How to Use AI in HR in 2026: 7 Prompt Patterns, a Worked Screening Rubric and the Legal Line
The practical way to use AI in HR is to keep the judgement and automate the reading: draft job descriptions, summarise structured interview notes, and score resumes against a written rubric, then have a human review every borderline case. Roughly 72% of Indian organisations already run AI inside their HR software.
- Write the rubric before you write the prompt. A model scoring against five weighted criteria with quoted evidence is useful. The same model asked for a "fit score" is a random number generator with good grammar.
- Never let the model reject anyone. Use it to rank and to surface evidence. Every rejection stays a human decision, with a name attached to it.
- The cost is not the problem. Scoring 500 resumes against a rubric works out near $5 at published Sonnet class API rates, which is under Rs 500. Your bottleneck is rubric quality, not tokens.
- Two dates decide your policy. India's DPDP obligations bite from 13 May 2027, and the EU AI Act's high-risk employment rules were scheduled for 2 August 2026 before a deferral agreement pushed them toward December 2027.
- Skip AI video interview scoring. It is the one category in this whole space where the evidence is thin and the legal exposure is thick.
- You do not need to code. Six of the seven patterns below run in a chat window. One needs twelve lines of Python, and it is the one worth learning.
It is Tuesday, you have 380 applications for one data engineer opening, the hiring manager wants a shortlist by Thursday morning, and your applicant tracking system has already filtered out somebody who wrote "PySpark" where the keyword list said "Spark". That is the actual job AI can help with. Not the future of work, not a reinvention of the people function. Just the 380 PDFs and the two days.
Throughout this guide, keep one team in mind: two HR generalists at a 400-person manufacturing firm in Pune, no data team, no engineering support, one shared Claude subscription and a laptop each. Everything below is sized for them, which means it is sized for most HR teams in India.
What AI Actually Does Well in HR Work, and What It Doesn't
AI is already inside your HR stack
The question is no longer whether to adopt it, but whether anyone in your team can audit what it does.
Of Indian organisations reported AI features already integrated into their HR software, per the Capterra India HR Software Trends Survey. Most of those features were switched on by a vendor, not chosen by HR.
Figure checked 26 September 2026.
That number is the whole problem in one figure. The AI in most HR functions arrived as a toggle in a product someone else procured. Nobody in HR wrote its instructions, nobody knows what it weights, and when a candidate asks why they were screened out, the honest answer is a shrug.
So the useful split is not "AI good, AI bad". It is: which tasks can a model do where a human still sees the reasoning, and which tasks look automatable but hide a judgement call.
| HR task | What the model is genuinely good at | What it gets wrong | The human check that must stay |
|---|---|---|---|
| Job descriptions | Turning a hiring manager's five bullet points into a structured, readable JD in one pass | Inflating requirements. It will cheerfully add "5+ years" to a role that needs two | Hiring manager confirms every must-have is genuinely a must-have |
| Resume screening | Finding whether a named skill appears with evidence, and quoting the sentence that proves it | Judging seniority. "Led a team" reads identically whether the team was two interns or twelve engineers | Human reads every resume scored near the cut line, in full |
| Interview question design | Generating behavioural probes tied to a specific competency, plus follow-ups for a vague answer | Producing generic questions when the competency itself is vaguely defined | Panel agrees the question actually tests the competency |
| Interview note summarising | Compressing 40 minutes of scribbled notes into evidence grouped by competency | Smoothing over contradictions in the notes rather than flagging them | Interviewer reads the summary against their own notes before it enters the record |
| Policy questions from employees | Answering from an uploaded handbook, with the clause quoted | Answering confidently when the handbook is silent | Force a "not covered, escalate to HR" fallback and test it |
| Video interview scoring | Nothing you should rely on | Inferring competence from accent, lighting, background and speech rate | Do not deploy this. See the caveat below |
Here is the opinion I will defend: of those six rows, exactly one is worth building a process around this quarter, and it is resume screening. The others are conveniences. Screening is where the hours actually go, and it is the only one where a written rubric turns an opaque vendor score into something you can show a candidate, a regulator or a labour lawyer.
