Spanish Intelligence Investigated for AI-Driven Pegasus Espionage Scandal

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Spanish authorities, including former CNI director Paz Esteban, are under judicial investigation for allegedly using AI-powered spyware Pegasus (and Candiru) to illegally surveil Catalan politicians and business leaders. The incidents, centered in Barcelona, involve privacy violations and have led to multiple legal actions and public controversy.[AI generated]

Why's our monitor labelling this an incident or hazard?

Pegasus is a sophisticated AI-enabled spyware system capable of infiltrating mobile devices. The event describes an ongoing legal investigation into the alleged use of this AI system for espionage against political figures, which constitutes a violation of rights and privacy. Since the spyware's use has already occurred and is under judicial scrutiny for harm caused, this qualifies as an AI Incident due to violations of human rights and breaches of legal protections related to privacy and surveillance.[AI generated]
AI principles
Privacy & data governanceRespect of human rightsAccountabilityTransparency & explainabilityDemocracy & human autonomy

Industries
Government, security, and defenceDigital security

Affected stakeholders
GovernmentBusiness

Harm types
Human or fundamental rightsPublic interest

Severity
AI incident

AI system task:
Other


Articles about this incident or hazard

Thumbnail Image

La exdirectora del CNI Paz Esteban declara el lunes como imputada en el "caso Pegasus"

2025-09-28
La Razón
Why's our monitor labelling this an incident or hazard?
Pegasus is a sophisticated AI-enabled spyware system capable of infiltrating mobile devices. The event describes an ongoing legal investigation into the alleged use of this AI system for espionage against political figures, which constitutes a violation of rights and privacy. Since the spyware's use has already occurred and is under judicial scrutiny for harm caused, this qualifies as an AI Incident due to violations of human rights and breaches of legal protections related to privacy and surveillance.
Thumbnail Image

La exdirectora del CNI reitera que no puede declarar sobre el espionaje a ERC

2025-09-29
EL PAÍS
Why's our monitor labelling this an incident or hazard?
The Pegasus software is an AI-enabled system used for sophisticated surveillance and infiltration of mobile devices. Its use by the CNI to spy on political figures has directly led to violations of privacy and potentially other human rights, as evidenced by ongoing legal investigations and court proceedings. The involvement of the AI system in causing these harms is clear and direct. Hence, this event meets the criteria for an AI Incident due to the realized harm involving violations of rights through the use of an AI system.
Thumbnail Image

La ex directora del CNI alega que no puede declarar sobre el espionaje a dos dirigentes de ERC con Pegasus

2025-09-29
EL MUNDO
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system used for surveillance, which directly implicates violations of human rights and privacy. The article describes an ongoing investigation into the use of Pegasus to spy on political leaders, which is a clear case of harm to fundamental rights. The involvement of the AI system (Pegasus) in the espionage and the resulting legal proceedings indicate that harm has occurred. Hence, this is an AI Incident as per the definitions provided.
Thumbnail Image

La exdirectora del CNI se escuda en el deber de reserva para no declarar sobre el espionaje de Pegasus

2025-09-29
Diario Sport
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that was used to intercept communications and extract data from the mobile phones of political figures without their consent. This constitutes a violation of fundamental rights, specifically privacy and potentially other human rights, fulfilling the criteria for harm under the AI Incident definition. The article details actual espionage events, not just potential or hypothetical risks, confirming that harm has occurred. Hence, the event is classified as an AI Incident.
Thumbnail Image

La exdirectora del CNI se escuda en el deber de reserva para no declarar sobre el espionaje de Pegasus

2025-09-29
El Periódico
Why's our monitor labelling this an incident or hazard?
Pegasus is a sophisticated spyware tool that uses AI techniques for surveillance and data extraction. Its use to spy on political figures without proper authorization constitutes a violation of human rights and privacy, which is a breach of fundamental rights under applicable law. The article details actual espionage incidents and ongoing investigations, indicating realized harm rather than potential harm. Hence, this event meets the criteria for an AI Incident as the AI system's use has directly led to harm.
Thumbnail Image

La exdirectora del CNI declarará este lunes por videoconferencia...

2025-09-28
europa press
Why's our monitor labelling this an incident or hazard?
Pegasus is a sophisticated AI-enabled spyware capable of infiltrating mobile devices to extract information covertly. Its deployment against political figures constitutes a violation of human rights, specifically privacy rights, fulfilling the criteria for harm under (c) violations of human rights. The article details ongoing judicial investigations and imputations related to this espionage, indicating that harm has occurred. The AI system's use is central to the incident, making this an AI Incident rather than a hazard or complementary information.
Thumbnail Image

La exdirectora del CNI alega que no puede declarar sobre el presunto...

