Automated cybercrime monitoring systems in view of legal restrictions
Keywords:
Artificial Intelligence, Cybercrime Monitoring, Computational Law, Compliance-by-design, Deterministic Legal Verification, Machine-readable LawAbstract
The inclusion of Legal Compliance in Cybercrime Monitoring Systems through Deterministic Verification Using Executable C–P–L Rules
This study introduces and experimentally validates a legally-informed ACMS that incorporates deterministic legal verification into the AI-based decision making process via executable Condition – Permission – Limitation (C-P-L) rules. We combine doctrinal legal analysis with the formalization of these rules computationally, machine learning, and deterministic compliance verification. In addition, we evaluate our method comparatively under three different regulatory configurations. Our methodology is evaluated on a controlled dataset of 18,500 structured cyber events, and forty-two operationally defined legal rules. The integrated ACMS achieved an F1-score of 89.2%, compared with 91.4% for the standalone AI subsystem, while its accuracy was 89.8% compared with 91.6% for the baseline AI subsystem. The observed differences reflect the addition of deterministic legal verification to the end-to-end decision-making workflow rather than modification of the underlying AI model. The compliance control also enforced mandatory manual review when the operational decision was determined to be non-compliant based upon the encoded legal rules. In addition, cross-jurisdictional testing demonstrated that the regulatory configuration used to determine which legal rules were applied could be changed by simply modifying the executable legal rules, and not by altering the base AI model. This research has shownб that it is possible to develop cybercrime monitoring systems with computational law, artificial intelligence, and cybersecurity governance by design as an alternative for legally compliant cybercrime monitoring systems.
Downloads
References
ALLAHRAKHA, N. “Legal frameworks for AI-driven cybercrime prevention”. Uzbek Journal of Law and Digital Policy, v. 2, n. 1, 2024, pp. 1-24. https://irshadjournals.com/index.php/ujldp/article/view/253
ATKINSON, K., BENCH-CAPON, T. and BOLLEGALA, D. “Explanation in AI and law: Past, present and future”. Artificial Intelligence, v. 289, 2020, Article 103387. https://doi.org/10.1016/j.artint.2020.103387
AVGERINOS LOUTSARIS, M. “Mapping the European Legislation Identifier (ELI) and Akoma Ntoso ontologies for legal data interoperability”. ACM Digital Library, 2023, pp. 41-53. https://doi.org/10.1145/3614321.3614327
BOROVYK, A., SHYRA, O., and KRAVCHENKO, O. “Criminal law aspects of financial security of a state”. Baltic Journal of Economic Studies, v. 11, n. 1, 2025, pp. 221-230. https://doi.org/10.30525/2256-0742/2025-11-1-221-230
BUÇAJ, E., and THAQI, A. “Global regulation of cybercrime through international law and cyberconventions”. Criminology, v. 7, 2025, pp. 155-170. https://doi.org/10.18716/ojs/krimoj/2025.1.9
CALIFORNIA PRIVACY RIGHTS ACT. CPRA – text of the California Privacy Rights Act. 2020 Available at: https://www.caprivacy.org/cpra-text/ (accessed on 25 May 2026).
CMS Expert Guide to Data Protection and Cyber-Security Laws: Ukraine. Law of Ukraine “On Personal Data Protection” No. 2297-VI 2025. Available at: https://cms.law/en/int/expert-guides/cms-expert-guide-to-data-protection-and-cyber-security-laws/ukraine?utm_source=chatgpt.com (accessed on 25 May 2026).
CONG, W., HARVEY, C., RABETTI, D., and WU, Z-Y. “An anatomy of crypto-enabled cybercrimes”. Management Science, v. 71, n. 4, pp. 3622-3633. https://doi.org/10.1287/mnsc.2023.03691
COUNCIL OF EUROPE. Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108+) (CETS No. 223). 2018. Available at: https://www.coe.int/en/web/data-protection/convention108-and-protocol (accessed on 25 May 2026).
COUNCIL OF EUROPE. Convention for the protection of individuals with regard to automatic processing of personal data (Convention 108+). 2022. Available at: https://rm.coe.int/16802fa3a3 (accessed on 25 May 2026).
COUNCIL OF EUROPE. Convention on cybercrime (ETS No. 185). Available at: https://www.coe.int/en/web/cybercrime/the-budapest-convention (accessed on 25 May 2026).
COURT OF JUSTICE OF THE EUROPEAN UNION. Case C-634/21, SCHUFA Holding AG (Scoring), EU:C:2023:957. 2023.Available at: https://curia.europa.eu (accessed on 25 May 2026).
COURT OF JUSTICE OF THE EUROPEAN UNION. Case C-203/22, Dun & Bradstreet Austria, EU:C:2025. 2025. Available from: https://curia.europa.eu (accessed on 25 May 2026).
