โ†
AI for Public Safety & First Responders
Strategic ยท M19 ยท lesson 19 of 19 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Writing an AI Use Policy
๐Ÿ“–
now learning

Writing an AI Use Policy

15 min

Chief Anita Reyes set her coffee on the conference table at 6:47 a.m., opened a blank document, and typed the words "Artificial Intelligence Use Policy" at the top. She had been asked by the city manager to have a draft ready before the next city council meeting, three weeks away. Her agency had been running Axon Draft One, the AI-assisted report-writing tool that drafts patrol narratives from body-worn camera (BWC) audio, for four months. The reports were going out. The time savings were real. But she had no written policy, and she knew it.

Why the Policy Exists Before the Problem Arrives

Chief Reyes did not need a policy because her officers were misusing the tool. She needed it because every AI-assisted document that left her agency without a governing policy was an unguarded exposure: a report whose chain of authorship was undocumented, a disclosure that had never been standardized, a prohibited use that nobody had named. The policy is not the solution to a crisis. It is the architecture that makes a crisis less likely and the response to one coherent.

This is the practical meaning of governance: naming the rules before they are tested. A police report is evidence. Under Brady v. Maryland (1963), the government must disclose exculpatory evidence to the defense. Under Giglio v. United States (1972), the government must disclose impeachment material, including evidence that could call a witness's credibility into question, which includes the credibility of the officer who wrote the report. "Brady" and "Giglio" are not abstract legal concepts. They are the two constitutional doctrines that make AI-assisted report writing a disclosure question, not just a technology question. If the method of generating a report is material to the defense's ability to challenge it, that method must be disclosed. The policy is the place where that obligation is made operational.

In King County, Washington, a prosecutor's office formally barred AI-written police reports from cases it would charge. The reason was not hostility to technology. The reason was that no governing policy existed to tell the prosecutor's office how the AI had been used, how the officer had reviewed the output, what corrections had been made, and what disclosure had accompanied the report. In the absence of that documentation, the prosecutor could not represent the report's reliability to a court. The King County decision is not a warning about AI. It is a warning about ungoverned AI. The policy Chief Reyes is writing is the answer to that warning.

A use policy does not restrict what AI can do. It specifies what the agency will do with it, and what it will document, so that every AI-assisted report can be defended by the officer who signed it, the prosecutor who filed it, and the chief who authorized the program.

The Four Pillars Every Policy Must Cover

A defensible AI use policy for a law enforcement agency must address four structural questions. Each question maps to a concrete vulnerability. Missing any one of them leaves a gap that a defense attorney, an oversight board, or a prosecutor will find.

Pillar One: Authorship

Who is the author of the report? This question has only one acceptable answer in a sworn context: the officer. Axon Draft One, to use the specific product Chief Reyes's agency has deployed, drafts a narrative from the audio captured by the body-worn camera. That draft is a starting point. It is not a report. The officer reviews it, corrects it, supplements it with personal observations the audio did not capture, and adopts it. The moment the officer submits the report, they are the author of record. Not the AI. Not the vendor. The officer.

The policy must say this explicitly, and it must say it in terms an officer can quote in a deposition. "Did you write this report?" is a question the officer will be asked. The answer is: "I reviewed the AI-assisted draft, made corrections as necessary, and adopted it as my sworn account." That answer is defensible. "The computer wrote it" is not. "I'm not sure where that sentence came from" is not. The policy creates the framework that makes the first answer possible and the other two impossible.

Authorship language in the policy should include: (1) the officer is the author of every submitted report regardless of how the draft was generated; (2) submission of the report constitutes adoption of its contents as the officer's sworn account; (3) the officer's review is not optional and is not satisfied by reading the draft without checking it against the source record; and (4) any correction made to the AI draft must be documented in the report's audit trail.

Pillar Two: Verification

How must the officer verify the draft before adoption? This is the technical heart of the policy, and it is the pillar most agencies underspecify. Saying "officers must review the draft" is not a verification standard. It is an invitation to a wide range of practices, most of which will not survive cross-examination.

