so a forwarded link is refused. What comes back is six separately-evidenced findings, each written by a human reviewer and anchored to a moment in the session, with the candidate granted the identical report.
Rank your shortlistCan you even tell an agent filled out the application?
No, not reliably. An agent runs in the candidate's own browser or signs in with their own credentials, so it arrives as their session, their address, their history. The controls at the door do not separate it either: in a study of 1,400 participants solving 14,000 CAPTCHAs, the authors report that the results suggest bots can outperform humans on both solving time and accuracy across the types tested 5.
The one artifact you could inspect is the writing, and inspecting it is worse than useless. Seven detectors run over 91 TOEFL essays written by non-native English speakers produced a 61.3% average false-positive rate: 97.8% of those human-written essays were flagged as AI-generated by at least one detector and 19.8% by all seven, while the same tools were near-perfect on essays by US eighth-graders 4. The error lands on people writing in a second language, and national origin sits directly behind that. Whether AI detectors work at all in hiring has not become a closer question since.
What your systems actually see is volume and pattern: the same resume across nine openings, a session that fills forty fields in four seconds, an address that has applied eleven times this month. Those are facts about traffic. None of them tells you who did the thinking, and none of them survives a candidate who simply types fast and applies widely.
So a ban on agent use is a rule you would enforce on whoever struck somebody as suspicious, which is a different test given to different people and the hardest kind to explain afterwards. The same failure shows up when hiring managers reject candidates for sounding like AI. The suspicion is sincere, the evidence behind it is style, and style has never been evidence.
Which acts have to be the candidate's own?
Three, and the signatures among them are settled by statute rather than by your policy. The assessment or work sample, because that is the thing you are measuring. The live conversation, for the same reason. And every authorization the process asks a candidate to give, because US federal law puts those signatures on the person and not on anyone acting for them.
The background check is the clean case. The Fair Credit Reporting Act conditions a consumer report obtained for employment purposes on a clear and conspicuous disclosure made in writing to the consumer, in a document that consists solely of the disclosure, and on the consumer having authorized in writing the procurement of the report 1. The statute puts the disclosure and the written authorization on the consumer personally, so route that step to the person rather than argue later about whether an agent's click was the consumer authorizing anything. The exposure for getting it wrong sits with the employer who relied on it.
Work authorization is the same shape and blunter about it. Federal law requires the individual to attest, under penalty of perjury on the designated form, that they are a citizen or national of the United States, a lawful permanent resident, or otherwise authorized to be hired 3. Perjury is personal by construction. Nobody delegates it, and no wording you choose can make that step optional.
The assessment belongs on the list for a plainer reason: if an agent does it, you measured the agent. That needs no citation, but it does carry a design consequence. A step you require the person for has to be a step where the work happens somewhere you can see it, rather than a document that comes back finished with no account of how.
Jurisdiction and date, because both matter: these are United States federal statutes, read against the US Code on 25 August 2026, and state rules layer on top of them. What you may ask a candidate about their own AI use is a separate question with separate limits, covered in whether you can legally ask candidates how they use AI. Counsel owns the final wording of anything you publish.
Why allow the agent to handle scheduling at all?
Because the job will ask for the same delegation, and because the alternative taxes the wrong people. A candidate whose assistant holds the calendar, fills repeated fields and answers a scheduling email is doing what your own team does with the same tools on a Tuesday afternoon. Nothing in that traffic tells you anything about their judgment, in either direction.
Hardening the form is where this usually goes wrong. In that same CAPTCHA study, human participants took 15 to 26 seconds on reCAPTCHA image challenges and got 81% of them right, while the automated solvers in the paper's comparison table were faster or more accurate on every type it covers 5. Friction at the door is a cost your genuine applicants pay and your automated traffic mostly does not.
If the real complaint is volume, say that instead, because volume has a different fix. A stack of applications that all clear the filter is a screening problem, and it was already breaking before agents arrived: an ATS keyword filter that every resume now matches stopped sorting anything the moment the words became free to produce. Banning the tool does not put the signal back.
There is also an access question buried in a blanket ban, and it is cheaper to avoid than to argue. The Americans with Disabilities Act requires employment tests to be selected and administered so that results reflect the skill the test purports to measure rather than an applicant's impaired sensory, manual or speaking skills 2. A rule written as no automated assistance anywhere in this process reaches past the assessment and into the form, where a candidate may be using a tool for access rather than for advantage. Write the requirement narrowly enough that it never has to be defended that broadly. (United States federal law, 42 U.S.C. 12112(b)(7), read 25 August 2026.)
Write the two lines your invite is missing
Most of this fails because the rule was never stated where the candidate would see it. Put two lines in the invite: which steps an assistant may handle, and which steps the candidate does personally. Then hold everyone who got that invite to the same two lines, so the rule existed before anybody applied instead of arriving after one application looked wrong.
The lines, close enough to paste:
- An assistant may fill this form, pick an interview slot, and handle scheduling email.
- The assessment, the interview and anything you sign are yours to do personally.
- If a step is hard to complete unassisted, say so and it will be arranged. How the work is judged does not change.
Leave out the attestation. A checkbox swearing no AI touched this application cannot be checked by you, invites a lie onto a form you then keep on file, and buys nothing you could act on. What actually belongs in an AI hiring policy is the long version of that argument, and the comparison in honor-system disclosure, detection or observation is worth reading before you pick a posture you have to defend.
