Financial Crime · Strategic Guide
Preserving Evidence in an AI-Enabled Fraud Investigation
An AI output may be the most visible part of a suspected fraud, but it is rarely the whole evidence. Craig MacKenzie explains how organisations should preserve the prompts, source material, model and account data, human decisions and surrounding records needed to reconstruct what happened, test competing explanations and protect both incriminating and exculpatory evidence.
- Author
- Craig MacKenzie
- Role
- Partner and Solicitor Advocate
- Published
- 27 July 2026
- Reading time
- 26 minutes
The final output is not the complete evidence
An organisation discovers a suspicious document, generated email, altered invoice or artificial recording. Someone takes a screenshot, forwards it to the investigation team and deletes the original from the live system.
The visible content has been saved. Much of the evidence may already have been lost.
Generative AI does not usually produce a self-contained artefact with an obvious history attached. An output may depend upon:
- the precise prompt and earlier turns in the conversation;
- files uploaded by the user;
- information retrieved from connected systems;
- hidden system instructions or organisational configuration;
- the model and version used;
- tool calls and automated actions;
- account, device and access data;
- edits made after generation;
- human selection between several outputs; and
- the business process in which the output was used.
A final answer, image or document may therefore reveal what appeared on screen without revealing how it came to exist, who caused it to be created, what source material shaped it, whether it was altered, or why anyone acted upon it.
That missing history can point in either direction. It may show deliberate fabrication. It may reveal an innocent drafting process, a system error, an unauthorised user, a compromised account, an inaccurate retrieval source or a warning which the final screenshot omitted.
The central principle is:
Preserve the generation trail, not merely the final output.
Evidence preservation is not an exercise in collecting material which supports the first allegation. It is the disciplined protection of material capable of proving, qualifying or disproving what happened.
Why AI changes the preservation problem
The established principles of digital evidence still apply. AI does not displace the need to preserve original material, document handling, maintain integrity and enable another competent person to understand what was done.
It does, however, make the evidence more distributed, more dynamic and more dependent upon systems outside the organisation’s direct control.
The relevant material may be spread across several custodians
A single output may involve:
- an employee’s browser or mobile device;
- a personal or corporate AI account;
- the AI provider’s systems;
- a cloud storage platform;
- a retrieval-augmented generation knowledge base;
- an email or messaging platform;
- workflow automation software;
- application programming interface logs;
- identity and access-management systems;
- a customer relationship or finance system;
- external consultants or service providers; and
- the recipient who relied upon the output.
No single custodian may hold the complete history.
The system may be continually changing
Providers update models, safety systems, interfaces, retention settings and export functions. A prompt repeated later may produce a different answer. A model name visible to the user may not identify every technical component used at the relevant time.
Recreating the interaction is useful as an experiment. It is not a substitute for preserving the original interaction.
Apparently permanent material may be volatile
Conversation histories can be deleted manually, removed under automatic retention rules or excluded from ordinary exports. Temporary chats, cached material, application logs, tokens and tool traces may have short retention periods. Connected data sources may change after the output is generated.
Delay can therefore alter the evidence without anyone deliberately destroying it.
The output may not disclose its provenance
Text copied into a document may lose the account, timestamp, prompt and model information displayed in the original interface. A screenshot may omit earlier turns. A downloaded image may lack information held in a separate generation record. An email created by an automated workflow may not identify the system which drafted or sent it.
The evidential value lies not only in the content, but in the relationship between the content and its history.
Preservation, collection and analysis are different tasks
These terms are sometimes used interchangeably. They should be separated.
Preservation protects potentially relevant material from alteration, deletion or loss.
Collection acquires material in a controlled form for review or examination.
Analysis interprets the material and tests propositions about what it shows.
The distinction matters. An urgent preservation notice can be broad enough to protect material before the investigation knows exactly what it needs. Collection should then be planned and proportionate. Analysis should be conducted on controlled working copies wherever possible.
