Beyond the Artifact

Psychology, AI, and the Human Story Inside Digital Forensics

When most people hear digital forensics, they picture a specialist recovering deleted files, examining a phone, or building a timeline from logs. That work matters, but it is only the beginning. The harder part usually comes after an artifact has been found: deciding what it means, how it relates to everything around it, and what the evidence can support without stretching beyond it.

My own path into this field has never been purely technical. I studied psychology before completing graduate work in digital forensics and cyber investigations, and I have never viewed those subjects as separate disciplines. Every device is used by a person. Every account reflects choices, habits, pressures, relationships, and sometimes mistakes. The technology records pieces of activity; the investigator still has to reconstruct the human story behind them.

Every device carries a human story

A download, file deletion, cloud sync, removable-drive insertion, or unusual login can be significant, but none of those events automatically explains itself. A large transfer may be routine project work, careless convenience, preparation for departure, or deliberate theft. A deleted message may reflect concealment, embarrassment, normal housekeeping, or an automated retention rule. The same technical action can carry very different meaning depending on the person, the environment, and the events surrounding it.

This is where psychology helps. It does not allow an examiner to read someone’s mind, and it should never be used to force a motive onto incomplete evidence. It provides a disciplined way to think about behavior: routines, incentives, stress, opportunity, rationalization, concealment, and the small inconsistencies people create when their actions do not match their explanation. Those ideas help form better questions and better competing hypotheses. They tell us what else to look for, not what conclusion we are entitled to assume.

Behavioral context also matters in ordinary, non-malicious cases. People take shortcuts. They reuse personal cloud storage, send work to themselves, forget which device holds the latest version, or let convenience outrun policy. Understanding those patterns prevents every policy violation from being labeled an attack while still recognizing when a familiar shortcut becomes the path for real harm.

Psychology also protects the investigation from itself

The person being examined is not the only human factor in an investigation. Examiners, leaders, attorneys, and clients bring expectations into the room. Once a theory takes hold, confirmation bias can make every new artifact look like support. Hindsight can make an earlier decision seem more obvious than it was at the time. A dramatic artifact can become an anchor that receives more weight than the quieter evidence around it.

A psychology-informed approach turns the lens back on the investigation. What evidence would weaken the current theory? Is there a routine explanation that fits the same activity? Are we treating correlation as causation, access as use, or opportunity as intent? A defensible report should separate observed fact from analytical inference and explain what the available evidence does - and does not - establish. The goal is not to produce the strongest-sounding accusation. It is to produce the conclusion most capable of surviving scrutiny.

From Riley vs CA to the AI inflection point

One of the people who sharpened how I think about this field is Dr. Greg Gogolin, a former professor of mine and mentor. From his early work in information technology through the growth of modern digital forensics, Greg has watched the discipline move from the far less settled environment of the 1990s into a field with more mature methods, professional standards, legal precedent, and expectations for defensible reporting. His publication record follows that development, from "The Digital Crime Tsunami" and Digital Forensics Explained to work on civil proceedings and the project management of complex examinations.

What has stayed consistent is his emphasis on understanding the process before becoming attached to a particular tool. In Digital Forensics Explained, he warns that tools and screenshots age quickly as technology changes, while methodology and investigative discipline endure. That is especially relevant now. A product may help an examiner acquire, parse, or sort data, but no product can relieve the examiner of the need to understand how the evidence was created, what altered it, what context is missing, and how confidently it can be interpreted.

"An understanding of the process is primary." - Dr. Greg Gogolin

I remember Greg bringing up Riley v. California while we were discussing the evolution of digital forensics and the legal framework that now surrounds it. Riley held that police generally must obtain a warrant before searching the digital contents of a cell phone seized incident to arrest. The U.S. government’s amicus brief cited Greg’s 2013 edition of Digital Forensics Explained repeatedly.

The brief drew on his work to discuss device isolation, forensic extraction tools, costs, training, and the practical risk of losing data. That connection matters because the case did more than establish a rule. It recognized that a phone is not merely another physical container; it can hold a breadth and depth of a person's life that older search doctrines were never designed to address.

We are now at another inflection point. AI changes both sides of the forensic problem. It creates a new class of artifacts through prompts, responses, uploaded source material, generated files, account records, and the actions that follow. At the same time, it is becoming part of how investigators collect, index, cluster, prioritize, summarize, and connect large volumes of evidence. The lesson from the field's earlier transitions is not that new technology replaces established principles. It forces us to reexamine how preservation, authorization, scope, validation, transparency, and human judgment apply when the technology’s scale and capability change.

AI has entered the evidence set

For the last several years, much of the conversation around AI and digital forensics has focused on what AI can do for the examiner. It can identify patterns, reduce repetitive work, summarize large collections, flag anomalies, and help an analyst move through information at scale. That can be enormously useful.

But speed is not the same thing as understanding. AI should be treated as an accelerator, not a substitute for judgment. There is now a second and equally important question: what happens when a person’s use of AI becomes part of the matter being examined? People increasingly use generative systems to research, plan, write, summarize, translate, code, analyze files, and make decisions. Those interactions can reveal objectives, questions, drafts, source material, instructions, and a sequence of thought that may not exist anywhere else in the same form.

AI is not one new artifact. It is a new evidence environment.

That environment can include prompts, responses, conversation titles, timestamps, uploaded files, generated downloads, account and authentication records, browser history, cached content, local application data, integrated-tool activity, and traces left on endpoint, identity, network, and cloud systems. Some evidence may live on the device. Some may exist only in a service provider’s environment. Some may be synchronized across several systems, and some may disappear quickly. Understanding where AI touched the workflow is becoming as important as understanding the endpoint itself.

