Instructions for Use

Instructions for use of the Jaicob platform as a high-risk AI system under the EU AI Act (Regulation (EU) 2024/1689), provided pursuant to Article 13.

📘

Who should read this

This document is for every organisation that uses the Jaicob platform to recruit ("you", the deployer in AI Act terms). It is the "instructions for use" that Jaicob, as provider of a high-risk AI system, must supply under Article 13 of the EU AI Act. Share it with the people in your organisation who own recruitment, compliance, and data protection.

This document is informational and does not constitute legal advice. Consult your own counsel for your specific situation.

Document version: 1.0 (August 2026). This document is kept up to date; the version shown here always reflects the current platform.

1. Provider identification

ProviderJaicob B.V.
AddressBurgemeester Stekelenburgplein 199, 5041 SC Tilburg, the Netherlands
Chamber of Commerce (KvK)92883761
Contact[email protected]
Public transparency statementhttps://jaicob.ai/legal/ai

Jaicob B.V. is the provider, within the meaning of Article 3(3) of the EU AI Act, of the AI systems embedded in the Jaicob platform. Registration and conformity obligations that rest on the provider of a high-risk AI system are handled by Jaicob; obligations that rest on the deployer are yours and are described in Section 7 and in the companion document EU AI Act: Deployer Checklist.

2. Classification and intended purpose

2.1 Classification

The AI features of the Jaicob platform are classified as a high-risk AI system under Article 6(2) of the AI Act in conjunction with Annex III, point 4(a): AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates.

2.2 Intended purpose

The platform's AI features are intended to be used by professional recruiters and hiring teams to support the recruitment and selection of candidates:

  • identifying potential candidates for a specific vacancy (AI Sourcing);
  • comparing candidate profiles and applications against the requirements of a specific vacancy and producing advisory match scores, screening summaries, and rankings (AI Matching and screening);
  • carrying out recruiter-configured outreach and follow-up tasks under approval rules (AI Agents);
  • conducting structured screening conversations with candidates via chat, SMS, or voice (AI interviews);
  • assisting recruiters with questions and tasks on their own data (Copilot); and
  • extracting structured data from documents such as CVs (document understanding).

All AI outputs are decision support. The intended operator of the system is a trained human recruiter who reviews AI output before it affects a candidate.

2.3 Reasonably foreseeable misuse (do not do this)

The following uses are outside the intended purpose. They are either prohibited by law, blocked by the platform, or contractually not permitted:

  • Fully automated hiring or rejection: acting on AI output without meaningful human review, or treating approval queues as a formality (see Section 6 on automation bias).
  • Emotion inference: using the platform, or attempting to configure it, to infer candidates' emotions. Emotion inference in the workplace context is prohibited by Article 5(1)(f) of the AI Act. The platform contains no such capability and none may be recreated via custom prompts or agent instructions.
  • Filtering on protected characteristics: instructing agents or search features to select or exclude candidates by gender, nationality, ethnicity, age, religion, disability, or other protected characteristics. The platform withholds gender, nationality, and date of birth from AI evaluation by design.
  • Use for other HR decisions: the system is intended for recruitment and selection. Using its outputs for decisions about existing employees (promotion, termination, performance evaluation) is a different high-risk category (Annex III, point 4(b)) and is not the intended purpose of the platform.
  • Non-recruitment evaluation of people: creditworthiness, insurance, tenant screening, or any other evaluation of natural persons.
  • Undisclosed AI conversations: disabling, circumventing, or instructing agents to circumvent the built-in AI disclosures (they cannot be disabled, and attempting to prompt around them is misuse).
  • Use on minors: the platform is intended for the recruitment of adults.