DLA PIPER. Data protection laws of the world. 2026. Available at: https://www.dlapiperdataprotection.com/?t= (accessed on 25 May 2026).
EUROJUST. Cybercrime judicial monitor. 2025. Available at: https://www.eurojust.europa.eu/sites/default/files/assets/files/cybercrime-judicial-monitor.-issue-10.pdf (accessed on 25 May 2026).
EUROPEAN COMMISSION. Ethics guidelines for trustworthy artificial intelligence. Brussels: High-Level Expert Group on Artificial Intelligence, 2019. Available at: https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai (accessed on 25 May 2026).
EUROPEAN COMMISSION. Shaping Europe's digital future. 2024. Available at: https://digital-strategy.ec.europa.eu (accessed on 25 May 2026).
EUROPEAN COMMISSION. White Paper on Artificial Intelligence: A European Approach to Excellence and Trust COM(2020) 65 final. 2020. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52020DC0065 (accessed on 25 May 2026).
EUROPEAN COMMISSION FOR DEMOCRACY THROUGH LAW (VENICE COMMISSION). Rule of Law Checklist (CDL-AD(2016)007). 2016. Available at: https://www.venice.coe.int (accessed on 25 May 2026).
EUROPEAN COURT OF HUMAN RIGHTS. Big Brother Watch and Others v United Kingdom, Applications Nos. 58170/13, 62322/14 and 24960/15, Grand Chamber, Judgment of 25 May 2021. 2021. Available at: https://hudoc.echr.coe.int (accessed on 25 May 2026).
EUROPEAN DATA PROTECTION BOARD. Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement. 2024. Available at: https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-052022-use-facial-recognition-technology-area_en (accessed on 25 May 2026).
EUROPEAN PARLIAMENT and COUNCIL OF THE EUROPEAN UNION. Regulation (EU) 2022/2065 on a single market for digital services (Digital Services Act). 2022. Available at: https://digital-strategy.ec.europa.eu/en/policies/digital-services-act (accessed on 25 May 2026).
EUROPEAN UNION. Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). 2024. Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj (accessed on 25 May 2026).
EUROPEAN UNION. Convention on Cybercrime — EUR-Lex Summary. 2023. Available at: https://eur-lex.europa.eu/EN/legal-content/summary/convention-on-cybercrime.html (accessed on 25 May 2026).
EUROPEAN UNION. Directive (EU) 2022/2555 of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union (NIS2 Directive). 2022. Available at: https://eur-lex.europa.eu/eli/dir/2022/2555/oj (accessed on 25 May 2026).
EUROPEAN UNION. Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). 2016. Available at: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (accessed on 25 May 2026).
EUROPEAN UNION. Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). 2024. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj (accessed on 25 May 2026).
EUROPEAN UNION. Charter of Fundamental Rights of the European Union. 2012. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12012P/TXT (accessed on 25 May 2026).
EUROPEAN UNION AGENCY FOR CYBERSECURITY (ENISA). ENISA Threat Landscape 2025. Luxembourg: Publications Office of the European Union, 2025. Available at: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025 (accessed on 25 May 2026).
EUROPEAN UNION AGENCY FOR FUNDAMENTAL RIGHTS (FRA). Getting the future right – artificial intelligence and fundamental rights. 2024. Available at: https://fra.europa.eu (accessed on 25 May 2026).
FLORIDI, L. and COWLS, J. “A unified framework of five principles for AI in society”. Harvard Data Science Review, v. 1, n. 1, 2019, pp. 1-14. https://doi.org/10.1162/99608f92.8cd550d1
FORCEPOINT. Tracking global data protection laws in 2026. 2026. Available at: https://www.forcepoint.com/blog/insights/tracking-global-data-protection-laws-2026 (accessed on 25 May 2026).
FUTANE, S. S., PATIL, P., and NAGRALE, N. “Adaptive multi-model cybercrime identification, prediction using machine learning, and explainable AI”. International Journal for Research in Applied Science and Engineering Technology, v. 13, n. 8, 2025, pp. 2113. https://doi.org/10.22214/ijraset.2025.73926
N-LAWS. Privacy & Data Protection Laws 2025: The definitive global data protection guide. 2025. Available at: https://n-laws.com/privacy-data-protection-laws-2025-the-definitive-global-data-protection-guide/ (accessed on 25 May 2026).
NISHA, M. P. “Dark web guardian: Real time threat detection and analysis”. International Scientific Journal of Engineering and Management, v. 4, n. 5, 2025, pp. 1-7. https://doi.org/10.55041/isjem03502
OASIS. LegalRuleML Core Specification Version 1.0. 2025. Available at: https://docs.oasis-open.org/legalruleml/legalruleml-core-spec/v1.0/csprd01/legalruleml-core-spec-v1.0-csprd01.html (accessed on 25 May 2026).
