Screening

Pasting Resumes Into a Chatbot Is a Regulated Employment Decision

Nothing forbids a manager pasting resumes into a chatbot to compare candidates. The problem is doing it off-system: no notice, no record, no consistent criteria across applicants, and candidate personal data in a consumer account with unclear retention and training terms. Since January 1, 2026 Illinois has treated AI with a discriminatory effect in recruitment or hiring as a civil rights violation. California counts a computational process that facilitates an employment decision as one whose inputs and outputs a covered employer keeps for four years.

The takeAI hiring policies get written for the tools somebody bought, because those are the ones with a contract, an invoice and an owner. A manager, a browser tab and forty PDFs at eleven at night has none of those, which is why it gets no clause. Write that clause first. The exposure your organisation cannot account for is the one nobody approved, nobody logged and nobody thought to name.

Where Olive fits

Open a role and see what the work shows

Since a resume no longer tells you who wrote it, Olive assesses the work rather than the document: a 40-to-60-minute assignment grounded in the role, done alongside an AI assistant, returned as six findings each carrying the moment in the session it came from. The candidate receives the identical report.

Rank your shortlist

What rule does this break?

Two of them, and neither is a rule about chatbots. Since January 1, 2026 the Illinois Human Rights Act has made it a civil rights violation to use AI with the effect of discriminating in recruitment or hiring, and separately to fail to notify an employee that AI is being used for those purposes 1. Its definition of artificial intelligence covers a machine-based system generating recommendations that can influence an outcome, and expressly includes generative AI 1.

The notice clause has a gap the discrimination clause does not. It runs to an employee, and Article 2 of that Act defines an employee as someone performing services for remuneration, an apprentice, or an applicant for an apprenticeship 1. Whether an ordinary job applicant is owed notice is left to Illinois Department of Human Rights rulemaking, which the statute also hands the timing, circumstances and means of notice 1. The discrimination clause names recruitment and hiring outright, so it reaches the resume pile either way.

California reaches the same activity from a different direction. Its amended employment regulations, effective October 1, 2025 and binding on California employers with five or more employees, define an automated-decision system as a computational process that makes or facilitates a decision about an employment benefit, and they name screening resumes for particular terms or patterns as an example 25. Facilitates is the operative word: a tool that only advises a human is still inside the definition.

Then comes the part that costs money rather than embarrassment. The same amendments extended the employment-records retention period from two years to four and stated expressly that automated-decision-system data is included 2. The four years run from the record's creation or the personnel action, whichever is later 2. A chat transcript in a personal account is that data, held somewhere your company cannot reach, under a retention setting nobody chose.

The near miss belongs to New York City. Its rule attaches where a tool substantially assists or replaces discretionary decision-making, and an employer that decides its tool merely informs a human reviewer takes itself out of scope 3. That argument is available to you. It is not available to a manager who never told anyone, because there is no record of what the tool did or how much weight it carried.

Why is the bias warning the wrong worry?

Visible risk is the manageable kind. A careful reader who knows the model can be wrong reads the output sceptically, checks the ones that matter, and catches most of it. Nobody catches a missing record. The procedural failure leaves no symptom at the moment it happens and produces its consequence eighteen months later, in writing, to somebody else.

The quality warning has one measured version. In a Harvard Business School field experiment with Boston Consulting Group consultants, on one task deliberately chosen to sit outside the model's capability, those using a 2023 model were on average 19 percentage points less likely to reach the correct answer than the control group 4. That is one task and one sample on a model that is no longer current, and the finding is not that AI makes people worse. It is that people could not tell which side of the capability line the task was on.

Resume comparison sits close to that line. It has the shape of summarisation, which models handle well. What it demands is inference about a person from thin evidence, which they handle confidently and badly. The failure mode is a plausible ranking of candidates on a criterion the model invented, which reads exactly like a plausible ranking on the criterion you meant.

Notice the same mistake running the other way through the funnel: managers rejecting applicants for sounding like a machine wrote their resume. If that is happening in your process too, how to stop managers rejecting candidates for sounding like AI covers the other half of it.

Write the criteria first, then run it somewhere the company controls

Two fixes, both free, and the first one carries most of the weight. Write the evaluation criteria down before you open the tool, and apply the same ones to every candidate in the pool. Then do the work inside an account your organisation administers, so the inputs and outputs land in a place a records request can reach.

The first fix changes what the artefact is. If the criteria exist in a document, the transcript becomes working notes about criteria you can produce and defend. If they do not, the transcript is the only evidence of how the decision was made, and it says whatever the model happened to emphasise that evening. The order matters more than the wording: criteria written afterwards to match an outcome are worth nothing and read as exactly that.

The second fix changes where the data lives. A company workspace is where three things become settings somebody is accountable for: whether the content trains a model, how long the history is kept, and who can export it. A personal account gives you none of those levers and no way to check which way they are set. This is also the moment to check whether the tools already in your stack are doing the same thing quietly, which is the question behind whether your ATS counts as AI.

