Article page checkbox is not checked in page info.
Artificial intelligence and crime
Artificial intelligence and crime
Martina Prpic, Members' Research Service
Summary
Artificial intelligence (AI) has transformed a wide range of activities, including crime and law enforcement. Its development presents both threats and opportunities. AI has lowered barriers to some forms of crime and expanded the capabilities available to offenders by increasing the sophistication and reach of their activities. In some cases, it has also enabled criminals to distance themselves from their criminal acts, making it more difficult to link them to those crimes and prosecute them. Some AI systems can produce harmful outcomes without direct human input, raising questions about criminal responsibility.
Like criminals, law enforcement agencies have started using AI to improve their efficiency, but unlike criminals, they must use it in accordance with the law and ethical principles. For instance, law enforcement agencies must respect the rights and privacy of individuals and ensure that their use of AI is fair and non-discriminatory. One of the biggest challenges in using AI in law enforcement is identifying, assessing and mitigating potential bias in AI systems and their underlying data. Human input and oversight therefore remain indispensable. Other challenges include keeping pace with technological changes and training practitioners to use the new technology responsibly. This is not only important for protecting the rights of individuals but also to preserve the integrity and credibility of law enforcement procedures. The EU is at the forefront of legislation on AI, one such example being the 2024 AI Act that set standards on how to regulate this complex and constantly evolving phenomenon. The European Parliament has been a strong advocate for the responsible and cautious use of AI.
Introduction
Artificial intelligence (AI) has had a profound impact on a wide range of economic and social activities in the relatively short time it has existed. It has changed how people perform daily activities, such as shopping or driving, and how children do their homework, mostly by enabling certain tasks to be completed faster and more efficiently than humans ever could on their own. It has also affected key areas of state activity, such as defence and security.
However, AI has also changed how criminals commit crimes, enabling certain criminal activities to be conducted more efficiently, on a larger scale or with greater anonymity. This gives criminals and criminal networks new, rapidly developing capabilities to do harm. Some AI systems are autonomous, making it easy for criminals to conceal their identity and better evade detection.
Law enforcement agencies have also recognised the value of using AI to combat crime and have used it to improve their efficiency. However, further action and closer collaboration between policymakers, law enforcement agencies and the technology sector are needed to address the growing threats and harness the opportunities presented by AI. For law enforcement, it is also crucial that AI is used responsibly, most notably to ensure fair treatment and respect for the fundamental rights of individuals, as well as the integrity of law enforcement procedures. This creates additional operational challenges for law enforcement, as criminals can disregard the same rules and take full advantage of the possibilities offered by AI.
The European Union (EU) is at the forefront of recognising the potential of AI both to benefit society and, in particular, to cause harm. With this dual potential in mind, it has been developing a regulatory framework and setting standards for responsible use, in particular through the AI Act, adopted in 2024.
Use of AI in committing crimes
Reports show that criminals use AI in increasingly diverse ways and with increasing frequency. While criminals use generative AI to make their activities more convincing and sophisticated, for example, by crafting realistic messages in multiple languages, agentic AI – systems capable of autonomous operational planning and execution – can enable offenders to distance themselves from illicit operations and significantly reduce the likelihood of getting apprehended by law enforcement.
Several interconnected and overlapping areas can be identified where AI plays a significant role. Some sources propose a typology of the malicious use and abuse of AI based on an analysis of academic literature, reports and other documents. This typology has two levels. The first distinguishes between the direct and indirect involvement of AI, i.e. whether AI is used directly to perpetrate crimes or is used indirectly, by being targeted by attacks or by simply producing unintended, potentially criminal, outcomes. The second level identifies specific types of acts within these categories. A slightly adapted version of this typology is presented below.
1) Malicious use of AI: AI-enabled and AI-enhanced attacks
Social engineering, phishing and fraud
Social engineering uses deception techniques to manipulate people into sharing sensitive or personal information, which can then be used for fraudulent purposes. This can take the form of deception and phishing, in which hackers use social bots to deceive people into complying with their requests, or 'big nudging' and manipulation, in which large numbers of bots are used to malicious ends, for example, to influence public opinion or the outcome of elections. Although deception has existed since the early days of the internet, AI has made these techniques more sophisticated and accessible to a greater number of perpetrators. AI can be used to craft messages in multiple languages, which can then be sent globally. It can also help perpetrators target recipients more effectively.
