Cut bias risk and data exposure with
The EU AI Act classifies all recruitment AI as high-risk, with full enforcement from August 2, 2026 and penalties reaching 35 million euros or 7% of global turnover. Igris redacts candidate identifiers before the model sees them, reducing bias risk and data exposure with the same control, while the audit trail documents every screening and evaluation decision for EU AI Act, EEOC, and NYC Local Law 144.
AI Resume Screening
Resume screening AI processes the most concentrated collection of candidate personal data in any hiring workflow: full names, home addresses, phone numbers, graduation years, and in some cases national identity references. Two simultaneous and equally urgent risks exist. The data protection risk: every identifiable candidate record reaching an external LLM without redaction controls is a GDPR Article 22 automated decision-making exposure for EU candidates, a DPDP Act 2023 violation for Indian candidates, and an EEOC evidentiary problem if transmitted data includes information supporting a later disparate impact claim. The regulatory risk is immediate: the EU AI Act's Annex III, Category 4 classification of all recruitment AI as high-risk carries mandatory documentation, testing, human oversight, and audit trail requirements with full enforcement from August 2, 2026. Penalties reach €35 million or 7% of global turnover. Only 24% of enterprises have begun compliance preparation despite 87% already using AI in hiring decisions.
Guard PII redaction strips candidate names, addresses, phone numbers, graduation years, and identity document references before any resume reaches the LLM for analysis — removing the identifiers that create data protection exposure and simultaneously removing the protected characteristic proxies that create disparate impact risk under EEOC Title VII. The Igris audit trail records every screening decision — which candidate record was processed, which model analysed it, which policy was applied, what was redacted — creating the EU AI Act Article 12 technical documentation and high-risk system audit logging that full enforcement requires by August 2, 2026, and the per-decision record satisfying EEOC compliance evidence needs and NYC Local Law 144 bias audit obligations.
Candidate personal data is protected and bias-inducing identifiers are removed by the same technical control, on every resume, before the LLM analyses anything. The EU AI Act documentation obligation is met by the audit trail before the August 2, 2026 enforcement deadline. When an EEOC investigator asks for the decision record, or an EU candidate exercises their Article 22 right to an explanation, the governance log provides the documented answer.
AI Interview Assistant
A platform using AI to generate interview questions and evaluate candidate responses operates two distinct data protection problems simultaneously. The first is candidate data: interview context includes the candidate's name, prior experience, and salary expectations — creating GDPR Article 22 obligations for EU candidates and EEOC disparate impact risk if evaluations incorporate identity-linked context. EU AI Act Annex III, Category 4 explicitly classifies interview scoring AI as high-risk, with full enforcement from August 2, 2026. The second problem is specific to recruitment agencies: the platform must guarantee that Candidate A's evaluation cannot appear in any context influencing Candidate B's assessment, and that Client Company X's candidate data cannot cross into Client Company Y's session.
Guard content guards redact candidate names and identifying details from every interview generation and evaluation prompt before the call reaches the LLM provider. Tenant isolation on Igris connections creates a hard boundary between each recruitment agency client's candidate pool — no context, no prompt history, and no evaluation from one client's candidates can appear in another's session. Response inspection applies a final check to every AI-generated evaluation output before it reaches the recruiter, catching any candidate identifying detail or cross-candidate data that re-surfaced in the model's response. The full audit trail records every interview AI interaction across all clients, creating the EU AI Act high-risk system documentation August 2, 2026 enforcement requires.
Every interview evaluation is generated and scored against candidate responses, not candidate identities. Each recruitment agency client's candidate data is isolated at the infrastructure level. Response inspection prevents cross-candidate data leaks. The EU AI Act audit trail exists for every decision across every client, assembled automatically, ready for the enforcement date.
AI Performance Management and Promotion Decision Support
HR platforms using AI to support performance management cycles operate AI systems the EU AI Act classifies as high-risk under Annex III, Category 4. Employee performance records, manager assessment notes, compensation histories, and productivity metrics are among the most sensitive employment data any organization holds. When this reaches an external LLM without documented controls, GDPR Article 9 obligations may apply, DPDP Act 2023 obligations apply for Indian employees, and EEOC disparate impact liability applies if AI-supported promotion decisions produce discriminatory patterns. Only 39% of HR leaders have clearly defined AI guidelines and only 32% have a named governance role.
Guard PII redaction strips employee identifying details from performance analysis prompts, reducing the bias-inducing identifiers that create disparate impact risk in promotion decisions. Tenant isolation ensures each organization's employee data is completely separated at the gateway level. The Igris audit trail records every AI-supported performance decision — the EU AI Act high-risk documentation the regulation requires by August 2026, the EEOC decision log enforcement may demand, and the GDPR Article 22 record European employees are entitled to access when automated systems contribute to decisions affecting their employment.
Performance management AI supports human decision-making with documented governance controls on every interaction. EU AI Act high-risk system documentation exists for every decision the AI informed. The organization can respond to an employee's GDPR Article 22 request with a governance log.
AI Background Screening and Reference Verification
HR platforms automating background check analysis and reference verification with AI process data at the strictest intersection of employment data protection law: criminal conviction records are special-category data under GDPR Article 10, and identity verification outputs carry DPDP Act 2023 sensitive personal data protections for Indian candidates. In the United States, EEOC ban-the-box enforcement and Title VII disparate impact analysis apply to any AI system incorporating criminal history in screening decisions. If background check data reaches an external LLM provider without documented redaction controls, the platform has created the specific evidence chain that makes EEOC disparate impact litigation straightforward. The EU AI Act classifies background screening AI as high-risk under Annex III, Category 4, with full enforcement from August 2, 2026.
Guard applies content policies to background screening prompts with special-category detection for criminal conviction references under GDPR Article 10 and identity document patterns under DPDP Act 2023. Redaction policies strip data elements not required for the specific verification task. The audit trail records every background check AI interaction — the EU AI Act high-risk documentation, the EEOC decision record, and the GDPR Article 10 processing justification — in a single governance log. Tenant isolation ensures background check data from one employer client cannot appear in another's verification context.
Criminal record data and sensitive identity verification information are governed by documented technical controls on every background check AI call. The EU AI Act audit trail exists from the first screening run. EEOC decision records are captured automatically. When a candidate exercises their GDPR Article 10 rights, the governance log provides the documented answer.
Get ready for the August 2026 deadline
See how HR platforms redact candidate identifiers, isolate client data, and produce EU AI Act high-risk documentation on every decision.