โ†
AI for Public Safety & First Responders
Visionary ยท M16 ยท lesson 16 of 16 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Your 90-Day Transformation Plan
๐Ÿ“–
now learning

Your 90-Day Transformation Plan

15 min

Chief Elaine Morales put down the last lesson of the program on a Thursday evening and sat for a moment with the question every executive asks at the end of a serious curriculum: what do I actually do first? She had command staff to brief, a vendor contract renewal coming in six months, a city council that would ask about cost savings, a civilian oversight board that would ask about safeguards, and a prosecutor's office that had quietly flagged three cases in the past year where AI-assisted reports had generated discovery questions. She did not have an AI problem. She had an AI program that was running informally, without a governance structure, without a measured verification standard, and without a disclosure architecture. She had ninety days before the contract renewal that would lock the agency into another seven years of the current configuration. The plan in this lesson is the plan she built.

Why Ninety Days, and What It Can Accomplish

Ninety days is not the transformation. Ninety days is the foundation that makes the transformation possible. The difference matters because executives often approach AI governance the way agencies approached body-worn camera (BWC, the recording device worn on an officer's uniform) adoption: the tool comes first, the policy comes later, and the policy is retrofitted to cover what is already running rather than designed to govern what is about to run. The ninety-day plan reverses that sequence. Before the next major procurement decision, before the next capability expansion, before the next annual report that claims AI success without a defined standard for measuring it, the agency builds the governance foundation that every subsequent decision rests on.

At the end of ninety days, the agency should have accomplished four things that cannot be purchased from a vendor: a documented inventory of every AI function currently in use, with the current state of its human review step assessed and recorded; a formal AI governance board that has held at least one working meeting; a disclosure architecture that is built into the report template and case file workflow; and a public statement of AI use that the community oversight board and the prosecutor's office have reviewed. None of these are technical products. They are governance decisions, and governance decisions are the only kind that survive a vendor contract, a platform update, and a regime change.

The ninety-day plan has three phases of thirty days each. Phase One is the inventory and baseline. Phase Two is policy, governance, and training. Phase Three is disclosure architecture and community engagement. They overlap slightly at the margins, but the sequence is deliberate.

The governance that does not exist before the next contract renewal will not exist after it. Build it now, or negotiate it away.

Phase One, Days 1 to 30: Inventory and Baseline

The first thirty days are diagnostic. The question Phase One answers is: what is the actual state of AI use in this agency, and what governance exists around it? The answer is almost always more complex than command staff believes and more improvised than any policy document describes.

The AI Function Inventory

Begin with a structured inventory of every AI tool in active use. This means every AI-assisted function in the BWC evidence platform including report drafting and redaction assistance, every AI feature in the computer-aided dispatch (CAD) system including transcription and call classification suggestions, every AI module in the records management system (RMS) used for public-records release queue processing, and any AI tools used in investigations, crime analysis, or intelligence functions. For each function, document four things: what the AI does, what the human review step is (or is not), whether the output is captured in any audit log, and whether the function produces outputs that enter the criminal justice evidence record.

The inventory will likely surface three categories of function. The first category is functions with a genuine, documented, and measured human review step. These are the functions in responsible operation. They require monitoring, not repair. The second category is functions with an informal or inconsistently applied human review step, where individual officers or staff exercise judgment about whether to verify and how thoroughly. These are the priority repair items. The third category is functions where the AI output enters the case file or the evidence record without any documented human review step. These are the critical risk items. If a critical risk item is producing output that enters a court-relevant record, the agency's Brady v. Maryland disclosure obligation (the 1963 Supreme Court case requiring prosecutors to disclose exculpatory evidence to the defense) may already be implicated. Legal counsel should be notified before the end of Phase One.

The Verification Baseline

For the most active AI function in the agency, which is almost always AI-assisted report drafting, establish the current verification rate. This requires pulling a sample of AI-assisted reports from the most recent month, enough to be representative, and determining what proportion of them have a documented verification record. This is the baseline. It is almost always lower than command staff estimates. Do not be discouraged by the number. The baseline is not the destination. It is the starting point from which improvement is measured, and a low baseline is honest intelligence about where the work is needed.

