A council office desk in the morning, with a folded sheet beside an opened envelope and a yellow highlighter

Plain language administrative letters: AI without exposing anyone

A woman comes back to the counter with the letter she was sent three weeks earlier. She could not make sense of it, so the officer who saw her the first time gave her a "simplified" version, rewritten in two minutes by a consumer AI tool. That version was crystal clear. It had just lost, along the way, the paragraph telling her she had two months to challenge the decision. The deadline has passed.

It is the mistake seen most often in departments that are switching to plain language, and it is a double one. The text was simplified to the point of losing what protected her. And to get it, the whole letter went to an outside provider, with her name, her address, her case number and the details of her situation. Here is the same rewrite done twice: first the way it is often done, then the way it should be done.

What an administrative letter must keep, even in plain language

Plain language is not a summary. A letter notifying a decision carries elements that have legal effects: the decision itself, the reasons for it, the amounts, the documents requested, the deadlines, the ways to appeal, the department that took it and the person to contact. In several legal systems, France among them, an appeal deadline can only be held against the person if it appears, together with the ways to appeal, in the notice of the decision. In Switzerland, administrative procedure requires a decision to state its reasons and indicate the available remedies. A more readable version that leaves out one of these elements is not a better letter: it is a letter that weakens the person receiving it, and sometimes the department too.

As far as data is concerned, nothing changes compared with the rest of your work: public servants are bound by official secrecy and a duty of discretion, and the data of the people you serve falls under the GDPR in the European Union, and under the FADP or cantonal data protection law in Switzerland. Your administration's own rules come on top of that. If it prohibits AI tools, the right course is to raise it with your line management, not to work around the rule.

Preparing the letter before giving it to AI

Before: the person's letter pasted as it is

The officer opens the letter in the case management software, selects everything and pastes the text into a consumer AI tool. Along with it go the woman's identity, her address, her benefit reference number, the amount of the benefit that was stopped and the reason it was stopped, which touches on her family life. That text now sits with a third party that neither the administration nor she chose, and which often keeps the conversation history. For a task that is purely about wording, that is a lot.

After: the standard letter, with placeholders

The rewrite is about form, and the form is the same for everyone who receives this letter. So the officer starts from the letter template, not from the letter that was sent. Where the data was, he leaves readable placeholders: [NAME], [CASE NUMBER], [AMOUNT], [DATE OF DECISION]. The amounts can stay as consistent examples, since they are only there to check how the sentences read.

He gives this standard letter to IA Confidential on a confidential model. By default, the assistant answers with open models installed on servers in Switzerland, outside the reach of the CLOUD Act, which pass nothing on to third parties. For rewriting a letter, they are more than enough.

If he does have to start from a real letter, scanned or as a PDF, the attached document is read in his browser. If the question then goes to an external model, only pseudonymised extracts are sent. And when a letter remains identifying even once masked, because an address, a date and a family situation are enough to recognise someone, the assistant says so under the heading "Identifying document" and offers to have it handled by a confidential model or to send only the question. To understand why removing the name is not enough, see our guide to anonymisation and pseudonymisation.

Rewriting in plain language without losing the law

Before: "simplify this letter"

The instruction is three words long, and the AI does exactly what it is asked: it simplifies. It shortens the sentences, which is good, but it also removes whatever looks like jargon to it, which is less good. "You may request a review of this decision" becomes "you can write to us". "Where applicable" disappears, and with it the condition under which a document was only required from some people. A "may" becomes a "must". The result reads in one go, and nobody compares it line by line with the original: it looks right.

After: the list first, the rewrite second

The fix is to make the AI work in stages: first list everything the letter requires or allows, then rewrite it, then prove that nothing is missing. The request, to copy and adapt:

Here is a standard letter from our department. Before rewriting it, list everything it requires of or allows the recipient: every deadline, every amount, every document to provide, every way to appeal, every condition, with the original sentence. Then rewrite it in plain language: sentences of twenty words at most, active voice, addressing the reader directly and politely, one idea per paragraph, the decision in the first sentence, the documents as a list. Never turn an obligation into an option or the other way round, and keep the placeholders in square brackets exactly as they are. Finish with a check table: for each item on the list, the sentence in the new version that covers it, or "missing".