Examples of this abuse include online fraud schemes (OFS), the fastest-growing area of organised crime. The most common forms are investment fraud, business email compromise, romance fraud, tech support fraud and fraud against payment systems. AI –both agentic and generative – is used extensively in this area, especially to assist with coding and the generation of conversation scripts, while voice chatbots are deployed to pre-screen and select potential victims for human operators. A widely reported example is the 2025 case of a French woman who lost €830 000 after being deceived into believing she was corresponding with Brad Pitt. The criminals used AI to deceive the victim, for example by creating a fake news report claiming that Brad Pitt was in an exclusive relationship with her.
Deepfakes, misinformation and fake news
AI plays a dual role in the information ecosystem. While AI can support investigative journalism, cyber-defence and fact-checking, and help electoral commissions to counter misinformation, it can also be misused. AI systems can fuel the creation and spread of falsehoods, which, if convincing and/or strategically timed, can pose a risk to society and democratic processes, for example, during pandemics or elections. An analysis of studies on AI and disinformation has identified several key thematic areas, including political disinformation and propaganda (the use of false or misleading information to influence public opinion and manipulate political processes); scientific disinformation (the use of AI to create research articles, abstracts and other academic texts to mislead the academic community and the public); and deepfakes (realistic AI-generated or manipulated video and audio content with potentially negative consequences for public trust). An example is the 2022 deepfake video purporting to show Volodymr Zelenskyy declaring peace and calling on Ukrainians to lay down their arms. Deepfakes can have both direct and indirect impacts on politics and political processes. One indirect impact is the 'liar's dividend', whereby individuals exploit the existence of deepfakes to dismiss authentic evidence as fabricated, thereby eroding trust in legitimate sources.
AI can also be used for the production of synthetic child sexual abuse material (CSAM). AI has given offenders more opportunities to groom their victims and to produce CSAM, creating additional challenges for analysing of imagery and identifying offenders. This material can be fully synthetic, meaning that images are generated entirely from text prompts, or partially synthetic, created by modifying existing images of children or adults, who can be made to look younger using AI.
Deepfake pornography poses a big problem, as it makes up 98 % of all deepfake videos online, with 99 % of them depicting women, according to a 2023 report.
AI-generated malware and hacking for cyber-attacks
Cyber-attacks can be facilitated by AI, including through the automation of repetitive tasks, such as password cracking and malware generation. Malware, or malicious software, can infiltrate or gain control over a computer system or a mobile device and steal or damage valuable data. Although malware threats have existed for decades, AI can now be used to create software that is more effective and harder to detect.
An example is EvilAI, whose operators disguised their malware as legitimate applications (productivity or AI-enhanced tools) to bypass security measures, steal credentials and compromise organisations worldwide, predominantly in manufacturing, government/public services and healthcare.
Other hacking methods that AI can support include phishing (tricking users into giving their credentials or clicking on malicious links), exploiting software vulnerabilities (taking advantage of systems using outdated software with known flaws), credential stuffing (using leaked username-password combinations from past breaches to access other systems), man-in-the-middle attacks (intercepting communications between two parties to steal or manipulate data, for example, on unsecured Wi-Fi networks or through misconfigured VPNs) and supply chain attacks (targeting trusted third-party software or vendors as a backdoor into otherwise secure systems). AI can also help automate attacks in which hackers use prebuilt kits, open-source tools and subscription-based attack platforms available on the dark web.
Physical facilitation
Criminals can also use AI to facilitate crimes in the physical world, not just in cyberspace. Examples include creating fake official documents, such as passports and driving licences, designing toxic molecules or drugs, producing designs for 3D printed guns, planning criminal logistics and surveillance, etc.
