Agent gateway

Obligations for AI agent operators

What we expect when your AI agent accesses JobsAI on a candidate's behalf - in line with the EU AI Act.

JobsAI lets candidates use their own AI agents (via OAuth2 + MCP). Your agent is a separate AI system that you operate; these rules keep acting on a candidate's behalf transparent, auditable, and respectful of their autonomy.

Label AI-generated content

If the agent generates a cover letter or other text, set the coverLetterAiAssisted flag on submission. Both the employer and the candidate must know the content was AI-made (AI Act Art. 50).

Respect the candidate's consent envelope

Act only within the granted scope, audience and validity of the signed envelope. Stop immediately on revocation. Sending messages (messages:write) requires a separate second consent.

Do not send special-category data

Do not pass GDPR Art. 9 special-category data (health, origin, religion, sexual orientation, etc.) via free text. Violations can lead to suspension of the agent's access.

Pass the AI screening notice to the candidate

The get_job call returns an ai_screening_disclosure block with model-card links and the candidate's rights. Before deciding to apply, surface it to your user (AI Act Art. 26(7)).

Honour scopes, rate limits and spend caps

Do not exceed the granted scopes or rate limits. Breaches are rejected at the API boundary and recorded in the audit trail.

Your own obligations as an AI provider

Your agent's transparency to its user and any general-purpose-model (GPAI) obligations are yours. JobsAI logs every call (AgentActionLog, AgentTokenAudit) for both sides' auditability.

This overview is not legal advice. The AI Act does not address agents separately - the standard AI provider and deployer roles apply.