An officer who took the oath in the weeks after September 11, 2001, is at or past the 25-year service mark today. An entire generation of U.S. policing has now been recruited, trained, promoted, and (in many cases) retired entirely inside the institutional framework that 9/11 built. For the profession, this anniversary is more than commemoration. It is an opportunity to audit whether the lessons of that day still match the threat and whether the machinery built to apply those lessons still reaches the places where critical information now lives.
The central lesson has never been in dispute. The 9/11 Commission concluded that information sufficient to disrupt the plot existed inside the U.S. government before the attacks. The failure was in assembling it. Individual agencies each held fragments: a flight school inquiry; a watchlist nomination that never propagated; and two known al Qaeda operatives living openly in San Diego, California. No mechanism, and often no willingness, existed to bring the fragments together. The phrase “a failure to connect the dots” became a lasting part of the profession’s vocabulary following the commission’s report. Its prescription was equally memorable:
The culture of agencies feeling they own the information they gathered at taxpayer expense must be replaced by a culture in which the agencies instead feel they have a duty to the information—to repay the taxpayers’ investment by making that information available.1
A quarter century later, U.S. law enforcement has substantially absorbed that lesson as it applies between agencies. The infrastructure built in response—fusion centers, expanded Joint Terrorism Task Forces, standardized suspicious activity reporting, and a federally codified information sharing environment—represents one of the most significant structural reforms in the history of policing.
But the dots have moved. Today, the fragments that matter to a terrorism case, a trafficking network, or a serial offender are as likely to sit in different systems inside a single agency as in different agencies across a region. And they arrive in volumes that no realistic analyst headcount can fuse by hand. Since 2011, the information sharing problem has changed shape; agentic artificial intelligence (AI) systems that perform investigative assembly work under human supervision are best understood as the next chapter of the same lesson. The governance disciplines the profession learned while building the fusion center network should shape what agencies adopt next.
What the Profession Built
It is worth recalling how much of the current landscape did not exist on September 10, 2001. Legal and cultural walls separated intelligence from criminal investigation. State and local agencies—the largest sensor network in the United States—had no systematic channel into national counterterrorism information. Federal holdings rarely flowed outward.
The response was rapid and structural. In March 2002, the IACP convened a summit that produced the National Criminal Intelligence Sharing Plan—the first U.S. blueprint for moving criminal intelligence lawfully among local, state, tribal, and federal partners.2 The Intelligence Reform and Terrorism Prevention Act of 2004 created the U.S. director of national intelligence, the National Counterterrorism Center, and the information sharing environment.3 States and major urban areas stood up fusion centers to serve as the connective tissue between national intelligence and local operations; the national network today comprises 80 fusion centers across the states and territories, which are recognized by the U.S. Department of Homeland Security.4 The FBI’s Joint Terrorism Task Forces, which numbered a few dozen before the 1993 World Trade Center bombing, grew rapidly to roughly 200 task forces after 9/11, with at least one in each of the FBI’s 55 field offices; membership drew from more than 500 state and local agencies.5 The Nationwide Suspicious Activity Reporting Initiative standardized how frontline observations move from a patrol officer’s contact to national counterterrorism review.
The results are real. Plots have been disrupted through the kind of sharing that failed in 2001. Intelligence-led policing moved from a specialty concept to an executive doctrine. Most importantly, the profession internalized the cultural shift the 9/11 Commission demanded: The presumption today is that information about a threat is shared, and an agency that hoards it bears the burden of explaining why.
None of this is finished work. Interagency sharing still depends on relationships, funding cycles, and classification practices that frustrate local partners. But the between-agency problem now has governance, standards, training, and dedicated institutions. The same cannot yet be said for the problem that has grown quietly alongside it.
What Has Changed
Two things have changed since 2001: the threat and the data.
The current national threat assessments describe a landscape defined less by directed plots with long planning timelines than by lone actors and small cells who radicalize quickly online, drawing selectively from jihadist propaganda, domestic extremist narratives, and personal grievance, often without any organizational direction that traditional collection would detect.6 At the same time, transnational criminal organizations have industrialized fentanyl production, human smuggling, and cyber-enabled fraud and are themselves adopting AI to adapt faster than enforcement can respond.7 Hostile cyber actors hold access to U.S. critical infrastructure networks against future need. The common thread across these threats is that the earliest observable signals are local. A patrol contact, a school threat assessment, a suspicious purchase, an online post reported by a community member—these land in a local agency’s systems long before anything reaches a federal database.
