close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Data Privacy News

ADMT Hiring Risk: The AI Prompt to Run Before You Hire

Daniel Barber - September 9, 2026

Most HR and legal teams know they’re supposed to keep a human in the loop on hiring decisions. Few have actually tested whether the human they’ve got would pass California’s new ADMT test.

That gap is exactly where your ADMT exposure is hiding.

Applicant tracking systems, resume-matching tools, and pre-hire assessments increasingly do more of the deciding than anyone officially admits. California’s ADMT rules test whether a human meaningfully reviewed an automated output and could realistically have reached a different conclusion, not whether a human clicked the final button. Most hiring workflows were never built with that test in mind, which is exactly why they fail it.

If you’re in-house counsel, an HR or talent-acquisition leader, or a privacy lead who needs to know whether your hiring process counts as ADMT before the CPPA tells you, this prompt is for you.

First, let’s look at why employment is the one significant-decision category no company can opt out of, or jump straight to the prompt.

Do you need an AI-powered ADMT test?

Most companies assume that because a recruiter or hiring manager makes the final call, their process isn’t ADMT. Under California’s rules, that assumption doesn’t hold. The test is whether a human meaningfully reviewed the machine’s output, not whether they clicked the button at the end.

This test is especially worth running if your organization:

  • Uses an ATS, sourcing tool, resume-matching engine, or pre-hire assessment anywhere between “applied” and “interviewed”
  • Gets enough applicants per role that no one is realistically reading every resume by hand
  • Has a process where a human reviews a shortlist or a ranked list, rather than the full applicant pool
  • Has never run a bias audit, disparate-impact test, or documented risk assessment on that step
  • Wants a fast, defensible first read on exposure before the CPPA (or a plaintiff’s attorney) asks the question first

What does a good ADMT compliance check include?

A quick “we have a human in the loop” answer doesn’t hold up to the actual legal test. The exposure usually lives in the gap between what a tool does and what anyone can honestly say a human reviewed.

A useful ADMT test goes beyond asking whether a human exists in the process and tests whether that human’s review was real. At minimum, it should assess:

  • Significant decision scope: Does the process touch employment or contracting decisions, including compensation, screening, ranking, or shortlisting?
  • Substantial replacement: Did a human meaningfully review the tool’s output and could they have realistically reached a different conclusion, or did they defer to the machine?
  • Ranking as a safe harbor (it isn’t): If a tool scores or ranks candidates and a human acts on that order, the ranking substantially drove the decision even if a person clicked the final button.
  • Volume: When there are far more applicants than any human could actually read, an automated cut is almost certainly doing the deciding.

The prompt below is built to apply exactly that test to your own numbers, structured as a hiring-specific compliance check rather than a general AI-policy conversation.

What you’ll need before running the prompt

This prompt works in any general-purpose AI chat tool. It’s designed to interview you one question at a time rather than let you wave off the risk with a general answer, so the more specific you are, the sharper the output.

Before running it, have these ready:

  • Roughly how many applicants you get for a typical open role
  • Every tool that touches your pipeline between “applied” and “interviewed” (ATS, sourcing, matching, assessment, scheduling)
  • Whether any of those tools rank, score, match, grade, or auto-reject candidates, and which ones
  • How your team actually reviews a shortlist: genuinely re-reading rejected applicants, or trusting the tool’s cut
  • Whether candidates get any notice that automation is involved, or any way to request human review
  • Whether you’ve ever run a bias audit, disparate-impact test, or documented risk assessment on this step

You don’t need precise numbers to get value from a first pass. The prompt asks its questions one at a time and will work with your best estimate. What it won’t do is let a vague answer pass as a safe one.

Here’s the exact AI prompt you can copy and paste

ROLE

 

You are a senior AI governance and privacy analyst who specializes in California’s ADMT (automated decision-making technology) rules under the CPPA, and how they land on real hiring and recruiting workflows. You are precise, skeptical, and plain-spoken. You do not give me the benefit of the doubt.

 

WHAT I WANT

 

Tell me whether my company’s hiring process legally counts as using ADMT to make a “significant decision” about employment, how exposed we are, and exactly what we would have to do to be compliant. Employment is the one significant-decision category that applies to every company that hires, so do not let me talk my way out of it.

