Building an internal AI usage policy requires moving beyond general guidelines to specific, enforceable controls—especially in regulated sectors like public safety. A successful policy balances AI productivity with strict adherence to frameworks like CJIS and HIPAA, ensuring data sovereignty and human oversight.
Imagine a dispatch center in Fresno. The team is staring at a backlog of hundreds of hours of 911 call recordings that need to be transcribed and summarized for an evidence report. The temptation is high: a staff member discovers a free, AI-powered transcription tool that can process an hour of audio in seconds.
But for a public safety agency, that convenience is a potential CJIS (Criminal Justice Information Services) problem. The moment a recording containing Criminal Justice Information (CJI) is uploaded to a public cloud AI, the agency has likely violated data residency requirements and potentially exposed sensitive data to a model that “learns” from every input it receives. If that data is used to train a public model, the agency hasn’t just leaked data—it has permanently integrated sensitive law enforcement information into a system it no longer controls.
This is the gap between a generic AI policy and a compliance framework built for regulated work. In the Central Valley, where public safety and healthcare agencies are the backbone of community stability, “best practices” aren’t enough. You need a policy that understands the difference between a marketing email and a CJIS-regulated dispatch log. If you want the broader governance picture first, our AI acceptable use and governance policy guide covers the organization-wide foundations this post then hardens for regulated data.
Why is a “standard” AI policy a liability in regulated industries?
Most AI policies you find online are written for marketing agencies or software startups. They focus on “academic integrity” or “brand voice.” For a clinic in Dublin, Ohio, or a county IT department in Modesto, those policies are dangerously insufficient.
In high-compliance environments, the risk isn’t just hallucinations or biased output; it’s the total loss of data sovereignty. Most public AI tools operate on a data-for-service exchange: you get the compute power for free or cheap, and in return, the provider may use your data to improve the model. In a regulated environment, that is an immediate failure of control.
When we help our clients build their policies, we start by identifying the regulatory red lines. For a public safety agency, that means the CJIS Security Policy.1 The policy sets requirements that cloud service providers must meet so that sensitive data is encrypted, access is controlled, and the data remains within authorized boundaries. A generic rule that says “do not upload sensitive data” is too vague. A compliant policy says: “No CJI may be processed by any AI tool that does not provide a written Zero-Data-Retention (ZDR) agreement and meet CJIS cloud provider requirements.”
Where do CJIS and HIPAA clash with AI?
If you are managing a clinic or a law enforcement agency, you are likely operating under a strict control framework. Whether it’s HIPAA for healthcare or CJIS for public safety, the core requirement is the same: the data must be protected, and the chain of custody must be verifiable.
AI introduces a black box into this chain. If an AI tool is used to summarize a patient’s EHR (Electronic Health Record), where does that summary live? Is it cached on a server in a different region? Is it being retained to train a model? These are the questions your policy has to answer before a tool is approved, not after an incident. Deciding what data can go where starts with knowing what you hold — our data classification and governance policy guide is the companion step to this policy.
This is why we advocate for a tiered approach to AI adoption. You cannot treat a generative AI tool used for drafting a staff memo the same way you treat a tool used for transcribing evidence recordings. The latter requires a human-in-the-loop (HITL) workflow where the AI provides a first draft, but a certified human reviewer validates the output against the original audio before it is entered into the record.2
How to build your AI usage policy: a framework for approval
To move from a vague guideline to an operational policy, you need an approval matrix. Not all AI is created equal. We categorize AI tools into three levels of risk based on the data they touch and the sovereignty they provide.
AI tool approval matrix
| Tool Type | Best Fit | Data Sovereignty Risk | Approval Status | Recommended Control |
|---|---|---|---|---|
| Public LLMs (e.g., free consumer chatbots) | Public-facing marketing, generic brainstorming | Critical: input may be used for training; no ZDR | Prohibited for sensitive data | Use only for non-confidential, public-facing drafts |
| Enterprise LLMs (e.g., private cloud AI services) | Internal reports, policy drafting, admin tasks | Medium: data encrypted; ZDR available via contract | Conditional approval | Requires a signed BAA for PHI3 or a CJIS-compliant cloud contract |
| Local/On-Prem LLMs (e.g., a model on a private server) | CJI analysis, EHR summaries, evidence transcription | Low: data never leaves the internal network | Approved for sensitive data | Full audit logs and access control via managed IT services |
Implementing the policy: a step-by-step guide
Building the policy is only half the battle; the other half is operationalizing it across your organization. Here is the workflow we recommend for agencies in the Central Valley and Southern California:
- Audit your “shadow AI.” Start by identifying which tools your employees are already using. Most staff have already started using AI for productivity; your goal is to move them from unauthorized to governed usage. Our shadow-AI policy template for regulated businesses gives you a starting document.
