Trending Topics

Shadow AI risks in policing

When officers use public AI tools outside formal oversight, agencies face data security, legal and credibility risks — unless leaders establish policy, training and clear guardrails

Shadow.png

BlackJack3D/Getty Images

Editor’s note: This article is part of Police1’s “Governing AI in policing” digital report. Download the complete report here.

By Shane Coleman

Across law enforcement, individual officers may be quietly turning to public AI tools like ChatGPT to draft reports, summarize interviews or analyze case information. This phenomenon, known as shadow AI, refers to the informal, unsanctioned use of public AI platforms in professional workflows. By default, these tools operate outside IT oversight and data security protocols.

The risks are substantial and can include data breaches, false information in official records and violations of public records laws. Yet the impulse driving shadow AI use is understandable. Officers face mounting administrative burdens, outdated technology systems and the appeal of tools that promise to help them work faster and more efficiently. The solution is not to ban AI or ignore it. It is to build institutional capacity before informal use becomes a crisis.

Why public AI tools create liability

Public AI platforms were not designed for law enforcement. They store user inputs to improve their models, meaning sensitive case information such as names, addresses or investigative leads may be retained and reused in ways agencies cannot control. Officers working outside official channels may not realize such risks exist, particularly without adequate training.

Beyond data security, there is the problem of accuracy. AI systems may generate “hallucinations” — text that appears credible but may be entirely false. In 2023, two New York attorneys submitted a ChatGPT-generated legal brief containing fabricated citations. They trusted the output without verification and were fined $5,000 each. Similar incidents have appeared across industries, from students citing nonexistent sources to journalists publishing false quotes.

In every case, the human professionals bore the consequences, not the technology. For law enforcement, the stakes are even higher. A single unverified AI-generated sentence in a police report could undermine a prosecution or permanently damage an officer’s credibility.

From shadow use to structured implementation

Shadow AI use highlights both risk and potential. Many officers experiment with public AI tools because they see opportunities to improve efficiency, not because they intend to disregard policy. This curiosity reflects a genuine interest in innovation, but it must be managed responsibly.

If your agency is not using a law enforcement-specific AI product, this is the time to establish clear policy and training. Officers should understand what is and is not appropriate when engaging with public AI tools, particularly regarding sensitive information and data privacy. Defining expectations early helps prevent accidental misuse and protects both the officer and the organization.

If your agency decides to explore or adopt a law enforcement-specific AI product, implementation should follow a deliberate and transparent process. Begin by establishing metrics, developing a pilot program and involving appropriate stakeholders. This structured approach allows agencies to evaluate the technology’s impact on accuracy, efficiency and community trust before expanding its use.

In both cases, the goal is to balance innovation with accountability by pairing new technology with policy, training and clear human supervision.

The path forward: Expertise, policy and transparency

Agencies that decide to implement law enforcement-specific products can position themselves to use AI responsibly and effectively. This requires three foundational investments.

1. Build internal expertise

Designate AI subject matter experts (SMEs) within the agency. These individuals, whether full-time coordinators or cross-trained law enforcement executives, should evaluate tools, translate policy into practice and serve as liaisons to prosecutors, IT staff and community stakeholders.

Internal expertise prevents overreliance on vendor claims. Without it, agencies can become passive consumers rather than informed decision makers. SMEs help ensure policy reflects operational realities, not just what is written in legal drafts.
Even small agencies can develop this capacity. An individual with training in AI fundamentals and data security can provide critical oversight that protects the department’s interests.

2. Develop policy

Policy must evolve as the technology evolves. Waiting for state or federal guidance creates delay, and government-issued policies are often too generic for the privacy-sensitive nature of policing.

Effective policies should:

  • Define approved AI applications that are centrally deployed and monitored
  • Establish data security standards and vendor requirements
  • Require human review of all AI-generated content
  • Specify audit and accountability mechanisms

Treat policy as iterative. As your agency gains experience through pilots, audits and lessons learned, update policy accordingly. Transparency in this process builds legitimacy and trust for future technology initiatives.

3. Engage stakeholders early

Successful AI implementations share a common pattern: early and consistent engagement with prosecutors, government officials and community members. Transparency during the pilot phase reduces resistance and builds confidence.

Regular communication through briefings, social media updates or community meetings demonstrates that the agency is approaching innovation responsibly. It also surfaces concerns before they become crises.

Prosecutors must understand how AI tools are used in case preparation. Discovering AI-generated reports during trial, rather than during planning, erodes trust quickly.

Why acting now matters

Ignoring AI is not a neutral decision. It transfers control to individual officers making choices under time pressure and guarantees that the agency will be unprepared when an AI-related incident occurs. In contrast, agencies that invest in understanding AI today will be better positioned to adapt as technology evolves. Early research suggests modest time savings from current tools, but capabilities are advancing rapidly. Departments that build expertise now will be equipped to evaluate emerging applications in report generation, body-camera transcription, evidence analysis and investigative support.

Agencies that maintain public trust will act proactively: establishing policy, training personnel and reinforcing human oversight from the start. The alternative is waiting for a crisis to dictate the response.

About the author

Shane Coleman is a 12-year veteran of the Chicago Police Department and a graduate of the University of Chicago where he conducted a national study on the use of artificial intelligence AI in law enforcement. His research, which included interviews with police chiefs and LE executives across nine states, AI tech companies and AI researchers, identified critical gaps in AI policy development and AI literacy within LE agencies.

Artificial intelligence is already shaping investigations, dispatch and data analysis. The question isn’t whether agencies will use AI — it’s whether leaders will govern it responsibly

Police1 Special Contributors represent a diverse group of law enforcement professionals, trainers, and industry thought leaders who share their expertise on critical issues affecting public safety. These guest authors provide fresh perspectives, actionable advice, and firsthand experiences to inspire and educate officers at every stage of their careers. Learn from the best in the field with insights from Police1 Special Contributors.

(Note: The contents of personal or first person essays reflect the views of the author and do not necessarily reflect the opinions of Police1 or its staff.)

Interested in expert-driven resources delivered for free directly to your inbox? Subscribe for free to any our our Police1 newsletters.