2025-09-29
europa press
Why's our monitor labelling this an incident or hazard?
The article mentions the Pegasus spyware, which is an AI-enabled system used for espionage, but the content centers on the ex-director's legal rights and obligations in a judicial investigation. There is no new harm or potential harm described, nor is the article focused on updates about mitigation or governance responses. Therefore, this is Complementary Information providing context and updates on a known AI-related incident rather than reporting a new AI Incident or AI Hazard.
Thumbnail Image

Estos son los cinco empresarios catalanes que denuncian a la Guardia Civil y al CNI por espionaje con 'Pegasus' y 'Candiru'

2025-09-30
Público.es
Why's our monitor labelling this an incident or hazard?
The spyware Pegasus and Candiru are AI systems designed to infiltrate and monitor devices covertly. The event describes actual harm caused by these AI systems through illegal surveillance and privacy violations of multiple individuals, including prominent figures. The involvement of AI systems in the espionage is explicit, and the harm to human rights (privacy, illegal access to information) has materialized. Hence, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Malestar en el Gobierno con la exdirectora del CNI por su silencio ante la jueza del 'caso Pegasus'

2025-09-29
Cadena SER
Why's our monitor labelling this an incident or hazard?
The article explicitly involves the use of Pegasus spyware, an AI-enabled system, in surveillance activities against political leaders, which is under judicial investigation for illegal espionage. The use of this AI system has directly led to violations of privacy and potential breaches of fundamental rights, fulfilling the criteria for an AI Incident. The harm is realized (illegal spying), and the AI system's role is pivotal. The article does not merely discuss potential or future harm but ongoing legal cases and confirmed surveillance activities, so it is not an AI Hazard or Complementary Information. It is not unrelated because the AI system Pegasus is central to the incident.
Thumbnail Image

La exdirectora del CNI se niega a aclarar por segunda vez en el juzgado el espionaje con Pegasus - ElNacional.cat

2025-09-29
ElNacional.cat
Why's our monitor labelling this an incident or hazard?
Pegasus is a sophisticated AI-enabled spyware system used to infect mobile devices and extract data covertly. The article details confirmed infections of politicians' phones and ongoing judicial investigations, indicating realized harm through illegal surveillance and violation of privacy rights. This fits the definition of an AI Incident as the AI system's use has directly led to harm in the form of rights violations. The event is not merely a potential risk or complementary information but a concrete case of harm caused by AI-enabled spyware.
Thumbnail Image

El blindaje de la exdirectora del CNI con Pegasus - ElNacional.cat

2025-09-29
ElNacional.cat
Why's our monitor labelling this an incident or hazard?
Pegasus is a well-known AI-enabled spyware system that uses advanced AI techniques to infiltrate mobile devices and extract data. The article describes the use of Pegasus for illegal espionage against political figures, which constitutes a violation of human rights and privacy. This is a direct harm caused by the AI system's use. Although the article focuses on legal and political developments, the core event is the AI Incident of illegal surveillance and rights violations. Therefore, this qualifies as an AI Incident due to the realized harm caused by the AI system's use.
Thumbnail Image

La exdirectora del CNI declara este lunes por videoconferencia como imputada en el 'caso Pegasus'

2025-09-29
Diario de Noticias
Why's our monitor labelling this an incident or hazard?
Pegasus is a sophisticated AI-enabled spyware system capable of infiltrating mobile devices covertly. Its alleged use by the CNI to spy on politicians and activists constitutes a violation of human rights and breaches legal protections. The event details ongoing judicial proceedings investigating these harms, indicating that the AI system's use has directly led to violations of rights. Therefore, this qualifies as an AI Incident due to realized harm involving an AI system's use causing violations of fundamental rights.
Thumbnail Image

La exdirectora del CNI declara este lunes por videoconferencia como imputada en el 'caso Pegasus'

2025-09-29
Deia
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system capable of sophisticated surveillance and data extraction. Its alleged use by the CNI to infect phones of political figures constitutes a violation of human rights and legal protections. The event describes ongoing legal investigations into these harms caused by the use of this AI system. Therefore, this qualifies as an AI Incident because the development and use of an AI system (Pegasus) has directly led to violations of rights and harm to individuals.
Thumbnail Image

Paz Esteban se acoge a la Ley de Secretos Oficiales y evita declarar por el caso Pegasus en Barcelona

