Screening
Should You Hide an Instruction to Trap AI-Written Applications?
Don't hide an instruction in a job posting to catch AI-written applications; the trap sorts by how closely someone read. Hide the line properly and the only person it flags is the one who didn't reread their assistant's draft. Leave it buried in plain sight and a model follows it more reliably than a tired applicant reading at midnight. Either way you learn who proofreads, not who thinks. Say the AI rule in plain text instead, then ask a question whose good answer takes having done the work.
The takeNobody plants a trap because they believe it detects AI. They plant one because it costs nothing per application, and cost per application is the number that moved. My read is that this is the whole appeal: a screen nobody has to staff, reached for right as applying got cheap for everyone on the other side of the table. It won't hold. A filter that costs you nothing to run is a filter an applicant spends nothing to pass. The screens that survive the volume are the ones somebody still has to read.
Where Olive fits
Open a role and see what the work shows
No line you can put in a posting tells you who did the thinking, so Olive skips the artifact and assesses the person: a 40-to-60-minute occupational assignment done with an AI assistant, returned as six findings with the timestamped excerpt behind each one. The candidate is granted the same report.
Rank your shortlistWhat does hiding the line do to your posting?
It decides which candidates can read your posting at all, and the two ways of hiding a line fail in opposite directions. Content hidden with display:none or visibility:hidden is, in WebAIM's words, "removed from the visual flow of the page and is ignored by screen readers" 3, so a blind applicant never meets your instruction. Position it off-screen and "screen readers will read it" 3 while sighted readers do not.
There is no third technique that reaches everyone equally, because reaching everyone equally is the thing you are trying not to do. Whichever one you pick, some candidates are answering a different posting from the rest, and which group that is falls out of the assistive technology they use rather than out of anything about the job.
The listing most candidates see is not your page anyway. Google's job posting documentation says the feature "recognizes the following HTML tags: <p>, <ul>, and <li>" and does not recognize character-level tags 5. Three tags are recognized there and none of them is a way to make text invisible. The same page requires that "all information in the markup must be visible on the job page" 5, which is the reverse of what a trap is for.
Google's spam policies name your exact techniques too. Hidden text abuse is defined as "the practice of placing content on a page in a way solely to manipulate search engines and not to be easily viewable by human visitors", with "Using white text on a white background", "Using CSS to position text off-screen" and "Setting the font size or opacity to 0" given as examples 6. A trap line is not aimed at a search engine, so it may sit outside that definition, and the only carve-out for text that stays invisible covers text that exists only for screen reader users and is meant to improve their experience 6, which a trap is not either. That leaves an automated system deciding what you intended, on a document whose whole job is to be found.
The plumbing has a vote, too. Postings get syndicated, and boards, aggregators and ATS ingest pipelines sanitize markup on the way in. A careful white-on-white sentence can arrive at part of your audience as ordinary black text sitting in the middle of the requirements, where it reads as a typo or as an instruction the candidate had better follow. Part of the channel gets a trap and the rest gets a strange sentence.
Why does the trap stop working so fast?
Two clocks run against it and neither one is yours. A phrase planted in text a model retrieves is indirect prompt injection, the technique named in Greshake and colleagues' 2023 study of LLM-integrated applications, where adversaries exploit an application remotely by "strategically injecting prompts into data likely to be retrieved" 2. Assistants are being hardened against exactly that behavior. The second clock is your applicants, who talk to each other.
Postings circulate. One screenshot in a subreddit, one thread on a careers Discord, and everyone applying to that role knows the word. The people most likely to be in those channels are the ones already following hiring closely, which is again not the population you set out to sort. A trap that is public knowledge selects for being plugged in.
The artifact arms race has already run this experiment in public, and the detector lost. Seven detectors, run over 91 TOEFL essays written by non-native English speakers, produced a 61.3% average false-positive rate; at least one detector flagged 97.8% of those human-written essays as AI generated, all seven agreed on 19.8% of them, and the same tools "accurately classified the US student essays" written by eighth-graders 1. The study also reports that "a simple manipulation in prompt design can easily bypass current GPT detectors" 1. The full version of that question is whether AI detectors work at all in hiring, and the answer has not improved since.