Then keep the record: which invite carried which wording, the date it changed, and what happened the one time somebody asked. A policy whose history nobody can produce is a policy that gets described from memory in the worst available meeting.
What if the agent answered a substantive question?
Then you learned something about the answer and nothing about the candidate, and the fix is upstream. Stop putting weight on questions answered by email. Move anything you actually intend to weigh into a step where the person is present and the work is happening. Until they say it themselves, treat the emailed answer as unattributed rather than as evidence, and do not build a rejection on it.
What that swap looks like, by the role you are hiring for:
- Financial analysis. An emailed question about handling a filing that contradicts the deck gets a fluent answer from anybody's assistant. Put the packet in front of them and the question becomes which line they opened and what it changed.
- Software engineering. Emailed system-design prose reads well from everyone now. A small unfamiliar repo, plus an assistant willing to write the whole change if nobody stops it, reads differently per person.
- Legal operations. An emailed summary of a policy position is free. A packet where the playbook, the system record and the signed precedent disagree is not.
- Healthcare revenue cycle. Asked by email, everyone appeals everything. Given a queue of denials containing one claim that should be conceded, they do not.
- Marketing. An emailed positioning rationale is confident by default. Research where the most on-message statistic is the one least likely to be opened separates the people who opened it.
Be honest about the ceiling on all of it. A written round gives you an answer about checking rather than a check, and an agent in the loop only widens a gap that existed before it arrived. What narrows it is watching the delegation itself: what the candidate kept, what they handed over, and whether that split was deliberate or merely convenient. See how Olive measures this.
Common questions
Should you ban candidates from using AI agents to apply?
No, because you could not enforce it evenly. An agent submits through the candidate's own session and credentials, so the ban would fall on whoever seemed suspicious rather than on whoever actually used one. Write the narrow rule instead: agent-handled logistics are allowed, and the assessment, the interview and every signature are the candidate's own. State it in the invite, apply it to everyone who got that invite, and keep a record of how it was worded and when.
Can an AI agent sign a background check authorization for a candidate?
No. The Fair Credit Reporting Act conditions an employment consumer report on a clear and conspicuous written disclosure to the consumer, in a document consisting solely of that disclosure, and on the consumer's own written authorization 1. That is a United States federal requirement, read against the US Code on 25 August 2026. The work-authorization attestation has the same shape: the individual makes it under penalty of perjury 3. Route both to the person, and treat a step completed implausibly fast as a reason to re-send it rather than to accuse anyone.
Is it cheating if an agent answered your scheduling email?
No. Scheduling is logistics, and delegating it says nothing about how someone thinks. The word only starts to apply when a step you told them was theirs was done by something else, and even then the honest move is to ask rather than to accuse: bring the question into a live conversation and let the answer settle it. If the emailed round was carrying real weight, that is a design problem in the round rather than a character problem in the candidate.
How do you keep application volume down if agents apply for everyone?
You do not, and volume was rising before agents arrived. What you can change is what the top of the funnel measures. A filter tuned to keywords now matches almost everything, so move the first real judgment to a step that produces evidence: a short structured task, a live conversation, or a work sample the candidate does personally. Extra friction at the form is a tax your genuine applicants pay and automated traffic mostly does not 5.
What do you tell a candidate who asks whether they may use an agent?
Tell them exactly what the invite says, in the same words. An assistant may handle the form, the slot and the scheduling email. The assessment, the interview and anything carrying their signature are theirs. Say it plainly enough that nobody has to guess, because a candidate guessing at an unstated rule is the most common way an honest person ends up on the wrong side of one.
References
- 1. 15 U.S.C. 1681b - Permissible purposes of consumer reports ✓ uscode.house.gov Subsection (b)(2)(A) supports the claim that a background check for employment requires a clear and conspicuous written disclosure to the consumer, in a document consisting solely of the disclosure, and the consumer's own written authorization.
- 2. 42 U.S.C. 12112 - Discrimination (Americans with Disabilities Act, Title I) ✓ uscode.house.gov Subsection (b)(7) supports the claim that employment tests must be selected and administered so results reflect the skill the test purports to measure rather than an applicant's impaired sensory, manual or speaking skills.
- 3. 8 U.S.C. 1324a - Unlawful employment of aliens ✓ uscode.house.gov Subsection (b)(2) supports the claim that the individual, not a representative, must attest under penalty of perjury on the designated form that they are a citizen or national, a lawful permanent resident, or otherwise authorized to be hired.
- 4. GPT detectors are biased against non-native English writers ✓ pmc.ncbi.nlm.nih.gov Supports the false-positive figures for text detectors: seven detectors over 91 human-written TOEFL essays, 61.3% average false-positive rate, 97.8% flagged by at least one detector and 19.8% by all seven, against accurate classification of US eighth-grade essays.
- 5. An Empirical Study & Evaluation of Modern CAPTCHAs ✓ arxiv.org Supports the study size (1,400 participants solving 14,000 CAPTCHAs), the human reCAPTCHA image figures (15 to 26 seconds, 81% accuracy), and the paper's own statement that results suggest bots can outperform humans on solving time and accuracy across the CAPTCHA types compared.
5 sources, numbered by first appearance. Every one was opened and checked against the claim it carries. How Olive sources claims
General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.
Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.