←
AI for Recruiters
Capable · M6 · lesson 6 of 27 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

Editing and Verifying AI-Drafted Messages

15 min

Devon is a recruiter at a 220-person healthtech company, running three open requisitions for clinical-data engineers with a team of two coordinators. He leans on an LLM assistant to draft the first version of almost everything: cold outreach, scheduling notes, rejections, even the occasional offer summary. The drafts are fast and usually readable. What changed Devon's practice was not the speed but a near-miss. One morning he nearly sent a rejection that thanked a candidate for "your strong work at Cedar Memorial" to someone who had never worked at Cedar Memorial. The AI had invented it. Devon caught it with eight seconds to spare, and from that day forward he stopped thinking of the AI as a writer and started thinking of it as a fast first-draft intern whose work he signs. This lesson is the verification workflow he built so that the next invented detail never makes it out the door.

Why the Recruiter Owns Every Word

When a message goes out under Devon's name and his company's brand, he is accountable for it whether he typed it or an AI did. A candidate reading a cold message does not know or care which sentences came from a model. They experience one thing: a recruiter who either did the research or did not, who either represents the company accurately or does not. The AI is a drafting tool, like a template or a clever colleague who writes fast and occasionally makes things up. It carries no liability and feels no embarrassment. Devon does. That is the entire reason verification is not optional.

The deeper reason is how the model fails. It optimizes for fluent, confident, plausible text, and fluent confident text is exactly what a fabricated detail looks like. Nothing in the output flags which parts are grounded in Devon's notes and which the model filled in to make a sentence flow. This is the difference between using AI and using AI well. Using AI means asking for a draft and sending it. Using AI well means asking for a draft, reviewing it critically, editing it, and sending only when you are confident it represents you and your company accurately.

That is the mental shift that makes the rest of the workflow stick. Devon does not read an AI draft asking "is this good writing?" He reads it asking "can I stand behind every specific claim in this, and would I be comfortable if the candidate forwarded it to their lawyer or posted it on LinkedIn?" Those two questions catch most of what matters, and everything below is the systematic version of them.

The Five Risk Passes Before You Send

Devon runs every AI draft through the same five-pass review before it leaves his outbox. The order matters: he checks for the high-damage, hard-to-undo problems first. A tone misfire is awkward; a fabricated fact or a compliance-risky promise can cost a candidate's trust or create legal exposure. The five passes are factual grounding, personalization tokens, tone fit, compliance and promises, and protected-class and accommodation language. The whole sweep takes about three minutes per message, which is less time than writing from scratch and far less than cleaning up after a bad send.

None of these checks require special tooling. Devon does them against two sources of truth: his own notes and research on the candidate, and the canonical record in the ATS. If a claim in the draft cannot be traced to one of those two places, he treats it as unverified until he confirms it, and if he cannot confirm it, it comes out. That rule is what makes the review fast, because it replaces a judgment call about plausibility with a lookup.

Pass One: Accuracy and Fabricated Details

The first and most important pass is factual grounding. Devon reads the draft sentence by sentence and asks, for every specific claim, "where did this come from?" He is checking four things at once. Does it correctly attribute the projects and experiences it names, meaning the candidate actually did that thing? Does it describe his company accurately, including funding stage, size, and what the team does? Does it state the role correctly, with the title and responsibilities matching the requisition rather than the one he worked last month? And are there small factual errors hiding in the flattering sentences, the wrong employer, the wrong product, the wrong year?

Accuracy is load-bearing because the opening reference carries the credibility of everything after it. A candidate who reads "I noticed your work at TechCorp on their payment system" when they actually worked at PayMasters on their checkout flow knows immediately that no real research happened, and the message is an automatic delete. The dangerous claims are the specific, flattering, research-flavored ones, because those are precisely the details a model invents to make outreach feel personalized. Company names, project names, technologies, tenure, school names, publications, and conference talks are all places an LLM will confidently supply a detail that sounds right and is simply false.

