DeepMind's "Don't Share This Doc" Form Is Outbound Sourcing in Drag
Google DeepMind quietly told AI safety candidates to bypass Google's own AI hiring filter. Here is why that memo is an argument for outbound sourcing.
On August 10, 2026, Bloomberg reported that Google DeepMind's AGI Safety and Alignment Team is circulating a Google Doc, marked "PLEASE DO NOT SHARE THIS DOC WIDELY," telling candidates to fill out a special form so their CVs bypass Google's own AI-powered application filters. The team's own words: the system has "a non-trivial probability your CV will be screened out incorrectly." Google, meanwhile, sells that exact category of tool to enterprise HR through Workspace and Gemini. Read the memo again. It is not a bug report. It is a market signal.
What DeepMind actually shipped
DeepMind built a private, human-only channel for its highest-stakes hires, which is structurally identical to outbound sourcing. The bypass form routes named candidates directly to hiring managers on the AGI Safety team, skipping recruiter review and the ATS entirely.
Three quotes from the leaked doc matter:
- "We have an applications system with a non-trivial probability your CV will be screened out incorrectly or take too long to reach us."
- Filling out the form "makes sure that a real human on the team will get to see your application."
- "A real human will read these. These humans get really tired of reading LLM answers, because they all sound very samey."
A Google DeepMind spokesperson told Bloomberg the team "set up a special form to go past the recruiter review, and get their resumes direct to the people on the team," while denying the systems filter candidates out. Both things can be true. The team built the bypass because the funnel loses people, and the fix is not a better model. The fix is a human reading the actual work.
That is what outbound sourcers have always done: find the person, verify the work, deliver them to a hiring manager. DeepMind reinvented outbound and called it a Google Form.
Why a 10% false-negative rate would gut the pool
For roles this narrow, an AI hiring filter with even a small false-negative rate destroys a meaningful fraction of the entire hireable universe. In Refolk's index, only about 30 people across the US and UK carry an exact-title match for "AI Safety Researcher," "AI Safety Engineer," or "Alignment Researcher." That is not a funnel. That is a guest list.
| Segment | Count | Source |
|---|---|---|
| AI Safety / Alignment titles, US + UK | 30 | Refolk index |
| Same titles globally with RL/ML/PyTorch skill | 25 | Refolk index |
| New York based (subset of US+UK) | 4 | Refolk index |
| London based (subset of US+UK) | 3 | Refolk index |
| San Francisco based | 2 | Refolk index |
| Oxford based | 2 | Refolk index |
| US companies using resume-scanning programs | 75% | HBS Hidden Workers |
| Fortune 500 using resume-scanning programs | 99% | HBS Hidden Workers |
| Executives admitting systems screen out qualified candidates | ~90% | HBS Hidden Workers |
| US "hidden workers" filtered by automated systems | 27M | HBS / Fuller & Raman |
The mechanism is arithmetic. When your total addressable pool is 30 profiles, a screening tool that misroutes one in ten strong CVs is not an efficiency loss. It is a strategic own-goal. DeepMind's team almost certainly ran that math and concluded that any filter, however good, was strictly worse than a human inbox.
Google is short the product it sells
Google's HR-facing pitch and its internal behavior contradict each other. Workspace materials tell HR departments to use Gemini for drafting job descriptions, writing candidate outreach, summarizing interview threads, and, per a Workspace page for HR teams, running "high-volume workflows, from resume review to policy FAQs." The AGI Safety team, staffed by people who understand these models better than any enterprise buyer, refuses to trust them for its own hires.
If Gemini-for-HR resume review worked well enough for elite technical hiring, DeepMind would dogfood it. It does not. They do not. Founders evaluating AI screening vendors should treat that as the single most important reference customer signal of 2026: the vendor's own most defensible team routes around the product.
The world's most sophisticated ML org just picked human sourcing over its own AI screening stack. Copy the homework.
Inbound signal has collapsed on both sides
Applications are now low-signal by construction, because candidates and employers are both running LLMs at the same funnel. DeepMind's complaint that LLM answers "all sound very samey" is the employer-side symptom. Greenhouse's 2025 AI in Hiring report found 41% of US job seekers now use "prompt injections," hidden text in resumes designed to beat ATS keyword filters. That is the candidate-side symptom.
The arms race has a predictable equilibrium:
- Candidates use LLMs to mass-apply and to smuggle keywords past filters.
- Employers use LLMs to summarize and score the resulting applications.
- Both sides lose fidelity. The application no longer reflects the candidate; the score no longer reflects the application.
- The only remaining high-signal channel is direct evidence of work: GitHub commits, papers, employer history, shipped products.
That is exactly the ground outbound sourcing stands on, and it is the exact gap Refolk closes. You describe the person you actually want in plain English, across GitHub, LinkedIn, and the open web, and get a ranked shortlist keyed to verified work rather than self-reported keywords.
Where the real AI safety pool actually sits
The hireable pipeline for AI safety talent is not at FAANG; it clusters at labs, residencies, and university programs. In Refolk's index, the top current employers for AI-safety-titled candidates with RL/ML/PyTorch skills include Algoverse, LASR Labs, Snap, Pinterest, and AI Safety Camp. That is not the org chart most recruiters would guess.
Concrete implications for anyone sourcing AI safety engineers in 2026:
- Residencies are the pipeline. LASR Labs, AI Safety Camp, and ERA Cambridge are effectively the feeder schools. Track cohort rosters, not job boards.