OECD. OECD Principles on Artificial Intelligence. 2024. Available at: https://oecd.ai/en/ai-principles (accessed on 25 May 2026).
PALMIRANI, M. “A smart legal order for the digital era: A hybrid AI and dialogic model”. Rivista Italiana di Informatica e Diritto, 2023, pp. 633-655. https://doi.org/10.1415/105387
PARK, H., and HONG, S. “Germany’s online search and IT fundamental rights”. Korean Constitutional Law Association, v. 29, n. 3, 2023, pp. 81-123. https://doi.org/10.35901/kjcl.2023.29.3.81
PEOPLE’S REPUBLIC OF CHINA. Personal Information Protection Law (PIPL). 2021. Available from: https://digichina.stanford.edu/work/translation-personal-information-protection-law-of-the-peoples-republic-of-china-effective-nov-1-2021/ (accessed on 25 May 2026).
PUBLICATIONS OFFICE OF THE EUROPEAN UNION. Cybercrime judicial monitor: EU AI act (Regulation (EU) 2024/1689). 2025. Available at: https://op.europa.eu/en/publication-detail/-/publication/c4ead02c-5aec-11f0-a9d0-01aa75ed71a1/language-en (accessed on 25 May 2026).
SARTOR, G. Legal reasoning: A cognitive approach to the law. Dordrecht: Springer, 2005.
SHARMA, V. “Artificial intelligence in cybercrime prevention, detection & investigation: A legal perspective”. VIDHIGYA the Journal of Legal Awareness, v. 19, n. 1-2, 2024, pp. 34-38. https://doi.org/10.5958/0974-4533.2024.00004.4
SIMBOLON, N. Y. “Ancaman cybercrime di Indonesia: Tinjauan sistematis dan peran cybersecurity pada e-commerce dalam hukum pidana”. Jurnal Sosial Humaniora Dan Pendidikan, v. 4, n. 2, 2025, pp. 815-825. https://doi.org/10.55606/inovasi.v4i2.4425
STUPNYK, Y. V., and KHOMA, O. I. “Methodological principles of forming a comprehensive system of combating crime in the activities of law enforcement agencies”. Analytical and Comparative Jurisprudence, v. 2, n. 3, 2025, pp. 475-481. https://doi.org/10.24144/2788-6018.2025.03.2.76
SYTNYK, G., ZUBCHIK, O., and OREL, M. “Conceptual Understanding of the features of management of innovative development of the state in modern conditions”. Science and Innovation, v. 18, n. 2, 2022, pp. 3-15. https://doi.org/10.15407/scine18.02.003
TAYLOR WESSING. Interoperable Europe act published in official journal. 2024. Available at: https://www.taylorwessing.com/de/insights-and-events/gdh-latest-news (accessed on 25 May 2026).
UNITED KINGDOM. Data (Use and Access) Act 2025. 2025. Available at: https://www.legislation.gov.uk/ukpga/2025/18/contents/enacted (accessed on 25 May 2026).
UNITED NATIONS OFFICE ON DRUGS AND CRIME. United Nations Convention against Cybercrime. 2024. Available at: https://www.unodc.org/unodc/en/cybercrime/ad-hoc-committee.html (accessed on 25 May 2026).
VERKHOVNA RADA OF UKRAINE. On protection of personal data (Law of Ukraine No. 2297-VI). 2010. Available at: https://zakon.rada.gov.ua/go/2297-17 (accessed on 25 May 2026).
ZAKHAREVYCH, R. V. “Implementation of foreign experience into Ukrainian legislation on combating cybercrime”. Analytical and Comparative Jurisprudence, v. 2, n. 3, 2025, pp. 372-376. https://doi.org/10.24144/2788-6018.2025.03.2.60
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Ivo Svoboda, Serhii Hermanov, Olesia Urlapova, Ihor Fedchak, Oleh Zachek

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Those authors who have published with this journal, accept the following terms:
The authors cede all their copyrights to the magazine Cadernos de Dereito Actual, which will be in charge of disseminating and always quoting the author.
The authors agree not to send the article or publish it in another magazine.
The authors are allowed and recommended to disseminate their work through the Internet (e.g., in institutional telematic archives or on their website) before and during the submission process, which can produce interesting exchanges and increase the number of citations of the published work, provided that reference is made to Cadernos de Dereito Actual.
All contents published in the magazine are protected under a "Creative Commons - Attribution - Non-Commercial" license. Everyone has the right to freely access the contents of the magazine.
