Skip to content
Chatbotscape
European Commission, NYC DCWP and eCFR pages read 28 August 2026; review corpus re-searched the same day
Candidate screening· Recruitment operations and compliance
Candidate screening is the step between receiving applications and interviewing anybody: narrowing a pool against stated criteria so that a human only spends time on the people who could plausibly be hired. It covers eligibility checks, knockout questions, resume review, ranking and shortlisting. When software performs any part of it, the screening step is where employment law attaches, because it is the first point at which a candidate is removed from consideration.
By Chatbotscape Editorial· Methodology· Published 29 August 2026· Updated 29 August 2026

Candidate Screening — The Line Where a Recruiting Chatbot Stops Being a FAQ Bot and Becomes a Regulated Instrument

Quick answer: Candidate screening is the narrowing step: turning everyone who applied into the shortlist somebody will actually talk to. On a chatbot project the definition matters less than the boundary it draws. A bot that answers what is the shift pattern is a support bot that happens to be talking to applicants. A bot that asks do you have a forklift license and routes the "no" answers out of the pipeline is performing selection, and four separate bodies of law have something to say about that. The surprise for anyone who spent 2026 preparing is which one binds first. The EU AI Act names recruitment screening as high-risk in Annex III, but the obligations that follow were moved to 2 December 2027 by the AI Omnibus that entered into force on 27 July 2026. Meanwhile Illinois has required notice and consent before AI analyzes a video interview since 1 January 2020, New York City's bias-audit and notice rules have been enforced since 5 July 2023, and the broader Illinois AI notice duty took effect on 1 January 2026. The rule that was six days away is now fifteen months away. The rules that felt like somebody else's problem have been live for years.

The mechanics, briefly, because they are the easy part

Screening in a conversational interface is slot filling with a decision attached. The bot collects a small set of values and compares each to a rule.

Knockout questions are the sharp instrument: binary, verifiable, and disqualifying on a single answer. Are you legally authorized to work in this country? Do you hold a current commercial driving license? Can you work the 6am shift? Each is a hard requirement of the job, each has an unambiguous right answer, and a "no" ends the application there.

Ranking questions are the soft instrument, and they behave very differently. How many years have you spent in a customer-facing role? Rate your Excel skills. Nothing here disqualifies on its own; the answers feed a score, and the score orders the pile.

That distinction does real work. A knockout question implements a stated requirement that a candidate can read on the posting and check for themselves. A ranking question implements a preference, expressed as a number, that nobody outside the company can inspect. Nearly everything difficult about screening software concentrates on the second kind, and so does the legal exposure.

Two words that get used interchangeably and should not be. Pre-employment screening usually means background and reference checks run on someone you have already chosen, and in the United States it drags in the Fair Credit Reporting Act and a different set of duties entirely. This entry is about the earlier step. If you are building a bot that touches criminal records, credit files or verification vendors, stop reading here and talk to counsel.

Why the same bot changes category when it starts narrowing

Under New York City's Local Law 144 of 2021, the operative object is an automated employment decision tool: in the statute's words, "any computational process, derived from machine learning, statistical modeling, data analytics, or artificial intelligence, that issues simplified output, including a score, classification, or recommendation, that is used to substantially assist or replace discretionary decision making for making employment decisions that impact natural persons." The definition carries its own carve-out for tools that do not substantially assist or replace discretionary decision-making and do not materially impact people, which is the statute drawing the same line this entry draws. A bot that returns a shortlist issues a classification. A bot that answers questions about the dress code does not.

Where a tool meets that definition, the city's Department of Consumer and Worker Protection summarizes the duties this way: the tool must "have been subject to a bias audit within one year of the use of the tool," information about that audit must be "publicly available," and "certain notices have been provided to employees or job candidates." The notice must be given 10 business days before use — a period set by the Administrative Code at §20-871(b), which we read in secondary form, and which DCWP's own page records itself having clarified in June 2023 — and DCWP records that enforcement began on 5 July 2023. DCWP has been enforcing this for three years. Note that the two duties are not scoped identically: the notice provision is written for candidates and employees who reside in the city, and the audit and publication provisions are not written that way. Which of your roles and applicants the law reaches is a question for counsel, and we are not going to guess at it for you.

