TL;DR: AI is good at recall and terrible at judgement. Use it to widen the pool and rank against a scorecard you wrote first, then keep every rejection and every hire decision with a human. Gartner expects 1 in 4 candidate profiles to be fake by 2028, so verify identity before you spend interview time, screen on paid work samples rather than resumes, and log a reason for each rejection.
I talk to engineering and hiring leaders most weeks, and the sourcing complaint has flipped. It is no longer that they cannot find candidates. It is that they cannot tell which ones are real. So this is the workflow we run at Second Talent to match engineers across nine markets in 24 hours, and where AI beats a person. It is for whoever owns hiring at a company small enough that a bad hire hurts. If you want a tool ranking instead, read our roundup of AI sourcing tools for recruiters. This is the process those tools plug into.
Why Sourcing Got Harder After AI, Not Easier
It’s because AI reached candidates before it reached you. The same models that let you screen 800 profiles let one candidate send 800 applications, each one tailored, formatted and submitted without a human reading it.
So your pipeline grew without getting better. The signal that used to separate applicants, a well-written resume that matched the job, now costs nothing to produce and tells you nothing.

The fraud numbers are the part I find teams underrate most. Gartner predicts that by 2028, one in four candidate profiles worldwide will be fake, and in its survey of 3,000 candidates, 6% admitted they had already taken part in interview fraud.
This is not theoretical. The US Justice Department found that more than 300 American companies had unknowingly hired impostors tied to North Korea for remote IT roles, and CNBC documented how deepfake applicants pass live video screens.
If your process assumes the person on the call wrote the resume and will do the work, AI broke that assumption. The workflow below rebuilds it.
What AI is Actually Good at in Sourcing
AI is good at recall and bad at truth. It can read more profiles than any recruiter and rank all of them against the same rubric, but it cannot tell you whether a candidate wrote the code they submitted.

The split holds across every tool on the market. Teams get burned handing AI the reject decision. That is where a ranking error turns into a candidate who never hears back, and a bias claim you cannot answer.
The Six-Step Sourcing Loop
Run these in order. Step 1 is the one teams skip, and skipping it makes every later step unauditable.

Step 1. Write the scorecard before you open a tool
Write four to six observable signals and score each 1 to 5. Observable means you could point at evidence: shipped a service handling real traffic, debugged something they did not build, wrote tests before anyone asked.
Years of experience and university are not signals. They are proxies that AI optimises against, which is how you end up with ten identical candidates.
Without a scorecard, an AI ranking is untraceable. You cannot explain why candidate 40 beat candidate 41, which matters for quality now and for compliance later.
Step 2. Point AI at recall, not at the shortlist
Ask for 200 ranked candidates, not the top 5. AI earns its keep by finding candidates your search terms would have missed, then ordering them against your scorecard.
This is the step I see skipped most often. A top 5 hands the judgement call to the model, which is the one thing it is worst at, and you lose the recall you bought the tool for.
Give it the scorecard as the ranking prompt and require a one-line reason per candidate tied to a specific signal. Reasons you can read are the difference between a tool you can audit and a black box.
Two prompts worth running: turn a messy role brief into a boolean search string, and find candidates whose public work matches a named repository or product rather than a job title.
Watch what this costs. Per-seat sourcing tools price on volume, so a wide pool is the expensive setting. Our AI recruitment tools cost comparison breaks down where the pricing tiers bite.
Step 3. Verify identity before you spend interview time
Check identity before the first call, not after an offer. Ask for government ID matched against a live video check, and run the profile photo through a reverse image search.
Teams resist this because it feels distrustful. Frame it as standard for any remote role with repository access, and apply it to every candidate so nobody is singled out.
Step 4. Screen on work, not on resumes
Replace the resume screen with a paid two-hour task from your real backlog. A resume is now an AI artefact, and screening on one measures prompt quality.
Score submissions blind against the rubric from step 1. AI can draft the score with its reasoning, and a human confirms it by reading the code.
Pay for the task. An unpaid four-hour take-home filters for candidates with spare time, not candidates who are good.
Expect AI-assisted submissions, and decide your position before you see one. Most teams now allow AI tools and judge the result, which is closer to the actual job. Our breakdown of AI-native versus traditional engineers covers what to look for when both used a model.
Step 5. Interview the submission live
Spend 30 minutes asking the candidate to change what they built. Add a constraint, break an assumption, ask them to handle 10 times the load.
This is the single highest-signal step in the loop. Someone who did not write the submission cannot extend it, and no resume screen or recorded interview will surface that.
Let AI transcribe and structure the notes, but keep the conversation and the scoring with the interviewer. If you run this at volume, our review of AI video interview solutions compares what the platforms automate.
Step 6. Record the reason for every rejection
Log one line per rejected candidate, tied to a scorecard item. Do it at the moment of rejection, because reconstructing it later is guesswork.
This log does two jobs. It tells you which scorecard signals predicted good hires, and it is the evidence a regulator asks for.
Who Decides at Each Stage
AI ranks and drafts. A human rejects and hires. That one line keeps quality up and keeps you on the right side of the rules below.

