Key Facts
- Deployment: MahaCrimeOS AI expanded from 23 Nagpur police stations to all 1,100 across Maharashtra
- Announcement Date: 12 December 2025
- Partners: Maharashtra Government, Microsoft, CyberEye, and MARVEL initiative
- Capabilities: Drafts First Information Reports, extracts data from complaints in English, Hindi and Marathi, suggests investigative pathways
- Reported Impact: Reduces investigation turnaround time by up to 80%; FIR creation time reduced to 15 minutes
- Legal Question: Who signs the Section 63(4) BSA certificate when the output is generated by a machine learning model?
- Certificate Requirement: Under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, electronic records produced as secondary evidence require a certificate signed by a responsible official of the computer system
Direct Answer
On 12 December 2025, Maharashtra and Microsoft announced the statewide rollout of MahaCrimeOS AI, expanding from 23 Nagpur police stations to all 1,100 across the state. The platform, developed with the state’s MARVEL initiative and built by CyberEye using Microsoft Foundry and Azure OpenAI Service, drafts First Information Reports, extracts data from complaints in English, Hindi and Marathi, and suggests investigative pathways.
Microsoft says it reduces investigation turnaround time by up to 80%.
That is a significant operational capability. It also creates an evidentiary question that has not been resolved.
When MahaCrimeOS analyses a complaint, links cases, or drafts a legal notice, its output becomes part of the investigative record. Under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, electronic records produced as secondary evidence require a certificate signed by a responsible official of the computer system. The certificate must describe the system, attest to the conditions in which the record was produced, and confirm the integrity of the process.
An AI system that generates an investigative insight is a computer system. Its output is an electronic record. The certificate requirement applies.
But the framework does not yet address who signs that certificate when the output is generated by a machine learning model. The investigating officer? The system administrator? The vendor? If the officer cannot inspect the model’s reasoning, what is he attesting to?
The capability is deployed. The accountability framework is still pending.
In this article:
- What MahaCrimeOS AI Does
- The Operational Impact: Faster FIRs, Faster Investigations
- The Section 63(4) BSA Certificate Requirement
- The Unresolved Question: Who Signs?
- The Dual Certification Mechanism
- The Hash Value and the Black Box Problem
- What the Regulators Have Not Addressed
- Frequently Asked Questions (FAQ)
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police forces since 1996.
What MahaCrimeOS AI Does
MahaCrimeOS AI is an AI-powered platform developed by CyberEye, a partner independent software vendor of Microsoft, with the Maharashtra Government’s Special Purpose Vehicle MARVEL and Microsoft India Development Center (IDC). It is built on Microsoft Azure OpenAI Service and Microsoft Foundry.
The platform enables instant case creation, multilingual data extraction, and contextual legal assistance. It integrates advanced AI assistants, automated workflows, and secure cloud infrastructure.
Key capabilities:
- Upload unstructured inputs including cybercrime complaints, chat messages, bank records, screenshots and handwritten notes
- Works across English, Hindi and Marathi
- Extracts information from unstructured material
- Generates drafts of First Information Reports and official requests
- Suggests investigative workflows
- Drafts requests to banks, telecom companies and online platforms for account freezes, call detail records and account takedowns
- Provides access to criminal law databases and open-source intelligence
- Enables investigators to link cases and identify patterns
Officers interact with the system through a dashboard that displays active cases, pending actions and incoming responses.
The Operational Impact: Faster FIRs, Faster Investigations
The reported impact is significant.
According to officials involved in the Nagpur pilot, tasks that earlier took months now take days, allowing individual officers to handle multiple cases simultaneously.
Before MahaCrimeOS AI:
- Collecting information could take two to three months
- Officers had to visit multiple banks, draft letters, collect statements, track IP addresses and manage multiple mobile numbers
- An officer could handle one case at a time
After MahaCrimeOS AI:
- FIR creation time reduced to 15 minutes
- Tasks that took months completed in about a week
- An officer can handle seven to eight cases a month
The state government has cited capacity constraints to justify deploying AI tools in cybercrime investigations. Investigations requiring coordination with multiple banks, telecom providers and online platforms place sustained pressure on existing resources, which the system seeks to address.
The national context:
According to government data cited by the Indian Cyber Crime Coordination Centre, authorities recorded over 2.26 million cybercrime complaints across India in 2024. The scale of the problem is evident.
The Section 63(4) BSA Certificate Requirement
Under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, electronic records produced as secondary evidence require a certificate in the prescribed format.
The certificate must be signed by a person in charge of the computer or communication device, or the person in charge of the management of the relevant activities.
The BSA additionally requires the certificate to be signed by an expert, in addition to the person in charge of the device concerned.
The Schedule to the BSA is in two parts:
- Part A: Certificate to be filled by the party submitting the evidence
- Part B: Certificate to be filled by the expert
The certificate requires disclosure of details relating to the electronic record, including its hash value.
The Supreme Court, in Pune Bar Association vs. Union of India, upheld the constitutional validity of Section 63(4) BSA. The Court observed that electronic records are susceptible to continuous mutation and modification, concerns that have been amplified by advancements in artificial intelligence and deepfake technology.
The Court held that these requirements bear a rational nexus to the object of the BSA.
The Unresolved Question: Who Signs?
The framework does not yet address who signs the certificate when the output is generated by a machine learning model.
