Inspiration

Every Canadian has the legal right to request government records under the Access to Information Act but the Information Commissioner's own 2024-2025 report shows compliance dropping and departments spending millions fighting backlogs (CBSA alone got an extra $2.1M). We also learned the government has publicly asked for exactly this: automation tools and more consistent exemption decisions.

What it does

Redactor is an AI-assisted redaction system for Access to Information requests. It:

  1. Reads a government document and classifies text under specific ATIA exemption categories (personal information, cabinet confidence, advice/recommendations, and more), with a plain-language legal justification per redaction
  2. Runs an adversarial Leak-Tester agent that only sees the redacted output and tries to reconstruct hidden information from context — catching leaks that survive word-level redaction
  3. Runs a Consistency Engine that checks new redaction decisions against a corpus of past released documents, flagging cases where similar information was treated differently before
  4. Gives requesters a transparency panel showing their released document passed a leak check and a cross-request consistency check before reaching them

How we built it

Redactor is a web app with a document viewer and officer/requester dashboards. Gemini powers the core exemption classification, justification generation, and the Leak-Tester's reconstruction attempts. Tiger Data (Postgres + pgvector) stores redaction decisions, leak-risk scores, and embeddings for the consistency corpus. Auth0 handles officer vs. requester roles. We tested against real, publicly released ATI documents so we had ground truth to check our own output against.

Challenges we ran into

Legal exemption boundaries are genuinely fuzzy, the line between "advice or recommendations" and plain factual content is contested even in real ATIP case law, so getting consistent classification took a lot of prompt iteration. Building three interdependent components (core engine, leak-tester, consistency engine) with three people also risked a serial bottleneck, so we had to agree on shared data contracts up front and build against mocked outputs before the real pipeline was ready.

Accomplishments that we're proud of

We're proud we built a system that doesn't just redact but checks its own work two different ways attacking its own output for leaks and cross-checking it against real past decisions. We anchored every design choice to something the Information Commissioner had actually written in a public report, so the problem, and the fix, are both real. All three components integrated cleanly by demo time because we planned the contracts before writing code.

What we learned

We learned that the hardest part of "AI redacts a document" isn't detection, it's trust, an officer or requester needs to see why a decision was made and proof the system checked itself, not just a black-box output. We also learned a lot about how the ATIP process actually works, and how much of the current backlog is a resourcing problem the Commissioner has already flagged, not a hypothetical one.

What's next for Mr. Redactor

Expand exemption coverage to more sections of the Act, ground the classifier's justifications in real Information Commissioner rulings and Federal Court decisions (citation-backed reasoning instead of model opinion), and grow the consistency corpus across more departments so cross-request contradictions surface department-wide, not just within our demo set.

Built With

Share this project:

Updates

Submission history