Spyware, AI and the New Battlefield: Predator, Intellexa and the Infrastructure of Power

Share
Spyware, AI and the New Battlefield: Predator, Intellexa and the Infrastructure of Power

The Global Market of Leverage Predator, Cyber Ecosystems, and the Structural Transformation of Informational Powe

Feb 27, 2026

The ruling issued on February 26, 2026, by a Greek court against four individuals linked to the Intellexa consortium marks a significant judicial milestone in what has become known as “Predatorgate.” Among those convicted is Tal Dilian, a former Israeli military intelligence officer and founder of Intellexa, alongside other executives involved in the commercialization of the Predator spyware. The combined sentences exceed one hundred years of imprisonment, although the actual time to be served is considerably shorter.

On the criminal level, individual responsibilities have been established: illegal access to information systems, violation of communication secrecy, and repeated manipulation of personal data.

But the issue does not end in the courtroom.

Predator is not merely software. It is an architecture of invisible access. And in the twenty-first century, invisible access to personal devices is a form of power.

To understand the magnitude of this phenomenon, one must begin with the technical layer. New-generation spyware such as Predator—or those developed by NSO Group—does not operate like traditional wiretapping systems. These tools rely on advanced exploit chains, sometimes zero-click vulnerabilities, enabling infection of a smartphone without any action by the user. Once compromised, the software gains system-level privileges: it can access messages, emails, files, images, authentication tokens, browsing history, contacts, and GPS location data.

It can remotely activate microphones and cameras. It can read encrypted communications from applications such as Signal or WhatsApp by extracting data before encryption or after decryption on the device itself. It can reconstruct relational networks and behavioral patterns.

This is no longer simple interception. It is the transformation of a phone into a permanent sensor.

Capabilities that until recently were the near-exclusive domain of highly specialized state intelligence agencies are now marketed by private companies.

The offensive cybersecurity industry has developed within hybrid ecosystems where military expertise, technological research, and venture capital converge. Israel represents one of the world’s most concentrated hubs in this sector. Unit 8200 of Israeli military intelligence has trained generations of specialists who, after leaving service, founded startups in cybersecurity, data analytics, and dual-use technologies.

Companies such as NSO Group and the Intellexa consortium operate within this broader context. Their products are subject to export licensing regimes authorized by Israeli defense authorities. This does not prove that the state directs every operation. It does, however, demonstrate that these tools are not ordinary software—they are technologies classified as sensitive and strategic.

When a European state acquires digital intrusion tools from a foreign supplier operating within a highly integrated military-technological ecosystem, the relationship is not merely commercial. It is technological and geopolitical.

In recent years, several countries have initiated internal audits concerning the use of foreign-origin surveillance tools. The European Parliament established the PEGA Committee of Inquiry to examine the use of Pegasus and equivalent spyware within EU Member States, recommending stronger transparency measures, reinforced judicial oversight, and independent technical verification.

In the United States, the Department of Commerce placed entities linked to the spyware market on its Entity List, restricting access to American technological components on national security grounds.

These developments are not isolated episodes. They signal a broader recognition: informational leverage has become strategic infrastructure.

Yet leverage does not originate with code.

The case of Jeffrey Epstein remains, in judicial terms, an individual criminal matter. Structurally, however, it revealed how cross-sector access to political leaders, financial elites, academic institutions, and philanthropic networks can generate informational asymmetry. Epstein’s proximity to heads of state, major investors, university presidents, and global foundations illustrates how accumulated high-density relationships create potential vulnerability. One does not need to prove state coordination to understand that concentrated social proximity produces latent leverage.

In contemporary systems, asymmetry is already power.

Within this broader context, the figure of Isabel Maxwell—sister of Ghislaine Maxwell—also deserves structural consideration. Unlike her sister, who was prosecuted in U.S. federal court, Isabel Maxwell built a career in the technology sector. She served as CEO of Commtouch, an Israeli-based company specializing in email security.

To grasp the significance of this role, it is important to recall that in the late 1990s and early 2000s, email was the primary vector for cyber intrusion: phishing, malware distribution, credential theft, and mass spam campaigns all moved through email infrastructure. Companies like Commtouch developed large-scale filtering, authentication, and behavioral analysis systems capable of scanning vast volumes of global email traffic in real time, identifying malicious patterns and botnet activity.

