If your Applicant Tracking System uses AI to screen CVs, there's a trick going around that you should probably know about. Some candidates are hiding instructions inside their CVs that a recruiter may not see, but an AI screening system can still read. Those instructions can be designed to influence how the AI evaluates the candidate, including telling it to rate them more highly regardless of fit. It's called prompt injection, and it's becoming a real issue for AI-powered recruitment.
The bigger question isn't simply whether candidates are trying it. It's whether recruiters can tell when an Applicant Tracking System result doesn't make sense.
How Common Is Prompt Injection in CVs?
The numbers vary depending on who's counting and what exactly they're measuring. Researchers studying roughly 200,000 real CVs submitted to a recruitment platform found that around 1% contained deliberate prompt injections.
Other reports and surveys have produced much higher figures, particularly when asking job seekers whether they've tried or considered techniques designed to influence AI screening.
Those numbers shouldn't necessarily be treated as directly comparable. But they point towards the same problem: hidden AI prompts in CVs are something any Applicant Tracking System using AI needs to account for. What might once have sounded like a strange trick is becoming a genuine AI security issue.
Why Does Prompt Injection Matter for an Applicant Tracking System?
If your Applicant Tracking System reads a CV and gives you a ranking or match score, prompt injection is an attempt to interfere with that output.
Some techniques can be surprisingly simple.
For example, instructions might be hidden using white text on a white background so a recruiter doesn't immediately see them, while an AI system processing the document still can.
And that's where the bigger problem appears. If an Applicant Tracking System gives you a score without enough context behind it, how do you know when something has influenced the result? This isn't just about one platform or one AI recruiting tool.
It's a broader problem for recruitment software that uses AI to interpret, screen or evaluate candidate information. The less visibility recruiters have into the result, the harder it becomes to notice when something doesn't add up.
What Should You Look for When Comparing Applicant Tracking Systems?
Prompt injection gives recruiters another factor to think about when choosing an Applicant Tracking System. It isn't only about features, speed or price anymore.
There are some useful questions to ask,
- Can you see why a candidate appeared in your results?
- Can you see which parts of the CV actually support the match?
- If an AI result looks strange, is there enough information for you to question it?
And has the vendor considered how its Applicant Tracking System responds to hidden instructions inside candidate CVs? That last question is particularly important. An AI system producing a result doesn't automatically mean that result should be trusted. Recruiters still need enough context to decide whether it makes sense.
How Does EdgeTal Approach AI Candidate Matching?
- EdgeTal doesn't claim to be immune to prompt injection. That's an important distinction because prompt injection remains an active area of AI security research.
- Instead, EdgeTal focuses on giving recruiters more visibility into the candidates returned by its search. Candidate results include a match percentage alongside information showing what matched the recruiter's search.
- EdgeTal also uses semantic search. Rather than depending entirely on exact keywords, semantic search looks at the meaning behind a candidate's skills and experience.
- This can help recruiters find relevant candidates even when their CV uses different wording from the original search.
- Recruiters can also provide feedback when search results aren't useful rather than simply accepting whatever the AI returns. None of this means prompt injection becomes impossible. It means recruiters have more information to work with when deciding whether a result actually makes sense.
Join EdgeTal Early Access to explore private, on-device AI candidate search.
Does On-Device AI Prevent Prompt Injection?
- EdgeTal also takes a different approach to candidate data.
- Its AI processing happens directly on the device rather than sending candidate CVs to a cloud server for AI processing.
- That has an important privacy benefit, but the distinction matters here:
- On-device AI doesn't automatically prevent prompt injection.
- Data privacy and prompt-injection security are two different problems.
Running AI locally can reduce the need to send sensitive candidate information elsewhere. But an AI system can still potentially encounter malicious instructions inside the information it's processing.
So, when comparing an Applicant Tracking System or AI recruitment tool, privacy and AI security should be considered separately rather than assuming one automatically solves the other.
Why Human Oversight Still Matters
Prompt injection is another reminder that AI results still need human judgement. An Applicant Tracking System can help recruiters find and evaluate candidates faster, but a match score shouldn't make the final decision. Recruiters still need enough context to understand the result and recognise when something doesn't add up.
AI can help narrow the search. The recruiter still makes the call.
FAQs
What is prompt injection in recruitment?
Prompt injection happens when instructions are hidden inside a CV with the aim of influencing how an AI recruitment system evaluates the candidate.
Can hidden text in a CV affect an Applicant Tracking System?
Yes. If an Applicant Tracking System uses AI to process CV content, hidden instructions may potentially influence how the system evaluates or ranks a candidate.
How can recruiters spot unusual AI candidate matches?
Recruiters should look beyond the match score and review the candidate's actual skills, experience and supporting evidence to check whether the result makes sense.
Does on-device AI prevent prompt injection?
No. On-device AI can improve candidate data privacy by processing information locally, but it doesn't automatically prevent prompt injection. Data privacy and prompt-injection security are separate issues.