Policy
Your ATS Shipped AI You Never Bought
When an ATS switches on AI hiring features nobody asked for, switch them off, then decide whether any go back on. Off is the only state you can defend without evidence, and a feature nobody evaluated has no evidence behind it. Treat the release note as an unreviewed purchase: run the review you would have run at procurement, on the output, the human override, the notice it triggers and the export. Then subscribe a named person to the vendor's release notes so the next feature arrives as a decision.
The takeThere is a large literature on how to choose an AI hiring tool and almost none on the ones that arrive. That gap matters more than it sounds, because the arriving kind skips every control an organisation actually has. No purchase order, no security review, no legal sign-off, no owner. The duties attach anyway, on the vendor's schedule rather than yours. Any AI governance policy that only fires at procurement is a policy with a hole exactly the size of the last upgrade.
Where Olive fits
Open a role and see what the work shows
A feature nobody chose is hard to explain afterwards, because there is no record of a decision. Nothing in an Olive report is automated: a person writes each of the six findings, every one carries the timestamped excerpt behind it, and a released report exports with its rubric, scorer and bank versions attached.
Rank your shortlistTurn it off, then decide whether to turn it back on
Because the review is what turns a running feature into a decision somebody made, and until it happens the feature runs on a vendor's judgment about your hiring. This is not a judgment about the feature. It is a sequencing rule: a control you have not reviewed should not be running while you review it, for the same reason a new payroll rule does not go live during the audit of that payroll rule.
The usual objection is that recruiters are already using it and turning it off breaks their week. Sometimes true, and it is a two-week problem against an open-ended one. The alternative is a stage in your funnel that nobody in HR can describe, which stays invisible until somebody asks: an applicant who wants to know how they were assessed, an insurance renewal questionnaire, a document request in litigation.
There is a narrower version if a full stop is genuinely disruptive. Leave the feature running for internal summarisation only, disable anything that orders, hides, tags or excludes a candidate, and put a date on the review. Write down which of those two you chose and why, with the date on it. A decision you can date is a decision you can defend.
The reason to do this in the same week: the obligations attached on the vendor's release date, which came before HR knew there was anything to review.
What a release note hands you without a purchase order
Potentially a regulated tool and a candidate-notice duty, arriving together. California's employment regulations, effective October 1, 2025, define an automated-decision system as a computational process that makes or facilitates an employment decision, name resume screening for particular terms or patterns as an example, and treat an agent acting for the employer as an employer under the Act 16. Nothing in that definition asks who chose the feature.
A deadline is what bites in New York City. Local Law 144 has applied there since January 1, 2023: where a tool substantially assists or replaces discretionary decision-making, the employer needs a bias audit conducted within the prior year, a public summary of the results, and notice to the candidate at least 10 business days before the tool is used 2. Ten business days is not a period you can create retroactively. A feature switched on Tuesday and used on Wednesday cannot be brought into compliance by writing a notice on Thursday.
Illinois adds a third shape. From January 1, 2026, it is a civil rights violation to use AI that has the effect of discriminating on a protected basis, to use zip codes as a proxy, or to fail to notify an employee that AI is being used for covered purposes 3. The statute leaves the timing and means of that notice to state rulemaking, so the duty's practical shape is not yet readable from the bill.
California also changed what you must keep. The same rulemaking extends the employment-records retention period from two years to four and says automated-decision system data is included 1. The rule does not ask how the records were generated: records produced by a feature nobody reviewed are still records you have to be able to produce.
If you have not yet listed which tools in your stack are already inside these definitions, whether your ATS already counts as regulated AI is the inventory this review depends on.
Who owns the release notes?
Somebody in HR, by name, with a recurring calendar entry and the authority to disable a feature without a meeting. That role does not exist at most employers, which is the actual reason default-on features go unnoticed: nobody was assigned to look. Vendors publish the change. Nobody is subscribed on the side that carries the duty.
Make the job small enough that it survives a busy quarter. Fifteen minutes a month, reading the hiring suite's release notes for three things: any feature that produces a statement about a candidate, any change to defaults, and any new integration that writes into the candidate record. Everything else can wait for the annual review.
Give that person one standing power and one standing obligation. The power is to switch a new feature off pending review, without escalation. The obligation is to log what shipped and what was decided, even when the decision was to do nothing, because a log of no-action decisions is what shows the process ran.
Do not expect an enforcement deadline to do this work for you. A New York State Comptroller audit of the first two years of Local Law 144 enforcement found that DCWP received two AEDT complaints in the whole period, and that nine of twelve test calls to 311 never reached the agency 4. Read it as a fact about the complaint pipeline. It says nothing about how employers are behaving. The reason to run the review is that the record exists when a candidate, an insurer or a court asks, and the insurance renewal questionnaire that now asks whether you use AI in hiring tends to ask first.
Write the standing rule now, in about this many words
One paragraph in the hiring policy, written before the next release lands. The rule has to be short enough that a recruiter remembers it and specific enough that a vendor change trips it automatically. Something close to this does the job, and adapt it to your own vocabulary before it goes in:
> New AI features in any hiring system ship disabled. A named reviewer enables a feature only after recording what it produces, who can override it, what notice it triggers and whether its output can be exported for a named candidate. Enablement is dated and logged. Any vendor change to an enabled feature's defaults returns it to disabled pending review.
