Skip to content
Flag_of_Finland.svg

Finland

Tools Tools
AinoAid chatbot | FERMI | RANKKA | Specialised systems
Tasks Tasks
Administrative support | Case management | Data review and analysis | Evidence review and analysis | Legal research, analysis and drafting support | Predictive analytics
Users
Law enforcement | Defence | Victims
Scope Scope
Nationwide
Training Training
No mandatory or systematic training
Regulation Regulation
No dedicated legislation for AI in criminal proceedings. EU AI Act applies, as well as the GDPR and LED, NIS2 cybersecurity legislation, as well as criminal procedure and human rights laws
Cases Cases
In 2021, Finland’s Deputy Data Protection Ombudsman issued a statutory reprimand to the National Police Board after the National Bureau of Investigation ran an undisclosed trial of Clearview AI’s facial recognition software to identify sexual abuse victims
Insight Insights
Since 2019, Finland’s Passenger Name Record system has used AI to flag individuals potentially linked to terrorism or organised crime — including people not previously under suspicion — based on travel-pattern analysis, with ‘risk indicators’ triggering mandatory manual review by officers
Information uploaded as at July 2026

AT A GLANCE

AI use in Finnish criminal justice is limited and concentrated in law enforcement — including a Passenger Name Record system flagging terrorism/organised crime risk (with mandatory human review), the FERMI disinformation-detection project, and RANKKA for suspicious financial transactions. Facial recognition has been tightly restricted since a 2021 unlawful Clearview AI trial. Prosecutors and courts report no AI use; some defence lawyers use commercial AI tools for research and e-discovery, and a chatbot (AinoAid) supports domestic violence victims. Training remains non-mandatory.

There is no dedicated framework governing AI in criminal proceedings, and its use is addressed through EU law and general domestic legislation. The EU AI Act is the primary framework, implemented via the Act on the Supervision of Certain AI Systems (2025), with Traficom acting as single point of contact and a National Sanctions Board empowered to fine above €100,000. This sits alongside the GDPR, LED, and Cyber Security Act (NIS2). No AI-specific guidelines exist for practitioners, and AI-generated materials are generally admissible under Finland's ‘Free Theory of Evidence.’

USE

As at July 2026, AI deployment in criminal proceedings in Finland is limited and focused on law enforcement.

Law enforcement

Predictive analytics

In 2019, Finland’s Act on the Use of Passenger Name Record Data (657/2019) implemented an AI-assisted system used to analyse ‘Passenger Name Record’ data. This system analyses traveller patterns to identify individuals who may be involved in terrorist offences or serious organised crime, even if they were not previously under suspicion. The system identifies ‘risk indicators’ that trigger manual review by officers in the Passenger Information Unit.

The Police University College participated in the EU-funded FERMI (Fake News Risk Mitigator) project (2022–2025), a three-year initiative involving 17 European organisations. This AI-based tool identifies the spread and the speed at which disinformation (deliberately false information) occurs online and assesses its potential to incite crime or social unrest. The tool provides authorities with proposals for countermeasures, such as increasing police presence in specific geographic areas, although the final decision-making remains human-led.

Data review and analysis

The deployment of facial recognition technology in Finland has been subject to strict legal oversight. In early 2020, the National Bureau of Investigation (NBI) conducted a trial of the Clearview AI software—a service that matches photos against a vast database scraped from the internet—to identify victims of sexual abuse. This trial was found to be illegal by the Deputy Data Protection Ombudsman, because it was initiated without a Data Protection Impact Assessment or the approval of the data controller, and it involved the processing of sensitive biometric data without a specific legal basis. Since this incident, the use of facial recognition technology by Finnish law enforcement has been relegated to controlled, legally sanctioned environments under the Data Protection Act for Authorities in Criminal Matters (discussed below).

Finland’s National Forensic Laboratory, housed at the National Bureau of Investigation, relies heavily on automation and digital information systems for analysing over 100,000 samples per year. Laboratory statements are used directly in criminal proceedings and have a direct impact on the legal rights of citizens.

The NBI leverages AI for complex financial investigations through projects like RANKKA, which uses machine learning (a subset of AI that enables systems to learn from data) to identify suspicious transactions related to money laundering and terrorist financing.

The Finnish police launched the Vitja project in 2009 to replace ageing IT systems and create a unified platform that combines data collected on Finnish citizens, with the goal of improving the authorities’ efficiency. However, the project struggled with underestimated timelines, insufficient planning and escalating costs, causing repeated delays. In 2023, Vitja was officially discontinued after it became clear that its goals could not be achieved within the available resources.

Futuristic Data Display

Prosecutors

As at July 2026, there are no reported examples of prosecutors in Finland making use of AI. Though there have been digitisation efforts, including a ‘Material Bank’ project (the AIPA system) to function as a centralised system allowing prosecutors to manage cases entirely electronically, these systems do not yet incorporate AI.

Courts

As at July 2026, there are no reported examples of courts in Finland making use of AI.