- Geography is thin and knowable. 4 in New York, 3 in London, 2 in San Francisco, 2 in Oxford. A single well-run coffee tour in each city covers a majority of the addressable pool.
- Adjacent titles matter more than exact matches. RL researchers at Snap or Pinterest with a public safety-adjacent side project are functionally in the pool even if HR filters would not code them as such.
- The "AI safety researcher" title itself is trailing. Many of the strongest candidates carry ML engineer or research scientist titles and route into safety work through papers and residencies.
This is the mechanical reason the outbound vs inbound debate is over for pools this thin. There is no inbound funnel to optimize. There are 30 people, they mostly know each other, and the winning move is to talk to them.
The legal math just flipped for small teams
AI-hiring-filter compliance load is now large enough that outbound is cheaper than inbound-plus-AI-screening once you count risk. Two data points force the reprice:
- Workday is defending a lawsuit alleging its AI hiring systems screen applicants based on race, age, and disability. Workday denies the claims and says humans make hiring decisions. The case still creates discovery exposure for every buyer running similar workflows.
- The EU AI Act, finalized in 2024, classifies AI hiring tools as "high-risk" systems, subject to strict transparency, accuracy, and human-oversight requirements. That means documentation, audit trails, and bias testing, per role, per model version.
For a 20-person startup, the fully loaded cost of using an AI resume screener now includes counsel review, an audit trail, and a plausible plaintiff. Outbound sourcing, one human identifying named candidates and reaching out, carries essentially none of that load. The math that made inbound-plus-filter attractive in 2020 has inverted.
What to copy from DeepMind's memo
If DeepMind's bypass form is outbound in disguise, the practical playbook is to skip the disguise. Five moves any founder or head of talent can run this quarter:
- Name the pool. Before writing a JD, write a list. If you cannot get to 100 named candidates, you do not have a hiring problem; you have a sourcing problem.
- Kill the AI screener for senior technical roles. For any role where the addressable pool is under a few hundred, the false-negative cost dominates the throughput benefit.
- Build a bypass channel on purpose. A public "email me directly" line from the hiring manager, on the JD, does what DeepMind's form does, without the leaked-doc awkwardness.
- Source against verified work, not keywords. GitHub activity, paper authorship, and employer history are harder to game than a resume. Refolk indexes exactly those signals against plain-English queries.
- Read applications like DeepMind reads them. A human, tired of LLM slop, looking for one paragraph that could not have been written by a model. If you cannot tell the difference, the role is too generic.
The uncomfortable read for HR software buyers
75% of US companies and 99% of the Fortune 500 use resume-scanning programs, and roughly 90% of executives admit those programs weed out qualified candidates. Most large employers already know their filters miss people. They keep them for throughput. DeepMind's memo is what happens when a team cannot afford throughput logic because the pool is 30 people.
Joseph Fuller, who ran the HBS Hidden Workers study, put the mechanism plainly: "The effort to make the process very efficient is creating a significant amount of the shortage that they complain about." Cathy O'Neil put it more sharply in Weapons of Math Destruction: "Algorithms don't just reflect our biases. They launder them." The DeepMind memo is the operational admission that both are correct, from the org with the most to lose by admitting it.
For anyone running a serious search, particularly for sourcing AI safety engineers or any pool measured in dozens rather than thousands, the argument is settled. The market leader in machine learning just told its candidates, in a doc it did not want you to see, to go around the machine.
FAQ
Does the DeepMind memo mean all AI resume screening is broken?
No. It means AI resume screening has a false-negative problem that scales with how narrow and senior your pool is. For high-volume, low-specificity roles the throughput case can still hold. For roles where the addressable universe is measured in dozens (AI safety, alignment, senior infra) the math flips fast. DeepMind's team is the extreme case, but the same logic bites at 300-person pools too.
Is outbound sourcing actually cheaper than inbound plus AI screening?
Once you price in compliance risk, increasingly yes for small teams. Inbound-plus-filter carries EU AI Act documentation load, litigation exposure of the kind Workday is defending, and a hidden false-negative cost that gets larger as your pool gets smaller. Outbound shifts the cost from software and legal to sourcer hours, which is easier to control and easier to defend.
Where do you actually find AI safety candidates in 2026?
Residencies and small labs, not FAANG. Refolk's index shows the top current employers for AI-safety-titled talent with RL/ML skills include Algoverse, LASR Labs, Snap, Pinterest, and AI Safety Camp, with ERA Cambridge as a strong feeder program. Geographically, the US+UK pool clusters in New York (4), London (3), San Francisco (2), and Oxford (2). A plain-English query pointed at those employers and cities returns most of the addressable universe in one pass.
What is the one thing to change in my hiring process this week?
Add a bypass channel and mean it. Publish a direct email on senior role JDs, staffed by a hiring manager or founder, that skips your ATS entirely. That is the operational content of DeepMind's leaked doc, stripped of the "do not share" theater. If your best candidates are worth reading personally, tell them how to reach you personally.
Try it on your own search
Stop building boolean strings. Just describe the person.
Type one sentence and I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web live, then hand back a ranked shortlist with the reasoning behind every name. No filters to learn, no export to clean up, no sales call to sit through.
- One sentence in, a ranked shortlist out. No boolean, no filters, no seat to buy.
- Read live at search time, not from a database that went stale last quarter.
- Watch every step as it runs, and see why each name made the list.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
500 free credits on sign-up. No card, no demo call. See real searches.