Table of contents
- Executive Summary / Key Findings
- Key Terms and Definitions +
- Introduction and Methodology +
- Part 1:
AI-Enabled Human Rights Threats to Civil Society + - Part 2:
Civil Society Deployment of AI: Hurdles to adoption and navigating ethical questions + - Part 3:
Advocating for AI Accountability and Governance + - Part 4:
Case Studies + - Part 5:
Conclusion and Recommendations + - Download report +
Part 1: AI-Enabled Human Rights Threats to Civil Society
As a result of increased deployment of AI in surveillance, civil society ctors feel monitored, unsafe, and more afraid to engage in civic and public matters
AI deployment by state and non-state actors and digital platforms pose several threats to civil society around the world. Survey respondents were most concerned about risks emanating from AI in surveillance, specifically within the digital space (56 percent of respondents) and in public space (50 percent). Predictive policing was a concern for 43 percent of respondents.
A little less than half of respondents stated that they were concerned about AI deployment in generating content (46 percent) and curating, ranking, and recommending content (43 percent). Slightly over a third of respondents were concerned about algorithmic content moderation systems.
This chapter provides an overview of AI systems that undermine civic space and pose a threat to civil society .
How AI is shaping and exacerbating surveillance of civil society around the world
The deployment of AI-powered surveillance and policing technologies pose a serious risk to civil society. Despite calls from civil society to strictly regulate and reign in the deployment of the most invasive AI systems, states around the world continue to acquire these systems from companies looking to profit from lucrative government contracts and deploy them in ways that violate human rights. These technologies include FRT, predictive policing, data analytics, and risk analysis tools and spyware.
Overview of AI-enabled public space and digital surveillance tools and tactics
This sub-section provides an overview of different AI-enabled surveillance technologies that threaten civil society.
Facial Recognition Technology (FRT)
FRT enables deployers to scan facial biometrics of people and compare them against databases of images, often captured illegally or without consent, such as by scraping people’s images from the internet.33 People can be tracked and identified in real time or retroactively, but regardless, FRT is considered a tool of mass surveillance that threatens the rights to privacy, association, and peaceful assembly, and exposes Black, Indigenous. and People of Colour (BIPOC) to discrimination and bias.
FRT deployment has been increasing around the world despite the severe risks this technology poses to fundamental rights and freedoms and the work of civil society. In Iran, authorities have used it to identify and track protesters, dissidents, and women not adhering to the country’s mandatory hijab rules.34 In China, the “world leader” in FRT deployment,35 these technologies are deployed as part of a national surveillance system that constantly tracks people and targets minority groups.36 In Russia, which is second to China in FRT use, the authorities use the technology pre-emptivelyto stop those who joined protests in the past from joining other protests.37 Other governments in Europe, including those of Hungary, the UK38 and the Netherlands, deploy such technology at protests.39
In India, where FRT use by law enforcement agencies has been proliferating,40 data collected from facial recognition systems is connected to a “comprehensive and integrated database of criminal records and crime statistics across the country”.41 In Phuket, Thailand, as part of a safe city project,42 the government contracted a UK company to provide “a smart city system with AI-powered video analytics connected to international databases for facial recognition and wanted persons”.43
Across Africa, governments are buying CCTV camera surveillance tech with facial and car number plate recognition, with Nigeria, Ghana, and Zambia having each spent over US$350 million on ‘safe cities’ mass surveillance programmes from China, according to a 2025 report from the African Digital Rights Network.44 Egypt has been building dozens of new smart cities, including a new capital that has a surveillance network of 6,000 facial recognition cameras.45 This is viewed as an attempt by the ruling regime to control the public space and prevent a repeat of the 2011 protests that toppled the Mubarak dictatorship.46
In Latin America, the technology’s adoption “has advanced quickly and quietly”, where it is applied the most is in “public safety” and “surveillance of public spaces” as well as “applications in the framework of transport, social assistance and migration”.47 In 2024, it was reported that law enforcement agencies in several countries in Latin America and the Caribbean, including Brazil, Colombia, Chile, the Dominican Republic and Trinidad and Tobago were deploying a facial recognition tool developed by a controversial U.S. company, Clearview AI.48
O Panoptico: Mapping FRT in Brazil
O Panoptico, a Brazilian civil society monitoring project, has documented 535 facial recognition technology projects across the country — affecting an estimated 97 million people.
The project reveals how FRT deployment has expanded rapidly with little regulatory oversight or public debate.
Predictive policing and border management
Predictive policing relies on AI and data analytics to predict potential crimes or undesirable activity (such as a protest) before they happen.49 While it is not new for law enforcement agencies to track and monitor crimes, AI provides them with the capabilities to analyse vast amounts of data. In many cases, this data is collected in illegitimate ways.
Israel50 has used algorithms to profile Palestinians under the pretext of preventing terror attacks by analysing vast amounts of social media data such as a user’s social media posts, profile photos, age and hometown to “identify attackers before they act”.51 These systems are already inherently biased, given the Israeli government’s criminalisation of Palestinians’ peaceful calls for an end to the occupation or their resistance to it.52 Authorities in a number of Indian states deploy predictive policing.53 “Delhi’s Crime Mapping Analytics and Predictive System (CMAPS) collects data every three minutes from the Indian Space Research Organisation’s satellites, historical crime data, and the ‘Dial 100’ helpline to identify ‘crime hotspots’ which are crime-prone areas”.54
Policing data, on which predictive policing software is built, is incomplete or biased, leading to a ‘feedback loop’, amplifying policing of communities that are already over-policed and face discrimination.55 The technology was shown to perpetuate existing biases and forms of discrimination against Black people in the U.S.56 These systems are also deployed to predict the likelihood that someone who was convicted of a crime is likely to reoffend.57
Predictive policing, risk-assessment and data analytics tools are deployed in border and migration areas, which can not only hinder freedom of movement, but potentially endanger the migration status of people, including activists.