The Giglio v. United States context (the 1972 case extending disclosure obligations to impeachment evidence about officers and witnesses) is directly relevant to the baseline exercise. If officers are not verifying AI-drafted claims and an inaccurate claim reaches a sworn report, that inaccuracy may be material to the defense at trial. The verification rate is not just an operational metric. It is an indicator of the agency's current Brady and Giglio exposure.

The Vendor and Contract Audit

Pull every current AI vendor contract and identify the following for each: the contract term and renewal date, what Criminal Justice Information Services (CJIS) compliance provisions are included, whether the contract includes provisions requiring vendor notification when AI features are updated or added, whether the contract gives the agency the right to disable features that have not been approved through the agency's governance process, and what the data retention and audit log provisions are. If these provisions are absent or inadequate, note them as negotiating targets for the next renewal. If the contract renewal is within six months, this audit is urgent, because contract renewals are the best and sometimes only opportunity to correct governance gaps in the vendor relationship.

At the end of Phase One, brief legal counsel and, informally, the prosecutor's office on the inventory findings. Share the verification baseline. Share the list of AI functions producing court-relevant output. Ask the prosecutor's office whether any AI-related discovery or disclosure questions have arisen in the past year. The answer to that question is the most important piece of intelligence Phase One produces. If the prosecutor has received defense challenges to AI-assisted reports and has been managing them without the agency's involvement, the agency's disclosure architecture is already lagging behind the adversarial process.

Phase Two, Days 31 to 60: Policy, Governance, and Training

Phase Two converts the Phase One inventory into formal governance. It has three components: the AI use policy, the governance board, and the training update.

Writing the AI Use Policy

The AI use policy is not a technical document. It is an accountability document. It should be written in plain language that an officer, a dispatcher, a records clerk, a prosecutor, and a community member can all read and understand. It has six required sections.

The first section defines the scope: which AI functions are covered, which are not, and how a function enters or exits coverage. Every function identified in the Phase One inventory should be explicitly named in the scope section or explicitly noted as not subject to the policy with an explanation.

The second section defines the authorship and verification standard: the officer is the author of every AI-assisted report they submit, the footage-grounded verification pass is required for every factual claim in every AI-assisted narrative, and the verification must be documented. The verification standard is not a recommendation. It is a condition of submission.

The third section defines the disclosure standard: AI assistance is documented in the case file, the disclosure package produced for the prosecutor includes a standardized statement of AI use and review, and the agency's policy on AI disclosure is available to defense counsel on request. This section should address Brady and Giglio by name, establishing that the agency treats AI-assisted report production as a disclosure matter under those cases.

The fourth section defines prohibited uses: functions where AI may not be used regardless of the availability of a review step. Use-of-force authorship without officer verification and adoption, dispatch priority decisions, and arrest recommendations are in this section. These are the functions this program identified as must-stay-human regardless of AI capability.

The fifth section defines the governance structure: the AI governance board's composition, meeting cadence, authority, and the conditions that trigger a review, a function suspension, or an escalation to command staff and legal counsel.

The sixth section defines the kill switch: the named process by which any AI function can be suspended pending a governance review, the conditions that trigger activation, and the communication required when a function is suspended.

Standing Up the Governance Board

The AI governance board should hold its first working meeting in Phase Two. The meeting's agenda is the inventory output from Phase One. For every function on the inventory, the board confirms or corrects the Phase One assessment of the human review step and the audit log status. For every function categorized as a critical risk item, the board makes a decision: suspend the function pending a governance review, implement a minimum viable governance requirement as a condition of continued operation, or escalate to legal counsel with a defined timeline for resolution. The board does not defer critical risk items to the next quarter. They are acted on in Phase Two.

The governance board's cross-functional composition is essential. It should include at minimum: a representative from patrol operations who can speak to the verification standard at the officer level, a representative from records who can speak to the CJIS audit trail and public-records release workflow, a representative from dispatch who can speak to the CAD transcription and triage assistance functions, legal counsel or a legal advisor who can assess Brady, Giglio, and CJIS compliance, and a representative from the civilian oversight mechanism if the agency has one. The board is not a technology committee. It is a governance committee. Technical expertise is welcome, but the decisions are policy decisions, not engineering decisions.

