TRUTH
Resources · HR & AI Blog

Trust at the heart
of modern hiring

CV fraud, AI optimisation, credential verification — the new frontiers of HR trust, decoded by our experts.

7 articles · Monthly cadence
🎯 For CHROs, Talent Managers & CIOs
Recent articles
Magnifying glass on documents
01

Falsified CVs: the silent epidemic eroding recruiter trust

One recruiter in three has hired a candidate whose CV contained at least one piece of false information. Fabricated degrees, inflated tenure, exaggerated responsibilities: document fraud has reached industrial proportions.

72%
of CHROs have discovered fraud after hiring
38k€
average cost of a failed hire in France
×3
increase in falsifications over 5 years

CV fraud is not a marginal phenomenon. According to our analysis of more than 40,000 verifications carried out in Europe, nearly one in three candidates shows at least one significant inconsistency between their CV and their LinkedIn or verifiable professional data.

"An elite-school degree can appear on a CV in 30 seconds. Verifying it once took weeks. Today, AI does it in 60 seconds."

The most frequent forms of falsification: title inflation (e.g. "Manager" for a coordinator role), artificial extension of assignment lengths, and fake degrees from non-existent programs. Tech, consulting, and finance account for 68% of detected cases.

The stakes go beyond recruitment: in case of proven fraud, the company bears legal liability if the position required regulated qualifications — medical, audit, certified engineering. The gap left by failing controls can cost far more than €38,000.

AI at keyboard
02

AI that rewrites CVs: when optimisation becomes imposture

ChatGPT, Claude, Gemini — LLMs have become CV-writing agencies one click away. In a few prompts, a mediocre profile turns into a dream application. The line between legitimate optimisation and structured falsification has evaporated.

67%
of candidates use AI to write their CV
4.2×
more ATS keywords in AI vs human CVs
89%
of HR teams cannot detect fully AI-generated CVs

The phenomenon is massive and structural. Job platforms — LinkedIn, Indeed, Welcome to the Jungle — are flooded with AI-optimised applications that pass every ATS filter with perfect scores, but no longer reflect the actual profile.

"AI doesn't lie, it embellishes. But embellishing incompetence is lying to the employer who hires on the strength of that document."

The mechanism is insidious: the candidate doesn't strictly "fabricate". They ask the AI to reformulate their experience to maximise impact, add "transversal" skills never truly practised, infer managerial responsibilities from an individual-contributor role.

Result: candidates selected for interviews based on a profile that's only half theirs. Recruiters feel it without being able to formalise it — the "disconnect" between the CV and the person across the table is more and more frequent. CV/LinkedIn consistency becomes the first signal of truth a recruiter can exploit.

Secure digital network
03

AI credential verification: the new HR trust standard

Faced with industrial fraud and AI-overtrained CVs, companies hiring without structured verification are playing Russian roulette. Intelligent credential verification is no longer a luxury — it's an HR governance imperative.

91%
of inconsistencies detected in under 60 seconds
5
dimensions analysed: consistency, progression, legitimacy…
RGPD
EU AI Act compliant, data deleted after 48h

AI credential verification rests on a simple but powerful principle: automatically cross-check what a candidate declares on their CV with what their LinkedIn profile, dates, titles, and career evolution reveal objectively.

"Hiring without verification is signing a contract with your eyes closed. Verification AI is simply opening your eyes — fast, and without bias."

Five dimensions are analysed: temporal consistency (do the dates fit?), logical progression (is the trajectory credible?), title legitimacy (does the responsibility level match seniority?), skills consistency, and red flags such as unexplained gaps or LinkedIn/CV inconsistencies.

Companies that have integrated systematic verification report a 78% reduction in failed hires on senior profiles, and a significant improvement in onboarding quality. Trust is not a feeling — it's an infrastructure.

European institutions Brussels
04

EU AI Act & HR verification: what changes on August 2, 2026 for CHROs

Six months from full application of the EU AI Act to "limited risk" AI systems — including automated candidate profile verification. Mandatory transparency, documented human oversight, decision register: compliance is no longer optional. Here's the checklist every European CHRO must have closed before summer.

