
Loading summary
A
Foreign.
B
Welcome to the Tech Pill, a podcast that looks at how technology is reshaping our lives every day and exploring the different ways that governments and companies use tech to increase their power. My name is Gus Hossain, and I'm the executive director at Privacy International.
A
And I'm Caitlin and I'm PI's campaigns coordinator. Hi.
B
This week we're very fortunate. This week?
A
Yeah. I mean, we're currently releasing it fortnightly. So this two weeks.
B
Yeah. This Fortnite sounds like Abraham Lincoln, four score.
A
Or indeed, like a teenager. This fortnight. This Fortnite game.
B
That's right.
A
I'd say bi weekly, but I think that fortnightly, like fortnight, is a really useful term that has fallen out of fashion. And people argue over what biweekly means. If it means fortnightly, if it means twice a week. And I think it should mean twice a week, fortnightly should mean every two weeks. Because it is a fortnight. Because we have a word for that in British English. And I appreciate it's a weird hill to dial and irrelevant to this podcast, but nonetheless.
B
Okay, so this fortnight, right? Or this week?
A
Yeah, no, easy.
B
This fortnight. This fortnight we're talking to a very old friend of PI, Marianne Rameh, who was key to a report by one of our wonderful partner organizations called smex.
A
So this fortnight we're talking to Marianne who has co authored their new report, produced, Tested, Deployed, the Militarization of Technology in the swana, or Southwest Asia and North Africa region. Smacs, a really interesting organization. They do a ton of really cool human rights and digital spaces work in the region, and they're very old friends of PI's. We've been working with them, I think, longer than I've been at PI, which is seven years, so quite a long time.
B
So at least nine or ten years. Been working with smacs. And what I love about Marianne in particular is she's the person I go to to understand the dynamics in that region, but also to understand, like when we started working on the issue of militarization of tech, she basically raised her hand and said, hey, we've been here for a while. It's very fascinating. Listen to me. I got things to say. So we're very fortunate to have her as a guest and to hear those very interesting things that she has to say.
C
Bosch. I'm Marianne. I am currently a senior coalitions and research lead at smex. I work on many things. Platform accountability, militarization of tech, which is what we will be discussing Today, and I am the coordinator of the MENA alliance for Digital Rights, which is an alliance born in 2021 for the Mena region for digital rights. And yeah, that's pretty much me.
B
And so swana, as you helped us to identify, is Southwest Asia and North Africa, and then MENA is Middle east and North Africa. Like apart from MENA and the term Middle east being a colonial term, is there any geographic difference between those two?
C
I think Southwest Asia and North Africa is a broader look at the region. It includes countries that are not usually included in Middle east and North Africa, for example, we've moved away from the colonial Mina term to also be able to look at issues in Iran, in Turkey that might influence, you know, the direct focus of the organization. So that is why we've been using SWANA for the past two years, I think. Yeah, I think you will ask, but why do we still call it the MENA alliance for Digital Rights? It's just.
B
Oh, I wasn't being picky, but I just wanted to everybody understand.
C
No, no, but we still. Because, I mean, it's just a phonetic thing. Because imagine calling it the SWANA alliance for Digital Rights. The acronym would be SWANA Swanader, something like that. And it was very heavy, so I get it. So we actually stuck with the madr. MENA alliance for Digital Rights.
B
Okay. Okay, got it. And you are joining us from Paris, right?
C
Yes, indeed.
B
And so that's the beautiful Parisian traffic that we're hearing in the background.
C
Uh huh. You're gonna hear ambulances, traffic, people cursing.
B
Gotta love Paris.
A
There's a non zero chance you hear my cat who is wandering around. She's been told firmly that she's on thin ice and if the door needs to be shut, it will be shut. But she doesn't always listen to me, so there is that. Okay, so you cover a lot of things, you know, a lot of things. But we're here today to talk specifically about militarisation and how different Swarna countries have kind of been engaging in the militarisation of tech and their different strategies and engagements with surveillance technologies, for which, conveniently, you've just done quite an interesting report. So. Yeah, do you want to start by kind of explaining a little bit the research that you've been doing?
