Building with Confidence: AI Risk and Regulation in Recruiting
Ashby Senior Legal Counsel Kelly Fish walks through how the EU AI Act's risk-based framework applies to recruiting tools, and Tourlane's Max Rauschen and hyperexponential's Lucy Szypula show how they turn that framework into vendor questions and day-to-day AI guardrails.
Speakers
Key Takeaways
- AI Act compliance turns on what a feature actually does, not on whether “AI” is on the label. A scheduling tool and a scoring tool face very different obligations under the Act’s risk-based structure, as Ashby’s legal team laid out at Ashby One London.
- A vendor’s compliant AI tool doesn’t make a deployer’s use of it compliant. Ashby’s legal team frames it as shared responsibility: the vendor documents and tests the feature, the talent team owns how it’s configured and deployed.
- Tiering AI risk by what it touches, individual work, team workflows, or business-critical systems, lets a team calibrate scrutiny instead of applying one blanket review, as hyperexponential has built into its process.
- Reframing a vendor switch around what’s genuinely new, rather than re-clearing every compliance question from scratch, sped Tourlane’s legal sign-off, since roughly 85% of its existing obligations carried over unchanged.
- A vendor’s AI maturity often shows up before the feature comparison even starts, in how confidently they can name a tool’s risk and how prepared they are to answer questions, as both panelists described when picking vendor partners this year.
Session Overview
Ashby’s Senior Legal Counsel Kelly Fish opens with a practical walk-through of how AI regulation actually applies to recruiting, then hands off to Lucy Szypula, Head of Talent at hyperexponential, and Max Rauschen, Head of TA at Tourlane, for a working look at how two talent teams put that framework into practice.
Fish’s opening frames EU and UK AI law as a shared responsibility: vendors carry obligations to build and document compliant AI features, but the talent team stays accountable for how a tool actually gets deployed, including whether it discriminates. She walks through the EU AI Act’s risk-based structure, its higher-risk treatment of recruitment use cases, and how the UK instead leans on existing frameworks like the Equality Act and data protection law rather than an AI-specific statute.
The panel then grounds that regulatory picture in day-to-day decisions. Rauschen describes building the legal case for Tourlane’s move to Ashby by isolating what was genuinely new rather than re-clearing ground his team had already covered with its previous vendor. Szypula walks through the three-tier scrutiny model hyperexponential built to let individual experimentation move fast while routing anything touching sensitive data or business-critical systems through a heavier review.
Both speakers return repeatedly to vendor evaluation: what a strong AI posture from a partner looks like, what due diligence conversations reveal about maturity, and how legal fluency has changed for their teams over the past six months. The session closes with a shared framework: map where you’re regulated, align on risk appetite, build a scrutiny framework, and choose vendor partners who can help carry that work forward.
Chapters
- (00:00) Kelly Fish opens: risk appetite and the regulatory roadmap
- (02:13) The EU AI Act’s risk-based framework for recruiting AI
- (07:23) How the UK’s approach differs: Equality Act and data protection law
- (10:13) The common thread across frameworks: meaningful human oversight
- (12:10) Tourlane and hyperexponential on how the AI Act delay affected their plans
- (17:24) Max Rauschen’s compliance case for switching ATS providers
- (22:25) Lucy Szypula’s three-tier framework for AI risk at hyperexponential
- (27:03) Build versus buy, vendor evaluation, and closing takeaways
Q&A
Q: What compliance risks come with using AI in candidate screening?
A: Under the EU AI Act’s shared responsibility model, a vendor’s compliant tool doesn’t make your use of it compliant, Ashby Senior Legal Counsel Kelly Fish explained at Ashby One London. If a screening tool is configured to filter out candidates born before a certain date, the deploying company owns that discrimination risk regardless of what the vendor built.
Kelly Fish, Senior Legal Counsel at Ashby: “If you configure a screening tool, for example, to filter out anyone born before a particular date, you can’t point to your vendor when someone says that’s discrimination and go, ‘Oh, but my AI did that.’” (05:09)
Q: What does good AI governance look like in talent acquisition?
A: At hyperexponential, Head of Talent Lucy Szypula routes every AI build through a short product-style brief before assigning any scrutiny level: what it’s for, what problem it solves, who the user is, and what data it touches. That brief, not a fixed compliance checklist, decides how much review a given AI project actually needs.