A prompt is not an act - and an answer is not a fact

AI evidence carries its own interpretive traps. A prompt can show that a question was entered, but it does not automatically prove that the person carried out the action being discussed. Asking a system to draft an email is not the same as sending it. Requesting code is not the same as executing it. Uploading a document for summary does not prove the user accepted, understood, or acted on the summary. Even authorship may require corroboration when accounts are shared, text is pasted from elsewhere, voice input is used, or automated tools submit requests in the background.

The model’s answer requires even more care. A generated response may be incomplete, inaccurate, or confidently wrong. Its forensic significance may be that certain information was presented to the user, not that the information was true. An examiner must distinguish among what the user requested, what the system generated, what the user retained or modified, and what later occurred on the device or network. Collapsing those steps into one conclusion can turn a useful artifact into a misleading one.

The same discipline applies when AI is used inside the investigation. A generated summary, classification, or proposed connection should be treated as a lead until it can be traced back to the original evidence and reproduced or independently validated.

Connecting the dots without inventing the picture

Strong forensic conclusions rarely come from one source. They emerge when endpoint artifacts, identity records, network activity, cloud logs, mobile data, and security telemetry begin to support the same sequence. If a sensitive file was copied at 11:42, the timestamp alone says very little. When it aligns with a new access grant, an unusual login, a bulk download, a cloud upload, an AI conversation about the material, and later activity involving the generated output, the investigator has a much fuller picture to test.

The purpose of correlation is not to make the story more dramatic. It is to challenge alternative explanations. Does the timeline remain consistent across systems? Do the account and device belong to the same user? Are the clocks synchronized and the time zones understood? Is there evidence of execution, transmission, or access after creation? What looks suspicious in one data source may become ordinary in another, while a seemingly minor event may become decisive when placed in sequence.

Forensic tools are excellent at parsing, indexing, carving, and organizing enormous amounts of data. They can reveal relationships an examiner might otherwise miss, but they cannot decide which relationships matter, which explanations are credible, or how firmly a conclusion can be stated. Technical knowledge, behavioral understanding, and evidentiary discipline still have to work together.

Preserving AI evidence requires a wider lens

An AI conversation visible on a screen is only one layer of the record. A screenshot may document appearance, but it may not preserve origin, account identity, hidden metadata, uploaded content, edits, or the relationship between the conversation and a generated file. When authority and access allow, the better record includes native exports, relevant account data, timestamps and time zones, associated files, model or service information, browser and endpoint traces, and the surrounding identity and network activity.

The fundamentals do not change: preserve the original, document how it was acquired, verify files with cryptographic hashes, maintain chain of custody, and record what could not be collected. What changes is how many places the evidence may live and how quickly it may change. Cloud retention, conversation history, model behavior, and integrated tools can all evolve. In AI-related matters, early preservation may determine whether the full context remains available.

Why human judgment matters more as the tools improve

AI can make an inexperienced person sound polished, make copied work appear original, or turn a rough idea into a finished product in seconds. That complicates authorship and weakens many of the surface cues people once relied on. It also amplifies familiar human behavior: curiosity, convenience, impulsiveness, concealment, experimentation, and the tendency to trust an answer that arrives quickly and sounds certain.

Psychology helps an investigator ask how and why the system was used. Digital forensics shows what traces that use left behind. Corroboration tests whether those traces connect to real-world activity. Just as importantly, evidentiary discipline limits how far the conclusion can go. Advanced tools can process more information, but human instinct still identifies what may matter, and decisive action still depends on conclusions that are clear, measured, and defensible.

The next forensic mindset

Digital forensics is no longer limited to examining a device. It is the reconstruction of activity across devices, identities, cloud services, AI interactions, and human decisions. The examiner of the near future will need to understand not only how to use AI, but how AI systems create, transform, store, and sometimes obscure evidence. Technical fluency alone will not be enough, and neither will behavioral intuition without a verifiable record.

The strongest work will continue to come from the overlap: sound acquisition, careful preservation, technical validation, behavioral insight, and the humility to stop where the evidence stops. Digital artifacts are fragments. Our responsibility is to connect them without forcing them into a story they cannot support.

The best forensic work does not force the evidence to fit a picture. It takes human instinct, experience, and judgment to connect the right dots…. and the discipline to stop where the evidence stops. - Rob White, Founder, Cipher Ridge LLC


Sources and further reading:

Gogolin, G. (2010). "The Digital Crime Tsunami." Digital Investigation, 7(1-2), 3-8. doi:10.1016/j.diin.2010.07.001.

Gogolin, G., and Jones, J. (2010). "Law Enforcement's Ability to Deal with Digital Crime and the Implications for Business." Information Security Journal: A Global Perspective, 19(3), 109-117.

Gogolin, G. (2013). Digital Forensics Explained. CRC Press. Second edition published in 2021.

Gogolin, G., and Jones, J. (2013). "Digital Forensic Issues in Civil Proceedings." Journal of Civil & Legal Sciences, 3:110. doi:10.4172/2169-0170.1000110.

Gogolin, G., Gogolin, I., and Gogolin, S. (2023). "Project Management in Digital Forensic Investigations." Journal of Forensic Sciences & Criminal Investigation, 17(1), 555951. doi:10.19080/JFSCI.2023.17.555951.

Riley v. California, 573 U.S. 373 (2014).

Brief for the United States as Amicus Curiae Supporting Respondent, Riley v. California, No. 13-132 (2014).

Previous
Previous

Insider Threat: Psychology, Opportunity, and Risk

Next
Next

Your VPN Is Not a Force Field: What That Encrypted Tunnel Actually Protects