2025-09-29
Estrella Digital
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-powered spyware system that was used to spy on individuals, leading to violations of privacy and potentially other human rights. The article details the use of this AI system by the CNI, the resulting espionage scandal, and the legal and political consequences. Since the spyware's use has already caused harm through unauthorized surveillance, this qualifies as an AI Incident under the framework, specifically under violations of human rights or breach of legal protections.
Thumbnail Image

La exdirectora del CNI declarará este lunes por videoconferencia como imputada en el 'caso Pegasus'

2025-09-28
NoticiasDe.es
Why's our monitor labelling this an incident or hazard?
Pegasus is a sophisticated AI-enabled spyware system capable of infiltrating mobile devices covertly. Its use for espionage on political figures constitutes a violation of human rights, specifically privacy rights, and breaches legal protections. The article details ongoing judicial investigations into these alleged harms, indicating that the AI system's use has directly led to violations of rights. Therefore, this qualifies as an AI Incident due to realized harm from the use of an AI system (Pegasus) in illegal surveillance activities.
Thumbnail Image

Directivos de NSO, titulares de Pegasus, imputados por primera vez por espionaje a políticos independentistas - ElNacional.cat

2025-10-01
ElNacional.cat
Why's our monitor labelling this an incident or hazard?
Pegasus spyware is an AI system used for surveillance and espionage. The event describes actual spying on politicians using Pegasus, which is a direct violation of human rights and privacy. The harm has already occurred, and the legal actions against NSO executives confirm the direct link between the AI system's use and the harm. Hence, this is an AI Incident involving violations of human rights caused by the use of an AI system.
Thumbnail Image

ERC usa las medidas de Sánchez contra Israel para exigir que desclasifique todos los documentos del espionaje con el programa israelí de Pegasus

2025-10-01
EL MUNDO
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system used for surveillance and espionage. The article details ongoing investigations and political demands related to its use against political figures, implying violations of rights and legal breaches. The spyware's use constitutes a direct or indirect cause of harm through privacy violations and potential breaches of fundamental rights. Therefore, this event qualifies as an AI Incident due to the realized harm and legal implications stemming from the AI system's use.
Thumbnail Image

Justicia española ordena investigar a directivos de la empresa de Pegasus por espionaje

2025-10-01
LaPatilla.com
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that uses sophisticated AI techniques to infiltrate and control mobile devices, leading to serious violations of privacy and human rights. The article details ongoing legal actions against the company and its executives for their involvement in this espionage, which has already caused harm to the targeted individuals and communities. The direct use of this AI system for unauthorized surveillance and data extraction constitutes a violation of fundamental rights, fitting the definition of an AI Incident. The investigation and legal proceedings are responses to this harm, but the primary event is the realized harm from the AI system's use.
Thumbnail Image

Imputan a tres directivos de NSO por el espionaje a dos dirigentes de Esquerra

2025-10-01
LaVanguardia
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-powered spyware system capable of sophisticated surveillance and data extraction. Its use to spy on political leaders constitutes a violation of fundamental rights, specifically privacy and potentially other human rights. The article describes ongoing legal proceedings imputing NSO Group executives for this espionage, confirming that harm has materialized due to the use of this AI system. Therefore, this qualifies as an AI Incident under the framework, as the AI system's use has directly led to violations of human rights and legal breaches.
Thumbnail Image

ERC exige a Sánchez que desclasifique los documentos de Pegasus tras la imputación de tres directivos israelís

2025-10-01
El Periódico
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system that has been used to spy on political activists and leaders, leading to violations of fundamental rights such as privacy and political freedoms. The article reports on legal actions against NSO Group executives and political demands for transparency, indicating that harm has already occurred due to the use of this AI system. Therefore, this event qualifies as an AI Incident because the development and use of the AI system directly led to violations of human rights.
Thumbnail Image

La Justicia ordena imputar a los empresarios israelíes creadores de Pegasus por el espionaje a ERC

2025-10-01
eldiario.es
Why's our monitor labelling this an incident or hazard?
The Pegasus spyware is an AI system used for surveillance and espionage, which has already caused harm through unauthorized spying on individuals, constituting violations of rights. The article discusses judicial orders to investigate the NSO Group executives and related legal processes, which are responses to past harms. Since the article does not describe a new incident of harm or a plausible future harm but rather legal and governance responses to an existing AI-related harm, this qualifies as Complementary Information. It provides important context and updates on societal and governance responses to an AI Incident but is not itself a new AI Incident or AI Hazard.
Thumbnail Image

Imputados 3 directivos de NSO Group por el presunto espionaje a Jové...

