← Back to all research
AI & GOVERNANCE · SEMESTER 2 · MA IT LAW

Designing a Lawful AI System for Investigating Online Child Exploitation: Requirements, Admissibility and Cross-Border Reach

Coursework written during my MA in Information Technology Law at the University of Ghana, 2025–2026. Presented as an academic working paper, not a peer-reviewed publication or current legal advice. Original language and arguments retained. This assignment was completed as group coursework.

The Secret Service of Ogyakrom are concerned about child sex exploitation videos being distributed and sold through internet communities. They are however lacking the manpower to manually check websites for illicit content, let alone penetrate the initial layer of such a network (the most serious images are typically hidden from open view). They are considering adapting webcrawlers to autonomously identify suspicious websites and possibly gather sufficient evidence for prosecution.

Working in your class groups of mixed IT, security and law professionals, design the technical requirements for a top-secret artificial intelligence and autonomic agent software for this task and then address the following issues:

Q 1: Would your investigative software be lawful for intelligence purposes?

Q 2: What will be the legal basis for the admission of your evidence in court?

Q 3: What is an online search? Is it comparable to the offline search of a premise?

Q 4: What are the legal problems if the software investigates a person while s/he is abroad, and

seizes evidence from servers located in another jurisdiction?

Your combined answer for both parts of the question may not exceed 1,000 words.

Introduction

The online distribution and sale of child sexual exploitation material (CSEM) through internet communities poses a significant challenge in Ogyakrom. The Secret Service of Ogyakrom lacks the manpower to manually monitor websites and infiltrate hidden online networks where such material is often concealed. It is considering adapting an AI-powered autonomic webcrawler to identify suspicious websites and gather evidence for prosecution. This paper examines the system's technical requirements, lawfulness, evidential admissibility, online and offline searches, and the jurisdictional challenges arising from cross-border investigations.118

Technical Requirements

The software would operate as an autonomic intelligence system capable of continuously monitoring, analysing and responding to online activities with minimal human intervention while remaining subject to human oversight. Consistent with Kephart and Chess' autonomic computing model, it would continuously monitor online environments, analyse data, plan investigative responses and execute authorised actions using a dynamic knowledge base.119

First, the system would employ multi-layered web crawling to search the surface web, password-protected websites and, where judicially authorised, darknet platforms accessible through the Tor network. To minimise detection, the crawler would rotate IP addresses, vary user-agent identities and mimic normal browsing behaviour through randomised requests.120

Secondly, the detection engine would combine multiple AI techniques to improve reliability. Known CSEM would be identified using perceptual hashing technologies such as PhotoDNA, while supervised machine learning models, particularly convolutional neural networks (CNNs), would detect previously unknown images and videos. Natural language processing (NLP) would analyse webpage content, filenames, metadata and online communications for contextual indicators of CSEM. Combining visual, textual and metadata analysis reduces false positives and enhances reliability.121

Thirdly, to ensure evidential integrity, every digital artefact would be immediately cryptographically hashed, securely timestamped and stored with immutable audit logs and comprehensive chain-of-custody records in accordance with ISO/IEC 27037 and NIST digital forensic guidelines.122

Finally, the software would not independently determine criminal liability. Every AI-generated alert would be independently reviewed and validated by a trained investigator before further investigative or prosecutorial action is authorized. Human oversight improves explainability, reduces algorithmic bias and ensures that legal discretion remains vested in public officials rather than software.123

Is the Software Lawful?

The lawfulness of the proposed software depends on compliance with constitutional and statutory safeguards rather than the use of AI itself. Article 18(2) of the 1992 Constitution protects the privacy of correspondence and communication, permitting interference only where authorised by law. Accordingly, the software must operate within statutorily defined limits.124

The Cybersecurity Act, 2020 (Act 1038) empowers authorised agencies to obtain production orders, preservation orders and interception warrants for cybercrime investigations.125 AI would therefore function only as an investigative aid, with legal responsibility remaining with human investigators.126 The system would also incorporate proportionality safeguards by collecting only relevant information, deleting false positives and using explainable AI to justify its findings.127 These measures promote accountability, minimise bias and protect constitutional rights while enabling the effective investigation of child sexual exploitation material.

Admissibility of Evidence

The admissibility of AI-generated evidence depends on its authenticity, reliability and forensic integrity. Section 51 of the Evidence Act 1975 (NRCD 323) permits the admission of relevant evidence, while section 7 of the Electronic Transactions Act 2008 (Act 772) recognises the legal validity of electronic records.128 Accordingly, investigators would establish an unbroken chain of custody through cryptographic hashing, secure timestamps and audit logs to demonstrate that the evidence remained unaltered.

