The claim under test: the roster is wrong before the ranking even starts
Almost every published ranking of AI recruiting agents contains a product you cannot buy, and the correction most writers make to fix it is also wrong. That is the cleanest available demonstration of why a vendor list needs re-checking rather than copying, so it is where this article starts.
The product is Moonhub. Most lists still rank it, usually with the note "acquired by Salesforce." TechCrunch reported the deal on 2 June 2025 under a headline saying Salesforce "buys" the company — and then carried a same-day correction in the body, in which a Salesforce spokesperson stated that Moonhub "has not, in fact, been acquired (by the company's definition of the term)." What actually happened is that Moonhub was shutting down and only some of its team joined Salesforce, where they went on to work on Agentforce. Moonhub's own announcement, signed by founder and CEO Nancy Xu, said the team was joining Salesforce; it contained no wind-down date, no customer-continuity statement and no statement about the product's future. Salesforce was already both a customer and an investor. The company had raised $14.4M.
So a writer who notices the product is gone and "corrects" the entry to "acquired by Salesforce" has published a characterisation the acquirer publicly denied. The only accurate framing is the narrow one: the team was absorbed into Salesforce Agentforce while the company wound down, and Salesforce disputed the description of it as an acquisition. The domain still resolves, which is how it keeps surviving in listicles — but it is a frozen shell, with a banner about the team joining Salesforce, a login, some demo calls-to-action, no pricing, and a footer reading "© Moonhub 2025." It does not go in the table.
The pattern this article is built to defeat.The other error in this category is quieter and more expensive: every ranking scores accuracy, match quality, time saved and ROI, and every one of those numbers is published by the vendor about itself. There is exactly one instance where a regulator went and checked such numbers, and it is worth knowing about before you read anyone's marketing.
In In the Matter of Presto Automation Inc., an administrative proceeding instituted on 14 January 2025 and believed to be the SEC's first AI-washing enforcement action against a public company, a drive-thru voice AI vendor had told investors its product delivered "over 94% accuracy even in noisy environments" and 95% to 99% "automated order completion." The SEC found the product "lacked the capability to take orders on their own and required substantial human involvement," with "human order takers located abroad (primarily in the Philippines and India), who processed the vast majority of drive-thru orders." An internal message quoted in the order put it more directly: the company was "telling investors Presto AI is running 95%+ accuracy without disclosing AI is doing NONE of the work and all orders are processed by humans."
Three framing points that must travel with that citation: Presto consented to the order without admitting or denying the findings; the remedy was a cease-and-desist order with no civil penalty, so it was not a fine; and the findings run against Presto only — the order's "Supplier A" is a different company against which the SEC made no findings at all. The relevance here is narrow and useful: this is what happened the one time a regulator audited a vendor's published AI performance metrics. It is why the table below scores only the things you can go and check yourself, and why the section immediately after this one is a list of what we refused to score.
If you want the cross-industry version of this argument — the same methodology applied to agent vendors in eight other verticals — it lives in our general ranking of the top AI agents in 2026. This article narrows it to one reader: the owner or principal of a staffing firm, executive search firm or agency recruiting desk. Not a corporate talent acquisition team. That distinction changes which products are even relevant, and it disqualifies several that dominate the generic lists.
How we ranked, and what we refused to score
We scored four things, all of which you can re-check yourself in an afternoon: whether a named independent auditor has published a dated bias audit of the product, what security attestations the vendor actually publishes on its own trust page, which staffing applicant tracking systems appear in its current public integration documentation, and whether it publishes real prices. Every cell in the table carries either a checkable fact or the literal words "not publicly disclosed." We never estimated a price.
Methodology block — checked 2026-08-23.
Scored:published independent bias audit (auditor named, date stated, results public); security attestations as stated on the vendor's own trust or security page, quoted at the level of precision the vendor uses; documented staffing-ATS integrations from current public documentation; pricing transparency; ownership and funding from public record; whether the product locks you to a suite; retention and residency commitments where published.
Refused: accuracy, match quality, time-to-fill improvement, submission-to-placement lift, hours saved, quality of hire, candidate satisfaction and ROI. Every published figure of that kind in this market comes from the seller.
How to re-check it:open the vendor's trust page and its integrations page, and search for the auditor's own published dashboard rather than the vendor's badge. Compliance pages change; ours is a snapshot dated 23 August 2026.
No independent benchmark of these products exists. That is not a rhetorical flourish; it is a finding, and it separates recruiting from several adjacent markets where genuine third-party evaluation does exist. Two benchmarks circulate in this category and each is run by a party that wins it. PeopleSearchBench, an arXiv preprint evaluating several people-search tools, was authored by the LessieAI research team, and Lessie ranks itself first on every metric it reports. The Exa People Search Benchmark, published in December 2025, is run by Exa, which is itself a vendor in the space. A third vendor's top score is self-reported on that vendor's own blog. None of that is fraud, and none of it is evidence.
G2, Capterra and Gartner Peer Insights are user-review aggregators, not evaluations. They measure who asked their customers to leave a review. Citing a Peer Insights position as independent validation of an agent's performance is a category error, and it is one of the more common ways a vendor deck looks better sourced than it is.
There is one genuinely independent, peer-reviewed study worth knowing, and it is important to scope it honestly. Kyra Wilson and Aylin Caliskan of the University of Washington Information School presented work at the AAAI/ACM Conference on AI, Ethics and Society on 22 October 2024 testing three open-source large language models on resume screening, using more than 550 real resumes against more than 500 job listings across nine occupations, generating over three million comparisons. They found white-associated names preferred 85% of the time against 9% for Black-associated names, and male-associated names preferred 52% against 11% for female-associated names; the systems never favoured Black male-associated names over white male-associated names. That study tests open-source models used for resume screening. It is not evidence about any named commercial product in this ranking. It is evidence that the risk is real, measurable, and large enough that a vendor who has never measured it on their own system is asking you to take it on faith.
Which brings us to the axis this ranking actually turns on. Bias auditing is the one attribute in this market where a vendor either has a named third party, a date, a sample size and published results, or it does not. It is binary, it is checkable from a public URL, and it maps onto a legal duty you carry. So it is weighted heaviest — with one gate in front of it. A tool your desk cannot connect to Bullhorn, JobDiva, Ceipal, Avionté or Tracker is not a candidate for an agency desk no matter how well audited it is, so integration coverage functions as a qualifier rather than a tiebreaker.
One honest caveat about the auditors themselves, because it changes how much weight a badge deserves. Warden AI, which produces the strongest artefacts in this market, is paid by the vendors it audits. It is independent of their engineering teams, which is the thing that matters most, and its dashboards are public and specific in a way vendor self-reports never are. But it is a commercial assurance relationship, not a disinterested regulator, and the honest description of a Warden dashboard is "continuous third-party assurance," not "certified fair."
The comparison table
Ten products, four verifiable columns, checked on 23 August 2026. The bias-audit column is the one that separates this market, and it is deliberately written to record what was published rather than what was claimed. Where a vendor claims an audit but does not publish the auditor, the date and the results, the cell says so.