C
Yes, of course. Actually we've started this research with Privacy International about how different actors across the Swana region are building, testing and deploying these technologies. And I think the main takeaway from this report is that what's very clear is that this isn't just about, like looking at military hardware or whatnot. It's about data. It's about who's collecting data. It's about who's processing it and who it's getting used against, if I can say that.
A
Yeah.
C
And, well, probably the militarization of tech, this systematic blurring between the civilian and military tools is one of the most defining human rights challenges of our time, as you know. And the region that we've focused on, the Swana region, is. It's really sitting at the center of this phenomenon. And it functions simultaneously as a production, a consumption market, and also, unfortunately, as a live testing ground. And what our report documents is these key patterns of technology militarization across the Swana region. And it also examines the key corporate actors who are driving this, while also analyzing the legal framework that is allowing all of this to flourish. The report actually looks at six countries.
B
Oh, cool.
C
These are six countries, but it's five patterns of militarization of tech.
B
But just to be clear, this doesn't sound like a feel good report. Right. This is not all that you read when.
C
Yeah, yeah.
B
You don't read it with a nice glass of wine. You read it with a stiff whiskey or something like that.
C
Yeah. Or a gigantic glass of wine that you keep the bottle next to you situation. Researching it was also pretty, you know, harsh. Especially as, you know, SMEX is based in Beirut. We're also living through this. So, yeah, I have a researcher friend
A
who I would talk to her and she'd be like, oh, the report's going great. Everything is awful. Like, the research is going amazing. Everything is terrible.
B
Yeah. There's a part of being human rights advocates where as the world gets worse, somehow you feel like you're. Yeah. Validate is not the right word. But it just somehow, oh, there's more data to work with, which is a
A
horrible way lacking in the right area.
C
But also one of the biggest difficulties we faced working on this report is actually the lack of data and the lack of information out there. Because, you know, all of this is happening, but you cannot really prove it unless someone from some company goes, you know, out and works as a whistleblower for this.
B
That's outrageous that we have to count on that.
C
Yes, yes. And that's why, like, there is a lot of gaps in the report that you will probably see. And you'll be like, okay, but what is this? Like, who's selling that? Why don't we know? And honestly, we don't know. And that's a very, very big problem with this militarization of tech. So we've identified five patterns. The scariest, most complete one, most dangerous one is obviously Israel. And Israel occupies a very structurally unique position because it's the principal developer and exporter of militarized surveillance and AI systems in the region, dare I say in the world, using the occupation of Palestine as a continuous testing ground. And you've all heard of the use of AI enabled targeting systems deployed in Gaza since October 2023. And who knows if it was happening before? We don't know. So lavender the gospel, Where's Daddy? And these represent the most extensively documented cases of algorithmic killing in the history of armed conflict. And major cloud providers, including Google, Amazon, Microsoft have provided infrastructure that potentially enabled these systems. So Israel really closes the loop on the militarization of tech. But other countries in the region are not, you know, innocent. So the second pattern is the GCC pattern, the Gulf countries pattern. And we've worked a little bit on the UAE and Saudi Arabia and the interesting thing about these countries is that historically they were only consumers of militarized technology, but they are slowly moving into being producers of militarized technology.
B
Is that so?
C
Yes. And so there is so many examples about recent projects that the UAE and Saudi Arabia have invested in, be it in producing drones, producing offensive intelligence capabilities, capabilities investing hundreds of billions in AI infrastructure and all of this under a very non existent legal framework to govern everything that's happening. So this is a very worrying trend that we've identified. It's the shift towards local production of militarized technology in the Gulf.
B
And this changes so much. Like, you know, it's. As a student of social sciences, I love when technology comes along and can change the way you tell stories about things that traditionally have been told about men and power. You know, so we talk about the region as men vying for power and then all of a sudden AI comes in, all of a sudden investment in tech comes in. And then when you look at Israel through the lens, as you just have the lens of the technology and the data and the act of warfare, it projects a different way of looking at Israel and then the region. But then the fact that Saudi Arabia and the UAE are, I knew they were investing, I didn't know they were actually in production.