How to Use AI in HR: The Four Tasks Where It Pays Off First
Indian teams are not early here. Reporting on AI in recruitment in India suggests a large majority of IT services firms have already deployed AI for at least one of resume screening, scheduling, candidate communication or structured interviews, and TeamLease's Digital HR Survey has reported time-to-hire falling 40% to 55% where AI handles initial screening. Treat those as directional rather than precise. The point is that the experiment is over and the implementation details are what separate teams now.
For our Pune pair, the sequencing that works is deliberately unglamorous. Rubric first, script second, review third, paperwork fourth, second recruiter last.
How to spend your first 10 hours
Most teams invert this and spend 80% of the time on tooling. The rubric is where the quality lives.
Recommended allocation from the sequence in this guide, not survey data.
The 25% spent re-scoring resumes you have already judged yourself is the step everyone skips, and it is the only one that tells you whether the thing works. Pick 20 applications from a closed role: ten you shortlisted, ten you rejected. Run them through your rubric. If the model puts a past rejection in your top five, read its quoted evidence. Either the rubric is wrong or you were. Both are worth knowing before you point it at 380 live candidates.
Choosing AI tools for HR: buy the workflow, not the model
When you evaluate AI tools for HR, the question to ask a vendor is not which model they use. It is: can you export, for a named candidate, the criteria used, the score per criterion, the text the score was based on, and the model version that produced it? If the answer is no, you have bought something you cannot defend. A plain chat interface plus a written rubric beats an opaque scoring product on exactly that measure, which is why our Pune team is better off with a subscription and a spreadsheet than with a mid-market screening platform.
If your organisation runs on Microsoft 365, the governance side of this becomes a real job rather than a setting, and it is the territory the Microsoft 365 Copilot and Agent Administrator course (AB-900) covers: which Copilot agents exist, what data they can reach, and who approved them.
7 Prompt Patterns for HR Work, With Copy-Paste Examples
These are patterns, not scripts. Each one is a shape that survives being adapted to your role, your grade bands and your industry.
Pattern 1: AI for job descriptions that do not read like every other JD
Do not ask for a job description. Ask for a JD constrained by what you will actually interview for. Give the model the five things the hiring manager said on a call, then require that every listed requirement maps to an interview stage. Requirements that map to nothing get deleted. This single constraint is what stops the "5+ years and a Master's" inflation, because the manager has to admit there is no stage that tests it.
Pattern 2: the evidence-and-quote rubric
The core pattern of this entire guide. Never ask for a score alone. Ask for a score plus the exact sentence from the source that justifies it, and force a null when no such sentence exists.
SYSTEM
You score one resume against one rubric. You never decide.
RUBRIC (JD: Data Engineer, 3 to 5 yrs, Pune)
R1 Python in production weight 3
R2 SQL window functions weight 3
R3 Orchestration (Airflow or ADF) weight 2
R4 Cloud warehouse experience weight 2
R5 Written clarity in own words weight 1
For each criterion return:
score: 0 | 1 | 2 (0 = no evidence, 2 = strong specific evidence)
quote: the exact sentence from the resume that justifies the score
If no such sentence exists, score 0 and set quote to null.
Return JSON only, no commentary.
Do not infer or use gender, age, caste, religion, marital status,
college tier, photograph or hometown. Ignore them if present.
The "quote or null" rule is doing the heavy lifting. A model that has to produce a sentence cannot quietly reward a familiar college name, because there is no sentence about Python to quote. Run the same resume twice and compare quotes: if they differ, your rubric criterion is ambiguous.
Pattern 3: the structured interview kit
Feed the model one competency and one seniority level, and ask for three behavioural questions, the follow-up to use when the answer is generic, and the specific detail that distinguishes a strong answer from a rehearsed one. That last clause is what makes the output usable. "Tell me about a conflict" is worthless; "ask what the other person's argument was, and listen for whether they can state it fairly" is a probe.
