Civic / Privacy / Digital Rights

Predictive Policing after the EU AI Act: PRECOBS in Germany, CAS in the Netherlands, and the Boundary Between Prohibited and High-Risk AI

Report summary

This report examines predictive policing in Europe – focusing on Germany’s PRECOBS, SKALA and KrimPro systems and the Netherlands’ Crime Anticipation System (CAS) – in light of the EU AI Act (Regulation 2024/1689). It analyzes each system’s technical design, deployment, legal status, and claimed eff

Status
Research archive item
Category
Civic / Privacy / Digital Rights
Length
5,757 words
Reading time
27 minutes
Report type
evaluation

Key topics

  • Civic / Privacy / Digital Rights
  • Civic
  • Privacy
  • Digital Rights
  • AI
  • Research Archive
  • Audit
  • Architecture
  • Governance

Research provenance

Archive status
Research archive item
Content identity
sha256:a53609cf98fbcc3f7d0e7f87eb235402b42973a10a037688aa34ee79b5b4561e

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

This report examines predictive policing in Europe – focusing on Germany’s PRECOBS, SKALA and KrimPro systems and the Netherlands’ Crime Anticipation System (CAS) – in light of the EU AI Act (Regulation 2024/1689). It analyzes each system’s technical design, deployment, legal status, and claimed effectiveness, and maps them onto the AI Act’s definitions of prohibited vs high-risk AI. It also compares European practice to developments in other jurisdictions (e.g. the FBI’s proposed Threat Screening Center AI) and assesses compliance, transparency, and human-rights implications. We draw on primary sources (legislation, official reports, audits, court judgments) and credible analyses.

