Toward AI-Enabled Response (and Its Limits)
The chief of a mid-sized department sat in her office at 6 a.m. on a Tuesday, reading a vendor briefing that promised the agency could "automate incident classification, predict patrol deployment, and accelerate report review with one platform." She had been through three budget cycles trying to claw back patrol hours from paperwork. She knew the 30 to 40 percent of every shift that officers spent writing reports was time those officers were not in the community. She also knew that her agency had just finished a two-year legal battle over a use-of-force case in which a contested detail in an AI-drafted narrative had added six months to the litigation. She set the briefing down and asked herself the question that this lesson is built to answer: of everything AI can do for public safety, what may we responsibly automate, and what must we not?
The Promise Is Real, and So Are the Limits
Before drawing any lines, the promise deserves a full and honest accounting. Axon's Draft One, the AI-assisted report drafting tool integrated into the body-worn camera (BWC, the recording device worn on an officer's uniform) evidence platform, reported testing officers experiencing an 82 percent decrease in report-writing time. If officers spend 30 to 40 percent of every shift on paperwork, as documented across patrol force research, that 82 percent reduction translates to returning between 25 and 33 percent of a shift to the community, to patrol, to investigations, to the interactions that the job is actually supposed to consist of. At the scale of an agency with 200 patrol officers, that is tens of thousands of hours per year. The opportunity is not hypothetical. Agencies are already capturing it.
AI is also demonstrating real value in computer-aided dispatch (CAD) call transcription, which converts caller audio to structured text in real time and gives telecommunicators a timestamped record without requiring manual data entry during the call. AI-assisted redaction is accelerating records management system (RMS) release queues, helping agencies meet public-records deadlines that once required weeks of manual frame-by-frame review. AI-powered interview summarization is giving detectives the ability to locate specific statements across hours of recorded interviews in minutes rather than hours, focusing investigative judgment on the facts rather than on retrieval.
These are genuine improvements. They are also improvements that carry distinct risk profiles. The question of responsible automation is not whether to use AI. At most agencies, that decision is already made, with vendors already under contract and tools already in use or on the near horizon. The question is which functions may be handed off, which may be assisted, and which must remain fully human regardless of how good the AI's output looks on any given day.
The right frame is not "how much can we automate" but "what are the costs of a failure at each step, and who bears them?"
What May Responsibly Automate
Responsible automation in public safety falls into a recognizable category: high-volume, rules-based tasks where errors are catchable before they cause harm, where the human review step is genuine and practiced, and where the cost of an AI error is proportionate to the corrective mechanism available.
Report Drafting with Verified Human Adoption
AI-assisted report drafting, when implemented correctly, sits within the responsible automation band. The key phrase is "with verified human adoption." The AI produces a draft. The officer runs a footage-grounded verification pass, checking every factual claim against the BWC recording and the CAD entry. The officer corrects errors, removes unsupported claims, and adopts the corrected draft as their own sworn account. The AI does not submit the report. The AI does not decide what is accurate. The AI produces a starting point, and the officer converts it into a sworn document through a defined review process.
What makes this automatable is that the failure mode is catchable before it causes harm, provided the verification pass is real. A gap-fill error, the model's tendency to fill audio gaps with statistically plausible but factually unsupported details, can be caught at the footage-verification step. Brady v. Maryland (the 1963 Supreme Court case requiring prosecutors to disclose exculpatory evidence to the defense) and Giglio v. United States (the 1972 case extending that obligation to impeachment evidence about officers and witnesses) create the standard: if AI altered the factual record and the error was not caught, it is a disclosure and evidentiary problem. But the error can be caught. That is the mechanism that keeps report drafting in the responsible automation column.
The King County, Washington, prosecutor's office demonstrated the boundary when it barred AI-written police reports from its courtrooms. The bar was not on AI assistance. It was on AI-written reports that could not be shown to have undergone human verification and adoption. The King County action is a governance line, not a prohibition on the tool. It tells the public safety executive exactly what the standard is: if you can demonstrate verification, you can use the tool. If you cannot, you cannot use the output.
