A review three years in the making
On 23 July 2026, the European Commission opened a targeted stakeholder consultation on the overall evaluation of the Dual-Use Regulation, closing 11 September 2026 — one day after the formal review clock starts. Article 26(4) of Regulation (EU) 2021/821 requires the Commission to evaluate the regulation, including Article 5's "catch-all" control on cyber-surveillance exports, and report findings to Parliament, Council and the European Economic and Social Committee sometime between 10 September 2026 and 10 September 2028, according to the Commission's own consultation page. A parallel, longer-running open public consultation invites businesses, researchers and civil society to weigh in as well.
Article 5 was the headline achievement of the 2021 recast: for the first time, EU exporters must seek authorization for cyber-surveillance items — intrusion software, telecom interception systems, forensic extraction tools — even when those items aren't on any control list, if the exporter knows or has been told the goods may enable internal repression or serious human rights violations. It was billed as Europe's answer to the commercial spyware industry that produced Pegasus and Predator.
The steelman: the harm is real and documented
The case for tightening this regime is not speculative. The European Parliament's PEGA committee spent over a year investigating Pegasus deployment against journalists, lawyers and opposition figures inside the EU itself, adopting a 145-page report in March 2023 that found Greek, Polish and Hungarian legal frameworks had violated EU law, per the Parliament's own think-tank summary. A July 2026 joint statement from EDRi, CDT and other civil society groups, prompted by the revelation that a former MEP investigating spyware abuse was himself targeted with Pegasus, calls the situation "a rule of law emergency." And a May 2026 Human Rights Watch report documents specific licensed exports — Bulgarian intrusion software to Azerbaijan, Polish interception systems to Rwanda — that reached governments actively surveilling journalists and dissidents. If Article 5 is meant to prevent exactly this, the review has to reckon with cases where it plainly didn't.
That argument deserves to be taken seriously, not waved away as regulatory overreach. Export controls that exist on paper but aren't enforced are worse than none: they give exporters, buyers and the public a false sense that due diligence is happening.
Why the fix isn't a bigger dragnet
But the HRW findings point to an enforcement and transparency failure, not a scope failure. Only 14 of 27 member states reported cyber-surveillance export data to the Commission for 2022–2023, and just 7 of 27 responded to HRW's freedom-of-information requests, with 12 outright denials. That's not evidence Article 5's definition of "cyber-surveillance items" is too narrow — it's evidence that national licensing authorities have wildly uneven capacity and willingness to apply a subjective, awareness-based test at all. The Commission's own October 2024 guidelines on Article 5 due diligence exist precisely because exporters and regulators alike didn't know how to operationalize the rule; SIPRI's assessment of the catch-all control found its use had been "limited to date," largely from confusion rather than reluctance.
The temptation, in a review shaped by PEGA and HRW's findings, will be to respond with a broader net: reclassify more forensic and penetration-testing tools as listed items, or impose blanket destination bans. That would repeat a mistake the export-control world has already made once. When the Wassenaar Arrangement's 2013 members tried to control "intrusion software" broadly, the resulting 2015 U.S. implementing rule drew such fierce pushback from security researchers, bug-bounty platforms and defensive tool vendors — who use identical techniques to find and fix vulnerabilities — that regulators spent two years walking it back. Cyber-surveillance tools and cybersecurity research tools are often the same code with different intent; a rule that can't distinguish them chills the researchers who make the internet safer while doing little to stop a state buyer who can route through a reseller anyway.
What proportionate reform looks like
The more defensible path, and the one this review should prioritize, is harmonizing what already exists: a shared EU denial-notification database so a rejected license in Sofia doesn't get quietly approved in Warsaw, mandatory (not guideline-level) reporting of destination and technology-type data so oversight bodies can actually see patterns, and technical assistance for the smaller licensing authorities that plainly lack capacity. That raises the enforcement floor without redefining what counts as a controlled item — proportionate to the demonstrated problem, which is implementation, not the statute's text.
The consultation closing 11 September is a genuine opportunity to fix that gap. Widening Article 5 into a catch-all for dual-use cybersecurity trade generally would be a broader, blunter instrument than the evidence supports — and would land hardest on the legitimate security industry the EU says it wants to grow.