Predictive-Policing Systems: Technical Designs and Operations

  • PRECOBS (Germany – Bavaria and Baden-Württemberg): PRECOBS is a near-repeat burglary prediction system developed by the Institut für musterbasierte Prognosetechnik (IfmPt) and used by Bavarian and Baden-Württemberg police. It uses only historical crime data (past burglaries) as input. Crimes are characterized by “triggers” (modus operandi, target type, etc.) and “anti-triggers.” A crime that matches trigger criteria (and lacks anti-triggers like broken glass) spawns a forecast of a burglary within ~250 m over the next 24 h–7 days. The software outputs color-coded map squares (typically 250×250 m) indicating predicted hotspots. Police analysts first humanly review each Precobs alert; approved alerts lead to targeted patrols and preventive measures (e.g. undercover surveillance, neighborhood warnings). Deployment began as pilot projects around 2013–2015 (Munich, Nuremberg, and later other cities) and has been integrated into regular practice in some Bavarian and BW precincts. The system targets burglary (originally residential burglary) and operates at the district or city level, updating predictions daily. Evaluations (e.g. the Baden-Württemberg “P4” pilot) were externally conducted; they reported some positive signals but found the actual crime-reduction impact “unclear” or moderate. (An open-access evaluation noted that any decline in burglaries could not be conclusively attributed to the software.) Reported accuracy rates (~80%) come from internal promotional materials, but independent researchers warn that high precision in forecasting is not evidence of prevented crimes, and actual public safety benefits remain contested.
  • SKALA (Germany – North Rhine-Westphalia): SKALA (“System zur Kriminalitätsauswertung und Lageantizipation”) was developed in-house by the LKA NRW and implemented starting 2015. It is place-based and focuses on burglary (residential and commercial) and auto theft. The system ingests past crime records plus rich contextual data (population, unemployment, traffic density, etc.) for the entire state. SKALA uses IBM SPSS Modeler and generates risk maps by police precinct. Early project stages (2015–2017, in 6 cities) aimed to “examine possibilities” of forecasting crime. A formal evaluation (2018) found SKALA technically feasible, and the project was scaled up: by 2019 it was used in all 16 NRW district authorities. Officers use SKALA outputs to inform shift deployment (where to patrol, how to split forces), but the system does not identify specific individuals – it simply highlights geographic hot spots with elevated risk. The police have stated that SKALA extends beyond near-repeat to incorporate broad criminological patterns. Reportedly, SKALA predicted areas with more burglaries than expected, but again no clear crime-rate reduction has been attributed to it. (No public proof of SKALA reducing crime has been published.)
  • KrimPro (Germany – Berlin): KrimPro (“Kriminalitätsprognose”) was an LKA Berlin pilot (2016–2017) for burglary. In early 2016 Berlin police, with external support (Microsoft), developed KrimPro and ran it from Oct 2016 to June 2017 in several city precincts. It divided Berlin into 400×400 m cells and used recent burglary incidents plus “socio-economic” variables (e.g. city block data) to train a model. The output was map alerts of high-risk cells; officers could request the map for up to four crime types at a time. Each alert was to be analyzed by a criminal analyst before action. KrimPro’s development involved a human-in-the-loop: analysts would review algorithmic scores daily and then direct patrols accordingly. The project’s internal review claimed higher detection rates in “predicted” blocks, but an independent evaluation was not published. By mid-2017 the Berlin pilot ended, and no permanent continuation has been publicly announced, suggesting it did not become an ongoing program.
  • Crime Anticipation System (CAS, Netherlands): CAS was a national Dutch police project (2015–2025) for forecasting crime hot spots. Unlike PRECOBS, CAS covered multiple offense categories (robbery, burglary, etc.). Starting Oct 2015, the entire Netherlands was gridded into 125×125 m cells. CAS used police incident records from the prior 12 weeks: for each cell it computed (1) the number of incidents of each targeted crime type, and (2) the number of known suspects of that crime type living nearby. A combined logistic-regression model then estimated the probability of a future incident in each cell. The output was a daily risk map: police teams could view which cells had “increased risk” of a chosen crime category. Human analysts at police “information hubs” would interpret CAS results (combining them with local knowledge) and issue deployment recommendations. CAS was explicitly anonymized: all input data were depersonalized and unlinked from individuals. The algorithm and modeling were done internally (no external vendor). CAS was widely used through police teams and was formally evaluated (a Human-Rights & Algorithms Impact Assessment was done annually). In late 2025 the Dutch police decided to phase out CAS (effective Dec 2025) after review. The published register notes that CAS had not delivered distinct crime reductions, and that policing would rely on multiple information sources.
  • SyRI (Netherlands – Social Fraud Detection, 2014–2019): Although not a police crime-forecasting tool, SyRI (System Risk Indication) is relevant as an “adjacent” example of algorithmic risk profiling. SyRI was a welfare-fraud detection system run by Dutch government (Ministry of Social Affairs, not police). It linked multiple administrative data sets (taxes, benefits, health, etc.) and scored individual persons for risk of fraud. The Dutch courts found SyRI unlawful under the ECHR (it violated privacy and proportionality requirements). SyRI identified individuals’ risk, not aggregate locations; it was aimed at compliance and fraud prevention rather than predicting ordinary crimes in public. Importantly, SyRI generated no arrest warrants or police actions directly – it flagged cases for further investigation by social inspectors. SyRI thus falls outside the typical “predictive policing” definition, but under the AI Act its risk-profiling of persons would now be prohibited (Art.5(d)) had it involved criminal accusations.
  • Other EU jurisdictions (briefly): Austrian and Swiss police have experimented with predictive analytics, but few public details exist. In Switzerland, an Audit Office report (2022) noted over 20 automated risk systems in policing, some for crime prevention, but no clear large-scale predictive-crime program has been documented. (One pilot – PredPol/Palantir in Basel – was discontinued. AlgorithmWatch reports Swiss police had “little to show” for some predictive tools.) France primarily uses social-science methods rather than formal AI for forecasting. We focus on DE/NL due to available evidence.

Each program can be classified by what it predicts: PRECOBS, SKALA, KrimPro, and CAS are location-based hotspot predictors (they forecast crime in areas). None of these directly output a risk score for any specific person. (SyRI, by contrast, was person-based.) In most systems, human analysts interpret predictions and decide police actions.

