What happened
Twenty-nine members of the European Parliament signed a letter on Friday calling for Serbia's EU accession to be slowed until the government completes an investigation into its use of spyware, and for further progress to be tied to rule of law accountability, CyberScoop reports. The letter also asks Commission President Ursula von der Leyen to cancel a planned visit to Serbia.
The trigger is a report from the SHARE Foundation, working with Amnesty International and the Citizen Lab at the University of Toronto, that Pegasus and NoviSpy spyware were found on the phones of Serbian student activists and used against others. The groups did not assign responsibility for the Pegasus infections, but said evidence from the NoviSpy infections pointed to Serbian government authorities. The MEPs wrote that this is not a technical glitch but a direct state attack on democracy, accusing the government of using illegal digital surveillance to dismantle political opposition ahead of elections.
The letter lands amid wider friction. European leaders were already angered by Serbia's response to the death of Ratko Mladic, and the EU enlargement commissioner canceled her own visit over the alleged glorification of the convicted war criminal. MEP Hannah Neumann, a signatory, told CyberScoop the spyware issue would not be the only reason any demands are honored. The Serbian government did not respond to requests for comment.
Why this is a GRC story
State use of commercial spyware has moved from a technical story to a formal governance test. EU accession is now being framed around whether a country's surveillance is lawful, proportionate, and accountable, with civil society and universities doing the forensic work that exposes the gap between policy and practice. That is the same pattern GRC professionals recognize in any control environment: documented rules mean little when the people with power over the tools do not follow them.
There is a supply chain lesson here for the private sector. Intrusion software and surveillance vendors have become their own due diligence category, with export controls, abuse reporting, and buyer vetting shaping the market. Companies that buy or operate such technology face the same questions any high risk vendor raises: who made it, who is watching how it is used, and what happens when legitimate tools get pointed at legitimate targets.
The story also cuts toward Europe's own institutions. Recent cases of spyware found on the devices of European Parliament members, including someone tied to the committee that oversees spyware issues, show that oversight bodies can be targeted too. A governance regime is only as credible as the independence of the people running it.
What to watch
Watch whether the Commission actually links the pace of accession talks to the spyware investigation, and what that investigation turns up about which vendors were involved and how the spyware was procured. Names and procurement routes matter, because they determine whether this stays a bilateral dispute or becomes export control and sanctions territory.
For organizations that use or evaluate surveillance and intrusion technology, the practical takeaway is to review usage policies and oversight now. The bar for what counts as accountable use of powerful monitoring tools is rising, and it is being set in public.
Attribution: Analysis based on CyberScoop's reporting and related public reporting. This article is original commentary, not a repost of the source material.
