
– Tanya Kumari
- Introduction: When the Machine Is Always Right
Consider the experience of a postmaster in a quiet English village who discovers a cash shortfall at the post office, money that they are certain they never handled. However, the computer system indicates otherwise. Despite reporting the issue, their concerns are dismissed, as the computer’s output is trusted over human testimony.
This wasn’t just a hypothetical. Hundreds of sub-postmasters across the UK endured this ordeal. Beginning in 1999, the British Post Office prosecuted them for theft and fraud, all based on discrepancies flagged by a software system called Horizon. The courts accepted it without question. So did lawyers and judges. More than seven hundred convictions followed. (Impact of IT Act Amendments on the Indian Evidence Act, 1872, 2024) It took almost twenty years and a damning public inquiry to finally reveal what should have been clear all along: Horizon was full of errors, the Post Office knew and yet the justice system looked the other way because nobody dared question the computer.
The UK Post Office scandal isn’t just a story about mistakes in Britain. It’s a warning for any country where the law treats computer output as an unquestionable fact—including India. As we transition from the Indian Evidence Act of 1872 to the Bharatiya Sakshya Adhiniyam, We are at a turning point. The new law uses modern language, such as “semiconductor memory” and “communication devices,” and treats digital records as primary evidence. But there’s an important question: has this shift changed how we actually think about trusting technology in court, or just given old habits a fresh coat of paint? From what I’ve seen as a final year law student, it’s mostly the latter. That gap between new words and old thinking could be a recipe for future problems.
- What Is a Presumption, and Why Should You Care?
Before addressing the legal complexities, it is important to clarify the concept of a presumption. In essence, a presumption is a legal mechanism that allows a court to accept a fact as true unless it is disproven. This approach enables the law to proceed based on assumed facts, subject to challenge by contrary evidence.
There are two main kinds of presumptions. A rebuttable presumption can be challenged with sufficient evidence. A conclusive presumption, by contrast, can’t be questioned—it’s final. That difference matters in the real world. Section 114 of the IEA, now updated in the BSA, allows courts to decide whether they “may presume” certain facts based on context. But if the law says “shall presume,” the court has no choice; it must accept that fact. One approach invites reasoning; the other just gives an order.
In the context of technology, the presumption of regularity has traditionally meant that machines are assumed to function correctly unless proven otherwise. This assumption was reasonable for mechanical devices such as scales or speed radars, where malfunctions could be visually detected or verified by experts. However, extending this trust to modern software systems is problematic because even developers may be unable to explain the internal workings of complex algorithms fully.
- The IEA to BSA Transition: Real Progress, Real Gaps
The legislative shift from the IEA to the BSA is not cosmetic. The most meaningful change is in how electronic records are classified and admitted. Under the old regime, electronic records were treated as secondary evidence. Admitting them required compliance with the notoriously cumbersome Section 65B of the IEA, which required a signed certificate confirming the computer’s proper functioning, the regularity of its use, and the accuracy of the output. Simple in theory; brutal in practice. The Supreme Court spent years fighting over it.
In Anvar P.V. v. P.K. Basheer (2014), the Court held that the certificate was mandatory; without it, electronic evidence was inadmissible. Then came Shafhi Mohammad v. State of H.P. (2018), which softened this, allowing courts to summon certificates even when the party producing the evidence did not own the device. Then Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) walked it back again, reinstating the mandatory certificate requirement while clarifying who exactly could furnish it. Three landmark cases, three different answers. The uncertainty itself was a crisis.
The BSA steps in to resolve this chaos. Section 62 of the BSA takes a conceptually significant leap: digital records produced from “proper custody” are now primary evidence. No longer a secondary category requiring special justification, they stand on their own. Section 63 of the BSA replaces Section 65B, retaining the certificate requirement but with clearer language, and importantly, introducing the concept of hash value verification, the digital fingerprint that can confirm a record has not been altered between creation and production in court.
While these developments appear progressive, a significant limitation remains. Section 63(2) continues to presume that the computer generating the record was functioning correctly and used appropriately. The burden to challenge this presumption falls on the opposing party, typically the accused or a less powerful litigant, who rarely has access to server logs or maintenance records. In my view, this is where the law’s modernization efforts are insufficient.
- The Black Box Problem: You Cannot Presume What You Cannot See
Consider a hypothetical scenario: a judge is presented with a printout from a government facial-recognition database indicating that the accused was present at a crime scene. The requisite certificate under Section 63 is provided, and a representative of the software company attests that the system is functioning properly. Should a conviction be based solely on this evidence?
Under the law as it stands, you might feel pressured to convict because the presumption of regularity does all the work. But here’s the problem: nobody in the courtroom, not even the certificate, can explain how the system reached its answer. Facial recognition algorithms, like many AI tools, are “black boxes.” Even their creators can’t always say exactly how they work. The system spits out a result, but nobody can trace the reasoning behind it. So when the court assumes the system was working properly, it’s not really making a logical judgment; it’s just taking a leap of faith, dressed up in legal terms.