3. Capabilities and features

FeatureWhat it doesOutput type
AI SourcingSearches public and licensed professional data sources for profiles matching a vacancyCandidate suggestions
AI Matching / screeningEvaluates a candidate against vacancy requirementsAdvisory score, structured rationale, screening summary
AI AgentsExecutes recruiter-configured recruitment tasks (outreach, follow-up, shortlisting) step by step, with configurable approval gatesProposed and (after approval where required) executed actions, fully logged
AI interviews (chat / SMS / voice)Conducts structured screening conversations with candidatesTranscript, structured answers, summary
CopilotAssists recruiters on their own tenant dataAnswers, drafts, executed recruiter-requested actions
Document understandingExtracts structured data from CVs and similar documentsStructured candidate data for human verification

4. Limitations of performance and known risks

You must take the following limitations into account when interpreting output. They are inherent to the technology and are the reason human oversight is mandatory.

  • Probabilistic output. The system is built on large language models. Outputs are probabilistic, not deterministic: the same input can produce different phrasing, and scores are estimates, not measurements. Never treat a match score as an objective fact about a person.
  • Errors and fabrication. Language models can produce plausible-sounding but incorrect statements, including in summaries and rationales. Verify substantive claims against the underlying source (the CV, the transcript, the application) before relying on them.
  • Document extraction errors. CV parsing can misread layout-heavy, scanned, or unusual documents. Extracted data is an aid for, not a replacement of, reading the document.
  • Language coverage. The platform performs best in English, Dutch, German, and French. Quality can degrade in other languages and with mixed-language documents.
  • Voice conversation limits. Speech recognition accuracy varies with connection quality, background noise, and accents. Transcripts can contain recognition errors; treat them accordingly. Voice processing is used for transcription and conversation only; the platform does not create voice prints or analyse biometric characteristics.
  • Bias risk. Language models can reflect biases in their training data. Mitigations are described in Section 8, but no technical mitigation eliminates this risk entirely. Your own monitoring and fair-hiring practices remain necessary.
  • Data recency and completeness. Sourced profile data reflects the source at crawl/query time and can be outdated or incomplete.
  • Input quality dependence. Output quality is bounded by input quality. Vague vacancy requirements produce vague evaluations. See Section 7 on your input data obligations.

The system provides no guaranteed quantitative accuracy metrics for individual assessments. Aggregate behaviour of scoring features is monitored by Jaicob on an ongoing basis (Section 8).

5. Transparency toward candidates

The platform builds the AI Act's transparency obligations (Article 50) into the product:

  • AI agents identify themselves as AI, never claim to be human, and never deny being AI when asked. This behaviour is region-independent and cannot be disabled.
  • AI voice calls announce at the start of the call that the candidate is speaking with an AI system.
  • SMS conversations disclose AI involvement and honour STOP (and HELP) keywords.
  • The platform records candidate consent where it is captured through platform flows (for example interview/SMS opt-in and privacy consent on public application forms), with server-side timestamps.

What remains yours: informing candidates that AI is used in your recruitment process before it is used on them, in your job postings, application flows, and privacy notices, and within one month for candidates sourced without their prior interaction (Article 14 GDPR). Section 7 and the Deployer Checklist contain a sample notice text.

6. Human oversight measures (Article 14 AI Act)

The platform is designed so that natural persons can effectively oversee it. The measures below exist in the product; assigning competent people to use them is your obligation (Article 26(2) AI Act).

6.1 Built into the platform

  • Mandatory approval floor (EU). For deployers operating under EU rules, actions that negatively affect a candidate (disqualifying a candidate, rejecting an application) always require explicit human approval before they take effect. This floor is enforced server-side, is applied to stored agent configurations, and cannot be disabled by configuration.
  • Configurable approval gates. You control which additional agent actions require approval. Each proposed action can be approved or refused individually, with the refusal reason fed back to the agent.
  • Full activity logging. Every agent run is recorded step by step: every tool action, its inputs at a summary level, its outcome, and the approval trail. Runs are visible in the product.
  • Explanations. The platform can generate a written explanation of the main elements that contributed to an AI-assisted assessment, in stable, auditable wording, for use in answering candidate explanation requests (Article 86 AI Act, Article 22(3) GDPR).
  • Interruptibility. Agents can be paused or stopped. Candidates can end AI conversations at any time; opt-outs (such as SMS STOP) are honoured immediately.