Deployment Timelines and Current Status (2026)

  • PRECOBS: Deployed gradually from 2013 onward. Bavaria started pilots in Munich in 2013, officially used in multiple Bavarian precincts by 2014–2015. Baden-Württemberg’s trial (P4) ran Oct 2015–Apr 2016 and was extended. As of 2026, Precobs (or its successor versions) remains in use in Bavaria (in several city precincts) and possibly BW. The developer (IfmPt) continues to offer updated Precobs software.
  • SKALA: Began in 2015 (project phase). By early 2018 the SKALA pilot concluded, and NRW police report it is now routinely used in all 16 district police (polizeipräsidien) of NRW. (Official sources say SKALA “became the largest predictive policing solution in Germany” by 2019.) There is no indication SKALA has been formally discontinued; it has been integrated into police analytics routines in NRW.
  • KrimPro: The Berlin pilot ran Oct 2016–June 2017. Public information on KrimPro ends in 2017; no further development has been reported. It appears that KrimPro was not continued after the test phase.
  • CAS (Netherlands): Officially ran from Oct 2015 to Dec 2025. In 2025 the Dutch police phased it out (“Out of use”) following evaluation. By early 2026 CAS is being discontinued; the police cite moderate benefits and plan to rely on other techniques.
  • SyRI (NL): Introduced 2014, suspended March 2020, and effectively ended after court rulings (2019–2020).
  • Other systems: No other large-scale predictive-policing programs are known in Austria, Switzerland, or France as of 2026.

Place-Based vs. Person-Based Predictive Policing

Predictive policing strategies fall into two categories: place-based (“location-based”) and person-based (also called “predictive targeting”). Place-based systems forecast areas or times of likely crime; person-based systems assign risk scores to individuals. Most European projects (PRECOBS, SKALA, CAS, KrimPro) are place-based: they predict hotspots for burglary or other offenses, not who will commit them. By contrast, person-based systems (like Chicago’s “Strategic Subject List”) predict that a known offender or citizen may engage in crime. The EU AI Act treats person-based profiling differently: indeed Article 5(d) expressly prohibits assessing a natural person’s risk of offending based solely on profiling or personality traits. The Act’s distinction aligns with this taxonomy: place-based analytics (hotspot mapping) generally fall outside Art.5(d), while any attempt to algorithmically score individuals’ criminal propensity triggers the strict rules or bans. In short, location-forecasting tools (PRECOBS/CAS) lie outside the “solely profiling” prohibition, whereas targeted individual risk tools would fall under it.

EU AI Act Classification: Prohibited vs. High-Risk AI

Article 5(d) – Prohibited Practice: Regulation (EU) 2024/1689 (the AI Act) bans “the use of an AI system for making risk assessments of natural persons […] to predict the risk of a person committing a criminal offence, based solely on profiling or personality traits”. This ban targets person-based predictive policing if it uses only profiling (e.g. ethnicity, behavior patterns) or personality characteristics. The key word “solely” means that if an AI’s prediction incorporates other objective facts or evidential data, the blanket prohibition may not apply. Importantly, the prohibition does not apply when the AI merely “supports human assessment of involvement” that is already based on “objective and verifiable facts”. For example, if police already have specific evidence (CCTV footage, fingerprints, etc.) and use AI to flag related leads, that support is exempt. But an AI that profiles an individual’s risk without such grounding is banned. Guidelines clarify that “profiling” here is defined as in the Law Enforcement Directive – automated evaluation of personal aspects like reliability or whereabouts – and “personality traits and characteristics” covers broad attributes (Recital 42 of the Act lists examples like nationality or sex).

Annex III High-Risk (Law Enforcement): AI systems that are not fully banned but handle sensitive tasks are classified as “high-risk” and subject to strict controls (data governance, documentation, human oversight, etc.). Annex III (point 6) of the AI Act lists specific law-enforcement systems as high-risk: for instance, systems “assessed for the likelihood of a person offending or reoffending not solely based on profiling or personality or past behaviour”. In other words, if an AI predicts an individual’s criminal risk using both profiling AND other facts (like criminal record, situational evidence), it falls under (d) of Annex III, not the Article 5 ban. Annex III also covers AI for risk of victimization (6a), polygraphs/evidence reliability (6b–c), and profiling suspects in investigations (6e). Pure location-based tools like PRECOBS or CAS do not match any Annex III category; under Article 6(3) they are effectively excluded from even being “high-risk” – i.e. outside the Act’s scope (though transparency requirements under Article 50 may not apply if they are not publicly available systems).

