Policy

Your Employee AI Policy Does Not Reach the Candidate

An employee AI acceptable-use policy does not reach a candidate, on three counts: the candidate never agreed to it, cannot reach the approved tools it names, and is not the risk it was drafted to control. Keep two documents that share exactly one sentence. The employee policy governs data and tool approval from the day an offer is accepted. The candidate rule governs what a stage measures, and expires with the process.

The takeThis question keeps getting answered wrong because both documents have the words AI policy on them, and only one of them was ever about hiring. Extending the handbook is the cheapest-looking option in the room and the most expensive one afterwards: the first time a candidate asks which clause they broke, somebody has to explain a document the candidate was never shown. Two short documents beat one long one that reaches nobody.

Where Olive fits

Open a role and see what the work shows

What Olive puts in front of a candidate is an invite link that belongs to that one person, and afterwards a report of six findings written by a human reviewer. The candidate is granted that report free on every tier, in the same words the employer reads.

Rank your shortlist

Why doesn't the employee policy reach an applicant?

Three reasons, and they compound. A candidate never accepted it: acceptable-use policies bind through employment, an acknowledgment click or a handbook sign-off, none of which an applicant has done. A candidate cannot comply with it either, because the approved-tools clause names accounts they have no access to. And the risk it controls is not the risk in front of you.

Read a typical policy clause by clause against an applicant and it empties out:

  • Approved tools only. They cannot use your enterprise account. Read literally, this bans them from doing the assignment at all.
  • No confidential or client data in prompts. Already true, since they hold none of yours.
  • Human review before anything ships. Nothing they produce ships.
  • Sanctioned accounts, logged and retained. No account exists to log.
  • Breach leads to disciplinary action up to termination. There is no employment to terminate.

What survives is one sentence about confidentiality and a general tone of disapproval. That is not a rule, and a candidate who reads it will correctly conclude it was written about somebody else.

The timing is the cleanest way to hold the boundary. The employee policy attaches when an offer is accepted and stays live for the length of the employment. The candidate rule attaches when a stage begins and dies when the process ends, whichever way it ends. Nothing needs to be reconciled between them because they never run at the same time on the same person.

Which risk is each document actually controlling?

Data leaving on one side, a wrong read on the other. The employee policy is a containment document: it exists so customer records and unreleased material do not end up in a third party's pipeline. The hiring rule is an evidence document: it exists so a reviewer does not read a polished artifact as proof of judgment the candidate does not have.

The second risk is the one with measured teeth. In a field experiment with consultants at a large firm, on one task deliberately chosen to sit outside the model's capability, people working with GPT-4 were 19 percentage points less likely to reach the correct answer, 84.5% in the control group against 60% and 70% in the two AI conditions 2. One task, one sample, and a 2023 model, so treat the size of it lightly. What travels is the shape: the failure was not laziness, it was that nobody could tell which side of the line the task was on.

That is what a hiring stage is trying to see, and no containment clause touches it. An approved-tools list does not tell you whether a candidate noticed the answer was wrong. A confidentiality clause does not tell you whether they checked. The employee policy is well drafted for its own question and silent on yours.

It also explains why "did you use AI" is the wrong question for a candidate rule to ask, even though it is the natural question for a handbook to ask. One document cares about where the data went. The other cares about what the person did with what came back, which is the argument developed in asking candidates how they used AI.

What is the one sentence that does travel?

Confidentiality over your own assignment material, and nothing else. That one holds because the candidate accepts it at the moment they open the work, it protects something real, a case you paid to write and intend to reuse, and it asks nothing they are unable to do. Everything else in the handbook needs an employment relationship before it means anything.

Bind it where the work is handed over, in one line rather than a four-page agreement: this exercise and any material in it stays between you and the hiring team, and please do not post it publicly. That is proportionate, and a candidate will honour it. A full mutual NDA at the take-home stage reads as a company that has confused an applicant with a vendor, and it costs you people.

Beyond that, the boundary is legal rather than contractual, and it runs the other way than most people expect. The Uniform Guidelines on Employee Selection Procedures, the 1978 federal regulation at 29 CFR Part 1607, define a selection procedure as any measure or procedure used as a basis for an employment decision, broad enough to name informal or casual interviews and unscored application forms 1. Your candidate AI rule sits inside that definition, because it changes who passes a stage. Your staff handbook does not. The Guidelines attach a validation burden only where adverse impact shows up, so what that means for your own stages is a question for counsel.

What the candidate rule should actually say, clause by clause, is set out in the five clauses a candidate AI-use policy needs, and the sign-off and review questions around it are in what belongs in an AI hiring policy.

Check where the handbook already leaks into hiring

The leak is usually on your side, not the candidate's. A recruiter pasting resumes into a general assistant, a manager asking a model to compare two finalists, a coordinator running an AI notetaker through an interview: that is staff using AI on candidate data, and it is where the employee policy is genuinely in scope and usually silent.

