//The Standard · v1.0
The Evidence-Grade AI Standard
A framework for producing AI-assisted investigative findings that survive a courtroom challenge. Eight pillars and a checklist, from a licensed investigator who builds the systems and validates the work.
By Matt Aubin, Founder, Southern Recon Agency and E3 Legacy Intel. CDFE, FBCI. Investigating since 2009. Published . Updated .
The AI is never the source of the finding. A qualified human is.
AI accelerates the work. A licensed, credentialed examiner sources it, verifies it, and stands behind every finding. Evidence-Grade AI is AI used that way, and documented so it can be proven. This is a professional framework and general information, not legal advice.
Authored by Matt Aubin, CDFE, FBCI. Founder, Southern Recon Agency and E3 Legacy Intel. Version 1.0, published July 9, 2026, last revised September 19, 2026.
//Why it exists
Why this Standard exists
AI is entering investigations and courtrooms faster than the rules governing it. Most AI used in investigative and legal work today is not built to be defended: it hallucinates, it relies on tools no one has validated, it leaves no record of how a result was produced, and it is used without disclosure or independent verification. When that work is challenged, it fails, and the case fails with it.
Proposed Federal Rule of Evidence 707 signals where this is going: machine-generated evidence offered without a sponsoring expert would have to meet the same reliability standard the courts already apply to expert opinion under Rule 702 and Daubert. The rule itself is still being written and its timeline is unsettled, but that is beside the point, because it only extends a standard that is already the law. Someone has to be able to show the machine's output is reliable. This Standard is that showing, written down and made repeatable.
Want your workflow checked against this Standard?
The signed AI evidence audit is that check, delivered as one document a firm can hand its insurer, renewed every year.
//The framework
The eight pillars
Each pillar states a principle, ties it to the reliability standard courts apply, and gives the practical requirement.
01
Competent Human Authority
The work is directed and owned by a qualified human, appropriately licensed or credentialed for the matter, who is accountable for every finding.
A named, qualified examiner supervises the workflow and signs off on the result. AI does not make judgment calls, legal determinations, or final findings on its own.
02· reliability: sufficient facts and data
Sufficient, Sourced Inputs
A finding rests on sufficient, identified, and lawfully obtained data, not on the model's training or its guesses.
Every input the finding depends on is identified and preserved. Data is lawfully sourced under the same licensing, privacy, and evidence rules that govern the work without AI. Prompts are captured, because in an AI workflow the prompt is part of the data.
03· reliability: reliable principles and methods
Reliable Method
The AI-assisted method is documented, explainable, and repeatable, not a black box.
The method is written down so another qualified examiner could follow it. The specific system and its version are recorded. Where reliability is not self-evident, it is supported by testing, validation, or accepted practice.
04· reliability: reliable application to the facts
Reliable Application
The method was actually applied correctly to the specific facts of this matter.
Outputs are checked against the underlying sources for this case, not accepted because the method is generally sound. Errors and limitations are noted rather than smoothed over.
05
The Human Verification Gate
No AI output becomes a finding until a qualified human has independently verified it against source evidence.
Verification is a distinct, documented step, not an assumption. Unverified AI output is treated as a lead, never as a conclusion. This is the single discipline that separates Evidence-Grade AI from everything else.
06
Chain of Custody and Provenance
The inputs, the process, and the outputs are preserved with a defensible record.
The record answers, for any finding: what data was used, what system and version produced the output, what steps were involved, who verified it, and when. Evidence and its metadata are preserved so the trail survives challenge.
07
Disclosure
AI's role is documented and disclosed where required, and never hidden or overstated.
The work product states how AI was used and what a human did. Claims are calibrated to what the method can support. Acceleration is not presented as human analysis, and a probability is not presented as a certainty.
08
Reproducibility and Audit
An independent examiner, given the record, could follow it and reach the same result.
The workflow is built to be audited. The signed AI evidence audit exists to validate that a firm's workflow and its people meet this Standard as models and rules change.
//The gate
The Evidence-Grade AI Checklist
Run this against an AI-assisted workflow, or against a specific finding, before it leaves the building. A “no” on any line is a defensibility gap to close.
- A named, qualified, appropriately licensed human directs the work and owns the finding.