The AI software is not evidence; it merely identifies suspicious material, while the evidential value lies in the lawfully collected digital artefacts and metadata. Expert testimony may be required to establish the system's reliability, consistent with R v Shephard.129 Although Ghana does not apply an absolute "fruit of the poisonous tree" doctrine, courts may reject improperly obtained evidence where its admission would compromise the fairness or integrity of the proceedings.130

Online vrs Offline Searches

An online search involves remote examination, monitoring or retrieval of information stored on computer systems or electronic communications networks. Unlike an offline search, which requires physical entry into premises, an online search enables covert access to digital information without the suspect's knowledge.131 Although both seek evidence of criminal activity, online searches are broader in scope and may capture data across multiple devices, cloud services and third-party systems. Consequently, they require enhanced safeguards.132 Judicial authorisation should define the scope and duration of the search, while AI-powered web crawlers would collect only information relevant to CSEM investigations and discard irrelevant data. Online searches are comparable to offline searches but require stricter judicial oversight because of their greater intrusion into privacy.133

Cross-Border Jurisdiction

Cross-border cyber investigations present significant jurisdictional challenges because, although cyberspace is borderless, criminal enforcement remains governed by state sovereignty. Where suspects or evidence are located abroad, unilateral access by an AI system may violate international law and jeopardise the admissibility of the evidence. International cooperation is therefore essential. Article 32(b) of the Budapest Convention permits cross-border access only where lawful and with appropriate consent,134 while the Malabo Convention promotes mutual legal assistance.135 Similarly, Ghana's Cybersecurity Act and the Mutual Legal Assistance Act provide mechanisms for obtaining foreign evidence. Accordingly, access to overseas data should occur only through judicial authorisation and recognised international cooperation channels.

Recommendations

Ogyakrom should adopt a human-centred AI governance framework that treats AI as an investigative aid rather than a replacement for human decision-making. Intrusive online investigations should be subject to judicial authorisation, and all AI-generated findings independently verified before enforcement action. Legislation should establish standards for transparency, explainability, algorithmic auditing, evidence preservation and accountability. Where investigations involve foreign suspects or overseas data, authorities should rely on mutual legal assistance, the Budapest Convention and the Malabo Convention. Finally, regular technical and legal audits should ensure accuracy, minimise bias and maintain compliance with constitutional safeguards, thereby strengthening public confidence in AI-assisted investigations.

Conclusion

Artificial intelligence can significantly strengthen investigations into child sexual exploitation material by enhancing detection and evidence collection. However, its deployment must remain lawful, proportionate and subject to judicial oversight, forensic safeguards and human supervision. Properly regulated, AI can improve prosecutions while protecting constitutional rights, privacy and the rule of law.

Source notes

  1. Burkhard Schafer, 'The Taming of the Sleuth: Problems and Potential of Autonomous Agents in Crime Investigation and Prosecution' (2006) 20(1–2) International Review of Law, Computers & Technology 63.
  2. Jeffrey O Kephart and David M Chess, 'The Vision of Autonomic Computing' (2003) 36(1) IEEE Computer 41, 44–45.
  3. Register.com Inc v Verio Inc 356 F 3d 393 (2d Cir 2004).
  4. Evangelia Daskalaki, Emmanouela Kokolaki and Paraskevi Fragopoulou, 'Hashing in the Fight Against CSAM: Technology at the Crossroads of Law and Ethics' (2025) 5(4) Journal of Cybersecurity and Privacy 812; Martin Steinebach, 'An Analysis of PhotoDNA' (ARES 2023).
  5. ISO/IEC 27037:2012 Information Technology—Security Techniques—Guidelines for Identification, Collection, Acquisition and Preservation of Digital Evidence; Karen Kent et al, Guide to Integrating Forensic Techniques into Incident Response (NIST SP 800-86, 2006).
  6. Konstantinos Lazaros, Aristidis G Vrahatis and Sotiris Kotsiantis, 'Human-in-the-Loop Artificial Intelligence: A Systematic Review of Concepts, Methods, and Applications' (2026) 28(4) Entropy 377.
  7. Constitution of the Republic of Ghana, 1992, art 18(2).
  8. Cybersecurity Act, 2020 (Act 1038), ss 69–74.
  9. Schafer (n 1) 66–70.
  10. Daskalaki, Kokolaki and Fragopoulou (n 4) 824.
  11. Evidence Act 1975 (NRCD 323), s 51; Electronic Transactions Act 2008 (Act 772), s 7.
  12. R v Shephard [1993] AC 380 (HL).
  13. Raphael Cubagee v Michael Asare & Others (Supreme Court, Ghana); Evidence Act 1975 (NRCD 323), s 52.
  14. Schafer (n 1) 70–73.
  15. Wiebke Abel and Burkhard Schafer, 'The German Constitutional Court on the Right in Confidentiality and Integrity of Information Technology Systems – a Case Report on BVerfG, NJW 2008, 822' (2009) 6(1) SCRIPTed 106.
  16. Constitution of the Republic of Ghana 1992, art 18(2).
  17. Convention on Cybercrime (Budapest Convention) ETS No 185, art 32(b).
  18. African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention), art 28.
Explore more writing ↗