Transcription and Summarization
Transcription is among the safest forms of automation in public safety because the source of truth exists and is audible. When an AI transcribes an interview recording, the original audio remains. Any error in the transcript can be identified by replaying the relevant section. Verification is straightforward: a reviewer reads the transcript while listening to the audio and corrects any discrepancy. The Electronic Frontier Foundation (EFF), which has raised transparency concerns about AI in law enforcement contexts, focuses its sharpest criticism on uses of AI where the original record is not available for comparison. Transcription from retained audio does not have that problem. The original is preserved. The AI's work is checkable.
Summarization of interviews and case materials sits in a similar position, with one important additional requirement. A case summary that attributes a statement to a witness must have that statement verified against the original recording before the summary is used in any investigative or prosecutorial context. A summary that says "Witness A stated she did not see the vehicle until it was within ten feet" needs to be verified against the audio of the interview. The EFF's concern about AI-generated summaries is that a fabricated or distorted attribution in a case summary can corrupt an investigation before anyone realizes the summary was not accurate. The summary is safe to automate with human verification of every attribution. It is not safe to automate without that step.
Redaction Assistance
AI-assisted redaction of BWC footage and records for public-records release has demonstrated real operational value. Agencies facing public-records backlogs measured in months, with records staff doing frame-by-frame manual redaction of hours of footage, have used AI redaction tools to cut release times dramatically while meeting obligations under open-records statutes. The automation is appropriate because the verification step is built into a defensible workflow: AI proposes redactions, human reviewer confirms them and checks for missed instances, and the reviewed output is released.
The failure mode that keeps redaction from being fully automated without human review is the missed face or missed license plate, specifically the instance where AI misses a detail that should have been redacted, or over-redacts and obscures information the requester is entitled to receive. Both failure modes are violations: one of privacy, one of disclosure. The human review pass is not optional. But the AI doing the first pass, finding perhaps 95 percent of required redactions reliably, makes the human's job tractable rather than requiring the human to begin from nothing.
CAD Transcription and Entry Assistance
In 911 dispatch, CAD entry assistance, where AI transcribes and suggests structured call entries from live audio, frees telecommunicators from the data-entry burden that competes with listening and decision-making during active calls. This is appropriate automation because the telecommunicator retains command of the call, the priority decision, and the dispatch instruction at all times. The AI fills in the paperwork. The human works the emergency. The CAD entry suggestion is exactly that: a suggestion the telecommunicator confirms or corrects before it becomes the official record.
What Must Not Automate
The line between assistable and must-stay-human functions is drawn at decisions where an AI error cannot be caught before it causes irreversible harm, where the decision carries constitutional weight, or where the act of deciding is itself a legal act that must be performed by a person with authority.
Use-of-Force Authorship
The narrative in a use-of-force report may be drafted with AI assistance, but the authorship, verification, and adoption of every factual claim in that narrative must be explicitly human. Use-of-force reports are reviewed in civil rights litigation, administrative hearings, criminal proceedings, and oversight board inquiries. The officer who submitted the report will be asked, under oath, whether the report accurately reflects what happened. Brady and Giglio both apply: exculpatory evidence about the incident and impeachment evidence about the officer's credibility are both subject to mandatory disclosure. An AI-generated claim in a use-of-force narrative that turns out to be inaccurate creates a Brady problem, a potential suppression motion, and a civil rights liability exposure. These are not recoverable with a correction after the fact. The verification standard for use-of-force narratives is zero tolerance for unverified claims, and that standard cannot be met by any automated process because verified means the officer checked it against the footage and can testify to that check.
Dispatch Priority Decisions
AI may assist in classifying calls and suggesting priority levels. AI must not decide them. In 911 dispatch, the priority assigned to a call determines which resources respond, how quickly, and in what configuration. A misclassified call is not a data error. It is a potentially fatal operations failure. If AI classifies a medical emergency as a lower-priority call and the telecommunicator accepts that classification without exercising independent judgment, and a caller dies because the right resources did not arrive, the AI is not liable. The agency is. The telecommunicator is. The decision to assign a priority is a life-safety decision and must be made by a person with the training, authority, and accountability to make it.