Decision Tree: A simplified decision logic under the AI Act is:

  • Step 1: Does the AI system target natural persons’ risk of committing crime? If yes, go to Step 2; if no (e.g. it only forecasts area crime rates), it is neither banned by Art.5(d) nor listed in Annex III – it would typically be minimal-risk (outside the Act’s prescriptive obligations).
  • Step 2: Are the risk assessments based solely on profiling/personality? If yes, the system is prohibited (Art.5(d) ban). For example, a “suspect list” that uses only demographic data to predict crime risk would be banned.
  • If no (the assessment uses additional objective data, e.g. known criminal records, or the system is used to help verify a specific crime case), then the ban does not apply. Now the AI is allowed but must be treated as high-risk under Annex III (6(d)). It must meet all high-risk requirements (quality of data, human oversight, impact assessment, etc.).
  • Exception: If the AI merely augments a human judge or detective’s existing evidence-based judgment, it may be exempt from prohibition. Per the Act’s text, “AI systems used to support the human assessment of involvement … based on objective and verifiable facts” are not banned. CJEU case law (Ligue des droits humains) has emphasized this: any automated “hit” must be confirmed by a human using objective criteria. In practice, police analytics often include human vetting, which could place them in the exempt category as long as the system is not the sole decision-maker.

Thus, in EU law: systems like PRECOBS, SKALA, CAS (hotspot predictors using aggregated crime data) do not profile individuals, so they are not caught by Art.5(d) directly. However, if these systems were claimed to identify likely offenders from patterns alone, that component would be banned. If future European systems evolve to assign risk scores to persons, they must include concrete evidential factors to avoid prohibition – and even then would be regulated as high-risk under Annex III.

Territorial/Institutional Scope: The AI Act covers all AI used or placed on the market in the EU by public authorities (including police) or private entities. Law-enforcement agencies across the EU fall under it. National exceptions: Member States may forbid certain uses if more restrictive. For example, Germany’s Polizeigesetze may impose additional constraints (e.g. requiring individual suspicion for certain intrusions). But the EU Act is a floor: any system considered high-risk must meet its rules, and prohibited uses may not be masked by calling them “intelligence analysis” – the substance of the algorithm’s function controls its classification.

Implementation Dates: The AI Act entered into force July 2024, with staggered applicability. Crucially, Chapter II (including Article 5) applies from 2 February 2025. High-risk obligations (Article 6 and associated requirements) take effect from 2 August 2027. Thus, from Feb 2025 onward European police cannot deploy solely profiling-based crime-risk AIs; from Aug 2027 any deployed high-risk policing AI must be compliant with data- and risk-management standards, transparency, and oversight. Penalties for breaches are up to 6% of annual turnover or €35 M (whichever higher) for serious infringements (Chapter 12).

Beyond the AI Act, several frameworks govern predictive policing:

  • EU Law Enforcement Directive (LED) 2016/680: Governs processing of personal data by police. It defines “profiling” as “automated processing to evaluate personal aspects (e.g. reliability, behavior, location)”. This definition underpins the AI Act’s use of “profiling.” The LED generally prohibits special categories of data (race, health, etc.) unless strictly necessary for criminal-law purposes. A predictive policing system using sensitive data would thus face LED constraints.
  • GDPR (2016/679): Some predictive tools may process personal data. GDPR’s Article 22 forbids fully automated decisions producing legal effects, which could cover, for example, auto-generated arrest warrants or individualized patrol stops. Police have some derogations: decisions based on law (e.g. statutory stop-and-search rules) may override Article 22. But transparency obligations (info to data subjects) and data-protection principles (purpose limitation, accuracy) still apply. A DPIA (Data Protection Impact Assessment) is likely required for intrusive systems (Article 35 GDPR). Note: in the Netherlands, Police Data Act (“Wpg”) similarly restricts use of personal data and often requires anonymization or legitimate purpose. CAS’s anonymization was a GDPR compliance measure.
  • European Convention on Human Rights (ECHR): Predictive policing engages Art.8 (privacy), Art.6 (fair trial), and Art.14 (non-discrimination). Automated surveillance can interfere with “private life” (Art.8), especially if individuals are flagged or checked without individualized suspicion. The SyRI case is instructive: Dutch courts held that secretive risk-scoring violated Art.8 due to lack of safeguards. The CJEU (following ECHR principles) has ruled that algorithmic profiling requires human review to avoid arbitrariness. Article 6’s fair trial guarantee implies any evidence (or enforcement action) partly based on an opaque algorithm must be contestable by the accused. Article 14 forbids discrimination; hotspot policing can indirectly target minority neighborhoods, risking disparate impact. Although not explicitly settled, any predictive system must avoid biases or profiling that treat protected groups unfavorably. For example, algorithmic stops used by Austrian police were challenged under ECHR (ECtHR security/archive cases) when they targeted Roma communities – indicating that unchecked predictive policing could run afoul of anti-discrimination obligations.
  • National Criminal Procedure Laws: In Germany, the Federal Court of Justice has signaled that suspects must be informed of evidence (possibly including algorithmic reports) in a criminal case. Automated profiling may also bump into the prohibition on databases of suspects (German constitutional tradition and police codes). Dutch law forbids use of intelligence analysis against persons without suspicion. These national constraints mean predictive outputs must feed into human decision-making, not replace it.
  • Judicial Oversight: Any person adversely affected by predictive policing could seek judicial review. Courts in Europe are still adapting to AI: e.g., in the CJEU’s recent Liga des droits humains case (C-817/19), the Court struck down automated passenger checks without human validation. EU Charter rights (Arts.47, 48) guarantee effective remedy, which in context suggests that individuals should be able to challenge unfair automated police processes, even if not explicitly codified yet.