2025-10-01
europa press
Why's our monitor labelling this an incident or hazard?
The article describes the alleged use of Pegasus spyware, an AI system, to conduct espionage on political figures, which is a violation of rights and privacy. The involvement of NSO Group executives and the ongoing legal proceedings indicate that the AI system's use has directly led to harm (violation of rights). Therefore, this event meets the criteria for an AI Incident due to the realized harm caused by the AI system's use.
Thumbnail Image

ERC pide al Gobierno que desclasifique todos los documentos secretos sobre el espionaje con Pegasus

2025-10-01
Público.es
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system capable of sophisticated surveillance and intrusion, thus qualifying as an AI system. The article details ongoing legal investigations and political demands related to its use for espionage, which constitutes violations of fundamental rights and privacy. These harms have already occurred, as evidenced by the legal actions and imputations of NSO executives. Hence, this is an AI Incident due to the direct involvement of an AI system in causing harm through espionage and rights violations.
Thumbnail Image

ERC demana al Govern espanyol que desclassifqui tots els documents secrets sobre l'espionatge amb Pegasus

2025-10-01
Público.es
Why's our monitor labelling this an incident or hazard?
Pegasus is a sophisticated AI-enabled spyware system used for covert surveillance. Its use in spying on political figures and others constitutes a violation of human rights and fundamental freedoms, which fits the definition of harm under AI Incident (c). The article details ongoing legal actions and political demands related to this harm, indicating that the harm has already occurred. Therefore, this event qualifies as an AI Incident due to the direct involvement of an AI system (Pegasus) causing violations of rights through espionage.
Thumbnail Image

L'exdirectora del CNI es nega a aclarir a la jutge l'espionatge amb Pegasus en la seva segona imp... - ElNacional.cat

2025-09-29
ElNacional.cat
Why's our monitor labelling this an incident or hazard?
Pegasus is a sophisticated AI-powered spyware system used for surveillance. Its deployment against political figures constitutes a violation of fundamental rights, specifically privacy and potentially other human rights. The article details confirmed infections of mobile devices and ongoing judicial proceedings, showing that harm has materialized. Therefore, this qualifies as an AI Incident because the AI system's use directly led to violations of rights and harm to individuals.
Thumbnail Image

El blindatge de l'exdirectora del CNI amb Pegasus - ElNacional.cat

2025-09-29
ElNacional.cat
Why's our monitor labelling this an incident or hazard?
The event involves the use of Pegasus, an AI-enabled spyware system, which has directly caused harm through illegal surveillance and violation of privacy and political rights, qualifying as an AI Incident. However, the article mainly reports on the judicial and political aftermath, ongoing investigations, and lack of accountability rather than describing a new incident or hazard. Therefore, it serves as Complementary Information providing context and updates on a previously known AI Incident involving Pegasus spyware.
Thumbnail Image

Els directius d'NSO, titulars de Pegasus, imputats per primer cop per espionatge a polítics indep... - ElNacional.cat

2025-10-01
ElNacional.cat
Why's our monitor labelling this an incident or hazard?
The NSO Group's Pegasus spyware is an AI system used for covert surveillance, which has been employed to spy on politicians without consent, violating their rights and privacy. The article describes actual harm caused by the use of this AI system, including breaches of fundamental rights and legal actions against the company's executives. This fits the definition of an AI Incident because the AI system's use has directly led to violations of human rights and legal breaches. The judicial imputations and ongoing investigations confirm the harm has materialized, not just a potential risk.
Thumbnail Image

L'exdirectora del CNI s'escuda en la llei de secrets per no declarar

2025-09-29
El Punt Avui
Why's our monitor labelling this an incident or hazard?
Pegasus spyware is an AI-enabled system used for surveillance and espionage, which can lead to violations of human rights (privacy). The article discusses an ongoing investigation into its use but does not confirm any realized harm or incident resulting from the AI system's deployment. The refusal to testify and legal constraints are procedural and do not themselves constitute harm or a hazard. Therefore, this is complementary information providing context on legal and governance responses related to AI-enabled surveillance, rather than a new AI Incident or Hazard.
Thumbnail Image

L'exdirectora del CNI apel·la de nou a la llei de secrets per no declarar per Pegasus

2025-09-29
El Punt Avui
Why's our monitor labelling this an incident or hazard?
The event involves an AI-enabled system (Pegasus spyware) but centers on legal restrictions and investigation procedures rather than any realized or potential harm directly linked to the AI system's operation. There is no indication of injury, rights violations explicitly caused by AI misuse, or disruption attributable to AI malfunction. The focus is on the legal process and secrecy obligations, which is complementary information about AI's societal and governance context rather than a new incident or hazard.
Thumbnail Image