Defence

As at July 2026, there are limited reported examples of defence counsel in Finland making use of AI. However, most defence counsel operate primarily through private law firms, some are reported to have independently adopted AI tools.

Legal research, analysis and drafting support

Finnish lawyers can use commercial generative AI tools for case law research. The Code of Conduct for Attorneys-at-Law emphasises that attorneys at law are obligated to maintain and develop their professional skills and avoid unnecessary expenses.

Evidence review and analysis

In complex criminal cases involving large volumes of digital evidence, the defence uses AI-powered ‘E-Discovery’ tools to identify exculpatory materials (evidence that tends to prove the innocence of the accused). While there are no reports of tools developed specifically by Finnish companies or for use in Finland, lawyers in Finland have access to and make use of the wide array of E-Discovery tools available on the market.

Victims

Finnish law treats the victim as the injured party (asianomistaja), a formal procedural status that attaches a range of active rights across all stages of the process. The key statutory sources are the Criminal Procedure Act (laki oikeudenkäynnistä rikosasioissa, 689/1997, ‘CPA’) and the Criminal Investigation Act (esitutkintalaki, 805/2011, ‘CIA’).

Stage

Nature of Standing

Key Provisions

Pre-trial investigation

Direct – right to information, to request measures, to attend interviews

CIA Ch. 3 s. 7; Ch. 4 ss. 10, 15; Ch. 7 ss. 13, 17, 19; Ch. 10 s. 1

Trial

Party status, right to endorse and adjust charges (in specific and limited cases), present evidence, make submissions

CPA Ch. 1 s. 14(3); Ch. 6 s. 7(1); Ch. 3 ss. 9–10

Civil Claim

Direct – through prosecutor or independently

CPA Ch. 3 ss. 9–10; Ch. 11 s. 10

Appeal

Direct right of appeal (except in favour of defendant)

CPA Ch. 1 s. 14(3)

Where prosecution waived

Subsidiary – private prosecution available

CPA Ch. 1 ss. 14–15; Ch. 7 ss. 1–22

Administrative support

The IMPROVE project, which includes participation from the Finnish Police, has developed an AI-based AinoAid chatbot specifically designed to help victims of domestic violence. This service uses natural language processing (technology that allows computers to understand and interpret human language) to provide victims with tailored legal and safety information. In 2025, the European Commission recognised this as the best innovation of the year for improving access to justice for vulnerable populations.

TRAINING

As at July 2026, there is no mandatory AI-specific training for criminal justice practitioners in Finland. The Finnish Data Protection Ombudsman, however, released guidelines for ensuring lawful use of personal data in AI systems, emphasising risk assessment, security measures, legal basis selection, and compliance with GDPR principles.

In addition, there are ongoing initiatives to improve capacity-building possibilities. The Police University College has participated in the EU-funded FERMI (Fake News Risk Mitigator) project, which developed educational content on the ethical use of AI in policing, specifically addressing how AI can be used securely and responsibly and the ethical questions raised by AI-based tools for law enforcement.

Moreover, in October 2024, the Ministry of Finance formed a co-operation group to unify generative AI pilot projects and share best practices across government ministries.

REGULATION

As at July 2026, Finland does not have a dedicated legislative framework governing the use of AI in criminal proceedings specifically. Instead, its use is regulated through a combination of EU law—principally the EU AI Act—and existing domestic legislation on data protection, cybersecurity and criminal procedure, which may be construed to apply to AI tools even without express reference to them.

Hacker at Work

AI regulations

EU AI Act (Regulation (EU) 2024/1689)

The EU AI Act is a key part of the legal framework regulating the use of AI across the EU. It entered into force on 1 August 2024, and sets out a comprehensive legal framework aiming to ‘guarantee safety, fundamental rights and human-centric AI’. The EU AI Act is being phased between 2025 and 2030. Finland is obliged to implement and comply with the provisions of the Act, which set out a harmonised legal framework for ‘the development, the placing on the market, the putting into service, and the use’ of AI systems across the EU.

The EU AI Act introduces a risk-based approach, categorising AI systems into four levels of risk, banning ‘unacceptable-risk’ systems, and imposing strict obligations on high-risk systems. The rules on prohibited uses have applied since 2 February 2025, the rules on general-purpose AI models and the designation of competent national authorities have applied since 2 August 2025 while obligations related to the use of high-risk AI systems are being introduced later.

The EU AI Act includes explicit references to AI systems related to the administration of justice, and to criminal proceedings. These are mainly classified as high-risk given ‘their potentially significant impact on ... the rule of law, individual freedoms ... the right to an effective remedy and to a fair trial’ as well as the right to defence and the presumption of innocence, particularly if ‘such AI systems are not sufficiently transparent, explainable [or] documented’. The Act highlights the potential ‘difficulty in obtaining meaningful information on the functioning of those systems and the resulting difficulty in challenging their results in court, in particular by natural persons under investigation’.