Authorities across the world deploy AI-powered profiling and risk-assessment tools to profile passengers and analyse their data with the purpose of anticipating their risk level.58 Based on outputs from these tools, border and migration authorities can decide whether to allow entry to a traveller or subject them to additional security checks. Companies that sell such tools “claim their software can detect terrorists, human traffickers, drug dealers, serious criminals, missing persons and increasingly, people migrating without papers”. For instance, French company Idemia’s BORDERGUARD suite combines AI and biometrics for border control. It includes BORDERGUARD Targeting, an AI-based risk-assessment software for governments to “anticipate risks by processing and analyzing passenger data”.59 In 2023, as Kenya implemented an Electronic Travel Authorisation (ETA) system to replace its previous e-Visa system, it acquired a border security system from a Swiss company called Travizory.60 According to the company, its system combines “real-time carrier data, AI-powered profiling and risk-assessment and automated alerts” and “enables proactive intervention and informed decision-making to prevent threats from reaching the border”.61 The government of Kenya reportedly replaced the Travizory system with a different one in 2025.62 However, the system has been operational in the Seychelles since 2021.63
Spyware, DPI and phishing attacks
State and non-state actors deploy algorithms in different forms of online surveillance that infringe on civic actors’ rights to privacy, freedom of expression and information, and freedoms of peaceful assembly and association. These include Deep Packet Inspection (DPI), phishing, and spyware attacks.
While DPI is a method that can be used for legitimate purposes, such as the detection and blocking of spam, viruses, and child exploitation content, governments use it to censor legitimate speech. For example, the Egyptian government uses it to block access to websites, including those of independent media and CSOs64 as well as to virtual private networks (VPNs),65 which can help users navigate the internet more privately and circumvent government censorship. Machine learning allows deployers of DPI to be more precise in monitoring and categorising content to be blocked.66
Machine learning is used in spyware attacks by governments to infect the devices of targeted individuals in order to access and steal sensitive information and monitor their behaviours.67 Governments around the world deploy spyware to spy on opponents, dissidents, HRDs, and journalists.68 Since the 2010s, spyware providers have been integrating machine learning with their software which “has broadened targeted surveillance capabilities”.69 Machine learning can be deployed at different stages of a spyware attack, making it easier for attackers to identify victims, discover software vulnerabilities to be exploited in zero-day attacks,70 and bypass passwords and security tests.71
In addition, governments and cybercriminals can abuse Generative AI in phishing attacks72 to gain unauthorised access to others’ personal information. Governments use phishing to target opponents, critics and civil society. Generative AI allows attackers to better research their targets and craft convincing messages. Attackers can also deploy AI to create deepfakes, –hyper-realistic audio, videos, and photos–aimed at impersonating someone the target knows in order to trick them into clicking on a link that contains malware or installing spyware onto their device.
Impacts of AI-powered surveillance on civil society
Civil society groups and activists around the world are concerned about the impact of AI-powered surveillance technologies on human rights and their work, especially given that robust, rights-based regulation of AI still significantly lags behind development and deployment. AI deployment in surveillance and invasive technologies such as FRT, spyware, and predictive policing infringe on privacy, freedom of movement, right to association and freedom of expression.
In the Occupied Palestinian Territories, Israel has for years deployed facial recognition systems to subject Palestinians to constant surveillance and policing and restrict their freedom of movement.73 During the genocide in Gaza, Israel has accelerated its deployment of facial recognition technology , which it uses, along with automated decision making tools,74 to identify, track, and select targets for killings.75 The Israeli military has deployed machine learning tools, such as Lavender, which “assigns ratings to people in Gaza related to their suspected affiliation with Palestinian armed groups for purposes of labeling them as military targets” and Where’s Daddy?, which “purports to determine when a target is in a particular location so they can be attacked there”.76 These tools, which rely on mass (biometric) surveillance, lack proportionality and human oversight, and have contributed to mass killings and the evisceration of civilian infrastructure in Gaza,77 affecting everyone including journalists, humanitarian workers, and HRDs. According to the Committee to Protect Journalists (CPJ), at least 259 journalists and media workers have been killed in the conflict (through 30 March 2026),78 making it the deadliest conflict for journalists since CPJ started collecting data more than 30 years ago.79
“You are being constantly watched through various systems, and they are all collecting so much data because we know the Israeli surveillance regime is extensive. Our phone calls are always tapped; our communications are always going through Israeli ports…There are also the drones that are collecting so much information on Palestinians. There are also the checkpoints, where every checkpoint has a set of cameras. So someone like me as a Jerusalemite, I really worry about how much information they are collecting and how it could affect me in a harmful way. It is the way the occupation works. It is control and domination. So if anything is a bit off, according to them, which could be totally legal and normal for me, they use that information to harm us. We fear retribution if we practice our basic rights and civil liberties”, said Jalal Abukhater, Policy Manager with 7amleh, a Palestinian digital rights organisation. He added, “Because of the killing and the genocide in Gaza people are terrified of the idea of communicating over WhatsApp or communicating over certain channels because they know that any sort of information that Israel receives, they have AI systems that are created to just assume that you are guilty and assume that you and your entire family can be bombed”.
“Our phone calls are always tapped; our communications are always going through Israeli ports”
— Jalal Abukhater
These systems severely obstruct civic freedoms, and the impacts are disproportionate for excluded groups and individuals. FRTs are more likely to mis-identify people of colour and predictive policing systems are trained on historical racist policing data that are more likely to criminalise historically marginalised groups.
The Pakistan-based disability rights organisation, Spring NGO (R055), reported that:
Predictive policing powered by AI can result in the overpolicing or profiling of marginalised groups, including persons with disabilities, under the guise of maintaining security
“Predictive policing powered by AI can result in the over-policing or profiling of marginalised groups, including persons with disabilities, under the guise of maintaining security. Such practices may discourage community members and activists from participating freely in public advocacy events, thereby shrinking civic space and creating an atmosphere of fear. Public space surveillance technologies, such as facial recognition, also threaten privacy and freedom of assembly. These systems often fail to accurately identify persons with disabilities or those using assistive devices, leading to discrimination or misidentification. The knowledge that public gatherings or protests might be monitored using AI-driven tools can reduce public participation in advocacy activities supported by Spring NGO. Digital surveillance through spyware or phishing attacks directly undermines the security of NGOs. As Spring NGO engages with human rights defenders, government bodies, and international partners, AI-powered digital threats could expose sensitive information, jeopardize the safety of activists and erode trust among stakeholders.”
