By Alexis Anagnostakis
When algorithms start gathering evidence, the right to a fair trial has to catch up.
There is a quiet shift happening in criminal justice systems across Europe, and most of the public has not noticed it yet. Investigators are no longer relying solely on informants, wiretaps, and forensic labs. Increasingly, they are relying on algorithms — systems that flag suspects, decode encrypted communications, analyse crowds through facial recognition, and predict where crime is “likely” to occur next.
For prosecutors, this looks like progress. For the defence, it raises a harder question: can you cross-examine a black box?
The New Evidentiary Landscape
AI-assisted investigation now touches nearly every stage of a criminal case. Predictive policing tools direct resources toward certain neighbourhoods before any crime has occurred. Facial and gait recognition systems identify individuals from CCTV footage with a confidence score that juries — and sometimes judges — mistake for certainty. Mass-decryption operations, most notoriously EncroChat and Sky ECC, have produced millions of intercepted messages processed and filtered by automated systems long before a human investigator ever reads them. Machine-learning classifiers now triage digital evidence, deciding which of thousands of documents or images are “relevant” enough for a case file.
Each of these tools promises efficiency. Each of them also inserts a layer of automated judgment between the citizen and the state — a layer that, unlike a human witness, cannot be asked why it reached its conclusion.
Three Structural Risks for the Defence
1. Opacity dressed as objectivity. Algorithmic tools are frequently presented in court as neutral and scientific, when in fact they encode the assumptions, training data, and error rates of their designers. A confidence score of “87%” sounds precise; it rarely comes with an explanation the defence can actually test. Without access to the underlying model, training data, or validation studies, the defence is asked to accept a conclusion it cannot meaningfully interrogate.
2. Disclosure gaps. Many AI investigative tools are proprietary, developed by private vendors under contracts that treat the underlying methodology as a trade secret. This creates direct friction with the defence’s right to disclosure of material that could undermine the prosecution case or assist the accused. If the defence cannot access the tool’s logic, it cannot identify the errors, biases, or misapplications that might be buried inside it.
3. The illusion of corroboration. Perhaps the subtlest risk is psychological rather than technical. When an algorithm and a human investigator reach the same conclusion, that alignment is often treated as independent corroboration — even though the human may have been influenced, consciously or not, by the machine’s output in the first place. Automation bias does not announce itself; it simply narrows the range of hypotheses an investigator is willing to consider.
What the Case Law Is Starting to Say
The European Court of Human Rights has begun addressing these tensions, most significantly in Yalçınkaya v. Türkiye, where the Grand Chamber scrutinised the use of an encrypted messaging application’s data as the near-exclusive basis for a criminal conviction. The judgment is a warning shot: when a single, technically complex data source becomes decisive, courts must ensure the accused had a genuine and effective opportunity to challenge both the authenticity of that data and the inferences drawn from it. Mere access to a printout is not the same as a meaningful opportunity to contest.
The EncroChat and Sky ECC litigation across multiple jurisdictions has raised parallel questions: how was the data intercepted, decrypted, and filtered; what happened to the material that was excluded before it ever reached the case file; and can a domestic court really assess the reliability of a foreign intelligence-derived process it was never shown in full. These are not abstract concerns — they go to the heart of equality of arms.
What “Guarantees” Should Look Like
If AI is going to be part of criminal investigation, the guarantees have to be built in from the start, not bolted on after conviction. A defence-informed framework should include:
- Explainability as a disclosure obligation. If a tool contributed to identifying, charging, or convicting a person, the methodology, error rates, and known limitations should be disclosable — not shielded as commercial confidentiality.
- Independent technical review. The defence must have realistic access to independent experts capable of auditing the tool, not just the vendor’s own validation report.
- Human decision-making preserved. Automated output should inform, not substitute for, human judgment at the charging and evidentiary stages, with a documented record of how it was weighed.
- Proportionality and necessity testing, akin to that already required for other intrusive investigative measures, applied specifically to predictive and biometric tools.
- A meaningful right to contest, not merely to be informed — the distinction Yalçınkaya draws so sharply.
A Discipline, Not a Panic
None of this is an argument against technology in criminal justice. Properly constrained, AI tools can reduce the burden of genuinely voluminous digital evidence and even work in the defence’s favour — surfacing exculpatory material that a human review might have missed under time pressure. The point is not resistance to the machine; it is discipline in how it is admitted, explained, and challenged.
Defence lawyers have spent decades learning to cross-examine fallible human witnesses — memory, bias, motive, perception. The next decade of practice will require the same rigour applied to a witness that never sleeps, never doubts itself, and cannot be asked to explain what it actually saw.
What safeguards would you want built into an AI investigative tool before it could be used against you?