The verification standard the policy should establish draws directly from what this program calls the footage-grounded verification pass: every factual claim in the draft must be checked against the body-worn camera recording, the computer-aided dispatch (CAD) entry, and the officer's field notes. CAD is the timestamped record of dispatch information. The records management system (RMS) is the database where reports are stored and from which they are retrieved for prosecution and discovery. CAD and RMS entries are corroborating records; the footage is the primary evidentiary anchor.

The policy should specify minimum verification steps: (1) check sequence of events against footage timestamps; (2) verify every quoted statement against the audio; (3) flag and correct any use-of-force description that is not grounded in what the footage shows; (4) confirm that names, dates, addresses, and call data match the CAD entry; and (5) document the verification as completed in the audit trail before submission.

The use-of-force section deserves separate, explicit treatment in the policy. AI models trained on law enforcement reports encounter use-of-force boilerplate with high frequency and can apply standard language to describe specific incidents in ways that are not accurate to what the camera recorded. The policy should state that use-of-force descriptions in AI-assisted reports are subject to zero-tolerance verification: every claim about what a subject did, what the officer did, and the sequence of physical events must be confirmed against the footage before the report is submitted.

Pillar Three: Disclosure

What must be disclosed, to whom, and when? This is the pillar that directly addresses the King County-style objection. The policy should establish a standard disclosure statement, appended to or embedded in every AI-assisted report, that identifies: (1) that the report was drafted with AI assistance; (2) the name and version of the tool used; (3) the officer who reviewed and adopted the draft; (4) the date and time of review; and (5) that corrections were made as needed.

This disclosure is not a mark of weakness. It is the documentation that keeps a case from being thrown out. A defense attorney who receives a disclosure statement knows exactly what to ask about. A defense attorney who learns in discovery that an AI tool was used but no disclosure was made has the grounds for a motion to suppress and a Brady violation argument. Disclosure by design, embedded in the workflow rather than added at the discretion of the individual officer, removes that vulnerability from every case the agency works.

The policy should also address disclosure to the prosecutor's office. The district attorney's (DA) office and the agency need a shared protocol. That protocol should define what documentation accompanies a case charging package when AI-assisted reports are included, and it should be established in writing before cases are charged, not during discovery when the defense is already in the file. The working-with-prosecutors lesson covers this in depth; the use-policy lesson establishes the agency-side obligation to have the conversation.

Disclosure under open-records statutes is a separate matter. Public-records requests for AI-assisted reports may implicate disclosure of the AI tool's role, depending on the jurisdiction's public-records law. The policy should address this: the agency's records unit should document AI assistance in a way that is responsive to public-records requests without disclosing privileged investigative material. Over-redaction and under-redaction are both failures. The policy should make clear which fields are disclosable and which are protected, and who makes that determination.

Pillar Four: Prohibited Uses

What is the AI tool not permitted to do? A use policy without a prohibited-uses section is not a policy; it is a permission slip. The prohibited-uses section names the specific applications the agency has determined are outside the scope of authorized use, regardless of what the vendor's platform technically allows.

A model prohibited-uses list for a report-drafting AI includes:

  • Generating reports for incidents the officer did not personally witness or respond to. The officer must have been on scene. An AI cannot substitute for presence.
  • Drafting use-of-force reports without a human-only review step separate from the standard verification pass. Use-of-force reports should carry a second review by a supervisor who has also reviewed the footage.
  • Using AI-generated output as the basis for sworn affidavits, search warrant applications, or arrest warrant applications without explicit command-staff authorization and a documented independent review. Warrant affidavits are sworn documents with immediate liberty consequences. The threshold for AI assistance in that context is higher, and the policy must reflect it.
  • Uploading criminal justice information to a third-party AI platform not covered by the agency's Criminal Justice Information Services (CJIS) security agreement. CJIS is the Federal Bureau of Investigation's (FBI's) security policy for criminal justice information. Obligations under CJIS stay with the agency, not the vendor. A patrol officer who pastes a case summary into a consumer AI chatbot for help rewriting it may have just violated CJIS. The policy must say so explicitly.
  • Using AI to generate or alter evidence, to create retroactive accounts of incidents not captured on camera, or to supplement a report with details the officer does not personally recall and cannot verify from the footage.
  • Using AI-assisted tools without completing and logging the required verification pass. The verification step is not optional. Submitting a report without completing it violates the policy.

