โ†
AI for Public Safety & First Responders
Strategic ยท M14 ยท lesson 14 of 19 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Standing Up an AI Governance Board
๐Ÿ“–
now learning

Standing Up an AI Governance Board

15 min

The first meeting of the Riverton Police Department's new AI Governance Board lasted three hours and produced one useful document: a list of things nobody in the room had been thinking about before they sat down together. The deputy chief wanted efficiency metrics. The city attorney wanted a record trail. The patrol union rep wanted to know who got blamed when a report went wrong. The records manager wanted to know whether CJIS (Criminal Justice Information Services, the FBI-administered security policy that governs how criminal justice data is stored, transmitted, and accessed) obligations transferred to the vendor when footage went to the cloud. The civilian oversight commissioner wanted public-facing transparency reports. None of those people had been talking to each other about AI. The board was why they were in the same room.

Why a Board Exists: The Governance Gap

When an agency deploys AI-assisted report writing, procurement usually happens faster than governance. A vendor offers a pilot of Axon Draft One or a comparable tool. The tool drafts police report narratives from body-worn camera (BWC, the recording device mounted on an officer's uniform) audio, and testing agencies report substantial time savings: the most cited figure is an 82% decrease in report-writing time in early pilots. Officers who spend roughly 30 to 40% of every shift on paperwork see an obvious benefit. Command staff see overtime costs falling. The contract gets signed.

What does not automatically arrive with the contract is an answer to the questions that officer-at-the-console and the defense attorney at discovery will eventually ask. Who decided this tool is accurate enough to draft sworn evidence? Who reviewed the disclosure policy? Who owns the decision when a case surfaces an AI-generated error? Who ensures that data sent to the vendor's cloud does not violate CJIS obligations the agency never transferred? Who authorized the specific call types the tool is permitted to draft?

These are governance questions. They require legal judgment, operational knowledge, and oversight standing, and they rarely share the same desk. The AI governance board is the structural answer: a standing body with the authority to make those decisions, the documentation to show it made them, and the cadence to revisit them as the technology changes.

An agency that deploys AI without governance has saved time and created exposure. A governance board converts the exposure into a documented, defensible posture.

The King County (Washington) prosecutor's office barred AI-written police reports from its cases in 2023, citing concerns about accuracy and the absence of a documented verification standard. The Electronic Frontier Foundation (EFF, the digital civil-liberties organization that monitors law enforcement technology) has raised transparency concerns about AI police reports, specifically about whether defendants and the public can understand what the AI produced versus what the officer wrote. Both of those actions were responses to a governance gap: agencies deploying tools without answering the questions the outside world was already asking.

A governance board does not prevent those concerns from arising. It prepares the agency to answer them. That is a fundamentally different posture than hoping no one looks closely.

Who Belongs at the Table

The composition of the board is the first and most consequential decision. A board populated only by command staff will optimize for operational efficiency and underweight legal risk. A board populated only by legal counsel will produce cautious policies that line staff cannot implement. A board without oversight representation will have no standing to answer the oversight board when it asks what the governance body actually reviewed.

The minimum viable composition for a law enforcement AI governance board has four seats that must never be empty.

The agency attorney or designated legal counsel must be a voting member of the board, not a resource the board consults on difficult questions. AI-assisted report writing sits at the intersection of Brady v. Maryland (the 1963 Supreme Court case establishing that prosecutors must disclose exculpatory evidence to the defense) and Giglio v. United States (the 1972 case extending that obligation to impeachment evidence, including evidence that could undermine an officer's credibility). When an AI tool drafts a report, any error in that draft that is not corrected and not disclosed is a potential Brady violation. When the tool's error pattern becomes part of an officer's documented record, it is a Giglio issue. These are constitutional obligations, not compliance preferences.

Legal counsel on the board ensures that every tool authorization decision includes an analysis of what disclosure is required, what documentation must accompany the report to satisfy Brady and Giglio, and what the agency's liability exposure looks like if the tool produces an error that is not caught. Legal also owns the relationship with the prosecuting office. The King County precedent exists because an agency-prosecutor relationship around AI disclosure did not happen before the ban. A board with strong legal presence will build that relationship before an incident forces it.