Lucy Szypula, Head of Talent at hyperexponential: “What is it for? What’s the problem we’re trying to solve here? Who is the user? What’s the flow? What data will this be touching?” (23:29)
Q: Which recruiting tasks should stay human when a team adopts AI?
A: Ashby Senior Legal Counsel Kelly Fish frames the standard simply: treat AI as a copilot, not an autopilot, especially in higher-risk hiring decisions like screening or scoring candidates. Human oversight, not a blanket ban on the tool, is what regulators and the panel’s own vendor-vetting questions actually test for.
Kelly Fish, Senior Legal Counsel at Ashby: “Across all these different frameworks, when you actually get into the detail, you'll notice the same principles coming up again and again. Fairness, transparency, candidate rights, and accountability, and underpinning all of them, meaningful human oversight. Using AI as your copilot, not your autopilot, particularly as you move into those higher-risk use cases.” (10:39)
Q: How should talent teams evaluate an AI vendor’s compliance readiness?
A: Preparation is the signal both panelists trust most, though it shows up differently for each. hyperexponential’s Lucy Szypula watches for vendors who volunteer where a tool’s risk sits before she has to ask; Tourlane’s Max Rauschen looks for a vendor’s team arriving with a clear starting question already in hand.
Lucy Szypula, Head of Talent at hyperexponential: “Also advising me, ‘You should actually not use AI for this,’ or, ‘This is actually a big risk, in this part of the product, but this is how we’ve mitigated it. You should know that too.’” (38:36)
Kelly Fish (00:00): Hi, everyone. I'm Kelly Fish, senior legal counsel here at Ashby. I'm dual qualified in England and Wales as well as California. I'm originally from Lancashire, as you can probably tell from the accent, but based in San Francisco, so I've had the pleasure of navigating regulation on both sides of the Atlantic.
Now, I've got just ten minutes to walk you through the regulatory environment, and then we'll bring up our panelists to show you how this plays out in practice. So let's dive in. All right, here's the roadmap. But like any good lawyer, I'm going to start with a disclaimer. Nothing I say today should be taken as legal advice.
And my goal today is not to turn you into mini AI lawyers. It's to give you enough fluency to understand what matters, to ask the right questions, and make conscious decisions about which tools are right for your hiring process and your organization because there isn't necessarily one right answer. So rather than trying to memorize all the regulation I'm going to take you through today, I want you to leave knowing what to look for and what to ask.
All right, so let's start with the challenge, and this has been spoken about a lot today, but there is no shortage of AI tools on the market right now. There's a strong appetite to adopt them, and teams are being asked to do more with less, and AI can genuinely deliver operational value to hiring teams.
But the regulatory environment is evolving fast, and that can make these decisions about whether, how, and which tools to adopt feel more complex than perhaps it needs to be. So let's start by simplifying one part of that decision, understanding your company's risk appetite. Now, some companies are ready to lean into AI, and others are preferring to lean out, and both approaches are entirely reasonable.
Your risk appetite is probably being influenced by things like what stage of growth you're at, where you're hiring, whether you're already in a regulated landscape, and whether how you use AI could become a reputational question for your organization. And that's really important because something being legally compliant doesn't necessarily mean it's right for every company.
So understand your risk appetite first, and then consider the legal requirements. So the legal requirements. I'm going to start with the EU AI Act because that's the most comprehensive framework we're going to walk through today and probably top of mind for many of you. So the EU AI Act applies across all twenty-seven member states and can apply to organizations headquartered outside the EU as well if you're hiring in Europe.
And at its core, it takes a risk-based approach, so the more consequential the AI use case, the greater the compliance obligations that attach to it. But the AI Act doesn't replace existing law. GDPR, employment, anti-discrimination law, they still all apply alongside the act. For example, GDPR already restricts certain significant decisions made solely through automated processing under Article twenty-two.
There will be a test on this. I'll come back to that later. But the act specifically identifies recruitment as an area where AI can be high risk. But there's an important nuance. Not every AI feature in your hiring workflow is automatically high risk just because you're using it in a recruitment context.
Narrow procedural or preparatory tasks may fall outside of that category under this exception you can see on screen. And that's my first practical takeaway. Feature-by-feature analysis really matters here. Look at what the AI is actually doing. An administrative scheduling tool is very different to a tool that scores candidates and doing very different things, even though they both have AI written on the label.
