AI for public defenders is arriving one tool at a time, and that pattern carries a cost most offices never put in the budget. NACDL’s new white paper, Parity in Practice: The Defender’s Duty to Ethically Use AI, argues that defenders have an ethical obligation to close the technology gap with prosecutors. It also, without quite saying so, shows why closing that gap tool by tool is the expensive way to do it.

The obligation itself is not really in dispute. In an adversarial system, a one-sided technology advantage is never neutral. Prosecutors are already using AI for evidence management, discovery review, transcription, redaction, and pattern identification across cases. The paper’s position is that defenders have a duty, rooted in competence and diligence, to understand what those tools do and whether comparable capability belongs in their own hands.

The paper also documents that defenders are already moving. State defender agencies are using AI transcription tools to handle the surge of bodycam footage, cutting hours per case from evidence review and surfacing contradictions in police statements that manual review would have missed. Others use video tools to isolate clips and build court exhibits from bodycam and interrogation footage. One large county office built a custom document pipeline that reduces manual data entry by up to 85% and proactively alerts defenders to new filings from law enforcement, the courts, and the prosecution. This is real work by real offices, and it is closing the gap.

But read those examples together and a second problem comes into focus. Nearly all of that progress is happening one tool at a time: a video tool here, a document tool there, a case file that lives apart from both. That pattern carries a cost, and the cost is not the license fee.

Why Every New AI Tool Means Another Security Review

Every AI tool an office adopts triggers its own full diligence cycle, and the white paper spells out exactly how long that cycle is. Before a single tool is approved, defenders should determine whether it runs in a closed environment, whether data is encrypted in transit and at rest, who inside the vendor can access stored data, what third-party service terms apply, whether the vendor trains on customer data, what audit and logging capabilities exist, and how the vendor handles breaches. Then come the contract terms: prohibiting use of submitted data for training, requiring deletion on request, indemnifying the office against breaches caused by vendor negligence, and specifying jurisdiction and venue for disputes. Then a judgment about the vendor itself, including whether a young company has the financial stability, certifications, insurance, or escrow arrangements to survive the length of the relationship.

That is a serious and correct list. It is also a list that gets run in full for every single tool. Four tools means four security reviews, four contracts, four renewal cycles, and four sets of terms to re-read when the vendor quietly updates them. The paper flags a particular trap here. Obligations flowed down from underlying model providers are, in its words, “often unenforceable by the attorney yet fully enforceable against the firm,” creating an asymmetric risk exposure that most users never recognize. Every additional vendor is another opportunity to inherit terms nobody read.

For an office of ten attorneys with no dedicated IT staff, this is where modernization quietly dies. Not because the tools fail, but because the fifth diligence cycle never gets done. Either the tool gets adopted without the review, or it does not get adopted at all. Both outcomes are bad, and the second one is the one that keeps offices on paper.

Where AI Findings Go When They Live Outside the Case File

They stay in the tool that produced them, and a person has to move them by hand. This is the second cost of piecemeal adoption, and unlike the first one it shows up only after the tool works.

A defender runs six hours of bodycam through a transcription tool and finds three contradictions in an officer’s account. Where do those findings live? In the video tool. Someone has to move them by hand: to the case file, to the trial notebook, to whatever the supervisor actually reviews before a suppression hearing. Multiply that by every tool and every case, and the office has rebuilt manually the connective tissue the case management system was supposed to provide. The AI saved four hours of review and gave back two hours of copying and pasting.

The white paper’s verification expectations make this harder, not easier, and they are right to. Every AI output requires human review before use. Transcripts get checked against source audio. Every citation gets verified against the actual case rather than by asking the AI whether its own citations are real. High-stakes submissions warrant documented verification by one or more reviewers. But verification is only auditable if there is a record of who reviewed what and when. When the tool that generated the output lives outside the system of record, that record is a person’s memory or a spreadsheet somebody maintains until they leave.

The paper’s more encouraging examples point the other direction: case management systems that centralize files into searchable folders accessible to everyone working the same case, integrated with justice partner systems rather than sitting beside them. Integration is not a nice-to-have. It is the thing that makes the rest defensible.

One AI Use Policy, Five Separate Systems to Govern

The white paper gives defender offices one year to adopt a written AI use policy, and that policy has to cover every AI tool in the building, not just large language models but transcription services, image generators, and analytics platforms. It has to define permitted, supervisor-approved, and prohibited uses. It has to specify approved tools by name. It has to set confidentiality and verification protocols, mandate training before use, and establish monitoring and enforcement.

Every tool added expands that surface. Another entry in the approved-tools list. Another module in the training curriculum. Another system to audit. Another vendor to re-review when the policy comes up for its annual revision. An office that adopted five point solutions to close the AI gap has also committed itself to governing five systems, with staff it was never funded to hire. That is administrative drag wearing a different coat.

How an Integrated Case Management System Changes the Math

It collapses the repeating costs into single ones: one contract, one security review, one training curriculum, one audit log. That is the problem ZLS.app was built around. Every type of discovery lives in one platform, with AI that reviews and synthesizes large document sets, and the output lands on the case file it belongs to. Not because integration is technically elegant, but because the alternative asks a chief defender to run a procurement and governance operation nobody funded.

Built by public defenders for public defenders, for this practice area rather than adapted to it. Data as a byproduct of the work, not another system to feed.

ZLS.ai AI-Aided File View

What AI Parity Actually Requires of a Public Defender Office

Parity requires a path the office can sustain, not just a collection of tools that each work. NACDL’s framing is the right one, and the question is no longer whether AI belongs in public defense, because the paper settles that. The open question is whether an office can reach parity by a route it can actually carry, or whether closing the gap tool by tool simply converts one form of administrative burden into another.

If your office is starting this conversation, the white paper is worth reading in full. And it is worth asking one question before the first vendor call: how many separate contracts, security reviews, and training modules is this office prepared to carry, and what does that answer imply about the right approach to public defender AI adoption?

“Parity in Practice: The Defender’s Duty to Ethically Use AI,” NACDL Task Force on Artificial Intelligence. Available at NACDL.org/ParityInPractice.