Artificial Intelligence and Criminal Proceedings: Evidence, Digital Identity and New Risks (2026 Guide)
In this article
Key Takeaways
- Deepfakes: absence of intent
- Organisational failure
- eIDAS 2: digital identity theft
- Metaverse: art. 173 CP
- P300 and self-incrimination
Artificial intelligence and emerging technologies are redefining criminal proceedings on five fronts: real-time deepfakes make the deceived employee a victim of the fraud, not its perpetrator; quantum computing calls for reviewing encryption, whose inadequacy is penalised under the GDPR, not the Criminal Code; the European Digital Identity Wallet (eIDAS 2) creates new risks of forgery and identity theft; attacks on avatars in the metaverse are debated as an offence against moral integrity (art. 173 CP); and neurotechnology raises the question of whether a brain-based test violates the right against self-incrimination.
Need help with your case? Talk to a criminal defence lawyer at Alonso Sala.
Artificial intelligence and the technologies surrounding it have ceased to be a promise of the future and have become an everyday reality in the criminal courts. In this guide we bring together the five fronts where that impact is already tangible: cognitive attacks using generative AI, the threat of quantum computing to secrecy and data custody, the criminal implications of the European Digital Identity Wallet (eIDAS 2), the debate over harassment in the metaverse and the emergence of neuro-rights in the face of brain-based evidence. As criminal defence lawyers specialising in cybercrime, we analyse the risks each technology creates, who can be held liable and which lines of defence are taking shape.
1. Cognitive Attacks: Social Engineering in the AI Era
The year 2026 marks a turning point in cybercrime. The spread of multimodal AI models has allowed criminal organisations to scale their social engineering attacks to unprecedented levels of sophistication. We are no longer talking about simple phishing emails full of spelling mistakes, but about personalised cognitive attacks: cybercriminals no longer just attack systems, they attack the people operating them, exploiting their trust in what they see and hear.
The paradigmatic example is videoconference fraud: real-time voice and image cloning has broken the "proof of life" barrier, and cases are increasingly frequent in which financial executives authorise multi-million transfers after holding videoconferences with what they believe is their CEO, when it is in fact a hyper-realistic synthetic avatar.
The criminal law question splits into two levels:
- The deceived employee: is a victim of the deception, not its author, because fraud and disloyal administration are only punished where there is intent (Art. 12 CP). If they are investigated, the defence shows they were unaware of the fraud, and the technical sophistication of the deception helps to prove it.
- The company: is not criminally liable for having been defrauded. Art. 31 bis CP only attributes to it the offences in its catalogue committed in its name and for its benefit, and organisational failure is assessed within that framework. A lack of security measures over personal data has administrative consequences (GDPR); verification protocols against deepfakes are, above all, fraud prevention.
2. Quantum Computing: Encryption, Data Custody and Negligence
The risk that quantum computing may eventually break RSA keys makes it advisable to plan the migration to post-quantum cryptography. The risk is not only in the future: in attacks known as Harvest Now, Decrypt Later, encrypted data is stolen today to be decrypted tomorrow, once the technology allows it.
The legal dimension of this scenario revolves around the duty of custody, but the two planes should not be confused. It is the GDPR that requires "adequate security measures" (Art. 32 GDPR), and breaching that duty is penalised through administrative channels. There is no offence of negligent data custody: the offences against privacy require intent, and negligence is only punished where the law expressly provides for it (Art. 12 CP). A chief information security officer (CISO) answers, above all, in employment and compliance terms.
For professions bound by professional secrecy, the threat is qualitatively greater: the confidentiality promised today is only worth as much as the encryption protecting it tomorrow.
3. eIDAS 2: Digital Identity as a New Target of Crime
The full roll-out of the European Digital Identity Wallet concentrates the national ID, the driving licence and banking credentials in one official app. Bureaucracy is simplified, but a critical single point of failure is created for fraud.
Two behaviours concentrate the criminal risk:
- Digital identity theft: accessing someone else's Wallet without authorisation to sign a document can constitute an offence of document forgery (Art. 392 CP, or Art. 395 if the document is private and the aim is to cause harm) and, if it is used to defraud, fraud. Usurpation of civil status (Art. 401 CP) only arises where another person's identity is assumed in full; with the holder's consent, the classification depends on the case.
- Biometric phishing: cybercriminals are no longer after passwords, they are after the user's face. Through real-time deepfakes, facial biometrics are spoofed to authorise operations in the Wallet. For the victim, the burden of proof consists of showing that the biometric system failed.
4. Harassment in the Metaverse: an Offence Against Moral Integrity?
It seemed like science fiction, but it is a real legal debate: the question arises whether conduct such as "sexually assaulting" a person's avatar in an immersive virtual reality environment could amount to a criminal offence. Even without physical contact, it is being discussed whether the psychological impact and the humiliation could fall within an offence against moral integrity (art. 173 CP), possibly with a hate-based aggravating factor. It remains to be seen how the Spanish courts will respond to such cases.
The doctrinal foundation points to an underlying idea: in fully immersive environments (haptic VR), the avatar may not be a mere drawing, but a projection of the personality of the person controlling it. On that reading, attacking the avatar is attacking the dignity of the real person behind the headset.