So those two tools are going to have very different compliance requirements. And my second takeaway is this, even if it is high risk, that doesn't necessarily mean it's off-limits. High-risk AI can still be used in a recruitment context subject to meeting some additional requirements that have now actually been pushed to December next year under the Omnibus Act.
But that doesn't mean then the entire AI Act has been postponed. Other provisions such as the transparency requirements that you see in this limited risk column, they're already applicable and in place. But it does give organizations and vendors a little bit more time to prepare for those high-risk compliance obligations. So who's responsible for all of these compliance obligations?
Well, at a high level, it's a shared responsibility model. Your vendors have significant obligations around designing, testing, and documenting the AI features that it's putting on the market and giving you the information and controls that you need to comply with your compliance obligations. But buying a compliance, a compliant tool does not automatically make your use of it compliant.
You're responsible for how you deploy it within your hiring process, what it does, that you're using it appropriately, putting the right human oversight around it, and not configuring it in a way that discriminates. So if you configure a screening tool, for example, to filter out anyone born before a particular date, you can't point to your vendor when someone says that's discrimination and go, "Oh, but my AI did that."
Your vendor has responsibilities for the tool. You have responsibilities for how you use it
And this is where I want to focus on something really practical. Now, you don't need to know every provider obligation under the act, but you do need to know enough to tell if your vendor does. And don't worry, the questions on screen, I think they're in some take-home literature in the newspaper you have, so they'll be in there as well.
But these are the kind of questions that you can use to test if your vendor has done the work for you. Their answers to these questions should give you confidence that they've actually done the work and give you and your legal and compliance teams what they need to assess the tool with you.
Okay, but there's one more piece of the puzzle in Europe. The EU AI Act gives you a common framework across those member states, but that isn't the end of the analysis. You need to look at where you're actually hiring because additional local employment laws, data protection, and possibly some more AI-specific laws may sit alongside the EU AI Act.
For example, in Germany, if you have a works council, that could affect the introduction of AI into the recruitment process and other workflow processes as well. And Italy has actually adopted its own AI law, which includes additional requirements relating to AI in the workplace. Now, I can't possibly take you through the local requirements for every twenty-seven member states, and you don't need to memorize all of them.
The practical takeaway is simple: know where you're hiring, know where you're using AI, and involve your legal and compliance teams where you think you need to go deeper.
Max Rauschen (07:16): And that brings us to the beautiful UK.
Kelly Fish (07:20): So following Brexit, the EU AI Act doesn't actually automatically apply here, although UK companies can still find themselves within its scope when operating and hiring in the EU.
But if we just zoom in on the UK for a moment, the architecture is quite different and built largely on existing law. There's currently no UK equivalent of the EU AI Act. Instead, the UK has largely taken a pro-innovation approach, applying existing laws and existing regulators according to how the AI is actually being used.
But pro-innovation does not mean unregulated, and in hiring specifically, two existing frameworks are particularly important. First, the Equality Act. Using AI doesn't change your obligation not to discriminate. If an AI screening tool disproportionately disadvantages candidates with a protected characteristic, you can face the same discrimination issues as with any other hiring practice.
And second, UK data protection law. Remember that GDPR rule around automated decisions that I mentioned earlier? Can anyone remember what article that was? Article 22. Well, that was, that was automatically inherited by UK GDPR, but the Data Use and Access Act reformed that existing framework, and that's an important distinction actually to make.
The DUAA is not UK AI law. It's a much broader reform of UK data protection law. But one thing it did change is that inherited Article 22 framework for automated decision-making, and interestingly, it actually moves the UK into somewhat more permissive direction. Significant decisions can now be made solely through automated processing in a wider range of circumstances, subject to some safeguards being in place, and those safeguards are including candidates, able to obtain information about the decisions that have been made about them, that those candidates have the right to challenge that decision and obtain human intervention.
So this is a really good example of two different approaches we're seeing. The EU has adopted an AI-specific regulatory layer, and the UK is adapting existing frameworks such as data protection law. Different architecture, but very familiar practical questions. Is the tool fair? Are candidates appropriately informed?
Who is accountable? And where does the human stay in control?
Okay, that was a bit of a whistle-stop tour. We've covered a lot of ground. Let me try and pull it all together for you. So across all these different frameworks, when you actually get into the detail, you'll notice the same principles coming up again and again. Fairness, transparency, candidate rights, and accountability, and underpinning all of them, meaningful human oversight.