EU AI Act’s risk-based approach

Unacceptable risk (prohibited)

AI systems posing ‘a clear threat to safety, livelihood and rights of people’ are prohibited. This includes uses in law enforcement and criminal justice such as (1) assessing or predicting an individual’s criminal offence risk ‘based solely on the profiling of a natural person or on assessing their personality traits and characteristics’; (2) undertaking ‘untargeted scraping of the internet or CCTV footage’ to build or expand facial recognition databases; and (3) deploying ‘real-time remote biometric identification systems in public spaces or biometric categorisation to infer race, religion or other protected characteristics’ although narrow exceptions exist.

High-risk (subject to strict obligations)

AI systems that ‘can pose serious risks to health, safety or fundamental rights’ are deemed ‘high-risk’ under Article 6. This includes the use of AI (1) to assess the risks of persons ‘becoming the victim of criminal offences’, (2) to assess the risk of persons ‘offending or re-offending’ in certain circumstances and to profile persons during investigations or prosecutions, (3) to evaluate the reliability of evidence ‘in the course of investigations or prosecution of criminal offences’, (4) for remote biometric identification, biometric categorisation in certain circumstances, and emotion recognition, and (5) ‘to assist judicial authorities in researching and interpreting facts and law’ and ‘applying the law to the facts’ (emphasis added). AI systems used for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases are not considered high-risk.


High-risk AI systems are subject to strict obligations for developers, providers and users, including risk assessment; human oversight, the use of high-quality training data and ensuring explainability, accuracy, robustness and cybersecurity. When AI systems assist judicial decision-making, the persons concerned must be informed about the use of AI systems, and be provided with explanations about the role of AI in the decision-making process.

Limited risk (subject to transparency obligations)

This category refers to the risk associated with a need for transparency around the use of AI such as chatbots. Specific disclosure obligations apply for this category.

Minimal risk (no requirements)

Minimal risk or no risk AI systems are not subjected to any requirements.

Articles 51-56 of the EU AI Act establish a specific regime for ‘general-purpose AI models’, defined in Article 3(63) as models trained on large datasets capable of performing a wide range of tasks. They typically include large language models (LLMs) that can be integrated into legal research platforms, drafting tools or judicial support systems. Providers of such models must:

  • maintain technical documentation;
  • provide information to downstream integrators;
  • comply with EU copyright law; and
  • publish a summary of training data.

Under Articles 55-56, additional obligations apply to general-purpose AI models presenting systemic risk, including risk assessment, mitigation measures and incident reporting. The framework is particularly relevant to the judicial sector given that courts and prosecutors may rely on external LLM-based tools rather than developing their own systems.

In terms of governance and enforcement of the EU AI Act, the Act adopts a two-pronged approach. At the EU-level, according to Articles 64-69 of the AI Act, the AI Office of the European Commission and an AI Board (Article 65) are the main actors. The AI Office enjoys enforcement powers with respect to obligations of general-purpose AI models (Article 88 et seqq.). The AI Board assists the European Commission and the member States in facilitating coherent applications of the AI Act, and therefore contributes to the coordination among national authorities (Article 66(a)).

Finland has supplemented the EU AI Act (which entered into force in August 2025) through the Act on the Supervision of Certain AI Systems (which entered into force on 1 January 2026). The Act establishes a decentralised model with several market surveillance authorities and designating the Finnish Transport and Communications Agency (Traficom) as the single point of contact. A new National Sanctions Board will impose administrative fines above EUR 100,000. A second stage, addressing AI regulatory sandboxes and a national register for high-risk AI systems related to critical infrastructure, is expected to enter into force by 2 August 2026.

Several non-binding guidelines have already been published by the European Commission to provide further directions when implementing the AI Act:

  • Guidelines on prohibited AI practices (published on 04 February 2025) provide legal explanations and practical examples of AI practices that are deemed unacceptable and hence prohibited by Article 5 of the AI Act, due to their potential risks to European values and fundamental rights. The guidelines specifically address practices such as harmful manipulation, social scoring, and real-time remote biometric identification, among others.
  • Guidelines on AI system definition (published on 06 February 2025) explain the practical application of the legal concept of AI to assist providers and other relevant persons in determining whether a software system constitutes an AI system. The guidelines elaborate on each of the seven elements of the definition of an AI system provided by Article 3(1) AI Act: (1) machine-based system, (2) autonomy, (3) adaptiveness, (4) AI system objectives, (5) inferencing how to generate outputs using AI techniques, (6) outputs that can influence physical or virtual environments, and (7) interaction with the environment.
  • As at July 2026, other guidelines are being developed by the European Commission. For instance, the Commission has issued Draft guidelines on the classification of high-risk AI systems, setting out the Commission’s interpretation of certain concepts that are relevant for classification purposes, and contain practical examples of AI systems that should or should not be classified as high-risk. With respect to criminal proceedings, the Commission provides various examples of tools that would be considered high-risk AI systems, such as:
    • Domestic violence or human trafficking vulnerability risk assessment systems risk assessment systems. They influence critical interventions, including police protection measures and legal actions, which can either prevent harm from arising or, if flawed, leave victims vulnerable to further abuse.
    • AI systems intended to be used to analyse facial micro-expressions to assess the credibility of answers during an interrogation.
    • AI systems intended to be used to evaluate the reliability of evidence, including authenticity verification, data integrity and source reliability assessment tools.
    • AI systems assessing whether a specific person may offend or reoffend, used by criminal courts, probation officers, or penitentiary institutions.
    • AI systems intended to be used for the profiling of natural persons in the course of the detection, investigation or prosecution of criminal offences.