Three smaller habits close most of what remains:

  • Paste the same fields for every candidate, decided before you open the first PDF.
  • Ask the model to apply your written criteria and quote the line it relied on, then read that line yourself.
  • Keep the shortlist decision in your own words, in the ATS, so the human judgment is the record.

A controlled workflow does not make the resume screen good. It makes it defensible, which is a different and smaller claim. The deeper problem, that every resume now reads well, is worked through in what is actually left to screen on.

What if a chatbot has already been part of a live requisition?

Tell HR and counsel, and do not delete the chat. Deleting it converts a compliance gap you can explain into a records problem you cannot, and the transcript is the only evidence of what actually happened. Preserve it, export it if you can, and let the people whose job this is decide what the requisition needs.

Then work out what is owed going forward. If the pipeline included candidates in a jurisdiction with a notice duty, a late notice still beats none, and giving it now is better in every direction. The content and the timing are laid out in what your AI notice has to say and when.

Expect the harder question to come from a candidate before any regulator asks. Someone rejected during that stretch may ask how the decision was made, and the honest answer involves a tool nobody disclosed. That conversation is survivable and it has a shape: what a rejected candidate is owed when AI was involved.

Finally, write the clause that would have prevented it. Most AI hiring policies govern purchased tools and say nothing about the browser tab, which is why the browser tab is where the exposure accumulated. The full set of clauses and the sign-off question sits in what actually belongs in an AI hiring policy. Make the manager case the first paragraph rather than an appendix.

See a sample report

Common questions

Is it different if I strip names off the resumes first?

It helps with one problem and not the others. Removing names reduces some obvious bias vectors, though schools, dates and employers carry plenty of signal on their own. It does nothing about notice, nothing about records, and nothing about consistency of criteria. Redaction is worth doing, but treating it as the fix mistakes a data-handling improvement for a process one.

Does it matter that the model only recommends and I make the decision?

Less than most people assume. California's definition covers a computational process that facilitates a decision, not only one that makes it. New York City's rule turns on whether the tool substantially assists or replaces discretionary decision-making, and how much weight the output carried is the whole question. A human who accepts the recommendation nearly every time is not adding much review, and that pattern is visible in the data long before anyone admits to it.

Can I use AI to write the job description instead? Is that safer?

Safer, yes, because no candidate is being evaluated. Drafting a posting is content generation rather than an employment decision, so the notice and records questions do not attach in the same way. The remaining risks are ordinary ones: requirements that were never true of the role, and language that narrows the applicant pool without anybody choosing to.

What should the company workspace setting actually be?

Training off, retention set to match your hiring-records schedule, admin export available, and access logged. Confirm the training setting in the contract rather than in a product page, since defaults change between plans and between releases. If the answer is that nobody knows which plan the company is on, that is the finding, and it is worth more than any policy paragraph.

Is this a problem outside California, Illinois and New York City?

The specific statutes are, and the general one is everywhere. Federal discrimination law does not care what tool produced a disparity, and an employer that cannot show the criteria it applied is in a weak position wherever it is. State law is also moving fast and inconsistently, with intent standards in some states and effects standards in others, so a process that depends on being in a permissive jurisdiction is a process with an expiry date.

References

  1. 1. HB3773 Enrolled (Public Act 103-0804), amending the Illinois Human Rights Act Illinois General Assembly, 2024. ilga.gov Supports the January 1, 2026 effective date, the effects standard for AI used in recruitment and hiring, the separate notice clause and the term it runs to, the delegation of notice timing and means to IDHR rulemaking, and the statutory definition of artificial intelligence including generative AI.
  2. 2. Final Unmodified Text of Proposed Employment Regulations Regarding Automated-Decision Systems (Attachment B), 2 CCR sections 11008, 11008.1, 11009, 11013 California Civil Rights Department, Civil Rights Council, 2025. calcivilrights.ca.gov Supports the October 1, 2025 effective date, the five-or-more-employee scope, the automated-decision-system definition covering a process that facilitates a decision, resume screening as a named example, and the move from two years to four for records including that data.
  3. 3. Automated Employment Decision Tools: Frequently Asked Questions NYC Department of Consumer and Worker Protection (DCWP), 2023. nyc.gov Supports the substantially-assists-or-replaces scope limit and the fact that the employer makes that scope call itself.
  4. 4. Navigating the Jagged Technological Frontier: Field Experimental Evidence of the Effects of Artificial Intelligence on Knowledge Worker Productivity and Quality (Working Paper 24-013) Harvard Business School, 2023. mitsloan.mit.edu Supports the 19 percentage point average drop in correctness on one task chosen to sit outside the model's capability.
  5. 5. Rulemaking Actions - Civil Rights Council California Civil Rights Department, Civil Rights Council, 2025. calcivilrights.ca.gov The Council's own record of the automated-decision-system employment regulations: approved by OAL and filed with the Secretary of State, effective October 1, 2025.

5 sources, numbered by first appearance. How Olive sources claims

General guidance for hiring teams. What works at one company and one volume may not transfer to yours.

Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.

Back to answers

Open your first role Ten attempts a month against a live item bank, with a human-written report on every one.