Using AI as your co-pilot, not your autopilot, particularly as you move into those higher-risk use cases. And here's the other thing I really want you to take away from today. These protections aren't new. The right not to be discriminated against has existed for decades, and transparency, individual rights, and accountability have been fundamental rights of data protection law since GDPR came into force.
What's new is the technology, and yes, in some cases, the regulatory framework that's being built around that. But I actually think anchoring to that is really helpful because it makes it all feel a little less daunting. Now, I want to take you back to the beginning. You don't need to become an AI lawyer to navigate this and make good decisions about AI.
You need to understand what the tool is doing, what matters to your organization, and where you need to ask questions or bring in your legal and compliance team to go a bit deeper. The goal isn't to be afraid of AI or to adopt it simply because you think you should. It's to make informed and intentional decisions about what is right for you and your organization and your hiring workflows.
Max Rauschen (11:53): Okay, everyone still with me?
Kelly Fish (11:56): Let's do a little shimmy. Let's wake up a little bit and welcome to the stage two people who are going to help bring all this to life, Max and Lucy.
Max, Lucy, thank you for joining me. I've obviously just taken everyone through quite a bit of regulation, so for the next thirty minutes, I want to really ground that in what that looks like in practice and how you approach making these types of decisions. And there's not one right way to do that, so hopefully we can give this wonderful audience some practical takeaways for when they go to work tomorrow.
So quick open fire question first. Has the delay to the EU AI Act changed any of your conversations or approaches?
Lucy Szypula (12:39): So first of all, hi everyone. Really happy to be here, and I'm also so aware that we are the very final obstacle between all of you and the house party. So very aware of that. Back to your question.
So, no, it doesn't change a thing for us, the delay. At hyperexponential, we are very deliberately all in on AI. And that means that AI fluency across our teams is incredibly important for us. It's a non-negotiable for us. But we're also an enterprise technology scale-up operating in a highly regulated industry, so we're very much used to holding ambition and responsibility at the same time.
So we're building the muscle already.
Kelly Fish (13:27): Yeah. And Max, how about you?
Max Rauschen (13:29): Hi from me as well. Pleasure to be here. Thank you very much for staying with us for this amazing topic. I think no. So I think it's good that we know where we have to land on with a bit of time left, I guess. But at the same time, I think also my humble opinion is that, we are not building or we're not doing what we do, to comply with legal.
It's more that we build these amazing thing, things that we do, and we do it in the guardrails that we have. So for sure, no changes in what we want to do at the moment.
Kelly Fish (14:03): Yeah. So might have changed the timeline slightly, but not the direction for either of you, which I'm relieved to hear. And regulation is only one part of that equation as we just spoke about.
How you approach AI in practice also depends on the appetite for it within your organization and the people that you need to bring into that conversation as well. So let's talk about that a little bit. Max, you've described yourself as quite bullish on AI and what it can unlock for talent teams.
Is that the same mantra at Tourlane that's shared across your internal stakeholders?
Max Rauschen (14:35): Yeah, absolutely. So the whole business has a very, very big appetite. We are a B2C company, so efficiency is extremely important because our margins are comparably low, so we have to be as efficient as possible.
I think legal is playing with us on a stakeholder level, with a light green check. They're definitely not a blocker for us, moving things ahead. I think, one example that actually shows very well how bottom-up the organization is in terms of AI bullishness is that we have an AI ambassador program where people from all levels can actually bring in projects, efficiencies that they see, things that they want to drive forward.
And, through that program they get support, not only on the technical side, but also on the legal side to have the compliant part checked. And yeah, so there's a lot of bottom-up curiosity. The whole business is very, very excited about the opportunities. Saying we're bullish doesn't mean we're not responsible about it.
Of course, it is very, very important to keep data secure. We have a lot of customer data, we have a lot of candidate data, of course, in our business. And, we still see the opportunity first and then, yeah, we handle the compliances as we go.
Kelly Fish (15:51): Okay. Sounds good. And Lucy, you've described Hyperexponential as all in on AI, but very intentional about how you do that.
So talk us through how, what that looks like in practice for you and your stakeholders.
Lucy Szypula (16:04): Yeah, absolutely. Like, I think for us that intentionality does not sit with just one function. We have a very strong instinct across the business, to always ask, ourselves the question, what does doing this really well look like?
