Spyware rulebook enters final drafting with Gulf buyers' positions unrecorded
Amnesty’s Security Lab filed a joint civil society submission on the Pall Mall Process industry guidelines, due to be finalised in November. Nobody has established where the region’s purchasers stand.
Amnesty International’s Security Lab published a joint civil society submission on 21 September on the Industry Guidelines for Commercial Cyber Intrusion Capabilities being drafted under the Pall Mall Process, the UK- and France-led initiative that adopted a Code of Practice for States in 2025. The submission argues that the harms of commercial spyware are transnational and corrode national security, the rule of law and human rights, and credits London and Paris for admitting civil society to the process. The guidelines are expected to be finalised in November. Separately, the Citizen Lab said on 22 September that two UN reports drawing on its submissions had been published this month: one from the Office of the High Commissioner for Human Rights on risks to human rights defenders from digital technologies, and one from the UN Working Group on the use of mercenaries examining cybermercenaries, which underlines the absence of clear regulation in cyberspace.
The most-cited regional spyware item of the month sits outside this window and rests on thin sourcing. Middle East Eye’s Ragip Soylu reported from Ankara on 8 September that Apple had sent notifications to the phones of at least three Turkish ministers warning of possible mercenary spyware targeting, as part of a batch of alerts Apple sent to users across 110 countries in August. Ankara believes the attempts failed, citing hardened security and encrypted applications. The report rests on sources familiar with the matter; no forensic confirmation, no named vendor and no operator attribution has been published, and an Apple notification indicates suspected targeting rather than compromise. The page carries a recent update stamp and is recirculating as though new.
Assessment: The Pall Mall guidelines are the only live regulatory instrument with a deadline attached, and the file on them is conspicuously incomplete in one direction. Gulf states are among the significant purchasers of commercial intrusion capability, and no Gulf signatory, objector or abstainer position on the industry guidelines has been established publicly — a gap that will matter more in November than any individual infection report does now. Distrust the sequencing on the Turkish ministers: an Apple alert is a probabilistic warning, Ankara’s denial of success is unfalsifiable, and neither is evidence of who was operating. Watch instead for whether any MENA-based organisation appears among the submission’s co-signatories.