That reality collides with the second change: the data. Twenty-five years ago, the challenge was moving a small number of significant fragments between institutions that would not talk to each other. Today, the fragments arrive by the terabyte, and they land in systems that do not talk to each other inside the same building. A modern midsize agency holds relevant information in its records management system, computer-aided dispatch, jail management, field interview files, digital forensics extractions, body-worn and fixed camera video, license plate readers, tip lines, and case notes—plus the open-source footprint of any subject of interest. Forensic investigators in Denver, Colorado, report a 600 percent increase in audio and video evidence in the past five years; one prosecutor’s office processed more than 67,000 videos totaling 41,000 hours in a single year. A routine vehicular homicide that generated 79 photographs and no video in 2017 now generates hundreds of photographs and up to 90 hours of footage.8
The personnel available to fuse this material have not grown with it. Sworn staffing in the United States remains roughly 5 percent below January 2020 levels—even after recent hiring gains—and retirements rose again in 2025 as the large, post-9/11 hiring cohorts reach eligibility.[9] Intelligence units and crime analysis sections, which are never generously staffed, triage the data. The practical consequence is familiar to every executive; pattern-level insight—the alias that ties three cases together, the vehicle that appears at two scenes, the escalating series of low-level contacts that precedes an attack—tends to surface after an arrest rather than before an incident.
Stated plainly, the profession solved the willingness-to-share problem far more completely than the capacity-to-use problem. The dots are collected. They are lawfully accessible. What is missing is the labor to connect them at the speed and scale the threat now demands. That is no longer primarily a culture problem or a legal problem. It is an assembly problem—and assembly problems are what the newest AI systems are built to tackle.
Fusion at Machine Scale
Most executives’ experience of AI to date has been a chatbot—one general-purpose model answering questions from its training data. The systems relevant to the assembly problem work differently. An agentic, or multi-agent, system is a coordinated set of specialized software agents working under an orchestrator. In an investigative setting, one agent queries the records management system, another works through digital evidence, another checks open sources, and another reads prior case files—simultaneously. The orchestrator reconciles what comes back: the same person under three spellings of a name, the same vehicle under partial plates, and a timeline assembled across sources. The product is not a machine verdict. Done properly, it is a structured briefing in which every assertion is cited to its source, graded for confidence, and delivered to a human investigator or analyst who verifies, judges, and decides.
The profession already has the right mental model for this architecture, and it comes from 9/11. A Joint Terrorism Task Force works because specialists from different agencies sit together, share a common operating picture, and answer to unified supervision. A multi-agent system applies the same design to software, including specialist components, a common picture, and a single point of human accountability. What the task force model did organizationally for information between agencies, agentic systems can do computationally for information within them.
Four applications illustrate where this matters most for the threats this anniversary asks us to consider.
Threat assessment and tip triage. The post-9/11 reporting architecture succeeded in generating volume, such as suspicious activity reports, tip-line traffic, and school and workplace threat reports. Each item requires the same manual routine: check the subject against agency holdings, prior contacts, associated persons, and open sources, then decide whether it warrants escalation. This is precisely the repetitive, cross-system assembly work that AI agents can perform in minutes with full citations, so that trained assessors spend their time on judgment rather than lookup. Faster, more consistent triage of the reporting the public and patrol already provide is the closest available analog to connecting the dots left unconnected in 2001.
Pattern and network crimes. Lone-actor terrorism, serial offenses, trafficking, and organized retail crime share a property; the signal lives in aggregation, not in any single report. Walking a subject’s associates out two degrees, reconciling incidents across jurisdictions, and correlating communications records is hours of analyst work per subject. Performed in parallel by machine, it becomes feasible to do routinely rather than only for the highest-priority cases.
Case-file assembly and cold-case review. Sub-agents can extract entities and events from body-worn camera transcripts, interview recordings, warrant returns, and extractions; reconcile timelines; surface contradictions between statements; and produce a first-pass summary a detective verifies rather than builds. The same capability applied to cold cases—re-running old files against current holdings and open sources—regularly surfaces connections that did not exist when the case went cold.
Institutional knowledge continuity. The generation that built post-9/11 policing is retiring, and what a 25-year investigator carries—what to check, whom to call, or what the last plot looked like before it was a plot—rarely survives a two-week handoff. Systems that learn from an agency’s own case history and senior practitioners can put a version of that accumulated judgment beside a junior investigator from their first day. As the post-9/11 cohort exits, this may prove the most consequential application of all.
What these systems do not do is equally important. They do not decide, arrest, charge, or predict. They assemble, cite, and summarize; humans evaluate and act. An agency that keeps that boundary sharp gains capacity. An agency that lets it blur inherits every failure mode the technology has.
Legitimacy Is Built In, Not Bolted On
The fusion center era teaches a second lesson that belongs in any AI conversation. The network’s hardest years came not from operational failure but from legitimacy challenges: civil liberties organizations, congressional scrutiny, and communities asking what was collected about whom and under what authority. The centers that endured did so by making privacy, civil rights, and civil liberties protections structural—written policies, 28 C.F.R. Part 23 compliance, designated privacy officers, audits, and training. The lesson is that capability without governance is fragile, and retrofitted governance never fully recovers public trust.
Applied to agentic AI, that lesson converts into concrete requirements an executive should treat as nonnegotiable before any deployment:
1. Source citation on every assertion. If the system cannot show where a fact came from, the fact does not belong in a work product. Citation is what makes machine-assembled material verifiable, and what makes errors detectable.