Here is a real example from Devon's queue. He asked the AI to draft cold outreach to a senior data engineer named Rosa, feeding it three lines of notes: "8 years experience, currently at a logistics startup, strong Python and Airflow, lives in Austin." The draft came back:

"Hi Rosa, I came across your profile and was genuinely impressed by your work building the real-time pipeline at FreightLine that cut data latency by 40 percent. Your background scaling Airflow across a 50-person engineering org is exactly the kind of experience our clinical-data team is looking for. We're a Series C company and just closed our funding round..."

Devon's notes never mentioned FreightLine, a 40-percent latency improvement, a 50-person org, or the funding stage. The model fabricated all four. The candidate's employer was unnamed in his notes; "FreightLine" was invented. The 40-percent figure was invented. The org size was invented. And his company is actually Series B, not Series C, a fact he can confirm in seconds. Every one of those is a delete trigger for a sharp candidate, who knows their own resume better than Devon ever will and will read four invented details as proof that no real research happened. After editing, the message read:

"Hi Rosa, your eight years of Python and Airflow work caught my attention, and the data-pipeline reliability problems you have likely been solving map closely to what our clinical-data team is tackling right now. We're a Series B healthtech company..."

The edited version makes only claims Devon can defend. It trades invented specifics for honest specifics drawn from his actual notes. It is less dazzling and far more credible. The rule Devon follows: if a detail is impressive and you cannot point to where you learned it, the AI made it up. The verification method is equally simple, and it is the one thing he refuses to shortcut. Double-check every specific fact against your research and the candidate's actual background before the message leaves the outbox.

Pass Two: Personalization Tokens and Merge Fields

The second pass is about the mechanical personalization that breaks in unglamorous, mortifying ways. When Devon pulls a draft that uses merge fields, or reuses a message across candidates, the classic failures are a leftover placeholder like "Hi [First Name]," a name from the previous candidate left in the body, a role title that belongs to a different requisition, or a pronoun the AI guessed wrong. The ATS is the source of truth for every one of these, and Devon checks the rendered message rather than the template, because a template can look perfect while the merge silently fails.

He pays special attention to the gap between the greeting and the body. It is common for the salutation to merge correctly while a hardcoded name three paragraphs down still says "Marcus" from the message he adapted this one from. He also never lets the AI infer a candidate's gender or pronouns from a first name; if his record does not have the information, the message is written to avoid the guess entirely. A wrong name or wrong pronoun signals carelessness at exactly the moment Devon is asking someone to trust his company with their career.

Pass Three: Tone and Context Fit

The third pass checks whether the register matches the message type and the recipient. An LLM has a house style that tends toward enthusiastic and slightly salesy, which is wrong for most recruiting moments. A rejection needs warmth and brevity, not excitement. Outreach to a senior principal engineer needs respect for their time, not a hard pitch, while a message to an early-career candidate who is actively looking can be appropriately energetic. A message to someone not actively searching should be different from a message to someone who is. Tone also has to fit your company: a startup writing like a bank reads as stiff, and an enterprise writing like a startup reads as unserious.

Devon reads the draft aloud, because his ear catches what his eye skims. If a phrase is something he would never say to a person in a room, it gets rewritten. Then he asks the diagnostic question directly: how would this candidate feel receiving this message, respected or sold to? That question resolves most tone disputes faster than argument about individual word choices.

He watches for three specific tone failures. The first is oversell: "you would be perfect for this role" makes a promise about a process that has not happened yet, and Devon softens it to "this might be worth a conversation." The second is condescension, often hiding in phrases like "for someone with your background," which reads as a backhanded assumption about what someone like the recipient could be expected to have achieved. The third is false intimacy, the AI manufacturing a warmth that has not been earned with a stranger. Tone is not decoration. For a rejection in particular, tone is most of the message, because the candidate will remember how it felt long after they forget the words.

Passes Four and Five: Promises and Protected-Class Language

The last two passes are where the stakes move from brand damage to legal risk, and they are the passes Devon will not skip even when he is rushing. The fourth pass looks for promises and commitments the AI slipped in. Models love to be reassuring, so they generate lines like "we can definitely match your current salary," "this role is fully remote forever," or "you can expect an offer by Friday." Each is a commitment Devon may not be authorized to make, and a candidate can reasonably rely on it. He strips any promise about compensation, start dates, remote status, advancement, or job security that has not been confirmed by the hiring manager and the offer, and replaces it with accurate, non-binding language: "the team is currently remote-first" rather than "remote forever."