And actually, one of our, like, company values is we do the right thing, and I think it's, like, a really useful way to think about AI adoption as well. Maybe, like, don't make it a separate isolated compliance exercise at the very end. But maybe link this already to how your company makes decisions, more broadly, because it's so incredibly, incredibly important.
And, I don't see my role as someone who needs to say yes or no, to AI. I see my role as someone who, helps build that better judgment, so everyone can have a good level of understanding to make those good decisions, themselves. We still want to move incredibly fast, but the better we understand this, I think this is becoming our responsibility and a part of everyone's job.
Kelly Fish (17:21): Yeah. So genuine appetite, it sounds like, at both organizations. But then how do you have those conversations to kind of help support that appetite? And let's kind of turn to that for a little bit and kind of paint the picture there. Max, let's bring that to life through a recent transition that you recently did, your transition to Ashby.
When you evaluated that move against the appetite that you've just described, how did you build the compliance case for that?
Max Rauschen (17:51): That's a very fair question. Changing ATS is something that seems to be very intimidating in the first place. I remember myself being very intimidated, actually chickened out a year before, so I was very well aware.
And I think legal or the whole legal sphere is one part of the hesitation, I would say. I think what I realized when I then decided to move on to build this case was we already have an ATS. So roughly 85% of all of the major legal questions actually have already been answered with the vendor that we had for three years before, right?
So, I think specifically GDPR is a big topic, but it was also a big topic before. So, there wasn't really a need for checking everything from scratch. So I think we had eighty-five percent already covered. And what I then did was basically focusing on, yeah, what is the data? What do I have to assess?
What is the difference from the new tool versus the old tool while I know that the compliance that needed to be there anyways. Yeah. And yeah, I think practical example is that we had, I think, about at that time, one hundred fifty thousand applications in, so, candidates in our, in our system, so of course, we needed to have the same level of security and data security around that.
And, what I then focused my discussion with our legal team preparing this transition was really what was new rather than everything, basically. Yeah. And, yeah. I took the overlap, said eighty-five percent is confirmed, and then, yeah, the questions were very specific to the new capabilities, and, that is how we steered it.
Kelly Fish (19:29): Okay. That makes sense. So don't open every risk and compliance box you possibly do. Focus on what's net new, do that gap analysis, and focus the scrutiny there. Okay. And then how do you balance where Tourlane is today versus where it might be and what's important to it in two years' time when you're assessing a vendor?
Max Rauschen (19:49): Yeah, absolutely. I think, overall, the regulations that protecting our data and our candidates are not going to change. What is definitely going to change very rapidly is the capability of the tool that I'm using. Yeah. 'Cause that progress is always faster than legislation can follow up on, right? So, what I feel is, as a talent acquisition lead, I have more responsibilities than just checking that.
Like, I think my primary focus is to enable the business to do the great things that they do, and, that is what I have to cater for primarily. Compliance, no question, needs to be aligned with the legal base that we have, in our country and the different countries that we are working in.
But, my take is more that I would rather take the vendor that has the strongest capabilities and that I can make a bet on in the future to build on and, I would then choose that and work in the guardrails of our legal necessities. I think one good example for that is we built recently an AI interview trainer for our team leads.
A bit of background, we have a lot of salespeople in our organization. We hire roughly a hundred every year on top, with a small team, and that obviously leads to the challenge of how do you deliver feedback of an individual base. And that was always something because of a lean team, a lot of responsibilities, a lot of the plate was falling through.
So we built an AI tool that actually created individual feedback after every conversation to really level up our interviewer quality, which was something that was, as I said, like a bit lacking in the past. And I think every organization has very individual challenges. So for me, it is primarily what's the capability of the provider?
What do I have to comply with? But I would never take legal as the goal to build what I build. I'm just focusing on staying in the legal base, and that's it.
Kelly Fish (21:49): That makes sense. Now, Lucy, let's turn to how that decision-making process or framework looks at Hyperexponential. And you've both spoken quite a bit about enablement and enabling your teams or your organization to kind of move quick and move forward.
So for someone trying to figure out how to say yes to AI with that intentionality and safely and to empower your teams and not necessarily be the manager to kill a good idea, what does that look like for you day to day? How do you help empower your teams in the way you've just described?
Lucy Szypula (22:22): I think for me, if every experiment, every AI build, starts with asking for permission, something's definitely not quite right there.