Illinois legislated earliest of anyone and has legislated twice. Its Artificial Intelligence Video Interview Act has required notice, an explanation of how the system works and the applicant's consent before AI analyzes a video interview since 1 January 2020, which makes it the oldest US statute in this area and one that most 2026 coverage skips. The broader duty arrived later: the amendment to the Illinois Human Rights Act made by HB 3773 took effect on 1 January 2026. It makes it a civil rights violation for an employer to use artificial intelligence with the effect of discriminating on the basis of a protected class, to use zip codes as a proxy for a protected class, and to fail to give notice that AI is being used for covered employment decisions — a list that begins with recruitment and hiring. There is a wrinkle worth knowing: the Department of Human Rights published proposed implementing rules in May 2026 and then withdrew them, so the statutory notice duty binds while no regulation defines what a compliant notice looks like. That asymmetry is uncomfortable and it is the current state.

Europe named the same activity and then postponed the consequences. Annex III point 4(a) of the AI Act lists as high-risk "AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates." Article 6(3) offers a way out for systems that perform only a narrow procedural task, and then closes it for exactly the case at hand: "an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons." Scoring applicants is profiling. There is no version of a ranking bot that squeezes through the derogation.

But the timing changed, and the direction of the change is the opposite of what most 2026 planning assumed. The AI Omnibus entered into force on 27 July 2026, six days before the high-risk rules were due. The Commission's own summary lists, under Extended timelines, that rules for "High-risk AI systems in Annex III" now "apply starting 2 December 2027." What did not move is the AI Act's general application on 2 August 2026, including the Article 50 duty to tell a person they are talking to a machine — the obligation our customer service automation guide works through in detail. So a recruiting bot in the EU today owes disclosure and not a conformity assessment — and Article 50(1) writes that disclosure duty on the provider of the system rather than on the employer renting it, which is the part buyers most often get backwards.

The United States has been moving the other way at federal level while the cities and states move toward regulation. The EEOC's two technical-assistance documents on algorithmic hiring, one under Title VII and one under the ADA, were removed from eeoc.gov in late January 2025 and still return 404 as of 28 August 2026, with no replacement issued. What was removed was guidance. Title VII was not amended, and the Uniform Guidelines on Employee Selection Procedures remain in the Code of Federal Regulations, including the four-fifths rule at 29 CFR 1607.4(D). A vendor who reads the deletions as a reduction in your exposure is selling you something.

What our own reviews record, which is close to nothing

This is the part we can answer from first-hand work rather than from law, and the answer is a warning.

We publish fifteen platform reviews. Searched case-insensitively on 28 August 2026, the words recruitment, recruit, candidate and applicant appear in zero of them. "Hiring" appears once, in a Manychat user-review summary about scaling without hiring staff. No review in the corpus describes a recruiting use case, because none of these platforms is sold for one.

Two capability questions follow, and both have uncomfortable answers.

Can it talk to your applicant tracking system? A word-bounded, case-insensitive search for sixteen ATS and HRIS vendor names across all fifteen reviews returns three files, and two of them are false positives: "lever" in the Chatfuel review is the English noun, and "workable" in the AiSensy and Chatfuel reviews is the English adjective. What survives is one genuine hit: a BambooHR card among the 200-plus listings in the Botpress integration Hub. BambooHR sells applicant tracking as part of its suite, so calling it "not an ATS" would be too convenient; what our review actually records is the existence of the Hub card and nothing about what it exposes, so whether that integration reaches the hiring module is something we cannot tell you. No review in the corpus documents an integration with a dedicated recruiting ATS, and the single HR-suite hit is unresolved. Anything you build will reach the system of record through a webhook or a general automation tool, which works, and is a project rather than a checkbox. Our chatbot integration guide covers what that costs.

Can the candidate attach a CV? Most of the file-upload language in the corpus turns out, on reading, to be administrators uploading documents to train a knowledge base — Landbot indexing PDFs, Botpenguin's file-upload ingestion mode, AiSensy's knowledge-base attachment — or an agent attaching files in a shared inbox, which Manychat records and no other review does. Respondent-side upload, as a builder input, is documented in two reviews: Tars, whose builder ships "pre-built node types for structured data collection (number, email, phone, file upload, multi-select)," and Typebot, whose input types include file upload. In Typebot's case our review also records that file uploads sit on the Starter tier at $39 a month monthly-billed, not on Free.