A
Does them producing it change any of the dynamics in terms of the transparency?
C
In terms of transparency? I don't think so. Because as we will identify later on, there are a lot of obstacles for accountability in the region and one of them is this non existent transparency around anything from Public procurement, as basic as it sounds, two very opaque corporate structures. You know, we are dealing with authoritarian regimes in the end, so there's no winning with them. But also this, this kind of, this shift that is happening in the Gulf, it's also deepening this entanglement between the countries and global tech companies because of these major investments by be, the Public Investment Fund in Saudi Arabia or Abu Dhabi's Mubadala or other Gulf entities in companies like OpenAI or Entropic, Google, Microsoft and dozens of small AI startups, they create these conflict of interests that like systematically compromise this already limited capacity of companies to enforce human rights commitments. So if you're a startup and 90% of your money comes from a certain country or from a certain fund, then your hands are kind of tight. And this shift is allowing these Gulf states to increasingly develop, customize and export this militarization of mostly AI systems without depending on Western companies, like whose products are maybe subject to expert controls or human rights conditions. So, you know, they're producing their own tech, they don't need the Western companies anymore. And this shift is very worrying, especially that they are also, you know, defending their own interests within the region by giving X, Y or Z certain technologies. And we will get to that in the fifth pattern of militarization of tech that we've identified.
B
Keep going.
C
The third pattern is information dominance. The case of Egypt, for example. It's the case of many other Swana countries, dare I say so in Egypt, the militarization of tech takes on like a new face. It's the pursuit of total information dominance. And this is illustrated through the construction of this surveillance architecture that is designed to monitor everyone, to place entire national communications infrastructures under state control and to be activated whenever you need to target a certain activist or to silence a certain person. And this architecture that Egypt has built is built on deep packet inspection technology. Deep packet inspection technology, also known as dpi, is a network monitoring technology and it enables real time analysis of Internet traffic. So DPI examines the full content of data packets and it enables massive surveillance, filtering, traffic shaping and content manipulation on a very wide scale. So they're using dpi, they're using telecom interceptions, they're using biometric SIM registration while linking every mobile user's identity to their communications. And they're using a toolkit of surveillance platforms that are supplied by mostly European and North American firms.
B
I was wondering who was supplying it, because I remember in the Arab uprising, whereas this huge moment of hope in Egypt and the outrage around the role that Vodafone played. And one would have hoped that the telcos would have wisened up and not become complicit. But it sounds like the industry is complicit.
A
What was the role that Vodafone played?
B
It's just Vodafone was a dominant mobile provider and there was that moment where the network had to be shut down because the government was ordering it and industry was asking, what is our appropriate response when all the events are going on in the main squares? Should we be shutting down? And it caused a global conversation around the role of telcos in the protection of human rights. Finally, didn't last long, though.
C
This kind of took on new forms, I think, with Internet shutdowns, which I also mentioned in a bit. But it feels like the strategies are not new. It's just, you know, faster, bigger, wider when it comes to the scale. Yeah, so that's Egypt for you.
B
So are you saying Egypt is actually developing technology as well?
C
Not to our knowledge.
B
Okay, so they're consuming from elsewhere.
C
Yes. And the fourth pattern is the Syria example. And we are looking at the dangerous fiction of the dual use technologies and the terminology of dual use. So Syria is a very extreme example of militarization of tech because civilian infrastructure during the Assad regime became directly embedded in systems of torture, targeting and warfare. And before and during the civil war, Western companies have provided the Assad regime with monitoring technologies that were weaponized against the Syrian population. And in our opinion, it really demonstrates why the concept of dual use functions as a very dangerous fiction, that when the technology is transferred to authoritarian regimes, we're not really talking about dual use anymore.
B
So just to clarify, so dual use refers to technologies that have both a civilian and non civilian use. But I think what you're saying is that, sure, it might be okay to export a technology to Syria because it's not for the military. It's actually dual use. The reality of what you found is that it was used for aggressive and highly aggressive and deadly purpose.