Arrest and Charging Recommendations
No AI tool is authorized to recommend arrest or recommend charges in any jurisdiction without explicit human determination. Predictive tools, tools that analyze patterns across CAD data, criminal history records, or behavioral indicators, may surface information relevant to investigative decisions. They do not make those decisions. The arrest decision is a Fourth Amendment act. The charging decision is a prosecutorial judgment. Both require human exercise of discretion grounded in law and accountable to law. AI that influences those decisions through opaque weighting of historical patterns creates constitutional exposure that no disclosure framework can fully cure after the fact. The Electronic Frontier Foundation has specifically raised this concern about predictive tools in law enforcement: when the basis for a decision is an algorithm rather than articulable facts observed by a human officer, the constitutional foundation of that decision is weakened.
Automated Sentencing and Risk-Score Inputs
Risk assessment tools that inform bail, sentencing, or supervision decisions have drawn sustained civil liberties scrutiny because they encode historical data patterns that may reflect past enforcement disparities rather than individual risk. Courts have engaged with challenges to the transparency and accuracy of these tools. The public safety executive's role in this domain is to ensure that any risk assessment tool used in the agency's sphere has been subjected to bias auditing, is disclosed to defense counsel, and is not treated as determinative. A score is information. A human judge, prosecutor, or officer must evaluate that information in context and make a decision the law holds them accountable for. The automation of the scoring computation is permissible. The automation of the decision it informs is not.
Body-Worn Camera Activation Decisions
Whether to activate a BWC is a policy-governed human decision in most jurisdictions. Automated BWC activation triggered by AI-detected events, such as gunshot detection, elevated voice stress, or proximity sensors, raises constitutional and civil liberties questions about covert recording and officer notification that have not been resolved uniformly across jurisdictions. The public safety executive considering automated activation triggers must work through legal counsel and the agency's CJIS (Criminal Justice Information Services Security Policy, the federal framework governing the handling of criminal justice information) obligations before deploying this capability. CJIS obligations stay with the agency, not the vendor. Automated activation features that implicate criminal justice data must be compliant with CJIS requirements on data retention, access, and audit trails, and that compliance is the agency's responsibility regardless of what the vendor's platform documentation says.
The Vendor Contract and the Automation Creep Risk
One of the least discussed risks in public safety AI adoption is what might be called automation creep: the gradual expansion of what AI decides, recommends, or outputs without a corresponding expansion of the governance that governs those decisions. This risk is amplified by the structure of current procurement. Agencies are signing bundled, multi-year, sole-vendor contracts, cameras, drones, cloud storage, and AI, on the order of $45 million and up, with contract terms extending to ten years. These contracts are signed today under current governance frameworks. They will be active in 2030, 2032, and 2034, under governance frameworks that do not yet exist.
The risk is not the contract. The risk is the assumption that the AI capabilities included in the contract will remain within the governance framework that existed when the contract was signed. Vendors update their platforms. New AI features are added. A platform that was sold as a report-drafting tool may, over the contract period, add dispatch suggestion features, patrol deployment recommendations, and predictive analytics modules. Each addition to the platform's capability requires a governance review before deployment. The agency's AI governance board, if it exists and is functioning, should have a formal review process triggered by any platform update that introduces new automated decision-making capabilities. The contract should include language giving the agency the right to disable features that the agency's legal counsel and governance board have not approved. Without that language, the vendor's product roadmap becomes the agency's AI policy by default.
The CJIS Security Policy is relevant here. Under CJIS, the agency is the custodian of the criminal justice information it holds. Obligations for data security, access controls, audit logging, and breach notification stay with the agency. If a vendor's AI platform processes CJIS-covered data in a cloud environment, the vendor must be a CJIS-compliant cloud provider under a signed Criminal Justice Information Services User Agreement or equivalent, and the agency must verify that compliance. Automation creep that moves CJIS data through new vendor AI pipelines requires verification that those pipelines are covered under existing CJIS agreements. The fact that the data was already in the vendor's platform does not automatically mean a new AI feature operating on that data is CJIS-compliant.
Drawing Your Agency's Automation Line
The practical output of this lesson is a decision framework your agency can apply to any proposed AI automation. It has four elements.
The Failure Mode and Its Consequences
For any proposed automation, name the specific failure mode: what does the AI get wrong, and under what conditions does it get it wrong most often? Then trace the consequence of that failure in your operational context. If AI misclassifies a redaction, the consequence is a released document with an unredacted face or license plate. That is a privacy violation and potentially a lawsuit, but it is not irreversible in the sense that the release can be challenged and the agency can move to limit further harm. If AI misclassifies a dispatch priority and a cardiac arrest is sent a slower response, a person may die. The severity and reversibility of the failure mode is the primary determinant of whether the automation is responsible or not.