Preservation does not require investigators immediately to read every employee communication or copy every system. Nor should fear of over-collection justify allowing relevant volatile data to expire.
The immediate objective is to stabilise the evidence landscape while scope, legal authority and technical method are decided.
The legal framework is context-specific
There is no single statutory code governing every internal corporate investigation. The organisation may face several overlapping regimes depending upon whether the matter develops into a criminal investigation, regulatory inquiry, civil claim, employment process, insurance claim or contractual dispute.
Criminal investigations and disclosure
The Criminal Procedure and Investigations Act 1996 Code of Practice governs the recording, retention and revelation of material in criminal investigations by police and other investigators to whom it applies.
Its relevance test is deliberately broad. Material may be relevant if it has some bearing on an offence, a person under investigation or the surrounding circumstances, unless it is incapable of having any impact on the case. Investigators must pursue reasonable lines of inquiry whether they point towards or away from a suspect.
A private organisation conducting its own inquiry is not automatically exercising the statutory role of a police investigator. It should nevertheless anticipate that material it gathers may later enter a criminal process. Selective collection, unexplained deletion or a failure to preserve material pointing away from the allegation can impair the investigation and the fairness of any later proceedings.
Once material is supplied to law enforcement, its origin, completeness and handling history may become important to disclosure as well as proof.
Forensic standards
The Forensic Science Regulator’s statutory Code of Practice governs specified forensic science activities within the criminal justice system in England and Wales. Its detailed application depends upon the activity and provider involved.
An internal team should not claim accreditation or statutory compliance it does not possess. The broader disciplines remain valuable:
- use validated methods suitable for the task;
- define roles and competence;
- preserve integrity;
- keep contemporaneous records;
- manage contamination and information security;
- distinguish observations from interpretation;
- record limitations and uncertainty; and
- enable the work to be reviewed.
Where criminal proceedings are realistic and technical acquisition matters, an appropriately qualified digital forensic provider should be engaged early.
Civil disclosure
Different civil procedures apply in different courts and cases. In the Business and Property Courts, Practice Direction 57AD expressly requires reasonable steps to preserve potentially relevant documents when a person knows it is or may become a party to proceedings.
The concept of a document includes electronic material, metadata, information on servers and backups, and some information which has been deleted. Relevant deletion processes may have to be suspended, and employees, former employees, agents or third parties may need written preservation notifications.
That Practice Direction is not a universal rule for every forum. It illustrates why an organisation should not wait for a claim form before considering preservation where litigation is realistically in prospect.
Regulatory and cooperation expectations
Regulators and enforcement agencies may assess not merely what an organisation hands over, but how it preserved, collected and explained the material.
The Serious Fraud Office’s corporate guidance identifies preservation and production of digital and hard-copy material as relevant to cooperation. It also addresses internal investigative activity which may prejudice the SFO’s investigation.
Cooperation does not mean uncontrolled surrender of data or privilege. It does mean that preventable loss, opaque filtering or an inability to explain collection decisions can damage credibility.
Data protection and monitoring
Evidence preservation does not suspend data-protection law. Collection and review of employee, customer or third-party information require a lawful, necessary and proportionate approach.
The organisation should consider:
- the purpose and lawful basis for processing;
- the categories of personal and special-category data involved;
- whether monitoring is necessary and proportionate;
- who may access the preserved material;
- security, location and transfer arrangements;
- how irrelevant personal information will be protected;
- retention and deletion after the need ends; and
- whether a data protection impact assessment is required.
The Information Commissioner’s guidance on monitoring workers is an important starting point where employee systems or communications are involved.
Preserve first does not mean read everything. It means prevent loss while legal scope and access controls are established.
The nine-layer evidence map
An AI-enabled fraud investigation should map evidence across nine connected layers.