C
Yes, yes. And this loophole of saying my technology is dual use allows so many companies to bypass obligations that they might have when it comes to human rights and when it comes to exporting this kind of technology. There is actually a very interesting report from Privacy International called Open Season. And actually it was very useful for our research and it detailed, you know, how firms, including Italian firms, South African firms, German firms, had a played a role in Syria's repressive surveillance state between at least 2007 and 2012. And we have more and more evidence coming from Syria as the regime fell.
B
Oh, wonderful. You got some evidence out of that. Okay. Because that was what we struggled with when we were compiling that initial report was there was no data coming out of Syria. We could only track what we could about what was going in. And we had to make sure we were 100% right, because at that time, there were sanctions. And if we got anything wrong and got sued by the Syrian government, we could find ourselves having to break sanctions by paying insurance. It was just insane. So you got actual data. That's fantastic.
C
And this is all documented in the report. We've really based our work on your report and on work by the Business and Human Rights Resource center, the Tahrir Institute for Middle East Policy, and many others. The worrying thing about the Syria example is that there is a pattern in here. It's a regime using tools to hunt down and disappear its own citizens. And we all know the consequences. They were devastating. And the important thing here is that many activists, after being arrested, were shown their own private online communications, and they were shown printed transcripts of intercepted messages during these interrogations. So these dual use systems, they were integrated into intelligence operations and they were used for real time tracking of citizens and directly linked to this detention, torture, and disappearances. And this is horrible. But in the hands of authoritarian regimes, any tool can become a weapon. And that is where, you know, we criticize the regulatory frameworks that permitted these. Say, as you mentioned, Gus, there were so many sanctions, and how did any expert control regime allow this kind of sale?
B
How is it that PI was worried about sanctions in doing the report, but the companies that were selling, oh, what the hell, the world's upside down.
C
It tells you a lot about impunity and the lack of accountability when it comes to these things.
B
And this is all pre AI. So when you talk about the transcripts being shown to somebody, that meant somebody somewhere was actually typing down on some old computer system in the dark bowels of the intelligence agency of Syria. Now, this type of capacity is brought to you by name, any AI company on the planet. That's just extraordinary.
C
This is even scarier. Yeah. And it brings me to the last pattern of militarization of tech that we've identified in the region. And we've used the Sudan example to showcase that. So Sudan really illustrates how the militarization of tech intensifies and gets more activated during active armed conflict. As you know, the state capacity in Sudan is very fragmented. So we're showing through this example that the use of militarized technology is not confined to state Actors. And we're also showing how Gulf states. I'm going back to the Gulf countries are increasingly, you know, as they're becoming producers and exporters of militarized technology, are projecting this capacity outward and are using tech transfer, technology transfers as a tool of regional influence.
B
Of course, because the Israelis basically made that textbook and so did the Americans. Oh, of course, yes.
C
So authoritarian regimes listen and learn from each other. And since the start of the war in Sudan, both parties have deployed technology as a weapon against civilians. And external actors such as the UAE have used these technology transfers to interfere in this war. And both the Sudanese Armed Forces SAF and the Rapid Support Forces RSF have weaponized Internet shutdowns to block information flows in Sudan in areas controlled by the opposing side. And in February 2024, there was a near total communication blackout that descended on Sudan. And as you know, like telecommunications and Internet blackouts are pose severe risks to humanitarian coordination, to emergency services for millions of people. And this is also something we're still seeing in Gaza and in Palestine, the targeting of telecommunications and Internet infrastructures in Sudan as well as in Gaza, the infrastructure has been targeted physically as well as administratively, with all parties in Sudan attacking mobile towers and Internet exchange points. So, yeah, this civilian communication infrastructure is built and is operated for civilian purposes, and it is being repurposed as a weapon of war used to isolate, control and to harm civilian populations. And Internet shutdowns are not solely happening in Sudan and Gaza. They are happening all around the Swana region and all around the world. And this is horrible.