The Human Review Step
For every proposed automation, identify the human review step. Who reviews the AI's output, at what point, with what authority to correct or reject? If the answer is "a supervisor reviews a sample of outputs weekly," the review step is not adequate for high-stakes functions. If the answer is "the officer reviews every AI-drafted claim against the footage before signing the report," the review step is adequate because it is comprehensive, it happens before submission, and the reviewer has the authority and the information needed to correct errors.
The review step must be real. This is a constant operational pressure. When report-writing time decreases by 82 percent, the temptation is to let the draft go faster. The officer who spends three minutes reviewing an AI draft instead of thirty seconds is recovering most of the time saving while maintaining the safety margin. But the officer who clicks through the draft without reading it has eliminated the review step entirely while creating a liability that belongs to them personally. The agency's training and supervision must reinforce that verification is not optional and is not a formality.
The Disclosure and Audit Trail
For any automated function, define what is disclosed and how. Brady and Giglio require disclosure of evidence that is material to the defense. If AI generated a draft that influenced the factual record of a case, and the AI's draft was not verified and the error not caught, that fact is potentially material. If the AI's draft was verified, corrected, and the officer adopted the corrected version, the disclosure obligation is met by documenting the AI assistance and the verification process. That documentation should be in the case file, in the officer's workflow log, and in the agency's AI use record.
CJIS requires audit trails for access to criminal justice information. Any AI tool processing criminal justice data should generate and retain an audit log showing who accessed the data, when, through what system, and for what case. The agency, not the vendor, is responsible for ensuring that log exists and is retained per CJIS requirements. Do not assume the vendor's platform logs everything you need. Verify it.
The Kill Switch and the Review Cadence
Every AI function the agency deploys should have a defined kill switch: a named process by which the function can be suspended if the failure rate exceeds a defined threshold, if a specific type of error occurs, or if a governance review concludes the function should not continue. The kill switch is not a sign of distrust in the technology. It is the governance discipline that allows the agency to act quickly when a problem is identified rather than being locked into a running system by operational dependency.
Pair the kill switch with a review cadence. The AI governance board should review each active automated function on a defined schedule, not only when a problem is reported. The review should examine the error rate for the period, the nature of errors that occurred, whether the human review step was actually exercised in the cases reviewed, and whether any new capability has been added to the platform since the last review that has not been separately assessed. This is not a bureaucratic exercise. It is the operational intelligence the agency needs to distinguish between a function that is working and a function that has quietly drifted out of its safe operating range.
Key Takeaways
- The promise of AI in public safety is real and already being captured: Axon's Draft One reported an 82 percent reduction in report-writing time, and AI is demonstrating value in transcription, summarization, redaction, and CAD entry assistance across agencies today.
- Responsible automation requires that the failure mode be catchable before it causes irreversible harm, that a genuine human review step exists, and that the cost of a failure is proportionate to the corrective mechanism available.
- AI-assisted report drafting is in the responsible automation band when the officer runs a genuine footage-grounded verification pass, adopts the corrected draft as their own sworn account, and documents both the AI's involvement and the review.
- Use-of-force authorship, dispatch priority decisions, arrest recommendations, and any AI-driven input to bail or sentencing must remain fully human: these decisions carry constitutional weight, and an AI error in these domains cannot be corrected after irreversible harm has occurred.
- Brady v. Maryland and Giglio v. United States frame AI-assisted report writing as a constitutional disclosure matter: if AI touched the file and the touch was not documented and disclosed, the defense has a legitimate argument about materiality.
- CJIS obligations remain with the agency regardless of what AI features the vendor's platform adds over the contract period. Each new automated feature processing criminal justice information requires a CJIS compliance verification before deployment.
- Automation creep, the gradual expansion of AI decision-making without corresponding governance expansion, is the dominant structural risk in bundled sole-vendor contracts running ten years or more. The agency's AI governance board must have a formal review process triggered by any platform update that adds new automated capabilities.
- Every deployed AI function should have a named failure-mode analysis, a real human review step, a disclosure and audit trail, and a defined kill switch. These four elements are the operating charter for responsible automation in public safety.
Skill.re