2) Malicious acts stemming from vulnerabilities of AI models
Integrity attacks
Integrity attacks occur when attackers manipulate AI models or the underlying data to compromise the reliability of their outputs. For example, to achieve integrity attacks, threat actors can use 'adversarial examples': carefully crafted input data designed to mislead machine learning models – AI models that learn patterns from data rather than following only explicitly coded rules – into producing incorrect or biased predictions. Even small changes to input data, imperceptible to the human eye, can substantially alter a model's predictions, owing to the butterfly effect.
Unintended outcomes of the use of AI
Unintended outcomes occur when models used to train AI systems present results that differ from those expected by their developers. They can, for example, unintentionally disclose private or sensitive data that were used to train them, so it is important to ensure data privacy at that stage.
Some academic literature uses the term 'hard AI crime' to describe situations in which an autonomous AI system engages conduct corresponding to the elements of an offence without an identifiable natural person satisfying the requirements for criminal liability. Such scenarios raise questions concerning attribution, causation and criminal responsibility. In these scenarios, the AI system operates fully autonomously in performing the task and is responsible for all decision-making, and any humans involved did not intend the conduct in question. This presents a challenge for criminal responsibility because there may be no identifiable person who can be held criminally liable, and the discussion may therefore need to shift from blame to deterrence.
Algorithmic trading/stock market manipulation
Algorithmic trading can involve decisions that are difficult for humans to follow and can contribute to market instability and increase the risk of crashes. Harm may arise not only from malicious actors but also from technological accidents or insufficient testing. An example of deliberate market manipulation is the case of Navinder Sarao, who caused a 'flash crash' in May 2010, when financial markets briefly plummeted in value. He used specially adapted software to trade on the Chicago Mercantile Exchange and exploited the vulnerabilities of software used by high-frequency traders to move the market in one direction (these trading systems could all be manipulated by the same software).
Privacy attacks
Membership inference attacks are a type of privacy attack in which a malicious actor seeks to detect and reconstruct the data samples that may have been used to train a machine learning model. These attacks can compromise privacy, for example, by revealing that an individual's medical or biometric data were included in a sensitive medical dataset, and could breach data protection legislation, such as the General Data Protection Regulation.
Use of AI in policing
AI has the potential to significantly transform policing, but it is important that it be used ethically and responsibly. Its uses and advantages are numerous, from processing vast amounts of data to facilitating international collaboration among law enforcement agencies. Successful examples of its use include the identification of vulnerable and exploited children and support for the work of police emergency call centres. Furthermore, integrating AI in their daily work can help law enforcement agencies to keep pace with the rapidly evolving criminal landscape.
However, efforts to realise the potential of AI for improving policing must be accompanied by appropriate safeguards and restrictions to address the risks associated with its use, especially in the context of law enforcement. First and foremost, the use of AI must be in line with existing laws and regulations. In the EU, these are primarily the EU AI Act, the General Data Protection Regulation (GDPR) and the Law Enforcement Directive (LED). Evidence gathered using or with the help of AI must withstand scrutiny and meet the requirements for admissibility in court proceedings. Its collection and use must respect the right to a fair trial.
Where competent authorities process personal data for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, the LED generally provides the applicable data-protection framework; the GDPR applies to processing falling outside the material scope of the LED where that processing falls within the GDPR's scope. These instruments therefore complement the AI Act: while the AI Act lays down requirements and, in certain cases, prohibitions concerning AI systems and their use, the LED or GDPR, as applicable, governs the processing of personal data involved.
The AI Act classifies certain AI systems intended for specified law-enforcement purposes as high-risk and subjects them to specific requirements aimed at addressing risks to fundamental rights, including risks of discriminatory outcomes. The use of AI in law enforcement needs to be fair, unbiased and non-discriminatory, and this takes an effort to achieve because data that are used to train AI systems are mostly affected by some type of bias. For example, data feeding the algorithms may reflect racial and historical prejudices, which may result in incorrect identifications and bias against certain groups.
