Once an AI-assisted draft or a record of AI use exists, whether it has to be disclosed is decided by the same law that governs the rest of a police case file: the jurisdiction’s own discovery rules and, in a criminal case, Brady v. Maryland’s due process rule on evidence favorable to the defense. Whether it exists at all to be discovered is a different question, decided by retention law rather than discovery law. California’s statute on AI-drafted reports answers that second question by requiring the first draft to be kept, and adds one sentence that bears on the first, covered below. Utah’s imposes no retention duty. Neither the CJIS Security Policy nor the proposed federal rule on AI-generated evidence answers the first question.
Does a retention requirement also decide whether the draft gets disclosed?
No. Retention and disclosure are two separate legal questions, decided by two different bodies of law, and what has to be preserved when an officer uses AI to draft a report covers the first one in full: California’s Penal Code section 13663 requires an agency to keep the AI’s first draft as long as the official report is retained and to maintain an audit trail naming who used the tool, while Utah Code section 53-25-902 requires an agency policy on generative AI, a disclaimer in the report and the author’s certification that they reviewed it, with no retention duty at all. Neither statute says who else gets to see a draft or under what circumstances. California’s does say one thing that bears on it: except for the official report, a draft created with AI “shall not constitute an officer’s statement.” Beyond that, who gets to see the draft is left to the discovery rules and case law covered below.
The same split applies to the footage behind the draft. California’s audit trail must identify the video and audio footage used to create the report, if any, but section 13663 says nothing about disclosing that footage. That question stays with whatever rules already govern body-worn camera footage in the jurisdiction.
What do Brady and a state’s own discovery statute actually reach?
Under Brady, the prosecution’s suppression of evidence favorable to the accused violates due process where the evidence is material either to guilt or to punishment, a constitutional floor that applies in every U.S. jurisdiction. States set their own criminal discovery rules on top of that floor, and those rules differ from state to state, so this page works through one state’s statute as a worked example rather than a universal answer. California’s Penal Code section 1054.1 requires the prosecutor to disclose materials in the prosecutor’s possession, or known to be in the possession of the investigating agencies, including the statements of all defendants, any exculpatory evidence, and “relevant written or recorded statements of witnesses or reports of the statements of witnesses whom the prosecutor intends to call at the trial.”
When the officer who used an AI tool is a witness the prosecutor intends to call, section 13663 points two ways on that last category. Its subdivision (b)(2) says that, except for the official report, “a draft of any report created with the use of artificial intelligence shall not constitute an officer’s statement.” That leaves the signed report as the officer’s statement, which reads as fitting the category of witness statements, and says the AI first draft is not one, which a court could read as keeping the draft out of it. The duty to disclose “any exculpatory evidence” does not depend on that label. Whether a California court would order an AI first draft produced under section 1054.1 is a question no published decision has settled as far as we can find, which makes it unsettled here in the plain sense: a court ruling on a discovery motion, or the Legislature amending the statute, is what would settle it, not this page.
Brady does not turn on that label either. It is a due process rule, not a state statute, so the question under Brady is whether what the draft contains is favorable to the defense and material, for example where the draft says something the officer’s signed report does not. That is a fact-specific determination for the prosecutor and, on review, the court in the case, and it is exactly why a draft that was never retained cannot be evaluated either way.
Does the proposed Federal Rule of Evidence 707 make an AI report discoverable?
No, and it would not even if it were already in force. Proposed Rule 707 is an admissibility rule: it would require evidence produced by artificial intelligence, when offered at trial without an expert witness, to clear a reliability showing modeled on Rule 702. That is a question about whether evidence can be used at trial, not a pretrial disclosure duty. And as a Federal Rule of Evidence it would apply only to proceedings in federal courts, not in state courts, unless a state adopted a rule of its own.
Its own status also has not reached that point. A draft was published for public comment in August 2025, and the comment period closed February 16, 2026. At its May 7, 2026 meeting, the Advisory Committee on Evidence Rules reviewed the comments, withdrew the version it had published, approved in principle a revised draft that covers “artificial intelligence” rather than the broader “machine-generated” label it started with, and declined to release that revision for a new comment period. It chose instead to have technology experts and others in the field of AI and law vet the rule, and the agenda for its October 15, 2026 meeting sets a panel of AI experts for that purpose. The Rules Committee’s September 2026 report to the Judicial Conference lists Rule 707 only as something the Advisory Committee “continued consideration of,” an information item, not an approved amendment. As of September 26, 2026 it has not been adopted, has not been sent to the Judicial Conference or the Supreme Court for approval, and carries no confirmed effective date. Confirm its status directly before relying on it; committee schedules on a rule this new can move by the time this page is read again.
Has a police department already had to plan for this?
At least one has, in writing. The generative AI policy that Fargo, North Dakota’s Police Department issued on August 12, 2025 lists this among its AI coordinator’s duties:
“Developing procedures in coordination with the Brady information coordinator and the Records Manager for the compilation and potential release of any discovery or records related to the use of GenAI systems consistent with Brady and the North Dakota Open Records Law.”