Two caveats we would rather state than have pointed out. First, absence from a review is absence of a recorded finding, not proof a platform lacks a feature; these were general-purpose evaluations and nobody asked a recruiting question. Second, these are our own reviews at their own verification dates, and product surfaces move. The finding that survives both caveats is narrower and still useful: if you are choosing a chatbot platform to screen candidates, the two capabilities the job actually requires are the two our corpus is quietest about, and neither will appear in a feature comparison because nobody is marketing to you.

Where screening bots go wrong

The knockout question that is really a proxy. Do you live within 20 minutes of the depot sounds operational. Illinois legislated specifically against zip codes standing in for protected classes, and a commute-time filter is a zip-code filter wearing a stopwatch. Ask about availability for the shift, which is the thing you actually need.

The score nobody can explain. If a language model ranks free-text answers, the ordering exists and no one in the building can reconstruct it. That is difficult under any disparate-impact analysis and it is the pattern Article 6(3) refuses to exempt. Score against explicit criteria, or do not score.

Data collected because the field was there. Applicants type things into free text that you never asked for and are not allowed to consider. Our entity extraction entry covers why the fields you defined are not the data you now hold, and data retention policy covers how long you are keeping it — which for applicant records is a question with its own answers in several jurisdictions.

No way out. A candidate who cannot complete the flow is a candidate you rejected by accident. NYC's notice provision is built around telling candidates how to ask for an alternative selection process or an accommodation, which is a disclosure duty rather than a guarantee that one exists. Beyond compliance, a working human handoff is the difference between a screen and a wall.

FAQ

What is candidate screening?

It is the narrowing step in hiring: reducing everyone who applied to the people worth interviewing, by checking applications against stated criteria. In practice it covers eligibility and knockout questions, resume review, ranking and shortlisting. It sits after sourcing and application, and before interviewing. When software performs any part of it, screening is the step where employment law attaches, because it is the first point at which a candidate is removed from consideration.

What is the difference between a knockout question and a screening question?

A knockout question disqualifies on a single answer and implements a hard requirement of the job: work authorization, a required license, availability for the shift. A screening question is the broader category and includes questions whose answers feed a score rather than ending the application. The practical test is whether a candidate reading the job posting could predict the outcome of their own answer. If they could, it is a knockout. If the answer disappears into a ranking they cannot see, it is not, and it carries more risk.

Does a recruiting chatbot count as an automated employment decision tool?

It depends entirely on what the bot does with the answers, not on what the bot is called. Local Law 144 defines an AEDT as a computational process that issues a "simplified output, including a score, classification, or recommendation" used to substantially assist or replace discretionary decision making for employment decisions. A bot that answers questions about the role issues no such output. A bot that produces a shortlist, a rank or a pass/fail almost certainly does. The city's rules further define "substantially assist or replace" to reach cases where the output is relied on alone, weighted more heavily than any other criterion, or used to overrule other factors. That is a question for your counsel on your specific configuration, and the answer changes when you change the flow.

Is a recruiting chatbot high-risk under the EU AI Act?

If it analyzes, filters or evaluates applications, Annex III point 4(a) covers it, and Article 6(3)'s derogation for narrow procedural tasks is unavailable to any system that performs profiling of natural persons — which scoring candidates is. But the obligations that follow from that classification were postponed. The AI Omnibus entered into force on 27 July 2026 and the Commission's summary states that rules for high-risk systems in Annex III "apply starting 2 December 2027." Separately, and unchanged, the AI Act became generally applicable on 2 August 2026, so the Article 50 duty to disclose that a person is interacting with an AI system reaches a recruiting bot in the EU today. Article 50(1) places that duty on the provider of the system, so for most SMB buyers it describes the vendor and your job is to confirm the disclosure is present.

Do I need a bias audit for my hiring chatbot?

If Local Law 144 reaches you, the audit obligation attaches to the tool, must have been conducted within one year of use, and its summary must be published before use. Note where the duty sits: on the tool, not on your own hiring numbers. That placement is doing real work, because a small employer's applicant volumes are far too small for a fairness ratio computed on them to be informative. Our recruitment chatbot guide works the arithmetic through and publishes the code, and flags that the calculation is ours and endorsed by no authority. The practical consequence is that this is a procurement question. Ask the vendor for the audit, in writing, before you buy.

