Summarising CVs with AI: screen candidates without exposing them
Fifteen applications, a manager in a hurry, an AI that summarises in thirty seconds. What leaves with the CVs, and how to get the same summary without exposing the candidates.
Fifteen applications, a manager in a hurry, an AI that summarises in thirty seconds. What leaves with the CVs, and how to get the same summary without exposing the candidates.
"Could you put together a quick table of the candidates by lunchtime? I don't have time to read them all." The request lands on a Tuesday morning, with fifteen CVs in the inbox and a job description for a payroll officer. The reflex is easy to guess: drop everything into a consumer AI tool and ask it for a ranking.
The time saved is real. The problem is everything that goes with it: fifteen names, fifteen addresses, phone numbers, photos, dates of birth, sometimes a family situation or a disability mentioned at the bottom of the page. Here is the same task done twice: first the way it is often done, then the way it should be.
A CV is a dense bundle of personal data, entrusted for a single purpose: assessing an application. Employment law in many countries limits the information an employer may use to what helps judge whether the candidate is suited to the job. In Switzerland, the Code of Obligations sets the same limit for employee data, and the Federal Act on Data Protection (FADP) adds to it. At European level, the GDPR requires you to process only what is necessary, not to keep data longer than needed, and does not allow a decision that significantly affects a person to rest solely on automated processing.
Discriminatory criteria must play no part at all: age, origin, sex, family situation, health. An AI that reads an entire CV sees every one of them.
Then come your company's own rules: IT policy, the privacy notice given to candidates, approved tools. If AI is not allowed there, it is not allowed; the right step is then to raise it with your management.
The fifteen files go off as they are, with one instruction: "rank them from best to worst for this job". A ranking appears straight away.
Three things have just happened. The complete CVs now sit with a provider that neither the company nor the candidates chose, and which often keeps the history. The ranking rests on criteria nobody set: the AI may have favoured a linear career, a prestigious university, a familiar first name. And that ranking, passed on as it is to the manager, effectively becomes an automated decision, with no record of what drove it.
The recruiter starts by writing her scorecard: the five criteria that matter for this job, taken from the job description. In IA Confidential, she creates a "Payroll officer recruitment" space and pastes the scorecard into the space instructions, with a working rule: never a ranking, never any mention of age, photo, family situation or health. These instructions apply to every conversation in the space.
She then attaches the CVs to her message. They are read in her browser and processed by a confidential model: by default, the assistant answers with open models installed on servers in Switzerland, which pass nothing on to third parties.
For each attached CV, fill in the space's scorecard: a table with one row per criterion, what the CV shows, and the sentence or period that supports it. Write "not mentioned" when the CV says nothing. Do not rank the candidates and do not give any overall score. Ignore age, photo, address, nationality and family situation.
The result is not a verdict: it is an organised reading, criterion by criterion, which she compares herself.
The summary produced by the consumer AI tool repeats everything: "52, married, two children, lives forty minutes away". It goes by email to the manager, who forwards it to his deputy. Information that should never have carried any weight is now circulating in three inboxes, and in the end it does carry weight.
The summary she asks for contains only what serves the decision: relevant experience, skills measured against the scorecard, points to explore in the interview. The assistant writes it as a document, which the recruiter rereads, edits and exports to Word or OpenDocument to send to the manager.
Using the completed scorecard for this candidate, write a half-page sheet for the manager: three strengths with regard to the job, two points to check in the interview, and one interview question for each. Refer to the candidate as "Candidate C". Use only what is in the scorecard, and add nothing.
She adds the name at the end, by hand. The manager receives a basis for discussion, not an intimate profile.
For a more specialised role, you sometimes want the view of an external model, more powerful at certain tasks. Sending the raw CV means handing over the candidate's full identity.
If she chooses an external model, the Confidentiality filter steps in before anything is sent. It detects the sensitive data in the message and offers three routes: answer with a confidential model, message untouched; send an anonymised version, which she can reread and correct; or send it as it is, knowing the risk. The default choice remains the confidential AI.
For an attached document, only pseudonymised extracts go to the external model: names are replaced with placeholders, then restored in the answer she reads. Yet a CV often remains identifying even when masked: an unusual career path, a specific employer or a town is enough to recognise someone. In that case, the assistant flags it as an "Identifying document" and offers to have it handled by a confidential model, or to send only the question.
In the Privacy panel, she can also write her own anonymisation instructions: always mask the names of former employers, schools and towns.
AI reads fast; it does not judge. It can get things wrong: mix up two periods, credit a skill that appears nowhere, fill a gap in a career with an assumption presented as fact. Every scorecard is checked against the original CV before anything is drawn from it.
It can also reproduce biases, even with no prohibited criterion in the instructions: a choice of words, a type of career, a turn of phrase can sway it. That is why the scorecard comes from you, the ranking comes from you, and the decision to shortlist or reject an application remains with a person who can explain it.
With a confidential model, CVs and summaries are processed on servers located in Switzerland, and no file is kept on our servers. Your conversation history stays in your browser: we could not produce it if asked to, because we do not have it.
With an external model, nothing leaves without going through the filter, and you choose: anonymised version, pseudonymised extracts, the question alone, or the message as it is.
Two precautions specific to HR. Since the history lives in the browser, anyone using the same session on the same computer can read it: on a computer shared by the team, use a personal session and sign out when you leave. And candidate data may only be kept for a limited time: once the recruitment is closed, delete the space's conversations, or the whole space, as you would the paper files.
The same habits apply to all sensitive data: see our list of data you should never paste into an AI and our advice on using AI at work safely.
To try it out on fictitious CVs before your next recruitment: open the chat.