CJIS, Data Handling, and What the Vendor Cannot Own

Chief Reyes's agency is in a multi-year contract with a bundled vendor: body-worn cameras, cloud evidence storage, and the AI report-drafting tool are all from the same company. The contract runs for ten years and covers both hardware and software. This is a common procurement structure in 2026, with bundled contracts reaching approximately $45 million over ten years being reported across mid-size agencies. The structure is not inherently wrong, but it creates a specific obligation: the agency must understand what CJIS compliance the contract covers and what it does not.

CJIS, which stands for Criminal Justice Information Services Security Policy, sets minimum security controls for any system that accesses, stores, transmits, or processes criminal justice information. The FBI administers CJIS compliance, and every state has a CJIS Systems Agency that enforces it locally. The vendor's cloud platform may be CJIS-compliant. That does not mean every use of the platform is covered. If officers are uploading footage, case notes, or narrative drafts to a system not covered by the agency's CJIS agreement, or to a consumer AI tool entirely outside that agreement, the agency is out of compliance regardless of what the vendor's marketing materials say.

The policy must establish: (1) which AI tools are authorized for use with criminal justice information; (2) which platforms are covered by the agency's CJIS agreement; (3) the explicit prohibition on using consumer AI tools with criminal justice data; and (4) the process for adding a new AI tool to the authorized list, including a CJIS compliance review before authorization. This is not a procurement question. It is an operational obligation that belongs in the policy and in training.

Data retention is a related issue. AI-drafted reports exist in a vendor's cloud before they are adopted and submitted to the RMS. Who owns those pre-adoption drafts? How long does the vendor retain them? Are they subject to the same evidence-retention obligations as adopted reports? Are they discoverable? These questions must be answered in the vendor contract, and the policy should reference the answers. If the contract is silent on pre-adoption data retention, that is a gap the agency's legal advisor must close before the next case goes to trial.

Writing the Document: Structure, Language, and the Review Cycle

A practical AI use policy for a law enforcement agency does not need to be long. It needs to be precise. Chief Reyes's draft, when complete, should accomplish the following in approximately four to eight pages:

Section 1: Purpose and scope. What the policy covers, which tools it applies to by name, and which personnel are subject to it. If the policy applies only to patrol officers, say so. If it applies to investigators, dispatchers, and records staff using different tools, say that. Scope ambiguity is a compliance problem waiting to happen.

Section 2: Definitions. AI-assisted report, AI draft, verification pass, adopted report, disclosure statement, prohibited use, CJIS-covered platform. Every term the policy uses must be defined in the policy itself. Do not assume that officers will look up definitions elsewhere.

Section 3: Authorship standard. Verbatim: the text that officers can quote in a deposition and supervisors can apply in a disciplinary review. No ambiguity.

Section 4: Verification requirements. Step by step. Not "officers must review the draft." The specific steps, in order, with the use-of-force section called out separately.

Section 5: Disclosure requirements. The standard disclosure statement, verbatim. The requirement to provide it. The parties to whom it must be provided. The form in which it must be documented.

Section 6: Prohibited uses. A numbered list. Clear, specific, not open to interpretation.

Section 7: CJIS and data handling. Authorized platforms by name. The prohibition on consumer AI tools. The process for authorizing new tools.

Section 8: Audit trail and accountability. How AI use is logged, who reviews the logs, and at what cadence. This section is what makes the policy auditable rather than merely aspirational.

Section 9: Violations and consequences. What happens when an officer does not complete the verification pass before submitting. What happens when the CJIS prohibition is violated. The policy must have teeth, stated clearly, or the compliance rate will reflect its toothlessness.

Section 10: Review cycle. When the policy is reviewed and by whom. AI tools and the legal landscape around them are changing rapidly. A policy written in 2026 may need revision in 2027. The review cycle should be no longer than annual, and any change to the authorized tools list or any significant legal development (a new King County-style objection, a court ruling on AI-assisted reports, a change in CJIS guidance) should trigger an interim review.