August 2, 2026
Full enforcement date of the EU AI Act
7 %
global revenue: max fine per breach
3 obligations
key for "limited risk" HR tools

The European AI regulation classifies credential verification tools as "limited risk" systems — neither banned nor highly regulated, but subject to three strict obligations that many vendors have not yet integrated.

First obligation: transparency. The candidate must know, at the moment their profile is analysed, that an AI system is involved in the recruitment decision. Not in a buried T&C — in the application flow itself. Second obligation: human oversight. No rejection decision can be 100 % automated. An HR operator must be able to review, contest, and overturn every algorithmic score. Third obligation: traceability. Every verification must leave an audit log usable in case of dispute or DPA inspection.

"The EU AI Act doesn't kill AI in HR. It forces vendors to explain what they do, and CHROs to take back ownership of decisions. That's good news for the profession."

Concretely, CHROs must verify 5 points with their vendors before August 2: transparency notice delivered to the candidate, documented human-oversight workflow, retained decision register, GDPR Art. 28 DPA updated with AI Act mention, and impact assessment (DPIA) performed if candidate volume exceeds DPA thresholds.

The first sanctions will land in autumn 2026. France's CNIL and the upcoming French AI authority have already announced a wave of audits targeting candidate-scoring tools. Companies that anticipate now turn this constraint into competitive advantage: an auditable, explainable, defensible recruitment process becomes both an employer-brand argument and a legal shield.

Recruitment contract signing at agency
05

Replacement clause: why your recruitment agency bills you twice for the same mistake

The free replacement clause your recruitment agency promises is an accounting illusion. Between three months of wasted onboarding, the manager rewriting the evaluation, the demoralised team, and the missed commercial window, a bad hire costs on average 1.8 times their annual salary — and that bill is never refunded. Here is why the structural incentive misalignment between agency and client makes systematic verification before signing non-negotiable.

1.8×
annual salary: real cost of a mismatch (US Dept of Labor)
67 %
of CVs sent by agencies contain ≥ 1 verifiable inaccuracy
€0
refunded by the agency on induced costs (the silent clause)

The outsourced recruitment industry runs on an asymmetry no procurement department has ever corrected: the agency is paid on signing, not on retention. Its replacement guarantee covers the fee — typically 18 to 25 % of annual package — but it covers nothing else. And that nothing else is precisely what wrecks your P&L.

Real-world breakdown. An agency places a Sales Director at €120k for a €24k fee. Six months later the manager discovers the profile was not senior at HSBC but junior for 14 months, never "managed a team of 12" but coordinated one project, and shipped none of the deals claimed. You trigger the clause. The agency replaces for free — and sends its new invoice for active research. Client side: 6 months of salary paid out (€60k), 3 months of manager onboarding at 60 % bandwidth (estimate: €25k), a demobilised team, and two strategic deals lost for lack of leadership. Real cost not refunded: €85k minimum — not counting the second search restarting from zero.

The agency is not dishonest. The system is misaligned. The consultant is under placement pressure, the deadline is tight, deep verification slows the cycle. Result: "references taken" is declared based on a friendly call with a former colleague, CVs are accepted at face value, the funnel is optimised for closing — not for the candidate's lifespan in the role. The structural incentive is short-term. You pay the long-term.

An agency sells you a candidate. AttestAI sells you the certainty that this candidate is actually this candidate.

The fix is not to change agency nor to bring everything in-house. It is to insert a factual verification layer between the agency and the signing — and to make it contractual. AttestAI slots exactly there: before you make the offer, the shortlisted profile passes through automated verification of the objective points positions held, durations, titles, managerial scope, projects claimed, academic background, press mentions. The agency receives a documented Trust Score, you receive the same one. If a point fails, you know before the offer — not six months after.

For HR procurement, the dynamic changes radically: the brief is no longer "find me a Sales Director", it becomes "find me a Sales Director with Trust Score ≥ 80". The agency is aligned on factual quality, not just closing speed. The replacement clause becomes a residual insurance — not a risk-outsourcing mechanism.