Bias in AI and implications for law enforcement
Bias in AI is a significant problem that needs to be addressed, as AI use, especially in law enforcement, must be fair. Biases embedded in the design, development and deployment of AI systems can perpetuate discrimination and reinforce societal inequalities, as well as call into question the integrity of law enforcement operations. The 2025 Europol report on the issue tackles the importance of defining and measuring fairness in AI systems, as well as the challenges of achieving it in practice. Compliance with and consistent application of legal safeguards are crucial for mitigating bias and respecting fundamental rights. The report recommends that law enforcement agencies take several measures to mitigate bias:
-
documentation and transparency, which ensure traceability and accountability and aid in identifying where biases may occur;
-
holistic evaluation framework, which would require actively engaging a diverse group of stakeholders with varied expertise to ensure a broader range of perspectives;
-
regular training and awareness-raising, which would emphasise the value of human evaluation in reviewing AI-generated outputs and interpreting them responsibly;
-
rigorous pre-deployment testing, which should be conducted for all available datasets;
-
case-by-case analysis and technical training, as determining what is fair often depends on the context, which makes fairness metrics difficult to generalise;
-
continuous bias assessment and mitigation;
-
human involvement (human-in-the-loop) and evaluation, which emphasise the importance of human input throughout the process, including decisions on how to act on the information gathered by the AI system;
-
consideration of trade-offs between fairness and model quality, as excluding sensitive attributes or applying fairness constraints can reduce a model's predictive accuracy;
-
contextual and statistical consistency, both of which are required for AI models to be considered properly evaluated;
-
standardisation of procedures, which ensures consistent practices in bias assessment.
The report concludes that the responsible integration of AI technologies needs to be accompanied by risk management systems, transparency requirements and human oversight protocols.
Types of uses of AI in policing1
Data analytics
AI enables law enforcement agencies to analyse vast amounts of information quickly and make informed decisions on that basis. Traditional analytics can only point out the occurrence of a crime spike, but AI can potentially identify causes, correlations between external and unrelated events and other patterns. It can also be used, for example, to detect patterns in criminal activity, identify correlations between different data types and forecast resource requirements based on past trends. Predictive policing can thus help agencies deploy personnel most efficiently. Evidence shows that some deployments have reduced crime while others have failed to outperform conventional methods.
Digital forensics
Digital forensics is used to investigate the digital footprints of criminals. AI is also useful here because it provides an advanced capability to go through vast data repositories and automate processes that would otherwise take too much time if performed solely by a human. For example, AI can help distinguish regular network traffic from potential threats.
Computer vision and biometrics
Computer vision and biometrics have proven to be extremely useful in policing, both in crime prevention and investigation. AI can help the police to swiftly identify criminals and protect the identities of individuals not relevant to an investigation.
Legislative framework
Legislation on AI and crime in the EU is embedded in the wider framework of legislation on AI, cybersecurity, digital services, data protection, law enforcement and crime. The AI Act (Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence) establishes requirements and restrictions to address the risks associated with AI, including specific obligations for high-risk and AI systems. The legislation regulates AI systems and AI models based on their risks and capabilities.
The AI Act follows a four-tier risk-based approach, commonly described in terms of unacceptable, high, limited and minimal/no risk, based on the severity of the consequences. Article 5 originally prohibited eight categories of practices (a ninth prohibition has been added as part of the 2026 amendment to the act; see details further down), subject to specified conditions and exceptions. These original eight prohibitions, already in application, as follows:
-
Harmful AI-based manipulation and deception
-
Harmful AI-based exploitation of vulnerabilities
-
Social scoring
-
Individual criminal offence risk assessment or prediction based solely on profiling or assessment of personality traits and characteristics
-
Untargeted scraping of the internet or CCTV material to create or expand facial recognition databases
-
Emotion recognition in workplaces and education institutions
-
Biometric categorisation to deduce certain protected characteristics
-
Real-time remote biometric identification for law enforcement purposes in publicly accessible spaces (except if necessary for the targeted search of specific victims, the prevention of specific threats including terrorist attacks, or the search of suspects of specific offences).
