There Is No One to Cross-Examine
The mechanics of the Derbyshire case are, by now, familiar enough to serve as outline. A police officer is under investigation - for perverting the course of justice - over the alleged use of AI to create evidential material in a number of criminal cases. The officer has been removed from frontline duty. The cases are under review. We are not told how many; we are told "a number," which is the phrase investigators reach for when the count is large enough to be embarrassing but small enough, they hope, that specifics can wait. It is believed to be the first case of its kind in the UK criminal justice system, which is a polite way of saying it is the first one anyone caught.
The officer will face consequences, of some kind, under existing law. Perverting the course of justice is a crime; so is fabricating evidence. They are, in fact, very old crimes - among the oldest, because the oldest courts worked out early that without some mechanism for punishing liars, proceedings would be brief and arbitrary and decided largely by who was louder. Perjury law, evidence statutes, disclosure obligations: these exist precisely because someone, somewhere, will lie about what happened, and we need formal ways to punish them when they do. The entire edifice is a monument to the assumption that the liar is a person.
What we do not have - what no legal system yet has - is a formal mechanism for the case where the evidence fabricator is a process.
The Assumption Evidence Law Embeds
Every rule of evidence is built on a silent premise: that evidence has a human origin. Witness testimony comes from a person who perceived something, formed a memory, and recounts it under oath, with criminal penalties for deviation. Documentary evidence was created by someone, signed by someone, received by someone, and can be traced through a chain of custody that ends at a human hand. Expert evidence comes from an expert - a human expert - whose credentials can be challenged, whose methodology can be cross-examined, whose conflicts of interest can be exposed.
When evidence law worries about fabrication, it worries about intentional fabrication - someone who chooses to lie. This is why perjury requires mens rea: the state must prove not just that the testimony was false, but that the witness knew it was false and said it anyway. Intent is the pivot. Without intent, you have confusion, mistake, memory error - not perjury.
The AI system in Derbyshire did not intend anything. It generated. It produced an output that, in the officer's hands, became evidence. The officer may well have intended to fabricate; that is what the investigation is presumably determining. But the AI itself had no intent, because intent requires a subject, and text generation models do not have subjects. They have parameters.
This creates an immediate and unresolved problem if - when - the next case involves not a corrupt officer feeding AI output into a file, but an AI system that is authorized to produce reports directly.
Policing already uses automated systems for risk assessment, facial recognition, predictive routing, report drafting. The automation is increasing. At some point, the question "who authored this?" will have no clean answer, because the answer will be: a system that was authorized to produce it, with no individual operator who read it before submission.
At that point, perjury law has nothing to say. There is no one to swear. There is no one to cross-examine. There is a process, a log file, and a defendant whose liberty depends on both.
The High-Risk Gap
The EU AI Act classifies AI systems used in criminal justice - for risk assessment, evidence analysis, predictive policing - as high-risk. High-risk systems require conformity assessments, transparency obligations, human oversight, technical documentation. They must be registered. Their outputs must be explainable. Decisions based on their outputs must be subject to review.
All of this is correct. All of it applies, in theory, to the infrastructure that might otherwise have done what the Derbyshire officer did manually. The AI Act would not have prevented what happened in Derbyshire — because a corrupt officer can misuse any tool, compliant or not. But it would, in principle, create a framework within which the AI-generated report exists in a documented, traceable chain: what was the system, what was its input, what was its output, who authorized its use, when.
The problem is that the UK left the EU.
The high-risk provisions of the AI Act do not apply in Derbyshire. The UK's approach to AI governance remains, as of 2026, a principles-based framework without binding enforcement infrastructure for specific use cases. The police forces that are adopting AI tools are doing so under a patchwork of guidance documents, procurement standards, and institutional policies that vary by constabulary.
The gap between "AI system producing content that enters criminal proceedings" and "any legally binding obligation about that system's traceability" is therefore, in the UK, not small. It is currently the size of whatever a chief constable decides it should be.
The Clause that would close this gap has not been written yet. The Clause, sensing an opportunity in any space where accountability is optional and discretion is wide, is in no particular hurry to write it.
The Case This Will Become
Here is the thing that this case is, and the thing it is about to become.
Right now, it is a case about a corrupt officer. The AI was a tool; the officer was the agent; the intent was the officer's. Existing law can, in principle, handle this - the same way existing law handles an officer who plants physical evidence. It is the same crime with a new instrument.
The case it is about to become is different. It will not involve a corrupt officer. It will involve an authorized system that generated an authorized report that contained an error - or a hallucination, which is the neutral word for a confident falsehood produced by a process with no capacity for shame. And the defendant, or their lawyer, will ask: who is responsible for this?
The answer, under current law, is approximately: the deploying institution, probably, in some general negligence sense, subject to specific facts, to be determined. Which is not an answer that a person whose liberty depends on it will find satisfying. It is the same missing link that appears whenever a system acts and no identifiable human is found holding the other end of the chain - the problem The Principal Who Wasn't There traces in a commercial setting. Here the stakes are not a sabotaged research project. They are a custodial sentence.
The Court That Couldn't Answer the Question documented the difficulty courts have with questions that the law was not built to ask. Criminal evidence law was not built to ask who is responsible when the witness is a model. It was built to ask who is responsible when the witness lies.
Those are the same question only if you believe that what a language model does when it generates false content is the same as what a person does when they choose to lie. They are not the same. One is a moral act. The other is a statistical one.
The courts will have to decide which framework applies. They will not find this easy. They will also not find, in the existing literature, much help - because the legal scholars who built evidence law were thinking about fallible humans, not fallible processes. The fallible humans were the entire problem they were trying to solve.
Evidence law has, over centuries, developed remarkably sophisticated tools for testing whether a human witness is telling the truth: oath, cross-examination, prior inconsistent statements, motive, corroboration requirements, hearsay rules, expert challenge.
It has no equivalent tools for testing whether a language model was hallucinating when it generated the document that became the prosecution's exhibit 14. It does not have these tools because, until very recently, nobody needed them.
Somebody will need them soon. The Derbyshire case, when the history of AI in criminal justice is eventually written, will occupy a footnote: the last time a corrupt human was the only problem in the room.