While the classification of such systems as high-risk AI systems does not bar law enforcement institutions from using such systems, the EU AI Act imposes strict requirements and obligations on providers and deployers to ensure that they are trustworthy, safe to use, and respect fundamental rights (see above).

Other European Regulations and Guidelines

At the European level, the AI Act coexists with additional regulations and guidelines, although they do not postulate any concrete obligations for Finland:

Ethics Guidelines for Trustworthy Artificial Intelligence (2019)

Prior to the adoption of the AI Act, the High-Level Expert Group on AI set up by the European Commission presented the Ethics Guidelines for Trustworthy Artificial Intelligence on 8 April 2019. These guidelines provide a framework to achieve trustworthy AI based on fundamental rights as enshrined in the Charter of Fundamental Rights of the European Union (EU Charter).

The Guidelines put forward a set of seven key requirements that AI systems should meet in order to be deemed trustworthy:

  1. Human agency and oversight
  2. Technical robustness and safety
  3. Privacy and data governance
  4. Transparency
  5. Diversity, non-discrimination and fairness
  6. Societal and environmental well-being
  7. Accountability

European Declaration on Digital Rights and Principles for the Digital Decade (2022)

The European Commission adopted on 26 January 2022 the European Declaration on Digital Rights and Principles for the Digital Decade. This Declaration affirms the commitment of European institutions to ‘ensuring transparency’ in AI, guaranteeing the quality of data, preventing these tools from being used to predetermine individuals’ choices, and providing safeguards to protect individuals’ fundamental rights. Chapter III specifically declares that everyone shall be able to make ‘free and informed choices in the digital environment, while being protected from risks and harm to their health, safety, and fundamental rights’.

Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (2024)

The Council of Europe adopted in May 2024 the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, which is the ‘first-ever international legally binding treaty’ regulating AI. The Convention establishes rules relating to respect for fundamental rights at all stages of the AI systems lifecycle, which must be transposed into the domestic law of the signatory states.

The Convention establishes seven fundamental principles for AI systems development: human dignity and individual autonomy (Article 7), transparency and oversight (Article 8), accountability and responsibility (Article 9), equality and non-discrimination (Article 10), privacy and personal data protection (Article 11), reliability (Article 12) and safe innovation (Article 13).

The Convention applies across all public and private uses of AI where human rights may be affected, including within law enforcement, prosecution and judicial activities. It mandates risk and impact assessments to mitigate potential harms and provides safeguards such as the right to challenge AI-driven decisions.

The Convention has been signed on 5 September 2024 by Finland (as part of EU signature), but has not yet come into force.

European Ethical Charter on the use of AI in the judicial systems and their environment (2018)

Similarly, the European Ethical Charter on the use of AI in the judicial systems and their environment has been adopted by the Council of Europe’s European Commission for the Efficiency of Justice (CEPEJ) in December 2018. It lays out five basic principles relating to the use of AI in judicial systems:

  1. Respect of fundamental rights (‘ensure that the design and implementation of AI tools and services are compatible with fundamental rights’),
  2. Non-discrimination (‘specifically prevent the development or intensification of any discrimination between individuals or groups of individuals’),
  3. Quality and security (‘with regard to the processing of judicial decisions and data, use certified sources and intangible data with models conceived in a multi-disciplinary manner, in a secure technological environment’),
  4. Transparency, impartiality and fairness (‘make data processing methods accessible and understandable, authorise external audit’),
  5. Under user control (‘preclude a prescriptive approach and ensure that users are informed actors and in control of their choices’).

Guidelines for practitioners

As at July 2026, there are no AI-specific guidelines addressing the use of AI by practitioners in the criminal justice system in Finland. Legal professionals are bound by the Code of Conduct for Attorneys-at-Law, which, though not explicitly mentioning AI, emphasises that attorneys must understand the functions and limitations of the tools they use and maintain full liability for all work products.

As at July 2026, Finland has not issued specific legislative acts or official policy documents explicitly implementing the UNESCO Guidelines for the Use of AI Systems in Courts and Tribunals (2025).

Regional guidelines on judiciary’s use of AI

There are several European-level guidelines that address the judiciary’s use of AI, most notably the European Ethical Charter on the use of AI in judicial systems and their environment adopted by the CEPEJ of the Council of Europe (discussed above).

