AI Governance & Policy

Build the governance system before the technology builds the risk.

A practical framework for law enforcement and corrections agencies evaluating, approving, implementing, supervising, and auditing the use of artificial intelligence.

Core Governance Functions

01 Identify and classify AI systems
02 Assess legal and operational risk
03 Approve defined uses and limits
04 Require meaningful human review
05 Audit outcomes and revise controls
Why Governance Matters

AI policy is not simply an acceptable-use policy.

Artificial intelligence can influence how officers write reports, investigators analyze evidence, supervisors review work, agencies communicate with the public, and decision-makers evaluate information. Those uses create different levels of legal, evidentiary, operational, privacy, security, and reputational risk.

Effective governance therefore requires more than a prohibition against entering confidential information into public AI systems. Agencies need a repeatable process for deciding which systems may be used, for what purposes, under what conditions, by whom, and subject to what level of human review and documentation.

Governance Principles

Six principles for defensible agency AI governance

These principles should inform policy, procurement, deployment, supervision, training, and periodic review.

01 / PURPOSE

Defined Use

Agencies should identify the specific purpose for which an AI system is approved and distinguish authorized uses from prohibited or higher-risk uses.

02 / ACCOUNTABILITY

Human Responsibility

AI should support professional judgment, not replace accountability. Personnel remain responsible for the accuracy, legality, and appropriateness of work produced with AI assistance.

03 / RELIABILITY

Verification

Outputs that may affect reports, investigations, evidence, discipline, or public communications should be independently reviewed against authoritative source material.

04 / TRANSPARENCY

Documented Use

Agencies should determine when AI use must be documented, disclosed, preserved, or incorporated into audit trails, discovery systems, administrative records, or supervisory review.

05 / SECURITY

Data Protection

Policies should address what information may be entered into AI systems, where data is stored, whether vendors retain inputs, and whether agency information may be used for model training.

06 / OVERSIGHT

Continuous Review

Governance should continue after deployment through auditing, performance monitoring, incident review, vendor reassessment, and policy revision.

Governance Lifecycle

Govern the entire lifecycle, not just the purchase.

AI governance should begin before procurement and continue throughout deployment, supervision, auditing, and eventual replacement or retirement.

STEP 01

Identify

Determine whether a proposed system uses generative AI, predictive analytics, automated classification, computer vision, or another algorithmic capability.

STEP 02

Assess

Evaluate legal, operational, evidentiary, privacy, cybersecurity, civil-rights, and reputational risks.

STEP 03

Approve

Define authorized users, approved purposes, prohibited uses, required safeguards, and escalation requirements.

STEP 04

Deploy

Train personnel, establish documentation and review requirements, and confirm vendor and technical controls.

STEP 05

Audit

Review outcomes, errors, complaints, discovery issues, policy violations, vendor changes, and emerging legal developments.

Policy Architecture

What should an agency AI policy address?

A mature policy should address both general AI governance and use-specific requirements for higher-risk applications.

Scope & Definitions

  • Define artificial intelligence and covered systems.
  • Identify systems excluded from the policy.
  • Distinguish generative AI from other automated tools.
  • Clarify agency-owned, vendor-provided, and public AI platforms.

Approval & Procurement

  • Require review before acquisition or operational use.
  • Identify who has approval authority.
  • Evaluate data ownership, retention, security, and model training.
  • Assess auditability and vendor change-management practices.

Authorized & Prohibited Uses

  • Define approved operational use cases.
  • Identify uses requiring elevated review.
  • Prohibit unsupported factual assertions or fabricated content.
  • Address use in enforcement, discipline, and high-impact decisions.

Human Review

  • Require verification against original source material.
  • Preserve individual responsibility for final work product.
  • Establish supervisory review where appropriate.
  • Define situations in which AI output may not be used without corroboration.

Records, Discovery & Disclosure

  • Determine what prompts, outputs, drafts, or logs must be retained.
  • Address discoverability and litigation holds.
  • Establish disclosure requirements for reports and investigations.
  • Coordinate AI workflows with evidence-management systems.

Training & Oversight

  • Require role-specific training before authorized use.
  • Monitor errors and misuse.
  • Provide reporting mechanisms for AI-related incidents.
  • Review the policy and approved-system list periodically.
Risk Management

Where agencies should expect governance problems

Accuracy & Hallucination

AI-generated outputs can state inaccurate information confidently, omit important context, or introduce details unsupported by source material.

Evidence Integrity

Automated summarization, transcription, enhancement, or transformation may complicate provenance, authentication, preservation, and testimony.

Discovery

Agencies must determine whether prompts, drafts, outputs, metadata, audit records, and vendor logs constitute records that must be preserved.

Privacy & Confidentiality

Public or vendor-hosted systems may create risk when personnel enter personally identifiable information, criminal intelligence, medical information, or sensitive investigative data.

Bias & Automation Reliance

Personnel may give excessive weight to system-generated recommendations or classifications, especially when the underlying methodology is unclear.

Vendor Change

AI products can change materially through model updates, new features, altered retention practices, or revised terms without a traditional procurement cycle.

Leadership Review

Ten questions agency leaders should be able to answer

If these questions cannot be answered clearly, the agency may not yet have an operational governance system.

1

Which AI systems are currently being used by agency personnel?

2

Who has authority to approve new AI systems or use cases?

3

What information may and may not be entered into each approved system?

4

What human review is required before an AI-assisted output may be relied upon?

5

When must AI use be documented or disclosed?

6

What records of prompts, outputs, edits, or audit logs must be preserved?

7

How are vendor data retention and model-training practices evaluated?

8

What training is required before personnel use an approved AI system?

9

How are AI-related errors, complaints, or policy violations reported and reviewed?

10

Who is responsible for periodically reassessing the system, vendor, law, and policy?

A Critical Distinction

A policy should govern the use case, not merely the brand name.

Agencies should avoid assuming that approving a particular vendor means every feature or future use of that platform is approved. The same system may present relatively low risk when used for administrative drafting and substantially greater risk when used to generate police reports, evaluate evidence, classify individuals, or influence enforcement decisions.

Agency Assistance

Building or revising your agency's AI governance framework?

Shield Public Safety Training can assist agencies with AI governance, policy development, risk assessment, implementation planning, training, and review of specific AI use cases.

SHIELDPST.ai is an educational resource of Shield Public Safety Training. Content is provided for training and informational purposes and is not legal advice.