Pattern 4: notes to evidence, not notes to summary
Paste your raw interview scribbles and ask for them regrouped under the competencies on the scorecard, with contradictions flagged rather than resolved. If the notes say both "strong ownership" and "waited for manager sign-off twice", you want that tension surfaced, not averaged away.
Pattern 5: the handbook answer with a clause reference
Upload the policy document and require every answer to quote the clause number it came from, and to reply "not covered in this document, escalate to HR" when it cannot. Then test it with three questions you know the handbook does not answer. If it invents a maternity leave policy, the fallback is not working and you do not ship it.
Pattern 6: the rejection email that says something
Give the model the rubric output for one candidate and ask for three sentences of specific, non-actionable-free feedback. Non-actionable feedback is what candidates hate; "your resume showed no production Python, which was weighted highest for this role" is usable. Read every one before it sends. This is a small courtesy that costs you two minutes and buys real goodwill in a market where most candidates hear nothing at all.
Pattern 7: the adverse-impact self-check
After scoring, hand the model the distribution of scores alongside a protected attribute you hold separately, and ask it to describe the difference in plain language without recommending an action. You are not asking for a legal conclusion. You are asking whether the pattern is worth a human looking at. This is the pattern that keeps you out of the situation described in our compliance section, and it takes about four minutes per role.
Also read: How to Use AI in Finance Work in 2026 applies the same evidence-first discipline to a variance report, and the overlap in method is not a coincidence.
A Worked Example: From Job Description to Scored Shortlist in Under an Hour
Here is the full pipeline our Pune team runs for the data engineer role. You can reproduce every step.
Human-in-the-loop resume screening
The model reads and cites. Every arrow that removes a candidate passes through a person.
Pipeline as described in this guide, checked 26 September 2026.
Step 1: the rubric
| Criterion | Weight | Scores 2 | Scores 0 |
|---|---|---|---|
| R1 Python in production | 3 | Names a service or job they wrote that ran on a schedule for real users | "Familiar with Python" with no artefact |
| R2 SQL window functions | 3 | Names a specific problem solved with a window function or a CTE | Lists SQL in a skills bar only |
| R3 Orchestration | 2 | Names Airflow, Azure Data Factory or a Fabric pipeline plus what it orchestrated | No scheduler mentioned anywhere |
| R4 Cloud warehouse | 2 | Names a warehouse and a rough data volume | Cloud named only as a course completed |
| R5 Written clarity | 1 | Describes their own work in their own sentences | Pure bullet-point template language |
Maximum weighted score is 22. Our team cut at 12 and read everything from 9 upward, which in practice meant reading about 60 resumes properly instead of 380 badly.
Step 2: extract the text
pip install pdfminer.six
mkdir -p resumes_txt
for f in resumes/*.pdf; do
pdf2txt.py "$f" > "resumes_txt/$(basename "${f%.pdf}").txt"
done
ls resumes_txt | wc -l
Step 3: score in a loop
import anthropic, json, pathlib
client = anthropic.Anthropic()
for path in sorted(pathlib.Path("resumes_txt").glob("*.txt")):
msg = client.messages.create(
model="claude-sonnet-5",
max_tokens=1024,
system=RUBRIC_PROMPT, # the Pattern 2 block above
messages=[{"role": "user",
"content": path.read_text(errors="ignore")[:8000]}],
)
row = json.loads(msg.content[0].text)
row["file"] = path.name
print(json.dumps(row)) # pipe to scores.jsonl
That is the twelve lines. Pipe the output to a file, open it in Excel, sort by weighted total. If Python is a wall for you right now, the same loop exists as a spreadsheet formula in Copilot for Excel, and that skill sits squarely inside a live Data Analyst programme covering Excel, SQL, Python and Power BI.
