Home / Insights / Guides

Can a police department use ChatGPT or Claude under CJIS?

RedLens AI Security Research · 8 October 2026

The short answer

  • There is no yes-or-no answer, because the FBI does not certify any AI product or vendor for CJIS.
  • The questions that decide it are: does Criminal Justice Information (CJI) go into the tool, is the service inside your agency's CJIS boundary under the agreements the policy requires, and has your CJIS Systems Officer or CJIS Systems Agency made that determination.
  • A personal or consumer AI chat account is not inside your boundary. Keep CJI out of it.
  • An enterprise or government edition can be brought inside the boundary under agreement. Once it is, the work is not finished: the same controls that apply to any CJI system apply to it, and AI fails in ways ordinary testing misses.

Why "is it CJIS compliant?" is the wrong question

Compliance with the CJIS Security Policy is a property of an agency's environment, determined by its CSO or CSA, not a badge a vendor can hold. Vendor pages that call a product "CJIS compliant", or call a competitor "not CJIS compliant", are making a claim neither vendor is in a position to make. What a vendor can do is describe where its service runs, what agreements it will sign, and what evidence it can give you.

The three questions that actually decide it

1. Does CJI go into the tool?

If officers use an AI assistant only for material that is not CJI, the CJIS Security Policy may not be the governing question at all, though your agency's own AI policy still is. The moment CJI is pasted in, uploaded, or retrieved by the tool, it is.

2. Is the service inside your CJIS boundary?

CJISSECPOL v6.1 still numbers one policy area for this: 5.1 Information Exchange Agreements. A service that handles CJI has to sit inside the boundary those agreements define. A consumer account, used under a vendor's standard terms, does not. Some AI vendors offer enterprise or government-cloud editions designed to be brought inside under agreement; whether a particular one qualifies for your agency is your CSA's call.

3. Has your CSO or CSA made the determination?

That determination, not a vendor statement, is what you rely on. Bring it the specifics: which product and edition, where it is hosted, what data it will see, and who can access it.

Inside the boundary is where the work starts

Being inside the boundary settles where the data lives. It does not settle how the system behaves. The controls that matter most for AI apply whichever vendor's model is behind it: SI-10 Information Input Validation, AC-6 Least Privilege, and CA-7 Continuous Monitoring. Three common law-enforcement workflows show why.

Report-writing assistant

It reads witness statements, suspect statements and uploaded documents. Any of them can carry instructions the model follows. That is indirect prompt injection (CVSS 9.5 in RedLens's attack schema), and it is an input-validation question under SI-10.

Records-query agent

It has tools that reach records systems. The risks are an attacker steering which tool it calls (tool-chain hijacking, CVSS 9.7) and an agent widening its own actions (autonomous action amplification, CVSS 8.9). Both are least-privilege questions under AC-6.

Dispatch triage assistant

If it keeps state through a persistent connector, such as an MCP server, instructions planted there can resurface in later sessions (MCP memory poisoning, CVSS 9.0). That is SI-10 again, and the reason one-off testing is not enough under CA-7.

The CJIS Security Policy and AI guide lists all seventeen controls AI testing can evidence, with sanction status and what it cannot evidence.

What your agency's AI policy should say about testing

Where RedLens fits

RedLens tests the AI system, not your paperwork. It runs real adversarial attacks, including the injection, tool-abuse and memory-poisoning methodologies above, against the AI you deploy. For dispatch and records work it generates synthetic, clearly labelled incident logs, unit IDs and case identifiers, so no real call, record or CAD data enters a test. Findings map to the NIST AI RMF, and the evidence package cites CJISSECPOL v6.1 controls one by one, cross-referenced to v5.9.5. On the Enterprise plan it can run as a self-hosted, on-premise deployment that keeps your prompts, results and reports on your own hardware. It is on-premise, not air-gapped: attack generation and judging call the Anthropic API.

RedLens holds no CJIS authorization and cannot make your agency compliant. Your CSO or CSA is the authority on that.