Oversight: The Seat That Keeps the Board Honest

Civilian oversight, whether in the form of a civilian review board representative, an inspector general's office, or an independent monitoring structure, must have a seat. The oversight seat is not decorative. It provides standing: when the board publishes its transparency report or defends its policies to the city council, the presence of an oversight member with voting authority is the difference between the board reporting on itself and the board being audited by someone who sat at the table when the decisions were made.

The EFF concern about AI police reports is fundamentally a transparency concern: the public and defendants cannot distinguish what an AI wrote from what an officer wrote, cannot evaluate the accuracy standard applied, and cannot hold anyone accountable for errors when the authorship trail is opaque. An oversight representative on the governance board brings exactly the perspective needed to close that gap. They will push for public-facing documentation of the verification standard, the disclosure policy, and the error rates the agency tracks. They will ask whether the communities most affected by AI-assisted policing had any voice in the policy. Those questions belong in the boardroom, not in a city council hearing where the agency is already on defense.

Operations: The Seat That Grounds Policy in Reality

A patrol commander, a dispatch supervisor, or a records manager with direct operational experience must be at the table. Policy written without operational input produces verification procedures that look sound on paper and cannot be executed at 2 AM at the end of a twelve-hour shift. The operational representative knows which call types generate the most complex reports, which officers need the most support in verification, how long verification actually takes in the field versus how long the policy assumes it takes, and what the RMS (records management system, the platform where reports are finalized and stored) actually accepts as structured input.

This seat also brings the patrol union relationship into the governance process rather than letting it develop adversarially. Officers need to trust that AI assistance is helping them, not creating a new form of discipline exposure. A governance board that includes operational representation can design policies that officers will actually follow, rather than policies officers technically follow while working around in practice.

Technical: The Seat That Connects Policy to System

A technology lead or CJIS security officer completes the minimum viable board. This seat carries the responsibility of understanding what the vendor's system actually does with agency data: where it is stored, under what security controls, what the vendor's access to Criminal Justice Information Services-covered data looks like, and what happens to the data when the contract ends. CJIS obligations stay with the agency. The vendor signs a contract and may sign a CJIS addendum, but the criminal justice agency is the covered entity and bears the compliance obligation. The technical seat ensures the board never delegates that obligation to the vendor by default.

The technical representative also monitors the vendor relationship over time, tracking whether the tool's output quality changes after model updates, whether the vendor's data retention and deletion practices align with the board's policy, and whether bundled contracts (cameras, drones, cloud storage, and AI in a single multi-year package that can reach $45 million or more over 10-year terms) create vendor dependencies that compromise the board's ability to change tools if the governance picture changes. Lock-in is a governance risk, and the technical seat is where it is caught earliest.

Charter, Authority, and Meeting Cadence

A board without a charter is a meeting. A charter converts the meeting into a governance body with defined authority, defined decisions, and a record of what was decided and why. The charter is also the document the oversight community will request first when they audit the program. Writing it before the first incident means it reflects deliberate policy rather than reactive documentation.

What the Charter Must Contain

The charter needs six components that the reference documents for this program identify as non-negotiable for command-level governance.

First, scope: a specific list of AI tools the board governs, the call types each tool is authorized to assist with, and the case types or sensitivity levels that are explicitly excluded from AI assistance. The exclusion list is as important as the authorization list. A governance board that has not defined where AI assistance stops has not completed its governance function.

Second, authority: the board's decisions must be binding, not advisory, on tool deployment and policy. If a board recommends against deploying a tool and command staff can override without a documented exception process, the board is advisory and its recommendations are optional. That is not governance. The charter should specify which decisions require board approval (new tool authorization, changes to the verification standard, changes to the disclosure policy) and which decisions a specific board member can make administratively between meetings.

Third, the verification standard: a written definition of what constitutes adequate verification of an AI-drafted report. This should include the minimum steps (open the footage, verify each factual claim, document corrections), the documentation required (what the officer records about the verification process), and the consequence of skipping the standard (the report is not authorized for submission). Connecting the verification standard to the charter makes it a governance requirement, not a training suggestion.

