<!-- Bizible Script --> <script type="text/javascript" class="optanon-category-C0004" src="//cdn.bizible.com/scripts/bizible.js" ></script> <!-- End Bizible Script -->
Recruitment

Why recruitment agencies in Australia and New Zealand should be talking about AI security

AI is no longer a future consideration for recruitment agencies. It's in your CRM, outreach tools, and your payroll systems. The question most agency leaders are now asking isn't whether to use AI, but whether they can trust it with their sensitive data.  

This article focuses on the move from AI that produces outputs to AI that takes action. Here's what that means for your agency, candidates and clients.  

AI & Automation
Emily Ralph

by Emily Ralph

Content Specialist

Posted 18/09/2026

From AI assistant to AI agent and why the distinction matters

Not all AI tools carry the same risk profile. There's an important difference between AI that helps and AI that acts.

Conversational AI is the kind most recruiters are already familiar with. Drafts job ads, summarises candidate profiles, and answers questions. A human reviews the output and decides what to do next. 

Agentic AI goes further. It executes multi-step workflows, connects to external systems, modifies records, and acts on behalf of users, without waiting for approval. That's what makes it genuinely useful for recruitment. It can handle the sequences of repetitive tasks that eat up a recruiter's week. But it's also what raises the security stakes. 

When an AI agent can action tasks, the relevant questions become what can it do, on whose authority, and with what oversight? 

According to a knowbe4 article, 50% of surveyed ANZ organisations said their AI use was unapproved or ungoverned. IBM’s Cost of a Data Breach 2026 Report found that most breached companies this year lacked AI governance to manage AI or detect shadow AI (68% vs 63% last year).  

The agentic AI security risks that matter most for ANZ recruitment agencies 

Before choosing your new agentic AI platform, recruitment leaders should investigate the six risk categories listed below.  

1. Prompt injection 

Candidate documents, such as CVs and cover letters, can contain hidden instructions designed to manipulate AI outputs. If your AI screening tool reads a CV with embedded text instructing it to rank a candidate highly, and there's no detection layer in place, that instruction may be followed without your knowledge. 

2. Agent over-reach 

Agents that can take actions need clearly defined permission controls. An agent configured to update a candidate record, with no guardrails on scope, can be manipulated into accessing records it shouldn't, or triggering workflows without proper authorisation. 

3. Non-human identity sprawl 

AI agents and service accounts don't appear on your org chart, but they do have access to your systems. The more tools you add, the more of these non-human identities accumulate, often without the same access controls, monitoring, or offboarding processes applied to your human team. That gap is exactly what attackers look for. 

4. Supply-chain risk 

An AI platform's security is only as strong as the third-party tools and APIs it depends on. If your vendor has integrated an unvetted external service or open-source library, your agency may have inherited a risk it never assessed, without knowing it. 

5. Data accumulation and retention 

AI systems that retain data indefinitely, or accumulate context across sessions without limits, create a growing pool of sensitive candidate information. The longer data is held, the larger the exposure if something goes wrong, and the harder it becomes to meet your obligations under Australian and New Zealand privacy law. 

6. Ungoverned AI deployment 

AI tools deployed without audit trails, oversight mechanisms, or governance frameworks create a blind spot. If a regulator or client asks what your AI did and when, you need to be able to answer.

Why this matters under Australian and New Zealand privacy law 

Candidate data in recruitment is sensitive. It includes names, contact details, employment history, and in some cases special category information such as health records or criminal history. 

In Australia, recruitment agencies handling personal information are subject to the Privacy Act 1988 and the Australian Privacy Principles (APPs). The APPs require agencies to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. If your AI platform processes candidate data in ways you can't audit or explain, that's a compliance gap, not just a security concern. 

In New Zealand, the Privacy Act 2020 applies, with similar obligations around the collection, use, storage, and disclosure of personal information. The Act also includes mandatory breach notification requirements. If a privacy breach causes serious harm, you must notify the Privacy Commissioner and affected individuals. 

Both frameworks require you to be able to demonstrate what happened to personal data, and why. An AI platform with no audit trail makes that very difficult. 

How Access Evo addresses these risks 

Access Evo applies multiple layers of security controls to mitigate AI agent risks, covering authorisation, data protection, monitoring, and governance.  

