Assessing Agency AI Readiness
Chief Sandra Okafor had been in the job for eighteen months when her department received the first vendor proposal for an AI-assisted reporting suite. The pitch was polished: a 30-minute demo, a slide deck with the words "82% reduction in report-writing time" in 48-point font, and a contract that bundled body-worn cameras (BWC, the recording devices worn on officer uniforms), cloud storage, and the AI drafting platform into a single seven-year, $28 million agreement. Her technology commander loved it. Her union president was skeptical. Her city attorney had not yet reviewed the data-sharing clauses. She had three weeks before the council budget cycle required a decision. Chief Okafor did something her predecessor had not done with the last major technology purchase: she ordered a readiness assessment before she signed anything.
Why Readiness Comes Before Deployment
The readiness assessment is not a vendor evaluation. It is an internal audit that answers a simpler and more uncomfortable question: is this agency, right now, in a position to use AI responsibly enough that the people it serves, the prosecutors who rely on its reports, and the oversight bodies that watch its conduct can stand behind the outcome?
That question has teeth. Agencies that deploy AI drafting tools without a readiness foundation do not simply expose themselves to a bad vendor. They expose individual officers to depositions they cannot answer, prosecutors to disclosure obligations they did not know existed, and the community to a tool that operates without a governance structure. The failure is not always dramatic. It often accumulates quietly across dozens of reports before a defense attorney spots the pattern.
The King County (Washington State) prosecutor's office barred AI-written police reports when it determined that the review and disclosure infrastructure was not in place to guarantee the accuracy of AI-assisted narratives. That was not a verdict on the technology. It was a verdict on readiness. The prosecutor did not say the tool could never be used. The prosecutor said the agency had not demonstrated the controls necessary to use it responsibly under the evidentiary standards that criminal prosecution requires.
Chief Okafor's instinct was right. Before you evaluate a vendor, evaluate yourself. The readiness assessment gives you the baseline that tells you what you can responsibly deploy, in what sequence, and with what controls in place before the first live incident runs through an AI system.
Readiness is not a checkbox. It is an honest answer to the question: can we use this tool in a way that holds up for the officer in a deposition, the prosecutor at charging, and the community in an oversight hearing?
The Four Pillars of Agency AI Readiness
A complete readiness assessment examines four areas. Command staff should treat each as a genuine diagnostic, not a performance review. The goal is to find the gaps while there is still time to close them before a deployment decision.
Systems and Infrastructure
The first pillar is technical. The question is whether the agency's current infrastructure can support an AI deployment without creating new security or data obligations it cannot meet.
Start with the Criminal Justice Information Services (CJIS) Security Policy. CJIS is the Federal Bureau of Investigation's framework governing the handling of criminal justice information, including the data inside computer-aided dispatch (CAD) systems, records management systems (RMS), and body-camera footage platforms. CJIS obligations stay with the agency, not the vendor. A vendor can certify that its platform meets CJIS standards, and that certification matters, but the agency remains the responsible party. If the AI platform ingests CAD data to generate a report draft, the agency must verify that the ingestion pathway meets CJIS requirements for data transmission, access control, and audit logging.
This is not a theoretical concern. CAD and RMS data contain personally identifiable information, victim data, juvenile records, and information covered by federal privacy statutes. An AI system that routes that data through a commercial cloud API that is not CJIS-compliant creates a security and legal exposure the contract's indemnification clause will not fully cover. The agency's information technology staff, or an outside assessor, must map the data flows from CAD and RMS through the AI platform and verify compliance at each step before deployment.
Beyond CJIS, assess network capacity and BWC platform integration. If the AI drafting tool requires the BWC footage to be uploaded before a draft is generated, the time required for upload is part of the officer's workflow. An agency with slow network infrastructure at substations may find the theoretical time savings partially eaten by upload queues. Test this before signing a contract that uses a tested-environment speed figure as its headline benefit.
Policy and Governance
The second pillar is policy. Before deploying AI in any sworn-report context, the agency needs written answers to at least six questions.
First, who is the author of an AI-assisted report? The answer must be: the officer who reviews, corrects, and adopts the draft as their sworn account. This is not philosophical. It is the operational fact that determines what the officer can testify to under oath. If the policy is ambiguous, the officer is ambiguous on the stand.
Second, what verification standard applies? The policy must specify what "review" means, not in general terms, but in terms of what the officer does: opening the footage, checking each factual claim against the recording at the relevant timestamp, correcting any gap-fill before adopting the draft. A policy that says "officers should review AI-assisted drafts" without specifying that review means active verification against the footage is not a policy. It is a statement of aspiration.
Third, what are the disclosure requirements? When AI assists a report, what is disclosed to the prosecutor? To the defense? Does the agency's disclosure policy meet the requirements established under Brady v. Maryland (the 1963 Supreme Court decision requiring disclosure of exculpatory evidence) and Giglio v. United States (the 1972 decision requiring disclosure of impeachment evidence, including information that might be used to attack an officer's credibility)? An agency that deploys AI without a disclosure policy will eventually face a defense motion arguing that the undisclosed AI involvement violated Brady or Giglio. The policy needs to anticipate and answer that motion before it is filed.