“Predictive policing powered by AI can result in the over-policing or profiling of marginalised groups, including persons with disabilities”
— Spring NGO, R055, Pakistan
“I maintain that, in Chile, AI still makes mistakes in recognition that could endanger people or in the interpretation of attitudes, which could lead to a person being wrongfully detained due to a camera error”, R0228a respondent of the survey stated.
“I maintain that, in Chile, AI still makes mistakes in recognition that could endanger people or in the interpretation of attitudes, which could lead to a person being wrongfully detained due to a camera error”
— R0228, Chile
The repercussions for civil society activists with a migration background could include a ban on entry to a country or the revoking of their visa or their right of residence. This has been a concern for many Palestinian and non-Palestinian students involved in the Palestine solidarity movement in the U.S. In March 2025, the U.S. State Department announced the deployment of an AI-powered programme called Catch and Revoke, where “algorithms would collect data from social media profiles, news outlets, and doxing sites” to revoke visas of students for their pro-Palestine activism and positions.80
“I have lots of public information that is available, if someone wants to look into my name, they can see that Jalal writes about Jerusalem, about life in Palestine and works for 7amleh. This is easily identifiable information, if you go and ask the system, is this person anti-Israel, very obviously, the answer will be yes, but that is not a criminal act, that is not something illegal. The problem with the AI tools that are being used on those borders is that their standard is just anti-Israel, as if it is a crime of thought, as if it is a crime that you are suspected of. Your freedom of expression to be anti-Israel is unacceptable to them. You are denying people entry based on who or what they could stand for or the views they espouse. So, in a way, as a precaution, you are denying people entry just because of the views they hold, which are not illegal, they are harmless, and they are literally principled expressions, in a sense”, said Abukhater.
Surveillance and policing AI tools infringe on the right to privacy, leading to self-censorship and creating a chilling effect on freedom of assembly and freedom of expression.81 Israel’s use of predictive policing to allegedly prevent attacks severely infringes on Palestinians’ freedom of expression. According to Abukhater:
“AI does get things wrong many times and using it for predictive policing methods usually puts innocent people in the crosshairs and does not really effectively stop people who actually incite. It is just that people fear that they are all being targeted, and that your speech is being policed, and that you do not have any freedom of expression or freedom of association because AI tools or the assumption that you could potentially pose a threat means that you are already a criminal in the eyes of the occupation. Of course, it is not the way due process is supposed to be, but this is how it is for Palestinians”.
Governments do not have to acquire the most sophisticated and expensive AI tools to conduct surveillance. Readily available data mining tools allow them to easily analyse and observe what people are saying online, as one interviewee who requested anonymity said. For example, through automated scraping of vast amounts of data, law enforcement agencies can analyse and monitor what people are posting online and talking about, thereby obstructing users’ privacy and freedom of expression82 Social media monitoring is also deployed to monitor (potential) protests and profile protesters in order “to learn the identities and affiliations of the organisers, the location and timing of a planned action, and other related information”.83 Use of social media monitoring has been documented in Mexico, Colombia, and the UK, among other countries.84
These different AI surveillance systems are frequently deployed in contexts where privacy and data protection laws are weak, and state surveillance is not restricted or subject to independent oversight. In Libya, “the lack of transparency and regulation allows biometric and facial recognition systems to be misused for tracking activists and restricting freedom of expression and assembly”, survey respondent R0136 said, adding that, “AI-driven surveillance tools, supported by open-source intelligence (OSINT) practices and spyware, have been linked to monitoring of online activities by law enforcement and armed groups”. One civil society respondent who requested anonymity mentioned that AI deployment in predictive policing and surveillance threatens the organisation’s “ability to organise and mobilise young people freely”, further explaining that: “These technologies can be used to monitor gatherings, discourage civic participation, or unfairly target youth groups. Digital surveillance, including spyware and phishing, creates security risks for our team, volunteers, and community partners—undermining trust and open communication”.
In Africa, “a big problem is that there is no adequate legal framework in place. So, the technologies are being introduced without that framework, without adequate oversight, and even stakeholder engagement. Many are just waking up and seeing things being installed without them being explained…In some countries, there are still no data protection laws and in some countries, and if those laws are there, the institutions are not robust enough to oversee the security agencies”, Victor Kapiyo, a senior researcher at the Collaboration on International ICT Policy for East and Southern Africa (CIPESA), said in an interview.
“A big problem is that there is no adequate legal framework in place. The technologies are being introduced without that framework, without adequate oversight”
— Victor Kapiyo, CIPESA
Similarly, in Latin America, technologies are deployed without proper regulation. “Many countries do not have proper privacy or data protection policies beyond having data protection norms. For example, in Bolivia, there is no personal data protection law. In Argentina, the data protection law is very old, it is 20 years old”, said Juan Manuel Garcia, an independent consultant working at the intersection of technology and human rights, in an interview. In Brazil, where project O Panoptico has so far documented 535 FRT projects in public spaces and potentially more than 97 million people monitored by these technologies across the country (as of 4 April 2026),85 the data protection law does not apply to processing “done for purposes of public safety, national defense, state security, or activities or investigation and prosecution of criminal offenses”.86 Such a loophole gives authorities broad powers to infringe on people’s privacy rights. Yamin Curzi, a professor at the Center for Technology and Society with the Fundação Getúlio Vargas Law School in Rio de Janeiro, explained in an interview:
“We do not have anything right now in Brazil that actually addresses how data should be treated when collected by police forces, by authorities, by judges, etc. So, with this blank space, the city councils, the mayors, etc. are signing contracts with private enterprises to deploy CCTV and other facial recognition technologies without any transparency, without public consultations, without accountability. And people are vulnerable”. She added that there have been several cases of people who were misidentified by FRT systems in Brazil, especially people of colour. “But we also know that the systems, they cannot detect properly, for example, trans people and also children, they are also vulnerable”.