B
The idea that a telecommunications network that you rely on every day to contact your loved ones, to do your job, to figure out where to buy your daily goods and whatnot, the fact that it can be used against you or it can be turned off so you can no longer use it the way that you need to, I feel like that is particularly problematic as much as it's problematic in everyday life. It is particularly problematic in conflict when the stakes are so much higher, but also when conflict, ultimately, if you're going to draw a broad brush around, it leads to occupation. Governments wage war against other territories because they want to SERP that territory. And the idea that let's use. Maybe this wholly inappropriate, but let's use Lebanon as an example. Telecommunications network, Lebanese telecommunications network is probably every day targeted by neighboring countries. Let's just say, and I'll let you get into the details, because I don't want to try to simplify your story. And then ultimately, you know, if there is to be any Annexation. That infrastructure, whether it's telecommunications or any other type of infrastructure, ultimately is going to be owned by the occupying force, whether it's financial or just physical possession. And then they turn it against you, even more so than they did prior to annexation. And so the things that you come to rely upon are already being used against you and will ultimately be a tool of an oppressive occupying force. How do we use that knowledge to prepare? How do we harden our systems for the fact that there is more conflict, that there is more ambition to occupation? How do we learn from Israel? How do we learn from these horrible stories you're telling?
C
So I think it's really hard for Lebanon to deal with excessively funded war machines that are living around our borders. And there are a few steps that Lebanon can take to be in the right direction. I'm not doing a policy checklist for the Lebanese government, but I'm saying that there are concrete steps that we can take that we actually need to protect our data that's coming out of the country. And first of all, is closing this legislative vacuum that we have. And it's a very crucial problem that we have. We're trying to have a digital state, but we have no real data protection law. And we have the Electronic Transactions and Personal Data law that was passed in 2018. But if you take five minutes to go through it, first of all, the personal data section is horribly small and it does not protect Lebanese residents personal data. And it's obsolete and really ineffective. It was drafted in 2004 just for context.
B
Oh my God.
C
Yeah, we need a genuine data protection law with good implementation that provides actual safeguards for personal data, one that specifies what gets collected, how it gets stored, et cetera, all of the checklists, and not with the security, you know, exceptions that just make it hollow. Also, just as a side note, there are a lot of countries around Lebanon, especially in the gcc, that have implemented data protection laws that look practically like the gdpr, but that are actually draconian, that include so many exceptions and loopholes that allow this mass surveillance to flourish. And that's also one of the findings from our report. So first things first. Close the legislative vacuum. We need laws, we need actual laws that get implemented. We need to treat public registries not as open databases, because as you've probably seen, Lebanon's vehicle licensing plate data gets leaked almost annually. The voter registry is published online for everyone to look at. With so much personal data that is publicly put out there, and you don't need to be Israel to hack these public Registries, they are out there, they are just out there for anyone to come and take. So this is also a very, very big problem. We also need to have a cybersecurity strategy. We have one, it's not great. We need a better one and we need it to be actually implemented. SMEX works a lot with the government in. I mean, we try, we try as much as possible to have a positive attitude and try to support their work with whatever capacity we have. And all of our work reveals that most of government platforms lack even the most basic security standards, privacy policies or safeguards to protect residents data. And that's a very big problem that we faced during the COVID 19 pandemic with platforms that were not safe, that were not secure, that did not have privacy policies at least. I mean, we've had some wins with some platforms, but it's not enough. We need to have more transparency on public procurement, on deals with foreign tech companies. I mean, recently one of the ministries signed an MoU, a memorandum of understanding with Oracle. And we need more details about that happen. Exactly, yes. And we need of course, resources to protect civil society. We need to push the platforms and the licensing governments and every agency that is working in Lebanon to actually have the political will to create some change. We know that we are facing an extremely powerful entity, but we cannot just sit and do nothing. We need to do small steps to protect our data. I mean, I know we don't have the capacity to save everything and save ourselves from. Okay, no, maybe let's just cut the political that I'm about to say.