For agencies themselves, this is a competitive advantage: presenting a shortlist where each candidate is pre-verified and auditable reassures the client, shortens the validation cycle, and radically differentiates from competitors delivering raw CVs. Several boutique firms have already started embedding AttestAI verification in their process — as a quality certification, not as a constraint.

The replacement clause is not the problem. It is the bandage on the problem. The problem is the absence of factual verification between the search and the signing. When that layer exists, the clause becomes what it always should have been: a residual safety net, not a life insurance policy.

Tech scale-up team working together
06

Agency or in-house: the real hidden cost of the fake tech profile

At an average €130k for a Series B Senior Engineer, every casting mistake costs more than the role itself. Lost ramp-time, sabotaged sprint, team churn, cultural dilution: the mismatch generates cascading damage invisible in the P&L but visible in velocity. Whether you hunt via agency or in-house, the weakest link is the same — factual qualification of the profile before the offer. And that is precisely the point nobody addresses.

9 months
to full productivity for a Senior Tech (Stripe Atlas)
3.2×
annual salary: cost of a scale-up bad hire (HBR)
41 %
of tech candidates inflate stack or scope (Codility 2025)

Two schools clash in every scale-up COMEX scaling its tech teams: outsource through a specialised search firm (25 to 30 % of package, 90-day guarantee) or industrialise hiring in-house (robust ATS, senior Talent Acquisition, calibrated peer interviews). The debate almost always centres on direct cost. It should centre on the cost of error of each option — which is rigorously identical.

Search firm. The consultant knows the talent pool, accelerates sourcing, speaks tech better than a generalist. But the guarantee is capped at 90 days, and the business model incentivises closing the assignment — not digging beyond the reputed: "reputed senior at Stripe", "reputed payment tech lead". Reference checking remains anecdotal, factual audit nearly non-existent.

In-house hiring. No fees, controlled process, more natural cultural immersion. But Talent Acquisition often has neither the tools nor the time to verify technical claims at scope level, and peer interviews — however rigorous on craft — test live performance, not the truth of the trajectory. An excellent engineer can be an excellent liar about their last three experiences.

The shared weak link. In both cases, you technical-interview as if the CV is true, you verify as if it never lies. Typical patterns our clients flag every month: "Senior Engineer at Google" who was a contractor for 4 months on a peripheral project, "Led team of 8" who was an IC with no direct reports, "Shipped at scale" on a project that never left staging, "3 years of Kubernetes expertise" with a GitHub that confirms it nowhere. None of these claims is technically detectable in a 90-minute live coding session.

In tech, we burn 6 engineering hours on a test we would never have run if we had verified 8 minutes earlier.

Quick math for an 80-person scale-up hiring 12 Senior Tech per year. Realistic assumption: 20 % of offers end in mismatch detected between M+3 and M+9. That is 2.4 mismatches/year. Unit cost at 3.2× annual salary (HBR), average salary €130k: €1.0M/year of diffuse losses. At that scale, outsource-or-in-house is no longer the right question. The right question is: how do I factually qualify a profile before it consumes 6 hours of my engineers in technical interview?

AttestAI inverts the canonical order of tech hiring. Before HR screening, before the tech challenge, before the live coding, the profile passes through automated factual verification: companies and durations (cross-checked across 3 public sources), titles and managerial scope, projects claimed (cross-checked with press, releases, conferences, public GitHub), academic record. The output: a Trust Score documented line by line, delivered in under 90 seconds. If the profile fails pre-screening, you save 6 engineering hours and a manager interview slot. If it passes, the tech challenge finally tests what it is meant to test: craft, not veracity.

The ROI is measurable from the first quarter: fewer mismatches passing filters, shorter ramp-time (selected profiles are actually senior, not reputed-senior), and — often underestimated — a drop in managerial cognitive load. The CTOs and VP Engineering we work with say it directly: the permanent fear of discovering a fake senior four months after hiring is a silent fatigue. Automated factual verification does not eliminate the risk — it makes it traceable, contestable, and defensible. Three qualities no technical interview has ever offered.

