Braintrust AIR: Ensuring Compliance with U.S., Canadian and EU AI Regulations
At Braintrust, we believe compliance and trust go hand-in-hand. Braintrust AIR is built to meet the evolving demands of U.S., Canadian, and EU AI laws, ensuring that every interview conducted with our platform is fair, auditable, secure, and transparent. Our goal is simple: AIR supports recruiters; humans always make the hiring decisions.
For detailed policies and attestations, visit our Trust Center, Privacy Policy and Terms of Service. Also, a third-party AI audit has been completed, validating our fairness, transparency, and safety controls which can be found here.
Regulatory Compliance
What regulators expect: When AI touches hiring, laws generally require five things: (1) human oversight, (2) transparency about how AI is used, (3) explainability of outputs, (4) privacy & security for personal data, and (5) fairness (no unlawful discrimination).
What AIR does:
- Human‑in‑the‑Loop by design. AIR never auto‑accepts or rejects candidates. Recruiters review scorecards and video before decisions.
- Transparent & explainable. Each interview produces a clear scorecard tied to job‑specific competencies, plus transcript/video for context.
- Fairness controls. Standardized questions, consistent grading rubrics, and periodic bias testing; findings reviewed and tracked.
- Security & privacy. Minimal data collection (name, email), TLS 1.2+ in transit and AES‑256 at rest, RBAC + MFA, logging and monitoring on AWS.
- Accountability. Documented workflows, audit logs, change controls, and an annual review cycle. Third‑party AI audit completed.
U.S. Federal & State AI Requirements
FTC Guidance on AI Marketing & Fairness
Overview: The FTC enforces truth‑in‑advertising and fairness. If you use or market AI, you must be honest about what it does, avoid deceptive claims, and ensure your practices don't unfairly harm people (e.g., discriminatory outcomes).
How AIR complies:
- We plainly describe AIR's role and limits; humans make decisions.
- We back performance statements with data (pilot metrics, client outcomes) and our third‑party AI audit.
- Our Privacy Policy and Terms explain processing, rights, and responsibilities.
Illinois AI Video Interview Act
Overview: If AI is used to evaluate video interviews, candidates must be told AI is used, how it works in general terms, and who will see the video; consent is required and videos must be deleted upon request.
AIR compliance:
- Clear on‑screen and/or email AI disclosures and consent collection.
- We explain AIR's role (screening support, not decision‑making) and who can access results.
- Deletion requests honored via our Privacy Policy workflow; access controls restrict sharing.
California Privacy & AI
CCPA/CPRA (Privacy):
Overview: California residents have rights to know, access, delete, and limit use of personal information.
AIR compliance: Minimal PII (name, email), purpose‑limited use, deletion upon request, and DPA terms supporting clients' obligations.
New York City Local Law 144 (AEDT)
Overview: Requires annual bias audits, public notice of AEDT use, candidate notice and instructions, and an alternative selection process.
AIR compliance:
- AIR can be deployed as an AEDT with annual bias audits (third‑party supported).
- We provide notice templates and alternative process guidance; AIR itself does not render decisions.
Accessibility, Inclusivity, and Candidate Experience
What's expected: Hiring tools should work for everyone and avoid disadvantaging protected groups.
What AIR does:
- Screen‑reader friendly UI; candidate guidance and flexible completion times.
- Questions and rubrics reviewed for clarity and potential bias.
- Human-led alternative available upon client request.
- Feedback loops for candidates and recruiters; issues tracked to closure.
What We Provide Clients (Audit Ready Package)
- Trust Center: central hub for policies, subprocessors, security posture, and audit artifacts.
- AI Use Notices & Templates: candidate and website/email notice language (FTC/IL/NYC/ON/UT etc.).
- Bias Testing & Reports: independent assessments + remediation tracking; annual cadence.
- Logging & Retention: end‑to‑end logs; configurable retention (supports CA ADS 4‑year standard).
- DPIA/AIRA Kits: templates to complete client privacy/AI impact reviews efficiently.
- Incident & Appeal Playbooks: candidate inquiry/appeal workflows, takedown/deletion procedures.
Security Snapshot
- Encryption: TLS 1.2+ in transit; AES‑256 at rest.
- Access: RBAC, least privilege, MFA; SSO via WorkOS.
- Monitoring: AWS CloudTrail, GuardDuty; 12‑month log retention minimum.
- Testing: Patch management, change control; penetration tests as required.