| Product | Published independent bias audit | Security attestations, as the vendor states them | Staffing-ATS integrations documented | Pricing published |
|---|---|---|---|---|
| 1. HeyMilo | Yes. Warden AI, monthly, public dashboard; latest 9 July 2026, 17,442 candidates, 15 categories plus intersectional, all clear. Downloadable reports mapped to LL144, EU AI Act, Colorado and California FEHA | SOC 2 Type I and Type II; GDPR, PIPEDA, Quebec Law 25, CASL; DPA and subprocessors published | Bullhorn (native, bi-directional), Avionté, JobDiva, Ceipal, Tracker, plus enterprise systems. LinkedIn Recruiter not listed | Not publicly disclosed |
| 2. Findem | Yes, and the strongest in the set. Warden AI, monthly, public dashboard; audited 3 August 2026, 44,154 profiles, 11 bias categories including intersectional, zero concerns; separate LL144, EU AI Act and Colorado SB 205 reports | SOC 2 Type II, annual independent audit by Johanson Group; ISO 27001 described as aligned with, while not currently certified; DPA published | No Bullhorn, JobDiva or Ceipal integration confirmed. A real gap for an agency desk | Not publicly disclosed |
| 3. Alex (Apriora Inc.) | Yes, from two named auditors. BABL AI, published 12 August 2025; and Warden AI, continuous monthly, latest 8 July 2026, 17,544 interviews, counterfactual analysis on synthetic data | Trust centre states SOC 2 Compliant without specifying Type I or Type II; ISO 27001 certified; ISO 42001 certified — the only ISO 42001 claim found in this set | Deepest list found: Bullhorn, JobDiva, Ceipal, Avionté, Crelate, Loxo, Recruit CRM, TargetRecruit, Tracker, plus roughly 20 enterprise systems | Not publicly disclosed |
| 4. Bullhorn (Amplify Digital Workers) | None published. No trust portal; bullhorn.com/trust returns 404 | Its own wording: many Bullhorn service offerings boast SOC 2 Type 2 and/or ISO 27001 certifications. That is not a certification statement for a named product. Annual third-party SOC 1 and SOC 2 Type 2 audits stated | Bullhorn is the ATS. The only verified LinkedIn Recruiter System Connect partner in this entire research set, with published integration documentation | Starter $99 and Core $165 per user per month. Amplify Chat needs Pro; Amplify Digital Workers need Max, and both those tiers are quote-only |
| 5. Loxo | None published | SOC 2 Type II; DPA and subprocessor list published; quarterly and annual third-party penetration testing. No ISO 27001, no ISO 42001 | Loxo is the ATS and CRM. Adopting it is a replacement decision, not an integration | Core $149 and Professional $199 per user per month on annual billing; Enterprise custom. Agents sit on Professional with pooled monthly credits |
| 6. hireEZ | None. Its diversity reporting is self-generated by the product, which is a feature, not an audit | SOC 2 Type 2 and ISO 27001 — the only vendor here claiming both explicitly. GDPR validated by TrustArc, current as of 31 October 2025. DPA with customers and with data suppliers | Real Bullhorn marketplace listing; dedicated staffing and RPO product with ATS rediscovery | From $494 per month for a solo seat |
| 7. Juicebox | Yes, with two caveats that change what it means. Warden AI Ltd, report dated 12 June 2025, 5,760 samples — but run on Warden's own dataset due to a lack of access to historical data, and marked as meant for demonstration purposes | SOC 2 Type II; ISO 42001 followed, not certified; ISO 27001 not claimed; 22 subprocessors disclosed; US-only data residency | 41 ATS and 21 CRM connections claimed, but gated to the Business tier — the self-serve tiers an agency would buy do not include them | $99 and $179 per seat per month, plus $199 per agent per month |
| 8. Recruiterflow | None published | Homepage asserts SOC 2, ISO 27001 and GDPR compliance, but there is no trust page, no security page, no report request flow, no subprocessor list and no auditor named. Treat it as an unevidenced badge line | Recruiterflow is the ATS and CRM, and the only vendor here whose homepage names executive search first | Platform $149 per user per month; the AIRA agent plan is custom-quoted, with all current and future agents included at no per-agent fee |
| 9. Ribbon | Claimed, but not published. The bias-audit summary is behind a lead-capture form: no auditor named, no date, no selection rates, no impact ratios | SOC II Type I certified, with Type II described as in observation. Weakest security posture in the set. GDPR stated | Bullhorn, Greenhouse, Lever, Ashby, BambooHR and others through Kombo, a unified-API aggregator, so breadth is brokered rather than native. JobDiva and Ceipal not found | Growth $499, Business $999, Scale $1,999 per month on annual billing, with per-interview overage at $4.00, $3.00 and $2.50 |
| 10. Sense | None published | Security page states only that services are hosted on AWS, which is compliant with PCI DSS, SOC 1/2/3, ITAR and NIST. That is the cloud provider's compliance, not the vendor's. A separate SOC 2 Type II was announced in 2021; currency in 2026 unverified | Best breadth for agency stacks: Bullhorn, JobDiva, Ceipal, Avionté, LaborEdge, plus enterprise systems. Lever not listed | Not publicly disclosed |
Read the bias-audit column carefully, because the four states in it are genuinely different. A public, dated, named audit with a sample size is evidence. An audit run on the auditor's own synthetic dataset with a demonstration disclaimer is evidence about the model, not about your hiring outcomes. A claimed audit behind a form is not evidence at all until you have the report. And a product feature that flags biased language in a job description is not an audit in any sense — it is a spellchecker for bias, and two vendors in the broader market present it as though it were the same thing.
Considered and not ranked — including two that are your competitors
Two of the names that appear on nearly every list of AI recruiting tools are not tools a staffing firm buys. They are businesses competing for the same revenue your desk is competing for, and no competing ranking makes the distinction.
Mercor — a competitive threat to the staffing model, not a product for it
Mercor is a talent marketplace and labour supplier, not software a recruiter licenses. It recruits PhDs, lawyers, bankers, physicians and engineers to produce specialised work for AI labs and enterprises. The buyer is the AI lab. Mercor does the placing itself, which means it disintermediates the staffing firm rather than equipping it. Published on-platform rates for individual expert roles run $63 to $120 per hour; enterprise pricing is not published. It closed a $350M Series C at a $10B valuation led by Felicis on 27 October 2025. Reports in July 2026 described talks over roughly $500M at around a $20B valuation — that round was reported as in talks, not closed, and should not be stated as completed. If Mercor belongs anywhere in a staffing principal's reading, it is in the competitive-strategy folder, not the procurement one.
SeekOut — sold as an alternative to agencies, with two disclosure traps
SeekOut's agentic material names no staffing or search firms as buyers, and SeekOut Spot is marketed as a cost-effective alternative to traditional agencies. For this readership that makes it a competitor. Two verifiable disclosure problems compound it. Its security page states that SeekOut is "SOC 2 Type 2 certified as of June 8, 2023" — SOC 2 Type II is a recurring report covering an observation window, so a 2023 date on a 2026 page is three years stale and is itself a transparency finding. And it states that the company is "compliant with ISO/IEC: 42001:2023 and ISO/IEC: 23894:2023." Compliant is not certified, and the distinction is the single most likely thing to be misreported about this vendor. ISO 27001 is not claimed at all. Secondary reporting also describes a difficult few years — a roughly 7% workforce reduction in October 2023, a 30% reduction in May 2024, a further reduction reported in March 2025, and a new chief executive announced in April 2026 — which is worth knowing before signing a multi-year term.
The rest of the excluded set, with the reason in each case. Several of these are good products that are simply the wrong shape for an agency desk, and saying so is more useful than padding a top ten.
| Product | Why it is not in the ranking |
|---|---|
| Moonhub | Not purchasable. Salesforce disputed the characterisation as an acquisition; the company was winding down and part of the team joined Agentforce. The site is a frozen shell with a © Moonhub 2025 footer |
| Gem | No Bullhorn, Lever, JobDiva, Ceipal or LinkedIn Recruiter integration is documented; integrations run through Merge to Greenhouse and Workday only. For a firm on Bullhorn that is close to disqualifying, and it contradicts Gem's own agency marketing. Its agent flags biased inputs, which is a product feature, not a bias audit. Gem states SOC 2 without specifying Type II |
| Fetcher | Going-concern status unverified. Pricing is live at $115, $379 and $649 per month, but there is no 2026-dated content anywhere on the site, the last verifiable funding event was 2022, the careers page is empty, /security returns 404 and there is no SOC 2 evidence of any kind. Its top tier also includes a dedicated human sourcer, so part of the offering is a service rather than software |
| Ceipal | Independent and genuinely staffing-native in places — vendor empanelment and job-publishing compliance are VMS and MSP workflows no corporate-TA vendor ships. But all eight agents are labelled autonomous with no human-approval, escalation or review language anywhere, including an emailing agent that generates and sends candidate outreach automatically. No trust or security page could be located, so no certification can be attributed to it |
| Maki | Disqualified on plumbing. It lists a staffing use case, but its integration list contains no staffing ATS at all — no Bullhorn, JobDiva, Ceipal, Avionté, Tracker or Loxo. Its bias audit is real (Holistic AI, annual, most recent referenced March 2026) but covers two of its five agents. ISO 27001 only; SOC 2 Type II and ISO 42001 not mentioned |
| HireVue | Enterprise TA and government, not agency desks. No staffing-ATS integrations are named publicly, and the delivery model of validated assessments plus professional services is the opposite of a desk that needs to submit a candidate this afternoon. Its external auditor engagement with DCI Consulting from January 2023 is the deepest track record in the market, but the most complete published report is dated 14 August 2023 and is hosted on a client's CDN, so we cannot say it publishes a current audit. Note also that its stated ISO/IEC 27001:2013 is the superseded revision, and that FedRAMP grants authorization rather than certification |
| Ashby | The best compliance disclosure we found anywhere — SOC 2 Type II and SOC 1 Type II with listed report years, Data Privacy Framework participation, a full subprocessor list, a Responsible AI Statement and AI data flow diagrams. But its actions are corporate-TA shaped, its launch material contains no staffing-agency workflow, and pricing is banded by employee headcount, which is an employer model rather than an agency-desk model. Its bias audit report does not publicly identify the auditor, so independence cannot be determined |
| SourceWhale | Positioned exactly at this reader and with the best agency-stack integration coverage found anywhere — Bullhorn, Crelate, Firefish, JobAdder, JobDiva, Mercury, PCRecruiter, Top Echelon, Vincere — with modestly and honestly scoped agents. Not ranked because pricing is not disclosed and no compliance evidence could be verified. Worth a demo regardless |
| Paradox | No longer independent. Workday completed the acquisition on 1 October 2025; terms are not disclosed in either announcement, so the billion-dollar figure circulating in secondary coverage should not be repeated. It is now sold as the Workday Paradox Candidate Experience Agent — Workday's release does not use the name Olivia |
| SmartRecruiters | Acquired by SAP, completed 11 September 2025, terms not disclosed. Enterprise only |
| JobDiva | Not an agent vendor and does not claim to be. It markets patented semantic search, resume harvesting and matching. Agents reach JobDiva through third parties such as Sense, SourceWhale and Alex |
| Xref | Not an agent, and it credits itself for not pretending otherwise. Classic reference-checking automation, ISO 27001 under a UKAS-accredited body, published pricing from $70 to $485 per month. Its takeover by SEEK failed when shareholders voted it down on 3 February 2025 — 67.6% in favour against a 75% threshold — and it remains ASX-listed. Its own US FCRA status could not be verified, which is a live diligence question rather than a negative finding |
| micro1 (Zara) | Effectively unmarketed. micro1 has pivoted to AI data research; the Zara path serves the data-lab homepage and the app shell is not marketed |
The ten, in order
Each entry states what the product does, what is verifiable, what the vendor does not disclose, who it fits, who it does not, and who owns it. Where the only source for a claim is the vendor, it is attributed to the vendor in the text.