Other initiatives have given rise to guidelines for justice system professionals and for lawyers:

Sector

Title

Contents

Council of Bars and Law Societies of Europe

Considerations on the Legal Aspects of Artificial Intelligence (2020)

According to the Council of Bars and Law Societies of Europe, for the sake of transparency and in order to enable individuals to defend their rights, it seems appropriate that the persons impacted by the use of an AI system should be duly informed that AI is being used and that data concerning the individual may be considered by an automated system.


The Finnish Bar Association is a full member of the Council, rendering the guideline applicable to Finnish professionals.

Council of Bars and Law Societies of Europe

Guide on the Use of Artificial Intelligence-Based Tools by Lawyers and Law Firms in the EU (2022)

The Guide emphasises that lawyers should have at least a general understanding of how AI tools function. Where such understanding is lacking, this should be clearly communicated to clients and taken into account in the provision of legal services. Ultimately, under existing professional rules, lawyers remain fully responsible for the quality of their services and the outcomes for their clients, even where AI tools are used.


The Finnish Bar Association is a full member of the Council, rendering the guideline applicable to Finnish professionals.

Court of Justice of the EU

Artificial Intelligence Strategy (2023)

While the AI Strategy does not address the disclosure of AI use, it emphasises that once AI solutions, procedures, methods and governance are put in place, staff awareness and knowledge level should ensure that the reasoning behind AI algorithms should be clear and understandable, both for those created in-house and those acquired.


While the paper is not directly applicable to Finnish justice system professionals and lawyers, it serves as a guideline for their own AI use.

European Bars Federation

Guidelines 2.0 on How Lawyers Should Take Advantage of the Opportunities Offered by Large Language Models and Generative AI (2024)

The Guidelines explain that lawyers should maintain transparent communication with their clients regarding the use of generative AI in their legal practice. Lawyers should clearly explain the fact that they use it, as well as the purpose of such use, benefits, limitations, and guarantees, ensuring that clients understand the role of this technology in legal matters.

While the Finnish Bar Association is not a member of the European Bars Federation, Finnish professionals may refer to the guidelines as guidance for their own AI use.

Council of Europe

Use of Generative AI by Judicial Professionals in a Work-Related Context (2024)

The aim of this note is to give some preliminary thought to what judges and other public sector justice professionals can expect from the use of generative AI tools in a judicial context. The Council reiterated that it is essential, in particular in the case of justice, to be transparent about the use of generative AI as the relationship with the litigant is based on trust.


Finland is a member of the Council of Europe, rendering the guideline applicable to Finnish professionals.

Criminal procedure rules

As outlined in Chapter 17, Section 1 of the Code of Judicial Procedure (oikeudenkäymiskaari, 4/1734, ‘CJP’), Finnish evidence law is based on the ‘Free Theory of Evidence’ (Vapaa todistusharkinta), which means that AI-generated materials (e.g., algorithmic risk scores, deepfake analysis) are generally admissible in court.

Finland has no dedicated deepfake statute and no publicly identified legislative initiative specifically targeting deepfake evidence in criminal proceedings. The existing Criminal Code covers the most serious misuses through defamation, forgery, and identity theft provisions.

Data protection legislation

In addition to the EU AI Act, EU data protection regulations must be observed with regard to the use of AI in criminal proceedings. The EU AI Act does not seek to affect existing Union law governing the processing of personal data (according to Article 2 No. 7 AI Act and Recital 10). Data protection law governing the use of personal data may be relevant with regard to various stages of the AI lifecycle. Personal data can be relevant during AI development (e.g., collection and use of data for training) and AI use (e.g., personal data as input data).

On 25 January 2012, the European Commission presented the Data Protection Reform package, proposing a directive (LED) and a regulation (GDPR). On 27 April 2016, the European Parliament and the Council adopted:

  • The Law Enforcement Directive (Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data (‘LED’).
  • The General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the European Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (‘GDPR’).

The GDPR remains the primary regulation for ‘general’ processing of data, but the LED is the lex specialis for criminal matters, since it governs processing ‘for the purposes of the prevention, investigation, detection, or prosecution of criminal offences or the execution of criminal penalties’. These regulations have distinct scopes of application that are intended to be complementary.

In both regulations, ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Article 3(1) LED and Article 4(1) GDPR). As at July 2026, this term also includes pseudonymised data as indicated by Article 4(5) GDPR. Recital 26 sentence 2 of the GDPR points out that identifiability should (still) be recognised in view of pseudonymised personal data that could be assigned to a natural person based on additional information.

On 6 and 25 May 2018 respectively, the LED and the GDPR were implemented across all EU Member States.

EU Directive 2016/680, Law Enforcement Directive (LED) (2016)

The directive governs the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection, and prosecution of criminal offences or the execution of criminal penalties.