The fifth pass is protected-class and accommodation language. Devon scans for any reference, even a well-meant one, that touches age, race, national origin, religion, sex, pregnancy, disability, or other protected characteristics. An AI trying to be friendly might write "we love bringing on energetic young talent" or "this would be a great role for a mom returning to work," and both are the kind of language that creates discrimination exposure regardless of intent. He removes them entirely; recruiting messages should speak to skills and the role, never to who the person is.

He applies the same care to accommodation and ADA-adjacent phrasing. He never lets a draft ask about a disability or a medical condition in outreach, and when accommodations come up legitimately, such as in scheduling, he uses neutral, inviting language like "let me know if you need any accommodations for the interview" rather than anything that probes for a diagnosis. When in doubt on any compliance question, Devon routes the wording past his HR or legal partner rather than guessing, because the AI is not a source of legal truth and will state confident wrong things about employment law as readily as it invents company names.

The Three Checks the Risk Passes Miss

The five risk passes catch what can hurt you. Three further checks decide whether the message actually works, and Devon runs them as a second, quicker sweep. The first is authenticity: does this sound like it came from a person, or from a robot? He looks for a genuine human voice he could imagine using in conversation, for anything overly formal or corporate that does not match how he actually talks, for anything salesy enough to make him cringe, and for anything that over-promises or simply sounds insincere. Authenticity is hard to fake, and candidates feel the difference between genuine and templated even when they cannot name it. Reading aloud is the test here too: if you would not say it that way to someone, rewrite it until you would.

The second is company alignment: does this message represent the organization well? Devon checks whether it describes the mission and values accurately, whether anything in it contradicts the actual culture or hiring brand, and whether it matches how the company wants to be perceived as an employer. The practical test is to imagine the message being forwarded to the CEO or the hiring manager. Would they feel good about it going out in the company's name? If not, edit until they would. This is employer-brand protection: a message that misrepresents the company, or makes promises it cannot keep, damages trust that took years to build and is charged to a team that never saw the draft.

The third is conversion likelihood: will a good candidate want to respond? Devon checks for a clear call to action so the candidate knows what he is asking them to do, for an easy way to reply, for genuine interest generated without pressure or obligation, and for the right length, since too long goes unread and too short reads as low effort. He also looks for anything that would make someone ignore it: typos, generic language, a wrong name. Conversion here is not manipulation. It is the observation that if a message is accurate, authentic, well-toned, and company-aligned, conversion usually takes care of itself. The verification step is to step back and read the message from the candidate's chair, asking whether you would respond to it.

Editing Directly Versus Asking for a Revision

Once the passes surface what is wrong, the editing process has three steps. First, identify what needs changing by going through the checks and noting what failed and what merely needs improvement. Second, edit directly, which covers most of what you will find. Third, ask the AI to revise only when a direct edit would be more work than a rewrite.

Small, specific corrections Devon makes himself, because asking the AI to re-draft a whole message to fix one wrong fact risks introducing two new ones. Changing "your work on Python frameworks" to "your work on FastAPI" is a fact correction that takes five seconds. Changing "we're excited to chat" to "we'd love to chat" is a tone adjustment. Changing "you'd be perfect for this role" to "this role might be interesting to you" removes an oversell. Shortening a bloated paragraph, deleting a condescending phrase, and adding a specific detail from your own research are all faster by hand and keep him in control of the exact wording he is signing.

He reserves AI revision for genuine structural rewrites, and when he uses it he asks for a specific change rather than a vague improvement: "the tone feels too formal, make this warmer while keeping it professional," "this paragraph is too long, condense it to one or two sentences," or "revise this to sound more like a peer-to-peer conversation." Crucially, when he does ask for a revision, he runs the new version back through every check, because a fresh draft is a fresh opportunity for a fresh hallucination. The verification workflow is not a gate you pass once; it is the standard every version meets before it ships.

