AI-Assisted Classification of Child Sexual Exploitation Media
Enforcement · Safety & Security
What it collects that can identify you
- Images and videos depicting persons' bodies, including children and adults, sourced from lawfully seized digital storage devices, police submissions, and reports from partners such as NCMEC and CyberTip. The face-matching feature processes facial data to group individuals with similar characteristics across media in the same workspace.
Also collects operational data, which is anonymized data.
- Run by
- Royal Canadian Mounted Police (RCMP)
- Where
- No fixed location
- Kept
- Retained Not specified in AIA — governed by RCMP evidence retention policy and applicable legislation
- Shared with
- Accountable organization, 3rd parties
What it is for
Griffeye is a forensic tool used by RCMP investigators to sort and prioritize images and videos seized during child sexual exploitation investigations. It uses AI to automatically flag media likely to contain child exploitation material so that human investigators can focus their review on the most urgent content. All final categorization decisions are made by a trained human investigator — the AI serves only as a triage aid. The system processes lawfully seized evidence and does not connect to external networks during analysis.
What it collects and what happens to it
Data taken in
- Images and videos depicting persons' bodies, including children and adults, sourced from lawfully seized digital storage devices, police submissions, and reports from partners such as NCMEC and CyberTip. The face-matching feature processes facial data to group individuals with similar characteristics across media in the same workspace.
- Hash databases of known previously reviewed child exploitation material, used to match and de-duplicate media that has already been categorized, so investigators do not need to re-review content seen in prior investigations. Also includes EXIF metadata such as file paths, camera make/model, and timestamps embedded in media files.
Processing
- Trained classifiers analyze images and video frames to detect the presence of children, adults, sexual acts, nudity, and other defined visual categories. Object and image recognition is applied to group media by visual content for investigator review.
- Machine learning classifiers assign probability scores indicating whether media items contain child exploitation content, producing flagged groupings and priority rankings for human review. Hash matching against known-content databases complements the ML-based classification.
What it does
- The AI classifiers score and group media items by whether they appear to contain children, sexual acts, nudity, or other defined elements, producing a ranked priority list for human investigator review. The final categorization decision always rests with the human operator.
- The system processes raw image and video files, extracting embedded metadata (EXIF data) and applying computer vision to detect visual elements such as the presence of children, adults, or sexual content within media files.
Outputs
- The system outputs prioritized groupings of media items flagged as likely to contain child exploitation content, guiding the order in which human investigators review files. It also groups individuals across media using face-matching. These are advisory outputs — all final categorization determinations are made by human investigators.
- Hashes and associated metadata can be exported in PVIC format for sharing with partner agencies and compatible forensic tools, enabling intelligence sharing across law enforcement partners including NCMEC and other agencies.
Run by
- The RCMP deploys Griffeye through its National Child Exploitation Crime Centre (NCECC) Technical Unit to support investigators categorizing child sexual exploitation media evidence.
Built by
- Magnet Forensics is the vendor that developed and supplies the Griffeye Analyze CS and Di Pro tools, including the AI classifiers used for media triage.
Kept for
- Hashes and metadata derived from processed media are retained and may be exported for sharing. The AIA notes a Privacy Impact Assessment was completed collateral to the Five Eyes Hash Sharing Agreement. Specific retention durations are not stated in the AIA.
- Duration: Not specified in AIA — governed by RCMP evidence retention policy and applicable legislation
Shared with
- Outputs (media groupings, flags, categorization results, and audit trails) are available to authorized RCMP investigators and the NCECC Technical Unit. Access is controlled by a documented grant, monitor, and revoke permission process. The system operates in a closed environment with no internet connectivity during analysis.
- Hashes and associated metadata may be exported in PVIC format and shared with authorized law enforcement partner agencies (e.g., NCMEC, CyberTip, other LE agencies) as appropriate and authorized. Sharing is governed by a Five Eyes hash-sharing agreement reviewed by RCMP Legal, ATIP, and other internal stakeholders.
Stored
- The system operates within a closed environment with no internet or intranet connectivity during analysis. Data is controlled by the federal government (RCMP) and stored locally within RCMP systems, classified at Protected B/Protected C level.
- Duration: Not specified — governed by RCMP evidence retention policy
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada AI Register — Griffeye (RCMP)AI Register ID: 2526-RCMP-GRC-009; AIA Package ID: 89898244-aaae-4591-ba9b-fe5cd81d5924
- Policy documentGriffeye Algorithmic Impact Assessment (AIA) — Royal Canadian Mounted PoliceAIA version 0.10.0, Impact Level 2. Respondent: Sgt Tom Guineau, Technical Manager, NHQ/Tech Ops/SSIS/NCECC/Tech Unit.
- AI registerGovernment of Canada AI Register — Griffeye
- AI registerGovernment of Canada AI Register — Griffeye
- Register entryPublished by the Helpful Places. Reference 5507e30d. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseThe Government of Canada's AI Register and the published Algorithmic Impact Assessment disclose that the Griffeye system uses AI. As the system operates on lawfully seized evidence in a law enforcement context rather than on citizen-facing services, notice is provided through the AIA publication and departmental transparency mechanisms rather than direct notification to subjects.
- Right to a Human ReviewAll AI-generated media groupings and flags are subject to mandatory human review. No categorization of media as child exploitation material is made by the AI alone — a trained RCMP investigator must confirm every determination. The system enables human override of all system outputs and logs instances where overrides were performed.
- Right to Algorithmic TransparencyThe Algorithmic Impact Assessment for this system is publicly available on the Government of Canada Open Data portal, describing the system's role, data sources, and decision-making process. The AIA describes criteria used: classifiers evaluate whether images/videos contain children, adults, sexual acts, or nudity.
Risks and safeguards
- Psychological harmInvestigators are repeatedly exposed to traumatic child sexual exploitation material, risking psychological injury and occupational trauma.Safeguard: The system reduces unnecessary re-exposure by using hash matching to de-duplicate previously reviewed content, so investigators only confront new or unreviewed material. The AIA explicitly notes that reducing repetitive traumatic exposure to such media benefits investigator well-being.
- Reputational harmMisclassification by the AI could cause legitimate media to be incorrectly flagged as child exploitation material, or fail to flag actual exploitation material, potentially affecting investigative outcomes and the reputations of individuals whose devices are being examined.Safeguard: All AI outputs are advisory only — a trained human investigator confirms every categorization decision. The system does not make autonomous determinations about guilt or criminal content.