1. The business event
Preserve the transaction or decision around which the concern arose:
- payment instructions and bank records;
- invoices, purchase orders and contracts;
- approvals and exception records;
- customer, supplier or employee records;
- accounting entries and audit history;
- submissions to regulators, investors or public bodies;
- documents issued externally;
- dates, values and beneficiaries; and
- the commercial purpose said to justify the act.
Without this layer, the investigation may prove that AI was used without proving that any false representation, gain, loss, breach or dishonest purpose followed.
2. The human decision
Identify every person who created, selected, edited, approved, relied upon or rejected the output.
Preserve:
- contemporaneous notes;
- approval messages;
- tracked changes and document versions;
- comments and review history;
- oral instructions recorded in durable form;
- warnings raised and responses given;
- deviations from ordinary controls;
- training and policy material relevant at the time; and
- the sequence in which each person saw the information.
The same output can have different legal significance depending upon what the user knew, what warning they received and what they intended.
3. The AI interaction
This is the generation trail itself. Depending upon the system, preserve:
- the complete conversation, not a selected turn;
- prompts and follow-up prompts;
- generated responses, including rejected alternatives;
- uploaded files, images, audio and data;
- timestamps and time zone;
- conversation and message identifiers;
- visible model selection;
- citations, retrieved passages and search results;
- tool calls, code execution and automated actions;
- content warnings, refusals and safety messages;
- regeneration, edit and branching history;
- feedback submitted by the user;
- exported conversation data; and
- screenshots showing relevant interface context.
An export and screenshots can complement each other. Neither should automatically be assumed complete.
4. The model and configuration
Record what can reliably be established about the system used:
- provider and product;
- model name or deployment identifier;
- version information available at the time;
- corporate workspace or tenant;
- system and developer instructions under the organisation’s control;
- custom instructions;
- temperature or other parameters where exposed;
- enabled tools and connectors;
- safety or moderation configuration;
- fine-tuning or customisation;
- workflow and application version;
- data-retention setting; and
- relevant contractual or product documentation.
Do not overstate what this proves. A user-facing label may not reveal the full technical stack. Record both the information obtained and its source.
5. The source and retrieval material
An AI output may be shaped by documents or data which the user never placed directly into the prompt.
Preserve:
- the knowledge base available at the relevant time;
- retrieved chunks or passages where logged;
- file versions and modification dates;
- embedding or index version where relevant;
- search queries and results;
- connected mailbox, drive, database or website content;
- access permissions;
- data lineage;
- sources which were unavailable or excluded; and
- later changes to the source material.
A later recreation against an updated knowledge base may not reproduce the original context. Where feasible, preserve a defensible snapshot of the relevant source set or the exact versions retrieved.
6. Account, identity and access evidence
An output associated with a named account does not prove that the account holder personally created it.
Preserve:
- account ownership and role;
- sign-in and authentication logs;
- device, browser and session information;
- IP data where lawfully available;
- multi-factor authentication events;
- token creation and use;
- delegated or shared access;
- administrator changes;
- password resets;
- suspicious-login alerts;
- service-account activity;
- API keys and application identities; and
- joiner, mover and leaver records.
Take care not to rotate credentials or terminate sessions before relevant data is captured. Security containment and preservation should be coordinated.
7. Surrounding communications
The AI interaction may be only one part of the plan.
Preserve relevant:
- email;
- workplace chat;
- text and messaging applications;
- meeting invitations and recordings;
- telephone records;
- project-management systems;
- ticketing and approval platforms;
- external file-sharing links;
- instructions from supervisors or clients; and
- communications after the event, including attempts to explain, conceal or correct it.
The investigation should identify private or unmanaged channels lawfully and proportionately rather than assume corporate systems contain everything.
8. The financial and external trail
Where gain, loss or intended benefit is in issue, preserve:
- bank and payment-provider records;
- beneficiary and mule-account details;
- cryptoasset addresses and transaction identifiers;
- refunds, recalls and recovery communications;
- changes to supplier or payroll details;
- commission, bonus and target data;
- insurer notifications;
- third-party confirmations;
- domain, hosting and telecommunications records; and
- reports to law enforcement or regulators.