6.2 What you must do

  • Assign oversight to named people with the competence, training, and authority to exercise it, including the authority to overrule or discard AI output.
  • Ensure reviewers understand the capabilities and limitations in Section 4.
  • Guard against automation bias (Article 14(4)(b) explicitly requires awareness of it): an approval is a real decision. Reviewers must be able to explain why they approved an action, not merely that they did. Do not set quotas, incentives, or workflows that pressure reviewers into rubber-stamping.
  • Ensure a human decision-maker remains responsible for every hire/reject decision. The platform will not make these decisions for you, and you must not present them to candidates as AI decisions.

7. Your obligations as deployer

Summary of Article 26 AI Act and related law as it applies to your use of the platform. The companion Deployer Checklist turns this into an actionable list.

ObligationSourceWhat it means for you
Use per instructionsArt. 26(1)Operate the platform within the intended purpose (Section 2) and these instructions
Human oversight by competent personsArt. 26(2)Section 6.2
Input data qualityArt. 26(4)Vacancy requirements, screening questions, and candidate data you feed in must be relevant and sufficiently representative for the vacancy
Monitor operation, suspend on riskArt. 26(5)Monitor agent runs and outcomes; if you suspect the system presents a risk, stop using the affected feature and inform us without undue delay
Keep logsArt. 26(6)Logs are kept in the platform for at least six months (Section 9); do not delete them early; export them if you need longer retention
Inform workers and representativesArt. 26(7)Before putting the system into use at the workplace, inform affected workers and their representatives (e.g. works council; in the Netherlands, note WOR Article 27 co-determination may apply)
Inform affected personsArt. 26(11), Art. 50Tell candidates that AI is used in decisions concerning them
Cooperate with authoritiesArt. 26(12)We support you with documentation and log access
Right-to-explanation requestsArt. 86 AI Act, Art. 22 GDPRAnswer candidate requests for an explanation of AI-assisted decisions; the platform generates the explanation content
GDPR controller dutiesGDPRYou are the controller for candidate data; Jaicob is your processor under the DPA. Update privacy notices, honour data subject rights, and assess whether a DPIA is required (for AI-assisted recruitment it typically is, Art. 35 GDPR)
Fundamental rights impact assessmentArt. 27 AI ActIf you are a public body or provide public services, perform a FRIA before first use

Sample candidate notice (adapt with your counsel):

As part of our recruitment process we use the Jaicob platform, which uses artificial intelligence to support our recruiters, for example to compare applications against the requirements of the vacancy and to conduct screening conversations. AI does not make hiring decisions about you: every decision that affects your application is reviewed and taken by a person. You will always be told when you are talking to an AI system, you can request a human alternative, and you can ask us for an explanation of how AI was used in a decision about you. See our privacy notice for your data protection rights, and https://jaicob.ai/legal/ai for how Jaicob's AI works.

8. Data governance, fairness, and bias monitoring

  • Sensitive attributes are withheld from AI evaluation. Gender, nationality, and date of birth are excluded from the information AI evaluation features receive, and agents are instructed not to infer protected characteristics.
  • No emotion inference exists anywhere in screening, scoring, or interviews (Article 5(1)(f) AI Act).
  • Vacancy-specific evaluation. Candidates are assessed against the requirements of the specific vacancy, not against generic profiles.
  • Anonymised decision records. The platform retains anonymised records of AI-assisted decisions (directly identifying data removed and not restorable) as a bias-monitoring and audit dataset. These records survive candidate data erasure precisely because they are anonymised.
  • Aggregate quality monitoring. Jaicob continuously measures scoring behaviour on an aggregate, PII-free basis and investigates anomalies.
  • Bias audit exports. Deployers subject to formal bias audit obligations (e.g. New York City Local Law 144) can obtain a structured export of the anonymised assessment dataset via GET /agentic/audit/scoring-export (available to authorised client administrators) for use by an independent auditor.

