Evidence · Federal rules

FRE 902(13), 902(14), and electronic records from AI systems

Two rules added to the Federal Rules of Evidence in 2017 address self-authentication of machine-generated records and of data identified by hash value. Both are relevant to how AI decision records should be built.

Rule 902 lists categories of evidence that are self-authenticating, meaning extrinsic evidence of authenticity is not required as a condition of admissibility. Two subsections added in 2017 speak directly to machine-generated data.

  • 902(13) covers a record generated by an electronic process or system that produces an accurate result, as shown by a qualified person's certification.
  • 902(14) covers data copied from an electronic device, storage medium, or file, if authenticated by a process of digital identification, again with certification.

Both still require certification by a qualified person and notice to the opposing party. Neither makes a record automatically admissible or automatically believed. What they do is remove the need to call a witness merely to establish that a hash-identified copy is what it purports to be.

Why 902(14) mattered

The advisory committee's reasoning was practical: hashing was already standard forensic practice, and requiring live testimony to establish that a hash matched imposed expense without adding accuracy. The rule recognised what practitioners already did.

The same logic extends naturally to records whose integrity is established by cryptographic means rather than by custodial testimony.

Where AI decision records fit

An attested decision record is designed around the properties these rules care about:

  • It is generated by an automated process at the time of the event, not assembled later.
  • Its integrity is established by a hash, checkable by anyone.
  • Its time is witnessed by a public ledger the record's owner does not operate, which is a stronger claim than a system clock the owner controls.

The certification requirement does not go away. What changes is what the certifier has to assert: that a documented process produced the record and that the verification procedure is what it claims to be, rather than that nobody edited the database.

Check it yourself

Every Rubric attestation resolves publicly, with no account and no API key, and every anchor resolves to a public ledger message you can read without our cooperation.

HCS topic 0.0.10416909 · ML-DSA-65 signatures

Verify an attestation · Read the ledger ↗

Outside the United States

Other jurisdictions handle electronic evidence differently, and some place more weight on custodial process than on cryptographic identification. Independent anchoring is useful in both framings for the same underlying reason: it converts a question about institutional trustworthiness into a question anyone can check.

Related: How to prove an AI decision happened · Tamper-evident AI logs · Key custody