Who Must Sign Off

Chief Reyes should not finalize the policy without sign-off from the agency's legal advisor, the prosecutor's office (at least informally, as part of the relationship-building this program covers in the next lesson), and, depending on the agency's governance structure, the civilian oversight board. Getting those signatures is not a formality. It is the test of whether the policy is defensible. If the legal advisor has a problem with a section, the problem exists regardless of whether the advisor signed. Better to find it in draft review than in discovery.

Union leadership should also be involved in the review process, particularly around the authorship and verification obligations. An officer who understands the policy because their union was at the table during its drafting is more likely to follow it than one who received it in a training email. Operational buy-in is not separate from legal compliance. It is the mechanism by which legal compliance happens at scale.

The Policy Is a Living Document, Not a Filing Obligation

Three months after Chief Reyes published the policy, one of her investigators came to her with a problem. The AI tool had flagged a section of a report as potentially involving a use-of-force event that the investigator had classified as a simple arrest. The investigator was not sure whether the flagging constituted an AI recommendation or just a formatting artifact of the platform. The policy did not address AI-generated flags or alerts. It only addressed AI-generated drafts.

This is the nature of AI policy in 2026: the technology evolves faster than any single policy document can anticipate. The policy should not try to enumerate every possible AI behavior. It should establish the principles that govern any AI behavior: the officer is the author, the footage is the source of truth, prohibited uses are named and enforced, CJIS obligations are maintained, and disclosure is by design. When a novel situation arises that the policy does not explicitly address, those principles provide the answer. The investigator in Chief Reyes's agency should treat an AI-generated flag exactly as they would treat any other AI output: the officer determines its accuracy by checking it against the record, and if it is acted upon, that action is documented.

The Electronic Frontier Foundation (EFF) has raised transparency concerns about AI police reports, specifically about whether agencies and vendors are being sufficiently candid with prosecutors, defense attorneys, and the public about the role AI plays in generating evidence. Those concerns are legitimate and deserve a direct response in the policy. The answer to the EFF's concern is not a defensive posture. It is a disclosure standard and an audit trail that makes the AI role visible and accountable. A policy that would embarrass the agency if published is a policy that needs revision before it is finalized.

Chief Reyes finished her first draft at 9:15 a.m. She sent it to the legal advisor, the patrol commander, and the records supervisor. She also called the lead DA in the county and asked for thirty minutes before the next charging conference. She had a policy. Now she needed to make sure the people who would test it every day were part of building it.

Key Takeaways

  • A use policy is not a response to a crisis; it is the architecture that prevents ungoverned AI from becoming one. The King County prohibition on AI-written reports was a warning about ungoverned AI, not AI itself.
  • Every AI use policy for law enforcement must cover four pillars: authorship (the officer is always the author of record), verification (a specific, footage-grounded standard, not a passive read-through), disclosure (by design, to every party who receives the report), and prohibited uses (named specifically, not left to interpretation).
  • Brady v. Maryland and Giglio v. United States make AI-assisted report writing a constitutional disclosure question: if the method of generating a report is material to the defense's ability to challenge it, that method must be disclosed.
  • CJIS obligations stay with the agency. The vendor's CJIS compliance does not cover officers uploading criminal justice information to consumer AI tools. The policy must name authorized platforms and prohibit others explicitly.
  • The use-of-force section of any AI-assisted report requires a separate, heightened verification standard stated in the policy: every claim about what a subject did, what the officer did, and the sequence of physical events must be confirmed against the footage before submission.
  • The policy should be reviewed at least annually and whenever a significant legal development, a court ruling on AI-assisted reports, or a change in CJIS guidance occurs. The tools will change faster than a static policy can track them.
  • Legal advisor, prosecutor's office, and civilian oversight sign-off are not formalities. They are the tests of whether the policy will hold under the scrutiny it will face in court and in public. Get them before publication.
  • Transparency is the answer to legitimate EFF and civil-liberties concerns about AI police reports. A disclosure standard and an audit trail that make the AI role visible and accountable are the policy's best defense against those concerns, and against the suppression motion that follows their absence.