And, I've definitely found myself in a situation in the past when someone on the team had an absolutely brilliant idea, was very excited about this, build a prototype, and then I come in at the very end. I come into the conversation and I say, "Great. This is so great, but stop. We need to think about security."
And it's not fun to be that leader, absolutely not. I don't, I don't want that. So that made me definitely think a lot and reflect a lot about how we move that judgment much earlier into the process. And what we found really helpful is, it's not a new concept in people and talent, like thinking like a product person.
Every small improvement workflow build starts with preparing a little bit of a brief. What is it for? What's the problem we're trying to solve here? Who is the user? What's the flow? What data will this be touching? And once you start thinking like a product person and you start working through those questions, it really becomes much easier to work out how much scrutiny something will need from the get-go.
And broadly speaking, we think about it in, I would say, three tiers. So the first one really important for us is, individual productivity. If you want to do research for a project you're working on in Claude, or you want to do some talent market mapping, or things like that, absolutely please go for it.
It does not touch any sensitive data. Go for it. I don't want to know anything about that. I do, but not in a compliance sense. And then we've got that second tier, which is team workflows. Here things get a little bit more complicated because often with those workflows, you will have the workload touching some of that sensitive data.
It may or may not be the case. Good examples are like sourcing tools, analytics tools, pilots, also, all sorts of HR
Kelly Fish (25:02): Tech available
Lucy Szypula (25:03): To us right now. And here is where that product thinking really helps, where, is this touching any sensitive data and this type of questions. And based on that, we assess how much scrutiny we need.
And then finally, we've got, business-critical infrastructure. So those are all of those big, important, very serious systems like ATS, systems of records, our payroll systems. And we go all in on a due diligence that is incredibly important for us. And for me personally, this also links back to we are hiring that AI-forward, AI-native prototype of a person.
Not only in talent in people, but more broadly at HEX pretty much everywhere. And if you're hiring someone with that instinct of an AI builder, someone who will look at all the problems, all the challenges that we have in talent and how can I solve this with AI or how can I automate this? What can I build on top to make it better or faster?
And then you don't enable them on that judgment so they can build, experiment, both fast and safely. I think that's a failure mode. So definitely building that muscle is super important.
Kelly Fish (26:24): Yeah, and your framework helps do that.
Lucy Szypula (26:24): Yeah.
Kelly Fish (26:26): And just like magic, we've got your framework on screen actually, and it's, no coincidence that it looks quite similar to the frame that you all saw for the EU AI Act.
So different levels of risk, different levels of scrutiny. Yeah. So I imagine your briefs probably reflect that when you're doing a brief for the lower end versus the higher risk end. Mm-hmm. And I'm wondering if that framework actually helps with something that you mentioned build versus buy and that I think I've heard a lot of people talk about today, in the social areas.
Does your framework help with the build versus buy question?
Lucy Szypula (27:00): It definitely does. It does help. Like, I think it definitely doesn't, like, magically answer the question of build versus buy, but, like, it shows you, like, how much risk you're taking on if something- Yeah ... Something goes wrong. So that's, that's already really important.
And I think for us, given the stage we're in, the default is to buy really strong foundations. So, like ATS, a vendor who, like, obsesses over security, reliability, compliance, wink, wink, Ashby in our case. And then on top of that, we will default to build, if it gives us some unique particular leverage.
Something that will be specifically ours to own on top of a really strong foundation already.
Kelly Fish (27:49): Yep. And how about you, Max? That build versus buy question, how does that play out for you?
Max Rauschen (27:55): I would totally agree. Like, what we do is, like, what I focus on is, like, buying the compliant foundation and then build aggressively on it, I would say.
Yeah. Like, what I said earlier about the individual challenges that organizations have, we obviously all have shared ... challenges as TA leaders or TA people, but I think then every business has specifics. And then to cater that, you need to have the ability to build on top and, find solutions for your individual problem.
And I would totally second what you just said. Like, I want people in my team who have the appetite, and I don't want to be a blocker. But we also had a lot of discussions where the question was more around does what you do here really move the needle or not? And I think if it doesn't move the needle, it's more hobby.
It's not really a project, and therefore I think that's our measurement in general. And, then also if it moves the needle, it is a clear indicator that it's going to be a good investment to check with legal to make it compliant, to really put in the second layer of work aside from working on the actual problem so that you can be sure that, all your solutions in the end actually, yeah, make a difference in your team, make your life lighter and your work just more efficient.
