The Freedom of Information Act is broken. While delays in getting responses to requests have always been a scourge, the situation has become truly dire in the second Trump administration. The backlog of requests reached an all-time high in FY25, and a simple request to the Department of Education took an average of 171 days to complete. Many reporters are so frustrated with the law’s illusory timelines that they’ve abandoned it for anything with a shorter deadline than a book. For a law whose purpose is democratic accountability through timely access to information, things are not going well.
As is true in most other areas of life in 2026, AI is being floated as the solution to FOIA’s woes. The federal government is already bullish on it—the Department of Homeland Security, the National Archives, State, and Justice, among others, have dabbled in its use. These experiments can be understood as a response to both short- and long-term trends, from a depleted federal workforce to the ever-increasing number of requests submitted across the federal government. A record 1.7 million requests were submitted last fiscal year, a million more than a decade ago. And this all comes as the number of federal records being created and stored is exploding. Even if agencies’ FOIA resources had remained constant into the current administration (which they didn’t), the government would be falling behind.
The allure of AI to address these trends is understandable. As researchers like Jason Baron have noted, the ever-increasing volume of federal records makes AI-assisted searching a particularly attractive idea. Given how fast AI is progressing, though, it’s not hard to imagine it handling the entire FOIA pipeline: interpreting requests, locating records, reviewing and redacting them for exemptions, and responding to the requester. Deployed at scale, this technology holds out the promise of reviewing millions of pages of text, understanding decades of law, and tracking factual minutiae all without complaining about being sent to Siberia. In this vision of the future, AI is a wholesale replacement of the administrative process, cutting through the trends that had seemingly doomed FOIA. Assuming such a vision is technically possible, though, is it something we want to work towards?
Something clearly needs to change. After more than a decade of litigating requests for journalists and news outlets, I am acutely aware of FOIA’s problems and their effect on newsgathering. And after talking with countless government employees at mediations, conferences, and committees over the years, I understand many of the complexities within the government that have contributed to FOIA’s delays. But before introducing a radical new technology we must be clear-eyed about what we are trying to achieve, how we will mitigate risk, and the red lines that cannot be crossed. In short, we need a FOIA AI framework. I have endeavored to sketch one out here.
My proposal has two parts:
- First, we must assess the risk of introducing AI into any particular part of FOIA. The European Union’s AI Act provides a good basic formulation: what is “the probability of an occurrence of harm and the severity of that harm”? Risks should be categorized, and the most severe ones mitigated.
- Second, we must empirically test whether the core values of FOIA are being promoted by a particular implementation of AI. In a nutshell, those values are disclosing as much non-exempt information to the public as quickly as possible. We could test, for example, whether introducing an AI-powered search tool within an agency actually leads to faster request response times.
I want to focus on the first part of the framework in this piece, because the line from this White House has generally been an all-gas, no-brakes approach. We are charging into widespread AI adoption even though, as described below, there is serious risk to FOIA and not much theorizing about the nexus. In 2024, a subcommittee of the FOIA Advisory Committee (on which I served) called for the Department of Justice to issue guidance to agencies on their use of AI in the FOIA process. To date, that has not happened. And the Office of Management and Budget’s 2025 memo on AI, which calls for additional steps when it comes to “high-impact AI” within the government, does not include FOIA processing among its presumptive categories. That is a mistake that should be rectified.
A core part of risk management is evaluating the severity of harm that might result from any particular course of action. When it comes to FOIA, we should break out different parts of the administrative process for evaluation: on one end of the spectrum there are many basic, repetitive tasks where the potential harm is low. This includes actions like writing to the requester acknowledging receipt of their request, responding to basic queries from the requester (where is the request in the process, what is the estimated date of completion), and document management (like sorting and de-duplication). I classify these as low risk both because AI is pretty good at them and because the consequences of getting it wrong are not very serious.
At the other end of the spectrum are decisions at the core of FOIA: how to search for records, what to release, and what to withhold. The worst-case “harm” of getting it wrong here is the requester failing to get what they asked for. That could be disastrous for persons in immigration proceedings, who must generally FOIA their own files from the government. For the press and civil society, it’s going to be the deprivation of records promoting accountability and informed self-governance. These scenarios are unquestionably “high-impact”: FOIA has helped expose COINTELPRO, the torture of prisoners by the US government after September 11, the details of the Federal Reserve’s secret liquidity program, the Afghanistan Papers, the toll of civilian casualties from US-led airstrikes in the Middle East, the Robert Mueller investigation records, and so many more stories. These records have had profound implications in both domestic and foreign affairs, and that type of accountability must be preserved.
What is the likelihood of these most severe harms if AI were deployed to answer FOIA requests? So much depends on the technical details of the deployment, which are impossible to predict ahead of time. There are also endemic problems with AI, like its penchant for hallucinations, and those could certainly create problems in processing a request. But it is not hallucinations that worry me the most. It is the fact that AI can appear to be neutral and objective while it actually obscures and magnifies prejudices to a greater extent than other technologies. Each model contains biases from its training corpus, its fine-tuning, its background instructions, its prompts, and so on. Those reflect human biases stemming from deliberate decisions, predispositions, and prejudices. And they will, in turn, be imported into whatever system AI is inserted into.