The rights of data subjects are recognised but may be limited in order to ensure the proper conduct of investigations, prevention, and the prosecution of offences. These rights include the right to information, the right of access (often exercised indirectly through the supervisory authority), and the right to rectification or erasure. As such, the directive imposes obligations on data controllers that are comparable to those of the GDPR, but creates additional obligations that are specific to the criminal context:

  1. There must be a clear distinction among categories of data subjects: those suspected of committing or planning a criminal offence, those who have been convicted, victims of crimes, and individuals who may be at risk of becoming victims. It also includes third parties connected to a crime, such as potential witnesses, people who can provide information, and contacts or associates of the individuals mentioned above, as set out in Article 6.
  2. The processing of special categories of personal data is strictly regulated under Article 9(2) of the GDPR and requires the data subject’s consent, which shall be freely given and well-informed, or for a legitimate purpose. But the LED establishes a specific exception for criminal matters: Article 10 permits the processing of sensitive data without consent when it is strictly necessary, provided that appropriate safeguards are implemented.
  3. The LED also addresses automated individual decision-making. A decision ‘based solely on automated processing, including profiling, which produces an adverse legal effect concerning the data subject or significantly affects him or her’, is prohibited unless authorised by Union or Member State law to which the controller is subject and which provides appropriate safeguards for the data subject’s rights and freedoms of, at least the right to obtain human intervention on the part of the controller (Article 11(1)). The EU legislator specifies that this right to intervention comprises the right to express his or her point of view, to obtain an explanation of the decision reached after such assessment or to challenge the decision (Recital 38). Furthermore, such decisions shall not be based on special category data, unless suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests are in place (Article 11(2)). Special category data includes personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, the genetic or biometric data for the purpose of uniquely identifying a natural person, and data concerning health or data concerning a natural person’s sex life or sexual orientation (Article 10). The LED further prohibits profiling resulting in discrimination against natural persons on the basis of special category data (Article 11(3)).
  4. In order to protect individuals’ rights during criminal investigations, Articles 13 and 14 provide for information and access rights, while allowing limitations where their exercise could undermine ongoing investigations or prosecutions.
  5. Article 16 complements these safeguards by providing the right to request the rectification of inaccurate data and the erasure of data, and in the event of refusal, the possibility of lodging a complaint with a supervisory authority or seeking judicial remedy.
  6. Finally, Articles 27 and 29 impose obligations relating to risk assessment and data security, requiring competent authorities to assess the impact of high-risk processing operations and to implement appropriate technical and organisational measures throughout the criminal procedure.

Finland has transposed the LED into Finnish law through the Data Protection Act for Authorities in Criminal Matters, requiring a specific legal basis for the processing of biometric data in the context of criminal offences, which was central to the reprimand of the National Police Board in the Clearview AI incident.

Regulation (EU) 2016/679, General Data Protection Regulation (GDPR)

The GDPR protects fundamental rights in the digital landscape by imposing obligations on data controllers and processors upon all processing of personal data. Hence, in the area of criminal justice, the GDPR is relevant for (i) the processing of personal data collected by competent authorities for the purposes set out above but intended to be further processed for other purposes, (ii) processing by public bodies for other purposes from the outset (this includes, e.g., archiving conducted by criminal justice authorities), and (iii) any processing by natural persons or private entities (Article 9 (1) and (2) LED, Article 2(1) GDPR, Recital 19 to GDPR).

Obligations placed on data controllers include: lawful, fair and transparent processing; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability; transparency and information duties; security obligations; and data protection impact assessments. The GDPR also grants basic rights to data subjects such as access, rectification and erasure of personal data.

Compared to the LED, the GDPR establishes a higher level of protection regarding the lawfulness of processing. Several aspects of criminal proceedings are subject to the following provisions of the GDPR:

  1. Article 10 requires the processing of personal data relating to criminal convictions and offences to be carried out ‘only under the control of official authority’, and to provide for ‘appropriate safeguards for the rights and freedoms of data subjects’.
  2. Paragraph 1 of Article 22 prohibits any decision that produces legal or similar effects based exclusively on automated data processing. This serves as a key safeguard against ‘algorithmic judges’ or fully automated sanctions.
  3. Paragraph 1 of Article 35 provides that the controller must carry out a data protection impact assessment prior to any processing likely to pose a high risk to the rights and freedoms of individuals, particularly when new technologies are involved. A single assessment may cover multiple similar processing operations presenting comparable risks.

The GDPR is incorporated into Finnish law by the Data Protection Act (2018).

