Multi-Year Investment and Contracting
Sheriff Luis Navarro sat across from the vendor's regional director in the county conference room and looked at the proposal: cameras, drones, cloud storage, evidence management, and AI-assisted report writing, all in one agreement, for forty-four million dollars, term of nine years. "It's the best per-unit price you'll find," the director said. The sheriff understood the economics. What the director did not say was that in nine years the AI governance landscape would look nothing like 2026, the county's prosecutor might have adopted a policy resembling the King County, Washington, bar on AI-written police reports, and the sheriff would have no contractual right to exit the AI component without renegotiating cameras, drones, and evidence storage simultaneously.
The Investment Thesis for AI in Public Safety
Public safety agencies spend substantial resources on administrative work. Officers spend 30 to 40 percent of every shift on paperwork. In an agency of 400 sworn personnel averaging a 40-hour week, that is 4,800 to 6,400 officer-hours per week consumed by report writing, CAD (computer-aided dispatch, the system that logs dispatch events and unit assignments) entry, records management, and related documentation. At a fully-loaded labor cost of 90 dollars per hour, that is 432,000 to 576,000 dollars per week, or 22 to 30 million dollars per year, in sworn-officer time spent on documentation that AI can partially assist.
The case for AI investment is not speculative. Axon Draft One, which drafts police report narratives from body-worn camera (BWC, the recording device worn on an officer's uniform) audio, has been reported to reduce report-writing time by 82 percent in officer testing. AI-assisted redaction of body-camera footage for public records releases has been shown to reduce per-release processing time by substantial margins. AI-assisted call summarization reduces the time telecommunicators spend producing written summaries from recorded calls. These are real productivity improvements with a real dollar value.
The investment thesis rests on translating those productivity improvements into operational outcomes, not just budget savings. The hours AI returns do not automatically reduce headcount. They return to patrol, investigations, community contact, and training. An agency that uses AI to recover two hours per officer per shift has eight more officer-hours per day per officer available for the work that requires human presence, judgment, and accountability. At 400 officers, that is 3,200 additional patrol-equivalent hours per day. That is a significant operational capability expansion that does not require hiring a single additional officer.
The investment case to a city council or county board must make this translation explicit. A council that hears "AI saves time on paperwork" without understanding where that time goes will ask whether the agency can be run with fewer officers. That is the wrong question, and it leads to the wrong policy. The right framing is: AI returns time to sworn work. The agency uses that time for patrol coverage, investigation caseloads, and community engagement, all of which are currently constrained by the documentation burden. AI does not replace officers. It gives existing officers more time to do officer work.
The ROI Calculation
The return on investment for an AI program in public safety has multiple components. The labor productivity component is the most straightforward: hours returned multiplied by loaded labor cost, adjusted for the actual adoption rate and the actual time reduction realized in this specific agency's environment (the vendor's 82 percent figure is a benchmark to verify, not a contractual guarantee). The operational capability component is harder to quantify but more important: the reduction in report backlog, the reduction in overtime caused by documentation delays, the improvement in response time available from officers who are not at the station writing, and the improvement in case quality from investigators who can spend more time investigating.
The risk adjustment component is the one most agencies omit from their ROI calculations: the cost of a suppression motion caused by an AI error in a report that was not properly verified, the cost of a civil rights claim caused by an AI-assisted narrative that overstated a threat, and the cost of a case thrown out because the King County-style objection was sustained. These are not hypothetical risks. The King County, Washington, prosecutor's actual decision to bar AI-written reports is evidence that the litigation risk is real. An ROI calculation that does not include a risk adjustment is not complete and will not survive a council audit.
The Structure of Public Safety AI Contracts
Understanding how AI contracts are structured in public safety is essential before signing one. The dominant procurement model in 2026 is the bundled platform: a single vendor offering cameras, drones, cloud evidence storage, AI-assisted report writing, real-time crime center integration, and evidence management in a single agreement. This bundling is commercially rational from the vendor's perspective. It creates stickiness, reduces competitive exposure, and generates predictable recurring revenue. From the agency's perspective, it simplifies procurement but concentrates risk.
Contracts in this space have reached approximately 45 million dollars with terms of up to ten years. A nine-year, 44-million-dollar contract like Sheriff Navarro's proposal is within the normal range for a mid-to-large agency. These contracts are often presented as favorable per-unit pricing that is only available in the bundled form. That pricing advantage is real and should be weighed honestly. The lock-in cost is also real and must be weighed honestly. The question is not whether bundled contracts have value. They do. The question is how to capture the value while managing the lock-in risk.