That single clause treats this page’s question as an operational fact rather than a hypothetical: whatever a department’s AI tools produce may have to be compiled and possibly released, and someone specific needs to own that call before a request arrives. Not every department’s policy goes this far. Two other publicly posted department policies, from Boulder, Colorado and St. Paul, Minnesota, cover authorized use, required human review of AI-drafted report narratives, and a note on other work products that AI was used, but neither one, as posted, names a comparable discovery or records-coordination duty, even though St. Paul’s repeats much of the same wording as Fargo’s. A department adopting a published template should check its own copy for this duty rather than assume it is there.
What should a department do to keep this answerable either way?
- Keep the first draft and the audit trail. A record that was never made cannot be produced under any rule, favorable or not; see what has to be preserved for the baseline.
- Do not conflate retention with disclosure. Keeping a record and being required to produce it in a given case are different decisions, and the second one belongs with counsel, applying the jurisdiction’s own discovery rules and Brady to the facts of that case.
- Name who decides. Fargo’s policy has its AI coordinator develop the procedures for this with its Brady information coordinator and its Records Manager. A department with no equivalent role risks leaving the call to whoever happens to answer a request.
- Where no statute speaks to AI drafts, apply the rule your jurisdiction already has for other report drafts, rather than inventing a new category for them. Where one does, as California’s does, follow it.
- Do not wait on Rule 707. It is not in force, has no confirmed effective date, would govern admissibility rather than disclosure, and would not reach a state prosecution even if it is eventually adopted.
- Confirm the current rule in your own state before relying on any general description, including this page’s. Discovery rules are set state by state, and whether Brady reaches a given record is decided case by case.
Sources
- Brady v. Maryland, 373 U.S. 83 (1963). Full opinion text, read September 25, 2026.
- California Penal Code section 1054.1. Current code section, read September 25, 2026.
- California Penal Code section 13663, added by SB 524 (2025 to 2026 Regular Session). Chaptered bill text, read September 25, 2026.
- Utah Code sections 53-25-901 and 53-25-902, enacted by SB 180 (2025 General Session). Current code section, read September 25, 2026.
- Advisory Committee on Evidence Rules, Report to the Committee on Rules of Practice and Procedure, dated May 17, 2026, on proposed Rule 707. Full report, read September 26, 2026.
- Committee on Rules of Practice and Procedure, Report to the Judicial Conference of the United States, September 2026, with attachments. Full report, read September 26, 2026.
- Advisory Committee on Evidence Rules, agenda book for the October 15, 2026 meeting, including the Reporter’s memorandum of September 15, 2026 on proposed Rule 707. Full agenda book, read September 26, 2026.
- Federal Rule of Evidence 101, Scope. Rule text, read September 26, 2026.
- Fargo Police Department, Policy 345, Generative Artificial Intelligence Use, original issue August 12, 2025. Full policy text, read September 26, 2026.
- CJIS Security Policy, version 6.1, June 25, 2026, FBI Criminal Justice Information Services Division. Full policy text, read September 25, 2026.
Where Verillian fits
Verillian governs AI use on the devices you enroll. A checkpoint on each device sits between your people’s AI tools and agents and the AI providers it supports. For Claude and Claude Code traffic (the Anthropic API format), a tool call your policy bans is removed before your machine can run it; for the other supported providers, it screens and records the usage, and the Claude desktop app and Cursor are recorded only, with no redaction. Each record is signed on the device it came from and hash-chained to the one before it, so a change to its signed fields is detectable, and it stays on your own infrastructure. It cannot show that nothing was omitted. Redaction is best-effort, not a guarantee that every value is caught. The admin server runs where you choose: on-prem or in a private cloud you run. macOS is the supported install today; Windows has an interim scripted installer and Linux builds from source. For a department, each entry is attributed to the user and device the checkpoint reports, and when, on an enrolled device, which is one fact a discovery review or an audit might ask for, though not proof of who was at the keyboard. It does not decide what a court orders produced, and it is not a substitute for the first draft California’s statute requires an agency to keep. The architecture is aligned with CJIS Security Policy v6.1, not certified, because compliance with that policy is verified by audits of the agencies that use it, not by certifying products.
Verillian does not see inside a vendor’s own cloud. When a vendor’s service calls a model on the vendor’s servers, as an ambient scribe or a hosted report-writing tool does, the record of what that model received is created on the vendor’s side, and the contract is your lever for it. What Verillian gives you is the record of AI use that starts on your own devices.
For the CJIS baseline behind any of this, see what the CJIS Security Policy requires before AI touches CJI. Our compliance mappings show the controls the platform is designed to support, the audit trail page shows what a device-side record contains, and the public safety section of the site covers what this looks like for an agency already running AI tools day to day.