 

THE FRAMEWORK YOU MUST APPLY

  1. A “significant decision” includes decisions about employment or independent contracting opportunities, including compensation. Screening, ranking, filtering, scoring, matching, or shortlisting job applicants all count as steps in that decision.
  2. It is ADMT when a technology processes personal information and is used to replace or substantially replace human decision-making. The test is NOT whether a tool made the final call. The test is whether a human meaningfully reviewed the output and could realistically have reached a different conclusion, or whether they effectively deferred to the machine.
  3. Ranking is not a safe harbor. If a system scores or ranks candidates and a human then acts on that order (interviews the top N, ignores the rest), the ranking substantially drove the decision, even if a person clicked the final button.
  4. Volume matters. When there are far more applicants than any human could actually read, an automated cut is almost certainly doing the deciding.

 

HOW TO RUN IT

 

Ask me these one at a time. Wait for each answer before moving on. Do not lecture me between questions, just probe:

– Roughly how many applicants do you get for a typical open role?

– Walk me through how you get from that number down to the people you actually interview.

– Which specific tools touch that pipeline (ATS, sourcing, matching, assessment, scheduling)?

– Do any of them rank, score, match, grade, or auto-reject candidates? Name them.

– When a human reviews the shortlist, are they genuinely re-reading rejected applicants, or trusting the tool’s cut?

– Do candidates get any notice that an automated system is involved, or any way to opt out or ask for human review?

– Have you ever run a risk assessment, bias audit, or disparate-impact test on that step?

– Has anyone checked what your vendors do with the applicant data behind the scenes?

 

THEN GIVE ME, IN THIS ORDER

 

A) VERDICT: are we using ADMT to make a significant decision? Yes / No / Likely, in one line.

B) THE TRIGGER: the exact step in my described process where the automated decision happens.

C) EXPOSURE: our risk in plain English, including the discrimination and disparate-impact risk if the model systematically screens out a protected group, and who could come after us (regulator, applicant, class action).

D) RISK ASSESSMENT: what a required assessment would actually have to cover for this use.

E) OBLIGATIONS: any pre-use notice, opt-out, or access-to-human-review duties we are missing.

F) FIX LIST: the 3 to 5 concrete steps that would move us from exposed to defensible.

G) RISKIEST ASSUMPTION: the single most dangerous thing we are currently assuming is fine.

 

RULES OF ENGAGEMENT

 

Be direct. Use my real numbers, not hypotheticals. If I try to wave it off with “the tool only ranks, a human always decides,” push back with the actual test. If we are clearly doing ADMT and pretending we are not, say so in the first line and do not soften it.

Getting the most out of your results

The first pass gives you a verdict and a fix list. To sharpen it, run a second prompt in the same chat asking the AI to:

  • Turn the fix list into a project plan with an owner and a deadline for each item
  • Draft the pre-use notice or opt-out language candidates would actually see
  • Flag which parts of the verdict would change if you ran this separately for a different role, region, or hiring channel

That second pass usually turns a legal verdict into something HR and talent acquisition can actually act on without re-reading the whole analysis themselves.

A few practical notes on accuracy: this prompt is built to push back on hand-wavy answers and name the exact step where automation is doing the deciding. Even so, an AI tool only knows what you tell it. If you undersell how much a human actually reviews, or leave out a tool that touches the pipeline, the analysis will miss it too. Treat the output as a first-pass, pre-decision checkpoint, not a substitute for counsel’s sign-off. It gets you most of the way there, but it isn’t legal advice.

Final takeaways

Employment is the one significant-decision category under California’s ADMT rules that applies to every company that hires. There’s no “we’re not an AI company” exemption. If a tool touches your pipeline between application and interview, the question isn’t whether you’re using AI. It’s whether the human in your process is really deciding, or just rubber-stamping.

This workflow helps your team:

  • Catch the exact step where ranking, scoring, or auto-rejection is substantially driving the decision, before a regulator or plaintiff’s attorney finds it first
  • Give HR and talent acquisition a legal test to run against their own numbers, not a general AI-ethics conversation
  • Build a documented, repeatable compliance check you can point to for every role and every tool change
  • Turn “a human always makes the final call” from an assumption into something you’ve actually tested

Having a human in the loop was never the finish line. It just used to be where most companies stopped checking.

Building prompts of your own? Share them with our community in our #ai-labs channel, a space for privacy professionals to share wins and challenges applying AI to their work.

Contact Us image

Let’s get started

Ready to level up your privacy program?

We're here to help.