The CJIS Dimension of Contracts
The Criminal Justice Information Services (CJIS) Security Policy, which governs how criminal justice information is handled, stored, and transmitted, creates a specific contract consideration. Every vendor in this space will agree to handle data in a CJIS-compliant way. What agencies must understand is that CJIS compliance is not something a vendor can assume on the agency's behalf. The obligations stay with the agency. If the vendor has a data breach involving criminal justice information that was stored on the vendor's cloud infrastructure, the agency is accountable for that information's exposure. If the vendor's AI model ingests criminal justice data in a way that violates CJIS retention or access requirements, the agency is accountable. The vendor agreement to be CJIS-compliant is a contractual obligation the agency can enforce; it is not a transfer of the agency's CJIS accountability.
This means every contract for AI services involving criminal justice information must include: specific CJIS compliance attestation requirements, independent audit rights that allow the agency (not just the vendor) to verify CJIS compliance, breach notification requirements that specify exactly when and how the agency is notified if CJIS-covered data is exposed, and data destruction or return requirements at contract end that meet CJIS retention standards. These are not negotiating niceties. They are the minimum requirements for an agency that takes its CJIS obligations seriously, which every agency is required to do.
Negotiating Against Lock-In
The lock-in risk in a bundled, multi-year, sole-vendor contract is real and specific. It shows up in four scenarios: the AI model develops a systemic bias or accuracy problem; the vendor's data practices become legally or policy problematic; the policy environment changes (as it did when King County issued its bar) in ways that require the agency to use a different AI approach; or a competing technology emerges that is significantly more accurate, less expensive, or more privacy-protective than the locked-in vendor's platform.
Each of these scenarios is realistic. The King County scenario is historical fact. AI model bias discoveries are not hypothetical: bias in AI systems used in criminal justice has been documented in facial recognition and predictive policing contexts. Vendor data practice problems have occurred in the legal technology space. And the AI technology landscape is evolving rapidly enough that a technology decision locked in for ten years is almost certainly sub-optimal at the back end of that term.
The negotiating framework against lock-in has four components. They should appear in every AI contract an agency signs, regardless of term length or bundle configuration.
The first component is data portability. The agency's data is the agency's data. At contract end, or upon termination for any reason, the vendor must return or destroy all agency data in a format the agency can use with a different system. This includes BWC footage, CAD records, RMS (records management system) data, AI-generated drafts and logs, and any other criminal justice information the vendor's platform has handled. The data portability terms must specify the format, the timeline, and the cost (ideally zero additional cost). A vendor that resists data portability terms is telling the agency that its business model depends on data hostage-taking, which is information the agency should have before signing.
The second component is performance standards with independent audit rights. The contract must specify measurable performance standards for the AI components: accuracy metrics, false positive and false negative rates for any classification function, availability and uptime, and response time for error correction. The agency must have the contractual right to verify those standards independently, through its own review or through a third-party audit, not solely through vendor-provided reports. Vendor-provided performance data is not independent verification.
The third component is a termination for cause clause that includes AI-specific triggers. Standard termination clauses cover breach of contract and bankruptcy. AI contracts in public safety need specific termination triggers: documented systemic bias in AI outputs affecting protected classes, sustained accuracy failures below the contract standard, regulatory or legal prohibition on the use of the AI model in criminal justice proceedings (the King County scenario formalized), and documented CJIS violations by the vendor. These triggers allow the agency to exit the AI component when continuing would create legal or constitutional exposure, even if the cameras and cloud storage are working perfectly.
The fourth component is a modular structure wherever the bundle permits. Bundled contracts are sometimes negotiable into modular form: the AI component is separately priced and separately terminable, even if the cameras and cloud storage are in the same master agreement. A modular structure allows the agency to renegotiate or exit the AI component on a different timeline than the hardware and storage components, which have much longer useful lives and lower regulatory complexity.
The best time to negotiate data portability and exit rights is before you sign. The second-best time is now. There is no third-best time.
Multi-Year Investment Planning
A multi-year AI program in public safety requires multi-year budget planning, which is a different discipline than the annual budget cycle most agencies operate under. The costs of an AI program are not evenly distributed across years. Year one is typically the highest-cost year: contract inception, implementation, hardware deployment, training, and the governance infrastructure build (the policy, the audit trail system, the disclosure coordinator role, the review cadre). Years two and three are the validation and scaling years, with costs shifting from implementation to operations, measurement, and program management. Years four and beyond are the steady-state years, where the cost structure is primarily the recurring contract fee, the ongoing training program, and the measurement and oversight function.