A
I think one of the things that when it comes to personality, that made it really clear and obvious how much cybersecurity is important was the QR code drop where a ton of leaflets with QR codes got dropped all over Lebanon. And the idea was people would scan the QR codes. It's like very kind of bizarre industrial levels of weird phishing. And like we've been talking about don't scan weird QR codes since the COVID pandemic. And all the menus started being QR codes because slap a sticker on top and send someone in a different place. But they're all really basic cybersecurity things that people tell people that people kind of don't take that seriously. But in Lebanon the stakes are so much higher than being scammed and losing your life savings. The stakes are so much scarier. And the very simple, here is a flyer, here is a QR code. Please scan the QR code because data is Such a key aspect of then all of these modern systems that are in use. Whereas in the 90s when data protection law kind of came around last time, the implications of bad data protection were just not in this. Well, I'm guessing because obviously I was terribly, terribly young, which is definitely a dig at Gus. But the implications, which is in a vastly different arena than they are now, in particular in Lebanon, in particular in places in the Swano region. Yeah, we struggle to get people to take basic data protection, cybersecurity seriously and that's with a theoretically protective legal regime.
B
Well, that's why I think our governments are actually being negligent. And this is what I would say, if I dare say about Lebanon. And your point, Marianne, is that the government of Lebanon is being negligent by not ratcheting up privacy and security measures. It is interesting. There's only three countries that I've seen that have taken the same line as I have around privacy as a national security concern. And those three countries are Israel, where I remember when Netanyahu was trying to push a biometric ID in Israel, he recognized that that system they were building was going to be vulnerable and they'd have to make it extraordinarily safe for Israelis so that their data doesn't get leaked. Then the Biden administration started looking at data brokers and saying, hold on, all these companies are accumulating all this so called open data and other data from Americans and selling it to other governments. Isn't that outrageous? Said the Biden administration. And then third, the UK government recently did a consultation again on data brokers and saying there are national security concerns when this data is sold to others, but they don't want to stop the tap for themselves. And this is why I'm a little sympathetic to the Lebanese government and arguably all the governments you mentioned in your report because they want to make sure that they have access and if the price is that their citizens are at risk from foreign governments, I almost think that they're taking the approach like them, you know, we want to be able to control our people. It's too bad that others are going to. But when warfare leads to occupation, then governments are setting their theirselves and their people up for sale and worse.
C
Yeah, I think that also something important for the Lebanese context is that. So as you know, Lebanon has been dealing with crisis after crisis after crisis since its creation. Really. And as I think is the case in many other places around the world, privacy is not seen as very important given all of the other crisis that is ongoing. In the country, for example, on the QR codes, the response from the general security, you know, it was published, it's just that it was a bit late. And also there is not enough awareness around these issues and around privacy and around what a QR code actually can do. And we've actually analyzed the QR codes that were on these leaflets. And leaflets are a very, very old thing that the Israeli occupation does to Lebanon, especially in the south of Lebanon. Every couple of days they'd be like, okay, leaflets. And that's part of their psychological warfare. They're like, okay, we're in the sky above you. And these, these leaflets that had QR codes, when we've analyzed them, one was for a WhatsApp number and another one was for a Facebook page. And interacting with these codes as you know, can expose your phone number, your Facebook account, two Israeli intelligence units, and there was a website. And if you access it, it will immediately identify information about your device, including the type of phone you're using, your screen size, network information, if you're connected to via wi Fi or mobile data, your battery status, the type of browser. And that's just not an extensive list.
B
That's insane. And the duty extends to the phone manufacturers, the phone OS developers, Facebook and its metadata. But again, they don't want to turn off the tops of themselves.
C
No, but one thing that SMEX has done is basically try to do some awareness around this. And we've really, really worked on awareness during the past war. I mean, it's ongoing, so it's still this current war. The SMACS team has done really amazing work. I mean, I am not based in Lebanon, but the SMEX team has done really amazing work on the SMEX digital safety help desk in supporting people who had actually scanned this QR code. And also with in person trainings to anyone, really. We've done so many trainings about digital security in Lebanon during the war and how to protect yourself during the war. And this feels like this shouldn't be civil society's job, but at least there is civil society that is able to do that. Unlike other countries where the civic space is really, really, really closed, we are still able to do things like that.
