What is agentic AI, and why does it change security risks in recruitment?
There are two types of AI tools in recruitment right now. Each carries very different risk profiles.
Conversational AI drafts emails, summarises CVs, and answers queries. It produces outputs. A human decides what to do with them.
Agentic AI executes multi-step workflows, connects to external systems, modifies data, and acts on behalf of users. It does not wait for a human to approve each step, which makes it valuable for recruitment. But automating the repetitive sequences that eat up a recruiter's week, is also what raises the security stakes.
When an AI agent can take actions, the questions worth asking are: what can it do, on whose authority, and with what oversight?
According to a 2026 Dark Reading poll, 48% of security professionals now rank agentic AI as the number one attack vector for the year. IBM's 2025 Cost of a Data Breach Report found that breaches involving unmanaged AI cost an average of $4.63 million, $670,000 more than a standard breach.
What are the six agentic AI security risks that matter most in recruitment?
Before evaluating any agentic AI platform, it helps to know what you are actually evaluating against. These are the six risk categories most relevant to recruitment businesses.
1. Prompt injection
Hidden instructions embedded in candidate documents such as CVs, cover letters, portfolios, are designed to manipulate AI outputs. If your AI screening tool reads a CV containing hidden text instructing it to rank the candidate highly, and the tool has no detection layer, that instruction may be followed.
2. Tool misuse and agent over-reach
Agents that can take actions need permission controls. An agent configured to update a candidate record, with no guardrails on scope, can be manipulated into taking actions well beyond what was intended, e.g., accessing records it should not, or triggering workflows without authorisation.
3. Non-human identity sprawl
Every AI agent or service account that can access your systems is a potential attack surface. As agencies add more AI tools, the number of non-human identities with system access grows. Each one is a potential entry point if not managed with the same rigour as human user accounts.
4. Supply-chain compromise
An AI platform's security is only as strong as the third-party tools and APIs it depends on. If an agency vets its AI vendor but that vendor has quietly integrated an unvetted open-source library or external service, the agency has inherited a risk it never assessed. The vulnerability does not need to be in the vendor's own code to become the vendor's problem.
5. Memory poisoning and unbounded data accumulation
AI systems that retain data indefinitely, or accumulate context across sessions without limits, create a growing pool of sensitive candidate information. The longer data is held, the larger the exposure if something goes wrong.
6. Ungoverned AI deployment
AI tools deployed without audit trails, oversight mechanisms, or governance frameworks create a blind spot. Demonstrating compliance, responding to incidents, and answering a regulator's questions all depend on being able to see what your AI is doing and when.
How does Access Evo address agentic AI security risks?
Access Evo uses layered security controls to manage the risks associated with AI agents, including authorisation, data protection, monitoring and governance.
| Risk | Access Evo |
| Prompt injection | Prompt injection detection and blocking at the AI gateway layer; system prompts architecturally separated from user input; only defined output contracts accepted from model responses. |
| Tool misuse / agent over-reach | User-delegated authorisation required before any data-modifying action; agents cannot act without explicit authorisation; customers control which agents are enabled and which users have access. |
| Non-human identity sprawl | User access is routed through Access Identity, with authentication enforced on every API call; internal team access to customer data is just-in-time, time-bound, and auto-expires. |
| Supply-chain compromise | Third-party and MCP integrations run through a managed, reviewed connector catalogue with validation and sanitisation guardrails. |
| Memory poisoning / data accumulation | AI interaction traces held for up to 90 days; conversation and execution log retention is set per product, from 30 days up to deletion by the user; data hard deleted on expiry; no customer data used for model training by any provider. |
| Ungoverned deployment | Every guardrail decision logged and auditable; guardrail policies approved by Access's Information Security Board; Business Continuity Plan compliant with ISO 27001:2022, reviewed annually. |
All guardrail decisions are logged. Detailed audit logs of AI interactions and processing decisions are available to support customers' right to explanation processes - relevant for any agency subject to GDPR or ICO scrutiny.
How does AI recruitment software protect candidate data?
Candidate data in recruitment is sensitive. It includes names, contact details, employment history, and in some cases special category data such as health information or criminal records.
Here is how Access Evo handles candidate data in practice:
- Data segregation: All customer data is logically segregated by organisation ID across the platform, AI gateway, and observability layers. Your data is not commingled with another customer's.
- Encryption: All data is encrypted at rest using AES-256 (FIPS 140-2 compliant) and in transit via TLS.
- Perimeter security: Cloudflare WAF (Web Application Firewall) provides perimeter-level intrusion detection, inspecting and filtering all inbound traffic before it reaches the platform.
- Data subject rights: Subject Access Requests (SARs) can be fulfilled using internal tooling. Data portability is available via CSV export by an organisation admin. Personal data can be erased by the customer administrator.
- No automated decisions: No automated decisions with legal or similarly significant effect on individuals are made by the Evo AI Platform by default. AI outputs are suggestions. End users retain the ability to override or disregard them at all times.
That last point matters for recruitment specifically. The human stays in the loop, by design, not as an afterthought.
What security questions should you ask an AI recruitment software vendor?
Security conversations in software procurement tend to happen later, often only when a deal reaches contract phase. Multiple 2026 procurement benchmarking studies report that around half of companies have lost deals because they could not complete a security questionnaire on time, and that security reviews typically add four to ten weeks to a deal.
The better approach is to ask early. "Are you secure?" will get you a yes from every vendor. The questions that separate them are:
"Do you have a published product fact sheet covering your security controls?"
A vendor with nothing to share in writing is a vendor with nothing documented.
"How do you prevent prompt injection from candidate documents?"
If they cannot explain their detection layer, they may not have one.
"What authorisation is required before an AI agent takes a data-modifying action?"
The answer should be: explicit user authorisation, every time.
"What is your data retention policy for AI interactions, and is customer data used for model training?"
Short retention windows and a clear no-training commitment are the standard to hold them to.
"Who reviews and approves your AI guardrail policies?"
Look for a named governance body - an Information Security Board or equivalent - not a vague reference to "our security team."
A vendor with ISO 27001:2022 compliance, a published fact sheet, and an Information Security Board sign-off process can answer all of these directly. It is worth to scrutinise the ones who cannot provide the necessary documents before you sign.
Want to see how Access Evo handles security in practice?
If you are evaluating AI recruitment platforms and want to understand how Access Evo addresses the risks covered in this article, speak to us. We can share the full Product Fact Sheet and walk through the security architecture relevant to your agency's size and data obligations.
AU & NZ
SG
MY
US
IE