Fourth, what use cases are authorized, and which are prohibited? Not all AI use is equal. An AI system that assists with redacting third-party faces from body-camera footage for a public-records request carries a different risk profile than an AI system that drafts use-of-force report narratives. The policy must specify what the tool may be used for, what it may not be used for, and what happens if an officer uses it outside the authorized scope.
Fifth, what is the mandatory escalation path when an officer discovers that an AI draft contains a material error? The policy needs a clear reporting chain: the officer corrects the draft, documents the correction, reports the error type to a supervisor, and that error feeds back into the vendor review cycle.
Sixth, what are the training requirements before an officer is authorized to use the tool on a live case? Training cannot be a one-time video module. It must produce a demonstrated competency: the officer can identify the three gap-fill signatures, run a footage-grounded verification pass, and document the review in a way that is admissible as evidence of the review having occurred.
Workforce Readiness
The third pillar is the human one. Systems and policies are only as effective as the people running them. Workforce readiness has two dimensions: skill and culture.
On skill, the baseline question is whether officers, dispatchers, and records staff understand, at a working level, what AI can and cannot do in a public safety context. The specific risks matter: an officer who understands that a language model fills audio gaps with statistically likely language is an officer who approaches the verification pass with the right level of skepticism. An officer who believes the AI is simply transcribing what the footage shows is an officer who will skim the draft and sign.
In 2026, officers in many agencies spend 30 to 40 percent of every shift writing reports. The administrative burden is real and the case for AI assistance is genuine. But the adoption of the tool cannot outrun the training on how to use it safely. In an agency where officers are adopting drafts without running verification passes, the speed gain is creating evidentiary risk at the same rate it is creating administrative relief. The readiness assessment must honestly audit whether the workforce has the skills to use the tool the way the policy requires.
On culture, the question is harder. Does the command structure support officers who take the time to run a thorough verification pass, even if it takes longer than simply adopting the draft? The 82% report-writing time reduction associated with tools like Axon Draft One is a benchmark, not a performance target. If the message from supervisors is "you should be turning reports around faster," officers will cut the verification pass to meet the expectation. The command culture must explicitly protect the time required for verification, or the policy becomes a paper exercise.
Community Trust Posture
The fourth pillar is the one chiefs most often underestimate: where does the agency stand with the community on AI use, and what engagement is required before deployment?
The Electronic Frontier Foundation (EFF) has raised substantive transparency concerns about AI police report tools, specifically about whether communities know when AI is involved in producing the evidence used to prosecute their members. Those concerns are not fringe positions. They represent a constituency that will show up at city council hearings, file public-records requests, and potentially litigate if they feel the technology was adopted without adequate community input.
The readiness question is not whether the community will love the tool. It is whether the agency has engaged the community honestly enough that the deployment is not a surprise. Agencies that announce AI adoption after signing a contract tend to face far more organized opposition than agencies that engage community stakeholders during the evaluation phase. The engagement does not need to be a ballot measure. It needs to be a genuine conversation in which the agency explains what the tool does, what the safeguards are, and how concerns will be tracked and addressed.
Some communities will raise concerns about algorithmic bias, about the use of AI in producing evidence that can result in incarceration, and about the transparency of vendor systems. Those concerns deserve substantive answers, not dismissal. An agency whose leadership can answer the bias question, the disclosure question, and the accountability question in plain language is an agency that has done the governance work. An agency that cannot answer those questions has more readiness work to do before deployment.
Running the Assessment: The Baseline Audit
The readiness assessment is a structured audit, not a conversation. Command staff should commission it as a formal exercise with a written output, because the output becomes the baseline against which deployment decisions are measured and the document a city council or oversight board can review.
The audit structure covers six domains: data infrastructure and CJIS compliance; existing policy coverage and gaps; training program status and competency evidence; disclosure practices with the prosecutor's office; community engagement history and trust posture; and vendor evaluation status. For each domain, the audit produces a current-state description, a gap analysis, and a remediation estimate in both time and cost.
The time and cost estimates matter because they reframe the vendor's pitch. A vendor offering a $28 million bundled contract over seven years sounds like a significant investment. But if the readiness assessment reveals that the agency needs six months of policy development, three months of officer training, a network infrastructure upgrade, and a CJIS compliance review before the tool can be deployed responsibly, those remediation costs and timelines belong inside the total cost of ownership calculation. The contract price is not the program cost. The program cost is the contract plus the readiness gap remediation.
The Gap Analysis in Practice
Gaps fall into three categories: blocking, delaying, and manageable.
A blocking gap is one that must be resolved before any AI deployment proceeds. An unresolved CJIS compliance issue is a blocking gap. The absence of a written authorship and verification policy is a blocking gap. A complete absence of prosecutor coordination on disclosure is a blocking gap. Proceeding with deployment over a blocking gap exposes the agency to case challenges, suppression motions, and potential civil liability. No efficiency gain justifies that exposure.
