
Investigations & Evidence
AI-Assisted Cybercrime Investigations: Why Law Enforcement Can't Afford to Fall Behind
September 9, 2026
I've spent more than 35 years across technology, business, and law enforcement, including years investigating cybercrime with the Toronto Police Service, and I currently teach the Cybercrime Investigators Course for the RCMP at the Canadian Police College. I've said for years that the future of criminal investigations will rise or fall around what we do with the data. Having spent real time putting AI-assisted tools to work against real investigative data since I wrote that, I want to sharpen the thesis: law enforcement doesn't get to sit this one out. Either the profession builds the capability to use these tools responsibly and keeps pace with how fast cybercrime is scaling, or the gap between what criminals can do and what investigators can keep up with keeps widening. The people who pay for that gap are victims, not agencies.
The scale problem isn't slowing down
The FBI's Internet Crime Complaint Center has published an annual report on reported losses since long before AI entered this conversation, and the trend line alone makes the urgency case better than I can. Reported losses climbed from $6.9 billion in 2021 to $10.3 billion in 2022, $12.5 billion in 2023, $16.6 billion in 2024, and $20.9 billion in 2025 - over a million complaints that year alone, close to 3,000 a day. That's not a spike. That's compounding growth, year over year, and it's happening while the volume and complexity of the data behind each case keeps climbing right alongside it: financial records, device extractions, cloud accounts, OSINT, corporate filings, communications across a dozen platforms. An investigator with a spreadsheet and a good memory was never going to keep pace with that on their own, and the gap between rising case volume and static investigative capacity is exactly where this stopped being theoretical for me.
In 2020, researchers at UCL's Dawes Centre for Future Crime ran a study I still think about. They assembled a panel of 31 experts - academics, private sector, police, government, and state security - and had them rank 20 ways AI could be used to facilitate crime over the following 15 years, scored on harm, criminal profit, how achievable the crime was, and how hard it would be to stop. Six ranked as highest concern: audio and video impersonation, driverless vehicles turned into weapons, tailored phishing, disrupting AI-controlled systems, large-scale blackmail, and AI-authored fake news. Fake audio and video topped the list. Five years later, I'm seeing versions of several of those show up in real casework - voice-cloned "family emergency" calls, adviser impersonation, phishing that reads like it was written by someone who actually knows the target, because increasingly it was. The researchers gave the profession a fifteen-year runway. We're using it faster than that.
What a modern investigation actually has to do
I came up in an era where cross-referencing a name across three case files meant remembering which file it was in, or manually searching each one. That model doesn't survive contact with the volume of data a single cybercrime file generates now. What does is the same approach that changed how I think about search generally: Elasticsearch-backed platforms that can search, fuse, and surface connections across structured and unstructured data, in something close to real time, instead of an investigator stitching it together by hand.
I sit on the Advisory Board at Siren.io, and I've watched that idea move from a pitch to something governments are actively investing in. Siren Investigate is built natively on Elasticsearch, and its whole premise is data fusion - pulling together background records, OSINT, forensic data, and whatever else a case touches into a single explainable, auditable view, rather than a dozen disconnected systems an investigator has to check one at a time. In December 2025, Elastic - the company behind Elasticsearch - made a strategic investment in Siren specifically to accelerate that platform's AI capability, including a newly launched product called K9, an AI companion already in use by national security, law enforcement, and financial-crime agencies. I don't cite that as a sales pitch. I cite it because when the company that builds the search infrastructure underneath half the investigative tools in this space is putting money behind AI-driven investigation specifically, that's a signal about where the floor is moving, not just the ceiling.
I've also put this to work directly in my own practice, using Claude Code against Elasticsearch-backed data - asking it to help organize, query, and surface patterns across large, messy datasets the way I'd once have done by hand, one document at a time. I want to be precise about what that is and isn't. It's the same discipline I laid out when I wrote about AI in digital evidence work: AI as an investigative assistant, not an evidence source, a forensic examiner, or an attribution authority. It doesn't replace judgment, and it doesn't get to draw a conclusion I haven't independently verified. What it does do is close a gap my early career never had a way to close - the distance between how much data a case generates and how much of it an investigator actually has time to look at.
Recognition isn't the same as readiness
Here's where I think the profession is stuck, and it isn't a lack of belief in the technology. Mark43's 2025 U.S. Public Safety Trends Report, a national survey of 538 public safety professionals, found 90 percent of law enforcement respondents support their agency using AI - up sharply from the year before - and 89 percent think it would help reduce crime. The appetite is real.
What's missing is the operational readiness to match it. The National Policing Institute's August 2026 report, "The AI Adoption Strategy Gap in Policing," surveyed agencies already using the technology and found 83 percent had formally deployed at least one AI tool. But 44 percent had given their personnel no AI-specific training at all, and while 61 percent had designated someone or some committee responsible for AI governance, the report was blunt that the designation alone wasn't doing the job. Its authors didn't mince words: no American law enforcement agency has yet developed a proven, replicable accountability framework for AI that the rest of the field could adopt as a standard.
That's the actual gap. Not whether to use AI in investigations - that decision is already being made, tool by tool, agency by agency, whether or not there's a policy behind it. The gap is between deployment and the training, governance, and validation that make deployment something other than a liability waiting to surface in a courtroom.

What keeping pace actually requires
None of this works as a bolt-on. Train the people using the tools, not just the tools themselves - a platform is only as reliable as the investigator's judgment about when to trust its output and when not to. Build an auditable chain of reasoning into every AI-assisted step of a case, not just a chain of custody for the underlying evidence - what was queried, what model or system produced the result, what the investigator verified independently, what got rejected. Treat platforms like Elasticsearch- and Siren-class tools as core investigative infrastructure, budgeted and maintained accordingly, not a side pilot project one detective champions until they get reassigned. Build the governance framework before the tool is already load-bearing in active cases, not after the first disclosure challenge forces the question. And keep the human in the position of final authority on attribution and conclusions, always - speed is the goal here, not the automation of judgment.
The cost of not doing this
I wrote about the Ashley Madison breach recently, and the detail from that case I still think about most wasn't the technical failure - it was how long it took, structurally, to get a cybercrime unit formally engaged on a file of that size, and how much of an attacker's head start gets built in before an investigator even opens the case. That problem doesn't go away because better tools exist. It gets worse if the tools exist and the profession doesn't adopt them, because now the gap isn't just structural, it's a capability gap too, and criminals don't wait for a governance committee to finish its charter before they use the technology available to them.
The FBI's own 2025 data shows who actually absorbs that gap: Americans over 60 reported $7.7 billion in losses that year, up 37 percent from 2024 alone. Every dollar recovered depends on speed - following a financial trail before it goes cold, preserving evidence before it's overwritten, opening the file before the version of events you're investigating is already the second or third version of what actually happened. AI-assisted tools, used with the same evidentiary discipline that's governed investigations for decades, are one of the only realistic ways to buy back some of that speed at the scale this problem now operates at.
I don't think this is a close call. The investigators and agencies who come out ahead over the next several years won't be the ones who waited for a perfect framework before touching the technology, and they won't be the ones who deployed it without training their people or building the governance to back it up either. They'll be the ones who did both at once, deliberately, because they understood that cybercrime was never going to slow down and wait for law enforcement to catch up on its own timeline.