2. Confidence grading at the claim level. Investigators and analysts already think in degrees of certainty; the tool must express its output the same way rather than presenting weak inferences and strong records in the same voice.
3. Human review at every consequential step. No enforcement action, no inclusion in an affidavit, and no intelligence product should be released on machine output alone. The system proposes; a named, accountable person disposes.
4. An audit trail that survives discovery. Every query, source, and output must be logged and reproducible. If the workflow cannot be explained to a judge, a defense attorney, and a city council, it does not belong in an investigation.
5. Access control scoped to authority. The system must honor the same role-based and legal boundaries as the humans it serves. An agent queries only what its supervising user is authorized to see, and cross-agency data moves only under the agreements that already govern it.
6. Policy before procurement. The agency’s use policy, prohibited uses, retention rules, and community transparency approach should exist before a contract is signed, not after a controversy.
None of these requirements are exotic. They are the same disciplines the profession imposed on criminal intelligence after 2001 translated for a new tool. Vendors who cannot meet them are not offering law enforcement technology; they are offering liability.
Recommendations for Executives
Drawing the threads together, five practical steps can guide an agency of any size:
1. Conduct an internal information sharing audit. The profession knows how to audit sharing with external partners; few agencies have mapped which of their own systems can be searched together, which cannot, and what an investigator must do by hand to assemble a complete picture of one subject. That map is the business case, and the deployment plan, for any assembly technology.
2. Write the governance framework first. Adapt existing criminal intelligence and technology policies to cover AI-assembled work products, review responsibilities, and prohibited uses. The IACP’s technology policy resources and the fusion center privacy framework are directly reusable starting points.
3. Put the six requirements into procurement language. Citation, confidence grading, human review, auditability, access control, and policy alignment should appear as mandatory specifications in any request for proposal, and acceptance testing should verify them.
4. Start narrow and measure. Choose one bounded use case. Tip triage or first-pass case summarization are natural candidates. Define success in hours returned to investigators and quality of output. Evaluate before expanding. Credibility with officers, prosecutors, and the community is earned one use case at a time.
5. Engage prosecutors and the community early. Discovery obligations, admissibility questions, and public expectations are easier to address in design than in litigation. The agencies that navigated fusion center scrutiny best were those that explained before being asked.
The Duty to the Information, Updated
The 9/11 Commission asked the government to stop treating information as property and start treating it as a duty. U.S. policing answered. The task forces, fusion centers, and reporting systems built over 25 years stand as proof that this profession can remake itself structurally when the mission requires it, and the officers who spent whole careers building that architecture deserve to see it named as the achievement it is.
The 25th anniversary finds the same lesson wearing a new shape. The information that will matter in the next attack, the next network, the next series is almost certainly already in policing hands, whether collected by a camera, logged by a dispatcher, or filed in a report, all sitting lawfully in systems that do not speak to one another and in quantities no human team can read. The duty to the information now includes a duty to make it usable: to connect—at machine speed and under human judgment—the dots already being held. The profession that learned to share across agencies is fully capable of learning to assemble within them, and of doing it with the governance discipline that a quarter century of hard-won legitimacy demands. d

Michael Joy is a retired NYPD captain who served in intelligence and counterterrorism roles before commanding the Strategic Technology Division, where he led the agency’s technology modernization initiatives. He now leads the product team at Rilian, building AI-enabled solutions. Michael is a member of the IACP Computer Crime and Digital Evidence Committee and a published author of data analytics research.
Notes:
1National Commission on Terrorist Attacks Upon the United States, The 9/11 Commission Report: Final Report of the National Commission on Terrorist Attacks Upon the United States (U.S. Government Printing Office, 2001), 417.
2Global Justice Information Sharing Initiative, The National Criminal Intelligence Sharing Plan (U.S. Department of Justice, Bureau of Justice Assistance, 2003).
3Intelligence Reform and Terrorism Prevention Act of 2004, Pub. L. No. 108-458, 118 Stat. 3638 (2004).
4U.S. Department of Homeland Security (DHS), 2021 National Network of Fusion Centers Assessment: Summary of Findings (2022).
5Federal Bureau of Investigation, “Joint Terrorism Task Forces”; Federal Bureau of Investigation, “Celebrating 45 Years of FBI Joint Terrorism Task Forces,” April 21, 2025.
6Office of the Director of National Intelligence, 2026 Annual Threat Assessment of the U.S. Intelligence Community (2026).
7Office of Intelligence and Analysis, 2025 Homeland Threat Assessment (DHS, 2024).
8Allison Sherry, “Way Too Much Body Camera Footage: Police, Prosecutors and Defense Attorneys Struggle with Loads of Digital Evidence,” CPR News, January 2, 2026.
9Chuck Wexler, “PERF Survey Shows Police Staffing Increased Slightly in 2024 But Still Lower Than 2019,” letter to Police Executive Research Forum members, July 5, 2025.
Please cite as
Michael Joy, “The Dots Have Moved: The Next Chapter of Post-9/11 Information Sharing” Police Chief Online, September 30, 2026.


