Est.

AI Risk for Human Rights Workers in Repressive Jurisdictions

AI-powered surveillance is now predicting which human rights defenders to target before they act.

Reporter · · 10 min read
Cover illustration for “AI Risk for Human Rights Workers in Repressive Jurisdictions”
High-Stakes AI · October 4, 2026 · 10 min read · 2,187 words

AI has not just handed repressive governments new tools to add to an old toolkit. It has rebuilt the floor those tools sit on, making surveillance cheaper to run, easier to scale, and capable of acting on a person before that person has done anything a court or a journalist could point to. Freedom House's Freedom on the Net report found that government investment in AI may be misused to enable censorship and surveillance, especially in authoritarian states, and warned that sovereign AI programs in those contexts could deepen existing threats to basic rights like free expression. What makes this shift structural rather than incremental is cost: the same advances that make AI useful for medical imaging or translation also make mass surveillance affordable for governments that could never have staffed a comparable human intelligence operation. The old constraints, the need for armies of analysts, informants, and clerks, no longer apply when a model can sort through months of location data in minutes.

The sharper break is qualitative. Surveillance has historically worked backward: it documented what a dissident already said or did, then built a case. AI-driven systems increasingly work forward: they generate a risk score on a person who has not yet spoken publicly. The Geedge Networks case, covered in full later in this piece, is the clearest documented instance of that shift from record-keeping to prediction. An OHCHR report treats this as a defined problem that needs its own guidance, addressing the risks defenders face in an increasingly digital world. The fact that a major human rights body has moved to produce dedicated guidance on the subject says the threat is current. The sections that follow break this threat environment into its component parts, state infrastructure, predictive profiling, commercial spyware, cross-border reach, and the data risk built into defenders' own tools, because a threat built from layered systems cannot be understood, or countered, as a single problem.

State-built AI surveillance infrastructure and the "Safe City" model

Start with what is physically on the ground, because it sets the baseline every other vector in this piece builds on. Many governments have installed permanent, AI-integrated surveillance networks, and if you operate in or near their reach, genuine anonymity is nearly impossible. They are integrated architectures, camera networks, license plate readers, and facial recognition systems wired into a shared data layer. Piecemeal countermeasures, a burner phone here, a VPN there, cannot address what they're up against.

"Safe City" projects, built largely with hardware from Chinese technology firms, now run facial recognition and license plate readers across cities in Africa, Central Asia, and Eastern Europe. The pattern repeats closely enough across continents that you can call it a shared architecture of control. In Turkey, in March 2025, authorities used AI facial recognition to identify and detain demonstrators the morning after street rallies. Showing up at a protest now leaves a biometric trail with consequences that arrive after the crowd disperses. A leak exposed China's "Dynamic Management Platform for Overseas Personnel," a remote data collection and analysis tool built for the Public Security Bureau in Zhangjiakou, near Beijing, for tracking foreign nationals at scale. The data inside it included passport numbers, mobile phone numbers, workplaces, belonging to people who have lived or currently live in China, including foreign journalists marked "trackable," complete with records of their movements, associations, and entries at specific locations. Myanmar's military, separately, is building a national database that merges SIM records, airport data, CCTV footage, and identity records into one centralized system designed to eliminate anonymity. What ties a national tracking platform to a centralized identity database to a city's facial recognition cameras is aggregation: once enough separate data streams, biometric, telecom, travel, are joined into one system, the operational cover a defender once relied on stops existing by design.

Predictive profiling: AI targeting defenders before they act

If state infrastructure is the floor, predictive profiling is the step that changes who stands on it. The surveillance described above still, for the most part, catches people doing something, marching, posting, meeting. The more unsettling shift is AI's growing capacity to flag someone as a threat before they have done anything detectable. That changes who is at risk, and when, in a way that pattern-of-life surveillance never did: a defender who has stayed silent and off the streets can no longer assume that silence is protection.

Documents uncovered by Vanderbilt University show the clearest version of this in practice. Geedge Networks, a Chinese firm that already sells a commercial version of the Great Firewall, is building AI tools that analyze citizens' internet activity, location data, and telecommunications records to generate a profile estimating a person's "political risk," before that person has taken any public action a government could otherwise point to. Commercial spyware operators have converged on a similar logic through a different route: behavioral targeting. By mapping who communicates with whom, how often, at what hour, and around which subjects, these systems can flag high-value targets, a journalist in contact with a dissident, a lawyer corresponding with a particular client, an activist who crosses borders on a recognizable schedule, before any message is actually read. Reporting suggests the reach of Geedge Networks' tools likely extends past China's own borders, consistent with the state's continued use of digital methods for transnational repression. A defender's physical location, in other words, does not bound this particular risk. The UN Special Rapporteur on Freedom of Assembly and Association has named China as a source of active transnational repression, and points to state-linked cellular network attacks and SIM-cloning operations against Tibetan human rights defenders. That finding connects the predictive layer directly to the operational one: profiling does not stay abstract, it feeds targeting that follows people across borders, which is the subject of a later section in its own right.

Commercial spyware deployed against civil society: the Pegasus pattern

Predictive profiling tells a government who to watch. Commercial spyware is how that government gets inside the phone. What used to require a well-funded national intelligence service, custom malware, a stable of operators, a legal gray zone to work in, is now a service available to any government willing to pay for it. And the documented record across several countries shows civil society is the primary target of these tools.

