External Expert Report on Operationalising rights-based governance for AI and LEAs

Our latest External Expert Report published under the Ethical, Legal and Societal Observatory is from Antonio Landi and it focuses on the operationalisation of rights-based governance in the area of artificial intelligence (AI) for law enforcement in the areas of intelligence-support and decision support.

We’re collecting feedback on this report through the EU Survey Platform, if you’d like to share your thoughts please click on the link below.

https://ec.europa.eu/eusurvey/runner/enact-report-feedback

Read the report: From Compliance to Trust: Operationalising rights-based governance for AI-enabled intelligence support technologies in the EU FCT domain

Executive Summary

The increasing adoption of Artificial Intelligence (AI)-enabled intelligence-support and decision-support technologies is transforming the European Fight against Crime and Terrorism (FCT) landscape. AI-powered analytics, Open-Source Intelligence (OSINT), multilingual content analysis, visual analytics, graph-based intelligence and social media monitoring are significantly enhancing investigative capabilities, cross-border cooperation and situational awareness. At the same time, these technologies raise critical ethical, legal and societal (ELS) challenges concerning the protection of fundamental rights, proportionality, transparency, accountability, bias mitigation, human oversight and public trust. Ensuring that these technologies remain both operationally effective and aligned with European democratic values requires moving beyond regulatory compliance towards a governance model capable of demonstrating trustworthy AI deployment throughout the entire operational lifecycle.

The Advanced Report examines how rights-based governance can be operationalised for AI-enabled intelligence-support and decision-support technologies used by Law Enforcement Authorities (LEAs) in FCT contexts. The report focuses on translating legal, ethical and societal requirements into measurable and operational safeguards applicable throughout the AI lifecycle, from research and piloting to operational deployment. Particular attention is devoted to AI applications supporting intelligence analysis, OSINT and social media monitoring, multilingual content analysis, visual analytics and network intelligence. The analysis combines the applicable EU legal framework with recognised European and international AI governance and risk-management methodologies.

The report addresses three interrelated research questions. First, which ethical, legal and societal risks are most relevant when AI-enabled intelligence-support technologies assist criminal investigations, intelligence analysis and cross-border cooperation?

Second, how can principles, regulatory requirements and governance measures – including legality, necessity, proportionality, non-discrimination, explainability, auditability, cybersecurity, data protection and meaningful human oversight – be translated into measurable operational safeguards capable of supporting trustworthy AI deployment?

Third, which governance mechanisms, implementation indicators and evidence-based validation approaches can assist LEAs, researchers and technology providers in demonstrating responsible AI deployment while ensuring compliance with European legal and ethical requirements?

To answer these questions, the report proposes a structured governance model organised around four complementary layers: (i) legal qualification and purpose limitation; (ii) fundamental rights and data protection impact assessment; (iii) AI governance, risk management and human oversight; and (iv) societal accountability through transparency, documentation, logging, redress mechanisms and independent review where appropriate. Building upon this framework, the report introduces a Safeguards Effectiveness Matrix that provides qualitative indicators, implementation criteria, and supporting evidence for assessing the maturity and effectiveness of each safeguard. Particular emphasis is placed on distinguishing technical risks (including bias, robustness, explainability, cybersecurity and data quality) from organisational and governance risks, such as unclear allocation of responsibilities, insufficient accountability, inadequate documentation, limited staff training, ineffective human oversight and the absence of continuous monitoring. The report argues that these organisational dimensions frequently represent the most significant obstacles to trustworthy operational deployment, even where technical solutions are available.

The proposed methodology combines regulatory analysis with evidence from representative operational scenarios that reflect realistic FCT use cases, enabling practical validation of the proposed governance model across diverse investigative contexts. The report also examines how safeguards can be monitored throughout the AI lifecycle using practical implementation indicators and governance evidence that support accountability, auditability and continuous improvement. By adopting a scenario-based and implementation-oriented perspective, the analysis aims to bridge the gap between regulatory obligations and day-to-day operational practice.

The outcome is a concise, policy-oriented and operationally relevant report that provides actionable recommendations for policymakers, LEAs, researchers and technology providers. The report explicitly complements existing ENACT analytical outputs by extending prior work from a governance implementation perspective. It also provides practical governance guidance, implementation checklists and recommendations to support the trustworthy adoption of AI-enabled intelligence technologies across the European security ecosystem. Ultimately, the report demonstrates that effective security, operational efficiency and the protection of fundamental rights should not be regarded as competing objectives but as mutually reinforcing conditions for lawful, accountable, trustworthy and socially legitimate AI deployment within European law enforcement.