Step 4: the cost, worked out
A parsed resume runs roughly 1,200 tokens. Add a rubric prompt of about 600 tokens and you are sending near 1,800 input tokens per call, with maybe 350 tokens of JSON coming back. For 500 resumes that is 0.9 million input tokens and 0.175 million output tokens. At the published Sonnet class API rate of $3 per million input tokens and $15 per million output tokens, that is $2.70 plus $2.63, so about $5.33 for the whole role, which lands under Rs 500 at current rates. Prompt caching on the rubric would cut the input side further, since the rubric is identical across all 500 calls.
Five dollars. That is the entire technology cost of the thing HR software vendors charge a per-seat subscription for. What you are actually buying from a vendor is the workflow, the audit trail and somebody to blame, and sometimes that is a fair trade. Just know which one you are paying for.
AI Resume Screening: Why the Unilever Story Is Not Your Story
Every vendor deck cites Unilever. The facts are real: starting in 2016 with HireVue and Pymetrics, Unilever rebuilt entry-level hiring into a four-stage funnel of application, neuroscience-based games, AI-assessed video interviews and a final in-person centre. Published accounts of the programme report time-to-hire dropping from roughly four months to four weeks, a 75% reduction in recruitment time, and savings above GBP 1 million, across a pipeline that grew past a million applications a year.
Now notice what made it work, because it is not the AI. Unilever was hiring thousands of near-identical graduate roles against a stable competency model, at a volume where a percentage point of model improvement paid for a research team. Our Pune pair is hiring one data engineer. They have no volume to learn from, no baseline to measure against, and no budget to retrain anything.
Which means the transferable lesson from Unilever is narrow and specific: they defined what they were measuring before they automated the measuring. The four-stage structure came first. If you take one thing from that case, take the rubric discipline, not the video interviews.
AI resume screening is mediocre at the thing HR most wants from it, which is judging whether someone is actually good. It reads claims, not competence. A candidate who writes well about modest work will outrank a strong engineer with a terse resume, every time, and no prompt fixes that because the information simply is not in the document. If your hiring pain is "we keep shortlisting the wrong people", AI will not solve it and may harden the error. It solves "we cannot read 380 resumes by Thursday". Those are different problems. Be honest with yourself about which one you have.
How to Use AI in HR Without Breaking the Law
This is the section most AI-in-HR content skips, and it is the one that will decide whether your process survives contact with your legal team.
| What applies | Where it bites | Date that matters | What you must be able to produce |
|---|---|---|---|
| DPDP Act 2023 and DPDP Rules 2025 | Any Indian employer processing candidate data | Rules notified 13 November 2025; substantive obligations from 13 May 2027, with consent manager registration opening November 2026 | Consent record, stated purpose, retention limit, and accuracy of the personal data used in a decision affecting the person. Penalties run to Rs 250 crore for security failures |
| EU AI Act, high-risk employment obligations | Hiring for EU-based roles or assessing EU candidates | Scheduled for 2 August 2026; a Digital Omnibus agreement would defer employment-decision rules toward 2 December 2027, but only once formally adopted | Technical documentation, demonstrable human oversight, bias testing, registration in the EU database |
| EU AI Act transparency duties | Same | 2 August 2026, as originally planned | Tell candidates when they are interacting with an AI system, and disclose emotion recognition or biometric categorisation |
| Your own internal policy | Everywhere, today | Now, and nobody will remind you | Which model version scored which candidate against which rubric version, and the name of the human who made the call |
Read the last row again. It is the only one with no deadline, and it is the one that saves you. An audit log is four columns in a spreadsheet: candidate ID, rubric version, model name and date, human reviewer. Fifteen minutes to set up. If a candidate ever asks how they were assessed, or a regulator does, that spreadsheet is the difference between a clear answer and a very bad afternoon.
What usually goes wrong here
Someone in your team is going to paste a batch of resumes into a free consumer chat tab, because it is Tuesday and the shortlist is due Thursday. That is candidate personal data leaving your controlled environment, with no consent basis for it and no record that it happened. It will not feel like a data incident. It will feel like getting work done. Decide now whether your team uses an enterprise or API account with data controls, tell them plainly, and give them the working alternative before they improvise one. Most AI governance failures in HR are not decisions. They are Tuesdays.
