Deploy AI Undercover Agents That Hold Up in Court
Undercover AI agents can support investigations only when operators pre-approve legal authority, supervision, evidence capture, and exit rules.

Before an AI agent posts its first message, the operator must already know what it may say, who can stop it, and where its messages will be stored. The deployment is defensible only when that record exists before the agent enters the hostile space.
Infiltration agents are moving beyond scrapers
Aslan left stealth on September 1, 2026, after raising a $20.8 million seed round. Aslan provides agents to the FBI and broader intelligence community, and the agents can present themselves as analysts in underground criminal forums.
Aslan's platform deploys autonomous AI agents with human supervision, not passive scrapers or keyword monitors, inside criminal ecosystems. Aslan's agents are designed to join forums, create cover identities, and maintain activity over extended periods instead of only observing traffic from outside. One disclosed deployment ran for 21 days in Telegram channels, mapping who was coordinating border crossings and when they were likely to occur in a transnational smuggling case.
The risk is that the agent becomes both a source of information and a source of liability. If the operator cannot show who approved the cover, who reviewed the agent's messages, and where the data is stored, the output is hard to use. The operator needs a record that can survive a challenge, not just a transcript.
The checklist makes the agent defensible
A deployment is a case file in motion. The steps force the operator to answer the questions a prosecutor, judge, or internal reviewer will ask later. Each step should produce an artifact: a short mission statement, an ecosystem map, a cover brief, a supervision log, an evidence manifest, a legal sign-off, and an exit plan.
- Mission question. Write the question the agent must answer. If the answer cannot be used in a report, a referral, or a court filing, narrow the mission. Separate the intelligence product from the evidentiary record. The agent may produce leads, but the case needs a defensible path from message to conclusion.
- Target ecosystem. Map the channel, roles, trust signals, and risks before the agent posts. Identify who is likely to be harmed if the cover fails. Note the entry path, trust requirements, and false flags that would expose the cover.
- Cover identity. Pre-approve the persona, its limits, and the topics it may touch. The cover should support the mission, not expand it. It must not recruit, induce, or push targets toward new conduct.
- Supervision cadence. Set human review intervals, escalation triggers, and a named operator who can stop the agent. Tie supervision to risk, not convenience. Use sampled reviews, adversarial prompts, and a kill switch that does not depend on the agent's cooperation.
- Evidence preservation. Capture messages, metadata, timestamps, and the agent's actions in a defensible chain. Store copies where they cannot be altered after the fact. The manifest should list what was captured, when, by whom, and where it is stored.
- Legal and data review. Confirm authority, consent, data minimization, retention, and storage before deployment. Government customers have used Aslan mainly in brief trials while deciding how to impose guardrails and manage data collection and storage. If the legal authority is unclear, the deployment should not start.
- Exit criteria. Define when the agent stops, how it leaves, and what gets handed off. Aslan has not made public the legal basis for its deployments. That gap belongs in the pre-deployment review, not in the post-incident memo. The handoff should include the evidence manifest, the supervision log, and a plain-language summary of what the agent did.
Judge readiness before the agent speaks
Operators can judge a vendor or internal team by the same controls. A deployment passes when the operator can explain it to a reviewer in writing without improvising. Can the operator show why the agent is authorized, why its output is trustworthy, and why it stopped? If the answer is yes, the agent can support the case. If the answer is no, the agent should stay offline.