Statement

How Remit uses AI

Version 1.0 · last updated 6 September 2026

Remit’s position

AI assistance in Remit drafts, checks and cites. A person makes every decision: the scope decision, every risk rating, every approval, every signature and every submission to the DTA. Nothing the model produces becomes part of a record until a person accepts it.

This statement is written for the agency that uses Remit. Remit's own AI assistance is an AI use by the agency, so the agency may need to run the policy's threshold check on Remit, describe it in the agency's AI transparency statement, and satisfy its security and privacy advisers about what leaves the agency's systems. The facts below are the facts an assessing officer needs for each of those tasks. They describe the product as built and are not a verdict on scope or risk; those decisions are the agency's.

  • Human decision requiredA person makes every decision.
  • Quotes verified before displayEvery quote is checked against its source.
  • Every AI step loggedFull audit trail and versioning.
  • Works with AI assistance offEvery other feature still works.

Where AI assists, feature by feature

8 features
  1. 01Intake triage on a new use case
    What it does
    Reads a completed intake form, a project document or a typed description and proposes an answer to each of the five Appendix C threshold criteria, with the model's reasoning and a verbatim quote from the text, plus proposed register fields (name, description, product, technology type, domain, usage pattern) from Remit's controlled vocabularies.
    What is sent to the model
    The text extracted from the uploaded file or the typed description (at most 60,000 characters), the policy's own wording of each criterion, and the vocabularies. Nothing else about the agency or the register is sent.
    What comes back
    For each criterion a verdict of likely yes, possibly yes, unclear or likely no, its reasoning and a quote. A quote is shown only if it appears word for word in the source; verdicts are mapped conservatively (only 'likely yes' becomes Yes, only 'likely no' becomes No, everything else becomes Unsure).
    What the person does
    Sees each suggestion marked as a suggestion beside the question in the threshold wizard, and accepts, edits or discards it. Nothing is stored until the person records the scope decision, which then keeps what was suggested, what was recorded and what was changed.
    The limit
    The scope decision is the person's. The wizard works in full with AI assistance off. The uploaded file is kept as evidence only if the person chooses; otherwise it is used once and deleted, with an audit entry.
    Where in Remit: Use cases › New use case › Upload a document, or Describe it in your own words
  2. 02Drafting an assessment answer
    What it does
    Drafts an answer to one assessment question from the agency's own evidence for that use case, with a citation to the passage behind each claim, a list of the assumptions it made and any evidence gap it noticed.
    What is sent to the model
    The question, the DTA's guidance for it, the use case's register fields, and the passages retrieved from the evidence filed against that use case (its own and linked agency-wide documents) that best match the question.
    What comes back
    A draft answer with citations, assumptions and an evidence gap; on a risk question, a suggested rating with its reasoning, shown for consideration only. Each citation is checked against the indexed passage and counted as unverified if it does not match.
    What the person does
    Reads the draft and its citations, then accepts, edits or discards it. Only the accepted text is written to the answer, under the person's name.
    The limit
    The model never writes a rating. The rating fields are set by the person from the DTA's consequence and likelihood scales, and the matrix derives the result. One question at a time, on click; nothing runs in the background.
    Where in Remit: A question in the AI impact assessment › Draft with AI
  3. 03Register integrity check (the two model-based checks)
    What it does
    Reads the register records in the chosen selection together with excerpts of their evidence and points at contradictions: a register field that a document contradicts, and a scope answer the description does not support. Four further checks are rules in code and use no model.
    What is sent to the model
    For each use case in the selection: its register fields, its scope answers and excerpts of each linked document. Each document is capped (at most 20,000 characters, and a whole-register run shares a budget so that no document falls below 1,800 characters); a run sends at most 200,000 characters in total, and its step log states the cap used and any document that was cut.
    What comes back
    Findings, each with a severity, the place in the record it concerns and a quote from the document. Every quote is verified against the source text; a finding whose quote cannot be found is discarded and counted in the run log.
    What the person does
    Reads the finding with 'the record says' and 'the document says' side by side, opens the exact place in the record, and marks it resolved or dismisses it with a reason. Findings resolve themselves only when a later check no longer finds them.
    The limit
    The check never changes a record. It can be run over the whole register or one use case, and only by an administrator or the accountable official. The policy mandates no automated check; this is Remit's own assurance over the agency's compliance.
    Where in Remit: Governance › Register integrity › Run checks…
  4. 04Automatic checks
    What it does
    Runs the same register integrity check without a person starting it: on a daily or weekly schedule, or on one use case ten minutes after its record or evidence last changed.
    What is sent to the model
    Exactly what a manual run sends, for the selection and checks the administrator chose.
    What comes back
    The same findings, attributed everywhere to 'Remit, automatic' with the reason for the run.
    What the person does
    An administrator turns it on with a recorded reason and sets a monthly cap in US dollars on the estimated model cost; when the cap is reached the agency's automatic runs pause until the next month. Findings still need a person to resolve or dismiss them.
