Redaction isn’t an action, it’s a state: why pseudonymisation is essential for scaling enterprise AI

AuthorCharlot Eberlein
Published20.07.2026
Read time2 min

By reframing redaction as a reversible state, rather than a destructive action, we are able to use language models to reason about sensitive data without compromising privacy.

Large language models are powerful reasoning tools, but they are also black boxes, which can be a significant liability in highly regulated industries. As a result, many organisations feel forced to choose between compliance and automation. However, this choice rests on the false assumption that the only way to protect sensitive information is to destroy it. We propose that these goals are not mutually exclusive: viewing redaction as a reversible state allows us to both automate reasoning tasks and maintain confidentiality.

Redaction strategies

Current approaches to processing sensitive data often rely on destructive redaction, the complete deletion of sensitive information. While this guarantees privacy, it makes the redacted entities indistinguishable from one another. This prevents models from inferring logical relationships between these entities and therefore makes higher-order reasoning tasks about them impossible.

Consider a set of financial accounts. If a name like “Jane Doe” is removed completely, the model loses the ability to distinguish between her and other people mentioned in the document whose names have been removed, or even to discern if it was a name at all rather than a different type of sensitive information, like a location or a phone number.

We instead propose pseudonymisation: replacing “Jane Doe” with a consistent placeholder, or pseudonym, like <NAME-F6BAK4Z> allows the model to understand the role of this particular person within the document without ever revealing their actual identity.

An alternative approach is hosting the model locally, so that sensitive data never leaves the organisation. While this approach guarantees privacy, it also requires a substantial resource overhead, which limits access to large state-of-the-art models. By contrast, pseudonymisation provides comparable confidentiality at a significantly lower cost, allows better models to be used, and remains equally compliant.

A neurosymbolic approach

To pseudonymise documents reliably, we combine the versatility of probabilistic reasoning with the verifiability of deterministic, rule-based constraints. A four-stage pipeline creates a barrier between the LLM and sensitive data, preserving reasoning capabilities without compromising privacy. Deterministic checks sanitise the results of each probabilistic step, ensuring predictions are consistent throughout the document.

Ingestion. We use optical character recognition (OCR) to convert input documents into structured text using an internally-hosted convolutional recurrent neural network (CRNN).

Detection. We analyse the contents of the text using a named-entity recognition (NER) model that automatically identifies personally identifiable information (PII) present.

Pseudonymisation. We replace each PII entity detected in the text with a specific placeholder token unique to that entity. Once this stage is completed, it is safe to have the document processed externally.

Reconstruction. We swap the placeholders in the externally-generated output back to their original values using a secure, reversible mapping. The final result contains the real names and details from the source document.

Auditability

Compliance audits of redacted documents normally rely on manually reviewing a small sample of the population. This comes with inherent risks, since a clean sample doesn't guarantee the rest of the population is equally clean.

In our approach, the replacement step behaves predictably, which allows auditors to verify the logic directly rather than sampling outputs. Once verified, the same guarantee holds for every document processed. However, it is important to note that the underlying detection model is a neural model, meaning that there is a possibility of false negatives. This is an unavoidable consequence of working with probabilistic methods.

Looking forward

While consistent placeholders make reasoning possible, reversible mappings make the results usable by restoring the original values. Together, these properties allow organisations to use black-box models to perform complex reasoning tasks while maintaining confidentiality. This is particularly relevant in industries such as financial services, where documents must remain both machine-readable and auditable.

This is the kind of problem we work on at UnlikelyAI: getting powerful AI into the places where privacy, compliance, and auditability are not optional.

Follow us on LinkedIn to hear more from the team.

Charlot EberleinMachine Learning Engineer Intern
YouTube