AI-Assisted Data Analysis and Research for Aviation Security Staff
Research & Development · Planning & Decision-making
What it collects
- Internal CATSA documents, datasets, and organizational data used as the retrieval corpus for the RAG model. The register describes this as supporting 'data analysis' and 'data talking' from internal sources.
- Employee query inputs typed into the system — the prompts and questions posed by CATSA staff during their use of the assistant. These constitute behavioural interaction data processed at runtime.
- Run by
- Canadian Air Transport Security Authority (CATSA)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Accountable organization
- Your copy
- You cannot see the data it holds about you. What you can do
What it is for
This system gives Canadian Air Transport Security Authority (CATSA) employees an internal generative AI assistant that can answer questions about internal documents and data using a technique called Retrieval-Augmented Generation (RAG). It is designed exclusively for internal government staff and is not used to make decisions about the travelling public. The system is currently in development and is intended to speed up research and data analysis tasks for CATSA employees.
What it collects and what happens to it
Data taken in
- Internal CATSA documents, datasets, and organizational data used as the retrieval corpus for the RAG model. The register describes this as supporting 'data analysis' and 'data talking' from internal sources.
- Employee query inputs typed into the system — the prompts and questions posed by CATSA staff during their use of the assistant. These constitute behavioural interaction data processed at runtime.
Processing
- The system is built on Retrieval-Augmented Generation (RAG) language models that combine document retrieval with generative text capabilities to answer internal staff queries.
- The RAG pipeline retrieves relevant passages from internal CATSA documents before passing them to the language model, grounding responses in authoritative organizational content.
What it does
- The system uses a Retrieval-Augmented Generation (RAG) model to produce text responses to employee queries. A human employee reviews and decides how to use the generated output.
- The RAG component retrieves semantically relevant passages from internal documents to ground the generative model's responses in authoritative source material.
Outputs
- Text responses and analytical summaries generated by the system in response to employee queries, grounded in retrieved internal documents. Outputs are advisory and reviewed by the requesting employee.
Run by
- CATSA is the federal agency accountable for deploying this internal generative AI environment for use by its government employees.
Built by
Not stated by the Helpful Places.
Kept for
Not stated by the Helpful Places.
Shared with
- Outputs and interaction logs are accessible to CATSA as the accountable organization operating this internal system. The system is scoped exclusively to GC employees.
- The system is for internal government use only. Members of the travelling public and general citizens do not have access to this system or its outputs.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada Algorithmic Impact Assessment Register — CATSA GPT (2526-CATSA-ACSTA-009)Canadian Air Transport Security Authority, AI Register ID 2526-CATSA-ACSTA-009.
- AI registerGovernment of Canada AI Register — CATSA GPT
- Register entryPublished by the Helpful Places. Reference 81df1f93. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Algorithmic TransparencyCATSA employees using this system are informed that it is an AI-powered assistant. Information about how the system works is available through CATSA's internal governance processes. The system's existence is publicly disclosed through the Government of Canada AI Register.
- Right to Be Informed of AI UseCATSA employees are informed that the system is an AI environment before use. The Government of Canada AI Register provides public notice of the system's existence and its internal-use-only scope.
Risks and safeguards
- Psychological harmRAG-generated responses may contain hallucinations or confidently stated inaccuracies that mislead employees, potentially causing poor decisions on operational matters.Safeguard: The system is positioned as advisory; employees are responsible for verifying outputs before acting. The secure, closed environment limits exposure to only trained internal users.
- Reputational harmIf the system produces inaccurate outputs that are acted upon, CATSA's institutional credibility or the reputation of employees could be harmed.Safeguard: The system operates in a secure internal environment with access limited to GC employees, reducing public-facing exposure. Outputs are advisory and subject to human review.