Consider the State Department’s machine-learning declassification trial program. The system was not trained to produce an objectively “correct” result, but rather to match the decisions of the agency’s human reviewers. The same is true of an AI tool Health and Human Services has deployed, called “FRED,” that purports to “analyze, identify, and generate predictions of text for redaction” under FOIA. FRED was trained on certain inspection “forms before redaction and versions of those forms after redaction by FDA staff,” just as at State. The government might argue that AI matching the results of the human review is the correct result, but we know that FOIA officers routinely overredact records when reviewing them for release. If AI bots are trained against the output of human reviewers, similar over-redaction tendencies will emerge.
We should also consider that more insidious directions could be built into these systems. The current administration, for example, instructed FBI agents to “flag” any documents in the Epstein files that mentioned the president. Secretary Clinton set up a private email server, establishing a whole category of records that was never searched. ICE recently put out a purported policy of only releasing bodycam video when it is in the agency’s “best interests.” And so on. A bot that is trained to redact politically inconvenient information at scale, or instructed to never search a particular record repository, would pose grave risks to FOIA’s transparency mandate.
If FOIA is already experiencing these types of issues, though, perhaps a fairer measurement of risk is the delta between a human-centric FOIA system and one powered by AI. Even here, my sense is that it will be significant. Right now, line-level FOIA officers make the initial decisions about how to search for records and what to redact. Those decisions are subject to review and sometimes are overruled by higher-ups, to be sure. But in most cases the basic contours of disclosure are set by persons who have some distance from the White House, are trained to follow the law, and can push back against political meddling. A human reviewer might balk at a blatantly political instruction or blow the whistle about it, as happened with the Epstein files. Or humans might simply release the information anyway, as the Office of the Director of National Intelligence did last year with a memo on Venezuela.
Aggressively deploying AI could invert this structure, giving the White House near-complete control in FOIA responses from the get-go. If a FOIA bot is deployed to make the first cut on redactions, it could be given instructions like: redact anything that contradicts the president’s statements. AI can be trained from the outset to accept these types of instructions, and even if a human reviewer is “in the loop” somewhere they might never know that political instructions were built in. AI is so good at coming up with plausible-sounding explanations that a FOIA bot tuned to a particular set of goals could generate dozens of pages purporting to justify any redaction, even if it is contrary to black-letter law. Deployed at scale, it could cloak instructions by burying them in output.
Obscuring these types of instructions goes hand in hand with another major difference AI would bring: “automation bias.” This is the tendency of humans to “defer to automated systems,” leading to a reduction in “the amount of independent scrutiny that they exhibit when making decisions.” This is a well-documented phenomenon because it turns out that “people are bad at judging the quality of algorithmic outputs and determining whether and how to override those outputs.” If AI were to displace some or most of the FOIA processing pipeline, even humans somewhere in the loop might simply defer to whatever the AI says. Studies are already starting to show that using AI can reduce critical thinking, a finding that recalls Lisanne Bainbridge’s observations about the challenges of overseeing mechanized industrial processes in Ironies of Automation. We should be concerned that such tendencies, over time, will consolidate the locus of FOIA control higher up within the government.
Mitigating these risks will require extending current structural protections in FOIA. Congress wasn’t blind to the fox guarding the henhouse problem in creating this law, so review of the agency’s initial decision is already baked in, first through an administrative appeal and then de novo judicial review. The meaningfulness of these procedures must be preserved, both by disclosing additional information about AI’s usage and by limiting when it can be deployed.
My first set of risk mitigation proposals concerns the executive branch. Any AI FOIA tool development should be conducted in the open and, ideally, in collaboration with non-governmental experts and representatives of the requester community. Agencies should also be required to conduct periodic audits of any AI FOIA system and publish the results with enough detail for meaningful external review. These measures should not be controversial—the Justice Department’s FOIA handbook is public, as is its written guidance to agencies. OMB already requires “high-impact” AI applications to be subject to a number of additional procedures for testing and feedback. The government should extend these to FOIA systems to mitigate systemic risks.
When it comes to processing individual requests, agencies need to go further. Specifically, they must:
- Inform requesters whenever AI is used to respond to their request;
- Inform requesters how AI was used to respond to their request (e.g., for searching, for de-duplication, for exemption application);
- If AI was used to locate records, inform requesters as to which government databases/record repositories were searched;
- Preserve all of the inputs and outputs from AI systems that pertain to requests—the AI “administrative record”—so they can be reviewed; and
- Provide, upon request, a manual review and renewed decision regarding any action of an AI system.
These steps will not eliminate the risks of AI in the FOIA process, but hopefully they will lay the groundwork for ensuring it does not have the last say.
The second set of proposals concerns litigation. Judicial review is far from perfect (judges tend to agree with agencies most of the time), but it is the backstop for all of FOIA’s accountability. Indeed, the most impactful records released over the years have tended to come out in litigation. Preserving that independent review is a red line, and where AI’s involvement within the government must end. A situation where an agency can only gesture at the AI and claim it’s tokens all the way down cannot form the factual basis for judicial review. Once a case commences, defendant-agencies must conduct a manual review of their decisions and limit their litigation posture to the results of that human review.
What AI can do to improve the FOIA process is a question that should be discussed, experimented with, and empirically measured. But we must have guardrails in place to protect the law’s purpose first. Properly assessing and mitigating risk in the FOIA pipeline is overdue.
Adam Marshall is the director of national litigation at the Reporters Committee for Freedom of the Press. His work includes litigation in federal and state courts and training journalists on government transparency.