1. HeyMilo — the best combination of a real audit and a real Bullhorn build
What it does. Conversational AI screening interviews over phone, video and text, with per-question scores, model rationale, timestamped quotes and full transcripts pushed back into the ATS.
What is verifiable.Its bias audit is independent, public, current and named: Warden AI, monthly, latest dated 9 July 2026, sampling 17,442 candidates across 15 categories plus the intersection of sex with race and ethnicity, all clear, with downloadable reports mapped to Local Law 144, the EU AI Act, Colorado and California FEHA. The vendor's own framing of why it does this is unusually blunt: it does not trust itself to audit itself. It holds SOC 2 Type I and Type II, publishes a DPA and subprocessor list, states GDPR, PIPEDA, Quebec Law 25 and CASL positions, an EU AI Act classification analysis, AI-literacy training under the EU AI Act, a data protection officer reporting to the board, and 48-hour incident notification. Customer data is not used to train or fine-tune models, there is no cross-customer learning, personal data is masked before reaching models, deletion on request is logged and auditable, and prompt logs are held for roughly seven days.
The agency plumbing.This is the entry's real argument. The Bullhorn integration is native and bi-directional: interview-extracted skills write back as primary and secondary skills, reports write to candidate notes with recordings and transcripts, and job submissions auto-create with a response status, on a polling window from five minutes to daily. That is the actual screen-to-submit workflow of an agency desk, not a generic webhook. Avionté, JobDiva, Ceipal and Tracker are also supported, alongside enterprise systems, and public API documentation exists.
What is not disclosed. Pricing — the pricing path redirects to a demo booking. Data residency is not published. LinkedIn Recruiter is not listed as an integration. And there is a tension worth printing: HireAIScore, a third-party governance rubric operated by an AI-governance consultancy that publishes its methodology and discloses no commercial relationship with the vendors it scores, ranks HeyMilo eighth of 111 with a score of 61, graded D and labelled concerning — strong on bias-audit transparency at 83 out of 100, weak on fundamental rights impact assessment support at 42 and post-market monitoring at 46. The vendor with the best public bias audit in the set still scores poorly on a broader governance rubric. Both facts are true and both belong in a diligence file.
Fit. Good for a staffing desk on Bullhorn running volume screening. Weaker if you need documented Illinois or Maryland statutory mapping: consent is described as explicit, timestamped and immediately revocable and candidates are always told they are speaking to an AI, but neither the Illinois AI Video Interview Act nor the Maryland facial-recognition statute is named in the documentation. The mechanics support compliance; the paperwork does not cite it.
Ownership. Independent. The footer names Redsnack Technologies as the legal entity, which differs from the brand and matters when you are signing a contract. Reported $6M raised in June 2026 led by Category Ventures, after a $2.2M seed.
2. Findem — the strongest audit artefact in the market, with a plumbing gap
What it does. Attribute-based talent search and applicant matching over an enriched profile graph, aimed at both corporate TA and, since 2026, explicitly at staffing.
What is verifiable.Nothing else in this market comes close on published assurance. Warden AI maintains a live public dashboard for Findem's applicant matching, audited on 3 August 2026 — three weeks before this article was published — running monthly across 44,154 profiles and 11 bias categories including intersectional ones, with 84 clear results and zero concerns. Findem separately publishes audit reports mapped to NYC Local Law 144, the EU AI Act and Colorado SB 205. Its SOC 2 Type II is active with an annual independent audit by Johanson Group, and a DPA is published.
The distinction that must be printed.On ISO 27001, Findem's own language is that it aligns with the standard while not currently certified. Aligned is not certified. It is a reasonable and honest thing for a vendor to say, and it is exactly the sort of sentence that gets flattened into "ISO 27001 certified" in a comparison chart written by someone in a hurry.
What is not disclosed. Pricing is not publicly disclosed — demo request only — and we do not estimate. Data residency and retention are not specified. Most importantly for this reader: no Bullhorn, JobDiva or Ceipal integration could be confirmed. That is a genuine gap for an agency desk, and it sits awkwardly against a product strategy that names staffing directly.
Ownership and direction. Independent, with a $51M Series C on 21 October 2025 led by Silver Lake Waterman bringing total funding to $105M. It entered a definitive agreement to acquire Glider AI on 19 March 2026, terms not disclosed, with a release that explicitly targets the staffing industry; it also acquired Getro, reported December 2025. If the acquisition brings staffing-ATS connectivity, this entry moves up. Ask about it on the call and ask for the roadmap in writing.
3. Alex (Apriora Inc.) — the deepest staffing-ATS coverage, and the most public failure
What it does. The closest thing in this set to a genuinely autonomous agent: a self-described autonomous AI recruiter running interviewing, verification and scheduling as one loop, generating follow-up questions mid-interview across phone, video, SMS and WhatsApp in 30 languages. Modules cover AI interviews, resume screens, coordination, identity and fraud verification, and talent matching.
What is verifiable.Two named independent auditors, which no other vendor here can say. BABL AI published an audit on 12 August 2025 covering race, ethnicity and gender plus internal governance — note that the "passed all criteria" result is published on the vendor's own blog, so treat the auditor's identity as verified and the result as vendor-reported. Warden AI runs continuous monthly assurance with a public dashboard, latest 8 July 2026, 17,544 interviews, 100 clear and zero concerns, using synthetic data, scoring-module evaluation and counterfactual analysis. Its integration list is the deepest found: Bullhorn with a dedicated tab inside candidate and job views, JobDiva, Ceipal, Avionté, Crelate, Loxo, Recruit CRM, TargetRecruit and Tracker, plus roughly twenty enterprise systems. Opening a Bullhorn job creates a live two-way interview pipeline, and reports and summary notes post back to the candidate record.
Read the trust centre precisely.It states "SOC 2 Compliant" without stating Type I or Type II. Do not upgrade that for them. It also states ISO 27001 certified and ISO 42001 certified — the only ISO 42001 claim found anywhere in this research — plus GDPR, CPRA and TCPA positions. More than forty policy documents sit behind a request-access gate.
What is not disclosed, and what went wrong.Pricing is not publicly disclosed. No statute is named in its ethical-AI material: it asserts a human-in-the-loop standard and supports candidate disclosure and consent flows, but names neither the Illinois AI Video Interview Act nor Maryland nor Local Law 144. This is also the product carrying the most-cited independent critique in the category — Futurism documented the product, then trading as Apriora, glitching mid-interview with a real candidate, looping a phrase and terminating the interview; the clip went viral and was picked up widely, and reporting suggests the rebrand followed. HireAIScore ranks it sixteenth of 111 at 57, graded F, the lowest of the interview vendors it scores. And one claim in the vendor's messaging needs correcting on the spot: the assertion that compliance is covered overstates the law. The bias-audit duty sits on the employer or employment agency, not on the vendor.
Ownership. Apriora Inc., trading as Alex, founded 2023 in San Francisco. $20M total — a $3M seed plus a $17M Series A led by Peak XV Partners, announced 29 September 2025. Note that apriora.ai now redirects to alex.com; if you see both names on a shortlist, that is one vendor, not two. Its own performance claims — candidate preference rates, time-to-hire multiples, interview volume — are vendor-published and are not scored here.
4. Bullhorn (Amplify Digital Workers) — the incumbent, and the only verified LinkedIn partner
What it does. Amplify Digital Workers and Amplify Chat launched at Engage Boston on 28 May 2026 with ten skills: Enrich, Match, Screen, Outreach, Present, Prospect, Transcribe, Verify, Audit and Extract.
Why it matters more than its audit column suggests. Four of those skills are staffing-specific in a way no corporate-TA vendor ships. Present generates branded client-ready submissions. Verify flags AI-generated and fraudulent applications, which became a real operational problem for agency desks during 2026. Audit catches pay, billing and compliance errors. Extract processes timesheets and credentialing documents. That is middle-office work, and middle-office work is where an agency's margin actually leaks.
The LinkedIn fact. Bullhorn is the only vendor in this entire research set with a verified Recruiter System Connect partnership, with its own published integration documentation. Recruiter System Connect is restricted to LinkedIn-approved developers under a signed API agreement with data restrictions, and it is built for applicant tracking system partners rather than sourcing tools. If LinkedIn connectivity is a hard requirement, this is the only entry that survives verification.
What is not disclosed.The compliance line needs quoting exactly, because its hedges are load-bearing: many Bullhorn service offerings boast SOC 2 Type 2 and/or ISO 27001 certifications. "Many" and "and/or" mean that is not a certification statement about a named product. There is no trust portal — bullhorn.com/trust returns 404 — ISO 42001 is not mentioned, no bias audit is published, and residency and retention are not published. Pricing is partly published at Starter $99 and Core $165 per user per month, but Amplify Chat requires Pro and Amplify Digital Workers require Max, and both of those tiers are quote-only. The agents sit entirely behind unpublished pricing. Its published customer results — submission-to-placement lift, hours saved per week, placements per recruiter — are all vendor-published and uncited, and are not scored here.