EU AI Act (Regulation (EU) 2024/1689)

Acknowledging both existing data privacy regulations and the relevance of personal data in the AI context, the EU AI Act contains several provisions addressing the use of such data in the course of complying with broader obligations under the AI Act:

  1. The EU AI Act provides a (narrow) legal basis for the processing of special category personal data in the context of training or testing a high-risk AI system. Where such processing is strictly necessary for the purpose of ensuring bias detection and correction in relation to a high-risk system, the providers of such systems may exceptionally process special category data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. Exceptional circumstances exist where (in addition to the requirements for such processing set out in the LED or the GDPR) certain cumulative conditions are met, including where there are technical limitations and state-of-the-art security measures, including pseudonymisation, as well as strict security safeguards (Article 10 No. 5 sentence 2 AI Act, (6)).
  2. The data sets for training, validation, and testing of AI systems shall be subject to appropriate data governance and management practices that, in the case of personal data, shall also concern the original purpose of the data collection (Article 10 No. 2 (b) AI Act).
  3. Where applicable, deployers of high-risk AI systems shall use the information provided for such systems under their transparency obligation (Article 13 AI Act) for conducting a data protection impact assessment under the LED or the GDPR (Article 26 No. 9 AI Act).

Screenshot 2026-08-22 at 08.20.36

Cybersecurity laws

EU AI Act (Regulation (EU) 2024/1689)

For high-risk AI systems, the EU AI Act requires resilience against attempts by unauthorised third parties to alter their use, outputs, or performance by exploiting system vulnerabilities (Article 15(5)), which is confirmed by the underlying Recital 76, emphasising the crucial role of cybersecurity.

EU Cybersecurity Act (2019) and EU Cyber Resilience Act (2024)

As regards the demonstration of compliance with the AI Act’s cybersecurity requirements for high-risk AI systems, two other European regulations may be relevant:

EU Cybersecurity Act (‘CSA’) - Regulation (EU) 2019/881

Aims to achieve a high level of cybersecurity, cyber resilience and trust within the EU and sets forth a framework for the establishment of voluntary European cybersecurity certification schemes for so-called ICT products, i.e., an element or a group of elements of a network or information system (Articles 1 (1) (b), 2 (13) CSA). Where high-risk AI systems are also ICT products, compliance with the cybersecurity requirements laid down in the EU AI Act can be presumed by demonstrating certification under the CSA in so far as such certification covers the AI Act’s respective requirements (Articles 42 No. 2, 15 No. 1, 5 AI Act). Concerning law enforcement and criminal justice, this would be particularly relevant for high-risk AI-enabled software, for instance allowing for biometric identification. In January 2026, the European Commission announced a Proposal for a Regulation for the EU Cybersecurity Act (‘The Cybersecurity Act 2’) aiming at, inter alia, further simplifying the certification process.

Cyber Resilience Act (‘CRA’) - Regulation (EU) 2024/2847

Whereas the CSA establishes a voluntary certification framework, the CRA aims at ensuring that digital products and services are secure by design, resilient against threats, and able to maintain security throughout their life cycle, and sets out mandatory cybersecurity requirements for products with digital elements made available on the market. With most of its provisions applying from December 2027, the CRA will concern a wide range of products placed on the EU market, including AI-enabled software. For high-risk AI systems, compliance with the CRA requirements shall also be deemed to satisfy the AI Act’s cybersecurity requirements in so far as those requirements are covered under the CRA (Recital 51 to the CRA).

EU NIS2 Directive (2022) and Implementing Legislation

At the domestic level, Finnish cybersecurity law is primarily based on the implementation of the EU NIS2 Directive (Directive (EU) 2022/2555), which imposes strict risk management, incident notification, and security obligations on critical entities and public bodies.

In particular, EU NIS2 Directive establishes a high common level of cybersecurity across the EU, requiring entities subject to the framework to implement comprehensive cybersecurity risk management measures, covering access control, supply chain security, physical security of network systems, and human resources security, while management bodies are personally accountable for approving and overseeing such measures. On incident reporting, the Directive introduces a tiered architecture requiring an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and further reports as the situation develops. At the governance level, Member States must establish national cybersecurity strategies, designate competent authorities, and set up Computer Security Incident Response Teams.

At the domestic level, the Finnish Cyber Security Act (124/2025), which entered into force on 8 April 2025, implements the NIS2 Directive and establishes the framework for strengthening cybersecurity across key sectors in Finland. Finland has published a new Cyber Security Strategy (2024-2035) which specifically mentions the risks and possibilities of AI for national digital infrastructure.

Act on Electronic Communications Services (2014)

The Finnish Act on Electronic Communications Services (917/2014) (formerly the Information Security Code) establishes requirements for the confidentiality of electronic communications, ensuring that AI tools used in the justice sector must maintain the security of messages sent over their systems.

Human Rights

The Constitution of Finland (Section 21) guarantees the right to a fair trial and the right to have one’s case heard by a ‘competent and impartial court’. The Non-Discrimination Act (1325/2014) also prohibits discrimination based on race, gender, religion and other protected grounds, and extends to discrimination based on AI-driven decision-making.

Finland is bound by the European Convention on Human Rights, in particular Articles 6 (fair trial), 8 (private and family life) and 14 (non-discrimination), and by the EU Charter of Fundamental Rights, including Articles 7 (privacy), 8 (data protection), 21 (non-discrimination) and 47 (right to an effective remedy and a fair trial). The Charter of Fundamental Rights of the European Union applies to the processing of personal data by AI systems falling within EU law scope, including in the context of criminal proceedings governed by the LED and the EU AI Act.

