top of page

Regulating Dual-Use Technologies: The Effectiveness of EU Export Controls and Human Rights Sanctions

11 minutes ago
8 min read

The rise of dual-use technologies, including spyware, artificial intelligence, and cyber-surveillance tools, created new opportunities for human rights violations within and beyond the European Union (EU). These technologies are particularly challenging to regulate because, while designed for legitimate civilian purposes, they can also be used by repressive regimes and terrorists to enable surveillance, repression, and other violations of fundamental human rights. This raises an important question: to what extent are EU export controls and restrictive measures effective instruments for preventing technology-related human rights violations? The EU has attempted to address these risks through Regulation (EU) 2021/821, which establishes a framework for controlling exports of dual-use items, and the EU Global Human Rights Sanctions Regime, which enables restrictive measures such as sanctions against entities responsible for human rights violations. Together, these instruments have strengthened human rights protection within the EU’s regulatory and foreign policy framework. However, their effectiveness remains limited by the rapid development of emerging technologies, fragmented enforcement across Member States, reliance on private actors to identify illegal transfers, and the risk of circumvention. Overall, although the EU has created a strong legal framework to address technology-related human rights violations, several challenges remain in implementing these protections in practice.


The original EU dual-use regulation, Regulation 428/2009, primarily focused on preventing the spread of weapons of mass destruction and controlling the exports of military-related dual-use goods. It relied on international export control regimes, such as the Wassenaar Arrangement, to determine which technologies required export licences. At the time, cyber-surveillance technologies such as intrusive software were absent from international control lists. Many European surveillance technologies that were developed after this regulation were not monitored and could legally be exported even when there was evidence that they were being used to violate human rights. For example, in the early 2010s, numerous investigations led to the discovery of European-made surveillance technologies exported to governments such as Egypt, Bahrain, Ethiopia, Myanmar, and the United Arab Emirates, where they were allegedly used for repression and torture. In 2016, the European Commission proposed a new revision of the Regulation, which recognised that exports of cyber-surveillance technology could severely threaten privacy, freedom of expression, freedom of association, and the right to life. After negotiations between the Commission, Parliament, and the European Council, Regulation 2021/821 entered into force on 9 September 2021.


            One of the most significant innovations of the new Regulation was its shift from a primarily security-based approach to a focus on human security. The recast recognises that dual-use technologies can threaten individuals’ fundamental rights even when they do not pose a threat to national security. Accordingly, it expands the objectives of export controls to recognise that certain technologies may be used to facilitate human rights violations. This is particularly visible in the relationship between Annex I and Article 5. Annex I contains the EU’s list of specific dual-use items that are subject to export controls. However, technological dual-use developments can occur faster than these control lists can be updated. Article 5 addresses this problem by introducing a new ‘catch-all’ clause for certain cyber-surveillance items that are not included in Annex I. Under Article 5, an export licence may be required where the exporter is aware that a non-listed cyber-surveillance item may be used to violate human rights. This represents an important change from the previous Regulation, as it allows the EU to respond to emerging dangerous technologies even when they have not yet been added to the list of controlled items. In practice, this could be applied to technologies such as facial-recognition systems, biometric analysis tools, and location-tracking systems. As the Stockholm International Peace Research Institute attests, the introduction of Article 5 also places greater responsibility on exporters. Instead of relying on national authorities to identify risks, companies are expected to conduct due diligence and consider the end user and intended use of their products. Finally, they must notify authorities when they become aware that a non-listed cyber-surveillance item may be used for human rights violations. The Regulation therefore incorporates human rights considerations in its recitals and into its substantive provisions, portraying a shift towards including human security into the EU’s export-control system.


            Regulation 2021/821 goes hand in hand with the EU Global Human Rights Sanctions Regime, which was established through two legal instruments: Council Decision (CFSP) 2020/1999 and Council Regulation (EU) 2020/1998, both entering into force on the 7 December 2020. It is commonly referred to as the ‘EU Magnitsky Act’ because it follows the model first introduced by the United States in 2012 after the death of the Russian lawyer Sergei Magnitsky. Together, these instruments created a mechanism that allows the EU to impose targeted sanctions on entities responsible for human rights violations. The sanctions are adopted through a legal process that consists of two steps. Firstly, under Article 29 TEU, the Council adopts a decision establishing the restrictive measures as part of the EU’s Common Foreign and Security Policy (CFSP). This decision identifies the individuals targeted by sanctions and determines which restrictive measures apply to them. Secondly, if the measures are decided to be financial restrictions, Article 215 TFEU guides the implementation of the Council’s decision through Regulation 2020/1998. This is directly binding throughout the EU and requires Member States, individuals, and companies to comply with the sanctions. The measures can include asset freezes and prohibitions on making economic resources available to specific entities. The regime applies to international crimes, including genocide, crimes against humanity, torture, and slavery.


            These new legal measures are becoming increasingly important as the expanding market for cyber-surveillance technologies changes the relationship between export controls and human rights protection. Modern surveillance software can be used against civilians, journalists, and political opponents, making export controls a fundamental mechanism for preventing this technology from being abused. Human Rights Watch argues that commercial spyware and other surveillance technologies are increasingly used by governments to restrict fundamental freedoms. Moreover, a significant proportion of these technologies are exported from EU Member States, many of which contain surveillance technology companies that can facilitate repression beyond the EU.


            The Pegasus spyware developed by the Israeli company NSO Group provides one of the clearest examples of why surveillance exports have become an important issue in EU human rights debates. Pegasus allows operators to infiltrate smartphones without the user’s knowledge and gain access to private files, microphones, and location data. Since the Pegasus Project revelations, spyware has reportedly been used in more than 46 countries, including EU Member States, to target journalists and political opponents. The European Parliament’s PEGA Committee, established in response to these revelations, found that NSO Group had sold Pegasus to at least 14 EU Member States through 22 governmental end-users.