Ownership. Bullhorn, Inc., private equity owned; Stone Point Capital has held a majority since 2020, with Insight Partners and Genstar minority. The roll-up continues: SourceBreaker in 2022, Textkernel in June 2024, TargetRecruit in August 2025. Adopting Amplify is a decision to deepen a suite, not to add a tool.
5. Loxo — the most rigorous autonomy language anyone publishes
What it does. Nine agents inside an ATS and CRM: job intake in beta, job description writing and skill modelling, a longlist agent scaling to 10,000 candidates, an evidence-ranked shortlist agent across seven dimensions, data hygiene and deduplication in beta, a self-updating CRM, chat, and an MCP server.
What is verifiable, and why it earns the place. Loxo publishes an explicit stop-line that every other vendor in this market should be held to: it describes its agents as autonomous through the shortlist, never through the decision, and states that no candidate is ever contacted, advanced or rejected by an AI agent acting alone. That is a governance commitment written in public, in plain language, that you can hold a vendor to in a contract. It holds SOC 2 Type II, publishes a DPA and subprocessor list on its trust centre, runs quarterly and annual third-party penetration testing, and uses AES-256 at rest and TLS 1.2 or better in transit. Pricing is published and unusually complete: Core at $149 per user per month on annual billing with ATS, CRM and AI search but no agents; Professional at $199 per user per month with the full agent workforce on every seat, an agent impact centre, API access and 2,500 pooled credits per user per month; Enterprise custom.
A correction worth making.Third-party review sites circulate a Loxo price structure of a $169 basic tier with Professional quote-only. That is wrong against the vendor's own published page — and it is a small, checkable demonstration that the review-farm layer sitting between you and vendor pricing is not reliable. Read the pricing page.
What is not disclosed, and who it does not fit. No bias audit, no ISO 27001, no ISO 42001, and no published retention or residency commitment. Its outreach and pursuit agent is listed as coming soon, so do not buy on it. Loxo is the ATS and CRM, which makes adoption a rip-and-replace decision rather than an addition. And despite agency positioning, no executive search or staffing-specific workflow is documented — no redeployment, no bench management, no contractor-off-assignment logic. Ownership: independent and private equity backed, following a $115M growth investment led by Tritium Partners on 20 February 2025; whether that stake is majority or minority is not stated publicly.
6. hireEZ — the strongest security paperwork, and no bias audit at all
What it does. Sourcing across open web platforms with a dedicated staffing and RPO product, including rediscovery of candidates already sitting in your ATS.
What is verifiable. It is the only vendor in this set claiming both SOC 2 Type 2 and ISO 27001 explicitly. Its GDPR posture is validated by TrustArc, current as of 31 October 2025. It executes a DPA with customers and with its data suppliers, which is a distinction most sourcing vendors do not make and which matters directly to data provenance. And it publishes the most specific retention commitment found anywhere in this market: deletion on request, and otherwise three years, after which data is automatically destroyed. It has a real Bullhorn marketplace listing. Pricing starts at $494 per month for a solo seat.
What it does not have.No independent bias audit. Its diversity reporting is generated by the product itself and supports OFCCP-style reporting — that is a feature, and it is not an audit by an independent auditor in the sense the law uses. If your desk uses hireEZ purely for sourcing and outreach, that gap is narrower than it looks, because sourcing sits outside the Local Law 144 bias-audit duty entirely. It does not sit outside California's regulations, which expressly name directing job advertisements to targeted groups and screening resumes for terms or patterns as covered activities.
Two things to state carefully. On funding, publish the total and the date rather than the round label — $76.3M raised — because sources conflict on whether the most recent round was a Series C or a variant of a Series B. And on LinkedIn: hireEZ sources across a large number of open web platforms and benchmarks itself against LinkedIn, but claims no LinkedIn integration. There is a persistent claim in circulation that LinkedIn sent hireEZ a cease-and-desist. We could find no evidence of it. The famous cease-and-desist went to hiQ Labs, a different company entirely, and the conflation should not be repeated.
7. Juicebox — a real independent audit, with two caveats that must travel with it
What it does. Natural-language people search and automated sourcing, with an agent product layered on top.
What is verifiable, and the caveats.Juicebox has a genuine independent audit from a genuine independent auditor: Warden AI Ltd, a registered UK company, in a report dated 12 June 2025 covering 5,760 samples, with recorded impact ratios including sex at 1.00 for female and 0.97 for male, and race at 0.98 Asian, 0.91 Black, 1.00 Hispanic and 0.93 White. Two caveats from the audit document itself change what it means, and citing the audit without both would let a buyer believe they had inherited compliance they do not have. First, Warden used its own independent dataset of candidate profiles due to a lack of access to historical data — meaning it did not test Juicebox's real production outcomes. Second, the report states verbatim that it is meant for demonstration purposes and does not indicate the bias audit results of Juicebox's tools for any particular employer or job opportunity. It is an independent audit of a demonstration. It is not a compliance audit an employer can rely on.
Compliance and pricing. SOC 2 Type II held. ISO 42001 followed, not certified. ISO 27001 not claimed. Twenty-two subprocessors disclosed, US-only residency. Pricing published at $99 and $179 per seat per month plus $199 per agent per month — but ATS and CRM integration is gated to the Business tier, so the self-serve tiers an agency would actually buy do not include it. The subprocessor list includes unified-API brokers, which strongly suggests the large ATS and CRM connector counts are brokered rather than native; treat that as an inference to test on the call, not as a stated fact.
One thing not to repeat.A third-party security profile lists Juicebox as HIPAA, PCI, FedRAMP and CSA STAR aligned. The vendor's own trust centre supports none of that, and it should not be printed or relied on. Ownership: independent, with an $80M Series B at an $850M valuation on 10 March 2026 led by DST Global, bringing total funding to $116M.
8. Recruiterflow — the purest agency-native fit, and the weakest evidence
What it does. An ATS and CRM built for recruiting, staffing and executive search firms — the only vendor in this research whose homepage names executive search first — with an agent layer branded AIRA.
The two most desk-native agents found anywhere. The submission agent drafts the client-ready candidate submission, which is the actual billable moment on an agency desk and the thing generic TA tooling never touches. Job change alerts monitor the CRM for contacts moving into decision-maker roles, which is business-development triggered database reactivation — the agency-specific version of the reactivation story that every vendor in this market tells badly. Its own help documentation is honest about autonomy: outreach and submission agents draft, suggest mode proposes changes and will not apply them until you review and approve, and only one truly automated agent exists, a notetaker field updater. Hold that honesty against the marketing claim of thirty-six agents built in — only about sixteen are named or documented anywhere.
What is not disclosed, and it is the reason for the rank. This is the weakest compliance evidence in the set. The homepage asserts SOC 2, ISO 27001 and GDPR compliance, but there is no trust page, no security page — recruiterflow.com/security returns 404 — no report request flow, no subprocessor list, no auditor named and no bias audit. An unevidenced badge line is not an attestation. Ask for the report before you sign; if a vendor holds SOC 2 Type II, producing the report under NDA is a routine request that takes a day.
Ownership. Independent and bootstrapped — no venture capital, no private equity, at roughly $24.1M in annual recurring revenue. In a category dominated by private equity roll-ups, that is a real differentiator for a firm that does not want its ATS repriced after a change of control. Pricing: platform at $149 per user per month; the AIRA plan is custom-quoted but includes all current and future agents at no per-agent fee, which is a materially different commercial model from credit metering.
9. Ribbon — fully published pricing, a real API, and a material audit gap
What it does. Round-the-clock asynchronous voice and video screening with SMS, WhatsApp and email outreach, custom rubrics and integrity monitoring. It explicitly serves staffing agencies and RPOs alongside contact centres, BPOs and job boards, and targets high-turnover verticals — warehousing, trucking, security, cleaning, home care and quick-service restaurants.
What is verifiable, and genuinely good. It is the only vendor in this set whose agent product is fully priced in public: Growth at $499 per month for two seats, two roles and 100 interviews with $4.00 overage; Business at $999 for five seats, five roles and 400 interviews with $3.00 overage; Scale at $1,999 for ten seats, ten roles and 1,000 interviews with $2.50 overage; Enterprise custom with SSO, security reviews and an SLA. There is a seven-day trial with 50 free interviews. It also ships a genuine public API with an OpenAPI specification, webhooks and an MCP server — the only vendor here shipping MCP alongside Loxo — including a recording-revocation endpoint, which maps directly onto Illinois deletion duties.
The gap, and it is the most printable finding on this vendor. Ribbon claims to be proven by the world's toughest bias audit and displays a badge — but the audit summary sits behind a lead-capture form. No auditor is named, no date is given, and no selection rates or impact ratios are published. The New York City rules require the summary of results to be publicly available on the employment section of the website. A form-gated report does not do that. If you deploy Ribbon on New York City-linked roles, you are the party who has to publish, and you cannot publish what you have not been given.
Other constraints.Security posture is the weakest in the set: SOC II Type I certified, with Type II described as in observation. Integrations run through Kombo, a unified-API aggregator, by the vendor's own documentation — so the large integration count is aggregator breadth, not native depth, and write-back is materially weaker than HeyMilo's or Alex's native Bullhorn builds. JobDiva, Ceipal and LinkedIn Recruiter were not found. Illinois and Maryland are not documented. Ownership: independent, Toronto-based, founded 2022, with US$8.2M announced on 31 March 2025 led by Radical Ventures. Its published satisfaction, time-to-hire and volume figures are vendor claims and are not scored here.