The Training Update

Phase Two training has a narrow scope. It is not a full re-certification program. It is a targeted update to reinforce two specific behaviors: the footage-grounded verification pass standard, and the disclosure documentation requirement. Every officer and staff member who uses an AI-assisted function should receive a briefing, no more than two hours, that covers what the new policy requires of them, how verification is now documented, and what the disclosure statement in the case file looks like. The two-hour target is not a constraint on depth. It is a discipline. If the verification and disclosure requirements cannot be communicated clearly in two hours, the policy is too complex to implement consistently.

The training should include at least one worked example of an AI-generated gap-fill, the error mode where the model fills an audio gap in the footage with a statistically plausible but factually unsupported detail, caught and corrected through the verification pass. Officers who have seen the error mode caught once in a worked example are more likely to look for it in their own drafts. That is the outcome Phase Two training is trying to produce.

Phase Three, Days 61 to 90: Disclosure Architecture and Community Engagement

Phase Three makes the governance built in Phase Two visible to the external stakeholders whose trust the program depends on: the prosecutor's office, the defense bar, the community oversight board, and the public. It has two components: the disclosure architecture and the community engagement.

Building the Disclosure Architecture

The disclosure architecture has two elements: what is embedded in the report workflow and what is accessible on request. The embedded element is a standardized AI use statement that appears in every AI-assisted case file automatically, without requiring the officer to decide whether to include it. The statement records the AI function used, the date, the officer's documented verification, and any corrections made. It is factual, not defensive, and it is part of the case file record, not a separate disclosure form. When the disclosure package is assembled for the prosecutor, this statement is included automatically.

The accessible element is the agency's public AI use record: the policy, the quarterly governance board summary, and the aggregate metrics on verification compliance and error rates. These are published to the agency's public-facing documentation, in plain language, without requiring a public-records request to access. This is the proactive transparency posture that the Electronic Frontier Foundation (EFF), which has raised transparency concerns about AI in law enforcement, has called for. The EFF's concern is about opacity. The proactive record is the direct answer to that concern.

The CJIS (Criminal Justice Information Services Security Policy) requirement for audit trails is met by the same embedded disclosure architecture. Every AI-assisted function should generate a machine-readable audit log entry for every use, capturing the officer's badge number or staff identifier, the case number, the AI function used, the timestamp, and a flag indicating whether the verification documentation is present. The agency should verify with each vendor that this log is generated, is retained per CJIS requirements, and is accessible to the agency without requiring a vendor support ticket. If the vendor cannot confirm all three, this becomes a contract negotiating point at renewal.

The Prosecutor and Defense Engagement

Before the end of Phase Three, the agency should brief the prosecutor's office formally on the new AI use policy, the verification standard, and the disclosure architecture. The briefing should be a working session, not a presentation. The prosecutor's office should be invited to review the AI use statement template and to confirm whether it meets their discovery disclosure requirements. If the prosecutor has concerns, those concerns should be addressed before they arise in a specific case. The goal is to transform the prosecutor from a potential adversary of the AI program into a confident co-author of its disclosure standard.

Some agencies also brief the defense bar's appointed counsel organization or the public defender's office as part of Phase Three. This is not required, but it is consistent with the proactive transparency posture. A defense attorney who is aware of the agency's AI use policy and can confirm it is being followed is less likely to file a speculative motion challenging AI use in every case involving an AI-assisted report. The disclosure is not a concession. It is a demonstration that the program has nothing to hide.

The Community Oversight Board Presentation

The Phase Three community engagement should include a formal presentation to the agency's civilian oversight board or equivalent community oversight mechanism. The presentation covers the AI function inventory, the verification standard, the disclosure architecture, the governance board composition and authority, and the quarterly review cadence. It should include the Phase One baseline data, because demonstrating that the agency identified a problem and built a governance structure to address it is more persuasive than claiming the program has always been well-governed.

The presentation should also include a commitment to quarterly reporting to the oversight board, with the same metrics the internal governance board reviews, including verification compliance rates, error rates, and the status of any function under governance review. This is not additional bureaucratic overhead. It is the community trust investment that makes the program sustainable when a news cycle or a public-records request tests it.