And so yeah, I would say buy thoroughly and then build aggressively is probably the approach.
Kelly Fish (29:17): That makes sense. And whether it's build versus buy or whatever framework you're using, those decisions aren't being made in isolation. You've both spoken about lots of internal stakeholders that you're having these conversations with, so let's turn to that for a moment, and the conversations and the stakeholders and the level of fluency that you're having to bring to your roles now.
In fact, let's double-click on that. How much legal and regulatory fluency are you having to bring to these conversations compared to, say, maybe even just six months ago?
Max Rauschen (29:51): Yeah. So, when I'm saying we're building stuff on top of the foundation, that obviously means that with every integration, every other tool that we build, there's a new layer of agreements that we need to check.
So I would say in general, my personal legal fluency has definitely increased over the last six months. I think it is also super important to make sure that you are able to speak that language. One big example, I don't know if you're affected by it, but we have a workers council in France, for example.
That means we have to comply and we have to inform, and you're basically speaking primarily with their lawyers, which means that you have to be able to speak at, to a certain degree, the la- their language at the same time. And, I think overall it's an opportunity. It's not, it's definitely not a burden.
It's a skill that you develop and I think that has an effect on you, on the team as well, because of course they're also with more experience, they get more fluent in this language. And then, I think what also is very interesting to see, the more you get familiar with the legal base and the way that the conversations are going around it, the stronger your ability to anticipate those challenges in building tools and add-ons actually get.
So I think that's a very interesting take and the timeframe of six months is quite good because I think we learned a lot and I think this part of really having that legal perspective at least in mind while building is super helpful because then you don't have to change everything, in the end.
I think one good example also how we used legal is by getting Ashby through in our C-level with an executive briefing. Primarily, I'm not a lawyer, so I use Claude, of course, and, basically filled the gaps or identified the gaps that I needed to check with legal and also created, or proposed solutions already proactively to our legal team so that they didn't have to go too deep into it and that I got green lights
Lucy Szypula (31:54): Quite quickly.
Kelly Fish (31:54): Yeah. Using AI to pitch for AI. Why not? Why not? Lucie, does that resonate with you on the fluency piece?
Lucy Szypula (32:02): Yes, absolutely. A lot. I think our role has changed a lot, and I think the expectations are much, much higher now. I think, if you had asked me, like, three years ago, "Hey, Lucy, what do you have strong opinions on?"
I think AI governance and model permissions would not make the list. And here I am right now, and it's been delightful. So definitely. And, the way I think about it is it's also not about all of us becoming mini lawyers and security experts. I think it's all about understanding just enough, to be able to know where to dig a little bit deeper, where to ask more questions, where to demand more, and present credibly in the right forums.
And especially, the theme is very much that we're not offloading the decision-making, we are partnering in the decision-making. And I have found myself in situations where a good example would be permissions. Someone technical built a beautiful automation for skills assessments, and they're asking for an API key.
And actually, I am the only person in the room that understands that by giving them this tool, for example, they might be able to see their peers' interview feedback, right? And I think we as talent professionals bring that really interesting angle into that conversation, where sometimes we may be even in a situation where the info sec team say to us, "You can do it," and your head of legal will say, "You're allowed to do it."
And I think it does not always mean that you should do it. It'll often mean you can and you should, but not always. And I think we owe this. We owe this to our candidates, and I think we owe this to our talent, more broadly. And yeah, I couldn't agree more. Also, AI can really help you build that level of fluency to be a credible partner in that, in those conversations.
I've definitely used this to pressure test my thinking, go deeper on a info security topic many, many, many times.
Kelly Fish (34:28): And viewing it as an opportunity, I quite like what you said there, Max. Like, it's an opportunity to learn something new. You don't have to become an AI lawyer. Just treat it like any other educational topic you would in the workplace, to collectively evaluate that with your stakeholders and ask the right questions.
And your vendors should be able to help with that too. Well, any good vendor should be able to. So let me look at your take on your conversations with your vendors, how you include those, what you want to see them bring to the table when you're assessing a tool that you can then take back and help with your internal processes.
Lucy Szypula (35:07): Definitely. So, I think we're in a very buzzworthy vendor era. A couple of things that come to my mind immediately is, I always look at the overall AI posture, even before actually getting really detailed on the features. I think it can tell you a lot, whether the vendor you're potentially partnering with has done, has done the thinking and can talk confidently to it.
