The Atlantic Council convened researchers, advocates, and legal experts on August 26, 2025, to grapple with a thorny problem at the intersection of cyber law and human rights: how to hold commercial spyware vendors accountable when traditional litigation moves at glacial pace and international regulation remains years away.
Despite numerous calls for accountability regarding spyware abuses, efforts to establish norms at the international level and to enact binding regulations will take years, leaving a major gap when it comes to past and ongoing abuses. The Strategic Litigation Project and Cyber Statecraft Initiative hosted the panel in anticipation of two companion reports proposing divergent legal theories to bridge that accountability gap.
Two Paths Forward
The two companion reports explore how strict liability for ultrahazardous activities and product liability can be used to address and prevent spyware harms, respectively. These represent starkly different approaches to a question that has eluded policymakers: whether spyware development and deployment should be treated as analogous to explosives handling or defective consumer goods.
The strict-liability proposal draws on tort doctrine developed for abnormally dangerous activities—drilling, blasting, or transporting hazardous materials—to argue that spyware makers should absorb the costs of their products regardless of precautions taken. For strict liability, there is no need to prove that a duty has been owed or breached or that the defendant had any intent to cause harm; plaintiffs need to prove only that a defendant carried out an abnormally dangerous activity, that the plaintiff has been harmed, that the harm was the kind of harm that is a foreseeable consequence of the activity, and that the defendant's carrying out of the activity was a substantial factor in causing the harm.
The product-liability approach, by contrast, proposes a more limited framework. One proposal advocates a legislative safe harbor framework that would incentivize technology companies to engage in spyware accountability by shielding compliant firms from litigation related to software insecurity, including potential products liability claims, with companies qualifying for protection by meeting standards including comprehensive threat notification and detection programs, responsible information sharing with researchers and advocacy organizations, provision of enhanced security features, and rapid remediation of identified vulnerabilities.
The Accountability Bottleneck
The timing of these discussions reflects growing frustration with the speed of traditional litigation. Cases against spyware vendors take years—WhatsApp's decision in May is the result of a suit originally filed in October 2019, while spyware vendors continue to emerge and evolve, perpetuating abuses against individuals and developing new exploits against messaging apps, mobile operating systems, and other popular consumer products.
Obstacles to spyware accountability through litigation include a lack of awareness of targeted individuals, the intentional obscurity of spyware vendors, difficulties establishing jurisdiction, and the risks of exposing research. These barriers mean that most victims never learn they were targeted, and those who do often lack the resources to pursue claims across multiple jurisdictions.
What distinguishes the August 26 convening is its explicit challenge to conventional wisdom about tort law's applicability to cyber threats. The ultrahazardous-activity framework rests on a provocative premise: that the creation and deployment of spyware—software designed to evade detection and compromise fundamental privacy protections—shares essential characteristics with activities so dangerous they warrant absolute liability. The company selling the software bears the cost, period.
Contested Ground
Neither approach has gained consensus even within the cybersecurity policy community. Competing analysis argues that with respect to software products, a negligence framework is better than strict liability for shifting vendor behavior in the interest of the public, national security, and the digital ecosystem. This perspective, too, traces back to Atlantic Council work, suggesting the organization is orchestrating debate rather than endorsing a single path.
The intellectual tension is real. Strict liability may impose ruinous costs on software developers and chill innovation in legitimate security research. But a negligence standard requires victims to prove malfeasance—a burden already crushing given the forensic complexity of spyware infections and the opacity of vendor practices.
Implications for Cyber Law
What emerges from the August convening is a recognition that law is lagging behind threat. The spyware vendors are not merely breaking existing rules; they are occupying spaces where rules do not yet coherently apply. The Atlantic Council's effort to test-drive competing liability frameworks in a public setting signals that policymakers and practitioners are no longer content to wait for international consensus or parliamentary action. They are reviving and reimagining common-law tools.
The outcome will shape not only how jurisdictions pursue accountability for spyware, but whether cyber conduct more broadly can be regulated through traditional liability doctrine or whether digital operations demand fundamentally different legal architectures. For now, the frameworks remain in competition. The Atlantic Council's companion reports, previewed at that convening, set out to clarify which approach—if either—can bear the weight of legal accountability for tools designed to breach the sanctity of personal devices.
Sources
- Accountability now: Liability for spyware harms — atlanticcouncil.org/event/accountability-now-liability-for-spyware-harms/
- 404 Accountability not found: Spyware accountability through software liability — atlanticcouncil.org/in-depth-research-reports/report/404-accountability-not-found-spyware-accountability-through-software-liability/
- Spyware blasts: Strict liability for abnormally dangerous activities — atlanticcouncil.org/in-depth-research-reports/report/spyware-blasts-strict-liability-for-abnormally-dangerous-activities/
- Buying down risk: Cyber liability — atlanticcouncil.org/content-series/buying-down-risk/cyber-liability/
Correction
Issued 2 September 2026. As first published, this dispatch dated the Atlantic Council panel to August 26, 2026. The event was held on August 26, 2025; the date has been corrected. The description of the two companion reports and the closing paragraph, which anticipated their publication later in 2026, have been revised to reflect that the convening took place a year earlier. No other claim in the piece is affected. The article's URL retains the slug assigned at first publication.