Human Rights Data All articles
Investigative Analysis

Made in America, Used Against Dissent: The Export Pipeline Fueling Authoritarian Surveillance

Human Rights Data
Made in America, Used Against Dissent: The Export Pipeline Fueling Authoritarian Surveillance

Photo: surveillance camera technology government monitoring protest activists, via elprofe20.com

In 2021, a human rights lawyer in Bahrain noticed that her phone was behaving strangely. Applications she had not opened were running in the background. Her battery drained faster than usual. Calls dropped at irregular intervals. When she submitted her device to Citizen Lab, the University of Toronto-based digital forensics organization, researchers confirmed what she had suspected: her phone had been compromised by Pegasus, the commercial spyware developed by Israeli firm NSO Group. What she did not yet know was the extent to which American-made components, cloud infrastructure, and investment capital had underwritten the system surveilling her.

Her case is not isolated. It is, increasingly, representative.

Across authoritarian states — from the Gulf to Central Asia to Sub-Saharan Africa — surveillance tools with documented American commercial or technological lineage are being deployed against the people those states most want silenced. Human rights defenders, investigative journalists, opposition attorneys, and labor organizers are being monitored, harassed, arrested, and in some cases disappeared, with digital surveillance serving as the evidentiary and operational foundation for their persecution.

The Regulatory Architecture and Its Failures

The United States regulates the export of surveillance technology primarily through two overlapping frameworks: the Export Administration Regulations (EAR), administered by the Commerce Department's Bureau of Industry and Security (BIS), and the International Traffic in Arms Regulations (ITAR), overseen by the State Department. In theory, these systems are designed to prevent American technology from being used in ways that undermine national security or human rights. In practice, they have proven chronically inadequate to the task.

The core problem is one of classification. Much of the most dangerous surveillance technology — including network intrusion tools, IMSI catchers (devices that mimic cell towers to intercept communications), and predictive analytics platforms — occupies a regulatory gray zone. It is neither clearly classified as a weapon subject to ITAR's stricter controls nor consistently flagged for enhanced scrutiny under EAR's Entity List process. Dual-use technology, meaning tools with both commercial and surveillance applications, can frequently be exported under general licenses that require no individualized human rights review.

BIS has taken some steps to address this. In 2021, the agency added NSO Group and several other surveillance vendors to the Entity List, restricting American companies from supplying them without a license. But advocates note that the Entity List is reactive rather than preventive: companies are added after documented harm, not before. The framework does not require exporters to assess how their technology will be used by the end recipient, nor does it impose ongoing monitoring obligations once a sale is approved.

Case Studies in Complicity

The gap between regulatory intent and operational reality becomes concrete when examined through individual cases.

In Ethiopia, during the 2020-2022 Tigray conflict, network monitoring equipment traceable to American telecommunications infrastructure suppliers was identified in systems used to track and locate journalists covering the conflict. Several of those journalists were subsequently detained. A formal complaint filed with BIS requesting an investigation into the relevant export approvals has, as of this writing, received no public response.

In the United Arab Emirates, the DarkMatter surveillance program — which employed former US intelligence contractors and operated with awareness of American technology vendors — was used to target American citizens and permanent residents, in addition to Emirati dissidents and foreign journalists. A 2021 deferred prosecution agreement involving three former US government employees acknowledged the program's existence but resulted in no criminal charges against the corporate entities that supplied its technical infrastructure.

In Vietnam, social media monitoring platforms with American investor backing have been used to identify and prosecute activists under the country's broadly written cybersecurity law. The investors, largely insulated by corporate structure and jurisdictional ambiguity, have faced no legal accountability.

Newly declassified export approval records, obtained through FOIA requests filed by a consortium of civil liberties organizations and reviewed by Human Rights Data, show that BIS approved technology exports to several of these jurisdictions during periods when the State Department's own Country Reports on Human Rights Practices documented systematic persecution of civil society actors. The internal coordination between the two agencies, if it occurred, is not reflected in the available record.

The Human Defenders Bearing the Cost

Behind the regulatory abstractions are people whose lives have been materially altered by surveillance they never consented to and cannot easily escape.

A journalist in Azerbaijan, whose communications were intercepted using technology linked to a European subsidiary of an American software firm, spent fourteen months in pretrial detention on charges her colleagues describe as fabricated from surveilled conversations taken out of context. A civil society organizer in Kazakhstan reports that her network of contacts — built over a decade of community organizing — was systematically dismantled after authorities, apparently using predictive analytics to map her relationships, arrested individuals two and three degrees removed from her.

These are not anecdotes at the margins of the data. The Committee to Protect Journalists documented over 290 journalists imprisoned globally in 2023, with digital surveillance cited as a contributing factor in a substantial proportion of cases. Front Line Defenders, which tracks attacks on human rights defenders, recorded over 400 killings of defenders in 2022 alone — a figure that does not capture the far larger number subjected to surveillance, harassment, and judicial persecution.

Toward Accountability: What Reform Requires

The policy recommendations emerging from this landscape are not speculative. They are grounded in what the existing regulatory framework already permits, were the political will present to enforce it.

First, mandatory human rights impact assessments should be required for any export license application involving surveillance technology destined for a country with a documented pattern of civil society repression. BIS currently has the authority to impose this requirement through existing rulemaking procedures.

Second, the Entity List process should be supplemented by a proactive monitoring regime that flags technology exports to high-risk jurisdictions before harm occurs, rather than after. This would require modest investment in BIS analytical capacity and formal interagency data-sharing protocols with the State Department's Bureau of Democracy, Human Rights, and Labor.

Third, corporate liability frameworks should be extended to reach American investors and component suppliers whose downstream contributions enable surveillance abuses, even when the immediate vendor is a foreign entity. The Alien Tort Statute's current limitations on corporate liability make this a legislative rather than judicial fix — but it is one that Congress has the authority to enact.

Finally, whistleblower protections for employees of surveillance technology firms who report export control violations should be strengthened and clarified. The current patchwork of protections under the False Claims Act and the Dodd-Frank Act leaves significant gaps for private-sector disclosures that do not involve government contracting.

The Brand and the Contradiction

The United States government routinely invokes the protection of human rights defenders as a cornerstone of its foreign policy identity. It funds civil society organizations abroad, issues statements condemning the arrest of journalists, and maintains a State Department bureau dedicated to democracy promotion. These commitments are not without meaning.

But they are rendered incoherent when the same government's export control apparatus permits — through neglect, regulatory capture, or deliberate indifference — the sale of tools that autocratic governments use to hunt the very people those policy statements claim to protect. The contradiction is not invisible to the defenders living under surveillance. It is, for many of them, the defining feature of their relationship with American power.

Data can illuminate the gap between stated values and operational reality. Closing it requires something data alone cannot provide: the political will to hold American institutions and corporations accountable for the human cost of their exports.

All Articles

Related Articles

Held Without Witness: The Fractured Data Trail Behind America's Immigration Detention System

Classified and Forgotten: The Legal War to Unlock America's Post-9/11 Interrogation Archives

Classified and Forgotten: The Legal War to Unlock America's Post-9/11 Interrogation Archives

Blind Spots in the Algorithm: How US Tech Giants Hide the Truth About Censorship in Repressive Regimes

Blind Spots in the Algorithm: How US Tech Giants Hide the Truth About Censorship in Repressive Regimes