AI Acceptable Use Policy
Prohibited uses of Kempian's AI Features, including discrimination, prompt abuse, and reverse engineering.
> *This document is part of Kempian's Trust Center documentation. It is reviewed periodically and does not constitute legal advice. Draft v0.2 — pending final legal review before publication.*
This policy sets out the rules for using the AI-powered features of the Kempian platform, operated by Adept AI Inc. ("Kempian," "we," "us," "our"). Those features — Candidate Matching, Resume Parsing, the Job Creation Assistant, and the Chat Assistant (together, the "AI Features") — are described in full in the Kempian AI Transparency Notice.
1. Purpose and Scope
This policy applies to all users of Kempian who interact with the AI Features, including employers, recruiters (in-house and agency), and candidates. It supplements, and does not replace, the Kempian Terms and Conditions and Privacy Policy. Where this policy and the Terms and Conditions address the same conduct, both apply, and Kempian may rely on either in responding to a violation.
The AI Features are designed to support and assist human decision-making in recruitment, not to replace it. This policy exists to keep that design principle intact in practice — by setting boundaries on how the AI Features may be used, and by making clear that human recruiters and employers remain responsible for hiring decisions made using the platform.
This policy is deliberately behavioural rather than technical: it governs what users may and may not do with the AI Features. It applies regardless of the specific technical safeguards Kempian has in place at any given time. Kempian requires human review before an AI output affects a candidate, and continuously enhances its AI governance and technical controls as part of its ongoing compliance program. This policy is one of the primary means by which Kempian sets and enforces expected conduct, and users are expected to comply with it at all times.
2. Who This Policy Applies To
This policy applies equally to:
- Employers and recruiters, who use Candidate Matching, Resume Parsing outputs, the Job Creation Assistant, and the Chat Assistant in the course of sourcing, screening, and hiring.
- Candidates, who interact with AI Features through their profile, applications, and the Chat Assistant.
- Any other authorized user of a Kempian account who accesses the AI Features on behalf of an employer, agency, or candidate.
3. Prohibited Uses
Users must not use the AI Features to:
- Rely on an AI output as the sole basis for rejecting a candidate. Match scores, parsed resume data, and any other AI output are recommendations only. A rejection decision must involve human review of the candidate's actual profile and, where applicable, the reasons an AI output flagged a concern.
- Screen for, or infer, protected characteristics or their proxies. Users must not use the AI Features, directly or through crafted inputs, to identify, infer, filter, or rank candidates based on race, colour, sex, gender identity, sexual orientation, age, religion, national origin, disability, pregnancy, genetic information, veteran status, or any other characteristic protected under applicable law. This includes screening through proxy signals (such as names, neighbourhoods, schools, or affinity-group membership) used as a stand-in for a protected characteristic.
- Attempt to manipulate or bias matching outcomes. This includes crafting job requirements, prompts, or profile data with the intent of steering a match score toward or away from a particular candidate for a reason unrelated to genuine job qualification.
- Submit another person's personal data into the AI Features without a lawful basis for doing so. This includes uploading a third party's CV, contact details, or other personal data without the appropriate consent, authorization, or other lawful basis required under applicable data protection law.
- Use the AI Features for any illegal purpose, including but not limited to fraud, harassment, or violation of employment, anti-discrimination, or data protection law.
These prohibitions apply regardless of intent stated at the time of use. A user who configures job requirements, search filters, or chat prompts in a way that has the effect of screening on a protected characteristic or its proxy violates this policy even if that was not the user's stated purpose. Employers and recruiters are responsible for the configuration choices they make when using Candidate Matching and related search tooling, in the same way they are responsible for the criteria they would apply in a manual screening process.
4. Bias and Discrimination
Users must not rely on AI outputs — match scores, resume-parsed data, generated text, or Chat Assistant responses — in a way that produces or perpetuates discriminatory outcomes against candidates or groups of candidates, whether or not that outcome was intended. This obligation applies both to how an individual AI output is used in a single decision and to any pattern of use over time. For example, consistently deprioritizing candidates matched from a particular source, location, or demographic pattern can violate this policy even where no single decision appears discriminatory in isolation.
If a user, whether an employer, recruiter, or candidate, suspects that an AI Feature is producing a disparate or unfair impact on any group, they must report it promptly using the process in Section 11, rather than continuing to rely on the output while the concern is unresolved. Kempian's bias and fairness testing program (described in the Kempian AI Governance Statement) is ongoing and does not eliminate the need for human vigilance. Recruiters and employers remain the frontline check against discriminatory use, consistent with the human oversight obligations set out in the Kempian AI Transparency Notice and Governance Statement. They should apply the same non-discrimination standards to AI-assisted decisions that they apply to any other hiring decision, and should document the human reasoning behind a decision where an AI output was a contributing factor.
This section works together with, and does not narrow, Section 3's prohibition on screening for protected characteristics. Section 3 addresses deliberate misuse of the AI Features to target protected groups, while this section addresses the broader obligation to avoid discriminatory outcomes regardless of intent.
5. Privacy in AI Use
Users must not input personal data into Kempian's AI Features beyond what is necessary for the stated purpose of that feature. For example, entering a candidate's CV for parsing is expected. Entering unrelated personal data about that candidate or a third party into a chat prompt for an unrelated purpose is not. This includes not pasting bulk personal data (such as a spreadsheet of candidate contact details) into the Chat Assistant or any other AI Feature as a shortcut for a task the feature was not designed to perform.