The candidates:
- The investigating officer
- The system administrator
- The vendor
- An expert under Section 39 of the BSA
The problem:
If the investigating officer cannot inspect the model’s reasoning, what is he attesting to?
The Section 63(4) certificate attests something specific: that the output before the court is a faithful record of what the computer system produced. It does not attest to the truth of the content. It does not attest to the correctness of the AI’s reasoning.
But when the output is an investigative insight — a suggested link between cases, a recommended investigative pathway, a draft legal notice — the distinction between procedural integrity and substantive correctness matters.
The officer can attest that the system produced the output. He cannot attest that the output is correct.
The Dual Certification Mechanism
The BSA’s Section 63(4) introduced a dual certification mechanism.
Part A: Signed by the person in charge of the computer or communication device, or the person in charge of the management of the relevant activities.
Part B: Signed by an expert. The Supreme Court has clarified that persons possessing special skill and expertise in computer science and cyber forensics may sign Part B as experts. The Court disagreed with the Madras High Court’s view that Part B must be signed only by an Examiner of Electronic Evidence notified under Section 79A of the IT Act.
The application to MahaCrimeOS AI:
- Part A signatory: The investigating officer or the officer in charge of the police station using the system
- Part B signatory: An expert in computer science or cyber forensics
The question is whether the Part A signatory can meaningfully attest to the conditions in which the record was produced when the record is an AI-generated output.
The Hash Value and the Black Box Problem
The hash value is an electronic fingerprint of an electronic record. It verifies that the record has not been altered after it was produced.
The hash value can confirm that the AI output is the same as the output the system generated. It cannot confirm that the output is correct, reliable, or free from hallucination.
The black box problem:
Many machine learning models operate as black boxes. Their internal reasoning is not transparent or interpretable by the officers who use them. The officer can see the input and the output. He cannot see the reasoning that connects them.
If an AI system generates an investigative insight that is wrong — a hallucination, a false link, a biased recommendation — the Section 63(4) certificate will still attest to the procedural integrity of the record. The certificate will say the system produced the output. It will not say the output is true.
The risks researchers have flagged:
Researchers at the Digital Futures Lab have cautioned that embedding generative AI directly into investigative workflows raises unresolved risks around hallucinations, bias, data governance and fair-trial rights.
Dona Mathew, a researcher at the Digital Futures Lab, said: “Use of AI in law enforcement needs to be preceded by an assessment of potential risks,” particularly when systems are expected to analyse complaints or guide investigations.
What the Regulators Have Not Addressed
The regulatory framework has not yet addressed the specific question of AI-generated investigative outputs.
The gaps:
- No guidance on who signs the Section 63(4) Part A certificate when the output is AI-generated
- No standards for auditing or validating AI-generated investigative insights
- No requirements for transparency in AI decision-making
- No framework for challenging AI-generated evidence at trial
- No guidance on how AI outputs should be disclosed to the defence
The fair trial question:
From a trial perspective, applications like evidence analysis raise difficult evidence law questions. If an AI system is analysing evidence, who can be cross-examined?
The Section 63(4) certificate is a procedural mechanism. It does not create a witness. It does not create a person who can be cross-examined about the AI’s reasoning.
Frequently Asked Questions (FAQ)
What is MahaCrimeOS AI?
MahaCrimeOS AI is an AI-powered platform for cybercrime investigations developed by CyberEye with the Maharashtra Government’s MARVEL initiative and Microsoft India Development Center. It drafts First Information Reports, extracts data from complaints in English, Hindi and Marathi, and suggests investigative pathways.
When was it rolled out statewide?
On 12 December 2025, Maharashtra and Microsoft announced the expansion from 23 Nagpur police stations to all 1,100 across the state.
What does Section 63 of the BSA require?
Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, requires electronic records produced as secondary evidence to be accompanied by a certificate signed by a responsible official of the computer system.
Who signs the certificate?
The certificate requires two signatories: Part A by the person in charge of the computer or communication device, and Part B by an expert.
Why is the certificate a problem for AI-generated outputs?
The framework does not address who signs the certificate when the output is generated by a machine learning model. The investigating officer can attest that the system produced the output. He cannot attest that the output is correct.
What is the hash value?
A hash value is an electronic fingerprint of an electronic record. It verifies that the record has not been altered after it was produced.
What is the black box problem?
Many machine learning models operate as black boxes. Their internal reasoning is not transparent or interpretable by the officers who use them. The officer can see the input and the output. He cannot see the reasoning that connects them.
What risks have researchers flagged?
Researchers at the Digital Futures Lab have cautioned that embedding generative AI into investigative workflows raises unresolved risks around hallucinations, bias, data governance and fair-trial rights.
What has the Supreme Court said about Section 63(4) BSA?
The Supreme Court in Pune Bar Association vs. Union of India upheld the constitutional validity of Section 63(4) BSA, observing that electronic records are susceptible to continuous mutation and modification, concerns amplified by advancements in AI and deepfake technology.
What are the regulatory gaps?
There is no guidance on who signs the Part A certificate when the output is AI-generated, no standards for auditing AI-generated insights, no requirements for transparency in AI decision-making, and no framework for challenging AI-generated evidence at trial.
Explore More:
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
#AdvShoebHakim #MahaCrimeOS #Section63BSA #CyberForensics #DigitalEvidence #WhiteCollarCrime #LegalDefense #Compliance #ArtificialIntelligence #CriminalLaw