External records may be subject to retention periods outside the organisation’s control. Early preservation requests may be critical.
9. The investigation and preservation trail
The organisation must preserve evidence of its own work:
- the allegation as first received;
- incident and decision logs;
- preservation notices;
- custodian and system maps;
- acquisition records;
- chain-of-custody entries;
- hash values and verification results;
- search and filtering decisions;
- copies supplied to advisers, experts or authorities;
- interview records and drafts where relevant;
- analytical outputs;
- known gaps and failed collection attempts;
- changes in scope; and
- the reasons for material decisions.
An unexplained folder of files is weaker than a collection whose origin, handling and limitations can be reconstructed.
The first preservation actions
The precise response should be adapted to the incident, but the following sequence provides a defensible starting point.
1. Appoint one preservation lead
Give a named person authority to coordinate legal, technical, security, HR and operational teams. Record responsibility and escalation routes.
Avoid separate teams issuing inconsistent instructions or making unrecorded copies.
2. Define the event without deciding the conclusion
Prepare a neutral initial description:
- what happened;
- when it was discovered;
- the systems, transactions and people apparently involved;
- the possible legal or regulatory consequences; and
- what material appears at immediate risk.
Use language such as “suspected”, “reported” and “requires investigation”. Do not turn the preservation notice into a finding of fraud.
3. Identify volatile sources
Prioritise material capable of disappearing:
- temporary or deleted AI conversations;
- short-retention provider and API logs;
- live memory and active sessions where relevant;
- expiring cloud audit logs;
- ephemeral messages;
- dynamic web or knowledge-base content;
- CCTV;
- call recordings;
- third-party platform data; and
- accounts about to be disabled or devices due to be rebuilt.
Preservation priority is driven by volatility and significance, not convenience.
4. Suspend relevant deletion
Pause automatic deletion, mailbox or chat retention, device disposal, account closure and routine log rotation for the identified scope.
Do not suspend every retention process across the organisation without analysis. A preservation measure should be broad enough to be effective and narrow enough to remain manageable, secure and proportionate.
5. Notify custodians and providers
Issue clear written instructions identifying:
- the event or subject;
- relevant date range;
- systems and categories of material;
- the requirement not to delete, edit or overwrite;
- the treatment of personal devices or accounts, where lawful;
- who to contact with questions;
- confidentiality requirements; and
- confirmation steps.
Where a platform provider, outsourced processor or other third party may hold volatile data, identify the contractual and legal route for requesting preservation. A request to preserve is not necessarily a right to receive the material.
6. Capture before changing
Where safe, collect the information needed to understand a system before:
- deleting a conversation;
- revoking access;
- rebuilding a device;
- changing an integration;
- rotating an API key;
- disabling an account;
- updating the model or workflow;
- modifying a knowledge base; or
- correcting the underlying record.
Containment may sometimes have to come first. If so, record exactly what changed, when, why and by whom.
7. Separate master material from working copies
Create a controlled master collection. Restrict access. Verify integrity where appropriate. Conduct searches, conversion, transcription and analysis on working copies.
This reduces accidental alteration and makes later explanation easier.
Screenshots, exports and native material
No single capture method is always sufficient.
Screenshots
Screenshots can preserve:
- what the user saw;
- the visual sequence;
- warnings or interface labels;
- account and model information displayed on screen; and
- content which an export omits.
They may also omit metadata, earlier turns, hidden content and machine-readable structure. Cropping can remove context. A screenshot should be accompanied by a record of who captured it, when, from what account and device, and whether anything was expanded, translated or altered.
Platform exports
An export may provide more complete and structured content. Its limits should be tested:
- Does it include deleted or archived conversations?