Notice the offer row. There is no version of this where a model decides who gets hired, both because the accuracy is not there and because you cannot defend it.
How to Catch a Fake Candidate
Four checks catch most fraud, and each takes minutes. Run them on every candidate who reaches a live call.

The liveness check works because current face-swap filters degrade on profile angles and when a hand crosses the face. Ask for both in the same motion and watch the edges of the jaw.
The payment check catches organised fraud that passes every visual test. When bank country, tax residency and stated location disagree, stop and ask why.
Ask about a decision, not a fact
“Why did you pick Postgres over DynamoDB there?” is hard to fake. A stand-in has the resume but not the memory behind it, and they cannot look the answer up mid-call.
The Compliance Step You Cannot Skip
If AI touches your hiring decisions, two rules apply depending on where you hire. Both require the same thing: a human decision point and a written record.
The EU AI Act
Annex III classifies AI used for recruitment, hiring and promotion as high-risk. The obligations cover transparency, human oversight and bias testing.
The deadline moved. The Digital Omnibus entered into force on 27 July 2026 and pushed the compliance date for stand-alone employment AI from 2 August 2026 to 2 December 2027. Product-embedded high-risk AI moves to 2 August 2028.
Read the delay as time to prepare, not a reprieve. Recruitment stays in Annex III, so the obligations have not changed. Only the date moved.
NYC Local Law 144
This one is already live. If you use an automated employment decision tool for a role in New York City, you need an independent bias audit every year, published publicly.
You must also tell candidates at least 10 business days before the tool is used and let them request an alternative. Penalties run from $500 to $1,500 per violation, and the city’s official AEDT guidance from the Department of Consumer and Worker Protection sets out what counts as a covered tool.
The rule reaches further than most teams expect. It applies to remote roles tied to a New York office, which catches distributed companies that never think of themselves as NYC employers.
What puts you in scope
Both rules turn on whether the tool substantially assists or replaces a human decision. Keeping the reject and hire calls with a person is what keeps most teams out of scope, and it is the same thing that keeps quality up.
How to Tell If It Is Working
Track four numbers before and after you change the process. If quality-of-hire does not move, the tooling is theatre.

Screen-to-interview and interview-to-offer are the pair that matter. If both rise, AI is surfacing better fits and your scorecard predicts something real.
If screen-to-interview rises while interview-to-offer falls, your scorecard is wrong. AI is finding more of the thing you asked for, and the thing you asked for does not predict a good hire.
Ignore time-to-hire on its own. It is the easiest number to improve and the easiest to improve by lowering the bar. Retention at 90 days is the honest signal. For benchmarks across the market, see our AI in recruitment statistics.
Where This Leaves You
The teams getting value from AI sourcing did not buy better tools. They wrote down what good looks like, pointed AI at recall, and kept judgement with a person.
If you only adopt one step from this loop, I would make it the paid work sample. It is the slowest thing here and the only one a stand-in cannot get through.
That is also why the fraud numbers do not frighten a team running this loop. You check identity before interview time, and the work sample interview catches anyone who did not do the work.
Key takeaways
- Write a four to six signal scorecard before you open any tool. Without it, an AI ranking cannot be audited.
- Ask AI for 200 ranked candidates with a reason each, not a top 5.
- Verify identity before the first call. Gartner expects 1 in 4 profiles to be fake by 2028.
- Screen on a paid work sample, then interview the submission live. That is the step a stand-in cannot pass.
- Log a reason for every rejection. It tunes your scorecard and it is your compliance record.
- Recruitment AI is high-risk under the EU AI Act, compliance date 2 December 2027. NYC Local Law 144 applies today.
Skip the Loop
Running this well takes a scorecard, a verification step, a paid work sample and someone senior enough to score it. Most teams hiring one or two engineers a year cannot justify building it.
That is the work Second Talent already does. We vet engineers across nine markets, verify identity before anyone reaches you, and match against your scorecard in 24 hours. You interview candidates who have already passed the work sample. See how we hire developers, or tell us what you are hiring for and we will send candidates this week.


![Workplace Diversity Statistics. Top 100+ Workplace Diversity Statistics [2026], by Second Talent.](https://www.secondtalent.com/wp-content/uploads/2026/09/workplace-diversity-statistics-featured-v2-768x403.jpg)


![Tech Industry Hiring Statistics. Top 50+ Tech Industry Hiring Statistics: Salaries, Skills Demand [2026], by Second Talent.](https://www.secondtalent.com/wp-content/uploads/2026/09/tech-industry-hiring-statistics-featured-v2-768x403.jpg)