B
Yeah. So nobody's doing this in Egypt. Right? There's no civil society able to do this kind of essential work that first of all the state should be doing. But fortunately SMEX is doing.
A
I bet there are Egyptian organizations giving it the best.
C
Actually there are. We should all just learn from Egyptian civil society. They are amazing and they are relentless.
B
Yeah, I'm sorry, you're right. I didn't mean to disrespect. Civil societies mean the Egyptian government crushes civil societies. Like we've worked with Egyptian civil society and they are extraordinary, but they're working under such duress.
A
The context is really hard.
C
Yes, yes. They have so many things to face and they are at risk of literally being jailed the whole time. But yeah, I mean, we still have some space to work with in Lebanon and SMEX has really done so much during the war, but it's been a really big lesson on how much you can actually achieve.
A
I wanted to ask. It's a little bit of a topic leap, but like you mentioned UAE and Saudi and kind of the trends in UAE and Saudi becoming more building their own. Both have had quite large smart city programs and I wondered how much they have been development and staging areas for the new surveillance technologies that they've been starting to develop because they haven't really worked. How much they've been kind of more of a separate sideshow.
C
So actually the smart cities, or we like to call them surveillance cities, I
A
think taking away the implication that they're smart is good because they're mostly really not. Yeah.
C
It is actually something we've covered in the report. When we're talking about UAE, we've just covered one example which is the OurYoun program. Aryun in Arabic means the eyes. So it's literally called eyes. I mean, so we've detailed this example because in Dubai alone There are around 300,000 cameras integrated with AI powered facial recognition and behavioral analytics through the Aryun program. And this is one of the most extensive urban surveillance networks in the world. And it was announced in 2016, I think it was operational shortly after. As you've said it, it's framed as a smart policing initiative designed to reduce crime, accelerate emergency response, all of the, you know, national security stuff. But it actually integrates biometric identification, movement tracking, behavioral pattern analysis across a city that has 3.54 million people. And this example, we've used this example because it really exemplifies the smart city to surveillance pipeline. And it's basically an urban surveillance infrastructure that is marketed as a hallmark of technology modernity, but it's actually creating a comprehensive monitoring and surveillance system whose capabilities are very identical to the capabilities of a purpose built intelligence surveillance system. And there is to our knowledge no actual framework governing the audience program, data retention or access policies or limitations on use. And if there is even the idea of an oversight body, I don't know, so like, we have this, okay, it's not perfect, but it's there in EU countries, for example, you can go, you can ask, you can ask for what data do you have on me? It doesn't exist in this part of the world. And this is really part of a very long trend of the normalization of surveillance in the region. And this normalization, I mean, I'm going to say surveillance is not new to the region, it's not new to the Swana region, it's not new to the world. And the technology did not invent this, it just industrialized it in a way. And this is one of the most dangerous consequences of the militarization of tech. Because what feeds this militarization of tech, it's the constant surveillance and mass surveillance of people. And it's years and years of data being collected in the west bank, in Gaza, in everywhere in the region that is being weaponized right now. And these systems lavender the gospel. The, you know, if I made what we're seeing mostly in the press, they're not just like, okay, I'm going to create an AI assisted targeting system. It's just feeding on years and years of data collected by these intrusive surveillance systems. It's being stalked, it's being worked on, if I may say, on these civilian infrastructure, on clouds, on AI. And then we get the final product which is built, operated and tested in the Swana region. And that is the full loop of the militarization of tech that I was talking about at the beginning. It's that the Swana region really closes this loop because from conception, if I can say, until it is operational and until it is marketed, it's all happening in the region with assistance of international, mostly US tech companies, EU companies, other Western companies. This is all happening in this region. It has repercussions everywhere around the world. And that is one thing that the Militarization of Tech project by Privacy International has showed us, is that I thought that this was happening solely in the Swana region, but it's actually happening all around the world. And seeing, for example, how much Israeli tech impacts in Mexico, in other parts of the world, it really shows you how important it is to look at the militarization of tech as a phenomenon, as something that's happening as a danger to international human rights law and international humanitarian law.