Users must not attempt to use the Chat Assistant, prompts, or any other AI Feature to extract another candidate's hidden or protected contact data. This includes cases where that candidate's record is in a privacy state (Marketplace, AI-Discovered, or Connected, as described in the Kempian Candidate Privacy & Visibility Notice) that does not permit that data to be shown. It also includes a Connected candidate's own field-level permissions, which control what a connected recruiter can see and which no organisation-level setting can override. Attempting to coax, infer, or reconstruct hidden contact information through repeated queries, indirect questions, or other means is a violation of this policy regardless of whether the attempt succeeds. This includes attempting to use AI-derived engagement insights (such as response likelihood or preferred contact window) to indirectly deduce contact information the platform is designed to keep hidden at that candidate's privacy state.
Recruiters and employers should also bear in mind that candidate data entered into the AI Features may be transmitted to the third-party AI providers described in the Kempian AI Transparency Notice for processing. Users should not treat any input to an AI Feature as private to Kempian alone, and should exercise the same discretion they would apply to any other data-sharing decision within the platform.
6. Prompt Abuse and Prompt Injection
Users must not attempt to manipulate the Chat Assistant, Job Creation Assistant, or any other AI Feature through adversarial prompts, "jailbreak" techniques, or other methods designed to bypass the feature's intended behaviour or safety controls. This includes attempts to:
- Extract the system prompt, internal instructions, or configuration of an AI Feature.
- Access another tenant's (employer's, agency's, or candidate's) data through crafted prompts or inputs.
- Reveal information about the underlying models, providers, or infrastructure beyond what Kempian discloses publicly.
Users who discover a suspected prompt-injection vulnerability or similar AI safety weakness must report it responsibly through the channel in Section 11, rather than exploit, publicize, or share it before Kempian has had the opportunity to assess and address it.
7. Reverse Engineering
Users must not attempt to extract, replicate, reverse-engineer, or derive the underlying AI models, scoring logic, prompts, weights, or training data used by any Kempian AI Feature, whether by systematic querying, automated scraping of outputs, decompilation, or any other method. This restriction applies regardless of whether the underlying model is provided by a third party (OpenAI, Anthropic, HuggingFace) or hosted internally by Kempian.
8. Security
Users must not attempt to probe, disable, degrade, or circumvent the safety, human-oversight, rate-limiting, or logging controls associated with the AI Features. This includes attempting to bypass the human review points described in the Kempian AI Transparency Notice, disable logging of AI-assisted decisions, or exceed usage limits through automated or scripted access not authorized by Kempian.
9. Misuse and Platform Integrity
Users must not use the AI Features to generate or facilitate:
- Spam or unsolicited bulk messaging.
- Fraudulent, misleading, or non-existent job postings.
- Fake, duplicated, or misrepresented candidate profiles.
- Content generated by the Job Creation Assistant or Chat Assistant that the user knows or should reasonably know to be false, and that is published or sent to a candidate or employer without correction (see the hallucination-risk guidance in the Kempian AI Transparency Notice).
- Any other content intended to mislead employers, recruiters, or candidates about the genuineness of a job opportunity, an applicant, or a message.
Employers and recruiters remain responsible for reviewing and correcting AI-generated job description drafts before publishing them, consistent with Kempian's broader position that generative AI output is a draft for human review, not a finished product.
10. Consequences of Violation
Violation of this policy may result in suspension or termination of a user's access to the AI Features or to the Kempian platform generally, under the enforcement provisions of the Kempian Terms and Conditions. Kempian may also take other action available to it under the Terms and Conditions, including removing content, reversing an AI-assisted action taken in violation of this policy, restricting a user's access to specific AI Features while preserving access to the rest of the platform, or reporting conduct to relevant authorities where required or appropriate. The severity and nature of the response will generally be proportionate to the conduct at issue. However, Kempian reserves the right to act immediately where a violation poses a risk to candidate safety, data security, or platform integrity, including suspending access pending investigation.
Repeated or severe violations of this policy — including systematic attempts at prompt injection, deliberate discriminatory use, or unauthorized submission of third-party personal data — may result in permanent termination of an account, independent of any other remedies available to Kempian under the Terms and Conditions.
11. Reporting a Concern
Reports should go to the right channel for the subject matter:
- Security or prompt-injection vulnerabilities (Sections 6 and 8) should be reported to security@kempian.com, Kempian's responsible-disclosure channel.
- Bias, fairness, or discriminatory-outcome concerns (Section 4) and other suspected policy violations should be reported to privacy@kempian.com, or through the in-platform reporting channel where available.
- Enterprise customers raising a concern as part of a procurement, security-review, or account relationship may instead route it to trust@kempian.com.
Reports are reviewed by Kempian's AI governance and trust & safety functions, and, where a report concerns a candidate's own treatment, may also be handled under the human-review request process described in the Kempian AI Transparency Notice.
Users reporting a security or prompt-injection vulnerability in good faith, and who do not exploit the vulnerability beyond what is reasonably necessary to demonstrate it, will not be treated as having violated this policy for the act of responsible disclosure itself. Kempian will acknowledge reports and, where appropriate, provide an update on remediation status, though specific investigation details may not always be shareable with the reporting user.
This policy will be reviewed periodically alongside the Kempian AI Transparency Notice and AI Governance Statement, and may be updated as the AI Features, applicable law, or Kempian's controls evolve.
12. Related Documents
This policy should be read alongside:
- Kempian Terms and Conditions
- Kempian AI Transparency Notice
- Kempian AI Governance Statement
- Kempian Privacy Policy
Kempian — AI Acceptable Use Policy — v0.3 (Draft) — July 2026