Fourth, the disclosure policy: the specific language officers must include when submitting an AI-assisted report, the circumstances under which enhanced disclosure is required (use-of-force incidents, contested cases), and the mechanism for notifying the prosecuting office that a specific case file contains AI-assisted documentation. Brady and Giglio disclosure is not optional, and the board's charter should make that explicit in operational terms rather than leaving it to individual officers to interpret.

Fifth, incident response: a defined process for what happens when an AI-assisted report is found to contain an error. Who is notified? What review is triggered? What documentation is assembled? How is the prosecuting office informed? The incident response protocol is what transforms a potential scandal into a documented, contained, defensible response. This lesson's companion module goes deeper into incident response, but the charter should reference the protocol by name and assign ownership.

Sixth, the meeting cadence and quorum requirements: how often the board meets, what constitutes a quorum for binding decisions, and the minimum documentation requirements for each meeting. A board that meets without producing written minutes that record what was decided and who voted which way is not producing a governance record. The minutes are the audit trail.

Meeting Cadence: Quarterly Is a Minimum

AI governance is not a set-it-and-forget-it function. The tools change. Model updates can alter accuracy profiles in ways that are not announced. Vendor contracts evolve. Prosecutorial guidance shifts. The case law around AI-assisted evidence is developing faster than most governance frameworks anticipated. A quarterly meeting cadence is a minimum; agencies with active deployments across multiple tool types should consider monthly standing meetings with quarterly comprehensive reviews.

Each regular meeting should include a standing agenda item for error reports: any AI-assisted report that was found to contain an error, corrected or not, since the last meeting. This is not punitive. It is the mechanism by which the board learns what failure modes the tools are producing in the field, which call types generate the most errors, and whether the verification standard is working as intended. An error report agenda item treated as routine rather than exceptional is the difference between a board that governs its program and a board that waits for a crisis.

The First Meeting: Getting Practical Fast

Riverton's first governance board meeting worked because the deputy chief came with a draft agenda and a willingness to let the room reshape it. The draft agenda had six items. Four of them were substantially revised by the time the meeting ended, because the room contained people who knew things the deputy chief did not know he did not know.

The city attorney had a list of seven pending cases where AI-assisted reports were in the discovery record. She wanted to know whether each of those reports had been produced under a documented verification standard, because she was about to start getting deposition questions about it. The patrol union rep wanted to know whether the AI system's output was being used in any performance evaluations. The records manager wanted to know whether the vendor could access the CJIS-covered data in the footage that was uploaded to its servers. None of those questions were on the original agenda.

A good first meeting for an AI governance board should accomplish four things. First, it should produce a written inventory of every AI tool currently in use or under evaluation, with the call types each tool is used for and the approximate volume of reports it has touched. Second, it should assign ownership of the draft charter to a specific person with a specific deadline. Third, it should produce a list of open questions, organized by the seat responsible for answering them, with deadlines. Fourth, it should document what decisions the board has authority to make and what decisions require escalation to command or legal before the board can act.

That fourth item is the one that determines whether the board becomes a governance body or a meeting. Boards that cannot make binding decisions produce recommendations that wait for someone else to approve. By the time that approval comes, the situation has changed and the recommendation is stale. A board with clear authority to act produces policy that the agency implements, and produces the documentation trail that an audit will look for.

The Vendor Relationship and the Board

Vendor relationships in public-safety AI have become structurally complex in ways that governance frameworks from five years ago did not anticipate. Bundled contracts that package body-worn cameras, drone systems, cloud storage, and AI-assisted tools into a single multi-year arrangement can reach $45 million or more over terms of up to 10 years. Those contracts create dependencies that outlast the board members who approved them and the policies that governed them at signature.

The governance board should treat vendor relationships as an ongoing governance function, not a procurement event. That means the board should review vendor contracts before renewal, not after. It should require the vendor to report any material changes to the AI model's architecture, training data, or output behavior. It should define what the agency owns: the reports, the footage, the audit logs, and any derivative data the vendor produces from agency materials. And it should define the exit path: what happens to the data when the contract ends, and whether the agency can migrate to a different vendor without losing access to historical audit records.

The CJIS compliance question is central here. Criminal Justice Information Services Security Policy requires agencies to ensure that any system touching criminal justice information meets specific security standards. When footage containing CJIS-covered data is uploaded to a vendor's cloud for AI processing, the agency is responsible for ensuring the vendor's system meets those standards. A vendor's promise in a sales deck that they are "CJIS compliant" is not a substitute for a written CJIS addendum in the contract and a technical audit of the vendor's controls. The technical seat on the governance board owns this review.