            Emerging AI technologies further complicate the regulation of dual-use items because the same AI systems can have both civilian and military applications. Export controls are also becoming more difficult to enforce because AI technologies can be transferred electronically rather than through physical exports, making it harder for authorities to control their movement. Consequently, determining whether a technology presents a human rights risk depends not on the characteristics of the technology, but rather on its end use, end user, and destination country.


            The 2021 Regulation seeks to address these challenges primarily through Annex I and Article 5. As discussed above, Annex I provides the list of controlled dual-use items, while Article 5 allows the EU to address certain non-listed cyber-surveillance items when there is a risk of serious human rights violations. The Commission’s guidance also recognises the importance of emerging technologies, including facial-recognition systems and other AI-based surveillance tools. Export controls and restrictive measures both aim to protect human rights, but they do so at different stages. Export controls are mainly ex ante measures because they seek to prevent potentially harmful technologies from being transferred before they can be used for human rights violations. Restrictive measures, on the other hand, are mainly ex post measures, as they are imposed after human rights violations have occurred and are used to target the individuals responsible. In this sense, the two mechanisms complement each other: export controls focus on preventing the misuse of technology, while restrictive measures respond when such violations have already happened. However, as the examples of Pegasus and emerging AI technologies show, the effectiveness of both mechanisms depends on how consistently they are implemented and enforced in practice.


The difference between these two instruments can be seen in the EU’s sanctions against Iran adopted in October 2022, following the death of Mahsa Amini and the violent suppression of nationwide protests. While export controls aim to prevent technologies from being transferred for illegal purposes, restrictive measures were used to respond to human rights violations. The EU sanctioned 11 individuals and four entities, including Iran’s Morality Police, senior law enforcement officials, and the Minister of Information and Communications Technology for his role in internet shutdowns during the protests. The measures mainly consisted of travel bans and asset freezes. The Iranian case clearly shows how EU sanctions can be used to target those responsible for technology-enabled repression.

Despite these developments, the EU framework has several important weaknesses. The first is that technological development is often faster than the legal framework used to regulate it. AI and cyber-surveillance technologies are constantly changing, making it difficult for export controls to keep pace with new forms of technology. Although Article 5 aims to control certain non-listed cyber-surveillance items, its effectiveness depends on exporters being able to conduct due diligence. This becomes difficult when technologies have both commercial uses and the potential to violate human rights. The uncertainty is reflected in the limited practical use of Article 5. According to interviews conducted by the Centre for Democracy and Technology Europe, there have been no reported cases in which Member States formally notified exporters that authorisation was required under Article 5’s cyber-surveillance catch-all mechanism. This shows that the EU framework often reacts to risks instead of preventing them.

The second weakness is the fragmented enforcement of EU rules. Although Regulation 2021/821 applies across all Member States, export controls are enforced mainly by national authorities rather than by a central EU body. Export licence applications are assessed by different authorities across the 27 Member States, which can lead to differences in how the same laws are interpreted and applied. Research by the Centre for Democracy and Technology Europe also found several differences between Member States in reporting licensing data and human rights assessments. Similarly, although sanctions are adopted at the Union level, responsibility for implementing and enforcing them remains primarily with the Member States. National authorities are responsible for identifying frozen assets and supervising compliance under domestic law. In fact, as the European Times states, asset freezes are only effective if national authorities can successfully identify and freeze assets controlled by designated individuals. Financial institutions and other private actors also play an important role in ensuring compliance, as they are the primary actors responsible for implementing sanctions and must continuously update sanctions screening systems. While involving private actors can strengthen enforcement, it also creates differences in how sanctions are applied across the EU, weakening its approach in defence of human security.


The third weakness is the difficulty of preventing circumvention. Sanctioned individuals can attempt to hide assets through family members, subsidiaries, nominee shareholders, or other intermediaries, while cryptocurrencies can make it easier to move assets across borders. These challenges mean that having a legal prohibition does not ensure that it will be effective in practice. In addition, the requirement for unanimity when adopting CFSP sanctions under Article 29 TEU can make it difficult for the EU to respond quickly and consistently to human rights violations. Therefore, while the EU has developed a strong legal framework, its effectiveness is limited by the speed of technological change, fragmented enforcement, and the continuing possibility of circumvention.


            Several reforms could address these issues. The effectiveness of EU export controls and sanctions ultimately depends on international cooperation. The EU should therefore continue strengthening its ties with partners participating in multilateral export control regimes, particularly the Wassenaar Arrangement. Greater transatlantic coordination between the European Union, the United States, the United Kingdom, Canada, Japan, and South Korea would also promote positive change. Moreover, stronger cooperation would make export controls and sanctions more effective by reducing differences between state interpretations and preventing companies from circumventing restrictions through third countries. Exporters should also be required to submit regular reports demonstrating that exported technologies continue to be used consistently with the legal conditions under which export licences were granted. The EU should also introduce more innovative mechanisms for updating export control lists, allowing new technologies to be reviewed more rapidly, such as through regular updating of Annex I.

EU export controls and restrictive measures should consequently be understood as important but incomplete tools of human rights protection. Their legal significance lies in the EU’s recognition that technologies developed for legitimate civilian purposes can also become instruments of serious human rights violations. Ultimately, their effectiveness will depend on whether the EU can turn these laws into effective enforcement that keeps up with rapid technological change.

 

 



bottom of page