10. Sense — the best reactivation story, sitting on borrowed compliance
What it does. Six agents — FAQ, sourcing, score and match, AI interviewer, voice and candidate engagement — layered over your existing ATS rather than replacing it. Its sourcing agent re-engages past applicants, enriches profiles and builds ranked shortlists, and the staffing page pitches dormant-database reactivation directly. For a firm sitting on 200,000 stale candidate records, that is the most commercially interesting pitch in this whole category.
What is verifiable. Integration breadth is the best in the set for agency stacks: Bullhorn, JobDiva, Ceipal, Avionté and LaborEdge, plus Greenhouse, Workday, iCIMS, SuccessFactors, Taleo and Salesforce. Lever is not listed. It is not locked to an ATS, which is its real differentiator for a firm unwilling to replace Bullhorn.
The teachable red flag.Its security page claims that its services are hosted on Amazon Web Services, which is compliant with PCI DSS, SOC 1/2/3, ITAR, EU-US frameworks and NIST. That is Amazon's compliance, not Sense's. Every company running on AWS can say the same sentence, and it tells you nothing about the vendor's own controls. A separate SOC 2 Type II attestation was announced in 2021 and its currency in 2026 could not be verified. There is no ISO 27001, no ISO 42001, no subprocessor list, no published retention or residency, and no bias audit. Autonomy is asserted across all six agents with no review gates or escalation model documented, and the product heritage is rules-based multi-channel messaging.
What is not disclosed. Pricing. Also worth knowing: redeployment is listed as a capability but never actually detailed in the documentation, which is odd given that redeployment is a headline claim. Ownership: independent, with roughly $90M raised including SoftBank Vision Fund, Accel and GV, but no round found since a Series D in December 2021 — notable in a 2026 ranking, and a reasonable thing to ask about. Its published fill-rate and redeployment-rate figures are vendor claims and are not scored here.
The binding constraint: your firm is a regulated party, not a bystander
A staffing firm is not downstream of AI hiring law — it is named in it. New York City's Local Law 144 writes every operative obligation as applying to an employer or employment agency. California's FEHA regulations define an employment agency to include anyone who, for compensation, procures job applicants or opportunities to work "including persons undertaking these services through the use of an automated-decision system," and separately provide that an agent of an employer is also an employer for purposes of the Act. The audit, notice and recordkeeping duties land on your desk, not only on your client's. That single fact reorders the buying decision.
Local Law 144, precisely. A covered tool must have had an independent bias audit within the past year, a summary of the results must be published, and candidates must get notice at least ten business days before use. The notice must explain how to request an alternative selection process or a reasonable accommodation under other laws, if available — and the rules add, in terms, that nothing in the law requires an employer or employment agency to provide an alternative selection process. It is widely misreported as an opt-out right. It is not one.
Two consequences from the city's own published FAQ decide how you should shop. First, on responsibility: "Employers and employment agencies are responsible for ensuring they do not use an AEDT unless a bias audit was done. The vendor that created the AEDT is not responsible for a bias audit of the tool." A vendor may commission an audit, and the ones that do make your life much cheaper — but the duty does not transfer. Second, on auditors: DCWP does not maintain a list of approved independent auditors, and the law does not require auditors to be approved. So "audited" is not a status you can look up. You have to check who audited, and against three disqualifiers: they cannot work for you or for the vendor, cannot have been involved in using, developing or distributing the tool, and cannot hold a direct or material indirect financial interest in either party.
The split no competing ranking draws: sourcing is outside, screening is inside.
DCWP's FAQ answers it directly. Asked whether the requirements apply when a tool is used to scan a resume bank, conduct outreach to potential candidates, or invite applications, the answer is No — the requirements apply to assessing candidates for hiring or promotion, and a candidate is someone who has applied for a specific position. But "employment decision" is not just the final hire: if you use a tool to substantially help assess or screen candidates at any point in the process, you must comply first. So database reactivation, resume-bank scanning and cold outreach sit outside. Ranking, scoring and AI interviews of actual applicants sit inside. That line runs straight through the vendor table above — and it is a Local Law 144 exemption only. California's regulations reach any system that merely "facilitates human decision making," and expressly list directing job advertisements to targeted groups and screening resumes for particular terms or patterns as covered activities. A sourcing tool outside New York's rule can be squarely inside California's.
"We're not in New York" is not a defence.The law reaches use "in the city," which the rules define to include a job located at a New York City office even part time, a fully remote job whose associated location is a New York City office, or an employment agency located in New York City. A firm headquartered anywhere in the country is covered the moment it screens applicants for a remote role tied to a Manhattan office. This is the most commonly missed trigger on agency desks.
And the enforcement record is close to nil — which is a reason to be honest, not relaxed.The New York State Comptroller audited DCWP's enforcement in Report 2024-N-6, issued 2 December 2025, covering July 2023 to June 2025. DCWP received only two AEDT-related complaints in two years. The audit identified no formal investigations and no enforcement actions. DCWP surveyed 32 company websites and their bias audits and found one non-compliance issue; the Comptroller reviewing the same companies found at least 17 instances of potential non-compliance. The report's finding is that DCWP's complaint process "is ineffective in ensuring that all complaints related to non-compliance with LL144 are routed to DCWP." Law-firm commentary now predicts a tougher posture because the agency accepted the recommendations; a prediction is not a fact. The honest statement to a principal is this: your realistic exposure here is a client indemnity demand or a private plaintiff, not a city inspector.
Illinois changed on 1 January 2026, and it bites on matching models.Public Act 103-0804 makes it a civil rights violation for an employer to use artificial intelligence "that has the effect of subjecting employees to discrimination on the basis of protected classes... or to use zip codes as a proxy for protected classes," across recruitment, hiring, promotion, renewal, training selection, discharge, discipline, tenure and terms of employment — plus a separate violation for failing to give notice that AI is being used for those purposes. "Has the effect of" is a disparate-impact standard written into state statute, so intent is irrelevant. And the zip-code clause reaches any model that weights commutability, radius or market fit, which is most sourcing and matching products. The Act directs the Department of Human Rights to adopt rules on the circumstances, timing and means of notice; we could not verify whether final rules exist as of 23 August 2026, so check the Department's current status before you lock a notice format.
Illinois has had a second law since 2020 that is more immediately operational. The Artificial Intelligence Video Interview Act requires an employer, before a video interview, to notify the applicant that AI may be used to analyse it, to provide information explaining how the AI works and what general types of characteristics it uses to evaluate applicants, and to obtain consent — and an applicant who has not consented may not be evaluated. It limits sharing of applicant videos to persons whose expertise or technology is necessary to evaluate fitness, which constrains sub-processors and third-party model APIs. It requires deletion within 30 days of an applicant's request, including all electronically generated backup copies. The purchasing test that falls out of this is the sharpest one in the article:the duty to explain what the model evaluates falls on you, but only the vendor can supply the explanation. A vendor that will not give you a written, plain-language description of what its interview model evaluates cannot be used lawfully in Illinois. Ask for it on the demo call. Also note there is no 2025 or 2026 amendment to this Act adding an "explicit written consent" requirement, despite that claim circulating widely — its amendment history runs to 2022.
California is the heaviest lift, and it is already in force. The Civil Rights Council's automated-decision system regulations took effect on 1 October 2025. Beyond the employment-agency and agent definitions above, three provisions change vendor selection outright. The trigger is a system that "makes a decision or facilitates human decision making regarding an employment benefit" — materially wider than New York's "substantially assist," so the human-in-the-loop argument that keeps a tool outside Local Law 144 does not keep it outside California. Anti-bias testing is now evidentially relevant: it is unlawful to use a system that discriminates, "subject to any available defense," and relevant to any such claim or defence is "evidence, or the lack of evidence, of anti-bias testing or similar proactive efforts... including the quality, efficacy, recency, and scope of such effort, the results of such testing or other effort, and the response to the results." California made not testing legally relevant. And records retention moved from two years to four, expressly including automated-decision system data — the inputs, the scores and the outcomes.
A concrete, checkable buying criterion falls straight out of that.
California requires four years of retention of automated-decision system data. A vendor whose contract or trust page specifies a 30-, 60- or 90-day deletion default is architecturally in tension with that duty. Ask every vendor two questions in writing: can you retain scoring data and model inputs for four years, and will you export all of it to me on exit? Then notice the genuine conflict you have to engineer around — Illinois requires deletion within 30 days of an applicant's request. Different data, different states, but you need one retention policy that can do both, and most vendors have not thought about it.
Colorado, stated as a chronology rather than a headline.SB 24-205, the first US state AI act, was signed 17 May 2024 with obligations from 1 February 2026. SB 25B-004, signed 28 August 2025, moved that date to 30 June 2026. SB 26-189, signed 14 May 2026, repeals and reenacts the regime as an automated decision-making technology statute; its own text says the act takes effect January 1, 2027 and applies to consequential decisions made on or after January 1, 2027. Anyone citing "effective May 14, 2026" has read the legislature's banner, which reflects the act's safety clause, not the bill. Employment is expressly covered. Enforcement is exclusively by the Attorney General with a 60-day right to cure, and the act states that nothing in it creates a new private right of action. The most useful thing in it for a firm operating nowhere near Colorado is its definition of meaningful human review: an individual designated by the deployer with authority to approve, modify or override the decision, who considers relevant available primary evidence and is trained to conduct the review. That is a better internal standard than anything a vendor will hand you.