Four reasons that wording holds up better than a longer policy. It names the default state, so the absence of a decision has a defined outcome. It names an owner, so the review has somebody to be late. It lists four facts, so nobody has to interpret what adequate means. And it re-fires on vendor change, which is the failure this whole article exists to describe.
Two things to pair with it. First, California's amended regulations make an employer's anti-bias testing, and the lack of it, relevant evidence in a discrimination claim, weighing the quality, recency and scope of the effort and the response to the results 1. That cuts both ways: testing and then ignoring the result is worse than it looks. If an enabled feature has been ordering candidates for a while, how to run an adverse impact audit when the vendor holds the data is the next step.
Second, do not let a vendor's assessment stand in for yours. The EEOC's position in guidance it issued in 2023 and removed in January 2025 was that an employer administering a selection procedure may be responsible even where an outside vendor designed it, including for the acts of agents such as software vendors given authority to act on its behalf 5. That document is no longer published, so treat it as the agency's reading at the time. For the wider policy this clause belongs inside, what actually belongs in an AI hiring policy covers the rest of the document. Confirm the final wording with counsel.
Common questions
Can we leave a feature on while we review it?
Yes, at the cost of the cleanest version of the answer. Every day it runs generates candidate decisions you will have to characterise later without having decided anything. If a full stop is genuinely disruptive, narrow it instead: keep summarisation, disable anything that orders, hides, tags or excludes candidates, and set a review date. Write down which option you picked and why, because the value of this whole exercise is the record, and a running feature with no decision behind it produces no record at all.
The vendor says the feature is not an automated employment decision tool. Does that settle it?
No. The classification depends partly on how your team uses the output, which the vendor cannot observe. Get their assessment in writing, since it is evidence you will want later, then write your own against your actual workflow. Where a vendor is wrong about its own product, the employer that administered the selection procedure can still be the one answering for it, on the EEOC's 2023 reading of Title VII. Vendor assurances are input to a decision you make, not a substitute for making it.
How do we find out what our ATS switched on?
Three places, in order. The vendor's release notes for the last two years, which is usually the fastest and least pleasant reading available. The admin settings screen, where enabled features are visible and the defaults are usually not marked. And the recruiter's actual view, because some features only appear in the queue. Walk the third one with a recruiter; the documentation will not show it. Anything that puts candidates in an order, hides some, tags them or ends an application belongs on the list.
Does this apply to AI features that only help recruiters write?
Less. A tool drafting an outreach email or a job description concludes nothing about a candidate, so the automated-decision definitions do not reach it. Two caveats keep them on the list anyway. Job description language written by a tool can carry requirements nobody chose, which is a different exposure. And drafting features often sit one toggle away from features that do act on candidates, so the review is the same visit whether or not the answer changes.
What if we hire in only one state?
The tests key on different anchors, mostly not on where the candidate sits. New York City's Local Law 144 turns on the job's office location: a fully remote role counts only when its associated office is in NYC, though notice goes to NYC-resident candidates. Illinois binds employers operating in the state, and California those covered by its fair employment act. A posting open to remote applicants can pull in more than one regime at once. The federal Uniform Guidelines have covered any measure used as a basis for an employment decision since 1978. The practical planning assumption is the widest definition touching any candidate you actually consider, which for most employers is broader than the state on the letterhead.
How often should the review repeat?
Monthly for release notes, annually for the full inventory, and immediately whenever the vendor changes a default on a feature that is already enabled. The monthly pass is the one that keeps the annual pass short, because the alternative is reconstructing two years of changes at once. Put both on a named person's calendar, since a policy nobody has scheduled has no cadence at all.
References
- 1. Final Unmodified Text of Proposed Employment Regulations Regarding Automated-Decision Systems (Attachment B), 2 CCR sections 11008, 11008.1, 11009, 11013 calcivilrights.ca.gov Supports the automated-decision system definition and agent-as-employer clause, the extension of employment-record retention from two years to four including automated-decision system data, and anti-bias testing as relevant evidence.
- 2. Automated Employment Decision Tools: Frequently Asked Questions nyc.gov Supports the bias audit within the prior year, the posted summary, and the requirement to give candidates notice 10 business days before an automated employment decision tool is used.
- 3. HB3773 Enrolled (Public Act 103-0804), amending the Illinois Human Rights Act ilga.gov Supports the Illinois effects standard, the zip-code proxy ban and the duty to notify employees that AI is in use, effective January 1, 2026, with notice mechanics left to rulemaking.
- 4. Enforcement of Local Law 144 - Automated Employment Decision Tools, Report 2024-N-6 osc.ny.gov Supports the complaint volume across the first two years of enforcement and the broken 311 intake route, used to argue the reason for review is the record rather than the fine.
- 5. Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII of the Civil Rights Act of 1964, Question 3 (archived capture, 2025-01-25) web.archive.org Supports the point that a vendor's assessment does not transfer responsibility, quoted as the EEOC's 2023 position and noting the document was removed in January 2025.
- 6. Rulemaking Actions - Civil Rights Council ✓ calcivilrights.ca.gov The Council's own record of the automated-decision-system employment regulations: approved by OAL and filed with the Secretary of State, effective October 1, 2025.
6 sources, numbered by first appearance. How Olive sources claims
General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.
Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.