Following the September 11, 2001 attacks, digital communication security increasingly became embedded within national security frameworks. Email filtering systems, traffic analysis engines, and anomaly detection platforms became part of the broader architecture of digital risk mitigation.

Isabel Maxwell later participated in entrepreneurial networks and innovation initiatives, including programs associated with the World Economic Forum. These facts do not establish covert coordination. They do illustrate how technological entrepreneurship, venture capital ecosystems, and multilateral governance platforms frequently intersect within the same transnational circuits.

The relevance is systemic, not personal.

In the twenty-first century, power is exercised not only through armies or treaties, but through digital infrastructures: authentication systems, communication layers, cloud platforms, surveillance tools.

When such infrastructures are concentrated within ecosystems deeply integrated between military and private sectors, the issue is not conspiracy. It is concentration of capability.

Recent leadership resignations within the World Economic Forum highlighted another dimension of contemporary vulnerability: reputational exposure. In a permanent, retroactive information environment, relationships themselves become geopolitical variables. Public scrutiny—even in the absence of criminal findings—can affect the legitimacy of multilateral platforms.

In an increasingly multipolar world, digital sovereignty has become central to national security doctrine. Reviewing, suspending, or auditing contracts involving foreign cyber tools is no longer merely technical or administrative. It is strategic.

Contemporary power is networked. It flows through technology firms, investment funds, digital infrastructures, and export licensing regimes.

Democracies were designed to oversee visible hierarchies. They are far less equipped to govern transnational hybrid ecosystems in which state-grade intelligence capabilities are developed and sold by private actors.

Prosecuting individuals is necessary. But if the architecture remains intact, vulnerability persists.

Predator demonstrates the technical feasibility of transforming personal devices into total surveillance nodes. The Israeli cyber ecosystem demonstrates how military expertise can evolve into globally competitive industry. European audits and U.S. restrictions demonstrate that states increasingly recognize these tools as strategic assets.

Informational leverage has become infrastructure.

And when infrastructure is private, transnational, and concentrated in a limited number of high-density technological hubs, vulnerability is not an accident. It is a structural feature of the system.

The question is not who controls the world.

The question is whether democracies can adapt their oversight mechanisms to this new form of informational power before asymmetries become irreversible.

If in the Predator case leverage operates through compromised devices, in the case of artificial intelligence leverage operates through generative models capable of large-scale analysis, prediction, and automation. The emerging tension between Anthropic and the U.S. Department of Defense indicates that the battlefield is already shifting.

As this article was being finalized, another front in the same structural conflict emerged in the United States. The artificial intelligence company Anthropic reportedly rejected a Department of Defense offer worth approximately $200 million, setting two non-negotiable conditions: no use for mass surveillance of American citizens and no deployment in fully autonomous weapons systems without meaningful human oversight.

The technology that yesterday allowed a smartphone to become a surveillance instrument can today be integrated into systems capable of strategic analysis, decision-support automation, and operational planning.

The terrain is shifting.

If Predator represents the leverage of invisible access, artificial intelligence represents the leverage of large-scale processing and automated decision capability.

The next frontier is no longer only about who can listen.

It is about who can decide.

We will return to this.

Sources

  • European Parliament – PEGA Committee Final Report (2023)
    Inquiry into the use of Pegasus and equivalent surveillance spyware in EU Member States.
    (Official EU institutional source on spyware governance.)
  • U.S. Department of Commerce – Bureau of Industry and Security (Entity List Updates, 2023–2024)
    Sanctions and export controls applied to commercial spyware firms including Intellexa-linked entities.
    (Primary source on U.S. regulatory response.)
  • Citizen Lab (University of Toronto)
    Technical analyses of Predator, Pegasus, and commercial spyware infections.
    (Independent forensic research authority.)
  • Amnesty International – Security Lab Reports
    Investigations into spyware deployment and human rights implications.
    (Technical + rights-based documentation.)
  • Reuters Investigations (2022–2026 coverage)
    Reporting on Intellexa, spyware export restrictions, and regulatory actions across multiple jurisdictions.
    (Mainstream international wire verification.)
  • U.S. Federal Court Records – United States v. Ghislaine Maxwell (SDNY filings)
    Official judicial documentation related to the Epstein-Maxwell case.
    (Primary legal documentation reference.)