
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
The Israeli company NSO's AI-enabled spyware Pegasus exploited smartphone vulnerabilities to conduct covert surveillance on activists, journalists, and political opponents worldwide. The system extracted private data undetected, leading to significant privacy breaches and human rights violations through unauthorized, automated data exfiltration.[AI generated]
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-related system that uses advanced automated hacking techniques to infiltrate smartphones and extract data covertly. Its use has directly led to violations of human rights and privacy through unauthorized surveillance, which is a clear harm. The article describes realized harm from the use of this AI system, not just potential harm. Therefore, this event qualifies as an AI Incident under the OECD framework because the AI system's use has directly led to significant harm to individuals and communities.[AI generated]