Anti-Patterns

The first is sending without verification: the AI drafts a message, you read it quickly, it looks good, you send it. It fails because you have not actually verified accuracy, tone, or company alignment, which means you put your name on a message you did not fully review. The failure is invisible until the one time the draft contained an invented employer, and by then it is in the candidate's inbox. The defense is mechanical rather than motivational: run the checklist every time. It takes two to three minutes and prevents the embarrassing errors that are expensive to unwind.

The second is over-editing to perfection: you adjust the tone three times, rewrite the opening four times, and rework the call to action twice, and the message ends up technically flawless and completely stiff. It fails because perfect sounds inauthentic, and authenticity is what you were optimizing for in the first place. Good enough and human beats polished and lifeless. The defense is to let the checklist define done. Once a message passes the checks, send it and stop editing.

The third is not catching hallucinations: the AI writes "I saw your open source work on project X" when you never verified the candidate had open source work at all, you send it, and the candidate calls you out for not doing real research. It fails because you have damaged your credibility and your recruiting reputation with a person who now has a story to tell about your company. The defense is the accuracy pass done seriously: verify every specific fact, do the research before you draft rather than hoping the model supplies it, and read every draft specifically hunting for details you cannot source.

Practice

These build on each other. The first three take a few minutes; the last two are worth doing over a week of real work.

  • Verify a draft. Take an AI-drafted message, real or hypothetical, and run the full checklist: accuracy, authenticity, tone, company alignment, and conversion likelihood, plus the personalization, promises, and protected-class passes. For each, note what passes and what needs work.
  • Edit for tone. Take a message that feels slightly off and edit it directly, without asking the AI to revise. Change three to five specific phrases to adjust the register, and write down what you changed so the pattern becomes visible.
  • Practice the edit-versus-revise decision. Take three problems with an AI-drafted message and decide for each whether to fix it by hand or ask for a revision. The decision itself is the skill.
  • Run the checklist across a batch. Take three AI-drafted messages and check each one. How many pass everything immediately? How many need editing? What is the most common issue across the three?
  • Document a before and after. Draft a message with AI, review and edit it with the checklist, then write a paragraph on what you changed and why. The gap between the raw output and your final version is the value you are adding, and seeing it written down is what makes the habit stick.

Reflection

  • When you receive recruiting messages, what makes you take them seriously, and what makes you delete them immediately? How should that inform the way you verify your own outreach?
  • What is the biggest risk to your recruiting brand from AI-drafted messages: inaccuracy, tone, over-promising, or something else? What would you check first?
  • How long would the checklist actually take you on a typical message, and is that time investment worth it at your volume?
  • Which of the checks do you most often fail, and what would change if you fixed only that one?
  • What is one specific improvement you could make this week to how you verify outreach before sending?

Glossary

  • Accuracy. Whether the facts in a message are correct: does it accurately represent the candidate's background, the role, and your company?
  • Authenticity. Whether a message sounds like it came from a real person rather than a machine. Authentic messages get responses; inauthentic ones get deleted.
  • Hallucination. When AI invents or assumes facts you did not provide and that may not be true. Always verify specific claims in AI drafts.
  • Tone. The emotional register of a message. Appropriate tone matches the candidate type, the situation, and your company's culture.
  • Company alignment. Whether a message accurately represents and respects your company's mission, culture, and values.
  • Conversion likelihood. Whether a good candidate would want to respond, given the clarity of the ask, the ease of replying, and the length and quality of the message.
  • Merge field. A template placeholder such as a first name or role title that is filled from the ATS record at send time, and that must be checked in the rendered message rather than the template.

Closing

AI-drafted messages are tools, not finished products. Your job is to review, verify, and refine until the message represents you and your company well, and that quality control is what separates recruiting that scales from recruiting that damages your brand at scale. Devon's near-miss cost him eight seconds of attention and taught him a workflow he has used on every message since.

The way to build the habit is to use the checklist on every piece of outreach for a week and time how long it takes, which is almost always less than you expect. Identify the check you fail most often, whether that is accuracy, tone, or company alignment, and focus your attention there. One small improvement in your verification process compounds across every message you send, and verification is where AI-assisted recruiting becomes professional recruiting.