- The AI made no judgment call, legal determination, or final finding on its own.
- Every input the finding depends on is identified and preserved.
- All data was lawfully sourced under the rules that govern the work without AI.
- The prompts and instructions given to the AI are captured.
- The method is documented well enough for another examiner to follow.
- The specific system and its version are recorded.
- Every AI output the finding relies on was independently verified against source evidence.
- Unverified AI output was treated as a lead, not a conclusion.
- There is a record of what data, what system, what steps, who verified, and when.
- The work product discloses how AI was used and what the human did.
- No claim overstates what the method can support.
- An independent examiner could reproduce the result from the record.
//Where it sits
How the Standard sits alongside NIST AI RMF, ISO/IEC 42001 and Rule 702.
It is narrower than all three, deliberately. Two of them govern how an organization manages AI. One of them is the law a finding is tested against. This Standard governs one thing: whether a single AI assisted finding can be defended by the person who signed it. Nothing here claims certification, conformity or alignment with any of the three.
The NIST AI Risk Management Framework
NIST AI 100-1, the Artificial Intelligence Risk Management Framework (AI RMF 1.0), published January 2023 by the National Institute of Standards and Technology at the United States Department of Commerce. It is organized around four functions: Govern, Map, Measure and Manage. In its own words it is intended to be voluntary, rights preserving, non sector specific and use case agnostic, and it carries no certification or conformity assessment scheme, so nobody is certified against it, including this Standard.
How they fit: the framework asks an organization to govern, map, measure and manage AI risk across everything it does. This Standard answers one question inside Measure and Manage, for one kind of output, the finding that leaves the building. A firm using the AI RMF and looking for what to actually check on an investigative finding can use the eight pillars for that. Read it at nvlpubs.nist.gov.
ISO/IEC 42001
ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, published 18 December 2023 by ISO and IEC. It is a management system standard: it sets requirements for establishing, implementing, maintaining and continually improving an AI management system inside an organization. An organization is certified to it by an accredited third party certification body, never by ISO itself, and ISO/IEC 42006:2025 sets the requirements for the bodies that do that auditing.
How they fit: 42001 governs the management system around AI. This Standard governs the artifact that leaves the building. They are not substitutes for each other in either direction. A firm can hold 42001 certification and still produce a finding nobody can defend, and a firm with no certificate at all can produce findings that survive a challenge. Neither this Standard nor the signed audit is a certification under ISO/IEC 42001, and none is claimed. The catalog entry is at webstore.iec.ch.
Federal Rule of Evidence 702
As amended effective December 1, 2023, Rule 702 requires the proponent to demonstrate to the court that it is more likely than not that the expert’s specialized knowledge will help the trier of fact, that what the expert offers is based on sufficient facts or data, that it is the product of reliable principles and methods, and that the expert’s opinion reflects a reliable application of those principles and methods to the facts of the case. The 2023 amendment added the more likely than not language and put the burden on the proponent.
How they fit: this is the only one of the three that is law, and this Standard is written backwards from it. Sufficient, Sourced Inputs answers 702(b). Reliable Method answers 702(c). Reliable Application answers 702(d). Rule 702 is also the standard proposed Rule 707 would extend to machine generated evidence, which is why the discipline is worth having before that rule lands. Read the rule at law.cornell.edu, and the dated status of Rule 707 is on the Rule 707 page.
One line to hand a procurement team: the Evidence-Grade AI Standard is a published written discipline, not an accredited standard. No body certifies against it, holding to it is not certification under NIST AI 100-1 or ISO/IEC 42001, and it is published in full on this page so anybody can read it and check work against it.
//Using it
How to use this Standard
Investigators & examiners
Adopt the pillars as your working discipline and the checklist as your pre-delivery gate.
Law firms & insurers
Require Evidence-Grade AI of the investigators and vendors whose AI-assisted work you rely on, and validate it before you build a case or a claim on it.
Vendors & builders
Design your systems so the record the Standard requires is produced automatically.
The Evidence-Grade AI Audit validates a firm’s workflow against this Standard. See also how to make your AI investigation survive Rule 707. The Standard will be versioned as the technology and the rules of evidence evolve.