AI-Enabled Spyware 'Graphite' Used to Illegally Monitor Journalists and Activists in Italy

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Italian prosecutors confirmed that the AI-powered spyware 'Graphite,' developed by Israeli firm Paragon, was used to infiltrate the smartphones of journalists and activists, including Francesco Cancellato, Luca Casarini, and Giuseppe Caccia, on December 14, 2024. The unauthorized surveillance violated privacy rights and is under criminal investigation.[AI generated]

Why's our monitor labelling this an incident or hazard?

The spyware 'Graphite' is an AI-enabled military-grade system used to infiltrate and spy on targeted individuals. The event involves the use and malfunction (unauthorized use) of this AI system leading to direct harm: illegal surveillance and violation of privacy rights of journalists and activists. This fits the definition of an AI Incident because the AI system's use has directly led to harm (violation of rights and privacy). The investigation and technical analysis confirm the AI system's involvement and the realized harm, not just a potential risk.[AI generated]
AI principles
Privacy & data governanceRespect of human rights

Industries
Digital security

Affected stakeholders
Civil society

Harm types
Human or fundamental rights

Severity
AI incident

Business function:
Other

AI system task:
Other


Articles about this incident or hazard

Thumbnail Image

Caso Paragon, la procura conferma: "Cancellato è stato spiato, attacco il 14 dicembre 2024

2026-03-05
Fanpage
Why's our monitor labelling this an incident or hazard?
The spyware 'Graphite' is an AI-enabled military-grade system used to infiltrate and spy on targeted individuals. The event involves the use and malfunction (unauthorized use) of this AI system leading to direct harm: illegal surveillance and violation of privacy rights of journalists and activists. This fits the definition of an AI Incident because the AI system's use has directly led to harm (violation of rights and privacy). The investigation and technical analysis confirm the AI system's involvement and the realized harm, not just a potential risk.
Thumbnail Image

Paragon, Ruotolo (Pd): "Confermato lo spionaggio sul telefono di Cancellato, chi lo ha spiato con Graphite?

2026-03-05
Fanpage
Why's our monitor labelling this an incident or hazard?
The spyware 'Graphite' is an AI-enabled system used for surveillance and data exfiltration, which has been confirmed to have been used to spy on specific individuals, including journalists and activists. This use has directly caused harm by violating their rights and privacy, fulfilling the criteria for an AI Incident. The involvement of AI is explicit as the spyware is described as a software product used by intelligence agencies for interception and data extraction. The harm is realized and ongoing, not merely potential, and involves violations of human rights and legal protections, thus meeting the definition of an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Paragon, Cancellato spiato insieme a Mediterranea

2026-03-05
il manifesto
Why's our monitor labelling this an incident or hazard?
The spyware Graphite is an AI-enabled system used for surveillance and intrusion into smartphones. The event involves the use of this AI system to spy on journalists and activists without proper authorization, violating their rights and privacy. The intrusion has already occurred, causing harm to the individuals' rights and potentially to democratic principles. The involvement of AI in the spyware's operation and the resulting harm to human rights and privacy meet the criteria for an AI Incident.