Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Assisted Data Analysis and Research for Aviation Security Staff

Research & Development · Planning & Decision-making

What it collects

Operational data
Anonymized data
  • Internal CATSA documents, datasets, and organizational data used as the retrieval corpus for the RAG model. The register describes this as supporting 'data analysis' and 'data talking' from internal sources.
About behaviour
Anonymized data
  • Employee query inputs typed into the system — the prompts and questions posed by CATSA staff during their use of the assistant. These constitute behavioural interaction data processed at runtime.
Run by
Canadian Air Transport Security Authority (CATSA)
Where
No fixed location
Kept
Not stated by the Helpful Places.
Shared with
Accountable organization
Your copy
You cannot see the data it holds about you. What you can do

What it is for

This system gives Canadian Air Transport Security Authority (CATSA) employees an internal generative AI assistant that can answer questions about internal documents and data using a technique called Retrieval-Augmented Generation (RAG). It is designed exclusively for internal government staff and is not used to make decisions about the travelling public. The system is currently in development and is intended to speed up research and data analysis tasks for CATSA employees.

What it collects and what happens to it

Data taken in

Operational data
Anonymized data
  • Internal CATSA documents, datasets, and organizational data used as the retrieval corpus for the RAG model. The register describes this as supporting 'data analysis' and 'data talking' from internal sources.
About behaviour
Anonymized data
  • Employee query inputs typed into the system — the prompts and questions posed by CATSA staff during their use of the assistant. These constitute behavioural interaction data processed at runtime.

Processing

Language Models
  • The system is built on Retrieval-Augmented Generation (RAG) language models that combine document retrieval with generative text capabilities to answer internal staff queries.
Search & Retrieval
  • The RAG pipeline retrieves relevant passages from internal CATSA documents before passing them to the language model, grounding responses in authoritative organizational content.

What it does

Creating (Generative AI)
Human decides
  • The system uses a Retrieval-Augmented Generation (RAG) model to produce text responses to employee queries. A human employee reviews and decides how to use the generated output.
Understanding (Semantic AI)
Human decides
  • The RAG component retrieves semantically relevant passages from internal documents to ground the generative model's responses in authoritative source material.

Outputs

Generated content
Anonymized data
  • Text responses and analytical summaries generated by the system in response to employee queries, grounded in retrieved internal documents. Outputs are advisory and reviewed by the requesting employee.

Run by

Canadian Air Transport Security Authority (CATSA)
  • CATSA is the federal agency accountable for deploying this internal generative AI environment for use by its government employees.

Government of Canada AI Register — CATSA GPT

Built by

Not stated by the Helpful Places.

Kept for

Not stated by the Helpful Places.

Shared with

Available to the accountable organization
  • Outputs and interaction logs are accessible to CATSA as the accountable organization operating this internal system. The system is scoped exclusively to GC employees.
Not available to me
  • The system is for internal government use only. Members of the travelling public and general citizens do not have access to this system or its outputs.

Stored

Not stated by the Helpful Places.

How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Algorithmic TransparencyCATSA employees using this system are informed that it is an AI-powered assistant. Information about how the system works is available through CATSA's internal governance processes. The system's existence is publicly disclosed through the Government of Canada AI Register.
  • Right to Be Informed of AI UseCATSA employees are informed that the system is an AI environment before use. The Government of Canada AI Register provides public notice of the system's existence and its internal-use-only scope.

Risks and safeguards

  • Psychological harmRAG-generated responses may contain hallucinations or confidently stated inaccuracies that mislead employees, potentially causing poor decisions on operational matters.Safeguard: The system is positioned as advisory; employees are responsible for verifying outputs before acting. The secure, closed environment limits exposure to only trained internal users.
  • Reputational harmIf the system produces inaccurate outputs that are acted upon, CATSA's institutional credibility or the reputation of employees could be harmed.Safeguard: The system operates in a secure internal environment with access limited to GC employees, reducing public-facing exposure. Outputs are advisory and subject to human review.