The Pool Looks Closed From Here
Why "almost certainly" depends on where you're standing
Erin Murphy, the Norman Dorsen Professor of Civil Liberties at NYU, has a recent California Law Review article on what she calls “closed-universe searches” — cases where mass searches of large data repositories (genetic databases, geofence warrants, facial recognition footage) yield a small pool of suspects connected to a crime by happenstance. One person in the pool is almost certainly guilty. The rest are innocent bystanders who happen to share a data signature. Murphy argues this middle ground — too small to be indiscriminate surveillance, too large for any individual to meet probable cause — falls through the cracks of existing Fourth Amendment doctrine, and proposes a statutory fix: a “Material Evidence Warrant” framework that would govern how law enforcement can search within a closed-universe pool and what happens to the data afterward.
It’s an important contribution. The taxonomy is exactly what was missing. And yet I think the framework is being applied one step too late — for a familiar reason.
The universe only appears closed
Murphy’s definition of a closed-universe search requires the perpetrator to be “almost certainly” within the pool. That near-certainty is load-bearing: it’s what distinguishes the closed universe from an ordinary indiscriminate search, and it’s what makes intrusive investigation of pool members feel justified. A court that would not dream of authorizing DNA sampling from every man in a neighborhood might readily authorize it for three men if doing so could conclusively establish which one of three committed the crime.
But how confident should we actually be that the perpetrator is in the pool? That confidence is itself a product of base-rate reasoning — the kind courts and investigators systematically get wrong. Lindsey, Hertwig, and Gigerenzer made precisely this point about DNA database searches: the larger the database searched, the higher the probability of a coincidental match, which means the posterior probability of guilt given a database hit is far lower than it intuitively seems.
The pool feels closed and damning. But its apparent closure depends on the scale and imprecision of the upstream search.
There’s a further wrinkle, which I’ve been working through in the context of Chat Control. The error rates reported within a closed-universe pool — say, the share of pool members who turn out to be innocent — are false discovery rates on an already-filtered population. They can’t be read back as characterizing the technology’s general accuracy at the population level.
This means the “almost certainly” framing is doubly confounded by base-rate reasoning: once in the upstream search that creates the pool, and again in how within-pool error rates get interpreted as evidence that the technology is reliable.
The pool looks closed from here. It isn’t necessarily.
Upstream and downstream
Murphy’s framework starts from the premise that closed-universe pools exist and asks how to govern searches within them. My proportionality/suitability argument — sketched here in an EU law context — asks whether the upstream search should run at all, by requiring proponents to demonstrate in advance that the program will do more good than harm.
These are complementary, not competing. You need both ends of the pipeline covered: authorization standards before the pool is created, and conduct standards once it exists.
Murphy’s worry about proportionality is that it’s too subjective — especially in the U.S., where jurisdictional variation could be dramatic. This is a real concern.
But I think the solution is to give proportionality an empirical anchor rather than abandon it. Instead of (or alongside) crime-type gating, statutes could require proponents to demonstrate minimum acceptable positive predictive value, maximum acceptable false-positive rates, and some measure of expected resource absorption before an upstream indiscriminate search is authorized. That ties the inquiry to measurable operating characteristics rather than a judge’s intuition about seriousness.
It also makes the standard enforceable before the pool exists, which neither the Fourth Amendment nor Murphy’s statutory scheme currently provides.
The structural layer beneath the cognitive one
Murphy identifies tunnel vision and confirmation bias as risks specific to closed-universe searches — the danger that investigators, faced with a short list of suspects and a technology promising near-certain identification, will anchor on a candidate and filter evidence accordingly. The Joao Monteiro case she discusses is a good illustration: a miscommunication about DNA match results cascaded into a wrongful arrest because the detective already believed she had her man.
But there’s a structural layer beneath the cognitive one that Murphy’s framework doesn’t address.
I’ve been developing a four-pathway causal framework that formalizes this (now in the form of a paper applying it to Chat Control and iBorderCtrl). The short version: volume itself can degrade signal detection regardless of per-case accuracy, once a system is deployed at population scale. The BKA implementation data for Chat Control 1.0 illustrates the point — approximately 144,000 criminally irrelevant reports out of roughly 300,000 annually, a ~48% false positive rate among flagged communications. That’s cognitively manageable as a sorting task. Chat Control 2.0 projections push the ratio to approximately 555 false positives for every true positive, at which point the problem isn’t that investigators become anchored on the wrong person — it’s that the pipeline is structurally incapable of doing what it was supposed to do.
This matters for closed-universe searches because Murphy’s framework assumes the technology delivers on its promise of near-certain identification within the pool. If it systematically doesn’t — if the pool-creation step generates error at scale that isn’t visible in the within-pool statistics — then the statutory protections for pool members are governing a process that was compromised before it began.
Where this leaves us
Murphy’s article is the first to name and define the closed-universe search as its own distinct phenomenon, and the Material Evidence Warrant is a useful legislative template. It just also needs an upstream complement: standards that require proponents to demonstrate, before any indiscriminate search is authorized, that the resulting pool will actually have the properties the “almost certainly” standard assumes.
That’s harder than it sounds. It requires the kind of prospective benefit-cost analysis that policy processes generally avoid. And it requires transparency about operating characteristics that law enforcement agencies rarely volunteer; or, more broadly, that someone, somewhere collect and independently analyze efficacy data. But it’s also the right ask. The pool only looks closed from inside it.
From outside — from the vantage point of the population the upstream search sweeps — it was never as certain as it seemed.
Erin Murphy’s article, “Closed-Universe Searches,” was published in the June 2026 (Vol. 114) California Law Review. With thanks to Erin Murphy for sharing a pre-publication draft and for the exchange that sharpened these ideas.