- Are timestamps and identifiers preserved?
- Does it include uploaded files?
- Are branches and regenerated answers included?
- Does it identify tools, sources and model versions?
- Does it preserve formatting and attachments?
- When was the export requested and generated?
Preserve the export in its native package before extracting or converting it.
Native files and forensic acquisition
Native material may contain metadata and structure lost in PDF or printed form. In higher-risk cases, forensic imaging or specialist acquisition may be necessary.
It is not always proportionate to image every device. The method should be selected according to the issues, volatility, likely probative value and risk of alteration. The decision and its limitations should be recorded.
Hashes prove less than people sometimes claim
A cryptographic hash is a calculated value which can be used to compare data. If the hash of a preserved file remains the same, that supports the conclusion that those bytes have not changed since the hash was calculated.
It does not prove:
- that the file was genuine when first created;
- who created it;
- that the device clock was correct;
- that the file was complete;
- that no earlier alteration occurred;
- that the content depicts a real event; or
- that the person said to control the account performed the act.
The correct proposition is limited:
The hash helps demonstrate integrity from a defined point in the preservation process. It does not establish authenticity before that point.
Record the algorithm, value, date, operator, source and object to which each hash relates. Re-verify after transfer where appropriate.
Time is evidence
AI-enabled investigations often depend upon sequence:
- when a source document changed;
- when a prompt was entered;
- when an answer was generated;
- when a user opened or edited it;
- when an approval was given;
- when funds moved; and
- when suspicion arose.
Different systems may record local time, UTC, server time or no time zone at all. Clocks can drift. Exports can display generation time while file systems show download or modification time.
The investigation should:
- preserve the original timestamp and time-zone information;
- identify the clock source where possible;
- avoid silently converting times;
- record any conversion method;
- compare independent time sources;
- note daylight-saving changes; and
- distinguish creation, access, modification, export and collection times.
A polished single chronology should not conceal uncertainty in the underlying timestamps.
Do not “test” the evidence in the live account
An investigator may be tempted to open the conversation, edit the prompt, regenerate the response or ask the system why it produced the output.
That can:
- alter timestamps or state;
- create new messages in the same thread;
- overwrite or obscure the original branch;
- expose confidential material to further processing;
- contaminate recommendations or memory features;
- trigger automated actions; or
- create an apparently contemporaneous record which is actually part of the investigation.
Preserve the original state first. Conduct testing in a separate controlled environment. Record the model, settings, prompts, date and limitations of each experiment.
Repeated output is not proof that the original output occurred. Failure to repeat it is not proof that it did not.
Generated summaries and transcripts are derived evidence
AI can assist with chronology, transcription, translation, document review and anomaly detection. Any resulting material is derived from a source and should be treated as such.
Preserve:
- the original source;
- the tool and version used;
- the instruction or prompt;
- the generated result;
- human corrections;
- quality checks;
- known limitations; and
- the decision made from it.
Do not replace the source with the AI summary. Do not allow a generated transcript to become the only record of audio. Material passages should be checked against the original, especially where speaker identification, technical vocabulary, tone or timing matters.
If AI is used to review the investigation evidence, consider confidentiality, privilege, data location, contractual terms and whether the provider may retain or use the input.
Evidence which may point away from fraud
Preservation must resist confirmation bias.
Potentially exculpatory or qualifying material can include:
- earlier outputs showing an innocent development process;
- a warning that the user followed;
- evidence that a document was labelled as a draft;
- account-compromise alerts;
- prompts entered by another user;
- source data which was itself wrong;
- model behaviour inconsistent with deliberate fabrication;
- rejected outputs;
- records showing no external transmission;
- approval controls which operated;
- a correction made before loss;
- an alternative cause for the transaction; and
- documents undermining the reliability of a complainant or key witness.
Deletion of the generation trail can prejudice the organisation as readily as a suspect. It may destroy the evidence needed to distinguish dishonesty from mistake, automation failure or unauthorised access.
