Governance · 5 min read · Updated 2026-10-06
A dismissed spyware case and the audit trail nobody could produce
A California judge threw out a Pegasus spyware case brought by El Faro's journalists on jurisdiction, not on the facts. The infections were real; the record of who ordered them was not. That gap is a governance failure any regulated enterprise can inherit.
On 2 October 2026 a federal judge in California dismissed a lawsuit brought by journalists at El Faro, the independent Salvadoran news outlet, against NSO Group, the maker of the Pegasus spyware (The Record, 2 October 2026). The judge did not rule that the hacking did not happen. The order found the court lacked jurisdiction, calling the case "entirely foreign" despite the plaintiffs' argument that compromised infrastructure inside California had helped carry out the attacks (The Record, 2 October 2026).
What happened
The plaintiffs, led by El Faro co-founder Carlos Dada, had their devices infected with Pegasus at least 226 times between June 2020 and November 2021, with attacks intensifying ahead of the outlet's major investigations (The Record, 2 October 2026). The Knight First Amendment Institute filed the suit in November 2022, the first US case against NSO Group. It asked the court to order deletion of the data Pegasus had collected and to force NSO to identify the client who had ordered the surveillance. Neither request was reached, because a March 2024 ruling had already rejected the case on the same jurisdictional ground, and this second attempt failed the same test (The Record, 2 October 2026). The Knight Institute says it intends to appeal.
Strip away the law and one fact stands out: the infections are not contested. What collapsed was the ability to compel an answer to the only question that matters afterwards: who ordered this, and what did they take.
Why this is not an isolated case
El Faro is one outlet in one country, but the pattern around it is large and documented.
The Pegasus Project, run by the Forbidden Stories consortium with Amnesty International and media partners across nine countries, examined a leaked list of more than 50,000 phone numbers selected for surveillance by NSO Group's clients, and found at least 180 journalists worldwide among the selected targets, with NSO clients operating in more than 50 countries since 2016 (Forbidden Stories, Pegasus Project).
Apple has been issuing threat notifications to users it believes were targeted by mercenary spyware since 2021, and says it has now sent them to people in more than 150 countries, while declining to disclose the detection logic itself, to avoid helping attackers adapt (Apple Support, accessed 2026).
Both data points describe the same structural fact as the El Faro case: spyware vendors and their government clients operate across borders by design, which is precisely what makes their conduct hard to pin down in any single court, and hard for a victim to evidence without a record the vendor controls.
What it means for a regulated enterprise
Most organisations reading this will never be an NSO Group client or a spyware target. The exposure is adjacent, not identical: it is what happens when your own ability to answer "who did what, to what, and when" depends on records a court, a regulator or an auditor cannot compel, or that were never kept in a form anyone can produce.
The El Faro case failed on jurisdiction before it reached the merits, which means the question of what NSO's client actually did with the data was never tested in open court. Translate that into enterprise terms: if your AI agents, integrations or vendor platforms act on your data and the only record of what happened sits inside a third party's infrastructure, in a jurisdiction and format you do not control, you are in the plaintiffs' position before you have a dispute. Under the EU AI Act's record-keeping obligations, and under NIS2's expectation that management can account for risk decisions, "we believe nothing improper happened" is not the same statement as "here is the log." A regulator, like the California court, will ask for standing before it asks for the story, and standing in a data-governance sense means your own evidence, not an assurance from the party you'd need to challenge.
What actually addresses it
The mechanism that closes this gap is not a better contract clause with a vendor. It is keeping the record of what an AI system or agent did inside infrastructure you control, written at the moment the action happens, not reconstructed afterwards from a third party's cooperation.
That means three things working together: the system of record for an action sits on infrastructure you operate or can compel directly, not solely inside a vendor's cloud; the record is written as the action happens, so there is nothing to lose if the vendor relationship later turns adversarial; and the record cannot be edited after the fact, so a dispute does not come down to whose account is believed.
What to check on Monday
Pick one AI tool, agent or integration your organisation already runs against customer or employee data, and ask a single question: if a regulator, a court or an affected person demanded to know exactly what that system did last month, who accessed what and when, could you produce that record from your own systems within a day, without asking the vendor for help? If the honest answer involves "we'd have to ask them," you have found your own version of the gap that just cost El Faro's journalists their case.
Related guides
Compliance
The EU AI Act Article 12 readiness guide
What record-keeping and human-oversight obligations actually require operationally from August 2026 — and the evidence an auditor will ask you to produce.
9 min read
Read the guide →Risk
The credentials nobody reviews
Your AI agents hold OAuth tokens, API keys and service accounts that went through no approval process. The agent was reviewed. The studio was reviewed. The identity behind them was not.
5 min read
Read the guide →Security
When the agents organised themselves: what the Hugging Face swarm means for accountability
Roughly 700 AI agents divided labour, traded favours and compromised production infrastructure across four regions. The uncomfortable part is not that it happened — it is that the account of what happened had to be reconstructed afterwards, by outside parties.
6 min read
Read the analysis →