And in reality, what you're typically testing for is the level of maturity. Not looking for a perfect answer, but definitely looking for an answer and very, very fast because it also shows you that this is something that the vendor is absolutely prepared to talk about. And also whether they're going to be a great partner and help me make my internal case, and help me talk to my legal team, to my information security team.
That's also really important, for us.
Kelly Fish (36:18): Yeah.
Max Rauschen (36:18): Yeah. And, I think in general, we're way past the point where we choose a vendor based on AI or no AI, right? So there's no case where this doesn't come up in a way, right? And, I totally agree with you. I think, preparation and also, yeah, having someone on the other side, just very clearly differentiating the risk, giving me a clear indication, of what I need to solve, what I need to understand, what the primary focus has to be to be compliant, of course.
I'm generally a very impatient person, so these legal topics are not really my cup of tea in general. But I think, I really appreciate if someone is really drilling it down. That doesn't mean that I'm not going to do the work because that is definitely too important to ignore it. But at the same time, it is definitely helping a lot if you have someone on your side who is prepared, who knows what kind of challenges I will have to anticipate pushing it through internally but also complying to the rules in general.
Kelly Fish (37:19): Yeah, that makes sense. And you should leverage your vendors to help with those conversations certainly. And I see that, on the side of the fence that I'm on. We have some customers that just need to know the bare minimum, what are your classifications that sits with their risk appetite, and they're fine to move on.
Others will go through a big due diligence process and, that is right for those particular organizations. We're coming up to time, so let's end with something just really quick-fire and tangible. One green flag from your vendors that they could do or say or bring to the table as a very practical way to earn your trust as you're going through these assessments.
Lucy Szypula (38:03): I think, for me it's definitely, overall partnership vibes. Are we just trying to get through the procurement or are we, are we thinking about the whole process of, mutual discovery as an opportunity to build a long-term partnership? And I really appreciate being very upfront, honest, on it, and coming to me with the full truth.
Meaning also advising me where like, "Oh, you should actually not use this for this," or, "This is actually a big risk, in this part of the product, but this is how we've mitigated it. You should know that too." And I think, you can get a lot of trust signals, when someone is approaching it in that way.
Kelly Fish (38:54): Yeah. Full transparency.
Max Rauschen (38:58): Absolutely. Yeah, green flags. Shout-out to Constantine and Rick, who have been accompanying me on this journey, basically. I think that was the moment when we started talking about the legal perspective, I think the immediate question was, "What do you need?"
And I think that was very, very good as a starting point because that actually really helped me to work on it. It was a signal that they are prepared, that there was everything already available and it was more for me to then, together with them, define the topics that we needed to work on.
And the support was amazing and at the same time also very detailed. I might be happy with a summary. Our legal team might need to have the legislation behind it, so of course there's different layers and different things that you need to address. And, yeah, both levels were definitely fully catered.
So I think that is similar to what you said, what I would answer to that question.
Kelly Fish (39:53): It's a partnership. Thank you both so much. And I think what you've shown really nicely today is that there is not one right answer or operating model for navigating AI. Max, yours is very pragmatic. Lead with the value and focus your scrutiny on what's genuinely new. Lucy, yours is a more structured approach, and having that framework up there in place so that your team can know when they can move fast and when they might need to put more of a brief or some scrutiny in place.
Different models, but the discipline is actually quite similar. Be intentional about where and how you're using AI and adopt the right level of scrutiny to the level of risk. And to sum up on-screen, I thought this, these four stages might just help wrap everything up for the audience. So know your regulatory landscape. Align on your risk appetite.
Build your framework, whether that's something that's aligned with Lucy or Max's, and then choose the right partners and use them as a resource and leverage their knowledge. So hopefully we've given you some practical ways to do just that. Max, Lucy, thank you so much.
Recommended Sessions
Ashby Product Keynote
Ashby co-founders Benji Encz and Abhik Pramanik unveil the next generation of AI for recruiting at Ashby One 2026 in London. Highlights include Scheduled Agents, Career Page Builder, WhatsApp messaging, AI-assisted application review and report building, and more.
View session
Mapping Talent Intelligence
Don Fogarty, Head of Talent at Attio, shows how his team turns recruiting conversations into structured signals an AI agent can act on, from spotting outreach timing to triaging inbound applicants.
View session