The material most likely to test the allegation may sit one step before, after or outside the suspicious output.
Preservation and privilege
Legal professional privilege is not created merely by marking an internal document “privileged” or copying a lawyer into an email.
The organisation should obtain early advice on:
- who the client is;
- the purpose and structure of the investigation;
- the role of lawyers and non-lawyers;
- communications seeking or giving legal advice;
- material created for contemplated litigation;
- interview notes and reports;
- expert instructions;
- distribution and waiver risk; and
- how privileged and non-privileged material will be separated.
Preservation should not be delayed while every privilege question is resolved. Preserve potentially relevant material under restricted access, then review its status through a controlled process.
Guide 5 in this series addresses privilege, interviews and evidence contamination in internal investigations. The immediate rule is that preservation and privilege review are separate. A claim to privilege may affect production, but it should not become a reason to destroy or fail to secure the material.
Interviews must not overwrite the digital record
Witnesses can explain context which systems cannot. They can also be influenced by shared accounts, leading questions and reconstructed documents.
Before substantive interviews:
- preserve each witness’s original communications and notes;
- record their first account where appropriate;
- prevent unnecessary circulation of a common narrative;
- identify what documents they saw at the time;
- distinguish recollection from later inference;
- plan whether documents should be shown and in what order; and
- decide who will conduct and record the interview.
Do not ask a witness to open the live AI account and “show what happened” before it has been preserved. That demonstration may change the evidence.
Common preservation failures
Saving only the incriminating output
This removes the context needed to test creation, intention and attribution.
Forwarding content by email
Forwarding may alter formatting, omit headers or attachments, and create a new date. Preserve the native material as well.
Deleting the output for safety
Removing harmful or confidential content may feel prudent, but deletion can destroy critical evidence. Restrict access and neutralise operational risk while preserving a controlled copy.
Disabling an account without capturing logs
Containment may terminate sessions or trigger retention processes. Coordinate with security and record the action.
Letting routine retention continue
The absence of deliberate deletion does not make the loss defensible. Once a material investigation or dispute is reasonably anticipated, relevant automatic deletion should be considered promptly.
Collecting through the suspected user
Asking the subject to select and forward their own records risks omission and alteration. Use independent, authorised collection where possible.
Assuming the provider can recover everything
Contractual retention, technical availability and legal entitlement are different questions. Establish them rather than assume.
Converting everything to PDF
PDF can be useful for review but may strip metadata, dynamic content, links, comments and version history. Preserve native data.
Over-collecting without governance
Indiscriminate copying increases privacy, privilege, security and review risks. Stabilise broadly where necessary, then collect and review proportionately.
Treating absence as proof
A missing log may mean an event did not occur. It may also reflect retention, configuration, collection failure or a system which never recorded it. Prove what the system was capable of recording at the time.
A defensible preservation protocol
The following framework can be adapted to the organisation and incident.
| Stage | Essential question | Required record |
|---|---|---|
| Trigger | What event made preservation necessary? | Neutral incident description and decision time |
| Governance | Who controls scope and legal decisions? | Named lead, roles and escalation |
| Mapping | Where could relevant material exist? | Custodian, system and provider map |
| Volatility | What may disappear first? | Prioritised source list and retention periods |
| Hold | What deletion must be suspended? | Written notices, system changes and confirmations |
| Collection | How will each source be acquired? | Method, authority, operator and limitations |
| Integrity | How will unchanged material be demonstrated? | Master copies, hashes and access controls |
| Review | Who may inspect what, and why? | Review protocol, privilege and privacy controls |
| Analysis | How were findings produced? | Tools, searches, prompts, working copies and quality checks |
| Production | What was supplied externally? | Disclosure log, redactions and transfer record |
| Reassessment | What has changed in the case theory? | Updated scope, gaps and further preservation |
| Release | When may preserved data be deleted? | Legal approval, retention basis and documented disposal |
The protocol should be capable of answering:
- What was preserved?
