AI in Policing: How Agencies Are Governing "Efficiency AI" vs. "Decision AI" in 2026
A practical governance framework for law enforcement agencies distinguishing administrative AI tools from high-stakes decision-support systems in 2026.
By IPA-IAC · 6 min · 25 June 2026

The governance failure most agencies face in 2026 is not that they deployed AI carelessly. It’s that they deployed many different kinds of AI under a single policy — one that was written for the most dangerous use case and applied uniformly to tools that schedule shifts and tools that generate risk scores for patrol deployment. The result is either paralysis (everything requires a full ethics review) or blind spots (nothing gets adequate review because the policy is too burdensome to enforce).
The distinction that resolves this is not new to computer science, but it’s becoming central to law enforcement AI governance: efficiency AI versus decision AI. Getting the boundary right determines how much oversight each system needs, what documentation an agency must maintain, and what a credible audit looks like.
What the RAND/CCJ Taxonomy Actually Says
The Council on Criminal Justice’s national Task Force on AI published an AI Taxonomy for Criminal Justice in May 2026, produced in collaboration with RAND. The taxonomy categorizes AI applications not by technology type but by the functions and decision points they support — and by their automation level (advisory, augmented, or autonomous) relative to human oversight.
The taxonomy’s governance logic maps closely to a two-tier distinction:
Low-risk administrative applications — scheduling, document processing, resource routing — are characterized by high error detectability, strong contestability, and limited direct effects on liberty or rights. The taxonomy recommends streamlined governance for these functions: human oversight, basic logging, and the ability to override or correct.
High-risk decision-support applications — risk assessment, predictive patrol deployment, facial recognition — are characterized by opacity, potential equity harm, and consequences that can directly affect individual liberty. These require “stricter safeguards, independent auditing, explicit governance protections, and tailored regulation.”
This is the policy architecture that was missing from most agency AI frameworks written between 2019 and 2023. Applying it retroactively is the work most technology commanders are now doing.
A Working Definition for Agencies
For practical governance purposes, the distinction resolves to a single question: Does the AI output directly influence a decision about a specific person’s liberty, rights, or resources?
If yes, it’s decision AI. If no, it’s efficiency AI.
Efficiency AI examples:
- AI-assisted report drafting (officer reviews and approves) — now the subject of explicit disclosure statutes in California and Utah
- Scheduling optimization
- Evidence inventory management
- Traffic signal coordination
- Internal document classification
Decision AI examples:
- Predictive risk scores that influence patrol allocation to specific addresses
- Facial recognition used to identify a suspect in an investigation
- Recidivism or flight-risk scores used in charging or bail recommendations
- Automated license plate reader systems triggering enforcement actions
Some tools are genuinely ambiguous — a dispatcher-assist system that ranks incoming calls by AI-assessed urgency sits at the boundary. The DOJ’s December 2024 report on AI and criminal justice recommends resolving ambiguity by applying the stricter tier: when uncertain, govern as decision AI.
The Governance Requirements That Differ
The Policing Project at NYU Law released a preliminary AI Governance Framework in late 2025 that operationalizes the distinction with concrete requirements. The framework’s core mechanism is pre-deployment approval for “Covered AI Systems” — defined as any system with consequential automated influence over persons — followed by continuous monitoring.
For decision AI, the framework requires:
Pre-deployment:
- Impact assessment covering equity, accuracy, and data provenance
- Community engagement before deployment in public-facing functions
- Documentation of vendor validation claims, including independent testing data
- Explicit human-override protocol with training
Post-deployment:
- Audit logging sufficient to reconstruct every significant AI-influenced decision
- Regular independent performance audit (the CCJ/RAND taxonomy recommends NIST or a qualified independent body)
- Defined escalation paths when performance degrades or bias thresholds are breached
- Public-facing disclosure of system use and governance outcomes
For efficiency AI, the requirements are lighter: basic logging, training for operators, and periodic policy review. The overhead is proportionate to the risk.
What “Human Oversight” Must Actually Mean
The governance gap in many existing agency policies is a phrase — “human review is required” — that carries no operational specificity. A supervisor who signs off on an AI-generated patrol schedule after five seconds of review satisfies the letter of most policies. It satisfies nothing else.
Decision AI governance requires that human oversight be meaningful — that the reviewing officer have the authority, the information, and the actual capacity to override. The Police1 Leadership Institute’s 2026 series on AI governance calls this “consequential human decision-making” and distinguishes it from what it terms “automation bias ratification,” in which humans systemically approve AI outputs without critical evaluation.
Operationally, this means:
- Reviewers must see the confidence level or uncertainty range of any AI score, not just the output
- Override rates should be tracked; a 0% override rate over time is a governance red flag, not a success metric
- Training must include not just how to use the system but how to evaluate and reject its outputs
Documentation That Survives an Audit
Agencies operating decision AI that affects liberty interests should assume the documentation will eventually be reviewed by a court, an oversight body, a journalist, or all three. The DOJ’s December 2024 report recommends maintaining records of system design, training data selection, validation testing, regular updates, and performance audits.
At minimum, a defensible decision AI file includes:
- Procurement documentation identifying what the vendor represented about accuracy and bias performance
- Independent validation results (not the vendor’s own)
- Incident log of significant AI-influenced decisions
- Training records for operators and reviewers
- Results of periodic performance audits against current operational data
The DOJ report notes that “data selection and validation” is where most systems fail under scrutiny — the training data reflects historical enforcement patterns that agencies would not consciously endorse as policy.
The Governance Gap at the State Level
Federal AI legislation remains fragmented. The Morgan Lewis tracker of AI enforcement actions notes that federal agencies are relying on existing civil rights, consumer protection, and false claims statutes rather than AI-specific frameworks, while states are moving aggressively — creating a patchwork that law enforcement agencies in different jurisdictions navigate unevenly.
The practical consequence is that agencies operating without clear internal governance tiers are exposed on two flanks: civil rights litigation targeting algorithmic bias in decision AI, and vendor disputes arising from efficiency AI deployments that underperformed represented capabilities.
Internal tier governance — defining which systems are decision AI, what they require, and how outcomes are audited — is now the institutional risk management standard, independent of whether a jurisdiction has enacted specific AI statutes.
Building the Tier Inventory
The first step for any agency that has not completed this exercise is an AI system inventory categorized by tier. Every AI tool in use — licensed, piloted, or informally deployed — should be catalogued with:
- Function description
- Decision AI or efficiency AI classification
- Human-override protocol
- Current documentation status
- Last performance review date
The RAND/CCJ taxonomy provides a sector-by-sector application list that serves as a useful starting-point checklist for law enforcement. For agencies without dedicated technology counsel, the National Policing Institute’s AI readiness resources and the Policing Project’s governance framework templates are the two most operationally useful public references.
The goal is not a policy document that satisfies an audit. It’s a governance system that actually changes how consequential decisions are made.