Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Assisted Document Redaction for Access to Information Requests

Enforcement

What it collects that can identify you

Sensitive personal information
Identifiable data
  • In production, the tool will process government documents containing personal information about individuals (e.g. names, addresses, and other identifiers appearing in ATIP-subject records). During development only non-production and publicly available documents are used.
Sensitive personal information
Identifiable data
  • Production documents processed by this tool may contain Protected B or higher classified information, which can include health, financial, or other sensitive personal data subject to exemption under the Access to Information Act or Privacy Act.
Run by
National Defence (DND)
Where
No fixed location
Kept
Not stated by the Helpful Places.
Shared with
Accountable organization

What it is for

This tool uses AI models to automatically identify and redact sensitive information in government documents before they are released in response to Access to Information and Privacy (ATIP) requests at National Defence. A human reviewer remains in the loop for every decision. The system is currently in development and not yet in production use; when deployed, it will process documents containing personal information. Members of the public whose information appears in released documents may be affected by redaction decisions made with AI assistance.

What it collects and what happens to it

Data taken in

Sensitive personal information
Identifiable data
  • In production, the tool will process government documents containing personal information about individuals (e.g. names, addresses, and other identifiers appearing in ATIP-subject records). During development only non-production and publicly available documents are used.
Sensitive personal information
Identifiable data
  • Production documents processed by this tool may contain Protected B or higher classified information, which can include health, financial, or other sensitive personal data subject to exemption under the Access to Information Act or Privacy Act.

Processing

Classification & Prediction
  • The tool applies multiple AI classification models to label text spans within documents as either releasable or requiring redaction under applicable exemption categories.

What it does

Sensing (Perceptive AI)
Human decides
  • Multiple AI models read document text to detect and flag sensitive or classified information for redaction. A human reviewer validates every proposed redaction before it is applied.
Deciding (Analytical AI)
Human decides
  • The system classifies text spans as sensitive or releasable, producing a redaction recommendation for each passage. Final decisions rest with GC employees acting as human-in-the-loop reviewers.

Outputs

A recommendation or prediction
Anonymized data
  • The system outputs redaction recommendations — proposed passages to withhold — for each document. These are advisory; a GC employee makes the final redaction decision. The recommendations themselves do not identify individuals beyond what is already in the source document.

Run by

National Defence (DND)
  • The Department of National Defence is the Government of Canada institution deploying this AI tool to assist staff with Access to Information and Privacy (ATIP) document redaction workflows.

Government of Canada AI Register — entry 2526-DND-MDN-003

Built by

Government of Canada
  • The system is developed by the Government of Canada itself, with no external vendor identified in the register entry.

Government of Canada AI Register — entry 2526-DND-MDN-003

Kept for

Not stated by the Helpful Places.

Shared with

Available to the accountable organization
  • Output redaction recommendations and processed documents are accessible to GC employees at National Defence who administer ATIP requests. No information about third-party access is provided in the register entry.

Stored

Not stated by the Helpful Places.

How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Be Informed of AI UseThe register entry notes that AI use is not currently disclosed to users (members of the public submitting ATIP requests). Individuals whose information is processed by this system are not presently informed that AI is involved in the redaction process. This is a transparency gap the deployer should address before moving to production.
  • Right to Algorithmic TransparencyMembers of the public who receive redacted documents produced with the assistance of this AI system currently have no mechanism to learn that AI was involved. The Government of Canada's Directive on Automated Decision-Making requires transparency about the use of automated tools in administrative decisions; this right should be operationalized before production deployment.
  • Right to a Human ReviewHuman review is built into the system design — a GC employee validates every AI-proposed redaction before it is applied. Members of the public who disagree with redaction decisions in released documents may seek review through standard ATIP complaint processes with the Office of the Information Commissioner or the Privacy Commissioner of Canada.

Risks and safeguards

  • Civil liberties harmOver-redaction could suppress information that citizens are legally entitled to receive under the Access to Information Act, limiting transparency and democratic accountability. Under-redaction could expose personal or sensitive information, violating privacy rights.Safeguard: Human-in-the-loop review is built into the workflow — no redaction is applied without GC employee validation. The system is currently in development and not yet processing real personal information in production.
  • Reputational harmIncorrect classification of content as non-sensitive could result in the inadvertent release of personal information about named individuals, causing reputational harm.Safeguard: The human-in-the-loop model ensures a GC employee reviews all AI-proposed redactions before documents are released. Training and testing use only non-production or publicly available documents during development.