- From where and from whom?
- When was it preserved?
- By whom and using what method?
- What changed before or during collection?
- How was integrity checked?
- What was unavailable?
- What was excluded, and why?
- Who accessed or analysed it?
- Can another competent person understand and, where appropriate, repeat the process?
What boards and senior leaders should ask
Senior oversight should focus on the integrity of the response, not simply its speed.
Boards, general counsel and investigation sponsors should ask:
- Has routine deletion been assessed and suspended where necessary?
- Have volatile third-party and provider records been identified?
- Are security containment and evidence preservation being coordinated?
- Is the investigation collecting material which may disprove the allegation?
- Has the complete AI generation trail been protected?
- Are native data and metadata being retained?
- Can account use be attributed beyond the display name?
- Has the knowledge source available at the relevant time been preserved?
- Are personal data and employee monitoring being handled proportionately?
- Is privileged work separated without losing underlying facts?
- Are interviews being sequenced to reduce contamination?
- Is technical work being undertaken by competent people using defensible methods?
- Can the organisation explain every material gap?
- Has the need for reporting, cooperation or court disclosure been considered?
- Is there a documented point at which the preservation scope will be reviewed?
The board does not need to supervise every forensic step. It should be able to demonstrate that the right disciplines, authority and challenge were established.
Relationship with failure to prevent fraud
Evidence preservation is not only an incident-response issue. It can affect whether an organisation is able to demonstrate that its fraud prevention procedures operated in practice.
Relevant records may show:
- the risk assessment which identified AI-enabled fraud;
- approval and verification controls;
- training delivered to high-risk staff;
- alerts and exception handling;
- third-party due diligence;
- monitoring and testing;
- escalation routes;
- action taken after earlier incidents; and
- the reason a control was overridden.
Under the failure-to-prevent-fraud offence, the statutory defence concerns reasonable procedures at the time of the underlying fraud. A policy drafted after the event cannot supply that history. Preservation should therefore protect the evidence of the control environment which existed before the allegation arose.
For the full statutory framework, see Failure to Prevent Fraud: A Strategic Guide for Organisations and Senior Leaders.
The proportionate end point
Preserved data should not remain indefinitely merely because an allegation once existed.
The organisation should review:
- whether criminal, regulatory, civil, employment or insurance processes remain possible;
- any statutory, court-ordered or contractual retention requirement;
- limitation and appeal periods;
- continuing disclosure obligations;
- privilege and confidentiality;
- the rights and interests of data subjects;
- the risk of fragmented copies; and
- whether secure deletion can now resume.
Release from a preservation hold should be authorised, documented and communicated. Working copies, expert sets and adviser copies should be included in the disposal plan where appropriate.
The aim is neither premature deletion nor permanent accumulation. It is controlled retention for a defined legal and investigative purpose.
A strategic response
The first hours of an AI-enabled fraud investigation create decisions which may determine what can later be proved.
The organisation should:
- stabilise the relevant systems and transactions;
- appoint clear legal and technical leadership;
- identify volatile evidence before it disappears;
- suspend relevant deletion processes;
- preserve all nine evidence layers;
- keep native master material separate from working copies;
- document integrity, gaps and every material intervention;
- collect evidence pointing towards and away from the allegation;
- control privacy, privilege and interview contamination; and
- review the preservation scope as the case theory develops.
The most damaging mistake is often irreversible. It is the assumption that saving what appeared on screen has saved the event.
Preserve first. Interpret second. The generation trail may decide which interpretation survives.
Frequently asked questions
Is a screenshot of an AI output enough?
Usually not. A screenshot may accurately show visible content, but it may omit prompts, earlier turns, timestamps, identifiers, uploaded files, retrieved sources, alternative outputs and account data. Preserve the screenshot, native conversation, available export and surrounding records.
