Gloat
Gloat is an AI-powered internal talent marketplace and "agentic HR" platform that matches an employer's existing employees to internal job openings, gigs, projects, mentorships, and learning based on inferred skills and career goals.
§ 01 — Score breakdown
§ Score breakdown
Category scoring
Weighted contribution shown to the right of each bar.
- 01
Article 11 Technical Documentation
Weight 20%48
+9.6
- 02
Bias Audit Transparency
Weight 18%38
+6.8
- 03
FRIA Support
Weight 15%28
+4.2
- 04
Data Governance Disclosure
Weight 15%58
+8.7
- 05
Human Oversight Design
Weight 12%62
+7.4
- 06
Post-Market Monitoring
Weight 12%42
+5.0
- 07
Customer Documentation
Weight 8%62
+5.0
§ 02 — Strongest · weakest
Strongest category
Customer Documentation
Raw score 62 · contributes 5.0 to total.
Weakest category
FRIA Support
Raw score 28 · contributes 4.2 to total.
§ 03 — Cited evidence
Download diligence record→§ Evidence
Cited per category
Every score is backed by at least one cited piece of evidence.
§ 04 — Editorial notes
Company overview
Gloat was founded in 2015 (originally as Workey) by Ben Reuveni, Danny Shteinberg and Amichai Schreiber, is headquartered in New York with a major engineering presence in Tel Aviv, and operates through the entity named in its privacy policy as Gloat Ltd. It raised a $57M Series C led by Accel (2021) and a $90M Series D led by Generation Investment Management (2022), and sells to very large enterprises including Unilever, HSBC, Mastercard, PepsiCo, Nestlé, Schneider Electric and Standard Chartered. The core product deconstructs roles and projects into skills and matches them against an employee knowledge graph; in March 2026 Gloat launched "Gloat Agentic HR", layering workforce agents and a rules-extraction Governance Engine on that graph, with integrations into Workday, SuccessFactors, Oracle HCM, Microsoft Teams, Slack and Copilot. Pricing is unpublished and the deployment profile is unambiguously enterprise.
Regulatory exposure
Gloat's exposure is unusual in that it sits on the internal-mobility and promotion side of employment — which the same statutes cover explicitly. EU AI Act Annex III(4) captures AI used for promotion, task allocation and evaluation in work relationships, so Gloat's matching, skills inference and project allocation likely make it a provider of a high-risk system with Article 11 documentation, Article 10 data governance, Article 14 oversight and Article 72 post-market monitoring duties, and give EU customers Article 27 FRIA duties. NYC Local Law 144 defines an employment decision to include screening employees for promotion, so US customers surfacing internal candidates in New York City may need an annual independent bias audit — and Gloat publishes none. Illinois HB 3773 (in force January 2026) expressly reaches AI used in promotion and selection for training, and Colorado SB 24-205 treats promotion as a consequential decision with developer disclosure duties. The strongest mitigation is genuine: Gloat's end-user notice states that "Automated decisions without human involvement are not made on the Platform," which materially limits Article 22 and AEDT-style risk. The gap is evidentiary rather than conceptual — Gloat asserts fairness practices without publishing anything a regulator or deployer could inspect.
Path to a higher score
The highest-value move is publishing an actual algorithmic fairness audit: Gloat already claims "third-party audits" and "continuous self-monitoring of models" but names no auditor, date, methodology or result, so commissioning a named independent audit (Warden AI, Holistic AI, BABL AI, DCI or ORCAA) covering promotion and internal-mobility matching and posting a downloadable summary would move bias audit transparency from the high 30s toward 70+. Second, an Annex III-oriented technical pack — a system card with intended purpose, model description, known limitations, accuracy metrics and instructions-for-use, plus ISO/IEC 42001 alongside the existing ISO 27001 family. Third, EU AI Act deployer material: an Article 27 FRIA template and a provider-versus-deployer obligation split would lift the weakest score on the board. Finally, ungating — the compliance portal sits behind login approval and the help center behind SSO, so a public trust page exposing certifications, a subprocessor list, a DPA and a model-update changelog would convert existing internal maturity into scoreable public evidence at low cost.
§ Compare
Build any comparison→Gloat against its nearest-scoring peers.
In Candidate sourcing AI.
Conflicts of interest
No vendor pays for placement, scoring, or removal. Casework — the consulting firm that operates this directory — provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.
Casework has no commercial relationship with this vendor.