“We do not have anything in Brazil that addresses how data should be treated when collected by police forces or authorities”
— Yamin Curzi, Brasil
As a result of increased deployment of AI in surveillance, civil society actors feel monitored, unsafe, and more afraid to engage in civic and public matters
One Nigeria-based respondent (R0047) stated: “AI deployment, especially through state surveillance systems, predictive policing tools and data-driven profiling, interferes with our advocacy work by creating fear and mistrust among communities and activists we engage with. Civil society actors often feel monitored, which limits their freedom to organise, speak and mobilise around sensitive issues such as governance, human rights, and youth inclusion”.
A survey respondent working with the Centre Stage Media Arts Foundation (CSMA) in Zimbabwe, R0219, expressed concerns about the abuse of CCTV cameras to restrict the right to protest: “The deployment of cameras in public spaces is not only being used to maintain safety and public order. There is a real risk that as civic organisations, if we organise demonstrations, cameras are likely to be used for surveillance and violating our rights to freedoms of assembly and expression. This will likely result in further restrictions on civic space”.
Unauthorised access to an organisation’s systems or employees’ devices, for instance, through the deployment of AI-powered spyware and phishing attacks, can expose their information to governments or cybercriminals seeking to commit fraud.
“Hackers are well positioned to exploit your vulnerability in use of AI to sabotage an organisation’s work through hacking into its systems”, noted one respondent, R0016. Another, R068, stated: “we collect racism stories from asylum seekers, and participants request for anonymity; we are always afraid AI can expose our collection”.
Further, information extracted in an unauthorised manner can be later used by authorities to prosecute civic society actors or by state and non-state actors to discredit them in disinformation or propaganda campaigns. A Uganda-based respondent, R0048, said that: “AI-driven phishing attacks can compromise the security of organisational systems and data, potentially leading to the exposure of sensitive information about human rights defenders, beneficiaries, or partners. This could put individuals at risk of persecution or harm”. An interviewee who requested anonymity highlighted the sensitivity of financial information, when leaked and accessed by unauthorised parties, thereby putting civic activists at risk of prosecution on allegations of “illicit funds” and fraud. For example, Tunisian authorities have used foreign funding as a pretext to crack down on CSOs and independent media in recent years.87
An environmental organisation (R091) mentioned that mining companies “are always on the lookout for bad PR against them”.Unauthorised access to sensitive information can be abused to facilitate Strategic Lawsuits Against Public Participation (SLAAPs), legal actions initiated by private companies and individuals to silence critics.88
Algorithms used by digital platforms and their implications for civic space
Social media platforms deploy content moderation algorithms at scale to detect and remove content that violates their policies.89 Algorithmic techniques in content moderation include hash matching “the process of transforming a known example of a piece of content into a ‘hash’ – a string of data meant to uniquely identify the underlying content” and classification, which “assesses newly uploaded content that has no corresponding previous version in a database” to categorise it and predict whether such content vmay or may not violate a platform’s policies.90
These algorithms can have consequences for human rights and civic space when they result in over-moderation of legitimate speech, infringing on freedom of expression and access to information as well as hindering civil society’s ability to mobilise and reach audiences. In other cases, these algorithms may fail to detect content that is abusive, harassing, hateful or inciting, putting the safety and wellbeing of civil society activists and journalists at risk, and in turn, preventing them from doing their work.
Throughout the years, researchers, journalists, and activists have documented several challenges with algorithmic content moderation. First, there is the influence of socio-political factors and the Global North—particularly the U.S.– standards in the design and implementation of these systems, resulting in biases that disproportionately impact users in the Global South.91 For instance, Meta’s dangerous organisations and individuals (DOI) policy, based on which the company instructs its algorithms to remove content by “terrorist” organisations or in support of them, is highly influenced by U.S. foreign policy interests, and those affected by DOI-related removals are disproportionately of Middle Eastern, South Asian, and Muslim backgrounds.92
Second, while algorithms can categorise content, they still struggle with the context in which content is posted.93 For example, algorithms can accurately detect when content is graphic or should not be shown to younger users with high accuracy; however, it may still fail to recognise when violent or graphic content is posted for awareness-raising and educational purposes.94As R0051 noted: “AI-driven content moderation and ranking systems sometimes suppress nutrition advocacy posts that mention hunger or child malnutrition, misclassifying them as ‘graphic’ or ‘sensitive’.” In the aftermath of the 7 October 2023 attacks by Hamas on northern Israel and Israel’s ensuing war on Gaza, Meta’s algorithmic content moderation systems erroneously removed videos for depicting graphic violence.95 In another example, in 2020, Facebook and Instagram’s systems accidentally flagged posts about a big protest movement in Nigeria denouncing the controversial Special Anti-Robbery Squad (SARS) as “fake news”,96 associating the acronym SARS with misinformation about the COVID-19 virus.97
Third, the lack of “human in the loop” in algorithmic content moderation decisions can present challenges in human oversight, transparency, and access to effective remedy.98 This makes it difficult for people to understand why their content was removed and appeal such decisions at a time when social media platforms have come to rely on AI in content moderation.
Another challenge is the lack of high-quality training data to train content moderation systems in low-resourced languages, many of which are spoken in the Global South. In fact, English dominates the field of AI due to the availability of digitised text data in this language to train models.99 To address this challenge, platforms train their systems on multilingual, large language models which “infer connections between languages, allowing them to uncover patterns in higher-resourced languages and apply them to lower-resourced languages”.100 These systems, however, have shortcomings, as concluded in a 2023 study by the Centre for Democracy and Technology (CDT)which found that they often rely on machine-translated text that contains errors and does not reflect local languages. They do not work well in all languages and fail to consider and reflect the contexts of local language speakers; and when problems arise, they are hard to identify and fix.101
The biases, mistakes, and inaccuracies in content moderation are compounded by content recommendation systems, which activists and civil society actors say negatively affect the reach and visibility of their content and expose them to harmful content. “The right-wing movement in the United States is using AI and algorithms (primarily in social media) to their advantage to spread disinformation and radicalise people as they promote hate, bigotry, misogyny, xenophobia, etc”, said a U.S.-based survey respondent who requested anonymity. Another respondent, R0035, wrote that “social media algorithms often downrank grassroots voices from regions like South Sudan, limiting the visibility of our campaigns”.
