This website uses cookies

Read our Privacy policy and Terms of use for more information.

Sponsored by

How 2M+ Professionals Stay Ahead on AI

AI is moving fast and most people are falling behind. 

The Rundown AI keeps you ahead of the curve. 

It's a free AI newsletter that keeps you up-to-date on the latest AI news, and teaches you how to apply it in just 5 minutes a day.

Plus, complete the quiz after signing up and they’ll recommend the best AI tools, guides, and courses — tailored to your needs.

At A Glance

  • Employees are adopting AI faster than agencies are approving it.

  • Unapproved tools create CJIS, discovery, retention, security, and public-records concerns.

  • Every agency needs an inventory of AI systems and uses.

  • Every approved system needs a business owner, written controls, and a review date.

  • Internal Affairs should help audit compliance, but executive leadership must own AI governance.

The Problem In Action

A patrol sergeant sits down to write a use-of-force report.

He pastes his notes into a free AI writing tool on his phone, improves the grammar, and submits the report.

Nobody approved the tool.

Nobody reviewed where the information went.

Nobody knows AI touched the report.

Then a defense attorney asks during discovery whether artificial intelligence played any role in preparing the report.

The agency has no answer.

The Governance Standard Already Exists

Public safety agencies do not need to invent an AI governance model from the ground up.

The federal government has already established a useful framework.

The U.S. Department of Justice maintains an inventory of AI systems operating across the Department. The inventory tracks systems through several stages, including:

  • Development

  • Pilot testing

  • Production

  • Retirement

The National Institute of Standards and Technology also places governance at the beginning of AI risk management.

Under the NIST AI Risk Management Framework, governance comes before performance testing, bias review, system monitoring, and risk mitigation.

The lesson is direct.

Before an organization measures whether an AI system works, leadership must first know the system exists, who owns it, what information it processes, and what controls apply.

Many public safety agencies remain far from this standard.

They have officers experimenting with free report-writing programs.

Investigators use transcription platforms without formal review.

Training personnel upload agency policy drafts into public chatbots.

Supervisors adopt tools because they save time.

No one has a complete list.

No one owns the process.

No one could confidently answer the question:

What artificial intelligence is currently operating inside this agency?

Why Does Your Agency Need an AI Inventory?

An agency cannot control, audit, disclose, or defend technology it does not know employees are using.

The lack of an inventory creates three immediate areas of exposure.

Information Security

Agency personnel might enter sensitive information into an unapproved system, including:

  • Witness statements

  • Investigative notes

  • Arrest narratives

  • Employee information

  • Body-worn camera summaries

  • Intelligence information

  • Draft policies

  • Administrative investigative material

Leadership might not know where the information is stored, how long the vendor retains it, or whether the vendor uses the information to train other systems.

Legal and Discovery Exposure

When AI touches an official report or investigative file, several questions arise:

  • Did AI generate or revise any material statement?

  • Did the employee verify each factual assertion?

  • Did the system introduce information not found in the source material?

  • Does an audit trail exist?

  • Were prompts or earlier drafts retained?

  • Must the agency disclose the use of the tool?

  • Does the vendor possess agency information responsive to discovery or public-records requests?

An agency without an inventory might not even know where to begin looking.

Organizational Accountability

An officer using an unapproved transcription or writing tool might not intend to violate policy.

The employee might not know approval is required.

The problem then becomes more than individual misconduct.

Leadership failed to establish a system for approving, documenting, and monitoring technology use.

Silence is not an AI policy. It is an uncontrolled delegation of risk.

What Should an AI Governance Policy Require?

An effective AI policy should begin with organizational controls, not employee discipline.

At minimum, the policy should address six areas.

1. Maintain a Complete AI Inventory

Required control: Document every AI system used for agency business.

The inventory should identify:

  • System name

  • Vendor

  • Intended purpose

  • Unit or division

  • Authorized users

  • Information entered into the system

  • Approval status

  • Business owner

  • Legal review date

  • Security review date

  • Last audit date

  • Next scheduled review

  • Current system status

Why it matters: Leadership cannot govern technology it cannot see.

2. Require Approval Before First Use

Required control: No employee, supervisor, or organizational unit should place an AI system into agency service without documented approval.

The review should address:

  • CJIS requirements

  • Cybersecurity

  • Privacy

  • Records retention

  • Public-records obligations

  • Discovery requirements

  • Vendor data practices

  • Contract terms

  • Human verification

  • Audit capabilities

Why it matters: Informal use often becomes accepted agency practice before command staff knows the tool exists.

3. Assign a Business Owner

Required control: Every approved system should have a named organizational owner.

The owner should oversee:

  • Authorized uses

  • User access

  • Training

  • Vendor communication

  • Security findings

  • Legal updates

  • Audit results

  • Corrective action

  • Periodic review

Why it matters: “The agency owns it” is not a meaningful accountability structure.

Someone must answer for how the system operates.

4. Require Human Review and Audit Records

Required control: AI output should never become an official agency record without documented human review.

The reviewing employee should verify:

  • Names

  • Dates

  • Times

  • Locations

  • Quotations

  • Statutory elements

  • Probable-cause statements

  • Evidence descriptions

  • Conclusions

  • Source attribution

The agency should also determine whether the system preserves:

  • User identity

  • Date and time of access

  • Prompts

  • Output

  • Edits

  • Approval history

  • Final disposition

Why it matters: Without human verification and system records, the agency cannot show whether the employee verified the output or merely accepted it.

5. Complete Legal and CJIS Review Before Deployment

Required control: Legal, information security, records, and operational personnel should review the system before use.

The review should determine:

  • Whether criminal justice information enters the system

  • Whether the vendor meets applicable security requirements

  • Where information is stored

  • Who receives access

  • How long information is retained

  • Whether information is used for system training

  • Whether the agency can retrieve and preserve system records

  • Whether the vendor reports security incidents

  • Whether the agency can terminate access and remove data

Why it matters: Conducting a compliance review after the system becomes embedded in daily work creates operational and legal problems.

6. Establish Review and Retirement Procedures

Required control: Every system should have a scheduled review date and a formal retirement process.

The review should examine:

  • Vendor ownership changes

  • Updated terms of service

  • New system functions

  • Security incidents

  • Changes in data retention

  • Legal developments

  • Accuracy concerns

  • User complaints

  • Audit findings

  • Continuing operational need

Why it matters: Approval should not last forever.

A tool approved two years ago might operate under different terms, ownership, security controls, or data practices today.

Sample AI Inventory

A basic inventory does not need to be complicated.

AI System

Agency Use

Information Involved

Business Owner

Approval Status

Next Review

Report-writing assistant

Grammar and report revision

Incident reports

Patrol Operations

Pending

August 2026

Interview transcription tool

Recorded interview transcription

Audio and witness statements

Investigations

Approved

January 2027

Policy drafting chatbot

Policy research and formatting

Draft policy language

Professional Standards

Under review

September 2026

The inventory should remain current, accessible to leadership, and linked to the agency’s approval records.

Strengthen Your Agency’s Policy Framework

Does your agency need stronger policies for artificial intelligence, Internal Affairs, employee investigations, due process, or technology governance?

Review national training programs designed for public safety executives, Internal Affairs commanders, investigators, supervisors, and public-sector HR professionals.

Visit InternalAffairsTraining.com to explore available training and resources.

Sources:

  • U.S. Department of Justice, 2025 Artificial Intelligence Use Case Inventory and AI Governance Resources.

  • National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0).

Keep Reading