Mobley v. Workday, with the posture stated exactly. This is the leading AI-hiring case in the United States and it is misdescribed constantly. In July 2024 the Northern District of California dismissed the Title VII, ADEA and ADA claims brought on an employment agency theory without leave to amend — so nobody has held that AI vendors are employment agencies; the opposite was decided. What survives runs on an agenttheory plus disparate impact. On 16 May 2025 the court granted preliminary certification of a collective defined in the order as "[a]ll individuals aged 40 and over who, from September 24, 2020, through the present, [] applied for job opportunities using Workday, Inc.'s job application platform and were denied employment recommendations." The same order records that the standard at this stage is "loosely akin to a plausibility standard," that the "sole consequence" of preliminary certification is court-approved notice to workers who may wish to join, and that Workday may later seek decertification. That is an opt-in age-discrimination collective, not a Rule 23 class, and there is no merits ruling and no finding of liability. A 22 June 2026 order dismissed one plaintiff's disparate-impact race claim and the direct-employer claims with no further leave to amend, denied the motion as to another plaintiff's ADA claim, and otherwise denied dismissal of the FEHA claims.
Why a staffing principal should care about a case against a software company: the surviving theory is that a tool providercan be liable as the employer's agent for screening it performs on the employer's behalf. That is precisely the position your firm occupies relative to your clients. There is also a consolidation point worth raising in diligence rather than in outrage — Workday acquired HiredScore, whose scoring features caused the preliminary collective to be expanded in July 2025, and completed its acquisition of Paradox on 1 October 2025 with terms undisclosed. A firm evaluating Paradox in 2026 is buying from the defendant in that case. There has been no finding of liability, no merits ruling, and Workday denies the claims. The point is only that consolidation moves litigation risk into a suite a buyer may not realise they are joining.
Federal enforcement went quiet; federal liability did not. The EEOC's AI technical assistance documents from 2022 and 2023 are no longer published — we checked, and those URLs return 404 — while the Department of Justice's guidance on algorithms, AI and disability discrimination in hiring is still live. Executive Order 14281, signed 23 April 2025, directs agencies to deprioritise enforcement of statutes and regulations involving disparate-impact liability. It amends no statute. Disparate-impact liability under Title VII comes from the statute, from Griggs v. Duke Power Co. and from the 1991 Civil Rights Act codification, and private plaintiffs retain a private right of action — which is why Mobley survived a motion to dismiss and had a collective preliminarily certified after that order issued, why Illinois wrote an effects test into state law, and why California made the absence of testing evidentially relevant. Any vendor telling you the EEOC dropped the AI rules so this is fine now is selling you a misreading.
The framework underneath all of it is still the 1978 Uniform Guidelines on Employee Selection Procedures. Its four-fifths rule says a selection rate for any race, sex or ethnic group below four-fifths of the highest group's rate "will generally be regarded by the Federal enforcement agencies as evidence of adverse impact" — and, in the same paragraph, that "smaller differences in selection rate may nevertheless constitute adverse impact, where they are significant in both statistical and practical terms." It is a rule of administrative convenience, not a safe harbour, and a vendor marketing "we pass the four-fifths rule" is quoting a screening heuristic as a clean bill of health. The Guidelines also provide that where a user has not maintained adverse-impact data, the enforcement agencies may draw an inference of adverse impact from that failure. Not measuring is not neutral.
Two more that catch agency desks. On background and reference checking: the CFPB's Circular 2024-06, which said third parties assembling or evaluating worker information including algorithmic scoring developers may be consumer reporting agencies, was withdrawn on 12 May 2025 — many 2026 articles still cite it as operative. The Fair Credit Reporting Act itself is untouched. Checkr, Inc. appears on the CFPB's own list of consumer reporting companies under employment screening, which makes your firm a user of consumer reportswith the full disclosure, authorisation, pre-adverse-action and adverse-action stack. Ask any reference or credential vendor in writing whether it operates as a CRA and will support FCRA adverse action. On Europe: Regulation (EU) 2026/1744 deferred the Annex III high-risk obligations, which cover employment, to 2 December 2027. The "August 2026" date still printed in a great deal of content is the pre-Omnibus timeline and is wrong.
| Instrument | Status as of 2026-08-23 | What it does to a staffing desk |
|---|---|---|
| NYC Local Law 144 | In force since 2023; near-zero enforcement record per the State Comptroller | Binds employment agencies by name. Annual independent bias audit, published summary, 10 business days' notice — for screening, not sourcing |
| Illinois P.A. 103-0804 | In force 1 January 2026 | Effects-based discrimination standard plus a named prohibition on zip codes as a proxy. Notice duty. Implementing rules status not verified |
| Illinois AI Video Interview Act | In force since 1 January 2020 | Pre-interview notice, a written explanation of what the AI evaluates, consent, sharing limits, 30-day deletion on request |
| Maryland facial recognition consent law | In force since 1 October 2020 | Narrow: consent required before creating a facial template during an interview. A voice-only AI interview does not create one |
| California FEHA ADS regulations | In force since 1 October 2025 | Employment agency and agent both covered. Trigger includes facilitating human decisions. Four-year retention of ADS data. Absence of bias testing is evidence |
| California CPPA ADMT regulations | Compliance date 1 January 2027 | Separate regime; significant decisions expressly include hiring and the allocation or assignment of work |
| Colorado SB 26-189 | Signed 14 May 2026; effective 1 January 2027 | Applies to consequential decisions made on or after that date. Employment covered. AG-exclusive enforcement, no private right of action |
| Mobley v. Workday | Active; preliminary ADEA collective certified; no merits ruling, no Rule 23 class | The surviving theory is agent liability for screening performed on an employer's behalf — the position your firm occupies |
| EO 14281 / Title VII | EO in force; statute unchanged | Federal enforcement deprioritised. Disparate-impact liability and the private right of action are intact |
| CFPB Circular 2024-06 | Withdrawn 12 May 2025 | Do not cite it as operative. The FCRA statute is unaffected and still governs reference and background checking |
| EU AI Act Annex III | Deferred to 2 December 2027 by Regulation (EU) 2026/1744 | Employment obligations arrive later than the widely printed August 2026 date |
LinkedIn, scraping, and the case everyone cites wrongly
Not one of the sourcing vendors in this ranking has a verified LinkedIn partnership, and the reason is structural rather than sinister. Recruiter System Connect is the official mechanism, it is restricted to LinkedIn-approved developers under a signed API agreement with data restrictions, and it is built for applicant tracking system partners rather than sourcing tools. That is why Bullhorn is in it and the sourcing vendors are not. Reporting also suggests approval takes months and that new partner applications were not being accepted in 2026, though that last point is secondary and should be treated as such. What Recruiter System Connect actually delivers is narrow — rediscovered candidates, an in-ATS indicator, one-click export, a profile widget, InMail history and stub profiles. It is not a licence to bulk-export profiles.
So when a vendor says "LinkedIn integration," ask which programme. In this research the honest answers were: a browser extension that enriches LinkedIn profile pages in the browser, which is not an API partnership; outreach sequencing that sends messages through LinkedIn; job-board posting, which is not Recruiter API access; or a documented dependency on LinkedIn-sourced profile data with no partnership evidenced anywhere. Those are four different things and only one vendor in the set survives verification as a named partner.
"Scraping is legal" is obsolete, and the citation people use proves the opposite.
The famous 2019 Ninth Circuit holding in hiQ v. LinkedIn concerned the Computer Fraud and Abuse Act — scraping public data did not violate that statute. It did not settle the question. In November 2022 the district court granted LinkedIn summary judgment on breach of contract, and in December 2022 a consent judgment imposed $500,000 against hiQ plus a permanent injunction requiring it to stop scraping and to delete the source code, data and algorithms. CFAA liability and contract liability are different questions with different answers. A vendor whose pipeline depends on scraped LinkedIn data carries contract exposure regardless of the 2019 headline — and, because you are the one submitting those candidates to clients, so do you. One related claim we checked and rejected: there is no evidence of a LinkedIn cease-and-desist against hireEZ. That was hiQ Labs, a different company. The conflation is common and should not be repeated.
The numbers we refuse to print, and why the replacements are no better
"75% of resumes are never seen by a human" should never appear in a document your firm signs its name to.Its earliest attributable publication is a Computerworld article of 4 March 2012, which said applicant tracking systems "kill 75% of candidates' chances of landing an interview as soon as they submit their resumes, according to job search services provider Preptel." Read what that actually claims: it is about chances of an interview, sourced to a vendor, with no study behind it. The modern form — the ATS rejects three quarters of resumes before a human sees them — asserts something the original never said. Preptel sold resume-optimisation software; it was selling the cure for the fear it manufactured. It shut down on 30 August 2013, telling customers that after running three years in the red it had to close. It never published a study, a dataset, a sample size or a methodology. The company has been dead for thirteen years and the number is still circulating on pages dated 2026.
