Doctrine

Frontline Intelligence

AI and technology for fire, EMS, and emergency services.

The AI Data Problem Just Got Solved (For Fire & EMS)

Robert Grand · Battalion Chief who still runs calls

OpenAI announced a networking pattern that lets AI assistants reach private servers inside your firewalls without punching holes in the network, opening inbound ports, or exposing data to the public internet. The tech press called it a developer convenience. That was the wrong read.

This solves the constraint that has been locking fire & EMS out of AI entirely.

The Data Problem That Was Holding Everything Back

The conversation I keep seeing in fire and EMS is this: department leaders want to use AI. “I want AI to catch things in our ePCRs that we are missing. I want AI to surface patterns in our call data. I want decision support for dispatch. I want to find what we are doing wrong in our training materials.” Then the IT director or CIO asks the obvious question. “Great. Where does the data live?” “On our servers. Patient records, incident data, personnel files.” “Then no. We cannot send that to the cloud.”

That has been the conversation in most fire departments. Not “we do not think AI will help.” Not “we do not trust the technology.” But “we cannot send CJIS-compliant data or HIPAA-protected patient records to the public internet.” That is a legitimate constraint. A breach is a legal liability, a public trust violation, and an operational disaster. Most fire services have spent years hardening networks to keep patient data, incident data, and personnel information private. The answer to “how do we integrate AI?” becomes “we do not, because the security cost is too high.”

That constraint just changed.

What OpenAI Actually Shipped

OpenAI released Secure MCP Tunnel on May 27, 2026. MCP stands for Model Context Protocol. It is a system for letting AI assistants use external tools and reach data sources. What OpenAI added is a networking pattern that reverses the direction of the connection (https://developers.openai.com/api/docs/guides/secure-mcp-tunnels).

Normally, you have two options for connecting a private server to the public internet. Option one: open an inbound port on your firewall and let external systems reach your server. Option two: build a VPN, set up authentication, manage keys, patch systems, and maintain a separate secure layer on top of your network security. Both cost you complexity, both cost you vulnerability surface, and both require your IT team to maintain another system.

Secure MCP Tunnel is different. A lightweight daemon runs on a machine inside your network that can already reach your ePCR database, RMS, CAD system, or any other internal data store. That daemon opens an outbound HTTPS connection to OpenAI. It pulls work from the tunnel, forwards requests to your private servers, gets back responses, and sends them through the same tunnel. The whole thing is outbound only. Your firewall stays closed. Your network stays private. Your data never sits in the cloud.

Why This Solves the Fire & EMS Problem

Here is what this means operationally. Your ePCR system is HIPAA-protected and sits on private infrastructure. Your incident records are CJIS-compliant. Your training materials and call data are operational intelligence you keep internal. For the last three years, vendors have pitched decision support, analytics, and AI-assisted documentation. Your IT director has said no, because “the system cannot go to the public internet.”

With Secure MCP Tunnel, the data never leaves your network. Your private servers never open an inbound port. The outbound connection is just HTTPS, the same protocol your crews use to access email from the firehouse. It is the pattern that CIOs have been waiting for: “AI can have context about our data, but the data stays on our servers.”

This is not hypothetical. CJIS is the Criminal Justice Information Services program. It sets baseline security for law enforcement data. HIPAA sets privacy rules for patient information. Both are architectural constraints that make most cloud-first architectures impossible for public safety. Fire & EMS leaders have been watching large healthcare systems adopt AI decision support for clinical documentation, while law enforcement remains locked by the same CJIS constraints we face, and thinking, “That architecture is not available to us. Our data is too sensitive and too restricted.”

Secure MCP Tunnel changes that calculation. It is no longer “we cannot use cloud AI.” It is “we can use cloud AI, we just keep the data local.”

The Honest Constraint: Integration Still Requires Decisions

This solves the network security problem. It does not solve the governance problem.

A fire department that wants to use AI on its data now has to answer different questions. Your chief and command staff have to decide what use cases matter most and what accuracy you are accepting. Your legal team has to know that an AI system has been audited on your data and that you understand the liability. Your clinicians and field leaders have to be trained on when to override an AI recommendation and why. Your leadership structure has to decide which data you grant AI access to and which you keep isolated.

Those are not network security questions. Those are operational and legal questions. But they are the conversations that happen only after you have solved the network problem. For the last two years, fire departments have been stuck on the network question. “We cannot send our data to the cloud” meant those conversations never happened.

Now they can.

What This Means for the Next 18 Months

In the near future, the first fire departments will deploy AI systems using Secure MCP Tunnel. It will be someone willing to do the governance work, someone whose IT team understands outbound tunneling, someone whose leadership has thought through what data and what use cases matter first. They will learn what works. They will learn what breaks. They will publish their frameworks.

Every other fire department will watch that deployment. The ones that have been waiting for the network security question to be solved will start having real conversations about what AI can do with their ePCRs, their incident data, their call patterns, their training materials. The ones that thought the technology was not ready will reconsider. The ones that have been worried about CJIS and HIPAA liability will talk to their legal teams.

This is not the revolution moment. This is the permission moment. For the last three years, fire departments have been trying to do something (use AI on sensitive operational and clinical data) that the infrastructure did not allow. Secure MCP Tunnel removes that blocker. What happens next depends on whether your department is willing to do the work to use it safely.

The network question was the excuse. Now the real work starts.



Robert Grand is a Battalion Chief at Eugene Springfield Fire with 24 years of service. He writes Frontline Intelligence, a newsletter on operational doctrine, technology, and leadership in Fire & EMS.

If this landed, share it with someone in Fire & EMS who needs to hear it.

Subscribe

From the floor, not the vendor booth. Two times a week.