The Contract Renewal as the Ninety-Day Target

Chief Morales had six months before her agency's vendor contract renewal. The ninety-day plan was designed to reach the contract renewal with governance in place, a clear picture of what the current contract did and did not provide, and a set of specific negotiating targets. The target list from her agency's vendor and contract audit in Phase One included six items: a provision requiring vendor notification of any new automated feature before deployment, a right to disable any feature not approved by the agency's governance board, CJIS compliance verification for all AI pipelines processing criminal justice information, a data portability clause ensuring the agency's records are exportable at contract end, a defined audit log specification for each AI function, and a performance measurement clause defining the minimum acceptable human review documentation rate for AI-assisted reports.

Not all six were achievable in negotiation. Three were accepted by the vendor. Two were modified into acceptable compromise language. One, the performance measurement clause, required the agency to define its own internal standard in the AI use policy rather than in the contract, because the vendor declined to accept liability for the agency's internal compliance rate. That outcome is acceptable. The governance stays with the agency regardless of what the contract says, and the policy creates the accountability the contract clause would have created.

The bundled contract structure, cameras, drones, cloud, and AI on the order of $45 million for up to ten years, means the renewal decision is not just a technology procurement. It is a governance commitment. Signing a renewal without the governance provisions in place is signing the next decade's AI program without the decade's oversight architecture. The ninety-day plan is how an agency avoids that outcome.

What the Next Ninety Days, and the Year After, Look Like

The second ninety-day cycle builds on the first. The governance board has now held one working meeting and reviewed the inventory. The AI use policy is published. The disclosure architecture is in the report workflow. The prosecutor's office has reviewed the disclosure template. The community oversight board has received the first quarterly report. The second ninety days turns to the specific function improvements identified in Phase One: closing the verification compliance gaps, operationalizing the kill switch provisions by testing them in a tabletop exercise, adding the quarterly governance review data to the agency's public reporting, and beginning the capability expansion review for any new AI function the agency is considering.

By the end of the first year, the accountable agency should have: a governance board that has conducted four quarterly reviews and published their summaries, a verification compliance rate that has been measured, baselined, and improved, a disclosure architecture that has been tested in at least one case where defense counsel questioned AI use, a community engagement record showing pre-deployment engagement on any new capability, and a vendor contract that is aligned with the agency's governance requirements or that has a documented plan to achieve alignment at the next renewal opportunity. These are not aspirational achievements. They are specific, measurable outcomes that an agency committed to the program can accomplish in its first year.

Key Takeaways

  • Ninety days is not the transformation. It is the governance foundation that makes the transformation possible: an inventory of AI use with documented human review steps, a formal governance board with authority to act, a disclosure architecture in the workflow, and a community-accessible AI use statement, all in place before the next contract renewal or capability expansion.
  • Phase One, days 1 to 30, is the AI function inventory and baseline: cataloging every AI tool in use, assessing the human review step for each, establishing the verification baseline, auditing vendor contracts for governance provisions, and briefing legal counsel and the prosecutor's office on the findings.
  • Phase Two, days 31 to 60, is policy, governance, and training: writing the AI use policy with its six required sections including authorship, disclosure, prohibited uses, and the kill switch, standing up the governance board, and delivering the two-hour targeted training update on verification and disclosure to all AI-using staff.
  • Phase Three, days 61 to 90, is disclosure architecture and community engagement: embedding the AI use statement in the report workflow, publishing the proactive public AI use record, briefing the prosecutor's office formally on the disclosure standard, and presenting the complete governance picture to the civilian oversight board with a commitment to quarterly reporting.
  • The contract renewal is the ninety-day target because it is the best opportunity to negotiate governance provisions into the vendor relationship, including vendor notification of new features, the right to disable unapproved features, CJIS compliance verification, and a defined audit log specification.
  • Brady v. Maryland and Giglio v. United States frame AI-assisted reporting as a constitutional disclosure matter from day one. A critical risk function identified in the Phase One inventory, where AI output enters a court-relevant record without a documented human review step, may already implicate Brady obligations. Legal counsel should be notified before the end of Phase One.
  • The community oversight board is not the last stop in the ninety-day plan. It is the first external accountability relationship the agency builds, and the quarterly reporting commitment made in Phase Three is the investment that sustains community trust through the program's first incidents, first challenges, and first news cycles.
  • The program the ninety-day plan builds is the same program this course described from its first lesson: an officer who can answer a deposition question about AI with a clear documented account, a prosecutor who can defend the disclosure standard, an oversight board that trusts the program because the program earns its trust, and an agency that captured the time AI returns and put it back into the community it serves.