Should a harmful or fraudulent AI output be deleted?
Not before controlled preservation and legal assessment. Access can be restricted and operational risk contained without destroying the evidence. If an urgent security action requires deletion or account closure, record what was changed, when, why and by whom.
Does a matching hash prove that an AI file is authentic?
No. It supports the proposition that the preserved bytes have not changed since the hash was calculated. It does not prove that the content was genuine, complete or unaltered before preservation, nor who created it.
Must the organisation preserve every AI conversation?
Not automatically. Scope should be reasonable and proportionate to the issues, people, systems and period involved. The immediate hold may need to protect a wider set while those boundaries are established. Decisions to exclude sources should be reasoned and recorded.
What if an employee used a personal AI account?
The organisation should obtain advice before accessing or demanding personal account data. It should consider ownership, policies, contractual rights, privacy, data protection and the availability of narrower alternatives. The employee should be given an appropriately framed preservation instruction where relevant.
Can the investigation simply repeat the prompt?
Repetition may assist testing, but it does not recreate the original event. Models, source data, settings and random variation may differ. Preserve the original interaction, and record any later experiment as a separate derived exercise.
Should prompts and rejected outputs be retained?
If they may bear on the investigation, yes. They can reveal purpose, knowledge, correction, selection and the development of the final output. Rejected material may support or undermine an inference of dishonesty.
Does privilege protect the entire internal investigation?
Not necessarily. Privilege depends upon the nature and purpose of particular communications and documents, not the investigation’s label. Preserve the material, restrict access and obtain advice on structure, review and production. Guide 5 addresses this in detail.
When should a digital forensic specialist be instructed?
Early involvement is sensible where data is volatile, accounts may be compromised, devices require imaging, deleted material matters, provider exports are incomplete, authenticity is disputed or criminal proceedings are realistic. The specialist should be given a neutral brief and asked to record methods, limitations and changes.
Conclusion
An AI output is a point in a chain, not the whole event.
The evidence may begin with source material, pass through a prompt, model, tool and account, become one of several generated answers, be edited by a person, move through an approval process and finally affect a transaction. Each stage may carry evidence of authenticity, attribution, dishonesty, reliance, control failure or innocent explanation.
The organisation which preserves only the endpoint may lose the ability to prove its own case. The organisation which preserves the generation trail protects something more valuable than data: it protects the ability to reach a defensible conclusion.
Preserve the generation trail, not merely the final output.
Preserve the generation trail, not merely the final output.
Craig MacKenzie provides strategic advice through Forbes Solicitors to organisations and senior leaders on urgent evidence preservation, internal investigations, corporate and individual exposure, and engagement with investigators or regulators.
Request a confidential consultationDo You Require Advice About Your Circumstances?
This material provides general information and is not a substitute for advice about a specific investigation or case.
Craig provides legal services exclusively through Forbes Solicitors. To make an initial enquiry, contact Craig at:
craig.mackenzie@forbessolicitors.co.uk
An enquiry does not constitute an instruction. Forbes Solicitors must confirm in writing that it has accepted the matter before any solicitor–client relationship arises.
Related Guidance
The First 24 Hours After Suspected Corporate Fraud
Guide 1 in this series: controlling harm, preserving evidence and making defensible decisions on day one.
Failure to Prevent Fraud: A Strategic Guide
Guide 2 in this series: corporate exposure, the reasonable procedures defence and the evidence boards should be able to produce.
Deepfake and Voice-Clone Fraud
Guide 3 in this series: legal and investigative response when synthetic media is used in suspected fraud.
Internal Investigations: Privilege, Interviews and Evidence Contamination
Guide 5 in this series: privilege, interview sequencing and preventing evidence contamination in internal investigations.
AI-Enabled Financial Crime and Corporate Investigations
The cornerstone guidance hub on how AI is changing fraud, corporate liability and investigations.