And the debunkers' replacement figure is equally unusable, which is the part almost everyone gets wrong.The widely quoted counter-statistic — that 92% of recruiters say their systems do not auto-reject resumes — comes from a commercial AI resume-builder, a company with exactly the same commercial interest in ATS anxiety that Preptel had, arguing the other direction. Its own methodology note says the findings are based on 25 in-depth interviews and that they "represent consistent themes across recruiters rather than nationally representative statistics." The 92% is 23 people. The 8% who reportedly do auto-reject is two people. The direction of the debunk is well supported — an ATS organises and ranks, humans reject — but swapping one vendor's unrepresentative number for another's is not a correction. Make the argument without a statistic.
Three more that fail provenance."The average corporate job posting receives 250 applications" traces to a Glassdoor for Employers marketing listicle from 20 January 2015 with no citation, no footnote, no linked study, no date range, no sample and no definition of a corporate job opening; the "242" variant now circulating traces through a chain of blogs to an unmethodologised attribution. "Recruiters spend six seconds on a resume" comes from a 2012 press release by a paid job board that sold resume-writing services, with methodology stated only as eye-tracking of "dozens" of recruiters; the 2018 update to 7.4 seconds discloses no sample size, duration or protocol at all. And "a bad hire costs at least 30% of first-year earnings, per the US Department of Labor" is a fabricated attribution — no such DOL publication exists, and the dates given for it range across two decades.
What you can cite instead, correctly attributed. SHRM's benchmarking, on data collected April to November 2021 from a random sample of members, put mean cost-per-hire at $4,683 and the medianat $1,244. The circulating "$4,700" is that mean, rounded, and it describes almost no employer — the average is dragged by a long right tail, and executive cost-per-hire in the same table has a median of $8,750 against a mean of $28,329. SHRM itself has since abandoned the mean, writing that its analyses use median values to avoid the influence of extreme outliers; its 2025 report puts median cost-per-hire at $1,200 for non-executive roles and $10,625 for executive roles. On time-to-fill, "42 days" is unprintable — no SHRM publication stating it could be found — while SHRM's actual published medians are 44 days in the 2021 data, 44 days in 2025 and 39 calendar days in 2026, measured from requisition opening to offer acceptance including weekends and holidays. If you want a rigorous vacancy-duration series instead, be aware the one that existed was discontinued, with its last observation in April 2018.
The AI side is repeating the same pattern one generation later.The cluster of numbers propagating through every AI-recruiting content page — cost per screen reduced 75%, turnover down 35%, revenue per employee up 4%, 23 hours saved per hire, 70% reduction in time to fill — traces to a single resume-screening vendor's marketing page, with no hyperlinks, no footnotes, no sample, no dates and no definition of the "early adopter companies" it describes. That vendor's domain no longer resolves. In 2012 it was Preptel's 75%; in 2026 it is a defunct AI vendor's 35%. Same shape, same absence of method, same dead company. And there is a structural reason no vendor can have measured a quality-of-hire improvement across a customer base: SHRM's own benchmarking shows the share of organisations using quality-of-hire measures at 23% in 2017, 27% in 2022 and 20% in 2025, with SHRM writing that fewer than a quarter of organisations assess the value their new hires provide. Roughly four in five employers cannot detect a change in quality of hire. That retires every claim to have improved it.
A worked example: an 18-desk light-industrial contract firm
This is an illustrative scenario, not a client result — we will not print an invented outcome in an article whose whole argument is that unsourced numbers should not travel. The arithmetic below uses only prices the vendors publish themselves.
Consider an 18-recruiter light-industrial contract staffing firm on Bullhorn, running roughly 900 phone screens a month across warehousing and driver roles, with a candidate database of about 180,000 records of which perhaps a fifth have been touched in two years. Two jobs are worth automating: the first-pass screen, and the reactivation pass over the dormant database. Nothing else on that desk is a good first candidate.
The screening maths, using published rates.At Ribbon's Business tier, $999 a month covers 400 interviews with $3.00 per interview after that — so 900 interviews costs $999 plus 500 × $3.00, or $2,499 a month. The Scale tier at $1,999 covers 1,000 interviews outright. At this volume Scale is $500 a month cheaper than Business, which is exactly the sort of thing a demo will not tell you and a pricing page will. That is $23,988 a year for the screening layer, on published pricing, with no negotiation. Compare that to the platform decision underneath it: 18 seats of Loxo Professional at $199 is $3,582 a month, or $42,984 a year, and it replaces your ATS. Eighteen seats of Bullhorn Core at $165 is $2,970 a month — but Amplify Digital Workers require the Max tier, which is not priced publicly, so that comparison cannot be completed from public information. Neither can a comparison against HeyMilo, Findem, Alex or Sense, none of which publishes pricing.
The costs the pricing page does not show.If any of those 900 screens relates to a role tied to a New York City office — including a fully remote one — you are inside Local Law 144 and you own the audit, the published summary and the ten-business-day notice, whatever your vendor's badge says. If any candidate is in California, you owe four years of retention on the scoring data, which is a contractual conversation with the vendor before signature rather than a discovery after exit. If any interview is in Illinois, you owe a plain-language written explanation of what the model evaluates, and only the vendor can write it. Budget for a compliance workstream, not just a licence. In our experience the notice, the retention clause and the accommodation path are the three items that stall a rollout, and all three are cheap to solve in week one and expensive to retrofit in month nine.
Where the reactivation pass actually pays.The honest framing is that reactivation is not an AI achievement, it is a database achievement that AI makes affordable. Nobody was going to call 36,000 dormant records. An agent that re-engages them by text and email, updates availability and location, and hands a recruiter a ranked list of people who replied is doing work that previously did not happen at all — which means the comparison is not "agent versus recruiter," it is "agent versus nothing." That is also why this workflow sits outside Local Law 144: those people have not applied for a specific position. The moment one of them applies and the same system ranks them, you are inside it.
What breaks first
The failure that matters is rarely the model being wrong. It is the agent being confidently right about something it should never have acted on. Here is what actually goes wrong on recruiting desks, what the early signal looks like, and how you roll it back.
| Failure mode | Early detection signal | Rollback |
|---|---|---|
| Prompt injection through a resume, candidate email or client job spec | Agent output that references instructions nobody gave it; a candidate advancing with a summary that reads oddly on-message; unexplained tool calls in the action log | Kill the agent's write permissions first, not the agent. Re-run the affected batch with a human reviewer and re-check every record it touched in that window |
| Silent integration drift after an ATS field change | Submissions posting with a blank or default status; skills writing to the wrong field; a sudden drop in agent-created records | Pause the sync, not the tool. Reconcile against the ATS audit log for the period, then re-map before re-enabling |
| Score-following on the desk | Recruiters working the ranked list strictly top-down; nobody overriding the tool in a month of activity | This is the one that converts a tool outside Local Law 144 into one inside it. Retrain the desk, and document that recruiters consider factors beyond the score |
| Outreach volume outrunning consent | Opt-out rates climbing; complaints about texts or calls to candidates who never applied | Stop outbound immediately. AI voice is an artificial voice under the TCPA and marketing outreach needs prior express written consent; this is the failure that produces a lawsuit rather than a bad week |
| Retention default deletes what you needed | A vendor's 30- or 90-day purge quietly removing scoring inputs for California applicants | Cannot be rolled back — which is why it is a contract question, not an operations question. Fix it before signature |
| Vendor disappears or is acquired mid-term | Website content stops being dated; funding history goes quiet; support response times slip; the trust page stops being updated | Have an export path written into the contract on day one, including model inputs and scoring outputs, not just candidate records |
On prompt injection, be honest with yourself: it is unsolved. A recruiting agent reads the most adversarial input in business software — documents written by people with a direct incentive to influence the outcome. Candidates already embed hidden instructions in resumes. Nothing on the market prevents this; the realistic objective is blast-radius reduction. Give the agent read-only credentials wherever the workflow allows, scope every write to a single named object, require approval before any outbound message or status change, log every action alongside the input that triggered it, and make sure it cannot reach systems it does not need. The best design pattern we found in this market is Ashby's: agent actions run as the operating user, so every read and write respects that user's existing job, team and object-level permissions. We work through the attack classes and the mitigations in detail in our guide to prompt injection and the OWASP LLM Top 10.