Article 5 Decision Tree (Prohibited vs. High-Risk vs. Out-of-Scope)

A schematic decision tree under Article 5 of the AI Act is as follows (illustrative):

  1. Is the AI system used to assess/predict a natural person’s risk of crime?
  • No (e.g. purely place-based forecasting): The system is not caught by Art.5(d). Check Annex III: if it doesn’t fall under any high-risk use case (and location-hotspot tools typically don’t), it is outside the Act (subject only to general laws like GDPR, LED).
  • Yes (predicting individuals’ risk): Proceed to 2.
  1. **Is the risk assessment based solely on profiling or personality traits?**
  • Yes: This use is prohibited (Art.5(d)). No deployment allowed. Example: an AI that, solely on the basis of a person’s ethnicity and social media profile (and no concrete criminal evidence), labels someone “high-risk for violent crime.”
  • No (also includes other factual inputs, or is used to support human assessment): The blanket ban does not apply. But now check Annex III.
  1. Annex III High-Risk Law Enforcement: If the system is intended for law enforcement use and fits one of the listed categories, it is high-risk (subject to strict rules). Annex III(6)(d) specifically covers systems “assessing likelihood of offending/re-offending not solely based on profiling or personal characteristics or past behaviour”. Thus an allowed person-risk AI (step 2=No) automatically becomes high-risk. It must comply with Articles 9–27 (risk management, data governance, documentation, human oversight, accuracy, security, a fundamental-rights impact assessment, etc.).
  1. Special Case – Support of Human Assessment: Article 5(d) explicitly excludes AI that “supports the human assessment of involvement” already based on objective facts. In practice, if the AI is not the basis for new suspicion but only helps sort or visualize existing evidence, it falls under this exception. For example, an AI that flags files matching known criminal fingerprints for human follow-up would likely be exempt. The CJEU emphasized that human review must rely on objective, verifiable criteria (so that the algorithm’s output does not cause unjustified alerts).

Illustration: PRECOBS/CAS-type systems output location risk, not person risk → Out-of-Scope. A hypothetical AI that risk-scores people solely by profiling → Prohibited. A recidivism-risk score that uses arrest records plus some profiling factors → High-Risk (Annex III). An evidence-based pattern recognition tool used only to aid detectives → likely exempt.

Crime Reduction Effectiveness

Claims of crime prevention by predictive systems must be tested empirically. In practice, the evidence is weak or mixed:

  • Academic Evaluations: A scientific study of the Baden-Württemberg Precobs pilot (“P4”) reported some modest crime reduction, but noted methodological issues and uncertainty. It concluded that while police found Precobs useful, measurable effects on burglary rates were “unclear” and “moderate”. Another analysis (Karlsruhe and Hannover pilots) similarly found no statistically significant drop in offenses due to predictive patrols.
  • AlgorithmWatch Findings: Independent investigations conclude there is a “complete lack of evidence” that predictive policing tools reduce crime. For example, a 2023 Wired analysis cited by AlgorithmWatch found that one hotspot tool’s predictions in New Jersey were accurate in under 0.5% of cases. Police themselves rarely release rigorous results; an internal Dutch evaluation of CAS apparently saw only marginal improvements (insufficient to justify its continuation).
  • False Positives: Predictive maps often yield many false leads. AlgorithmWatch highlights that the German PNR (passenger-name record) system flagged tons of non-criminal data, with only 0.3% accuracy when human-checked. By analogy, a location-based predictor might generate dozens of “high-risk” blocks where no burglaries occur, leading to wasted patrols. The Dutch CAS reports did not claim blockbuster effects – they noted that CAS can guide patrols but is only one tool among many.
  • Interpretation: In summary, neither PRECOBS, SKALA, KrimPro, nor CAS has publicly demonstrated large crime-reduction benefits. Independent experts warn these tools can produce “optical illusions of accuracy” and may merely redeploy existing police effort to previously high-crime areas. As one analyst put it, predictive policing “is not a panacea”. Future evaluations must control for confounding factors (seasonality, general policing trends) to isolate any AI effect.