Over the past decade, research and investigative reporting have shed light on the way the algorithmic systems used by social media platforms to rank, curate, and recommend content are exacerbating the spread of hate speech, disinformation, and other harmful content. These algorithms are deployed as a part of business models aimed at generating profits from targeted advertising to the platforms and the companies that own them, determining the content users see, including ads, organic posts, recommended pages and accounts to follow, etc.102 These recommendations are made based on the data platforms collect and infer about users, including their location, language(s) they speak, age, profession, previous content they engaged with, interests, likes and dislikes, etc. This means that users are more likely to be recommended content that they would engage with so that they stay longer on the platforms, which can thus generate even more information for platforms to tailor further recommendations and targeted ads.
By prioritising engagement over quality of content, these algorithms often end up making sensationalist content,103 including sexist, racist, and hateful rhetoric go viral. This can lead to content that undermines civic space becoming more visible for users such as misogynistic influencers and the anti-rights movement, both of which spread disinformation and hate that impacts women, feminist groups, and LGBTQIA+ people, among others. In addition, those subjected to online attacks may retreat from civic space and public life, self-censor or adopt lower profiles.104 In a 2023 report exploring the negative impacts of gendered disinformation, a form of Tech-Facilitated Gender-Based Violence that is particularly deployed to target and silence women and -non-binary activists, HRDs, protesters and journalists, the UN Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression highlighted the role of algorithms in spreading this type of content: “Algorithmic recommender systems play a major role in exacerbating the problem. Adversarial narratives exploit the human tendency towards negative content and disproportionately drive engagement on platforms. Algorithmic newsfeeds craft automatically generated, highly personalized adversarial content streams that keep users engaged on the platform, and monetized, and that in the end corrupt the entire global information ecosystem”.105
The weaponisation of Generative AI to spread disinformation and target and discredit civil society is another threat to civic space. A Taxonomy of Human Rights Risks Connected to Generative AI, by the UN B-Tech Project, identified a number of risks that are relevant to civic space, including its use to create and spread disinformation, “inciting targeted physical violence against specific individuals or groups and non-consensual sexualised content”, and “derogatory or otherwise harmful outputs pertaining to people with marginalised identities”.106
The authors also noted: “Generative AI may be leveraged to create false but convincing content presented as authentic for the purpose of misleading people. Generative AI’s capacity to create this content at scale can make online abuse campaigns easier to carry out, by both private and public actors. Such campaigns may successfully harass targets—including journalists, activists, and political actors—into self-censorship. Female public figures are especially at risk of targeted online harassment”.
One form of AI-generated content that has been particularly harmful is the spread of deepfake sexual abuse, which disproportionately targets women. This is exemplified when the Grok AI chatbot, developed by Elon Musk’s xAI, was abused on a wide scale to generate fake and nonconsensual nudes of women and children and spread them on X, the social media platform he owns.107 A form of gendered disinformation,108 deepfake sexual abuse, particularly targets women who are visible online, such as journalists, HRDs, feminist activists and politicians, to discredit and silence them and exclude them from participating in political and civic life.
“For women human rights defenders in Tanzania, in Uganda, the women candidates, vying for elections in Uganda, image-based abuse is the tactic that is now draining their swamp in terms of political participation”, said Irene Mwendwa, a Nairobi-based consultant on technology, AI, and law. She noted that, while moderation of text-based content moderation in some African languages has improved, “non-consensual image sharing is still very, very high, and there is very limited knowledge or understanding about pulling some of this content down”. She added, “the implications are higher, so that is what is really happening, and women human rights defenders have really tried to hold training opportunities, but also to hold some of these tech companies accountable. But, from the Big Tech side, the content moderation and public policy and human rights departments were all slashed down”.
“For women human rights defenders in Tanzania, in Uganda, the women candidates vying for elections, imagebased abuse is the tactic that is now draining their swamp in terms of political participation”
— Irene Mwendwa, Nairobi
During protests and conflicts, where the role of civil society is even more crucial in disseminating factual information, including life-saving information, documenting violations and holding powerful actors accountable, abuse of GenAI and platforms by state and non-state actors disrupts information flow and access and thereby threatens civic space.
Victor Kapiyo, senior researcher at the Collaboration on International ICT Policy for East and Southern Africa (CIPESA), acknowledged in an interview that there have been positive uses of Generative AI by civil society, which “has made it easier to edit things, to advance its message around and do its work. But when we have groups that are organised to amplify wrong or misleading narratives, then it becomes a problem”. He explained, “AI-generated images, algorithms have been leveraged by different actors to target and ridicule or diminish the work of civil society. So, in some countries, we saw campaigns that targeted civil society to discredit their work. Also, from a civic space perspective, the resulting threat to information integrity, in the sense that spreading misinformation about key topics during elections and conflicts have become rampant. [There are] organised groups that are paid by politicians or other political actors to interfere with information”. He specifically referenced the spread of AI-generated images during anti-finance bill protests in Kenya in 2024. Some of these images were spread to manipulate public opinion. According to researchers at the Digital Forensic Lab (DFRLab), AI tools, including GenAI, were deployed by a “network of X accounts [that] appeared to operate in coordination, amplifying several hashtags that attacked protestors and boosted support for President William Ruto and the government”.109
Many survey respondents said they were concerned about how these GenAI tools could be used to distort narratives about their work and manipulate public debate. “Synthetic media and deepfakes increase misinformation, which can distort our narratives, harm our credibility, and weaken public trust in civic actors like us”, one respondent said. Another, based in the United Kingdom (R0120) wrote: “AI systems can generate inaccurate or misleading information, which may distort the narrative about our organisation’s activities or goals, potentially undermining our credibility with the public and policymakers”.
By suppressing civil society content on platforms and exacerbating the spread of harmful content, these algorithmic systems are shrinking opportunities for peaceful expression, exchange of ideas, and access to information in the digital space. This is disruptive to the work of civil society around the world.
