Guide · For recruiters

AI screening, bias and blind CVs

Taking the name off a CV before a model — or a person — scores it removes the loudest cues for gender, ethnicity and age. It does not remove the quiet ones. Here is what the evidence shows, where the law is heading, and a blind-CV protocol a small team can actually run.

Short answer

Stripping names, photos, addresses, dates of birth and graduation years before screening reduces bias. It does not remove it. Those fields carry the strongest signals for gender, ethnicity, age, religion and postcode, and both human screeners and language models have been shown to react to them. Take them out and there is less to react to.

What stays — gaps, school names, hobbies, the languages listed, the way the CV is written — still leaks. So a blind CV is a first-screen discipline, not a guarantee: strip the identifiers for screen one, score against written criteria, reveal the identity only once a shortlist exists, and log who decided what and why.

What the evidence actually shows

The third study is the one that matters for ChatGPT or Claude. A model learns from text written by people, shortcuts included. Ask it to “pick the strongest candidate” with no criteria and it reaches for the same shortcuts a tired human does — faster, with a confident justification attached. Stripping the cue it keys on most is the cheapest intervention available, and only the first one.

What a blind CV removes — and what it leaves behind

Think by signal rather than by field: each protected characteristic has a loud carrier, easy to strip, and quiet ones you cannot strip without damaging the CV.

Signal Loud carriers — strip at screen 1 Still leaks after stripping
Gender Name, photo, title (Mr/Ms), pronouns, maternity or paternity leave Single-sex school, hobbies, gendered job titles, a caring gap
Ethnicity, religion, nationality Name, photo, place of birth, nationality line, ID number Languages, faith or community schools, volunteering, first-job country, the military-service line
Age Date of birth, graduation years, “25 years' experience” Length of the career, obsolete technologies, dates on early roles, phrasing
Where they live, social class Address, postcode, phone area code School and university names, first employer's town, unpaid internships
Health, disability, family Explicit statements, driving-licence line, “reason for leaving” Unexplained gaps, part-time patterns, carer or patient-group volunteering

The right-hand column is why “blind” reduces rather than eliminates: nobody deletes a candidate's languages or schools and still calls it screening. In Israel the military-service line — unit, rank, “national service”, “exempt” — signals gender, religion or community as clearly to a model as to you; decide before screen one whether it stays.

Where the law is heading

Three rules frame AI-assisted screening. This guide describes the rules; it is not legal advice.

A blind-CV protocol a small team can run

Nothing here needs a platform: Word, a spreadsheet, a chat window and about ten minutes of discipline per CV.

  1. Write the criteria before you open a single CV

    Three to six must-haves and two or three nice-to-haves, each phrased as something a CV can show evidence of (“has run a team of 5+ for 12 months”, not “strong leader”), each weighted. Save it as criteria-v1.txt; the prompt and the log refer back to it.

  2. Make a working copy and strip the screen-1 fields

    Never edit the original. If the CV is a PDF, open it in Word (File → Open) or ask for a .docx. Then: name → [PERSON_1], phone → [PHONE_1], email → [EMAIL_1], address → [ADDRESS_1], LinkedIn and portfolio links → [URL_1], with Find & Replace → Replace All so the same value gets the same placeholder throughout. Delete outright: photo, date of birth, ID number, nationality and marital-status lines, every graduation year. To hide age properly, turn employment dates into durations (“3 yrs 2 mo”).

    Then the places people forget: header and footer, the file name (Dana_Cohen_CV.docx), and File → Info → Inspect Document → Document Properties and Personal Information → Remove All. Save as candidate-a.docx.

  3. Decide now what screen 2 reveals

    Usually name and contact details, and location only if the role depends on it. The photo is never needed. Write the list next to the criteria so nobody “just has a quick look” at the original mid-screen.

  4. Write the prompt so the model scores against criteria, not vibes

    A skeleton that works in any chat tool: “You are screening an anonymised CV for the role of X. Score it against each criterion below from 0 to 3 (0 = no evidence, 1 = weak, 2 = meets, 3 = exceeds). For every score quote the line or lines from the CV that justify it; if the CV is silent, write ‘not stated’ and score 0. Do not infer or mention age, gender, ethnicity, religion, nationality, health, family status or location. Do not compare with other candidates. Output a table: criterion, score, evidence.” Paste the criteria from step 1 underneath, save it as prompt-v1.txt, and change it only between hiring rounds.