Also read: AI Agent Governance in 2026: 7 Controls Every Enterprise Needs generalises this into the control set a larger organisation will ask you for.
6 Mistakes That Make AI in HR Worse Than a Spreadsheet
Letting the model reject
Auto-rejecting below a threshold is the single decision that converts a useful tool into a liability. It also removes the only person who could have spotted that the rubric was broken.
Keep stage 5Asking for a fit score
"Rate this candidate out of 10" produces a confident number with no traceable basis. Ask for per-criterion scores with quoted evidence and the number becomes checkable.
Evidence or nullNo golden set
If you have never run the rubric against 20 resumes you already judged, you do not know whether it works. You only know it produces output, which is not the same thing.
Test on old rolesA rubric that rewards pedigree
Criteria like "tier-1 institute" or "product company background" launder existing bias into a number. Write criteria about work done, never about where it was done.
Skills, not signalsConsumer chat for candidate data
Resumes are personal data. Pasting them into an unmanaged account creates an obligation you cannot evidence and a trail you cannot produce.
Use a managed accountNo version record
Models update. A rubric edited mid-role means two candidates were scored by different systems, and you will not be able to say which was which.
Log four columnsMistake 4 deserves a longer note, because it is the one that gets defended in meetings. Pedigree criteria feel predictive because they correlate with past hires who worked out, and past hires who worked out were also selected on pedigree. That is a loop, not evidence. Replace "tier-1 institute" with the thing you actually believe it proxies for, write that down as a criterion, and see whether the model can find evidence for it. Usually it can, in candidates you were about to filter out.
How to Learn This Properly, Without Becoming an Engineer
The skill underneath everything above is not prompting. It is the ability to specify a task precisely enough that a model's output is checkable, and to know which parts of a decision must never leave a human. That is a teachable discipline, and it is the substance of Anthropic's associate-level certification track.
The Claude Certified Associate Foundations (CCAO-F) prep course is built for exactly this reader: its live description states it runs blueprint-weighted modules across all seven exam domains with hands-on Claude Projects labs, two full-length timed mock exams with domain-wise score reports, and a Pearson VUE registration walkthrough, with no coding required. For an HR professional, the Projects labs are the useful part, because a Project with your handbook uploaded and your rubric saved is precisely Pattern 5 and Pattern 2 in production.
If you do want the engineering side eventually, the ladder is visible: the CCDV-F developer prep course next, then genuine retrieval and agent work in the AI Engineer course covering RAG and AI agents, and architecture-level design in the CCAR-F architect foundations track. Most HR readers should stop at the first rung. The full certifications overview lays out how the tracks connect, and a free webinar is the cheaper way to find out whether any of it is for you before you pay for anything.
Also read: CCAO-F Exam Prep 2026: A 4-Week Study Plan breaks the certification down week by week if you decide to go for it.
Learn to specify AI work well enough to defend it, with no coding required
A live 4-week weekend cohort preparing you for Anthropic's Claude Certified Associate Foundations (CCAO-F) exam, with blueprint-weighted modules across all seven domains and hands-on Claude Projects labs. Two full-length timed mock exams with domain-wise score reports, plus a Pearson VUE registration walkthrough. Batch starts 27 September.
Explore the course
What I Would Do If I Were Running Your HR Team
Build one thing this quarter and build it properly: a written rubric for your highest-volume role, tested against twenty resumes you already judged, run through a managed account, with a four-column audit log and a human reading everything near the cut line. That is a week of real work and it will hold up for years.
Then leave everything else alone. Do not buy an AI screening platform yet, do not touch video interview scoring, and do not automate rejections, however much the vendor demo shows you the time saved. The teams that get burned in the next eighteen months will not be the cautious ones. They will be the ones who bought a score they could not explain.
If you want the reasoning behind that discipline taught properly rather than absorbed from blog posts, the CCAO-F prep cohort is the closest fit, and if you would rather test the water first, sit in on a free webinar or book a demo class before you spend anything.