Can a general chatbot platform do candidate screening?

Mechanically, the conversation part is easy; it is slot filling with rules. The two hard parts are the ones our corpus is quiet about: getting a CV out of the candidate, which two of our fifteen reviews document as a builder input, and getting the result into your applicant tracking system, which none of them document at all. Budget for webhook work and check the file-upload capability on the specific tier you intend to buy rather than on the pricing page's feature list.

Did the EEOC's AI hiring guidance go away?

The two technical-assistance documents — one on adverse impact under Title VII, one on the ADA — were removed from eeoc.gov in late January 2025 and were still returning 404 when we checked on 28 August 2026, with no replacement published. Archived copies exist. What did not change is the underlying law: Title VII stands, and the Uniform Guidelines on Employee Selection Procedures remain in the Code of Federal Regulations, four-fifths rule included, at 29 CFR 1607.4(D). What was withdrawn was the agency's explanation of the law, and the law it explained is unchanged.

Sources

  • European Commission, Directorate-General for Communications Networks, Content and Technology. AI Omnibus enters into force, news article, publication date 27 July 2026, page's own last-update stamp 31 July 2026, read 28 August 2026. Source of: the 27 July 2026 entry into force, and the Extended timelines statement that rules for high-risk AI systems in Annex III "apply starting 2 December 2027" and for Annex I embedded products from 2 August 2028. ec.europa.eu
  • Regulation (EU) 2024/1689 (the AI Act), Annex III point 4(a) and Article 6(3). Quoted verbatim for the recruitment listing and for the profiling backstop. Attribution note: both passages were read from a secondary republication of the consolidated text rather than from the Official Journal, and are quoted here as the Regulation's wording; a reader relying on the exact text for a compliance decision should confirm against EUR-Lex (CELEX 32024R1689). The Article 50 transparency duty referenced in the body is covered, with its own primary sourcing, on /academy/customer-service-automation-guide and is not re-derived here.
  • New York City Department of Consumer and Worker Protection, Automated Employment Decision Tools (AEDT), read 28 August 2026. Source of the summary of duties quoted in the body — bias audit "within one year of the use of the tool," public availability of audit information, required notices — and of the two dates: DCWP's note that enforcement began 5 July 2023, and its record that the presentation slides were revised in June 2023 "to clarify that the Notice must be provided 10 business days prior to use of an AEDT." nyc.gov
  • New York City Administrative Code §20-870 (definition of "automated employment decision tool") and the DCWP rules at 6 RCNY §5-300 (the three-limb definition of "substantially assist or replace discretionary decision making" summarized in the FAQ). The statutory definition is quoted verbatim; the rules definition is summarized rather than quoted, because we read it in secondary form and an earlier, widely circulated draft of that rule used different wording. Penalty amounts are deliberately not stated on this page: the statutory range and DCWP's administrative schedule differ, and quoting either alone misleads.
  • Illinois Public Act 103-0804 (HB 3773), amending the Illinois Human Rights Act, effective 1 January 2026. Relied on for: the effective date, the prohibition on AI use with a discriminatory effect, the zip-code proxy provision, and the notice duty. Secondary reading, corroborated across the Illinois General Assembly bill-status record and multiple independent law-firm summaries rather than read from the enacted text, and labeled as such. The May 2026 publication and subsequent withdrawal of the Department of Human Rights' proposed implementing rules is likewise a secondary reading.
  • U.S. Equal Employment Opportunity Commission. Status of the two AI technical-assistance documents ("Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII" and the ADA companion) checked by HTTP request on 28 August 2026: both URLs return 404 with no redirect and no removal notice. Archive snapshots on the Internet Archive place the removal in late January 2025. We report the HTTP status and the archive dates as facts and make no claim about the reason. No replacement AI guidance has been published.