Risk  Access Evo 
Prompt injection  Detection and blocking at the AI gateway layer; system prompts architecturally separated from user input; only defined output contracts accepted from model responses 
Agent over-reach  All data-changing actions require explicit user-delegated authorization. Customers control agent availability and user access, and agents cannot act without approval. 
Non-human identity sprawl  All user access is authenticated via Access Identity and enforced at every API call. Internal team access to customer data follows a just-in-time model, is time-bound, and automatically expires when no longer required. 
Supply-chain compromise  All third-party and MCP integrations are governed through a managed, reviewed connector catalogue, with built-in validation and sanitization safeguards. 
Memory poisoning AI interaction traces are retained for up to 90 days. Conversation and execution log retention varies by product, from 30 days to user deletion. Data is permanently deleted on expiry, and customer data is never used for model training.  
Ungoverned deployment  Guardrail decisions are fully logged and auditable. Policies are approved by Access's Information Security Board, and the Business Continuity Plan is ISO 27001:2022 compliant and reviewed each year. 

All guardrail decisions are logged and auditable, with detailed records of AI interactions and processing decisions available to support GDPR right-to-explanation requirements and ICO scrutiny. 

How is candidate data protected in AI recruitment software?  

Recruitment processes involve the collection and handling of personal information, some of which may be sensitive in nature. This can include candidate identification and contact details, employment history, health information, and criminal record information. 

Access Evo applies a range of controls to ensure candidate information is protected throughout its lifecycle, including: 

  • Data segregation: Customer information is logically partitioned by organisation across the platform, AI gateway, and observability services. This segregation ensures that data is isolated and accessible only within the relevant customer environment. 
  • Encryption: All data is encrypted at rest using AES-256 (FIPS 140-2 compliant) and in transit via TLS. 
  • Perimeter security: Cloudflare Web Application Firewall (WAF) acts as a perimeter security control, inspecting and filtering inbound traffic before it reaches the platform. 
  • Data subject rights: Internal tooling enables the fulfilment of Subject Access Requests (SARs). Data portability is supported through CSV exports, and customer administrators can erase personal data in line with organisational retention and privacy requirements. 
  • No automated decisions: By default, the Evo AI Platform does not make automated decisions that produce legal or similarly significant effects for individuals. AI-generated outputs are provided as recommendations, with end users retaining full discretion to accept, modify, or disregard them. 

 

Agentic AI supports human judgement rather than replacing it, ensuring that people remain in control of all significant hiring decisions.  

How to assess the security of an AI recruitment platform? 

Strong security practices are no longer just an IT concern; they can directly influence revenue. In LogRhythm's The State of the Security Team report, 62% of Australian respondents said their organisation had lost a business deal because potential customers were not confident in its security practices.  

Ask these questions early to verify that the vendor has appropriate security controls in place. Their responses should give you confidence in how they protect data, manage risk, and support compliance. 

"How do you prevent prompt injection from candidate documents?"

If a vendor cannot describe how it detects, monitors, and responds to threats, there may be gaps.  

"What authorisation is required before an AI agent takes a data-modifying action?"

The correct answer is explicit user authorisation, required every time before an action is performed. 

"What is your data retention policy for AI interactions, and is customer data used for model training?"

Short retention periods and a firm no-training policy should be considered baseline requirements. 

"Who reviews and approves your AI guardrail policies?"

If they can't name the governance body, question whether meaningful governance exists. 

"How does your platform support compliance with the Australian Privacy Principles and the New Zealand Privacy Act 2020?"

Any vendor operating in ANZ should be able to answer this directly. If they can't, that's a red flag you should not ignore.  

 

Vendors with ISO 27001:2022 certification, published security documentation, and a clearly defined Information Security Board should be able to answer these questions with confidence. Take a closer look at any provider that cannot. 

Want to assess Access Evo's security credentials for yourself? 

To learn how Access Evo protects candidate information, supports privacy compliance, and enables responsible AI adoption, speak with our team today. We'll explain our security architecture, governance framework, and the safeguards built into the platform.  

Emily Ralph

By Emily Ralph

Content Specialist

Emily Ralph is a Content Specialist at Access Recruitment, producing content that explores recruitment marketing, AI adoption, and agency operations to help recruitment agencies navigate change and get more value from their technology.