- Map your data sensitivity levels. Create a clear taxonomy of what constitutes “Public,” “Internal,” and “Regulated” (CJI/PHI) data. If a staff member can’t tell the difference, the policy will fail.
- Define the zero-retention standard. Mandate that any tool touching regulated data must have a Zero-Data-Retention (ZDR) agreement, so the provider does not store the data after the session ends and does not use it for training.
- Establish a human-in-the-loop (HITL) requirement. For any AI-generated output used in a legal or medical capacity, require sign-off from a human reviewer. AI should be the first draft, never the final record.
- Create an AI request workflow. Instead of a blanket ban, provide a clear path for employees to request new tools. This lets your IT team vet a tool’s security posture before it enters the environment.
- Schedule quarterly compliance audits. AI evolves quickly. A tool that was compliant in January may change its terms of service by June. Quarterly reviews are non-negotiable.
Why is human-in-the-loop the non-negotiable safety valve?
In the context of public safety—such as a dispatch center in Merced—the risk of an AI error isn’t just an inconvenience; it’s a legal liability. If an AI summarizes a 911 call and misses a critical detail about a suspect’s weapon or a victim’s location, the consequences are severe.
This is why we insist on an HITL policy. The workflow should look like this:
- Ingestion: audio is processed by a CJIS-compliant, private AI instance.
- Transcription: the AI generates a raw text transcript.
- Human Review: a certified dispatcher reviews the transcript against the audio.
- Validation: the human corrects any errors and signs off on the accuracy of the record.
- Archival: the validated record is stored in the system of record, and the AI cache is purged.
By making the human the final arbiter of truth, you leverage the speed of AI without sacrificing the accountability required by law enforcement and healthcare standards.4
Securing your AI transition with Datapath
Building an AI usage policy is not a one-time event; it’s a continuous process of risk management. For mid-market businesses and government agencies, balancing productivity with compliance can be overwhelming. That is where Datapath steps in.
We don’t just provide IT support—we provide outcomes. Whether you are navigating the CJIS Security Policy in the Central Valley or managing EHR compliance in Southern California, we make sure your infrastructure supports your policy. From deploying private, on-premises AI instances to running rigorous CJIS compliance services and managed cybersecurity services, we provide the named team you need to stay compliant.
If you’re unsure whether your current AI usage puts your agency at risk, let’s have a conversation. We can help you move from the danger of shadow AI to a governed, secure, and high-performance AI environment that protects your data and your community.
Frequently asked questions
What is an internal AI usage policy?
It is a written, enforceable set of rules that defines which AI tools employees may use, for which types of data, and under what controls. In regulated environments it maps each tool to a data-sensitivity tier and specifies the contracts (such as a BAA or a CJIS-compliant cloud agreement) and workflows required before use.
Do CJIS or HIPAA prohibit using AI tools?
No. Neither framework bans AI outright. They require that regulated data—CJI under CJIS, or PHI under HIPAA—stays protected, access-controlled, and within authorized boundaries. AI is allowed when the tool and its contract meet those requirements, which is what your policy exists to enforce.
What is a zero-data-retention (ZDR) agreement and why does it matter?
A ZDR agreement is a written commitment from a vendor that it will not store your inputs after a session ends and will not use them to train its models. For regulated data it is the difference between a tool that processes information and one that quietly absorbs it.
Can we use a consumer AI chatbot if we don’t upload regulated data?
For genuinely public, non-confidential work—such as brainstorming a public-facing announcement—a consumer tool can be acceptable. The risk is human error: staff pasting regulated data into a prohibited tool. That is why the policy pairs the approval matrix with training and a clear request workflow.
What is a human-in-the-loop (HITL) workflow?
HITL means a qualified person reviews and validates AI output before it becomes an official record. In dispatch or clinical settings, the AI produces a first draft and a certified reviewer checks it against the source before archival, preserving the accountability regulators expect.