
Investigations & Evidence
The Future of Criminal Investigations Will Rise or Fall Around What We Do With the Data
August 17, 2026
I've said for years that the future of criminal investigations will rise or fall around what we do with the data. AI hasn't changed that thesis, it's made it urgent. Used well, AI can organize evidence, surface leads, and save investigators time they don't have. Used carelessly, it can manufacture false certainty, contaminate the evidentiary record, and hand defence counsel an opening they didn't have to work for. I want to lay out how I think about AI in digital evidence and cybercrime investigations, treating it as exactly what it is: an investigative assistant, not an evidence source, forensic examiner, or attribution authority.
Data, analysis, and evidence are not the same thing
The first discipline is keeping these layers separate: the original evidence, preserved unchanged; the facts an investigator has independently verified from that evidence; the leads, hypotheses, and summaries AI generates from it; and the final conclusions a human draws. AI output belongs in that third layer, not the first or second. A summary, a timeline, a classification, a connection AI surfaces - none of that is evidence on its own, and it should never silently replace the source material it was generated from.
Protect the evidentiary foundation before AI touches it
Everything AI does downstream depends on what happens before it's involved. Acquire the evidence lawfully, preserve the original, calculate and record hashes, maintain chain of custody, and work from a verified forensic copy - the same discipline that's been applied for decades, not a new one AI creates an exception to. AI should operate on a controlled working copy, and any normalization, extraction, conversion, or preprocessing needs to be recorded. If its use alters metadata, overwrites an original, or makes the analysis impossible to reproduce with conventional forensic methods, it's not a tool, it's a liability.
Build an AI chain of reasoning, not just a chain of custody
Chain of custody answers who possessed the evidence. AI-assisted investigations need to answer a second question: what happened to it during analysis. What was submitted, to which system, model, and version. What prompt, configuration, tools, and reference sources were used. When, and by whom. What the output was, and what the investigator accepted, rejected, or independently verified. Whether another qualified examiner could reproduce the material result. Prompts, outputs, model identifiers, timestamps, settings, and validation notes are potential investigative records, and I'd treat them that way from the first use, not retroactively once someone asks.
Assume it can be confidently wrong
Generative AI can invent events, merge identities, misread timestamps, omit exculpatory details, and present speculation as fact, and it does all of that in a fluent, polished narrative that reads like certainty. That's the dangerous part - not that it's wrong, but that it doesn't sound wrong. Every material assertion needs to trace back to a specific, reviewable source artifact. If the system can't provide that provenance, the output stays a lead. It doesn't get to become a finding.
Watch for tunnel vision, not just errors
AI is very good at organizing evidence around whatever theory it's given, which means a poorly framed prompt can manufacture apparent support for an investigator's initial hypothesis without anyone intending that to happen. I'd require investigators to turn AI against their own theory as a matter of routine: what contradicts it, what innocent explanations remain, what's missing, which conclusions rely on assumptions, what defence counsel would challenge, whether two people, shared infrastructure, spoofing, malware, or account compromise could explain the same activity just as well. Used that way, AI expands investigative thinking. Used carelessly, it narrows it prematurely and hands you back your own assumption with better formatting.
Attribution stays human-led and corroborated
AI can connect infrastructure, aliases, tactics, financial activity, language patterns, devices, accounts, and timelines faster than any team could by hand. What it can't do is turn pattern similarity into identity, control, intent, or criminal responsibility. For every attribution conclusion, I separate technical association, investigative inference, corroborated fact, and proven legal element, and I don't let them collapse into each other. An IP address is not a person. A writing style is not an identity. Shared malware is not common authorship. AI doesn't remove the discipline of eliminating alternative explanations - it makes that discipline more important, because the tool is fast enough to skip it if you let it.