    The limit
    Off by default. Manual runs are never capped. Nothing automatic ever changes a record, and no email or message is sent; the overview's attention list and the sidebar count carry the signal.
    Where in Remit: Admin › Automatic checks
  5. 05Policy answers
    What it does
    Answers a question about the policy from the DTA's own published pages and documents, which Remit fetches and indexes itself, never from the model's memory.
    What is sent to the model
    The question and the numbered passages from the policy corpus that matched it closely enough. If too little matches, the question is refused before any model is called.
    What comes back
    A short answer written only from those passages, with quotes. Each quote is verified against its passage and dropped if it does not match. With AI assistance off, the matching passages are shown as the answer.
    What the person does
    Reads the answer beside the passages it came from, with a link to each source page, and can open the run's step log to see what was searched, sent and verified.
    The limit
    The corpus is public DTA material; no agency record is sent for a plain question. No second model provider and no external search service are used.
    Where in Remit: Learn › Policy answers
  6. 06Apply the policy to a use case
    What it does
    Reports what the policy requires of a chosen use case and what its record and evidence show, by reading them through a bounded set of read-only tools.
    What is sent to the model
    The question, then only what the model asks to read through six read-only tools: search the policy corpus, read the use case record, read its scope decision, list its evidence, read passages of one document, and list its open integrity findings. At most 8 tool calls per question; the budget is enforced in code.
    What comes back
    A report of requirements against evidence, with quotes. Every quote is verified against the tool output it claims to come from and dropped otherwise. Every tool call is written to the step log, the AI call record and the audit entry.
    What the person does
    Reads the report as input to their own assessment and can trace every statement to the record or document it cites.
    The limit
    The tools are read-only by construction. The loop cannot rate, decide scope, approve, change a record or submit anything.
    Where in Remit: Learn › Policy answers › choose a use case
  7. 07Policy update agent (platform level)
    What it does
    When the DTA changes a page or file behind the policy pack in force, fetches the new document and proposes the exact changes to the assessment question set: an analyst model lists reworded, added and removed questions with a verbatim quote for each, a second critic model checks the candidate against the document, and the loop repeats until the critic passes or three passes are reached. Remit then validates the candidate deterministically (schema, the Word template's placeholders and checkboxes, a trial fill) and stages it as a candidate pack.
    What is sent to the model
    The current question set (question ids, numbers, titles, wording and types only), the text of the DTA's new document (at most 120,000 characters) and the names of the changed DTA pages. No agency data, no use case, no evidence.
    What comes back
    A list of proposed changes with quotes, the tool's version and date as printed, and the critic's verdict and findings. A change is kept only if its wording appears word for word in the document; a finding is kept only if its quote does.
    What the person does
    A platform operator starts the agent, or it starts after the daily refresh when the mode says so. The operator reviews the run's step log and the candidate, and activates the pack from a date; in the release mode the agent activates a pack itself only when every quote verified, the critic passed and every deterministic check passed.
    The limit
    Never rewrites the Appendix C threshold criteria: a proposed change to those is reported and the candidate is marked for review, because they decide scope under the policy. Never changes an existing assessment. Never runs without the DTA's actual document.
    Where in Remit: Platform › Knowledge › Policy packs
  8. 08Access for other agents and systems
    What it does
    Lets an agency's own systems and AI agents work with the register through 16 named tools and the public API: list and read use cases, findings and incidents, search and ask the policy, start an integrity check, propose scope answers from a document, log or update an incident, and record a governance report.
    What is sent to the model
    Nothing to any model unless the tool called is one of Remit's own AI features above, which then behave exactly as they do on screen and honour the agency's AI switch.
    What comes back
    The same data the screens show, scoped to the key's agency.
    What the person does
    An administrator issues each key, chooses read or read-and-write scope, and can revoke it. Every write is audited under the key's creator.
    The limit
    No key can change a use case record, rate, approve or submit. The agent is a client of Remit's rules, not a way around them.
    Where in Remit: Admin › API keys; the API under /api/v1 and the agent endpoint at /api/mcp

How you can check

  • Every quote the model offers is checked against the text it claims to quote before it is shown. A quote that cannot be found is dropped and the run log says so.
  • Every call is written to the AI call log and to the audit log, which is append-only at the database level.
  • Every prompt carries a version, so a change in wording is visible in the log and in the run steps.
  • Every screen shows what a run did: what was loaded, what was sent and how much, which model, the tokens used, what came back and what was verified.
  • No screen blocks on the model. Runs continue in the background and the page shows their progress; a failure leaves the record exactly as it was.
  • The rule-based integrity checks, the threshold wizard, the assessment, the exports and every other feature work with AI assistance off.