The Sole-Vendor Trap

A governance board that approves a bundled, sole-vendor contract without reviewing the long-term lock-in risk is abdicating a core governance function. When the agency's cameras, drones, cloud infrastructure, and AI tools are all on the same vendor's platform, changing any one component requires renegotiating the whole bundle. Policy changes that would require switching the AI tool are effectively blocked by the cost and complexity of exit. A governance that approved a 10-year contract with exit fees is a governance that traded long-term flexibility for short-term cost savings.

The board should require, as a condition of approving any multi-year bundled contract, a written analysis of the exit path at each major renewal milestone. What would it cost to switch the AI component while retaining the camera and cloud infrastructure? What data portability rights does the agency have? What happens to the historical audit logs if the vendor relationship ends? These are not hypothetical questions. They are the questions the board's successors will ask in year seven when the model has been updated fifteen times, the disclosure policy has changed, and the current vendor's AI component no longer meets the standard the board wrote in year one.

Transparency Reporting and Community Accountability

A governance board that does its work in private and publishes nothing produces internal documentation that may satisfy an audit but will not satisfy the community. The EFF's transparency concerns about AI police reports are not concerns about whether the agency has internal records. They are concerns about whether the public and defendants have enough information to hold the agency accountable. A governance board that takes those concerns seriously will build external reporting into its regular cadence.

External transparency reporting does not require disclosing sensitive operational information. It requires disclosing what the board has authority to disclose: what AI tools are in use, what call types they are authorized for, what the verification standard requires, how many reports were flagged for errors in the reporting period, and what the board's current disclosure policy is. A transparency report that answers those questions honestly, once a year, provides the community with the information they need to evaluate the program. It also preempts the requests for that information that arrive in a less organized form: public-records requests, city council inquiries, advocacy organization reports, and news coverage that fills the information vacuum with whatever facts it can assemble.

The civilian oversight representative on the board is the natural owner of the external transparency report. That representative has the standing, the relationship with community organizations, and the perspective to know what the public actually needs to understand versus what is operational detail. Giving the oversight seat ownership of the external report is also a governance structure signal: the board is not reporting on itself in isolation. It is accountable to an external constituency represented at the table.

Key Takeaways

  • An AI governance board is a standing body with binding authority over tool deployment, verification standards, disclosure policy, and incident response. A board that only makes recommendations is not governance; it is an advisory meeting.
  • The minimum viable board has four seats: legal counsel (Brady and Giglio obligations require a voting legal member, not an advisory consultant), oversight (civilian review or inspector general standing), operations (a patrol or dispatch commander who knows what verification looks like at 2 AM), and technical (CJIS security and vendor oversight).
  • The charter is the document that converts the board from a meeting into a governance body. It must define scope, authority, the verification standard, the disclosure policy, the incident response protocol, and the meeting cadence with quorum requirements.
  • CJIS (Criminal Justice Information Services) obligations stay with the agency. Uploading footage to a vendor's cloud for AI processing does not transfer the compliance obligation. The technical seat on the board is responsible for verifying the vendor's controls and maintaining the CJIS addendum in the contract.
  • Bundled multi-year contracts (cameras, drones, cloud, AI in a single package, sometimes reaching $45 million over 10-year terms) create governance lock-in. The board must require a written exit-path analysis before approving any sole-vendor bundle.
  • The King County prosecutor's ban on AI-written reports and the EFF's transparency concerns are both responses to governance gaps. A board that builds the relationship with the prosecuting office and publishes an annual transparency report answers those concerns before they become bans or headlines.
  • Every board meeting should include a standing error-report item: AI-assisted reports found to contain errors since the last meeting. Treating error review as routine governance rather than an exceptional event is how the board learns what failure modes the tools produce and whether the verification standard is working.
  • The first meeting should produce four things: a tool inventory, an assigned charter owner with a deadline, an open-questions list with owners and deadlines, and a clear definition of the board's authority to act. A board that leaves its first meeting without those four things will spend its second meeting relitigating the same ground.