9. Logging and record keeping (Articles 12, 19, 26(6) AI Act)

  • The platform automatically records events over the lifetime of each AI feature use: agent runs with every step and tool action, AI-assisted assessments, approvals and refusals with actor and timestamp, and candidate-facing conversation transcripts.
  • Logs are retained for at least six months; longer retention applies where configured or required. Log retention interacts with data protection: where logs contain personal data they follow the retention and erasure rules in the DPA and privacy documentation, and longer-lived audit records are anonymised (Section 8).
  • Logs are available to you in-product (agent run views, activity/audit trails) and support correlation of an action to its actor and context.
  • Provide log extracts to competent authorities when lawfully requested; we will assist.

10. Data protection and data residency

  • Roles. You are the data controller for candidate data; Jaicob is your data processor under the data processing agreement (Article 28 GDPR). For client account data, Jaicob is the controller (see the Privacy Policy).
  • Hosting. Platform data is hosted on AWS in the European Union (Frankfurt).
  • AI model providers. The platform uses general-purpose AI models from established third-party providers as subprocessors, under data processing agreements, with contractual commitments that your data and candidate data are not used to train their models. The current subprocessor list is part of the DPA.
  • International transfers are safeguarded as described in the Privacy Policy (SCCs, adequacy, DPF where applicable).
  • Regional configuration. Your tenant's regulatory region (EU or US) drives region-specific behaviour such as data retention and expiry policies. AI disclosure and human-approval safeguards for negative decisions are not region-configurable.
  • Erasure. Candidate erasure requests trigger deletion across platform stores (including message logs and stored documents); anonymised bias-monitoring records are retained as described in Section 8.

11. Accuracy, robustness, and cybersecurity (Article 15 AI Act)

  • Outputs are constrained by structured prompting, curated data projections (the model sees vetted fields, not raw records), and output validation; candidate-facing messages are sanitised before sending.
  • Scoring behaviour is monitored in aggregate; regressions are investigated as incidents.
  • The platform runs on infrastructure certified to ISO 27001:2022, with encryption at rest and in transit, role-based access control, and tenant isolation by company. See the Privacy Policy for the full security description and breach procedure (notification without delay, at the latest within 72 hours).
  • Abuse protections include rate limiting, permission gating of every AI tool action, and server-side enforcement of approval rules (approval state cannot be bypassed by the model or by client-side calls).

12. Maintenance, updates, and substantial modifications

  • The platform is continuously maintained; improvements and fixes are deployed on a rolling basis and recorded in the product changelog.
  • We may update or replace underlying AI models. Before doing so, we evaluate the change against our quality measurements; safeguards described in this document (disclosure, approval floor, logging, excluded attributes) are invariant across model changes.
  • Changes that materially alter the system's intended purpose, capabilities, or safeguards ("substantial modifications" in AI Act terms) are announced to clients in advance, and this document is updated accordingly. The version number at the top identifies the current revision.
  • There is no fixed end-of-life date for the system; if a feature is ever retired, clients will be notified with a migration and data-export path.

13. Incidents

  • Your duty: if you identify a serious incident, or suspect that use of the platform presents a risk to health, safety, or fundamental rights (for example, a suspected discriminatory pattern in outputs, an undisclosed AI conversation, or an action taken without required approval), suspend the affected use and inform us without undue delay at [email protected] with "AI incident" in the subject line (Article 26(5) AI Act).
  • Our duty: Jaicob operates post-market monitoring and reports serious incidents to the competent market surveillance authority within the deadlines of Article 73 AI Act. We will inform affected clients and cooperate on corrective actions.

14. Other jurisdictions

The safeguards above (AI disclosure, human involvement in decisions, logging, bias monitoring) apply platform-wide, not only in the EU. Depending on where you hire, additional local rules can apply to you as the employer/deployer, for example:

  • New York City Local Law 144 (bias audits and notices for automated employment decision tools): supported via the bias audit export (Section 8).
  • Colorado AI Act (duties for deployers of high-risk AI in consequential decisions, including employment).
  • Illinois rules on AI in hiring and video interview analysis.
  • California bot-disclosure rules (the platform's always-on AI disclosure is consistent with these).

These rules evolve; verify current obligations for your hiring locations with your counsel. We add supporting capabilities where regulation requires deployer-side evidence.

15. Support and contact

Read next: EU AI Act: Deployer Checklist.


Did this page help you?