Key Takeaways

  • You own every word the AI drafts. The candidate experiences one recruiter and one brand, not a human-AI collaboration. Read each draft asking whether you can stand behind every specific claim, not whether it reads well, because fluent and confident is exactly what a fabricated detail looks like.
  • Run five risk passes in order of damage. Factual grounding, personalization tokens, tone fit, compliance promises, and protected-class language. Check the highest-risk, hardest-to-undo problems first; the full sweep takes two to three minutes and saves far more in cleanup.
  • Treat every impressive specific as guilty until grounded. Company names, project names, metrics, tenure, and funding stage are where models invent. If a flattering detail is in the draft and you cannot point to your notes or the ATS as its source, the AI made it up and it comes out.
  • A wrong opening reference deletes the whole message. Citing the wrong employer or the wrong project tells the candidate no real research happened, and no amount of good writing after it recovers the credibility.
  • Verify the rendered message, not the template. Leftover placeholders, a previous candidate's name, mismatched role titles, and guessed pronouns all signal carelessness at the worst possible moment. The ATS is the source of truth, and you check what actually merged.
  • Match tone to the person and the moment. A rejection needs warmth and brevity, a senior passive candidate needs respect for their time, an active early-career candidate can take more energy, and the register should fit your company's culture. Read it aloud and ask whether the recipient would feel respected or sold to.
  • Strip promises you are not authorized to make. Compensation matches, permanent remote status, start dates, and offer timelines are commitments a candidate can rely on. Replace them with accurate, non-binding language until the hiring manager and the formal offer confirm them.
  • Remove protected-class and probing accommodation language. Friendly-sounding references to age, parental status, disability, or other protected characteristics create real exposure regardless of intent. Speak to skills and the role, keep accommodation language neutral and inviting, and route anything uncertain past HR or legal rather than trusting the AI on employment law.
  • Also check authenticity, company alignment, and conversion. Would you say this out loud, would your CEO be glad it went out under the company's name, and is there a clear ask a good candidate would actually want to answer?
  • Edit small fixes by hand, re-verify any AI rewrite. Hand-edit single facts, over-promises, and tone slips to stay in control of the wording you sign. Reserve AI revision for true structural rewrites, ask for a specific change, and run every new version back through the checks.
  • Perfect is the enemy of good. Over-editing produces a technically flawless message that sounds like nobody wrote it. Once a message passes the checklist, send it.

Frequently Asked Questions

Three minutes per message is a lot at my volume. What can I safely skip? Nothing in the compliance and protected-class passes, ever, because those are the ones that create exposure rather than embarrassment. What you can compress is the checking, not the standard. Draft from better inputs so there is less to catch: give the model only facts you have verified, tell it explicitly not to add details, and keep your prompts specific enough that it has no gaps to fill. A draft built from grounded notes needs a much shorter accuracy pass than a draft built from three lines and an invitation to be impressive.

Can I ask the AI to check its own draft for hallucinations? Not as your verification step. The model has no access to your notes or your ATS unless you put them in front of it, and it has no independent way to know which of its own sentences were invented, so a self-check produces confident reassurance rather than evidence. What does work is narrowing what it can invent in the first place: supply the facts, ask for a draft that uses only what you supplied, and then verify against your two sources of truth yourself. Verification is a lookup against a record, and the model does not have the record.

How specific should feedback in a rejection be, given the compliance passes? Specific about the job requirements and the evidence, never about the person. A reason tied to a documented criterion is defensible and useful to the candidate. Anything that touches a protected characteristic, or any speculation about fit you cannot trace to a written requirement, comes out in the fifth pass regardless of how kindly it was phrased. If you find the feedback hard to write without straying, that difficulty is usually telling you the evaluation criteria were not written down clearly enough, which is a problem upstream of the message.

The AI keeps writing better prose than I do. Should I really be editing it down? Yes, when the polish is buying inaccuracy or a register you would not use. The goal is not the best-written message; it is the message most likely to make a real candidate want to talk to you, and those diverge more often than they converge. A slightly plainer sentence you can defend beats an elegant one you cannot source, and a message that sounds like you beats one that sounds like a brochure. Keep the model's structure and rhythm where they help, and overwrite the parts that would not survive a candidate reading them closely.