Policy
The Five Clauses a Candidate AI-Use Policy Actually Needs
An AI-use policy for job applicants needs five clauses, and no more. Name the stage the rule covers. State what is allowed there in verbs rather than tool names. Say what you are asking the candidate to tell you. Say what you will and will not do with that answer. Then set a consequence you could actually evidence. Written that way the whole rule fits in a paragraph and lives inside the assignment, where the candidate reads it.
The takeMost candidate AI policies run long because nobody has decided what the assignment measures. Length becomes the substitute for that decision, and it is a poor one: a page of rules a recruiter cannot apply on a Thursday afternoon turns into an improvised judgment with a document behind it, which is worse than an improvised judgment alone. Decide what the stage is for. The clauses fall out of that in about ten minutes, and the ones you cannot write are the ones you were never going to enforce.
Where Olive fits
Open a role and see what the work shows
What a hiring team can show later is only what somebody wrote down at the time. An Olive report is six findings written by a human reviewer, each carrying the timestamped excerpt from the session it rests on, and the candidate is granted the identical report on every tier.
Rank your shortlistStart with the stage, not the tool
Name the stage first, because the answer changes with it. A resume is not a supervised exercise and never was. A take-home is a work sample. A live round is a performance. One rule stretched across all three is either too loose for the exercise you care about or too strict for the parts you never intended to police. Write the rule for one stage and repeat it wherever it applies.
Three stages cover almost every process:
- Application materials. Resume, cover letter, screening answers. Assume AI assistance and stop asking about it. Nothing you can do at this stage is worth the cost of the question.
- The take-home or work sample. The stage where the rule matters, because this is the artifact someone reads as evidence of capability.
- The live round. Say whether an assistant is open on the candidate's screen, and if it is, say what you will ask them about it afterwards.
Clause two is what is allowed, and it should be written in verbs. "No ChatGPT" is unenforceable and out of date within a quarter. "Drafting, research and code generation are fine; the reasoning in the write-up has to be yours" survives a model release, a tool switch and a candidate who uses something you have never heard of. Name behaviours, not products, and the rule keeps working after the tool names change.
One piece of federal selection law is worth knowing before you write either clause. The Uniform Guidelines, a 1978 federal regulation, define a selection procedure as any measure, combination of measures, or procedure used as a basis for an employment decision, and say expressly that this runs all the way down to informal or casual interviews and unscored application forms 1. A rule you enforce by rejecting people reads directly onto the definition's own words, any procedure used as a basis for any employment decision. The Guidelines are a 1978 text nobody has yet applied to a candidate AI rule, so treat the broad reading as the safe one and have counsel confirm it. Applying it in the same words to everyone at that stage is the practical consequence, and it is what keeps the stage explainable afterwards. If you are still deciding what the rule should be, that argument is worked through in whether to allow AI on the take-home at all.
What do you ask the candidate to tell you, and what happens to the answer?
Ask for two things and commit to one. Ask what they used it for, and what they changed or discarded in what came back. Commit, in the same paragraph, that a disclosure is never on its own a reason to reject. Without that commitment the question is a trap, and the honest half of your pipeline is the half that walks into it.
Clause three is the request. Two sentences of instruction, attached to the submission rather than to a policy page nobody opens:
> Tell us what you used an assistant for on this assignment, and what you changed or threw out in what it gave back. Two or three sentences is plenty.
Clause four is what happens next, and it is the clause almost every template skips. Say who reads the disclosure, say that it goes to the reviewer alongside the work rather than to a separate file, and say what it is used for: understanding the choices in the submission, not deciding whether the person continues. If a disclosure can only hurt the person who wrote it, you have built a question that rewards silence.
Retention belongs in this clause too, in one line. How long the answer is kept, and whether it travels to anyone outside the hiring team. Both of those probably have answers already in your privacy notice, so point at that rather than restating it.
The wording is finicky enough to be worth its own treatment, and the two-prompt version of the request, with the sentences a reviewer should actually read for, is in asking candidates how they used AI.
Write the consequence clause for evidence you can hold
The consequence has to attach to something you can show a person. Say plainly that the rule is enforced on the record: what the candidate submitted, what they told you, and what they can explain about their own work in a conversation. That is a short list on purpose, because the obvious fourth item, a tool that tells you a machine wrote this, is not reliable enough to carry a decision about a person.
Independent testing is the reason. A study of twelve public AI-text detection tools plus two commercial systems used in academic settings concluded that the available tools are neither accurate nor reliable, and that they lean toward calling text human-written rather than machine-written 2.
Evasion is the sharper half of the problem. In an ACL benchmark holding every detector at a five percent false-positive rate, swapping characters for lookalike homoglyphs dropped one tool's accuracy from 85.0 to 9.3, and five detectors lost an average of 40.6 points, while one lost 0.3 3. A check that folds to a find-and-replace is not a check on the people hiding something. It is a check on the people who were not.