The human-in-the-loop boundary
Write this table into your own operating procedure and hold vendors to it, rather than accepting whatever autonomy their marketing asserts. Colorado supplies the standard for what the review has to be: a named individual designated by your firm, with authority to approve, modify or override the decision, who considers relevant available primary evidence and is trained to conduct the review. Not a rubber stamp, and not a queue nobody reads.
| Task | May the agent act alone? | Why |
|---|---|---|
| Parse a resume to text; transcribe an interview | Yes | Transcription and format conversion are expressly excluded from the definition of a simplified output under the New York City rules. A ranking built on top of the parse is a different matter |
| Enrich a candidate record; deduplicate; update stale CRM fields | Yes | No employment decision is being made. Log the changes so you can reconstruct what the record looked like when a decision was taken |
| Scan a resume bank or contact dormant candidates who have not applied | Yes, with consent controls | Outside Local Law 144 per DCWP's FAQ. Still inside California's regulations, and any call or text sits inside the TCPA consent regime |
| Draft outreach, a job description or a client submission | Draft only | A submission is the billable moment on an agency desk. Loxo publishes the right stop-line: autonomous through the shortlist, never through the decision |
| Send outreach to a candidate or client | Needs review | It is your firm's name on the message. An AI voice is an artificial voice under the TCPA, and marketing outreach requires prior express written consent |
| Rank, score or shortlist actual applicants | Needs review, and triggers duties | Inside Local Law 144 and inside the California regulations. Recruiters must weigh factors beyond the score, and you must be able to show they did |
| Reject an applicant, or advance one to a client | Never alone | This is the adverse action. It is where disparate-impact exposure lives, and where the four-fifths analysis will eventually be run |
| Conduct an AI interview without a disclosed accommodation path | Never | Illinois requires notice, an explanation of what the AI evaluates, and consent; the New York City notice must explain how to request an accommodation. A vendor with no accommodation workflow is not deployable |
| Delete or overwrite candidate records and scoring data | Never alone | California requires four years of retention of automated-decision system data. You cannot produce what an agent tidied away |
Cost and timeline, if you decide to build instead
Buy first. For most staffing firms the right answer is a published-price product wired properly into the ATS you already run, and the ranking above exists to help you pick one. Building is the right answer in a narrower set of cases: when your workflow is genuinely unusual — VMS tiers, credentialing, redeployment logic, pay and bill reconciliation — when no vendor integrates with the system your desk actually lives in, or when the compliance artefacts you need for client audits do not exist in any product you can buy. We work through that decision in detail in our build versus buy analysis for AI agents.
| Engagement | Range | Timeline |
|---|---|---|
| Discovery + workflow audit | $9k–$22k | 2–4 weeks |
| Single-workflow agent | $28k–$70k | 4–9 weeks |
| Multi-workflow platform with system integration | $70k–$180k | 9–16 weeks |
| Enterprise / multi-site / regulated build | $180k–$420k+ | 14–24 weeks |
Senior-led engineering runs $150–$225/hr, retainers run $2,500–$9,500/month, and every build carries a 30-day post-launch warranty. We return a fixed-price phased proposal within 5 business days of a discovery call. Full source-code and IP ownership transfers to you — which matters more than usual here, because the audit trail and the retention architecture are the parts you will still need in four years when a client's counsel asks for them. Frenchy Digital is a senior-led, Black-owned agency in Los Angeles; you can reach us on +1 (424) 272-5601 or book directly at calendly.com/frenchydigital/discovery-call.
Not sure whether to buy one of these or build around your desk?
Bring us your ATS, your compliance exposure and the workflow you actually want automated. We will tell you honestly if an off-the-shelf product does the job — most of the time it does.
Red flags when evaluating a vendor
Every item below appeared in this research, in public, on a vendor's own pages. None of them requires you to be technical to catch.
- A bias-audit badge with no auditor named, no date and no impact ratios — or a report behind a lead-capture form. The rules require the summary to be publicly available; a gated PDF does not satisfy that, and you are the one who has to publish it.
- "Compliance is covered." It is not. The city's own FAQ says the employer or employment agency is responsible for ensuring a bias audit was done. A vendor that tells you otherwise has either not read the rule or is hoping you have not.
- A cloud provider's certifications presented as the vendor's own. "Hosted on AWS, which is compliant with SOC 1/2/3 and PCI DSS" is a sentence every company on AWS can write and tells you nothing about the vendor's controls.
- "Compliant with" a standard rather than "certified to" it, and "aligned with" rather than either. All three appear in this market and all three mean different things. Read the exact verb.
- A SOC 2 date three years old on a 2026 page. SOC 2 Type II covers an observation window and recurs; a stale date is a disclosure finding in itself.
- "SOC 2" with no Type stated. Type I tests design at a point in time; Type II tests operation over a period. Do not upgrade it for them.
- A homepage badge line with no trust page, no security page, no auditor and no report request flow. If a vendor holds the report, producing it under NDA takes a day.
- "Autonomous" agents with no human-approval, escalation or review language anywhere on the page — especially where one of them sends candidate outreach automatically.
- Classic ATS automation relabelled as agents: rules-based messaging, keyword matching and timesheet OCR renamed without changing what they do.
- "LinkedIn integration" that turns out to be a browser extension, job-board posting or outreach sequencing rather than a named partner programme.
- Any accuracy, time-to-fill, quality-of-hire or ROI figure offered as neutral fact. There is no independent benchmark of these products; the figure is the seller's.
- "The EEOC dropped the AI rules, so this is fine now." Federal enforcement priorities changed. Title VII, the ADEA, the ADA and the private right of action did not.
- A retention default of 30, 60 or 90 days sold to a firm with California candidates, where four years of automated-decision system data must be preserved.
- A G2, Capterra or Gartner Peer Insights position offered as independent validation. Those are user-review aggregators, not evaluations.
What we could not verify
Naming the gaps is part of the method, not an apology for it. As of 23 August 2026, here is what this ranking does not know.
- Several vendor trust pages could not be fetched: one trust portal returned 403 to an automated request, and the security paths for three vendors returned 404. Absence of a fetchable page is not proof a control does not exist — but it is proof the disclosure is not public, which is what we scored.
- Mercor's compliance posture was not researched at all, because it is not a product a staffing firm buys and it is not in the ranking.
- Legal entity names are not published for several vendors, which matters when you are signing rather than shortlisting.
- The Bullhorn Marketplace index is JavaScript-paginated and could not be enumerated. One vendor's dedicated listing does resolve directly, so treat absence from our reading of the index as a fetch limitation rather than evidence of absence.
- Whether the Illinois Department of Human Rights has adopted final notice rules under the 2026 statute could not be confirmed either way. We do not assert that rules exist, and we do not assert that they do not.
- New York City penalty amounts and the underlying code section numbers were not independently confirmed against the code text, so they are omitted rather than approximated.
- The Colorado Attorney General's current enforcement posture could not be verified from a primary source, so this article states the statutory chronology and nothing about enforcement intent.
- Texas, Utah, Virginia, Maryland's broader AI provisions, New Jersey and New York State AI employment measures were not verified and are therefore not described here at all.
- Pricing is genuinely unknown for five of the ten ranked products. We did not estimate any of them, and a comparison table that fills those cells with a guess is doing you harm rather than a favour.
- Bias-audit results are reported as published. We did not re-run any auditor's analysis, and we could not, because the underlying data is not public.
Employers and employment agencies are responsible for ensuring they do not use an AEDT unless a bias audit was done. The vendor that created the AEDT is not responsible for a bias audit of the tool.
— NYC Department of Consumer and Worker Protection, Automated Employment Decision Tools FAQ
That sentence is the whole article in miniature. The tooling is improving quickly, three vendors now publish genuinely independent and current bias audits, and pricing transparency in this category is better than in most. But the duty does not move when you buy software, the market has no independent benchmark to appeal to, and the roster changes faster than the content written about it. Re-check the table before you act on it — that is what we did to write it.
Thinking about building instead of buying?
We build agents that sit inside a staffing desk's existing stack, with the audit trail your clients will ask for. Book a discovery call and we will tell you honestly whether a build is the right call.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1NYC DCWP, Automated Employment Decision Tools: Frequently Asked Questions (PDF)↗
- 2NYC DCWP, Notice of Adoption of Final Rule on Automated Employment Decision Tools (PDF)↗
- 3New York State Comptroller, Report 2024-N-6, Enforcement of Local Law 144 (2 December 2025)↗
- 4Illinois Public Act 103-0804, amending the Illinois Human Rights Act (effective 1 January 2026)↗
- 5Illinois Artificial Intelligence Video Interview Act, 820 ILCS 42↗
- 6California Civil Rights Council, Final Text: Employment Regulations Regarding Automated-Decision Systems (PDF)↗
- 7Colorado SB 26-189, enrolled act as signed 14 May 2026 (PDF)↗
- 8Mobley v. Workday, Inc., Order Granting Preliminary Collective Certification, 16 May 2025 (PDF)↗
- 9Mobley v. Workday, Inc., Order on the Second Amended Complaint, 22 June 2026 (PDF)↗
- 10Executive Order 14281, Restoring Equality of Opportunity and Meritocracy, 90 FR 17537↗
- 11CFPB, Withdrawal of Interpretive Rules, Policy Statements and Advisory Opinions, 12 May 2025↗
- 12Uniform Guidelines on Employee Selection Procedures, 29 C.F.R. Part 1607↗
- 13US Department of Justice, Algorithms, Artificial Intelligence, and Disability Discrimination in Hiring↗
- 14Warden AI public assurance dashboard: Findem AI Applicant Matching↗
- 15Warden AI public assurance dashboard: HeyMilo↗
- 16Warden AI public assurance dashboard: Alex AI Recruiter↗
- 17LinkedIn Talent Solutions, Recruiter System Connect developer documentation↗
- 18Bullhorn, LinkedIn Recruiter System Connect integration overview↗
- 19Bullhorn unveils Amplify Digital Workers at Engage Boston, 28 May 2026↗
- 20Loxo pricing page↗
- 21Ribbon pricing page↗
- 22Meredith Levinson, 5 Insider Secrets for Beating Applicant Tracking Systems, Computerworld, 4 March 2012↗
- 23SHRM Benchmarking: Talent Access Report, data collected April to November 2021 (PDF)↗
- 24Kyra Wilson and Aylin Caliskan, Gender, Race, and Intersectional Bias in Resume Screening, AAAI/ACM AIES, 22 October 2024↗
- 25In the Matter of Presto Automation Inc., Securities Act Release No. 11352, 14 January 2025 (PDF)↗

