Who Watches Human Rights Defenders? Surveillance, AI and Digital Power

By Javier Surasky

Versión en español

Faceless official moving a surveillance camera like a chess piece over citizens, with UN buildings, government symbols, and digital monitoring screens in the background.

Who Watches Those Who Keep Watch on Power?

A new OHCHR report presented to the 63rd session of the UN Human Rights Council, Protecting Human Rights Defenders in the Digital Age (A/HRC/63/52), warns that surveillance technologies, digital platforms, and artificial intelligence are expanding the capacity of States and companies to monitor, classify, and target human rights defenders faster than safeguards and oversight mechanisms are developing. The report matters not only because it documents new digital risks, but because it exposes a broader shift in the distribution of power.

Its content can be summed up in one sentence: the expansion of State and corporate power over digital spaces has not been matched by equivalent safeguards, accountability mechanisms, and oversight systems. Digital protection is advancing, but digital power is advancing faster.

For this reason, reading the new OHCHR report as just another assessment of surveillance, censorship, spyware, and risks associated with artificial intelligence would be superficial: the document, presented to the 63rd session of the Human Rights Council, contains a deeper warning that we might translate as follows: “as the capacities of States and companies to observe, identify, classify, and intervene in people’s lives increase, the institutions meant to control that power are gradually being left without the tools they need to perform their functions.”

The problem described by the report is, therefore, a problem of power more than a technical issue.

I recognize, as the report does, that digitalization has expanded the possibilities available to those who defend human rights through digital technologies that allow them to gain visibility, carry out advocacy, build networks and, under certain circumstances, enhance their own management of protection.

That progress is real, as are certain legal and institutional advances highlighted by the report itself: the establishment of comprehensive data protection frameworks, independent oversight authorities, and judicial decisions aimed at protecting privacy, among others.

The report also makes a first point: regulation and human rights are not necessarily opposing objectives. Public policies that respond to legitimate security concerns without eroding the freedoms they are meant to protect are already part of our systems of social organization.

Companies have also taken some measures, such as creating mechanisms to address risks affecting human rights defenders, and some companies publish reports on their relationship with public authorities.

At the international level, the European Union and the United States issued joint recommendations for platforms in 2024 and, one year later, UNESCO and OHCHR published guidance aimed at strengthening the protection of critical voices in the context of digital technologies. At the regional level, the Inter-American Court of Human Rights recognized the right to defend human rights as an autonomous right that can be exercised both online and outside the digital sphere.

The report also highlights new forms of human rights advocacy emerging among programmers, engineers, and senior managers at leading digital companies.

Digitalizing Also Means Concentrating Power

For years, the debate on human rights and technology has revolved around how to prevent new technologies from violating existing rights. Today, we must add a second part: what redistribution of political capacities capable of affecting human rights is produced by digitalization.

A State with access to interoperable databases, biometric recognition, interception tools, automated analysis, and artificial intelligence systems possesses capacities for observing and classifying the population that, just two decades ago, would have been difficult to deploy on a massive scale.

Today, artificial intelligence changes that equation, and among the reasons for this shift the report points to the drastic reduction in the cost of data analysis and inference, the ease with which data can be deanonymized, and the growing sophistication of surveillance and interception technologies.

At Global Radar Analaytics, we have examined various issues related to AI, and each of them presents us with its own paradoxes. This case is no exception: the more digitalized civic space becomes, the greater the capacity to participate in it may be, but also the capacity to surveil and persecute its participants.

And there is a second related issue: more digital regulation does not necessarily mean greater protection of rights, since States, generally speaking, have shown themselves to be more concerned with combating cybercrime, protecting children, confronting terrorism, prosecuting crimes, or limiting certain forms of online violence, in the process producing imprecise regulation, broad executive powers, and surveillance systems without sufficient oversight.

OHCHR itself maintains that State regulatory responses have ultimately reduced protection for defenders through, for example, excessively broad criminalization of online conduct, interference with communications, and restrictions on access to certain digital tools.

In this sense, the report forces us to rethink the notion that digital governance consists of finding the right amount of regulation, because it tells us that it is far more relevant to ask who is granted new powers, subject to what limits, under what oversight, and with what real possibilities of recourse for those potentially affected.

The tension that, at first glance, appears to lie between prioritizing security and ensuring the full exercise of rights must become a less linear question: what institutional architecture makes it possible to pursue legitimate objectives without turning the exception into a permanent capacity for control?

Companies

The report is critical of both States and the corporate sector, offering an especially severe diagnosis of the latter when it recognizes that some companies have developed special channels for defenders, published transparency reports, identified spyware threats, strengthened security measures, and even initiated legal action against spyware developers, while at the same time reducing their “trust and safety” teams and staff, modifying moderation systems, eliminating verification mechanisms, and delaying transparency.

Faced with this, OHCHR’s conclusion is clear: corporate human rights due diligence remains the exception, in a context where economic incentives continue to favor data extraction and growth over individual security.

But even knowing this, human rights defenders cannot abandon major technological infrastructures because they need cloud services, search engines, phones, messaging, and platforms to carry out their work: as at many other points in history, the persecuted depend on the persecutor to carry out their work, a digitalization of Hegel’s master-slave dialectic in which talk of “user choice” is becoming increasingly unconvincing.

The Need to Move from Defensive Advances to Structural Transformations.

Many of these responses to the persecution of human rights defenders emerge, as often happens in the field of AI, only after a vulnerability has been exploited, an abuse discovered, or a dangerous technology widely commercialized. This leads to the recommendation in the OHCHR report that I consider most important: the protection of human rights cannot continue to function solely as an after-the-fact correction of technological decisions that have already been made.

And it is at this point that we find the main challenge the report leaves open: it contains ambitious recommendations, but it has also identified the power they confront—power arising from economic concentration, corporate incentives based on data extraction, State surveillance capacities, and society’s growing dependence on private infrastructures.

Regulating abuses will be insufficient if the structures that made them possible are not addressed, because for every abuse remedied, for every human rights defender who manages to secure protection, dozens of new abuses and acts of persecution will be generated by a structural order.

Persecution and abuses are not “system errors,” but part of its logic, some of its “normal accidents.”

For this reason, the indicator proposed by the report itself regarding the way a society treats, in the digital realm, those who challenge power may be useful not only for assessing whether its digitalization is contributing to democratization, as OHCHR proposes, but also for determining whether fundamental changes are taking place in the social order under the guidance of human rights.

A society can be extraordinarily digital and increasingly closed, or have extensive AI legislation that fails to alter the structural patterns through which its real threats spread.

If that happens, the problem will not be that our digital transformation has failed, but that it will have succeeded in distributing power in the wrong direction, and that, in my view, is the most important warning to emerge from the report.