Tres empresaris israelians imputats per l'espionatge a ERC amb Pegasus

2025-10-01
El Punt Avui
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-powered spyware system capable of sophisticated surveillance and data extraction. Its use to infect the mobile devices of political representatives directly violates their rights and freedoms, constituting harm under the framework's category of violations of human rights or breach of legal obligations. The imputations against NSO Group executives indicate that the spyware's deployment has led to actual harm, not just potential risk. Therefore, this event qualifies as an AI Incident due to the direct involvement of an AI system causing harm through illegal surveillance.
Thumbnail Image

L'exdirectora del CNI no declara sobre l'espionatge amb Pegasus i al·lega el deure de reserva

2025-09-29
ara.cat
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system used for espionage, which qualifies as an AI system. The event concerns an ongoing investigation into espionage activities involving Pegasus, but no direct or indirect harm from the AI system is described as having occurred or being newly revealed in this article. The article focuses on legal proceedings and the refusal to disclose information due to confidentiality obligations, rather than on new harm or potential harm caused by the AI system. Therefore, this is best classified as Complementary Information, providing context and updates on a previously known AI-related incident without introducing new harm or plausible future harm.
Thumbnail Image

L'ex-directora del CNI només declararà sobre Pegasus si Sánchez en desclassifica els documents secrets

2025-09-29
VilaWeb
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system used for surveillance, which is explicitly mentioned as being used to infect phones of political figures, leading to legal investigations for illegal spying. This constitutes a violation of human rights and breaches of legal obligations protecting privacy and fundamental rights. The spyware's use is directly linked to harm, fulfilling the criteria for an AI Incident. The article describes realized harm (illegal espionage) rather than potential harm, so it is not an AI Hazard. It is not merely complementary information or unrelated news, as the AI system's use has caused direct harm.
Thumbnail Image

Tres directius de NSO, investigats per primer cop per l'espionatge a polítics independentistes amb Pegasus

2025-10-01
VilaWeb
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-powered spyware system used to infect and surveil mobile phones, which is explicitly mentioned as being used against political figures. The investigation of NSO executives for their role in creating, selling, and controlling Pegasus links the AI system's development and use directly to violations of fundamental rights (privacy and political rights). The harm is realized and ongoing, as the spyware was used to spy on politicians. This fits the definition of an AI Incident due to violations of human rights caused by the AI system's use.
Thumbnail Image

L'exdirectora del CNI declara que no es va espiar polítics d'ERC amb Pegasus

2025-09-29
El Periódico de Catalunya
Why's our monitor labelling this an incident or hazard?
The event involves an AI-related system (Pegasus spyware) and concerns alleged misuse leading to potential violations of privacy and rights, which would qualify as an AI Incident if harm were confirmed. However, this article focuses on the former director's denial and ongoing judicial investigation without confirming new or additional harm. Therefore, it is best classified as Complementary Information, as it provides updates on legal proceedings and responses related to previously reported AI Incidents involving Pegasus.
Thumbnail Image

L'exdirectora del CNI es nega a declarar davant la justícia per l'espionatge polític del 'Catalangate'

2025-09-29
La República
Why's our monitor labelling this an incident or hazard?
Pegasus spyware is known to use AI techniques for sophisticated surveillance and intrusion, qualifying it as an AI system. The alleged use of this AI system for political espionage directly implicates violations of human rights, specifically privacy rights, which fits the definition of an AI Incident. The article details the investigation and legal proceedings related to this harm, confirming that the AI system's use has led to realized harm rather than just a potential risk. Therefore, this event is classified as an AI Incident.
Thumbnail Image

La investigació d'espionatge amb Pegasus a Catalunya, bloquejada per la Llei de Secrets Oficials - 3CatInfo

2025-09-29
3Cat
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system used to infect mobile phones without consent, leading to violations of privacy and potentially other human rights. The article describes actual infections and investigations related to this spyware, indicating realized harm. This fits the definition of an AI Incident because the AI system's use has directly led to violations of rights and harm to individuals. The investigation and legal proceedings further confirm the seriousness of the incident.
Thumbnail Image

ERC reclama que l'Estat desclassifiqui tots els arxius de Pegasus arran de la investigació judicial als directius de NSO per espiar polítics

2025-10-01
La República
Why's our monitor labelling this an incident or hazard?
Pegasus is an AI-enabled spyware system, so an AI system is involved. However, the article does not describe a new AI Incident (no new harm directly or indirectly caused by the AI system is reported) nor does it describe a plausible future harm event (AI Hazard). Instead, it reports on judicial and political developments, demands for transparency, and responses related to an ongoing investigation. This fits the definition of Complementary Information, as it provides supporting context and updates on a known AI-related issue without introducing a new incident or hazard.