Bias and Feedback Loops

Predictive-policing algorithms can inadvertently amplify existing biases and create harmful feedback loops. Key concerns include:

  • Data Bias: These systems rely on historical crime reports. If policing was already focused on certain neighborhoods or populations, those areas will generate more data, skewing the model to predict more crime there. For example, if minority or low-income neighborhoods have higher police presence, the algorithms may label them as high-risk repeatedly – a self-reinforcing cycle. AlgorithmWatch notes that hotspots “tend to be places where minority groups live,” and elevated patrols there lead to more recorded offences (often petty or surveillance arrests). This is known as the “Lüchow-Dannenberg syndrome”: more police presence produces more recorded crime.
  • Feedback Loops: Once an area is flagged, police concentrate there. Any increased detection (e.g. of vehicle break-ins or trespassing) further populates the database, making it appear ever-riskier. Meanwhile, other areas receive less attention, potentially allowing unreported crime to rise unseen. In practice, such feedback can create phantom risk “hot spots.” This distortion has been documented in U.S. studies of predictive policing and is a theoretical concern in Europe.
  • Disparate Impact: Even when not explicitly using race or religion, these tools can correlate with protected attributes. People flagged as suspects by proximity or social network can be arrested “by association,” broadening criminal suspicion beyond actual offenders. Human rights experts warn this yields racial profiling and discrimination: “numerous examples” show algorithmic policing leading to targeting of migrants or Muslims.
  • Algorithmic Bias: If socio-economic data (like unemployment or school dropout rates) are used as inputs (as SKALA did), any existing socio-spatial inequality might translate into biases. Without careful bias audits, the models can codify prejudiced assumptions. For example, if older statistical predictors undervalue petty theft, the AI may overlook rising theft patterns among underrepresented groups.
  • No Self-Correction: Most police AIs do not incorporate feedback to correct for their own errors. If a prediction turns out false, the fact is rarely fed back into retraining. There is a risk of “feedback incarceration” (akin to biased recidivism algorithms), where certain individuals or areas are repeatedly targeted without review.

The upshot is that predictive policing systems must be audited for bias continuously. The AI Act’s requirements (robustness, monitoring, stakeholder input) are intended to mitigate these risks, but many of the European projects described did not publish any independent bias assessment. Transparency and impact assessment (GDPR DPIAs, AI Act risk management) are critical to detect and prevent runaway biases.

Transparency and Accountability

Public transparency and redress rights are uneven across these systems:

  • Netherlands (CAS): The CAS was entered in the Dutch government’s Algorithm Register, providing a detailed public description of its operation. This register entry (in English) explains the data inputs, model (logistic regression on incident/suspect counts), and legal basis. Dutch law (2017 police transparency decree) requires such algorithm disclosure. A Human Rights Impact Assessment was also completed yearly. Citizens thus could learn how CAS worked, though CAS outputs themselves were internal to police teams. Under Dutch data protection, individuals have some rights: if a person felt disproportionately targeted by police patrols prompted by CAS, they could in theory file a complaint (though no precedent exists).
  • Germany (PRECOBS/SKALA/KrimPro): No equivalent public register exists. The use of these tools is generally internal knowledge of police; official information comes from occasional press releases or academic reports. For example, Bavaria’s interior ministry confirmed Precobs use in 2015 but provided no algorithmic details. There is no legal obligation for German police to disclose such models (though institutional audits might exist behind closed doors). Consequently, citizens have little transparency. In practice, an ordinary resident likely cannot find out whether patrol patterns are driven by Precobs data or just random shifts. Under GDPR, data subjects have limited rights in law enforcement contexts (Article 22 and LED mostly exempt automated police decisions). If a German citizen were “hit” by a Precobs patrol, it would be treated as ordinary policing, with no specific explanation offered.
  • Challenging Decisions: Since these systems do not produce formal “decisions” (e.g. a warrant), the right to contest them is unclear. However, the AI Act and GDPR could empower a person who is surveilled or stopped because of an AI flag to ask for information on the system logic. For now, the main accountability is internal: police regulations and supervisory bodies (e.g. data protection authorities, ombudspersons) may review deployments.
  • SyRI Case: The SyRI case illustrates lack of transparency: individuals were not informed that they were “profiled,” which the court noted undermined effective rights enforcement. By contrast, CAS’s anonymization meant individuals were never labeled, so no individual notice was provided or needed.
  • Summary: Dutch CAS earned high marks for transparency by disclosing its algorithm. German systems lack public scrutiny. The new AI Act (Article 11) will require logbooks and summaries of high-risk AI; this will force European police to document system design, training data, and outcomes (to supervisory authorities and – in redacted form – to public databases) once it takes effect. Until then, oversight remains largely internal, raising concerns about accountability.

Avoiding the Ban: Labels and Re-Characterizations

Police agencies may attempt to skirt prohibitions by how they label systems. For example, calling a predictive model “decision support” or “situational crime analysis” rather than “risk scoring” does not avoid the law: the AI Act looks at function, not name. If an AI predicts individuals’ likelihood of offending, it falls under Article 5(d) regardless of label. However, agencies sometimes emphasize that these tools are only “intelligence analysis” or “resource prioritization aids” to downplay regulatory triggers. The Act’s Recital 46 explicitly prevents such evasion: AI systems facilitating law enforcement are still covered even if termed “operational technology” or “intelligence tools.” In practice, say a police force calls its system an “analytics dashboard” rather than “predictive policing.” If the dashboard is essentially generating crime forecasts or suspect profiles, EU law still applies (the outcome is what matters).

The distinction between pure analytics and prohibited AI will hinge on whether automated risk scoring is core. For example, if PRECOBS is described as “pattern analysis of past burglaries,” that’s fine; but if it were repackaged as “identifying potential criminals,” it would be Art.5 material. The Guidelines make clear that AI used as a transparent “detection of criminals” is high-risk/prohibited if not based on facts. In short, rebranding is not a loophole: European law is substance-over-form.

However, there is room for permissible framing: The AI Act allows AI for “crime analytics” (Article 6(3) carve-out) if purely assisting human police without decisive influence. Some EU deliberations even exempt “data analysis for investigation” from high-risk classification. Thus police might legitimately say, “We only use this to generate leads, humans still do all decisions,” and that could place the system in a lower-risk category. But as soon as the AI output becomes a determinant factor (or profiles a person), heightened rules or bans kick in. The lesson: EU police must carefully document exactly how AI informs decisions and ensure compliance, rather than merely rely on euphemistic labels like “intelligence analysis.”

Comparison: FBI’s Proposed TSC AI (US)

For context, note that other countries are pursuing similar ideas, albeit under different legal regimes. In the U.S., the FBI’s Threat Screening Center (TSC) – originally for terrorism watchlists – is proposing new AI capabilities to “predict who might be a terrorist” by analyzing large domestic intelligence databases. A recent Reason magazine exposé details a 2026 FBI request for information about a predictive AI to flag individuals based on a wide array of “enriched data” (financial, travel, social media, etc.). This is essentially a person-targeting risk model for domestic threats.

Comparatively, the EU AI Act would treat such a TSC AI as prohibited if it assessed risk solely by profiling (and likely even if it used enriched data, it would be Annex III high-risk at best, given the profiling emphasis). But in the U.S., there is currently no comprehensive AI law or constitutional equivalent to this ban; the FBI faces only internal oversight and the courts (First, Fourth Amendment). The TSC example underscores how divergent approaches can be: European lawmaker’s caution (ban “solely profiling-based risk” algorithms) directly contrasts with some American agencies’ embrace of aggressive data-driven targeting. It also illustrates the scope of Article 5(d): the FBI system explicitly aims at future unknown offenders, analogous to SyRI but for terrorism. Under the EU AI Act, any such FBI tool would be banned in Europe (unless used only as a modest support tool for specific human-made cases).