A Nigeria-based respondent, R0047, recounted that “algorithmic bias in digital platforms can reduce the visibility of advocacy campaigns or misclassify human rights content as “sensitive” or “political”, thereby suppressing civic voices online. AI-generated misinformation and deepfakes further complicate advocacy efforts by spreading false narratives that can discredit organisations like ours or undermine genuine social justice campaigns”. A Ghana-based organisation, R007, responded: “Since we are a small startup and have not deployed AI tools ourselves, our main concern lies in how external AI systems—like social media algorithms and content recommendation tools—affect our visibility and outreach. These systems can sometimes limit the reach of our posts or misclassify our content, reducing engagement with our target audience. Additionally, the rise of AI-generated content and deepfakes poses a risk of misinformation, which can undermine public trust in genuine initiatives like ours. These challenges make it harder to communicate our mission effectively and maintain credibility in digital spaces”.
“For women human rights defenders in Tanzania, in Uganda, the women candidates vying for elections, image-based abuse is the tactic that is now draining their swamp in terms of political participation”
— Irene Mwendwa, Nairobi
33 Prysiazhniuk, V. & Ford, C. “How AI is accelerating the global surveillance state, and how you can defend yourself”. NymVPN, 18 September 2025. https://nym.com/blog/clearview-ai-and-palantir (accessed 30 April 2026).
34 Mahoozi, S. “Mahsa Amini death: facial recognition to hunt hijab rebels in Iran”. Thomson Reuters Foundation. 21 September 2022. https://news.trust.org/item/20220921162019-568vk/ (accessed 30 April 2026).
35 The Economist. “China: facial recognition and state control”. Youtube. 24 October 2018. https://www.youtube.com/watch?v=lH2gMNrUuEY (accessed 30 April 2026).
36 Zomorodi, M., Monteleone, K. & Meshkinpour, S. “How facial recognition allowed the Chinese government to target minority groups”. NPR. 9 December 2022. https://www.npr.org/2022/12/09/1141627539/how-facial-recognition-allowed-the-chinese-government-to-target-minority-groups (30 April 2026).
37 CIVICUS. “Facial recognition: the latest weapon against civil society”. 23 May 2025. https://lens.civicus.org/facial-recognition-the-latest-weapon-against-civil-society/ (accessed 30 April 2026).
38 Ibid.
39 Amnesty International. “Netherlands: Mass police surveillance of protests part of ‘growing control culture’ – new report”. 15 October 2024. https://www.amnesty.org.uk/latest/netherlands-mass-police-surveillance-protests-part-growing-control-culture-new/ (30 April 2026).
40 Sinha, A. “The Landscape of Facial Recognition Technologies in India”. Tech Policy Press. 13 March 2024. https://www.techpolicy.press/the-landscape-of-facial-recognition-technologies-in-india/ (accessed 30 April 2026).
41 SFLC. “Deployment of Facial Recognition Technology for State Surveillance and Monitoring”. 16 January 2024. https://sflc.in/deployment-of-facial-recognition-technology-for-state-surveillance-and-monitoring/ (accessed 30 April 2026).
42 Herta Security. “Safe City project with facial recognition in Phuket”. 14 December 2017. https://hertasecurity.com/news/safe-city-project-with-facial-recognition/ (accessed 30 April 2026).
43 Borak, M. “Thailand rolling out AI surveillance system after high-profile kidnapping of Chinese actor”. Biometric Update. 28 January 2025. https://www.biometricupdate.com/202501/thailand-rolling-out-ai-surveillance-system-after-high-profile-kidnapping-of-chinese-actor (accessed 30 April 2026).
44 Roberts, T. et al. (2023) Mapping the Supply of Surveillance Technologies to Africa: Case Studies from Nigeria, Ghana, Morocco, Malawi, and Zambia, Brighton: Institute of Development Studies, DOI: 10.19088/IDS.2023.027
45 Abrougui, A. (2025). Phishing, spyware, and smart city tech: Surveillance in Sisi’s Egypt. In T. Roberts & A. Mare (Ed.). Digital Surveillance in Africa: Power, Agency, and Rights (pp. 57–84). London,: Zed Books. Retrieved April 30, 2026, from http://dx.doi.org/10.5040/9781350422117.ch-3
46 Ibid.
47 Al Sur Consortium. “Facial Recognition in Latin America”. https://estudio.reconocimientofacial.info/en/ (30 April 2026).
48 Bergengruen, V. “A Controversial Facial-Recognition Company Quietly Expands Into Latin America”. Time. 18 June 2024. https://time.com/6988684/clearview-ai-latin-america/ (accessed 30 April 2026).
49 Lungu, M. “Predictive policing AI is on the rise − making it accountable to the public could curb its harmful effects”. The Conversation. 6 May 2025. https://theconversation.com/predictive-policing-ai-is-on-the-rise-making-it-accountable-to-the-public-could-curb-its-harmful-effects-254185 (accessed 30 April 2026).
50 CIVICUS Monitor. “Israel downgraded in global ratings report on civic freedoms”. 9 December 2025. https://monitor.civicus.org/press_release/2025/israel/ (accessed 30 April 2026).
51 Ibid.
52 Aljazeera. “Dareen Tatour sentenced to five months in prison over poem”. 31 July 2018. https://www.aljazeera.com/news/2018/7/31/dareen-tatour-sentenced-to-five-months-in-prison-over-poem (accessed 30 April 2026).
53 Rani M (2024). “Impacts and ethics of using Artificial Intelligence (AI) by the Indian Police”. Public Administration and Policy, Vol. 27 No. 2 pp. 182–192, doi: https://doi.org/10.1108/PAP-06-2023-0081
54 Ibid.
55 Privacy International. “How predictive policing can be used at protests”. 5 May 2021. https://privacyinternational.org/explainer/4501/how-predictive-policing-can-be-used-protests (accessed 30 April 2026).
56 Majid, K. “Predictive Algorithms: Help or Hindrance”? Center of AI and Digital Ethics, University of Melbourne. 30 March 2023. https://www.unimelb.edu.au/caide/news-media-and-events-archive/caide-community-blog/predictive-algorithms-help-or-hindrance (accessed 30 April 2026).