At the precautionary level, virtual restraining orders are already being proposed: measures prohibiting the aggressor from connecting to the same servers or platforms as the victim, on pain of a breach offence. Classic geolocation is replaced by "IP-location" in immersive cyberbullying.
5. Neuro-Rights: Brain Evidence and the Right Against Self-Incrimination
Devices capable of reading brain waves and decoding intentions or memories are entering the consumer market and forensic laboratories. The question is the most intimate one possible: whether the brain is the last refuge of privacy beyond the reach of the law.
The battleground is the P300 test: an involuntary brain wave emitted milliseconds after recognising a familiar stimulus. If a suspect is shown the image of the murder weapon and their brain emits a P300, they know what it is, even if they verbally deny it. The prosecution could argue that this is not a "statement" protected by the right to remain silent, but physical biometric evidence, like a fingerprint or DNA.
The defence position is the opposite: extracting information from the brain without consent is an invasion of physical and moral integrity (art. 15 of the Spanish Constitution) and violates the core of the right against self-incrimination. Unlike a fingerprint, a thought is cognitive content. Chile was a pioneer in legislating neuro-rights; in Spain and Europe, the legal battle is just beginning, and scholars are calling for a kind of habeas mentem: no court order should be able to force the extraction of thoughts, memories or emotions by technological means.
Common Threads: Evidence, Liability and Defence
These five fronts share three features that define technology-related criminal litigation:
- Expert evidence is the centre of gravity. Proving that a video was an undetectable deepfake, that a biometric system failed or that a brain wave does not amount to a statement requires highly specialised technical expert reports on both sides of the proceedings.
- Criminal liability remains personal and intentional. The deceived employee is a victim; the company is only liable for the offences in its catalogue committed for its benefit (Art. 31 bis CP), and a CISO's security failings are dealt with in administrative or employment terms: technology changes the evidence, not the rules of attribution.
- Fundamental rights mark the limit. Moral integrity (art. 173 CP), physical and moral integrity (art. 15 of the Spanish Constitution) and the right against self-incrimination delimit how far technology may go as an investigative tool.
Anyone facing a criminal investigation in any of these scenarios — as a suspect or as a victim — must secure the preservation of digital evidence and a solid expert strategy from the outset. In a field where technology evolves faster than the law, the difference between a conviction and an acquittal is often decided by the technical quality of the evidence and the strength with which the constitutional limits on obtaining it are argued.
Need a criminal defence lawyer?
If you are facing a criminal matter involving new technologies, our team of specialist defence lawyers can help. Contact us for a case assessment.
Official text: article 173 of the Spanish Criminal Code (BOE)
Frequently asked questions
If an employee authorises a transfer deceived by a deepfake of an executive, are they criminally liable?
Not if they were deceived. Fraud and disloyal administration are only punished where there is intent (Art. 12 CP): whoever orders the transfer believing they are speaking to their executive is a victim of the deception, not its author, even if they were careless. If they are investigated, the defence shows they were unaware of the fraud, and the sophistication of real-time voice and video cloning helps to prove it.
Can a company be criminally liable for failing to protect itself against AI fraud?
Not for having been the victim of the fraud. A legal person is only liable for the offences in its catalogue committed in its name or on its behalf and for its direct or indirect benefit (Art. 31 bis CP), and being defrauded is not one of them. A lack of security measures may, however, lead to administrative penalties where personal data are affected (Arts. 32 and 83 GDPR) and to civil liability towards third parties. Verification protocols against deepfakes are, above all, fraud prevention.
Is it an offence to use another person's digital identity Wallet?
It can be. Accessing someone else's Wallet without authorisation to sign a document can constitute document forgery (Art. 392 CP, or Art. 395 if the document is private and the aim is to cause harm) and, if it is used to defraud, fraud; usurpation of civil status (Art. 401 CP) only arises where another person's identity is assumed in full. With the holder's consent, for example between spouses, it is neither automatically an offence nor ruled out: it depends on the facts and the intent.
Can harassing or assaulting an avatar in the metaverse be a crime?
It is an open legal debate. Even without physical contact, it is being discussed whether the psychological impact and humiliation of an immersive virtual assault could fall within an offence against moral integrity (art. 173 CP), possibly with a hate-based aggravating factor. Legal scholarship suggests that, in fully immersive environments, the avatar may be regarded as a projection of the real person's personality. Virtual restraining measures are already being proposed, prohibiting the aggressor from connecting to the same platforms as the victim.
Can a judge order a brain scan to find out whether a suspect recognises the murder weapon?
P300 technology detects an involuntary brain wave emitted upon recognising a familiar stimulus, and the prosecution could try to classify it as physical biometric evidence, like a fingerprint or DNA. The defence position is the opposite: extracting information from the brain without consent invades physical and moral integrity (art. 15 of the Spanish Constitution) and violates the core of the right against self-incrimination, because a thought is cognitive content, not a physical trace.
Do you need criminal defence in this area?
We are criminal defence lawyers specialising in cybercrime and technological criminal law. We act urgently to protect your rights.
This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.