The pattern holds for anything that tests the artifact rather than the person. Whoever produces the artifact gets to iterate, and you find out months later, from nothing. A trap is a detector you wrote yourself, with no measured error rate and no way to acquire one, because the only thing it ever returns is a count of applications that tripped it.
Could you explain this screen to the candidate?
Run that test before you plant anything. If a rejected applicant asks what happened and the honest answer is that a sentence they could not see decided it, the screen has to be defended by describing the ambush. A rule someone could have followed had they known it existed is a rule. One they could not is a trick, and the two read very differently out loud.
The asymmetry is the part that lands badly. You asked candidates to be straight with you by being less than straight about what your own document contains, in a market where they already suspect the process of being automated at them. Every applicant who spots the line learns something durable about how this company screens, and a job posting is a public artifact that gets screenshotted.
US law already has a name for a step like this. The Uniform Guidelines on Employee Selection Procedures, 29 CFR 1607.16(Q), adopted in 1978 and still in force, define a selection procedure as "Any measure, combination of measures, or procedure used as a basis for any employment decision", reaching "the full range of assessment techniques from traditional paper and pencil tests" through "informal or casual interviews and unscored application forms" 4. A hidden line used to move applications sits inside that definition rather than outside it for having been informal. Whether a particular trap produces adverse impact is an empirical question about your own applicants, so take it to counsel before it becomes a step in the process, not after.
The practical exposure is consistency. The trap fires on some applications and not others for reasons unrelated to the job: who read closely, which board they came through, what assistive technology they use. Sorting on that is the same failure as rejecting a candidate for sounding like AI, with a plausible-looking artifact attached to make the guess feel like evidence.
Ask a question whose answer needs the work
Put one question in the application that an assistant cannot finish alone, because answering it takes an act outside the conversation. Not "why do you want this role", which a model writes beautifully. Ask for a claim the candidate checked, what they checked it against, and what changed when they did. Someone who ran the check answers in specifics inside two sentences.
By role, each answerable in a short paragraph:
- Financial analysis. Name a figure in a recent filing you would re-derive before trusting it, and say what you would reconcile it against.
- Software engineering. Describe a bug you found in code you did not write. What made you look there?
- Marketing. Give a statistic you have seen quoted about this market, and say what the underlying sample actually was.
- Legal operations. Describe a time a cited authority did not say what the summary claimed it said, and how you caught it.
- Data and analytics. Name a result you stopped trusting, and what you recomputed to settle it.
A model will happily draft an answer to any of these. The good ones carry a specific object: a filing, a fixture, a sample size, a paragraph. The generated ones carry a shape. That difference takes about ten seconds to read, and unlike a trap word it is a difference about the work.
Then state the AI rule in the posting instead of hiding one inside it. A single line does most of the job: AI is allowed, and the application should name what was generated and what was verified. It is answerable, gradeable, and identical for everyone who reads the posting in any medium, including aloud. What to ask for on the application now that cover letters are all AI and how to write the AI requirement into the job description go further into the wording.
The question has a ceiling, and it is worth knowing where that sits before you lean on it. A written answer is a claim about an act rather than the act, so a candidate can describe checking a figure they never opened, and a good writer with an assistant can describe it well. Nothing a posting or an application form does gets past that, which is why the checking has to be watched somewhere later in the process. See how Olive measures this.
Common questions
Does a hidden instruction in a job posting actually catch AI applications?
It catches applications nobody proofread, which is a smaller group than AI use and not the same one. A candidate who reads the model's draft before sending removes the planted phrase without registering it as a test. You also cannot read a clean application: it might mean no AI, careful editing, or a job board that stripped your formatting before anyone saw the line. One signal, three explanations, and no way to tell them apart.
Is it legal to plant a hidden instruction in a job ad?