So write the clause around the conversation instead:
> If the work you submit is not your own, or you cannot talk through the choices in it, the process ends there.
That is enforceable, it is honest about what you are actually testing, and it survives the case where you are certain and wrong. The three ways teams try to enforce this, and what each one costs, are compared in honor-system disclosure, detection, or watching how they work. The version of this that arrives after an offer has already gone out is a different problem with different answers, worked through in rescinding an offer over a broken AI rule.
Keep the whole rule to a paragraph
If it runs past a paragraph, something in it belongs to a different document. Retention rules belong in the privacy notice. Tool approval and confidential-data handling belong in the employee policy, which does not reach an applicant anyway. Accommodation and alternative-process language belongs in the notice you already send. What is left is five clauses, and they fit in six or seven lines.
Here is the whole thing at length, for a take-home:
> This assignment is a work sample, so what we read has to be your judgment. Use an assistant for drafting, research and code generation if that is how you work. When you send it back, tell us in two or three sentences what you used it for and what you changed or threw out. That note goes to the reviewer with your work; it is never on its own a reason to end the process. If the work is not your own, or you cannot talk through the choices in it, the process ends there.
Five sentences, five clauses, and every one of them is something a reviewer can act on without calling anyone. Put it at the top of the assignment brief and in the email that carries it, so nobody has to go looking for a policy page.
Two checks before you publish it. First, read it as a candidate: does it tell them what to do, or does it mostly tell them what happens if they misbehave? Second, count the sentences that came out of your staff handbook, because an employee AI policy does not reach a candidate and every borrowed sentence is one you cannot enforce. The wider version of this question, covering sign-off, review cadence and who has to approve the wording, is in what actually belongs in an AI hiring policy.
Common questions
Do I need a separate policy for each role or requisition?
No. Write one rule per stage and reuse it. What changes between roles is the assignment, not the rule about the assignment, so a single take-home clause covers every take-home you send. The exception is a role where the tool is the job: a posting for someone who will run AI workflows all day wants an assignment that says use whatever you would use at work, which is a different permitted-use sentence and worth writing once, separately.
Should the policy live in the job posting or in the assignment?
In the assignment, and in the email that carries it. A posting is read once, weeks before the stage the rule governs, by someone who has not decided whether to apply. The assignment is read immediately before the work happens, by someone about to make the exact choice the rule is about. Put a single line in the posting if you want the expectation set early, and keep the operative wording next to the work.
What if a candidate refuses to answer the disclosure question?
Treat it as an answer and carry on. A refusal tells you nothing about the work, and a rule that turns silence into a rejection is one you cannot apply consistently: some people skip it, some people miss it, some people object to the question on principle. Review the submission on its merits, and if the work raises questions, ask them in the follow-up conversation where the person can respond.
Can the policy ban AI use outright?
It can say it, but say it knowing you cannot verify it. A ban makes the honest candidate slower than the dishonest one and gives you no way to tell them apart afterwards. If a stage genuinely has to be unassisted, the workable form is a supervised live exercise where the constraint is the setting rather than the promise. Anything sent home is a stated preference, and pricing it as a rule invites an enforcement problem you have no evidence for.
Does the rule have to be the same for every candidate at that stage?
Yes, and that is the part worth being strict about. A rule that changes who passes a stage is best treated as part of that stage's selection procedure under the Uniform Guidelines, the 1978 federal regulation covering everything from formal tests down to casual interviews. Applying it to some candidates and not others is where the difficult conversation starts, so have counsel read the final wording. Accommodations are the deliberate exception, handled as accommodations rather than as an informal loosening of the rule.
How often should this be revisited?
Once a year, plus whenever a stage changes. The clauses themselves are stable because they are written in verbs rather than tool names, which is the point of writing them that way. What ages is the assignment underneath: an exercise that a current assistant now completes end to end is no longer measuring what it was written to measure, and no policy wording fixes that. Review the exercise and the rule together.
References
- 1. 29 CFR Part 1607 - Uniform Guidelines on Employee Selection Procedures (1978), sections 1607.16(Q) and 1607.3(A) govinfo.gov Supports the claim that a rule governing who passes a hiring stage is part of a selection procedure, down to informal interviews and unscored application forms.
- 2. Testing of Detection Tools for AI-Generated Text arxiv.org Supports the claim that no independently tested AI-text detection tool is accurate or reliable enough to carry the consequence clause.
- 3. RAID: A Shared Benchmark for Robust Evaluation of Machine-Generated Text Detectors aclanthology.org Supports the claim that trivial character-level edits collapse detector accuracy, so what a detector surfaces is the candidates who were not hiding anything.
3 sources, numbered by first appearance. How Olive sources claims
General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.
Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.