Essential elements for ensuring the industry guidelines for commercial cyber intrusion capabilities deliver on their potential
17 Sept 2026
TGI has joined 25 civil society organizations and independent experts in a joint submission to the Pall Mall Process, the UK- and France-led initiative currently drafting Industry Guidelines for Commercial Cyber Intrusion Capabilities (CCICs) — commercial spyware and similar targeted surveillance tools. The Guidelines, expected to be finalized in November 2026, follow last year’s Code of Practice for States, and our submission argues they represent a historic opportunity to make accountability the expectation rather than the exception for this industry — one that should not be lost to weak or diluted language.
Our submission is direct about the stakes: CCICs pose exceptional risks precisely because of their potential to facilitate grave, irreversible human rights violations, and these risks are not confined to state misuse. The proliferation of these tools is lowering the barrier for non-state actors to obtain sophisticated intrusion capabilities too, with serious consequences for human rights and security. The harms are also explicitly transnational — undermining national security, rule of law, and human rights across borders, and profoundly affecting the communities most negatively impacted by their misuse.
We’re calling for the Guidelines to set real limits, not aspirations: prohibiting the sale, transfer, or provision of CCICs to non-state actors outside legitimate state or public-interest research use, and to states with a documented pattern of abuse or inadequate safeguards; requiring genuine human rights due diligence before and throughout any procurement relationship, with clear criteria for excluding companies that present unacceptable risk; and making clear that signing a voluntary code is not, by itself, proof that a company has met its human rights responsibilities.
Critically, the submission insists that states’ duty to regulate and companies’ responsibility to respect human rights cannot substitute for one another — and it draws an explicit line protecting journalists, human rights defenders, political opponents, lawyers, judges, academics, and civil society organizations from being targeted for doing their work. It also calls for independent oversight with real teeth — auditable records, license controls, and the ability to suspend or terminate access quickly when misuse is found — and for accountability and remedy mechanisms that work across borders, including accessible grievance processes, victim notification, and protection against retaliation.
Finally, we’re pushing for the integrity of the process itself: sustained, substantive civil society participation, meaningful engagement with individuals and communities directly affected by spyware misuse, and a firm line against letting companies or individuals with documented records of facilitating abuse shape the standards their own industry will be judged by.
Signed by the following organizations:
Business and Human Rights Centre
Freedom House
Amnesty International
Centre for Democracy and Technology Europe
Access Now
Resident NGO
Human Constanta
Digital Rights Foundation
Institute for Policy Research and Advocacy (ELSAM)
Hiperderecho
CyberHUB-AM Threat Lab
Data Rights
Human Rights Defence Centre
TechMOV
Tech Global Institute
Fundación Acceso
IPANDETEC
Heartland Initiative
Protect.ngo
Economic Security Council of Ukraine
Conexion Segura y Libre (CSL)
Association for Progressive Communications (APC)
Ranking Digital Rights
Privacy International
Fundación Karisma
Individual experts:
Lisandra Novo, Senior Law & Tech Advisor
Ragheb Ghandour, Technical expert
Hinako Sugiyama, International Justice Clinic at the University of California, Irvine School of law