California's amended employment regulations show why that matters. Since October 1, 2025 they cover automated-decision systems, defined as a computational process that makes or facilitates a decision about an employment benefit, and they name resume screening for particular terms or patterns as an example 34. A recruiter improvising with a chat window on a shortlist is doing something the regulation describes, with no procurement decision and no vendor review behind it. Nothing in these regulations requires telling a candidate an automated-decision system was used, which is part of why this version goes unnoticed.

Five things to check in your existing document, all of them on the employer side:

  • Whether it says anything at all about candidate data, or only about customer data.
  • Whether recruiters are inside or outside the approved-tools rule in practice.
  • Whether an AI meeting notetaker counts as an approved tool, and who consents to it.
  • What happens to a chat transcript containing an applicant's details, and for how long.
  • Who is told when a hiring-adjacent use starts, and whether anyone is.

Fix those in the employee policy, where they belong. What you may ask candidates about their own use is a separate question with a separate answer, covered in whether you can legally ask candidates how they use AI, and the specific risk of dropping applicant material into a general chatbot is in pasting resumes into ChatGPT.

Read the evidence

Common questions

Can we just add a candidate section to the existing employee policy?

Nothing stops you, and it usually goes badly. The candidate rule has to be short, readable in ten seconds and delivered with the assignment. Buried as section 9 of a staff document, it reaches nobody it is written for, and the surrounding clauses about approved accounts and disciplinary action stay visibly inapplicable. If the governance process requires one document, keep the candidate wording as a standalone appendix that can be lifted out whole and pasted into an assignment brief.

What binds a candidate to anything at all, then?

What they accept at the moment they take part. Application terms, the assignment brief they open, and the invite they accept are all points where a short, specific commitment is reasonable and actually reaches the person: keep the exercise confidential, tell us what you used, do your own work. Anything further back than that, including a handbook they have never seen and a policy page they never opened, is a document you would rather not have to rely on.

Does an employee AI policy matter once the candidate is hired?

Yes, and the handoff is worth building deliberately. The day an offer is accepted, the employee policy attaches and the candidate rule falls away. Onboarding is the moment to say so plainly, because a new hire who was told to use an assistant freely on a take-home and is then dropped into an approved-tools regime with no explanation will assume one of the two documents was not serious. Name the change on day one.

Our vendor's assessment tool has its own candidate terms. Does that cover us?

It covers the vendor. The employer stays responsible for what a selection procedure does in its own process, and buying a tool does not move that. California's amended employment regulations, effective October 1, 2025, go further and treat an agent acting for an employer, including a vendor running the system, as an employer under the Act, which adds a defendant rather than removing one. Read the vendor's candidate-facing terms as a starting draft, not as your policy.

Is a confidentiality clause on a take-home enforceable?

Enforceability is a question for your own counsel, and it is rarely the one that matters. The remedy you actually want is that the exercise stays off public forums, not damages. Keep the ask to a sentence delivered with the material, so the candidate sees it at the moment they agree to it. Over-reach is what makes the clause a problem in the room whatever a court would later make of it: a term claiming ownership of the candidate's ideas, or restricting where they may work next, costs you the candidate in front of you.

References

  1. 1. 29 CFR Part 1607 - Uniform Guidelines on Employee Selection Procedures (1978), sections 1607.16(Q) and 1607.3(A) U.S. Government Publishing Office, Code of Federal Regulations (Title 29, Vol. 4, 2023 edition), 1978. govinfo.gov Supports the claim that a candidate-facing AI rule falls inside the definition of a selection procedure while a staff handbook does not.
  2. 2. Navigating the Jagged Technological Frontier: Field Experimental Evidence of the Effects of Artificial Intelligence on Knowledge Worker Productivity and Quality (Working Paper 24-013) Harvard Business School, 2023. mitsloan.mit.edu Supports the claim that the hiring risk is a confident wrong answer on a task that looks like one AI handles well, which is a different risk from data leaving.
  3. 3. Final Unmodified Text of Proposed Employment Regulations Regarding Automated-Decision Systems (Attachment B), 2 CCR sections 11008, 11008.1 California Civil Rights Department, Civil Rights Council, 2025. calcivilrights.ca.gov Supports the October 1, 2025 effective date, the automated-decision-system definition covering resume screening, and the vendor-as-employer clause.
  4. 4. Rulemaking Actions - Civil Rights Council California Civil Rights Department, Civil Rights Council, 2025. calcivilrights.ca.gov The Council's own record of the automated-decision-system employment regulations: approved by OAL and filed with the Secretary of State, effective October 1, 2025.

4 sources, numbered by first appearance. How Olive sources claims

General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.

Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.

Back to answers

Open your first role Ten attempts a month against a live item bank, with a human-written report on every one.