Moreover, the Council of Europe Framework Convention on AI and Human Rights, Democracy, and the Rule of Law deserves special mention as a multilateral initiative, being the first legally binding international treaty specifically designed to regulate AI. Opened for signature in September 2024, its primary objective is to ensure that as AI technologies evolve, they do not erode the fundamental pillars of modern society: human rights, democratic integrity, and the rule of law. As at July 2026, the Convention has not yet entered into force, as the minimum number of five ratifications has not yet been reached and the Convention therefore has no binding effect in Finland. The Convention focuses on the lifecycle of AI systems, from design to decommissioning, and mandates adherence to seven fundamental principles: human dignity, transparency, accountability, equality, privacy, reliability, and safe innovation. It requires signatories to establish independent oversight bodies and provide clear legal remedies for individuals who suffer harm due to AI systems.

Fair trial and privacy guarantees under other international human rights treaties to which Finland is a party, such as Articles 14 and 17 of the International Covenant on Civil and Political Rights or Articles 16 and 40 of the Convention on the Rights of the Child, may also be relevant

Outlook

Finland’s strategy for the next decade is defined by the Digital Compass 2030, which prioritises the digitisation of the administration of justice as a key target. The future use of AI in criminal cases is likely to evolve cautiously but steadily, shaped by Finland’s strong digital infrastructure and strict legal safeguards. With the AIPA system now fully operational across the criminal justice chain, Finland is well positioned to expand AI‑supported tools that enhance efficiency, evidence management, and analytical capacity, while maintaining human control over all substantive judicial decisions. As the EU AI Act imposes stringent obligations on high‑risk AI systems used in criminal justice, Finland’s regulatory environment will continue to prioritise transparency, explainability, and human oversight, ensuring that any future adoption of AI strengthens fairness and consistency without compromising the existing legal guarantees that ultimate decision‑making remains human‑led.

European Commission’s Proposed Digital Omnibus Regulation (2025)

In November 2025, the European Commission published its Digital Omnibus Regulation Proposal, a reform package to simplify and streamline existing EU regulations concerning the digital space, including the GDPR and EU AI Act. Respective amendments to the LED are to follow.

Notably, the European Commission intends to amend the definition of the term ‘personal data’ in Article 4(1) GDPR by stating that information is ‘not to be considered personal data for a given entity when it does not have means reasonably likely to be used to identify the natural person to whom the information relates.’ Accordingly, such an entity would not fall within the scope of the GDPR regarding the processing of such data. This approach is generally in line with CJEU case law establishing that existing additional information enabling an entity to identify the data subject does not as such mean that pseudonymised data are to be considered personal data in all cases and for every person. In other words, personal data can be pseudonymised for one entity and anonymised (and thus not identifiable) for another (EDPS v SRB, 4 September 2025, CJEU, C‑413/23 P). Such an amendment wording would, if implemented, significantly reshape the legal test to be conducted to assess applicability of the GDPR (i.e., the assessment of the existence of personal data) towards an entity-focussed approach and largely exclude pseudonymised data from the scope of the GDPR.

The European Commission, through its Digital Omnibus Regulation, also intends to clarify that the processing of personal data in the context of AI development may be carried out for purposes of a legitimate interest where appropriate (Article 6(1)(f) GDPR). Such an amendment would address an issue that has been widely debated since the emergence of LLMs, and which has also been subject to a dedicated Opinion of the European Data Protection Board (Opinion 28/2024, 18 December 2024, EDPB).

CASES

As at July 2026, there are limited cases concerning the use of AI in criminal proceedings in Finland.

Data protection

The Clearview AI Incident (2021) arose from the use of a service in which information security and compliance with data protection legislation had not been adequately ensured in advance. The NBI decided to test facial recognition technology in early 2020. The NBI’s unit responsible for combating the sexual exploitation of children tested a US service called Clearview AI for the identification of possible victims of sexual abuse to help manage the unit’s increased workload using AI and automation. During the trial period, the unit made around 120 searches in the software, which makes use of pictures of persons on social media.

This trial was found to be illegal by the Deputy Data Protection Ombudsman, because it was initiated without a Data Protection Impact Assessment or the approval of the data controller, and it involved the processing of sensitive biometric data without a specific legal basis. The Deputy Data Protection Ombudsman issued a statutory reprimand to the National Police Board as the controller responsible for the processing of personal data by the police. The Deputy Data Protection Ombudsman noted that the controller’s responsibility had not been fulfilled in these operations. It would have been the duty of the National Police Board to ensure that police personnel were familiar with regulations and the required procedures. In particular, the measures taken by the controller had not prevented the unlawful processing of personal data and had failed to ensure that the police took into consideration the requirements for processing special categories of personal data.