The budget planning must also account for costs that are outside the vendor contract. These include: the agency AI lead position, which is a new or reallocated FTE (full-time equivalent) with a fully-loaded cost in the 120,000 to 180,000 dollar range depending on market; the disclosure coordinator function, which may be a partial FTE or a responsibility added to an existing legal or records role; the training program, which has an ongoing cost per new officer and per policy update cycle; the audit trail infrastructure, which may require IT investment if the agency's current systems do not produce the required logs; and the legal review function, which should include periodic review of the disclosure format and verification standard by the prosecutor's office and agency counsel.
The total cost of the program, not just the contract cost, is what the council needs to evaluate the investment. An agency that presents only the contract cost to council and then later requests supplemental appropriations for the AI lead position and the audit trail infrastructure has not been transparent about the full investment, and the council will notice.
Phasing the Investment
The most financially sound approach to a multi-year AI investment is phasing: starting with lower-risk, faster-payback use cases, validating the operating model on those cases, and expanding to higher-complexity use cases only after the governance infrastructure is in place and proven. The redaction use case, as noted in the transformation playbook, offers a strong pilot: real time savings, a clear accuracy metric, and constitutional risk that is lower than the sworn report chain. A successful redaction program produces validated ROI that can fund or justify the higher-cost report-writing program that follows.
Phasing also allows the agency to renegotiate at natural break points. A two-year redaction pilot that succeeds gives the agency real performance data to bring to the table when it negotiates the report-writing contract. The agency is no longer buying a vendor promise. It is buying a performance record. That is a fundamentally stronger negotiating position than committing to a ten-year bundle before a single pixel of footage has been redacted.
The Disclosure Obligation as a Contract Requirement
The Brady v. Maryland (the 1963 Supreme Court case requiring disclosure of exculpatory evidence to the defense) and Giglio v. United States (the 1972 case requiring disclosure of impeachment evidence including information affecting officer credibility) disclosure obligations that arise when AI is in the evidence chain are not just program design requirements. They are contract requirements. The vendor's platform must support the disclosure workflow the agency's operating model requires.
This means the contract must specify: what data about AI involvement in a report is logged (the tool used, the timestamp, the officer's verification log, the original AI draft), in what format that data is retained, how long it is retained (which must meet both CJIS retention requirements and Brady's "any duration of the case" standard), and how it can be produced in response to a discovery request. A vendor whose platform cannot produce this data in a usable format is a vendor whose platform creates Brady exposure by design. That is not a product deficiency to overlook in exchange for a favorable per-unit price. It is a constitutional deficiency that makes the product incompatible with an agency's legal obligations.
The prosecutor's office should review the contract's AI logging and disclosure requirements before the contract is signed. This is an alignment step, not a procurement step. The prosecutor whose office will be expected to use the disclosed AI data in its own disclosure process needs to confirm that what the vendor's platform produces meets the standard the prosecutor's office will require. A platform that produces an AI-use log that the prosecutor's office cannot parse has not met its Brady obligation, regardless of what the contract says.
Key Takeaways
- The investment thesis for AI in public safety rests on translating productivity improvements into operational outcomes: officers spend 30 to 40 percent of every shift on paperwork, and AI returns hours to patrol, investigations, and community contact, not necessarily to budget savings alone.
- A complete ROI calculation includes the labor productivity component, the operational capability component, and the risk adjustment component: the litigation cost of a suppression motion or civil rights claim caused by an AI error that was not caught. Omitting the risk adjustment is an incomplete analysis that will not survive a council audit.
- Bundled sole-vendor contracts reaching approximately 45 million dollars with up to ten-year terms are the dominant procurement model. The per-unit pricing advantage is real; the lock-in risk is also real and must be weighed honestly before signing.
- CJIS obligations remain with the agency regardless of vendor contract terms. The vendor's agreement to be CJIS-compliant is enforceable but is not a transfer of the agency's accountability. Every AI contract must include CJIS compliance attestation, independent audit rights, breach notification requirements, and data destruction or return terms.
- Negotiating against lock-in requires four specific contract elements: data portability terms, performance standards with independent audit rights, AI-specific termination triggers (including a King County-style regulatory prohibition trigger), and modular contract structure where possible.
- Brady v. Maryland and Giglio v. United States make the vendor's disclosure logging capability a contract requirement, not a program design preference. A platform that cannot produce AI-involvement data in a format the prosecutor's office can use creates constitutional exposure by design.
- Multi-year budget planning must account for the full program cost, including the agency AI lead position, the disclosure coordinator, ongoing training, audit trail infrastructure, and legal review, not just the vendor contract cost. Presenting only the contract cost to council is incomplete disclosure.
- Phasing the investment, starting with lower-risk use cases like redaction and validating the operating model before expanding to sworn report writing, produces validated ROI data for subsequent negotiations and a fundamentally stronger contracting position than committing to a ten-year bundle before any performance data exists.
Skill.re