Key Takeaways
The National Design Studio, a White House office, released Rampart, a 14.7MB open-source AI model that redacts personal information in the browser before any data is sent to a server.
Rampart reports 98.4% recall across seven languages and runs in under four milliseconds, using local processing so sensitive data never leaves the device.
At 14.7MB it is roughly 190 times smaller than OpenAI's 2.8GB privacy filter, and its builders say it is also more accurate.
A White House office has released its own open-source AI model, and it is built to protect privacy. The National Design Studio introduced Rampart, a 14.7MB model that redacts personal information directly in a web browser before any text is sent to a server or a chatbot. It runs on a person's own device, so sensitive data never leaves it.
How Rampart works
Rampart uses two layers. A rules-based check catches Social Security numbers and credit card numbers with checksum validation, and a small AI model catches names and addresses that rules alone would miss. The model reports 98.4% recall across seven languages and runs in under four milliseconds on a browser GPU, using ONNX Runtime Web so nothing sensitive reaches external servers or logs. The code is open and posted on GitHub and Hugging Face for anyone to inspect or build on.
Smaller and sharper than a giant
The detail that traveled fastest is the size. Rampart is 14.7MB. OpenAI's own privacy filter is about 2.8GB, roughly 190 times larger, and Rampart's builders say their model is both smaller and more accurate. That inverts the usual assumption that bigger models always win, and it puts a working privacy tool in the browser rather than on a company's servers.
Why a government model matters
Most AI privacy today depends on trusting a company not to keep your data. Rampart moves that protection to the edge, closer to the approach courts have started to demand, as when the Supreme Court ruled that geofence warrants are a search. It also fits a broader push to give people control over their data, the same idea behind efforts to put cryptographic receipts on AI training data. A government shipping open code, not just rules, is the part worth watching.
People Also Ask
What is Rampart?
Rampart is a 14.7MB open-source AI model from the National Design Studio, a White House office, that redacts personal information in a web browser before any text is sent to a server.
How does Rampart protect privacy?
It combines rules-based checks for Social Security and credit card numbers with a small AI model that catches names and addresses, all running locally so sensitive data never leaves the device.
Is Rampart really better than OpenAI's privacy filter?
Its builders say so. Rampart is about 190 times smaller than OpenAI's 2.8GB filter, reports 98.4% recall across seven languages, and runs in under four milliseconds on a browser GPU.
Is Rampart open source?
Yes. The model is open and available on GitHub and Hugging Face for developers to inspect and build on.