Nothing bans it outright, and it is not outside the rules that govern selection either. In the United States, the Uniform Guidelines on Employee Selection Procedures (29 CFR 1607.16(Q), adopted in 1978) define a selection procedure as any measure used as a basis for an employment decision, explicitly reaching informal techniques and unscored application forms 4. A hidden line that moves applications is a step in your process and gets judged as one. Whether yours produces adverse impact depends on your own applicant data, so take it to counsel first.
Will a screen reader read hidden text in a job posting out loud?
It depends how it was hidden, and both answers are bad. Content hidden with display:none or visibility:hidden is ignored by screen readers 3, so a blind applicant never encounters the instruction. Text positioned off-screen is still read aloud 3, so they get it and sighted readers do not. Either way, candidates are answering different versions of your posting, sorted by the assistive technology they use rather than by anything about the job.
Candidates are hiding prompts in their resumes. Shouldn't employers do the same?
Both sides of that exchange are betting on the same defect, and it is being closed. Instructions planted in retrieved text are indirect prompt injection 2, and assistants get harder to steer that way with every release. The escalation is also asymmetric: a candidate doing it risks one application, while an employer doing it writes a hiring practice into a public document. Treat a resume with a hidden prompt in it as a judgment call about that candidate, not as grounds for arming your posting.
What should the job posting say about AI instead?
Two lines of plain text do it: the rule, then a question the assistant cannot finish alone. The rule is a sentence: AI is allowed, and the application should name what was generated and what was verified. The question asks for a claim the candidate checked, what they checked it against, and what changed. A filing reconciled, a citation opened, a number recomputed. Both are visible to every applicant, survive syndication to any board, and read the same aloud.
Is it fine if the trap line is visible, just easy to miss?
It is a different tactic, and it fails in the other direction. An assistant handed the whole posting follows a stated instruction reliably, while the person who misses it is the applicant skimming at the end of a long day. An unusual instruction stated openly in the requirements is a fair test of whether someone read the posting, as long as it is genuinely readable and applied to everyone. It stops being fair the moment it is styled to be missed, because you are then measuring rendering rather than reading.
References
- 1. GPT detectors are biased against non-native English writers ✓ pmc.ncbi.nlm.nih.gov Seven detectors over 91 human-written TOEFL essays: 61.3% average false-positive rate, 97.8% flagged by at least one detector, 19.8% flagged unanimously, against accurate classification of 88 US eighth-grade essays; and a simple manipulation in prompt design easily bypassing current GPT detectors.
- 2. Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection ✓ arxiv.org Defines indirect prompt injection: adversaries remotely exploit LLM-integrated applications, without a direct interface, by strategically injecting prompts into data likely to be retrieved.
- 3. CSS in Action: Invisible Content Just for Screen Reader Users ✓ webaim.org display:none and visibility:hidden remove content from the visual flow of the page and are ignored by screen readers; content positioned off-screen is still part of the page content, so screen readers will read it.
- 4. 29 CFR 1607.16 - Definitions, Uniform Guidelines on Employee Selection Procedures ✓ law.cornell.edu Paragraph Q defines a selection procedure as any measure, combination of measures, or procedure used as a basis for any employment decision, reaching the full range of assessment techniques from traditional paper and pencil tests through informal or casual interviews and unscored application forms.
- 5. Job posting (JobPosting) structured data ✓ developers.google.com The job posting feature recognizes only the p, ul and li HTML tags and does not recognize character-level tags; all information in the markup must be visible on the job page.
- 6. Spam policies for Google web search ✓ developers.google.com Hidden text abuse is defined as placing content on a page in a way solely to manipulate search engines and not to be easily viewable by human visitors, with white text on a white background, CSS off-screen positioning and zero font size or opacity as examples; the stated exception is text accessible only to screen readers and intended to improve their experience.
6 sources, numbered by first appearance. Every one was opened and checked against the claim it carries. How Olive sources claims
General guidance for hiring teams. What works at one company and one volume may not transfer to yours.
Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.