Build the governance system before the technology builds the risk.
A practical framework for law enforcement and corrections agencies evaluating, approving, implementing, supervising, and auditing the use of artificial intelligence.
Core Governance Functions
AI policy is not simply an acceptable-use policy.
Artificial intelligence can influence how officers write reports, investigators analyze evidence, supervisors review work, agencies communicate with the public, and decision-makers evaluate information. Those uses create different levels of legal, evidentiary, operational, privacy, security, and reputational risk.
Effective governance therefore requires more than a prohibition against entering confidential information into public AI systems. Agencies need a repeatable process for deciding which systems may be used, for what purposes, under what conditions, by whom, and subject to what level of human review and documentation.
Six principles for defensible agency AI governance
These principles should inform policy, procurement, deployment, supervision, training, and periodic review.
Defined Use
Agencies should identify the specific purpose for which an AI system is approved and distinguish authorized uses from prohibited or higher-risk uses.
Human Responsibility
AI should support professional judgment, not replace accountability. Personnel remain responsible for the accuracy, legality, and appropriateness of work produced with AI assistance.
Verification
Outputs that may affect reports, investigations, evidence, discipline, or public communications should be independently reviewed against authoritative source material.
Documented Use
Agencies should determine when AI use must be documented, disclosed, preserved, or incorporated into audit trails, discovery systems, administrative records, or supervisory review.
Data Protection
Policies should address what information may be entered into AI systems, where data is stored, whether vendors retain inputs, and whether agency information may be used for model training.
Continuous Review
Governance should continue after deployment through auditing, performance monitoring, incident review, vendor reassessment, and policy revision.
Govern the entire lifecycle, not just the purchase.
AI governance should begin before procurement and continue throughout deployment, supervision, auditing, and eventual replacement or retirement.
Identify
Determine whether a proposed system uses generative AI, predictive analytics, automated classification, computer vision, or another algorithmic capability.
Assess
Evaluate legal, operational, evidentiary, privacy, cybersecurity, civil-rights, and reputational risks.
Approve
Define authorized users, approved purposes, prohibited uses, required safeguards, and escalation requirements.
Deploy
Train personnel, establish documentation and review requirements, and confirm vendor and technical controls.
Audit
Review outcomes, errors, complaints, discovery issues, policy violations, vendor changes, and emerging legal developments.
What should an agency AI policy address?
A mature policy should address both general AI governance and use-specific requirements for higher-risk applications.
Scope & Definitions
- Define artificial intelligence and covered systems.
- Identify systems excluded from the policy.
- Distinguish generative AI from other automated tools.
- Clarify agency-owned, vendor-provided, and public AI platforms.
Approval & Procurement
- Require review before acquisition or operational use.
- Identify who has approval authority.
- Evaluate data ownership, retention, security, and model training.
- Assess auditability and vendor change-management practices.
Authorized & Prohibited Uses
- Define approved operational use cases.
- Identify uses requiring elevated review.
- Prohibit unsupported factual assertions or fabricated content.
- Address use in enforcement, discipline, and high-impact decisions.
Human Review
- Require verification against original source material.
- Preserve individual responsibility for final work product.
- Establish supervisory review where appropriate.
- Define situations in which AI output may not be used without corroboration.
Records, Discovery & Disclosure
- Determine what prompts, outputs, drafts, or logs must be retained.
- Address discoverability and litigation holds.
- Establish disclosure requirements for reports and investigations.
- Coordinate AI workflows with evidence-management systems.
Training & Oversight
- Require role-specific training before authorized use.
- Monitor errors and misuse.
- Provide reporting mechanisms for AI-related incidents.
- Review the policy and approved-system list periodically.
Where agencies should expect governance problems
Accuracy & Hallucination
AI-generated outputs can state inaccurate information confidently, omit important context, or introduce details unsupported by source material.
Evidence Integrity
Automated summarization, transcription, enhancement, or transformation may complicate provenance, authentication, preservation, and testimony.
Discovery
Agencies must determine whether prompts, drafts, outputs, metadata, audit records, and vendor logs constitute records that must be preserved.
Privacy & Confidentiality
Public or vendor-hosted systems may create risk when personnel enter personally identifiable information, criminal intelligence, medical information, or sensitive investigative data.
Bias & Automation Reliance
Personnel may give excessive weight to system-generated recommendations or classifications, especially when the underlying methodology is unclear.
Vendor Change
AI products can change materially through model updates, new features, altered retention practices, or revised terms without a traditional procurement cycle.
Ten questions agency leaders should be able to answer
If these questions cannot be answered clearly, the agency may not yet have an operational governance system.
Which AI systems are currently being used by agency personnel?
Who has authority to approve new AI systems or use cases?
What information may and may not be entered into each approved system?
What human review is required before an AI-assisted output may be relied upon?
When must AI use be documented or disclosed?
What records of prompts, outputs, edits, or audit logs must be preserved?
How are vendor data retention and model-training practices evaluated?
What training is required before personnel use an approved AI system?
How are AI-related errors, complaints, or policy violations reported and reviewed?
Who is responsible for periodically reassessing the system, vendor, law, and policy?
A policy should govern the use case, not merely the brand name.
Agencies should avoid assuming that approving a particular vendor means every feature or future use of that platform is approved. The same system may present relatively low risk when used for administrative drafting and substantially greater risk when used to generate police reports, evaluate evidence, classify individuals, or influence enforcement decisions.
Building or revising your agency's AI governance framework?
Shield Public Safety Training can assist agencies with AI governance, policy development, risk assessment, implementation planning, training, and review of specific AI use cases.