Assessing Remit under the policy

Appendix C, in the policy's own words
Each Appendix C threshold criterion in the policy’s own words, and the facts about Remit relevant to it.
The policy asks whetherWhat is true of Remit
More than insignificant harmThe use, misuse or failure of AI could lead to more than insignificant harm to individuals, communities, organisations, the environment or the collective rights of cultural groups including First Nations peoples.Every output is a suggestion reviewed by a signed-in officer before it can affect any record. A suggestion that is wrong and is accepted becomes that officer's recorded decision, in their name. The realistic harm to consider is a missed or misleading suggestion that an officer relies on.
Materially influences administrative decisionsThe use of AI will materially influence administrative decisions that affect individuals, communities, organisations, the environment or the collective rights of cultural groups including First Nations peoples.Remit's AI assistance informs the agency's own governance records about its AI use cases. It plays no part in any decision about a member of the public, a benefit, an entitlement or an obligation.
Public interaction without human reviewIt is possible the public will directly interact with, or be significantly impacted by, the AI or its outputs without human review.No member of the public interacts with Remit or sees anything its model produces. Every output is shown only to signed-in agency staff.
Personal, sensitive or classified dataThe AI is designed to use personal or sensitive data (as defined by the Privacy Act 1988 (Cth)) or security classified information (as defined by the Australian Government Protective Security Policy Framework).The register text and evidence documents sent to the model can contain personal information and material marked OFFICIAL: Sensitive. The agency controls what is uploaded and whether AI assistance is on; see the data-handling rows above.
DTA-directed elevated riskIt is deemed an elevated risk AI use case as directed by the DTA.No direction from the DTA concerning this kind of use is known to the operator at the date of this statement. The agency should check the DTA's current directions when it records its decision.

These are facts about Remit for the agency's own threshold check, set beside the policy's own wording of each criterion. They are not Remit's verdict on scope. The agency records its decision in Remit like any other use case. Source: Policy for the responsible use of AI in government, Appendix C.

What AI never does in Remit

  • Set or change a risk rating. Ratings come from the DTA's scales chosen by a person, and the matrix derives the result.
  • Decide whether a use case is in scope. The scope decision is recorded by a person from their own answers.
  • Approve, endorse or request changes to an assessment.
  • Sign as the accountable official or any officer.
  • Send anything to the DTA or to any system outside Remit, other than the model provider for the call itself and the agency's own ITSM connection for incidents.
  • Change, delete or create a register record, a scope decision, an evidence document or an audit entry.
  • Run without a record: every call is logged with who, what, which model and what came back.

Data handling

Read live from the installation where it can be
AI service on this installation
Not configured. No AI feature can run and no text leaves Remit for a model.
Provider and model
The Anthropic API. The model is set for the whole installation by the platform operator and shown on Admin › AI assistance; at the time this page was rendered it is the model set by the platform operator.
What is sent
Only the text the feature needs, listed feature by feature above: the description or document being triaged, the question and matching evidence passages, the records and document excerpts of an integrity run, or the policy passages of a question. Never the whole database, never credentials, never the AI service key, never another agency's data.
What Remit stores about each call
One AI call record: the feature, its outcome, the person (or 'Remit, automatic'), the agency, the record concerned, the model, a hash and version of the prompt, the citations, the output, the token counts and the estimated cost. A matching audit entry is written. Application code never deletes or edits these rows.
What the model provider keeps
[PLACEHOLDER — operator: state, from your agreement with Anthropic, the data-processing location, the retention period for API inputs and outputs, and confirm that API data is not used to train models under the commercial terms in force.]
Protective marking
Remit sends text at the marking the agency has put into it. Whether OFFICIAL: Sensitive material may be sent to the model is the agency's decision, made when its administrator turns AI assistance on and when its people choose what to upload.
Personal information
Evidence documents and register text can contain personal information. It is sent only within the limits above, only when the agency's switch is on, and it is never used by Remit for any purpose other than the feature the person invoked.

Controls the agency holds

Two switches
AI assistance runs only when the installation has an AI service key and the agency's own switch is on. A new agency starts with its switch off; an agency administrator turns it on or off under Admin › AI assistance with a recorded reason, and the change is in the audit log.
Shown, or explained
Every AI control on every screen is either available or replaced by the reason it is not. Nothing fails silently, and every screen works in full with AI assistance off.
Usage and cost
Admin › Usage and cost shows every call by feature, person and record with its tokens and estimated cost; the estimate is indicative and the provider's invoice is the record.
Monthly cap on automatic runs
An administrator sets a cap in US dollars on the estimated cost of automatic integrity checks; manual runs are never capped.
Service key
The AI service key lives only in the installation's environment with an expiry date beside it. Remit never reads it back to a screen or a log. From 14 days before expiry, administrators are warned on the overview, the Admin AI page and the Platform page.
API keys for agents and systems
Issued by an administrator, shown once, stored hashed, scoped to read or read-and-write, revocable at any time.

Sources

Statement version 1.0 · last updated 6 September 2026. Attach the Word copy to your agency’s record of its decision.

Download as Word