A subject where AI sits on both sides
Most topics on this site concern police adopting a technology and the questions that follow. Cybercrime is different, because the same technology is being adopted just as quickly by the people police are investigating. Any assessment of AI in cybercrime enforcement that looks only at what police are deploying is describing one side of an exchange.
What has actually changed for offenders
The most consequential change is not a new category of attack. It is a collapse in the cost of executing existing ones well.
Phishing is the clearest example. The advice given to the public for two decades leaned heavily on surface signals: poor grammar, awkward phrasing, obvious translation errors. Generative AI removes all of those at essentially no cost, and allows a message to be tailored to an individual target using publicly available information about them, at a volume that previously would have required a team. Advice built around spotting bad English no longer describes the threat.
Voice and video impersonation has moved on a similar trajectory. Synthetic audio of a specific person, generated from a short sample, has featured in reported authorisation frauds where the persuasive element was a familiar voice on a call rather than anything technical. This is covered further under deepfakes.
It is worth being precise about the limits of this. A highly capable, well-resourced attacker could already do most of these things. What has changed is that capabilities once requiring skill, time or a team are now available to people with none of those. The threat model shifts at the bottom of the distribution rather than at the top, which matters for volume much more than for severity.
Where AI helps investigators
The binding constraint in cybercrime investigation is usually analytical capacity. Reported incident volumes vastly exceed what can be individually investigated, and the digital evidence attached to a single serious case can run to volumes no team can read.
Triage is therefore the most immediately valuable application: sorting very large volumes of reports to identify which are connected, which are actionable, and which represent a campaign rather than an isolated incident. Related to this is clustering, identifying that a set of reports which look unconnected when read individually share infrastructure, technique or timing. That pattern-matching across large volumes is genuinely well suited to automation, and it is closer to the technology's actual strengths than most policing applications are.
Digital evidence processing is the other substantial area, overlapping with forensic science: automated triage of seized devices, classification of material, and prioritisation of what a human examiner should look at first.
Attribution, in both directions
Attribution in cybercrime has always been difficult and contested. AI affects it both ways, and the net effect is genuinely unclear rather than diplomatically described as such.
On the investigative side, correlating infrastructure reuse, code similarity and behavioural patterns across a large body of incidents is exactly the kind of task where automated analysis outperforms manual comparison. On the other side, some of the signals attribution has historically relied on are weakening. Distinctive linguistic patterns, characteristic errors and stylistic fingerprints in ransom notes or phishing text are far less informative when the text was generated rather than written, and deliberately misleading signals are correspondingly cheaper to manufacture.
Jurisdiction, which remains the harder problem
It is worth stating plainly that the primary obstacles in cybercrime enforcement are not analytical. They are jurisdictional. Offenders, infrastructure, victims and the evidence are routinely in four different countries with different legal systems, different data retention rules, and in some pairings no functioning mutual legal assistance relationship at all.
No amount of analytical capability resolves that. A force may identify an offender with confidence and still have no route to arrest them. This is a useful corrective to claims made for AI capability in this area: better analysis moves the constraint, it does not remove it, and the constraint it moves toward is diplomatic rather than technical.
Follow the coverage
PoliceAI News tracks AI and cybercrime as it develops: new attack techniques, law enforcement capability, major investigations, international cooperation agreements and regulatory responses. The feed refreshes every 30 minutes.
View Cybercrime Stories