A Watchdog Becomes the Target
On July 3, 2026, Citizen Lab published forensic findings that Stelios Kouloglou — a Greek journalist and former MEP who sat as a substitute member of the European Parliament's Committee of Inquiry on Pegasus (PEGA), which ran from March 2022 to July 2023 — was infected with NSO Group's Pegasus spyware at least three times: on October 21, 2022, while hospitalized in Greece, and again on March 6 and 7, 2023, while traveling between Athens and Brussels. Citizen Lab did not attribute the intrusions to a specific government customer and explicitly found "no indications that the Greek government is responsible," but identified technical overlap suggesting the operator had authorization to conduct surveillance across multiple European countries.
That detail matters more than it might first appear. It is the fact pattern that should worry anyone who believes export licensing alone can contain this technology.
The Reform That Was Supposed to Prevent This
Israel did not sit still after the first wave of Pegasus scandals. Following reporting that French President Emmanuel Macron's phone may have been targeted and after the U.S. Commerce Department blacklisted NSO Group in November 2021, Israel's Ministry of Defense cut its cyber-export list from 102 countries to 37 — restricting sales to established democracies, Five Eyes members, and a handful of others such as India and South Korea. The agency that administers this, the Defense Exports Control Agency (DECA), also began requiring end-user declarations limiting use to counterterrorism and serious-crime investigation, with sanctions for violators. A newer dual-use export control bill circulating for public comment in early 2026 would add catch-all licensing, brokering controls, and personal criminal liability for corporate officers — a genuine tightening of the regulatory architecture around Israeli cyber exports.
The steelman case for these reforms is real: before 2021, Pegasus was sold with almost no downstream constraint, and the tool ended up in the hands of governments that used it against journalists, dissidents, and opposition politicians in dozens of countries. Restricting the customer list to vetted democracies, backed by end-user declarations and licensing exposure for brokers, is the standard tool export-control regimes use for any dual-use technology, and it is not nothing — the customer base for Pegasus is genuinely smaller and more constrained than it was five years ago.
But the Kouloglou case exposes the reform's structural limit. Every plausible operator behind his infections — an EU member state security service with cross-border reach — was almost certainly already on Israel's post-2021 approved list. The restriction targets who may buy the tool, not how a licensed government buyer uses it once purchased. If the customer is a democracy in good standing, the export license does its job on paper while doing nothing to stop a national security service from spying on a sitting member of the very European Parliament committee formed to investigate that abuse.
Europe's Matching Failure
The European Parliament's own June 15, 2023 recommendation — adopted after 14 months of PEGA Committee hearings — is instructive here, because it correctly located the accountability gap on the buyer's side rather than the seller's. It called for an in-depth review of EU member states' spyware export licenses, stronger enforcement of the bloc's own export-control rules, and singled out Poland, Hungary, Greece, Spain, and Cyprus for scrutiny over documented Pegasus misuse. It also proposed an independent EU Tech Lab to investigate unlawful surveillance.
None of it happened. As Amnesty International noted in its July 2026 response to the Citizen Lab findings, "three years ago, the European Parliament's PEGA Committee on which Stelios Kouloglou sat issued clear and detailed recommendations for how to close the gaps that allow this abuse to continue" — and none of the substantive proposals were adopted into binding law. Civil society groups including CDT, EDRi, and Amnesty are now demanding an independent investigation into Kouloglou's case and a public roadmap on the stalled recommendations.
What Actually Follows From This
The honest reading of the Kouloglou case is not that Israel's export reforms are worthless — the 102-to-37 cut and the end-user declaration regime plausibly did shrink the population of illegitimate buyers. It is that export licensing was never designed to solve the problem this case illustrates, and treating it as if it were lets everyone else off the hook. If the operator here is an EU government, the failure sits with EU member states that either authorized surveillance of a fellow legislator or failed to build the internal safeguards — judicial authorization, independent audit, notification requirements — that the PEGA Committee itself recommended. Israel controlling its export list cannot substitute for the buyer-side rule of law that democratic governments were supposed to supply on their own.
The proportionate response is not to relitigate whether Pegasus should exist — commercial intrusion tools serve legitimate counterterrorism and serious-crime functions, and Israel's tightened licensing regime is a defensible model other dual-use exporters should study. The response that's actually missing is the one Europe keeps deferring: binding limits on when a member state's own security services may deploy spyware against a legislator, backed by real judicial oversight and enforcement teeth — the exact gap the PEGA Committee flagged in 2023 and that this case shows is still wide open.