Joint Statement September 17, 2026
25+ Civil Society Organizations Call for Strong Human Rights and Accountability Safeguards for Commercial Cyber Intrusion Industry
Essential elements for ensuring the industry guidelines for commercial cyber intrusion capabilities deliver on their potential.
The joint statement from civil society argues that the forthcoming Pall Mall Industry Guidelines on Commercial Cyber Intrusion Capabilities (CCICs), which includes commercial spyware, must establish enforceable expectations for governments and companies, and significantly raise the bar on existing industry practices.
The Guidelines are a historic opportunity to make accountability the new norm, but weak or diluted language could instead legitimize an industry associated with serious human-rights abuses.
Some highlights from the joint statement include:
- CCICs pose exceptional human-rights risks.
Technologies such as commercial spyware can facilitate grave and potentially irreversible violations, including arbitrary surveillance, detention and transnational repression. - Exceptional risks require exceptional safeguards and limitations. The use of spyware cannot be normalized.
The Guidelines should impose heavy restrictions and controls that drastically limit access and use, ensure oversight, embed accountability and facilitate remediation. - Certain actors should be prohibited from accessing CCICs.
The submission calls for an explicit prohibition on selling, transferring or providing certain CCICs, such as spyware, to non-State actors. - Governments must not outsource their human-rights obligations to companies, and companies cannot ignore their human rights responsibilities.
States have duties to regulate, oversee and provide remedies, while companies have an independent responsibility to respect human rights. Neither can substitute for the other. - “Responsible” must have a hard minimum baseline. This baseline needs to be substantially higher than what industry has established for itself to date.
The Guidelines should establish requirements below which a company cannot credibly be considered responsible. Merely signing up to a voluntary code should not itself demonstrate compliance with human-rights responsibilities. - Government procurement should become a major accountability lever.
Public authorities should rigorously assess companies’ human rights records, ownership and control, governance, safeguards, business relationships, and capacity to prevent, detect, and remedy misuse -- and exclude companies that present unacceptable human rights risks or have failed to address serious abuses. - Targeting journalists and other accountability actors, including any acts forms of intimidation against them, should remain explicitly prohibited.
This includes journalists, human-rights defenders, political opponents, lawyers, judges, academics and civil-society organizations that are holding governments and companies to account for their actions. - Oversight must be independent, effective, and supported by robust technical safeguards. The submission calls for independent authorization, monitoring, auditing, and review mechanisms, alongside safeguards such as auditable access and authorization records, license controls, continuous monitoring, and the capacity to promptly suspend or terminate access (kill switches) when misuse or abuse is identified.
- Victims need meaningful remedies — including across borders.
The Guidelines should provide avenues to challenge authorizations, ensure appropriate victim notification, accessible and rightsholder-centric grievance mechanisms, protection against retaliation, independent investigations and sanctions proportionate to the harms to ensure the prevention of recurrence. - Legitimate security research and public-interest digital rights work must be protected. The submission calls for safeguards for independent researchers, civil society organizations, and digital rights activists acting in good faith and in the public interest, including those who identify, investigate, and responsibly disclose vulnerabilities and document abuses involving commercial cyber intrusion capabilities.
- The process itself must be protected from conflicts of interest.
Civil society and affected communities should have sustained participation. Companies or individuals with documented links to serious abuses should face heightened scrutiny and should be prevented from shaping the standards governing the industry.