  • 29 CFR 1607 (Uniform Guidelines on Employee Selection Procedures), §1607.4(D), consulted on eCFR 28 August 2026 for the four-fifths rule and its own caveat that greater differences in selection rate "may not constitute adverse impact where the differences are based on small numbers and are not statistically significant." Cited as regulation text in force, not as advice about its application. A proposed rescission of UGESP appears on the Unified Agenda; no proposed or final rule had been published as of 28 August 2026, and an agenda entry is a plan to regulate rather than a regulation. ecfr.gov
  • Chatbotscape review corpus, searched 28 August 2026 and published so the counts reproduce. Denominator: ls sample-reviews/*-review.md | wc -l returns 15. A grep -v v1.backup filter appeared in an earlier draft of this note and has been removed as method theater: manychat-review.v1.backup.md does not end in -review.md, so the glob never matched it and the guard implied a hazard that does not exist here. Recruiting vocabulary: grep -rliE "recruit|recruitment|candidate|applicant" sample-reviews/*-review.md returns 0; grep -rliE "\bhiring\b" sample-reviews/*-review.md returns 1 (manychat-review.md, in a user-review summary). ATS and HRIS names: grep -rliE "\b(greenhouse|lever|workable|ashby|smartrecruiters|icims|jobvite|teamtailor|recruitee|breezyhr|jazzhr|workday|taleo|successfactors|bullhorn|bamboohr)\b" sample-reviews/*-review.md returns 3 files, and each matched line was read in context before classification, per the rule established on /glossary/data-retention-policy. Two are false positives on ordinary English words — "lever" (Chatfuel, three occurrences, all the noun) and "workable" (AiSensy and Chatfuel, the adjective). The single genuine hit is BambooHR in botpress-review.md, an HRIS listed among the Hub's integration cards. Publishing the file count alone would have reported three ATS integrations where there is at most one, and that one unresolved, which is the same failure mode as the corpus-counting errors recorded on /glossary/data-retention-policy and /glossary/business-associate-agreement, arriving this time from the opposite direction. File upload: grep -rinE '\b(upload|uploads|uploaded|uploading|attachment|attachments)\b' sample-reviews/*-review.md matches all fifteen reviews across seventy-three lines, every one of which was read before classification. The overwhelming majority of those lines describe an administrator loading documents into a knowledge base, and all fifteen reviews record that somewhere; two more describe an administrator uploading a brand asset into the widget (botpress-review.md:694 bot avatar, chatfuel-review.md:668 widget appearance image). That is why a naive file-upload search tells a recruiting buyer nothing. Sorting what is left by who is sending the file gives three groups. Respondent-side, as a builder input node, vendor-documented: two — Tars (tars-review.md:208) and Typebot (typebot-review.md:187). Upload capability recorded without establishing who sends the file: four — Intercom :230 "Standard image upload in conversations", Landbot :220 "image upload supported in flows", Chatbase :460 an "Upgrade for attachments & advanced models" gate in the model playground, and Tidio :725 a "Larger attachments" row in a plan-comparison screenshot. The first two are at least located inside a conversation or a flow; the Chatbase and Tidio hits are a paid-tier gate and a feature list, so they establish that something exists and nothing about where it appears. Grouping them together is our editorial call and the weakest classification on this page. Agent-side, inside a shared inbox: two — Manychat :731 (inbox reply tools) and AiSensy :185/:606 (multi-agent inbox image uploads, recorded as occasionally unreliable). This classification has now been rebuilt twice and was wrong both previous times, in both directions: a first draft filed Tidio as agent-side on a line that is a pricing row, and the correction that followed enumerated buckets from a partial search that silently omitted Voiceflow, Intercom, Landbot, Wati and the AiSensy inbox hit while presenting itself as exhaustive. Neither error moved the headline, which is that exactly two reviews document a respondent-side file-upload input; both were failures to publish a command that produces the published set, which is the one thing this section exists to do. The Typebot tier and price are quoted as that review recorded them and are monthly-billed per our pricing methodology. None of these findings was established in a hands-on recruiting test; no review in the corpus ran one.
  • Ahrefs Keywords Explorer, US overview and volume-by-country, queried 28 August 2026 — the demand, difficulty, CPC, global-volume and country-split figures in this entry's keyword note, including the checks behind declining 'applicant tracking system', 'ai recruiter', 'resume screening', 'ai interview', 'candidate sourcing' and, on the homonym grounds set out there, 'aedt'.
  • Chatbotscape evaluation methodology. /methodology (continuously updated).