Morocco offers the clearest accounting of this. Amnesty International documented the surveillance ecosystem that let Moroccan authorities deploy spyware against human rights defenders, and the research is specific on this point: civil society made up almost two thirds of all targets in the first four months after Morocco's domestic intelligence service, the DGST, acquired the system. That is not a tool drifting toward activists as a side effect of counterterrorism work. That is a tool aimed at them from the start. The pattern is not confined to one country or one spyware vendor. In February 2026, Amnesty International confirmed that Predator spyware had targeted a journalist in a country new to this pattern, the first forensically verified case of its kind against that country's civil society, extending a pattern already documented in several other nations into a new region. The geographic spread matters on its own terms: this is not a single government's excess but a market functioning normally, selling the same capability wherever a buyer appears. Behind each case is a journalist or defender who had no reason to expect their phone, specifically, had become the point of entry for a state intelligence service, and who often only learned of the intrusion once a forensic lab confirmed it well after the fact.

Transnational repression: surveillance that follows defenders across borders

Spyware and AI-driven harassment do not stop at a border crossing, and that fact breaks one of the oldest assumptions in human rights work: that leaving a country removes a person from that country's reach. A phone in the hands of an exiled journalist living abroad can be exactly as compromised as the one left behind, because the infection does not care which passport control the device passed through.

The UN Special Rapporteur's findings on China make this concrete rather than theoretical, documenting state-linked cellular network attacks and SIM-cloning operations aimed specifically at Tibetan human rights defenders living outside China. So for journalists and activists who fled persecution, often at real personal cost, digital surveillance functions as a direct extension of the regime's reach. A second, distinct form of this reach has grown alongside the technical one: AI-generated harassment carries a gendered weight that regular surveillance does not. CUT Female activists who challenge the Chinese Communist Party have faced coordinated, state-linked campaigns built specifically to destroy reputations through gendered shame, which places deepfakes inside an organized strategy rather than isolated incidents of online abuse. Geographic reach and gendered targeting are, in the end, the same mechanism pointed at two different vulnerabilities: both let a government extend its effective control over a defender's behavior well past the limits of its own territory. The OHCHR's report ties this directly to legal structure, noting that vaguely defined cybercrime laws and overly broad national security, counterterrorism, or online harms statutes are used to criminalize defenders, censor their work, authorize pervasive surveillance, and enable transnational repression.

Data exposure through the commercial AI tools defenders rely on

Every vector covered so far comes from outside, a government's cameras, a government's spyware, a government's reach across a border. The next one comes from the defender's own desk. The AI assistant a human rights worker uses to draft a report, translate a witness statement, or organize evidence can itself become a liability because of where the data goes once it leaves the user's device, regardless of the tool's intent.

Most AI services run on centralized infrastructure: a user's prompts and files travel to servers the company controls, not to the user's own machine. That interaction data may be shared with governments or other third parties, and when a company is not transparent about how long it keeps that data or who can access it, the risk that law enforcement or an intelligence service could misuse it only grows, a real rather than hypothetical weakness. Research into large-scale de-anonymization has shown that governments can link supposedly pseudonymous accounts back to real identities, so a defender who assumes an AI tool offers anonymity by default may be traceable regardless. The content at stake is not trivial, either: a query about a source, a tactic, a contact, or a location under investigation carries the same sensitivity as a phone call or an encrypted message, and a government willing to mine that data gets a direct window into exactly the work a defender is trying to protect. The Human Rights Foundation's AI for Individual Rights toolkit addresses this directly, warning against dependence on centralized providers and pointing instead to open-weight AI models that run locally on a person's own device, with no connection to an external server, as a way to keep prompts and data from being transmitted to a third party. If you run a model locally, you cut your dependence on infrastructure someone else controls, and with it, a meaningful share of the exposure that infrastructure creates. That does not erase risk, it relocates it: a poorly configured local setup introduces its own vulnerabilities, a problem the next section takes seriously rather than waving away.

Why technical countermeasures alone cannot close every gap

None of the measures described above, local AI models, encrypted messaging, careful operational habits, close every gap in this threat environment, and claiming otherwise would understate what defenders are actually up against. Zero-click spyware infects a device even if the user clicks nothing, opens nothing, and makes no visible mistake it can learn from. No training, no habit, no checklist changes that particular equation. So some threats here sit above what individual security hygiene can reach.

Law is one of them, and the European Media Freedom Act shows how a well-intentioned legal framework can still leave real gaps. The law bars EU member states from deploying intrusive spyware such as Pegasus against journalists and their sources as a general rule, and in principle that is a meaningful protection. But it permits that same deployment in serious-crime investigations with prior judicial sign-off, and it carves out "exceptional and urgent cases" where no prior judicial authorization is required. That exception sits inside the regulatory framework most often held up internationally as a model for protecting journalists, which raises a hard question for anyone inclined to treat law as a sufficient backstop: if the jurisdiction with arguably the strongest formal protections still leaves room for warrantless deployment under a vague urgency standard, what should defenders in weaker legal environments reasonably expect? Technical measures and legal frameworks both matter, and both have limits that compound each other rather than canceling out. Understanding where those limits sit, state infrastructure that cannot be evaded by individual choices, predictive systems that act before there is anything to hide, legal exceptions wide enough to swallow the rule they sit inside, is the condition for using the protective steps covered earlier in this piece honestly: as real but partial defenses against a threat built, deliberately, in layers.

Sources

  1. HRIC Digital Rights Report: May 2026
  2. IMPACT OF DIGITAL AND AI-ASSISTED SURVEILLANCE ON ASSEMBLY AND
  3. Protecting human rights defenders in the digital age
  4. How AI is Powering Transnational Repression - ECNL.org
  5. AI for Individual Rights - Human Rights Foundation
  6. How Autocrats Weaponize AI — And How to Fight Back
  7. AI: ‘African governments are using “smart city” systems to monitor dissent and consolidate state control’ - CIVICUS LENS
  8. Watching Huawei’s “Safe Cities”
Filed underHigh-Stakes AI

More in High-Stakes AI