Ensuring Compliance: A Checklist for European Police

For any EU police authority or contractor developing AI analytics, compliance under the new rules requires a structured audit. Below is a non-exhaustive compliance checklist:

  • System Classification: Identify whether the AI is place-based or person-based. If it predicts individual criminal risk, check Article 5(d) – is it solely based on profiling/personality? If yes, it is banned. If not solely (i.e. includes objective data), treat it as high-risk (Annex III). If the system only forecasts locations or assists human investigators, it may fall outside Art.5.
  • Legal Basis & Purpose: Ensure a clear legal framework authorizes the AI. For law enforcement, tie the use to specific statutory mandates (e.g. crime prevention under police law). Document the purpose (e.g. “resource allocation aid for burglary prevention”). Under GDPR/LED, establish which Article 6 condition justifies processing (e.g. “necessary for official law enforcement tasks” under LED). Avoid processing special categories or irrelevant personal data.
  • Data Governance: Use only lawfully collected, relevant data. Police records are usually allowed (WPG Art.8/13, LED). Remove personal identifiers if possible (CAS anonymized data). Evaluate sources for bias: if adding socio-economic data, test for correlation with protected traits. Maintain data quality logs and provenance (AI Act Art.10, 11).
  • Model Development: Keep model architecture and training methods documented. For high-risk systems, conduct a Fundamental Rights Impact Assessment (Art.27). Use explainable algorithms or add explainability layers. If using machine learning, calibrate against historical data and human expertise to avoid unjust bias.
  • Human Oversight: Design workflows so that no AI prediction is blindly acted upon. Embed human analysts to review alerts and make final decisions (“human-in-the-loop”). As per Art.5(d) and CJEU, ensure that any flagged persons are assessed on “objective and verifiable facts” by an officer. This fulfills both the AI Act exception and fair-trial guarantees. Document the oversight process (how many officers reviewed, criteria used).
  • Transparency: Even if not legally mandated yet, aim to be transparent internally and externally. Under EU law, high-risk AI must publish summary documentation and register with the EU database (Art.49). Prepare clear user manuals and logs. Communicate to affected communities (e.g. neighborhood groups) that crime maps or analytics are in use, to build trust.
  • Accountability & Remedies: Establish internal complaint channels. If a citizen feels targeted (e.g. by increased stops in their area), there should be a procedure to review the data that led to that decision. Ensure compliance with Art.22 GDPR: if any automated processing has legal effect on an individual (e.g. denying a permit, setting bail), give explanations and chance to contest.
  • Monitoring & Auditing: Regularly audit system outputs. Compare predicted vs. actual crime rates; track false positives/negatives. Analyze whether certain populations or areas are overrepresented. The AI Act (Art.61) will empower authorities to inspect high-risk AI – be ready with records, code reviews, impact study results.
  • Training & Policies: Train police personnel on the limitations of predictive AI (e.g. not to treat scores as facts). Develop written policies defining acceptable use-cases and prohibited use (e.g. “no automated decisions on individuals without human sign-off”). Include privacy and non-discrimination training.
  • Legal Oversight: Coordinate with data protection authorities and judiciary. For example, seek formal guidance (Article 50 of LED requires Member States to designate independent authorities). Stay informed about national rulings (like the Dutch SyRI verdict) that might analogously constrain new tools.
  • Emergency Provisions: The AI Act allows temporary derogations for serious crime (Art.5(h) permits certain biometric ID uses for missing persons, etc.), but not for broad profiling. No general “emergency” clause overrides the profiling ban. In short, don’t assume anti-terror or crisis scenarios can justify otherwise-illegal profiling algorithms without express law.

This checklist, while not exhaustive, outlines the main compliance points under EU and national law. In practice, it means predictive tools must be built with “AI by design” principles: privacy, fairness, security, and human control engineered from the start. Failing to do so risks not only technical failure but also legal sanction – under the AI Act and fundamental rights law.


Sources: Official laws and guidelines (Reg. 2024/1689, AI Act guidance, LED), government algorithm registries, police reports and audits, EU legal scholarship, scholarly evaluations, and credible reporting. These have been cited above. Statements not explicitly sourced reflect widely reported facts or legal interpretation.