Related guides
- What Is a Microsoft 365 Copilot Administrator? read this if the governance questions in this guide turned out to be somebody's actual job at your company.
- What Is Claude Cowork in 2026? the desktop tool that runs the file-heavy version of these patterns without a Python loop.
- What Is Claude Opus 5.5? useful when you need to decide whether a bigger model is worth the token cost on a scoring job.
- Prompt Engineer Salary in India 2026 for the HR reader who now has to write a grade band for one of these roles.
- Certification vs Projects in 2026 worth reading before you write "certification preferred" into your next job description.
- Highest Paying IT Certifications in India 2026 the advertised pay bands behind ten credentials you will see on incoming resumes.
Frequently asked questions
How to use AI in HR if my company has no budget for new software?
You need one paid chat subscription or an API key, a text editor and a spreadsheet. Write a weighted rubric, score resumes with the evidence-and-quote prompt in this guide, and log four columns for the audit trail. At published Sonnet class rates of $3 per million input tokens, scoring 500 resumes costs roughly $5. The expensive part is the hour you spend writing the rubric, and no software replaces it.
Can AI reject a job candidate automatically?
Technically yes, and you should not. Under the DPDP Act a data fiduciary must ensure the accuracy and completeness of personal data used to make a decision affecting a person, and the EU AI Act's high-risk employment rules require demonstrable human oversight. Beyond compliance, auto-rejection removes the one person who could have noticed your rubric was broken. Use the model to rank and to surface evidence; keep rejection with a named human.
Is AI resume screening biased?
It reproduces whatever your criteria encode, and it is very good at doing so consistently. Criteria like institute tier or product company background launder existing preferences into a number that looks objective. The mitigations that actually work are narrow: write criteria about work performed rather than where it was performed, force quoted evidence so there is nothing to cite for a pedigree signal, explicitly instruct the model to ignore name, photograph, gender and hometown, and compare score distributions afterwards.
What are the best AI tools for HR teams in 2026?
Judge any tool on one question: can it export, for a named candidate, the criteria used, the score per criterion, the source text each score was based on, and the model version that produced it? If not, you cannot defend a decision made with it. For a small team, a managed chat or API account plus a written rubric outperforms most mid-market screening platforms on that test. Avoid AI video interview scoring entirely.
Do HR professionals need to learn coding to use AI at work?
No. Six of the seven prompt patterns in this guide run entirely in a chat window with a document uploaded. Only batch scoring needs a loop, and that loop is about twelve lines of Python you can copy. The CCAO-F prep course is explicitly built for this: its description states no coding is required. If you later want to build rather than use, the developer and AI engineer tracks are where that starts.
How much does it cost to screen 500 resumes with an AI model?
Around $5.33 at published Sonnet class API rates. A parsed resume is roughly 1,200 tokens, the rubric prompt around 600, and the JSON response near 350, which across 500 calls is about 0.9 million input tokens at $3 per million and 0.175 million output tokens at $15 per million. Prompt caching on the identical rubric reduces the input side further. Token cost is not what makes AI screening expensive.
When do India's DPDP rules actually start applying to hiring data?
The Digital Personal Data Protection Rules were notified on 13 November 2025, with a phased roadmap. Consent manager registration opens in November 2026 and the substantive obligations covering consent, privacy notices and security requirements apply from 13 May 2027. Penalties reach Rs 250 crore for failures to maintain reasonable security safeguards. Candidate resumes are personal data, so your retention rule and consent basis need to exist well before that date.
Will AI replace HR jobs?
It replaces reading volume, not deciding. The tasks disappearing are resume triage, scheduling and first-draft writing. The tasks growing are the ones this guide is mostly about: defining what you are measuring, auditing what a system did, and being the accountable human on a decision. Those are harder and better paid. The HR professionals at risk are the ones whose work was mostly the triage.
About this guide. 360 Digital Transformation is an Authorized Training Partner of Anthropic and Microsoft. Other certification bodies, vendors and employers named here are not affiliated with us. Tools and versions change quickly; commands and figures cited were checked on 26 September 2026.