The check table changes everything: whatever has disappeared shows up, instead of being discovered at the counter. The officer reviews each line against the original, corrects anything that has slipped, and asks for a new version when the meaning has changed. He can also ask the AI to flag the terms it could not replace without losing something, such as the exact name of a type of appeal, so they can be kept and explained in brackets rather than deleted.

Plain language for the whole department

Before: every officer rewrites on their own

Three officers, three AI tools, three styles. One is almost chatty, another keeps the old formulas, the third has invented a name for a scheme that already has one. A person who receives two letters from the same department thinks they are dealing with two different administrations, and the consistency plain language was supposed to bring never arrives.

After: a space and shared instructions

In IA Confidential, the officer creates a "Letters to the public" space. In the Assistant tab of the space page, he writes the instructions that apply to every conversation he opens there: the polite form of address, sentence length, the rule about placeholders in square brackets, the official names of the department's schemes, the closing line saying who to contact. These instructions take precedence over his general preferences. The text of the instructions can be passed around among colleagues, each pasting it into their own space: the consistency comes from that shared text, not from the tool.

Once a version is approved, the assistant writes it as a document: the officer reviews it in the preview, edits it, keeps the successive versions and exports it to Word or OpenDocument. The layout is rebuilt on export and does not reproduce that of the original template: the text is then pasted back into the department's official template, with its letterhead and signature.

Plain language and external models: what the filter changes

Before: the best model, without looking at what goes out

For a tricky letter, it is tempting to reach for the most powerful model, often an external one. If any real data has stayed in the text, a name left in a greeting, a case reference in the subject line, it goes out with it.

After: the Confidentiality filter steps in

External models are the officer's choice, never an automatic switch. If he selects one, the Confidentiality filter checks the message first. If it finds sensitive data, it offers to answer with a confidential model, with the message unchanged, to anonymise it for the external model with a version the officer can review and correct, or to send it as it is, knowingly. The option offered by default remains the confidential AI.

In the Privacy panel, the officer can add his own anonymisation instructions, applied before anything is sent to an external model: always mask benefit reference numbers, case references, and the names of neighbourhoods or local organisations that would make it possible to recognise a family.

What AI does not do for you

AI can make mistakes, and it can make things up: a plausible but wrong deadline, a document that was never requested, a way to appeal that does not exist for this decision. The check table reduces that risk without removing it. Every amount, every deadline and every reference must be checked against the original text and against the rules in force.

Plain language also needs testing on real readers: a colleague from another department, a reception officer, and where possible a member of the public willing to read through a standard letter. A letter that seems simple to the person who wrote it is not necessarily simple for the person who receives it. And the letter is still signed by the department: the department answers for it, not the tool that shaped it.

What stays confidential

With a confidential model, the letter and its rewrite are processed on servers located in Switzerland, and nothing is kept on our side. The history of your conversations and spaces stays in your browser: we could not produce it if asked to, because we do not have it. Attached documents are read in the browser, and no file is kept on our servers.

With an external model, nothing goes out without passing through the filter, and you are the one who decides what goes out: an anonymised version you have reviewed, pseudonymised extracts, the question alone, or the message as it is.

On a shared computer at a reception desk or in a department, the history can be read by anyone using the same browser session: use a personal session and close it when you leave. And if you work from standard letters, what circulates cannot identify a member of the public in any case.

The other uses of AI in a public service, replying to a member of the public, summarising texts, a note for an elected official, are covered in our guide for public servants and the data of the people they serve. For what must never go out, even in a letter, see the list of data never to paste into AI.

To try it on one of your standard letters, without any personal data: open the chat.