A delaying gap is one that needs to be resolved within the first phase of deployment but does not prevent a carefully scoped pilot. If the agency lacks a community engagement plan but has resolved the CJIS and policy questions, a narrowly scoped pilot with a defined officer cohort and active monitoring is defensible while community engagement proceeds. The pilot cannot expand to full deployment until the delaying gap is closed.
A manageable gap is one that can be addressed in parallel with deployment: a specific training gap for a subset of officers, a reporting pathway that needs refinement, a disclosure language template that needs prosecutor sign-off. These do not block deployment but must be tracked and closed on a defined schedule, not left to drift.
What Good Looks Like: The Readiness Benchmark
An agency that is genuinely ready to deploy AI in a sworn-report context can demonstrate the following without hesitation.
The CJIS compliance review for the proposed platform is documented and complete. Every data flow between the BWC platform, the AI system, and the RMS has been mapped, and the compliance status of each segment is in writing.
The agency has a written AI use policy that specifies authorship, verification standard, authorized use cases, prohibited uses, disclosure requirements, training prerequisites, and the error escalation pathway. The policy has been reviewed by the agency's legal counsel and coordinated with the local prosecutor's office.
A training program exists that produces verifiable competency, not attendance. Officers who complete the training can demonstrate that they know what gap-fills are, how to recognize the three gap-fill signatures, and how to run a footage-grounded verification pass to the standard the policy requires.
The prosecutor's office has received a briefing on the tool and the agency's verification and disclosure practices, and has not objected. Ideally, the prosecutor's office has issued written guidance on what disclosure of AI involvement it expects in discovery packages.
The agency has conducted at least one community or stakeholder engagement on the proposed tool, has documented the concerns raised, and has answers to those concerns in writing.
The contract has been reviewed by legal counsel for data ownership, exit rights, CJIS compliance representations, and liability allocation, and the review is documented.
An agency that can produce all six of those demonstrations is ready to deploy a carefully scoped pilot. An agency that cannot produce them should not deploy, even if the vendor's demo is compelling and the time savings are real.
The Readiness Report and the Command Decision
Chief Okafor's readiness assessment took six weeks and produced a forty-page report. The report found two blocking gaps: the agency lacked a written AI authorship and verification policy, and the CJIS compliance review for the vendor's cloud routing had not been completed. It found three delaying gaps: no community engagement had occurred, the prosecutor's office had not been briefed, and no officer training program existed. It found four manageable gaps in areas like disclosure language templates and error reporting pathways.
The report recommendation was clear: do not sign the proposed contract on the current timeline. Negotiate a sixty-day extension, close the two blocking gaps, and return to the council with a deployment plan that includes the pilot scope, the monitoring protocol, and the community engagement schedule. The council approved the extension without dissent. Six months later, the agency deployed a scoped pilot with twelve officers, a verified training program, a documented prosecutor sign-off, and a community advisory briefing on record.
The pilot produced useful data. The time savings were real: officers in the pilot group reduced average report-writing time by approximately 60 percent, meaningful even if short of the 82-percent benchmark, which reflected a controlled testing environment rather than a mid-shift operational reality. The verification pass added back approximately 15 minutes per report, time well spent compared to the alternative. Three reports in the pilot period required material corrections to AI-generated content: two gap-fills in description language, one quote that the audio did not support verbatim. All three were caught by the verification process and corrected before submission. None reached a deposition.
That is what a readiness-first deployment produces: a program that holds up, a chief who can answer the oversight board's questions, and officers who are equipped rather than exposed.
Key Takeaways
- A readiness assessment is an internal audit of the agency's own systems, policy, workforce, and community posture, conducted before evaluating or committing to a vendor.
- The four pillars are: systems and CJIS infrastructure, policy and governance, workforce skill and culture, and community trust posture. All four must be assessed honestly, not performatively.
- CJIS (Criminal Justice Information Services) obligations stay with the agency regardless of what the vendor certifies. The agency must verify every data flow between its BWC, CAD, RMS, and AI platforms for compliance.
- A written AI use policy must resolve six questions before deployment: authorship, verification standard, disclosure requirements, authorized and prohibited uses, mandatory escalation, and training prerequisites.
- Gaps are blocking, delaying, or manageable. Blocking gaps must be resolved before any deployment. Deploying over a blocking gap creates case-level exposure that no efficiency gain justifies.
- The King County prosecutor's bar on AI-written reports was a readiness verdict, not a technology verdict. The prosecutor required controls that were not yet in place. The lesson is not that AI cannot be used; it is that the controls must come first.
- The total cost of ownership includes the contract price plus readiness gap remediation: policy development, training, infrastructure upgrades, and legal review. Command staff should present the full figure to city council, not the vendor's contract price alone.
- An agency that completes a genuine readiness assessment, closes its blocking gaps, and deploys with a scoped pilot is in a defensible position. An agency that deploys on timeline pressure without the assessment is not.
Skill.re