This is not hypothetical paranoia. Studies of facial recognition systems used in law enforcement, including in the United States and the UK, have documented significant error rates, with racial and gender bias baked into the training data. The Horizon scandal is again the proof of concept: presuming machine reliability without interrogating machine logic allowed a catastrophic injustice to persist for nearly two decades.
For Indian courts, the implications are both immediate and significant. Surveillance systems, predictive policing tools, and automated databases are becoming integral to law enforcement operations. If evidence from these systems is admitted solely based on a Section 63 certificate, without scrutiny of the algorithm’s accuracy, error rate, or dataset, the judiciary effectively delegates fact-finding to mechanisms not subject to courtroom audit. The certificate merely authenticates the output, offering no insight into the underlying reasoning.
- Deepfakes, Metadata, and Why “Proper Custody” Is Not Enough
There is a second dimension to this crisis that receives less attention: the presumption of genuineness. Under Section 90 of the IEA, a document 30 years old, produced from proper custody, was presumed genuine. The logic was sound for its time, as forging old documents was genuinely difficult, requiring expertise, aged paper, and period-accurate materials. That world no longer exists.
A deepfake video can be created in hours with freely available software. A photograph’s metadata, the invisible layer that records when and where it was taken, can be overwritten in minutes. A PDF can be altered without leaving any visible trace. In this environment, asking whether a document came from “proper custody” tells you almost nothing meaningful about its authenticity. What matters is not who held it, but whether it has been touched since creation.
And “proper custody” itself becomes complicated in the cloud era. When a record resides on a server operated by a third-party provider, is replicated across data centers in multiple countries, and is accessible to system administrators whose identities may be unknown, who exactly is the “custodian”? The BSA does not answer this question. It imports a concept designed for physical documents into a digital environment where physical custody has no meaningful equivalent.
Courts require it, but the law has yet to mandate a transition from content-based scrutiny to the examination of metadata, including creation timestamps, modification histories, author attributions, and hash values at each stage of transfer. Metadata serves as the digital counterpart to a document’s handwriting, signature, and seal. Any analysis of genuineness that disregards metadata is incomplete by contemporary technical standards.
- Who Should Carry the Burden? The Case for Flipping It
This brings me to what I think is the most important structural argument, and the one the BSA most clearly missed.
Right now, when a bank, a telecom company, or the State produces electronic records in court, Section 63(2)’s presumption operates in their favor. The other party, almost always the person with less power, less money, and no access to the system in question, must prove that the machine malfunctioned. Think about what that means in practice: a defendant is expected to disprove the reliability of a server they have never accessed, using logs they cannot obtain, and of software whose architecture they cannot inspect. That is not a burden of proof. It is a structural impossibility dressed up as procedural fairness.
A fairer and more principled approach would resemble the Daubert standard that U.S. federal courts apply to expert scientific evidence. Under Daubert, the proponent of technical evidence must first establish that the underlying method is reliable, has been tested and peer-reviewed, has a known error rate, and is generally accepted in its field. Only then does the evidence reach the jury. Transposing this logic to Indian evidence law would mean that, before the Section 63(2) presumption kicks in, the institution must demonstrate threshold reliability. The certificate under Section 63 could serve exactly this function, but only if its content requirements are substantially expanded beyond what the current statutory language demands.
This proposal is not radical; it logically follows from the BSA’s stated objectives. If the Act intends to treat digital records as primary evidence equivalent to paper records, the standards for verifying their integrity must be equally rigorous. The burden of demonstrating reliability should rest with the entity that controls the relevant system.
- Conclusion: Modernizing the Law Is Not Enough; We Must Modernize the Assumptions
Let me be clear about what I am not arguing. I am not arguing that the Bharatiya Sakshya Adhiniyam, 2023, is a failure. For Indian evidence law, it is a genuine step forward, recognizing the digital world as the primary domain rather than an awkward exception. That matters.
However, there is a distinction between updating a statute’s language and modernizing its epistemology, the foundational theory of what constitutes sufficient justification for belief. Presumptions constitute the court’s epistemological framework, determining which facts are accepted without proof. When such presumptions are extended to technologies that even experts cannot fully explain, they cease to be reasonable inferences and instead become institutional blind spots.
In the analog era, it was reasonable to presume a clock functioned properly, as its mechanisms were well understood and malfunctions could be identified and explained by expert witnesses. In contrast, presuming that an AI-driven policing tool or a cloud-hosted banking system operates correctly without examining its code, training data, error rate, or audit logs is fundamentally different. This constitutes institutional faith presented as legal inference. The Horizon scandal is not merely historical; it serves as a warning for the future.
As Indian courts increasingly evaluate AI-generated evidence, algorithmic decisions, deepfake materials, and cloud-based records, the question of which presumptions are appropriate becomes pressing. The pursuit of justice demands a shift from uncritical acceptance to verifiable reliability, ensuring that the presumption of machine correctness is rebuttable and that institutions substantiate it through transparency, documentation, and accountability.
The law has shifted from paper-based to digital systems. Legal assumptions must evolve accordingly.
*[The author is a fourth-year law student at Vivekananda Institute of Professional Studies, GGSIPU ]*