Decisions about how digital investigations get done are increasingly made by people who have never worked one. When those decisions go wrong, the cost lands on defendants, victims and anyone whose future turns on what an examiner finds.
Few people in the field have pushed back on that arrangement longer than Brett Shavers. A Marine at 17, he spent about a decade in law enforcement, much of it undercover, before moving into digital forensics and incident response, the field insiders call DFIR. He wrote Placing the Suspect Behind the Keyboard: DFIR Investigative Mindset. In a recent article, he put the problem plainly: “Digital investigations do not succeed or fail on an administrative spreadsheet. They succeed or fail at the scene, in the lab, during the investigation, and in the courtroom.”
The people making those decisions, he wrote, “see case counts, turnaround times, and budget lines.” What they do not always see is “inaccessible evidence, broken handoffs, unreasonable requests, tool limitations, staffing gaps, training issues, or the difficulty of defending technical findings in court.” And when practitioners stay silent, “non-practitioners fill that gap with assumptions and those assumptions become policies, purchasing decisions, staffing models, and procedures that practitioners are then expected to work around.”
The purchasing decision on the table now is bigger than any staffing model. It is artificial intelligence, and it is arriving inside the tools that produce what courts treat as evidence.
An Investigative Mindset Is Not A Software Feature
Shavers’ argument is that digital forensics is an investigative discipline before it is a technical one. A forensic tool can parse a phone or index a hard drive. It cannot decide what question the case turns on. Shavers’ book is about the part of the job that does not come in an installer: thinking like a detective, following a person rather than an artifact, treating every finding as something that must survive cross-examination. Tools are only as effective as the investigative mindset behind them.
That sounds obvious until you understand what it collides with. Shavers has spent years warning about button pushing, where an examiner runs the tool, accepts the output and calls it an examination. His recent writing tracks the same concern into the AI era.
AI In Forensic Tools Is Arriving Faster Than Anyone Can Validate It
The push is industry-wide. Forensic software vendors are adding AI assistants, natural language search and automatic evidence summaries across their product lines. Because of ever-increasing amounts of data to be analyzed, AI will have its place in digital forensics. But that place must be decided by practitioners.
Magnet Forensics unveiled Magnet AI this spring, an engine that surfaces artifacts in seconds and writes investigative summaries from the evidence. Its own framing is careful: the system produces “investigative leads” backed by citations, it says, and leaves verification and decision making “firmly in the hands of human judgment.”
Shavers has been making the case for that caution in talks on AI since before most examiners had touched the technology, asking whether AI in forensics is a black box or a tool an examiner can verify. The forensic problem underneath is old and unglamorous: repeatability. A finding another examiner cannot reproduce from the same data is not a finding. An AI model that answers the same question differently on two runs sits awkwardly inside that rule. And an AI output is a probability dressed up as an answer. Probability is not proof.
In most forensic disciplines, the thing being examined holds still. A collapsed building fails by the same physics every year, and the methods mature around a subject that does not move. Digital evidence never holds still: phones, platforms and file formats change constantly, and examiners advance with them. Digital forensics may also be the only forensic discipline where the evidence itself might be the work of a machine rather than a person. To a budget line, AI looks like the fix for that complexity. From inside the work, it is a second machine inside a question that is already about machines.
The cost of skipping the verification step is already on the record. An AI facial recognition match put a Tennessee grandmother in jail for five months for a fraud she could not have committed; the bank records nobody pulled showed she was home the whole time. An AI report-writing tool in Utah turned background movie audio into an official police report claiming an officer had transformed into a frog. The absurd error got caught. The subtle ones are the worry, because they read exactly like the truth.
I have spent more than 17 years in digital forensics, and the rule has never changed: the tool’s output is where the work starts. Findings must be verified against the device and the records around it first. AI does not change that rule. It just makes unverified output more fluent.
Where Digital Investigations Break Down: Asking The People With Boots On The Ground
His spreadsheet article doubled as an announcement: Shavers is partnering with Magnet Forensics on an independent research study to identify where digital investigations are breaking down across public safety, built on a survey of law enforcement leaders, examiners, investigators and prosecutors. The goal, in his words, is change guided “based on what happens in the field, not what someone thinks is happening from a spreadsheet.” He concludes, “If we want better decisions, the people doing the work must help shape them.”
He is right. The measure of a digital investigation is whether it reaches the truth, and truth has no cost-effective substitute. Let economics lead and the field gets built to the lowest common denominator: tools simple enough that pushing a button passes for expertise.
Magnet’s software runs in my own lab, so read this as a customer’s view as much as a columnist’s. A vendor going to practitioners first, asking where investigations break down before the roadmap hardens, is sequencing events in order. It is the right way around, and rarer than it should be. What matters now is what happens to the answers.
AI is going into forensic tools regardless. The open question is who decides how, and on whose experience. Every machine-generated summary and AI-ranked lead ends the same way, with a human being raising a right hand and swearing to findings that someone’s life may turn on. The software takes no oath. If decisions about that work keep drifting toward people at spreadsheet distance from it, the mistakes will not land on them. They will land on the next wrongly accused defendant, the next victim who never sees justice and the next business that pays for an answer nobody verified.