The legal basis for these prohibitions are Article 16 TFEU (data protection), for the specific rules restricting the use of AI systems involving the processing of personal data for remote biometric identification, risk assessments of natural persons and biometric categorisation systems, all for law enforcement purposes, and Article 114 TFEU (internal market) for all other prohibitions under Article 5.
High-risk AI systems can pose serious risks to health, safety or fundamental rights and are subject to strict obligations, including adequate risk assessments and mitigation systems, high quality datasets feeding the system to minimise the risk of discrimination, and appropriate human oversight measures. High-risk AI systems must undergo external and independent assessments before being placed on the EU market or put into service. Relevant cases of high-risk use include AI systems used for remote biometric identification, emotion recognition and biometric categorisation, where their use is permitted under the act; AI use cases in law enforcement that may interfere with people's fundamental rights; and AI solutions used in the administration of justice and democratic processes.
The AI Act entered into force on 1 August 2024 and became generally applicable on 2 August 2026. However, the rules for systems used in certain high-risk areas (biometrics, critical infrastructure, education, employment, migration, asylum and border control) will apply from 2 December 2027, and the rules for high-risk systems integrated into regulated products have an extended transition period until 2 August 2028 following the political agreement on the Commission proposal to simplify the AI Act, known as the AI Omnibus.
The Commission proposal to simplify the AI Act was presented on 19 November 2025 as part of the digital package on simplification, and political agreement was reached on 7 May 2026. The amending AI Omnibus Regulation entered into force on 27 July 2026. One of its most notable amendments was the introduction of an explicit prohibition of AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material, such as AI 'nudification' apps. This prohibition (the ninth in the list), will apply from December 2026.
However, the AI Act does not apply to areas outside the scope of EU law and specifically excludes from its scope AI systems used or deployed for military, defence or national security purposes. The objective of protecting national security, as described by the Court of Justice of the EU (CJEU), corresponds to 'the primary interest in protecting the essential functions of the State and the fundamental interests of society and encompasses the prevention and punishment of activities capable of seriously destabilising the fundamental constitutional, political, economic or social structures of a country and, in particular, of directly threatening society, the population of the State itself, such as terrorist activities.'2
When police and other law enforcement authorities are tasked with the prevention, detection, investigation and prosecution of criminal offences or the execution of criminal penalties, their use of AI systems falls within the scope of the AI Act. The use of AI systems by Europol and other EU security agencies for these purposes falls within the scope of the AI Act as well.
Since the AI Act does not apply to public authorities in a third country or international organisations, special care should be taken in judicial and law enforcement cooperation with them when they use AI systems. They must provide adequate safeguards for the protection of the fundamental rights and freedoms of individuals. Recipient national authorities and Union institutions, bodies, offices and agencies making use of such AI outputs are responsible for ensuring that their use complies with EU law.
The AI Act also complements other relevant EU legislation. For example, the AI Act and its prohibitions are compatible with the Digital Services Act, which 'prohibits dark patterns within the user interface to ensure that providers of online platforms do not mislead or coerce users into actions that may not align with their genuine intentions'.3 The Digital Services Act obliges providers of online platforms to ensure transparency in advertising and in the use of recommender systems and to protect minors. The AI Act also complements the Audiovisual Media Services Directive by prohibiting certain harmful AI-driven advertising and other manipulative and exploitative practices in the media sector.
Criminal law is also compatible with the AI Act. The prohibitions in Article 5 aim to prevent 'harmful behaviour that may constitute or lead to criminal offences, such as fraud, forgery, scams, coercion, or the generation and dissemination of illegal content, such as terrorist content, child sexual abuse material, hate speech and sexually explicit deepfakes'.4 Beyond legislation, in July 2026, the Commission also presented an EU plan to address the risks and opportunities of advanced AI for cybersecurity, which will bring together EU Member States, industry and EU-level organisations to strengthen cybersecurity across the EU digital landscape and address vulnerabilities associated with advanced AI.