  5. One CV per chat, same prompt, same model

    A fresh chat per CV — in ChatGPT a Temporary Chat, in Claude an Incognito chat — so earlier candidates can't colour later ones. Don't paste five CVs and ask for a ranking: models show position effects, and whoever is listed first or last can move for no good reason. If you must batch, randomise the order and run it twice, reversed. For the data-protection settings, see Is it safe to put a CV into ChatGPT?

  6. Read the evidence, not the score

    Open the CV next to the model's table and check each quoted line says what the score claims. Override where it doesn't, with one sentence why. A model will happily score 3 on “managed a budget” because the word “budget” appears.

  7. Reveal at screen 2 — and notice what changes

    Only for candidates who passed screen 1, open the key ([PERSON_1] = the real person, kept in your ATS, never in the chat). If anyone's position moves after the reveal, write a reason — the most informative line in the log.

  8. Log it, then clean up

    One spreadsheet row per candidate: code, date, prompt-v1, model and plan, score per criterion, evidence checked (Y/N), decision, reason for any override, reviewer initials. If you lawfully hold equal-opportunities monitoring data, compare shortlist rates by group across rounds. Then delete the chats and, in ChatGPT, the files from your Library.

What the manual protocol costs

Per CV
8–12 minstripping, dates to durations, one chat, evidence check, log row
At 20 CVs a day
≈ 3 hoursroughly a third of it stripping
What leaks
The quiet carriersschools, gaps, hobbies, languages — plus the footer you missed

Our estimates; your numbers will differ. The shape won't: stripping is the repetitive part; the judgement in steps 1, 6 and 7 can't be automated away.

What this doesn't solve

  • The quiet carriers. School and university names, gaps, hobbies, languages, the military-service line and the writing itself stay in the CV; Sunda does not remove them, no redaction tool sensibly can, and a model can still read them. Steps 1, 4, 6 and 7 are where fairness is decided.
  • Auditing the model. Nothing here tells you whether the model scored fairly; only your log, your evidence checks and lawful outcome comparisons by group can.
  • Photos, graduation years, PDFs. Sunda does not remove photos or anything inside images; a bare year such as “2018” is not a date to the rules, so delete graduation years yourself; a bare linkedin.com/in/dana-cohen (no https:// or www.) is not caught as a URL; and a PDF only works if its text is selectable and in Latin script — a scan, a photo or a Hebrew CV is refused with a message rather than half-redacted, so convert it or ask for the .docx. A PDF that does go through is rebuilt from its text: the words and page breaks survive, the layout, fonts and images do not.
  • Perfect detection. Emails, phone numbers, numeric dates, card numbers, IBANs and checksum-valid Israeli ID numbers are caught reliably by rules. Names, addresses and written-out dates depend on the optional on-device model and will miss some. Read the redacted CV before it goes anywhere.
  • Your legal footing. Placeholders reduce what you disclose and what a model can key on. They do not make a decision “not solely automated”, discharge any AI Act obligation, or write your candidate privacy notice. No tool makes you compliant with anything.

Questions recruiters ask

Does removing the name from a CV make AI screening unbiased?

No. It removes the strongest single cue — a name carries gender and, very often, ethnicity and religion — and with photo, address, date of birth and graduation year gone the model has much less to key on. But school names, gaps, hobbies, languages, a military-service line and the writing style remain, and a model reads those as well as a human does. Blind CVs reduce bias; written criteria, an evidence-per-score prompt and a decision log are what keep it down.

Is it legal to use ChatGPT or Claude for blind recruitment screening?

Not prohibited in itself, but two rules frame it. GDPR Article 22 gives people the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects, and the regulators' guidelines name automated e-recruiting with no human involvement as an example — so a person must genuinely make the decision and be able to explain it. The EU AI Act lists recruitment AI among its high-risk categories; how that applies to a recruiter using a general-purpose chatbot is still being worked out. This guide describes the rules; it is not legal advice.

What should be revealed at the second screen, and when?

Only after the screen-1 scores are recorded, and only for candidates who passed: name and contact details, and location if the role genuinely depends on it. A photo is never needed to screen. If the reveal changes anyone's position on the shortlist, write down why — that note is the point of running the screens separately.

Can a model still infer ethnicity, religion or health from a blind CV?

Yes. A language list, a religious or single-sex school, faith-based volunteering, a national-service or exemption line, a gap explained by illness or caring — each is enough for a model, or a person, to guess. Under GDPR Article 9 data revealing racial or ethnic origin, religious beliefs or health is a special category, and Israel's amended Protection of Privacy Law treats similar categories as data of special sensitivity, so telling the model not to infer them is a minimum, not a fix. Strip what you can; for the rest, the criteria and the log are your defence.