57 O’Neill, Cathy. (2017). Weapons of Maths Destruction: How Big Data Increases Inequality and Threatens Democracy. Penguin Press.
58 Chandler, C. “Inside the Black Box of Predictive Travel Surveillance”. Wired. 13 January 2025. https://www.wired.com/story/inside-the-black-box-of-predictive-travel-surveillance/?utm_source=chatgpt.com (accessed 30 April 2026).
59 IDEMIA Group. “BORDERGUARD™ Targeting”. Undated. https://www.idemia.com/borderguard-targeting (accessed 1 May 2026).
60 Chandler, C. “Inside the Black Box of Predictive Travel Surveillance”. Wired. 13 January 2025. https://www.wired.com/story/inside-the-black-box-of-predictive-travel-surveillance/?utm_source=chatgpt.com (30 April 2026).
61 Travizory. “Travizory API-PNR Targeting System”. Undated. https://www.travizory.com/what-we-do/advance-passenger-information (accessed 1 May 2026).
62 CapitalFM. “Kenya’s Controversial ETA System Switch Triggers Investor, Tourism Backlash”. Allafrica. 22 April 2025. https://allafrica.com/stories/202504220208.html (accessed 1 May 2026).
63 Lloyd, G. “African Border Security Week 2025”. Travizory. https://www.travizory.com/african-border-security-week-2025 (accessed 1 May 2026).
64 Access Now. “Egypt: rights groups condemn latest blocking of news websites. Press release”. 22 June 2023. https://www.accessnow.org/press-release/egypt-rights-groups-condemn-latest-blocking-of-news-websites (accessed 1 May 2026).
65 Abrougui, A. (2025). Phishing, spyware, and smart city tech: Surveillance in Sisi’s Egypt. In T. Roberts & A. Mare (Ed.). Digital Surveillance in Africa: Power, Agency, and Rights (pp. 57–84). London,: Zed Books. Retrieved April 30, 2026, from http://dx.doi.org/10.5040/9781350422117.ch-3
66 Švedkauskas, Zilvinas. 2022. “Digital surveillance, master key for MENA autocrats.” In: Liberty doom? Artificial intelligence in Middle Eastern Security. EuroMeSCo, Volume 27. https://www.euromesco.net/wp-content/uploads/2022/07/Policy-Study27.pdf (1 May 2026).
67 Ibid.
68 Abrougui, A. “Global Trends in Digital Security: Civil Society & Media”. October 2023. Internews. https://internews.org/wp-content/uploads/2023/11/Global-Trends-in-Digital-Security.pdf (accessed 30 April 2026).
69 Švedkauskas, Zilvinas. 2022. “Digital surveillance, master key for MENA autocrats.” In: Liberty doom? Artificial intelligence in Middle Eastern Security. EuroMeSCo, Volume 27. https://www.euromesco.net/wp-content/uploads/2022/07/Policy-Study27.pdf (accessed 1 May 2026).
70 In a zero-day attack, attackers exploit previously unknown and unaddressed software vulnerability.
71 Švedkauskas, Zilvinas. 2022. “Digital surveillance, master key for MENA autocrats.” In: Liberty doom? Artificial intelligence in Middle Eastern Security. EuroMeSCo, Volume 27. https://www.euromesco.net/wp-content/uploads/2022/07/Policy-Study27.pdf (accessed 1 May 2026).
72 D’Andrea, A., Palak, K. & Guccione, D. “How AI Is Making Phishing Attacks More Dangerous”. Keeper. 13 September 2024. https://www.keepersecurity.com/blog/2024/09/13/how-ai-is-making-phishing-attacks-more-dangerous/ (accessed 1 May 2026).
73 Amnesty International. “Automated Apartheid: Facial recognition entrenches the oppression of Palestinians”. Undated. https://banthescan.amnesty.org/opt/index.html (accessed 1 May 2026).
74 Yuval, A. “‘Lavender’: The AI machine directing Israel’s bombing spree in Gaza”. +972 Magazine. 3 April 2024. https://www.972mag.com/lavender-ai-israeli-army-gaza/ (accessed 1 May 2026).
75 Article19. “Israel: Stop using biometric mass surveillance against Palestinians”. 9 April 2024. https://www.article19.org/resources/israel-stop-using-biometric-mass-surveillance-against-palestinians/ (1 May 2026).
76 Human Rights Watch. “Questions and Answers: Israeli Military’s Use of Digital Tools in Gaza”. 10 September 2014. https://www.hrw.org/news/2024/09/10/questions-and-answers-israeli-militarys-use-of-digital-tools-in-gaza#_What_are_some (accessed 1 May 2026).
77 OHCHR. “Gaza: UN experts deplore use of purported AI to commit ‘domicide’ in Gaza, call for reparative approach to rebuilding”. 15 April 2024. https://www.ohchr.org/en/press-releases/2024/04/gaza-un-experts-deplore-use-purported-ai-commit-domicide-gaza-call (accessed 1 May 2026).
78 Hasan, M. & Sabbagh, W. “How Israel’s Unprecedented Killing of Palestinian Journalists in Gaza Makes Accountability Reporting Almost Impossible “. Global Investigative Journalism Network. 6 April 2026. https://gijn.org/stories/unprecedented-killing-palestinian-journalists-gaza-press-freedom/ (accessed 1 May 2026).
79 Committee to Protect Journalists. “Record 129 press members killed in 2025; Israel responsible for 2/3 of deaths”. 25 February 2026. https://cpj.org/special-reports/record-129-press-members-killed-in-2025-israel-responsible-for-2-of-3-of-deaths/ (accessed 1 May 2026).
80 Goodfriend, S. “The AI Dragnet”. Dissent. 30 April 2025. https://dissentmagazine.org/online_articles/the-ai-dragnet/#:~:text=The%20effects%20were%20nicely%20distilled,at%20the%20Harvard%20Kennedy%20School. (accessed 1 May 2026).
81 Privacy International “How predictive policing can be used at protests”. 5 May 2021. https://privacyinternational.org/explainer/4501/how-predictive-policing-can-be-used-protests (accessed 1 May 2026).