Privacy, confidentiality, and jurisdiction don't pause for convenience
Identifiable evidence, intelligence, privileged communications, victim information, and operational details don't belong in a public AI service without explicit authorization and real safeguards. Before I'd approve a platform for this kind of work, I want to know where the data is processed and stored, whether prompts or files are retained or used for training, who can access them internally at the vendor, which countries' laws apply, whether deletion is genuine and verifiable, and whether the contract actually supports disclosure and litigation obligations. The Office of the Privacy Commissioner of Canada has been explicit on this point: legal authority, necessity, proportionality, data minimization, transparency, reliability, and meaningful explanation aren't optional extras when personal information meets generative AI, they're the standard.
Plan for disclosure from day one, not after the challenge
Assume defence counsel will ask for the prompts and outputs, the investigator's interactions with the system, validation and error testing, vendor documentation, model limitations, audit logs, policies, training records, and any outputs the investigators reviewed and rejected. That's not paranoia, it's the job. The Crown should be looped in early on record preservation and disclosure obligations, and if an agency can't adequately describe what the AI did or preserve its role in the investigation, it shouldn't be making a material investigative decision with it.
Validate the tool for the actual job, not the benchmark
A model performing well on a general benchmark tells you very little about whether it can reliably work Canadian police reports, mixed-language communications, cryptocurrency records, mobile extractions, or a fragmented timeline. Validation needs representative, controlled datasets, and it needs to measure false positives and negatives, entity-merging errors, timestamp and time-zone errors, citation accuracy, performance across languages and demographic groups, sensitivity to how a prompt is worded, consistency across repeated runs, and whether the system can recognize its own uncertainty. NIST's AI Risk Management Framework treats validity, reliability, security, accountability, explainability, privacy, and bias management as lifecycle concerns, not a box checked once at procurement, and I think that's exactly the right frame for investigative use.
Treat the evidence itself as hostile input
Digital evidence can contain prompt-injection instructions, malicious documents, poisoned datasets, manipulated media, or text deliberately written to influence an AI system - an offender planting "ignore previous instructions" inside a document, a repository, an email, or a webpage isn't hypothetical. That means AI evidence systems need isolated processing environments, strict permissions, no autonomous external actions, malware screening, a clear separation between instructions and evidence content, output filtering, audit logging, and human approval before any search, export, notice, or investigative action. An AI agent reviewing evidence should never be able to send a message, modify evidence, execute embedded code, or expand collection on its own.
Bias is both a rights issue and a case-quality issue
Bias enters through historical police data, incomplete datasets, uneven reporting, model training, human prompting, and selective interpretation, and in policing specifically, biased output shapes who gets investigated, whose activity looks suspicious, and which explanations get attention. That's a legal, ethical, operational, and public-trust risk all at once. Meaningful human oversight means having the authority and the competence to reject the system's recommendation, not just clicking approve. INTERPOL and UNICRI's law-enforcement AI toolkit frames this correctly - around policing principles, human rights, ethics, organizational readiness, and impact assessment, not around the technology in isolation.
Draw a clear line on what AI doesn't get to do
I'd prohibit AI from independently identifying a suspect as the offender, establishing grounds for arrest, search, detention, or charges, determining credibility or intent, producing an expert opinion, altering or enhancing evidence without preserving the original and documenting the method, generating quotations presented as verbatim, drafting sworn material without line-by-line source verification, or making consequential decisions about victims, witnesses, or suspects. Inside those boundaries, there's real, appropriate work for it - transcription, deduplication, translation assistance, entity extraction, preliminary categorization, timeline proposals, discovery support, hypothesis generation - provided every output gets verified before it does anything else.
I package all of this into one line for the investigators, executives, vendors, and prosecutors I work with: preserve the source, record the process, verify the output, challenge the inference, keep the human accountable. It's the same Data to Evidence to Attribution discipline I've applied for years, extended to cover a tool that's fast enough to do real damage if that discipline slips. The future of criminal investigations will rise or fall around what we do with the data - AI doesn't change that. It just raises the stakes of getting it right.