Chain of Custody

Chain of Custody

Chain of custody refers to the unbroken documentation of who held a piece of evidence or a data record and when, and what was done with it. It is meant to prove that nothing was swapped, altered, or secretly added along the way.

Chain of Custody roughly translates to “chain of possession” or “chain of safekeeping.” It refers to an unbroken record of who possessed an object or a file and when. Every handover is logged: date, time, person, purpose. The term originates from police work. If a pistol is found at a crime scene, it must later be provable in court that this is indeed the same pistol and that no one swapped it along the way. This very principle is now also being applied to digital data, to supply chains, and to AI systems.

Why a single gap in the chain renders everything worthless

A chain of evidence is only as strong as its weakest link. If the record is missing for three hours as to where a piece of evidence was located, a lawyer can attack exactly that point. He doesn’t need to prove that manipulation occurred. Reasonable doubt that it could have been possible is enough. That’s why evidence that was entirely sound in substance is regularly thrown out in court.

In the digital realm, the problem is bigger because files can be altered without leaving a trace. A photo can be edited without it showing in the image. With a pistol, tampering usually leaves marks; with a file, it doesn’t. The better AI tools become at faking images and audio recordings, the more important proof of origin becomes.

In business, too, this has financial consequences. Anyone claiming their coffee comes from fair-trade cultivation must be able to prove the chain from field to package. If a link is missing, the seal becomes vulnerable to challenge. Similar rules apply to AI models regarding training data: a company that cannot document where its data came from has a genuine problem when facing copyright lawsuits.

Logs, hash values, and sealed bags

In the classic case, one works with forms and sealed bags. Every person who takes over the piece of evidence signs with date and time. The seal is designed so that it cannot be opened without being noticed. If a gap appears in the form, it is immediately visible.

Digitally, hash values are the primary tool used for this. A hash is a kind of fingerprint of a file: a long string of characters computed from its content. Change even a single pixel of an image, and the result is a completely different hash. The hash is noted down right at the time of seizure. Later, anyone can recalculate whether the file is still the same.

Added to this are timestamps and digital signatures. A signature binds the hash to a specific person or device, similar to a forgery-proof signature. Some systems write these entries into a database where subsequent changes cannot be hidden. It’s important to note: none of this proves that the content is true. It only proves that it has remained unchanged since a certain point in time. This distinction is frequently confused.

From forensic medicine to provenance proof for AI images

The principle is most visible in IT forensics. When investigators seize a laptop, they make a bit-for-bit copy of the hard drive and work only with the copy. The original remains sealed. Every step performed on the copy is logged, so that no one can later claim in court that investigators added files.

In the AI world, the term currently comes up mainly in connection with media provenance. An industry standard called C2PA attaches invisible provenance data to photos and videos: which camera, which software, which editing steps. Major camera manufacturers and AI providers now support this. The goal is not to detect forgeries, but to make genuine material provably authentic.

In corporate disclosures, you’ll also come across this term in the context of supply chains and data protection audits. There, the question is whether a company can prove which data it received from whom and who was authorized to further process it. The European AI legal framework explicitly requires such documentation for high-risk applications. Anyone working with gaps here risks fines, not just bad press.

Related Products

Latest News

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.