82 Privacy International. “Social media monitoring in the UK: the invisible surveillance tool increasingly deployed by government”. 17 July 2024. https://privacyinternational.org/long-read/5337/social-media-monitoring-uk-invisible-surveillance-tool-increasingly-deployed (1 May 2026).
83 Privacy International. “How social media monitoring can be used at a protest”. 6 May 2021. https://privacyinternational.org/explainer/4509/how-social-media-monitoring-can-be-used-protest (1 May 2026).
84 Privacy International. “Social media monitoring in the UK: the invisible surveillance tool increasingly deployed by government”. 17 July 2024. https://privacyinternational.org/long-read/5337/social-media-monitoring-uk-invisible-surveillance-tool-increasingly-deployed (1 May 2026).
85 O Panoptico. “Monitor de Novas Tecnologias na Segurança Pública do Brasil”. https://www.opanoptico.com.br/#publicacoes (accessed 3 May 2026).
86 Isaza, J.J. & Katshir, H. “Brazil Passes Landmark Privacy Law: The General Law for the Protection of Privacy”. American Bar Association. 24 April 2020. https://www.americanbar.org/groups/business_law/resources/business-law-today/2020-may/brazil-passes-landmark-privacy-law/ (accessed 1 May 2026).
87 CIVICUS. “Migrant support, women and LGBTQI+ rights organisations face suspension”. 17 March 2026. https://monitor.civicus.org/explore/migrant-support-women-and-lgbtqi-rights-organisations-face-suspension/ (accessed 3 May 2026).
88 Bychawska-Siniarska, D. and Nowicka, Z. “From Zero to Hero: Once grappling with SLAPPs, Poland could now be a model for how to fight them”. Verfassungsblog . https://verfassungsblog.de/anti-slapp-legislation-poland/ 4 September 2024 (accessed 3 May 2026).
89 Gorwa, R., Binns, R., & Katzenbach, C. (2020). Algorithmic content moderation: Technical and political challenges in the automation of platform governance. Big Data & Society, 7(1). https://doi.org/10.1177/2053951719897945
90 Ibid.
91 Ibid.
92 Alimardani, M. & Elswah, M. “Digital Orientalism: #SaveSheikhJarrah and Arabic Content Moderation”. In POMEPS Studies 43: Digital Activism and Authoritarian Adaptation in the Middle East. August 2021. https://pomeps.org/digital-orientalism-savesheikhjarrah-and-arabic-content-moderation (accessed 1 May 2026).
93 Gorwa, R., Binns, R., & Katzenbach, C. (2020). Algorithmic content moderation: Technical and political challenges in the automation of platform governance. Big Data & Society, 7(1). https://doi.org/10.1177/2053951719897945
94 Kayyali, D. & Altthabani, R. “Vital Human Rights Evidence in Syria is Disappearing from YouTube”. Witness. 30 August 2017. https://blog.witness.org/2017/08/vital-human-rights-evidence-syria-disappearing-youtube/ (accessed 1 May 2026).
95 Montgomery, B. & agencies. “Meta wrong to remove graphic Israel-Gaza videos, oversight board says”. 19 December 2023. https://www.theguardian.com/technology/2023/dec/19/facebook-moderation-israel-hamas-videos (accessed 1 May 2026).
96 Olasoji, T. “Facebook, Instagram indiscriminately flag #EndSars posts as fake news”. Mail&Guardian. 23 October 2020. https://mg.co.za/africa/2020-10-23-facebook-instagram-indiscriminately-flag-endsars-posts-as-fake-news/ (accessed 1 May 2026).
97 Ricks, B. Surman, M. and Contributors. “Creating Trustworthy AI”. Mozilla Foundation. 15 December 2020. https://www.mozillafoundation.org/en/insights/trustworthy-ai-whitepaper/ (accessed 1 May 2026).
98 Gorwa, R., Binns, R., & Katzenbach, C. (2020). Algorithmic content moderation: Technical and political challenges in the automation of platform governance. Big Data & Society, 7(1). https://doi.org/10.1177/2053951719897945
99 Nicholas, G. & Bhatia, A. “The Dire Defect of ‘Multilingual’ AI Content Moderation”. Wired. 23 May 2023. https://www.wired.com/story/content-moderation-language-artificial-intelligence/ (accessed 1 May 2026).
100 Nicholas, G. & Bhatia, A. “Lost in Translation: Large Language Models in Non-English Content Analysis”. CDT. May 2023. https://cdt.org/wp-content/uploads/2023/05/non-en-content-analysis-primer-051223-1203.pdf (accessed 1 May 2026).
101 Ibid.
102 Maréchal, N. & Biddle Roberts, E. “It’s Not Just the Content, It’s the Business Model: Democracy’s Online Speech Challenge”. New America Foundation. 17 March 2020. https://www.newamerica.org/insights/its-not-just-content-its-business-model/ (1 May 2026).
103 Diepeveen, S. (2022) Hidden in plain sight: how the infrastructure of social media shapes gender norms. ALIGN Report. London: ODI (https://www.alignplatform.org/ resources/report-hidden-in-plain-sight).
105 Ibid.
106 United Nations Human Rights Office of the High Commissioner. “Taxonomy of Human Rights Risks Connected to Generative AI: Supplement to B-Tech’s Foundational Paper on the Responsible Development and Deployment of Generative AI”. https://www.ohchr.org/sites/default/files/documents/issues/business/b-tech/taxonomy-GenAI-Human-Rights-Harms.pdf (accessed 1 May 2026).
107 Wislon, J. “Hundreds of nonconsensual AI images being created by Grok on X, data shows”. The Guardian. 8 January 2026. https://www.theguardian.com/technology/2026/jan/08/grok-x-nonconsensual-images (1 May 2026).
109 Chenrose, A. “AI tools used in Kenya to discredit protesters and allege Russian connections”. DFRLab. 20 December 2024. https://dfrlab.org/2024/12/20/ai-tools-used-in-kenya-to-discredit-protesters-and-allege-russian-connections/ (accessed 4 May 2026).