Proprietary technical architecture and circuits
07

"How do I know your AI isn't bullshit?" — AttestAI's honest answer

It is the first intelligent question every CHRO or CTO asks during an AttestAI demo: if you sell authenticity, how can I verify yours? Legitimate question — and we answer it head-on, because an authenticity tool that refuses audit is a walking paradox. Here are the 7 pillars that make AttestAI results traceable, contestable, and defensible — before a court, a board, or a wronged candidate.

80 / 20
proprietary AttestAI engine / external LLM layer (swappable)
0
black box — every Trust Score point documented with its source URL
7 pillars
that constitute the AttestAI authenticity guarantee

Before the pillars, the implicit question: AI bullshit exists, and it is everywhere. Models that hallucinate, scores that drift, providers who answer "trust me" when asked about method, vendors who hide behind "the model decided" the moment a dispute arises. This opacity is commercially comfortable — and legally untenable since the EU AI Act. AttestAI made the opposite choice, by construction. Here is how.

Pillar 1 — Traceable public sources. AttestAI invents nothing. Every verification points to a public URL anyone can consult: LinkedIn profile, business register (Pappers, Companies House, Crunchbase), press release, conference page, GitHub repository, academic publication. The delivered report cites its sources like a scientific paper. You open the URL, you verify yourself. If a source is wrong or stale, it is immediately detectable — not six months later in court.

Pillar 2 — 80 % proprietary architecture, swappable LLM. AttestAI is not an LLM wrapper. Our proprietary engine — source orchestration, deterministic scoring, journalisation, human oversight, contestation workflow — represents 80 % of the system. The Anthropic Claude Sonnet 4.6 model under DPA Art. 28 only serves as a NLP inference layer for 20 % of tasks: semantic extraction, rephrasing, textual comparison. No fine-tuning on your candidates. If Anthropic disappears tomorrow, changes pricing, or modifies its terms, we switch to another provider in a few days — your method, your history, your audit log remain intact. The dependency is outsourced, the trust never is.

Pillar 3 — Native human oversight. No rejection is ever 100 % automated. Every algorithmic score can be reviewed, contested, and overturned by an HR operator. EU AI Act "limited risk" compliance is not a bolt-on — it is built into the workflow itself. No candidate is eliminated by the machine alone.

Pillar 4 — Immutable audit log. Every verification, every score, every decision is timestamped and journalled to the Article 30 GDPR register standard. You can replay a decision made 3 months ago and see exactly which sources were consulted, the data state at that moment, the resulting score, and who (or what) validated. The log is cryptographically protected — not a modifiable Excel file.

Pillar 5 — Score explainable line by line. No "the model said 73". The Trust Score is the weighted sum of documented criteria: LinkedIn presence, platform tenure, company cross-referencing, title validity, press mentions, date coherence, weak fraud signals. Every point has a source, every weighting is documented, and the detail is delivered to client and candidate alike. The candidate scoring 67 knows why — and can contest point by point.

Pillar 6 — Candidate contestation coded into the workflow. The right to review is not a theoretical clause buried in T&Cs. It is a documented API endpoint and a web page delivered to the candidate at every verification. The candidate contests, the HR operator reviews, the decision is logged. GDPR-compliant (right to object, right to explanation) and EU AI Act-compliant (guaranteed human recourse) — by construction, not by declaration.

Pillar 7 — Vendor contractual guarantee. AttestAI assumes vendor liability. Our DPA Art. 28 is public, our liability clause is too. No deflection to "the algorithm", no exclusion of liability on model outputs. If a verification is shown to be wrong through our negligence, it is our responsibility — not that of an untraceable third-party provider.

Authenticity is not proven in a slide deck — it is proven in an audit log. AttestAI gives you both.

For the CHRO: if a candidate contests a score, you have the log. If the data protection authority asks, you have the Art. 30 register. If your ethics committee wants to audit, you have the source URLs. For the CTO: no black box, documented models, infrastructure hosted on Railway EU + Cloudflare EU, candidate data never used for fine-tuning. For the CFO: the LLM dependency is capped at 20 % of the system and is contractually swappable — no provider lock-in.

Trust is not a marketing argument. It is a verifiable architecture. AttestAI was designed to be auditable, not opaque — because an authenticity tool that refuses its own audit simply has no right to exist on the post-AI-Act European market. Ask the hard questions. We have the documented answers.