While the GDPR is based on Article 16 TFEU, the AI Act has a dual legal basis in Articles 16 and 114 TFEU. The two instruments are complementary: the AI Act explicitly recognises the continued application of EU data-protection law, including the GDPR, to the processing of personal data in connection with AI systems. The AI Act explicitly recognises its link to the GDPR, but there are also challenges in implementing the provisions of both instruments, as there is a risk that data protection could be undermined if AI systems are not adequately regulated. On the other hand, overly stringent regulation might deter innovation and hinder the development of beneficial AI technologies.
The LED obliges Member States to ensure that personal data are processed lawfully and fairly and in a manner that ensures their appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. It prohibits decisions based solely on automated processing, including profiling, which produce an adverse legal effect concerning the data subject or significantly affect him or her, unless authorised by Union or Member State law to which the controller is subject and which provides appropriate safeguards for the rights and freedoms of the data subject, including at least the right to obtain human intervention on the part of the controller. Profiling that results in discrimination against natural persons on the basis of special categories of personal data is also prohibited.
European Parliament position on AI
Parliament has repeatedly addressed the potential benefits and risks associated with AI. The resolution of October 2020 on the ethical aspects of AI, robotics and related technologies, which provided recommendations to the Commission during the preparation of the AI Act, emphasised that the development, deployment and use of high-risk artificial intelligence, robotics and related technologies should always be ethically guided and designed to respect and allow for human agency and democratic oversight. It also emphasised the importance of comprehensive risk assessment, transparency, accountability, non-bias and non-discrimination, social responsibility and gender balance. It specifically referred to law enforcement in the context of the need for the utmost precaution when using technologies that automate decisions otherwise taken by public authorities. In general, the resolution stresses that special care and scrutiny should be applied to the use of AI in law enforcement and border control, and warns that deploying AI in mass surveillance, predictive policing and breaches of due process rights can result in grave misuse.
In the negotiations on the AI Act, Parliament took an even more cautious approach than the Commission had proposed, by demanding a ban on the use of biometric identification systems in the EU for both real-time and ex-post use, all biometric categorisation systems using sensitive characteristics, predictive policing systems, emotion recognition systems in law enforcement, border management, workplaces and educational institutions, and AI systems using indiscriminate scraping of biometric data from social media or CCTV footage to create facial recognition databases. In its report setting out its position for the negotiations on the Digital Omnibus on AI, Parliament proposed a targeted ban on AI systems that generate sexual and intimate content without consent, which ended up in the final agreement, along with a prohibition on AI systems generating child sexual abuse material.
Main references
- Negreiro, M., AI image generation and the spread of online child sexual abuse material, EPRS, European Parliament, May 2026.
- Niestadt, M., Parliament's emerging position on the Digital Omnibus on AI, EPRS, European Parliament, March 2026.
- Marcelin, T., Enforcement of the AI Act, EPRS, European Parliament, March 2026.
- Niestadt, M., Digital Omnibus on AI, EPRS, European Parliament, June 2026.
- Negreiro, M., Children and deepfakes, EPRS, European Parliament, 2025.
- Clapp, S., Defence and artificial intelligence, EPRS, European Parliament, 2025.
- De Luca, S., Algorithmic discrimination under the AI Act and the GDPR, EPRS, European Parliament, 2025.
- Murphy, C., Understanding cybercrime, EPRS, European Parliament, 2024.
- Fuster, G., Artificial Intelligence and Law Enforcement - Impact on Fundamental Rights, IPOL, European Parliament, 2020.
Endnotes
Classification
Policy areas: Area of Freedom, Security and Justice | Digital
Committees: Civil Liberties, Justice and Home Affairs (LIBE)
Statement on the use of AI
Any AI-generated content in this text has been reviewed by the author.
Disclaimer
This document is prepared for, and addressed to, the Members and staff of the European Parliament as background material to assist them in their parliamentary work. The content of the document is the sole responsibility of its author(s) and any opinions expressed herein should not be taken to represent an official position of the Parliament.
Copyright
© European Union.
The reuse of this document is authorised under a Creative Commons Attribution 4.0 International (CC-BY 4.0) licence.
https://creativecommons.org/licenses/by/4.0/deed.en
To use or reproduce elements that are not owned by the European Union, permission may need to be sought directly from the respective rightsholders.