In Europe, developing AI tools for forensic and security purposes involves more than technical development. It also means navigating a dense, rapidly evolving regulatory environment. For projects like DETECTOR, which aims to support law enforcement authorities and forensic experts in identifying and analysing synthetic media, this environment is not a peripheral concern but rather it shapes how tools are designed, tested and adopted. This article outlines how DIGINNOV’s policy mapping work supports DETECTOR’s responsible development and future uptake.
Why policy matters for innovation
Policy can shape innovation in two different ways. On the one hand, clear and proportionate rules can support responsible development. They can create trust, legal certainty and common standards, helping new technologies move from research to practical use. This is also reflected in the European Commission’s Better Regulation approach[1], which links simpler, coherent and technology-neutral rules to competitiveness and effective implementation. Responsible innovation frameworks similarly highlight the importance of aligning innovation processes with societal needs, public values and potential impacts[2].
On the other hand, policy can become a source of uncertainty when obligations are unclear, overlapping or difficult to apply in practice. This is increasingly relevant in the EU digital landscape, where several legal frameworks may apply to the same technology or dataset. A European Parliament study on the interplay between the AI Act and the EU digital legislative framework[3] highlights this issue in relation to instruments such as the AI Act, the GDPR, the Data Act and the Cyber Resilience Act.
The European Commission’s ongoing work on guidelines for the classification of high-risk AI systems under the AI Act[4] is another example of this evolving landscape. Even after the adoption of major regulatory instruments, further clarification may be needed to explain how rules apply in practice and to support consistent implementation across different sectors and use cases.
This challenge is not only European. Emerging technologies often develop faster than traditional regulatory processes. The OECD has stressed the need for anticipatory governance approaches[5] that can respond to the opportunities and risks created by emerging technologies before regulatory gaps become too large. At the same time, different approaches across jurisdictions may increase fragmentation, especially in the field of AI regulation, where national, regional and global policy choices interact with each other[6].
Even within the EU, uncertainty may arise from the way rules are implemented and enforced. Harmonised legal frameworks do not always remove differences in national interpretation or administrative practice, and this can create additional uncertainty for innovators working across borders[7].
This context is directly relevant for DETECTOR, whose forensic deepfake detection tools are expected to operate in sensitive investigative and judicial settings. Legal and policy requirements can therefore shape the project’s practical choices, from how datasets are built to how detection results are documented and explained.
DIGINNOV’s contribution to policy mapping
As leader of Task 6.4, DIGINNOV contributes to DETECTOR’s wider impact, policy-making and exploitation work. The task is designed to support the long-term uptake of DETECTOR’s results by looking at how the project’s tools and outputs can be adopted, scaled and integrated into EU forensic and law enforcement frameworks.
To make this work concrete, DIGINNOV started by mapping the policy and regulatory environment around DETECTOR. This was necessary to understand which rules may influence the project’s future use in practice, especially where tools are expected to interact with public authorities, forensic workflows, sensitive data or cross-border cooperation.
The first output is a structured regulatory database covering EU and national-level instruments relevant to DETECTOR across partner countries. The current mapping covers 47 EU-level instruments and 80 national-level instruments, including regulations, directives, decisions, international and forensic standards, national transpositions, sector-specific rules, soft law, strategies and codes of practice.
From this broader mapping, 21 priority instruments were selected for in-depth analysis. Each instrument is assessed by looking at its key provisions, its implications for DETECTOR and the risks that could arise if it is not properly taken into account. This helps build a common understanding of the regulatory environment and supports compliance-by-design across the project.
Preliminary findings: key policy areas for DETECTOR
The preliminary mapping suggested that not all policy instruments will affect DETECTOR in the same way. Some instruments mainly define the broader legal context, while others are more likely to shape concrete design and implementation choices.
The AI Act is one of the most relevant where DETECTOR tools may support the assessment of authentic, manipulated or synthetic evidence. Consideration of its requirements begins at the design and development stages, including the assessment of whether specific tools fall within the high-risk AI category, and compliance with obligations concerning technical documentation, transparency, risk management, accuracy, and human oversight.
Data protection rules raise a different set of issues. The GDPR and the Law Enforcement Directive may affect the use of videos, facial images, voice data and other personal or biometric data, especially in relation to training, testing and validation of AI systems. The applicable legal bases, safeguards, and compliance requirements may differ depending on whether such data are processed for research purposes or for operational law enforcement activities. The distinction between research use and operational use is therefore a relevant compliance boundary that may require careful attention as the project develops.
Rules on cross-border exchange of electronic evidence, the potential use of the e-CODEX system, and digital forensic standards may also shape how DETECTOR outputs are handled in forensic and legal contexts. For a project whose results are intended to support investigative or judicial processes, alignment with these frameworks is important to ensure that results are not only technically robust, but also procedurally reliable and operationally usable.
Next steps
Partners will extend the national-level analysis by identifying the instruments most relevant to their own jurisdictions, adding further detail to the EU-level mapping already carried out.
This combined mapping will allow the consortium to examine more precisely how specific policies may affect the project, providing a stronger foundation for defining the implications of these policies for DETECTOR and responding to them. The aim is to bring these findings together into a clear framework that can be shared with the European Commission and used to guide the project’s next policy and uptake activities.
[1] European Commission, Better Regulation, available at: https://commission.europa.eu/law/law-making-process/better-regulation_en
[2] OECD, Responsible Innovation, available at: https://www.oecd.org/en/topics/sub-issues/responsible-innovation.html
[3] European Parliament, Interplay between the AI Act and the EU digital legislative framework, 2025, available at: https://www.europarl.europa.eu/thinktank/en/document/ECTI_STU%282025%29778575
[4] European Commission / AI Office, Draft Commission guidelines on the classification of high-risk AI systems and stakeholder consultation on the Draft Guidelines on the classification of high-risk AI systems under Article 6 of the AI Act, 2026.
[5] OECD, Framework for Anticipatory Governance of Emerging Technologies, OECD Publishing, 2024, available at: https://www.oecd.org/en/publications/2024/04/framework-for-anticipatory-governance-of-emerging-technologies_14bf0402.html
[6] Oxford Law Blog, AI Regulation: The Politics of Fragmentation and Regulatory Capture, 2025, available at: https://blogs.law.ox.ac.uk/oblb/blog-post/2025/06/ai-regulation-politics-fragmentation-and-regulatory-capture
[7] Cambridge University Press / European Journal of Risk Regulation, AI at Risk in the EU: It’s Not Regulation, It’s Implementation, available at: https://www.cambridge.org/core/journals/european-journal-of-risk-regulation/article/ai-at-risk-in-the-eu-its-not-regulation-its-implementation/A9FD120F3EACE2C083048ABCBF96C0F6