B
Yes, Marianne, that's perfect.
A
It is kind of perfect.
B
I really want to explore this, this point about privacy as a national security thing, because when you were talking about the UAE system and in light of the fact that we know the Israelis hacked Tehran's CCTV network and were able to monitor for months what was going on, to decide when they were going to do the initial attack. Again, it's insane to me that governments would set up these systems that just open people up. But as you say, it's because they get a loop. They don't really care. They want the data to build the system so the system can scale and they get the benefits of the security that they want. But to get to sell it elsewhere. Oh, somebody should do something about this, you know, thank God you are. You too.
C
And I think, yeah, you know, the main thing from this research is that it's not one single actor, it's not one single decision, it's not one single company. That is the problem. It's a whole set of mutually reinforcing relationships between states, companies, export regimes, legal frameworks and investors together make this. This militarization of tech profitable and therefore politically normalized and therefore largely unaccountable. And that's the loop that we are in. And we were trying to, you know, build a set of recommendations at the end of the report, and I was like, where do we even start?
A
It must be quite difficult to talk about international legal accountability in a context in which even existing laws are not exactly working as you would want them to work. I think it's fair, as somewhat an
B
understatement, to say to somebody from Lebanon. Yeah,
A
yeah.
B
Marianne, thanks so much for your time. We really appreciate it.
C
Thank you. It was lovely. No, let's not say. Let's not say it was lovely. It was not lovely.
B
Well, look, we talk about the worst.
A
Interesting.
B
Yeah. We talk about horror, horrible things. And if we can't smile and enjoy each other's company along the way, then it's just not worth it, you know?
C
Indeed.
A
Just never get out of bed.
B
Yeah, exactly. Yeah.
C
Thank you, PI.
A
Thank you.
B
Stay cool. Thanks for listening. You can sign up to be the first to learn more about our work@pvcy.org podsignup and we'll include some links to relevant articles and information in the description, wherever you're listening or on our website@pvcy.org techpill and of course, we'll also include links to the SMEX report. Don't forget to rate and subscribe to the podcast on whichever platform you use. Music is courtesy of Sepia. This podcast was produced by Max Brunel for Browse International.
Podcast by Privacy International
Episode Date: August 7, 2026
Host(s): Gus Hossein & Caitlin Bishop
Guest: Marianne Rameh (SMEX, MENA Alliance for Digital Rights)
In this episode, Privacy International interviews Marianne Rameh, senior coalitions and research lead at SMEX and coordinator of the MENA Alliance for Digital Rights, about SMEX's new report: "Produced, Tested, Deployed: The Militarisation of Technology in the SWANA (Southwest Asia and North Africa) region." The discussion dives into how regional governments are adopting, producing, and exporting militarised technology, how civilian and military applications blur, and the profound human rights challenges this brings. The episode emphasizes the SWANA region’s role as production hub, consumer market, and live testing ground for surveillance and AI-driven warfare, sounding a warning about the global implications of unchecked tech militarisation.
Focus has shifted from just military hardware to data – who collects, processes, and wields it.
Blurring between civilian and military uses is now one of the defining rights challenges of our time.
SWANA region acts as:
Quote [05:40] Marianne: "The systematic blurring between civilian and military tools is one of the most defining human rights challenges of our time..."
The episode underscores that the militarisation of technology in SWANA is not an isolated problem. The region serves as both the Petri dish and the springboard for global trends in surveillance, data-driven warfare, and unchecked tech power. The normalization and export of these technologies represent a growing global threat—enabled by profit motives, regulatory loopholes, and insufficient political will. Civil society’s tenacity is a thin but critical line of defense, but structural change is urgently needed at both national and international levels.
Recommended Action: