Skip to main content

Peters & Peters

Paint by Numbers, Disclosure by Algorithm

References to paragraphs are references to UK Government’s document Modernising the Criminal Disclosure Regime.

 

In our last piece on the MoJ’s AI Action Plan, we noted a pattern: decisions are reserved for humans, but the data and material those decisions rest on is being handed, ever more readily, to machines. We said transparency would be the thing to watch, and that challenges to AI-parsed decision-making would become increasingly technical. Disclosure is where that prediction gets tested first.

 

This month’s Government response to Jonathan Fisher KC’s Independent Review of Disclosure and Fraud Offences – Part One, Disclosure in the Digital Age – and to the disclosure chapter of Sir Brian Leveson’s Independent Review of the Criminal Courts, sets out a package of changes that will arguably do more to change day-to-day criminal practice than almost anything in the AI Action Plan itself.

 

The headline seems to be that technology, specifically including AI, is now expressly sanctioned to identify relevant material, flag what may meet the disclosure test, and build schedules. More importantly, there will be, for the first time, official approval for material to be identified by the prosecution for both relevance and disclosure without any human review.

 

Problems at scale

 

The GOV.UK press release announcing these reforms – published the same day, 14 July 2026, under the headline “AI to speed up justice under major disclosure reforms”, is worth reading alongside it, not least for the figures it puts on the problem. The current disclosure guidance, it points out, “was introduced in 1996, before iPhones, Google, Facebook or WhatsApp existed”, when a case file was “often contained to a single box”. Now, some investigations run to over 500,000 e-books’ worth of data, and the average fraud case contains more than four million documents.

 

As a firm, we have identified the same trend and grappled with the need to leverage technology to respond to the evolving demands of modern criminal practice, particularly the ever-increasing volume of digital data in investigations and disputes.

 

Old problems, new structures

 

None of this arrives out of nowhere. Government has spent the last two years grappling with strands of the same underlying problem in relative isolation: the MoJ’s AI Action Plan for the courts and tribunals; Leveson’s own review of court modernisation and the Crown Court backlog; a Police Reform White Paper promising a new National Centre for AI in Policing; and a succession of piecemeal digital forensics and technology governance reviews. All hampered by the Government’s well-reported difficulty in obtaining and (particularly) retaining digital skills in the civil service and beyond.

 

The Fisher/Leveson response pulls several of these separate strands together into one structure built specifically around disclosure – technology governance, workforce capability, an ethics protocol, and a cross-system forum that includes the defence and the judiciary from the outset.

 

That, on its own, is a welcome development, and criminal practitioners can recognise the benefit of replacing the patchwork of ad hoc practice and informal guidance around digital disclosure with a single, purpose-built framework – even one light on detail.

 

What’s changed?

 

The Criminal Procedure and Investigations Act 1996 (CPIA) Code of Practice has, until now, been silent on whether technology can stand in for a human reviewing disclosure material line by line. Fisher’s Recommendations 6, 7 and 9 asked the Government to fill that gap: to confirm that a disclosure officer or prosecutor can be “aided by technology” when identifying relevant material and material that may meet the disclosure test, and that metadata schedules can be used alongside descriptive schedules and block listing. The Government has agreed to all three and will amend the Code accordingly.

 

On one level, this is simply catching the law up with current practice, as anyone who has sat through a disclosure review on a six-figure document set will recognise. There is an ever-growing market of providers looking to assist with streamlining document review, from Technology Assisted Review (TAR, machine-learning predictive coding) and Continuous Active Learning (CAL, updating the model used in TAR with ongoing decision-making) to the more recent introduction of generative and agentic AI review.

 

In effect, the mechanics of the criminal disclosure process are catching up to the more flexible civil disclosure regime, in which the use of new technology can be championed and conducted through careful agreement between the parties, given the scale of the cost savings on offer.

 

Indeed, various parts of the criminal justice system have already trialled these technologies in different ways, including routine but data-heavy reviews where principles can be agreed with all parties, such as those assessing the existence of legally privileged material.

 

Fortunately, the Government recognises that the tools alone will not be enough. Having been involved in law enforcement reviews of this kind, we would flag that there are still major practical barriers to overcome. Some of these the Government has clearly turned its mind to, including the need for a workforce with “the skills and training to deploy and operate AI tools competently and in line with legal and professional obligations” (paragraph 14 of the Government’s response). Others it has yet to grapple with in any detail – not least the:

    • tactical considerations that will arise as parties (on both sides) work out how a given tool can be tested, gamed, or overwhelmed by volume; and
    • willingness of law enforcement to engage with defence teams, where there is mistrust coupled with surface-level understanding of new technologies.

 

Criminal defence lawyers and technology

 

Effective defence work has always required a mix of procedural and substantive knowledge. AI-assisted disclosure adds a genuinely new layer on top of that: to test whether a disclosure decision was properly made, a defence practitioner may now need to understand not just the disclosure test and the Code of Practice, but how the tool applying it actually works – what a predictive coding model was trained on, how a large language model was prompted, and where the seams are between what the software flagged and what a human then decided, or whether a human ever decided at all. That is a demanding ask at all levels, from legal aid clients and firms that may not have access to the technology, expertise and/or the funds to source them, to large clients bearing the cost of technical investigation alongside legal costs.

 

The Government faces a mirrored version of the same problem. Designing a cross-agency ethics protocol, or approving a given tool for use, requires the kind of deep technical literacy that lets an assessor spot bias or a logical flaw baked into a system’s design – not simply take a vendor’s or (as we assume is being alluded to) an operational partner’s word for it.

 

Large language models in particular carry risks that are easy to articulate but hard to manage in practice:

    • they can produce fluent, confident output that is simply wrong (perhaps due to hallucination or confabulation);
    • they inherit and can amplify the biases latent in their training data (including any historic skew in policing or investigative records used to train them);
    • their outputs can shift meaningfully depending on how a query or prompt is framed, in a way that sits uneasily with the consistent, “thinking” approach the disclosure regime demands.

 

Ongoing work will be required to ensure the fairness and transparency which the Government has recognised as key to its response, and it will require ongoing technical expertise.

 

Transparency and fairness

 

In any adversarial system (for all its faults and its enduring value) procedural fairness is often a function of equality of arms.

 

There is an inherent tension in building a system that can handle sensitive material at scale while allowing both sides genuinely to be able to test it, and several of the Government’s recent reforms arise from belated recognition of this imbalance and the impact on fairness and due process.

 

The Government declined to commit to two clear transparency proposals:

    • Fisher’s Recommendation 24 would have required prosecutors to certify, case by case in the Crown Court, that any AI tool used had been correctly configured and competently operated, alongside other elements of comfort about the prosecution’s processes and decisions. The Government has declined to do so, citing concerns from “operational partners” about personal certification; the assurance will instead sit within organisation-wide processes, rather than being attached to an individual officer’s name on a document the defence can see.
    • Recommendation 87 – letting the defence propose search terms for unused material, subject to judicial decision, and see the results – has been accepted only “in principle”, with implementation still to be worked out:
      • “The Government therefore accepts the principle that appropriate tools should be available to enable defence scrutiny of disclosure decision-making. However, further work is required to ensure that implementation of such measures is carried out proportionately and effectively, including appropriate timelines, the exercise of judicial discretion, and how this would operate with Artificial Intelligence powered tools. This could be implemented by changes to the Criminal Procedure Rules or Criminal Practice Directions and the government would therefore invite the Criminal Procedure Rule Committee and the Lady Chief Justice to consider the most appropriate means of implementing this, with regard to the above considerations” (paragraph 155).

 

Put those two together, and you have the practical question this whole area turns on: if a defence team suspects the prosecution’s AI missed something, what, exactly, can they ask for, and from whom? The Government’s own language is candid about this being unresolved – it is “considering” the recommendations on transparency of the disclosure tools used in a case, which is civil-service-speak for “watch this space”, and we are left waiting for the details of the cross-agency protocol.

 

In civil litigation, the parties can agree between themselves how to allocate that risk. The Government, by contrast, is allocating this risk on everyone’s behalf, and needs to be clear with all concerned about the technical detail – which large language models are used, what technical support is available to operators, and how technically literate those operators are.

 

The Government does at least point toward two mechanisms that could help close the gap:

    • the cross-agency protocol, which paragraph 13 of the response says should set out “responsible AI use in investigative analysis and disclosure, including appropriate human oversight, clear accountability, legality, proportionality, and safeguards to uphold fair trial rights”; and
    • the metadata schedules proposed to be introduced under Recommendation 9, which may, in practice, assist those challenging a disclosure decision to identify what unused material exists in the first place.

 

The overriding objective of criminal procedure is for cases to be dealt with justly, which includes dealing with the prosecution and defence fairly, and dealing with the case efficiently and expeditiously.  Problems arise when these components of justice point in different directions. The defence will always want more transparency, the prosecution more discretion, and the Government more efficiency. The Government must take care not to let its own institutional wants outweigh the legitimate requirements of the defence.

 

What next?

 

Four things are worth keeping an eye on:

    • Pilots before clarity
      • As with the rebuttable presumption reforms (paragraph 25), the Government’s instinct is to pilot AI-assisted scheduling and summarisation before wider roll-out. Practitioners, particularly in complex fraud and regulatory cases, should perhaps expect to encounter these tools in live cases well before the Code of Practice amendments and guidance are finalised.
      • We are likely to see roll-out accelerating; PoliceAI’s summarisation tools are expected to be rolled out across all forces in 2027.
    • Challenging the rough edges
      • We can expect satellite arguments about configuration, training data, prompt engineering and accuracy, and audit trails to migrate from the civil e-disclosure world, as well as scrutiny over the use by police forces and judiciary while policies and procedures are in flux.
      • Civil litigators have had over a decade to grapple with protocols around technology and disclosure, such as agreed protocols and keyword-testing exercises, with the benefit of well-resourced technical teams.
      • The criminal sphere will benefit from this existing knowledge, but will have to continue to assess (including testing the limits of risk apportioning) as it builds its own procedures.
    • A possible widening of the gap between prosecution capability and the defence
      • Prosecuting agencies are expected to be able to move fast – on the basis of the Government’s responses and media reporting – to build systems, whilst individual defendants and smaller firms will be the ones trying to work out what was broken in the speed (to brutalise the famous motto of Mr Zuckerberg).
      • Small defence teams will need to grapple with the technology on top of procedure, without the benefit of the AI Police Academy. The unresolved status of Recommendations 23, 24 and Leveson’s Recommendation 87 means this is one of the grounds on which the next generation of disclosure appeals are likely to be fought.
      • Technical competency may become a requirement, rather than a desirability, for modern defence lawyers.
    • Bias hiding in plain sight
      • Large language models and predictive coding tools inherit the biases of their training data and the choices made by their designers. Without independent technical scrutiny, a biased or illogical output is just as likely to be missed by a government auditor as by a defence solicitor without a computer science background – and that, rather than any deliberate misuse, is the most likely way an AI-assisted process could come to silently disadvantage a defendant.
      • There are myriad ways for the Government to seek accountability; it isn’t yet precisely clear which route they will follow (particularly when considering the shortage of tech skills in the civil service), but they might consider:
        • A statutory regulator, on the model of the Forensic Science Regulator. This offers genuine independence and accreditation, but regulators of this kind can be slow to establish, slower still to keep pace as the underlying technology moves, and prone to becoming an exercise in tick-box compliance rather than substantive, case-specific scrutiny of any given tool’s output.
        • A single joint expert model, mirroring the CPR Part 35 model used in civil proceedings. The Government could require the parties to agree a single joint expert (likely from a pre-existing panel obtained through a central procurement process) to provide independent technical scrutiny of the technology and processes applied to the review and disclosure exercise. The expert’s role would not be to re-review the underlying material, but to explain to the court how the relevant tools were used, assess whether they had been deployed appropriately and assist the court in evaluating challenges to the disclosure process.
          • This balances the procurement requirement, allows scrutiny to be case-specific and is open to genuine adversarial testing (as it is in the civil courts). However, it is difficult to see how it could cope with the sheer scale of material in the cases this reform is aimed at – the four-million-document fraud case, not the single-box 1996 file – and it risks placing a significant additional cost on an already stretched public purse in every case where it is used.
        • Outsourcing technical assurance to the private sector, buying in expertise from specialist providers rather than building it in-house. This is probably the fastest route to genuine technical competence, but it carries its own risks: cost, exposure to the same market dependency that has already produced the public sector’s skills shortage, and a real question about independence where the firms best placed to provide assurance are also selling review tools to the very agencies they would be scrutinising.

 

Our key takeaways on this latest buzzword-laden document

 

Our conclusion on the AI Action Plan was that decisions are still reserved for humans, but the material on which those decisions rest is not. Disclosure is the sharpest illustration of that yet: it is the one process in the criminal justice system whose sole purpose is to test whether the prosecution’s account of the evidence is complete and fair. Handing large parts of that process to a system that is, by design, not required to be manually checked is a serious step – arguably a bigger one than anything so far proposed for the courtroom itself.

 

The most welcome feature of the Government’s response, however, is what it says about who gets a seat at the table. By building the defence into the engagement group from the outset, rather than treating this as a matter for law enforcement and prosecutors to explain to the defence after the fact, the Government has at least signalled that equality of arms is meant to survive the shift to AI-assisted disclosure. That is a genuinely positive step, and one worth acknowledging and encouraging in the strongest terms, albeit one conspicuously missing in their press release.

 

But a seat at the table does not equate to expertise. What is missing from this structure is truly independent technical expertise: assessors or accredited experts throughout the life of the system, continually testing that a tool’s outputs are fair and that its underlying data and its design are free of the biases and logical flaws that neither side, left to their own devices, may have the expertise to spot.

 

True transparency either requires us all to understand how the system is operating, or to be in a position to place trust in those who do.