REPORTS

From Project Raven to AI: How the UAE’s Surveillance Empire Could Become a Global Security Threat

Dark Box – The most dangerous question surrounding the United Arab Emirates’ rapid rise as an artificial intelligence power is not whether Abu Dhabi can build bigger data centers, acquire more advanced chips or attract the world’s most powerful technology companies.

It is what happens when one of the Middle East’s most sophisticated surveillance states gains access to artificial intelligence capable of processing information on millions of people at a speed and scale that traditional intelligence operations could never achieve.

The UAE does not enter the AI era with a blank record. Long before Abu Dhabi began presenting itself as a global technology hub, its security establishment had built an extensive cyber-surveillance apparatus capable of penetrating phones and monitoring dissidents, journalists, political opponents and foreign targets.

Project Raven exposed how far that apparatus had already reached. Former employees of the U.S. National Security Agency and American military and intelligence institutions were recruited to work inside a secret Emirati cyber program. Internal documents and former operatives showed that Raven functioned as an offensive arm of the UAE’s electronic security system, targeting not only conventional security threats but critics of the Emirati government, human rights defenders and foreign political interests.

The program became so aggressive that its activities eventually triggered a U.S. criminal investigation. In 2021, former American intelligence and military personnel Marc Baier, Ryan Adams and Daniel Gericke entered deferred prosecution agreements with the U.S. Justice Department over their work providing sophisticated hacking capabilities to the UAE.

The Justice Department established that the operation included a powerful zero-click exploit capable of compromising devices without requiring victims to open a malicious link. The three agreed to pay more than $1.68 million to resolve charges involving violations of U.S. export-control, computer-fraud and access-device laws.

This was not theoretical surveillance capability. It was an operational system built with elite Western intelligence expertise and placed at the service of an authoritarian government.

Project Raven’s reach crossed national borders. Reporting based on former operatives and internal documents showed that the program monitored political opponents, journalists, activists and foreign government interests. During the confrontation between the UAE and Qatar, Raven operatives targeted prominent Arab media figures, including the chairman of Al Jazeera and BBC Arabic presenter Giselle Khoury. Reuters also documented surveillance involving a British activist and American journalists.

The significance is difficult to overstate. Abu Dhabi had acquired the ability to turn techniques developed inside the American intelligence establishment toward journalists, political rivals and civil society figures across borders.

Then came DarkMatter.

Project Raven was transferred into the Emirati cybersecurity company DarkMatter, embedding offensive cyber capabilities deeper inside the UAE’s expanding technology sector. Citizen Lab later connected the UAE-linked Stealth Falcon surveillance ecosystem with DarkMatter and documented the targeting of Emirati human rights defender Ahmed Mansoor.

Mansoor’s case became one of the clearest warnings of what sophisticated surveillance technology could mean under the UAE’s political system.

In 2016, Mansoor received suspicious text messages promising information about torture in Emirati prisons. Instead, the links contained an extraordinarily sophisticated chain of previously unknown iPhone vulnerabilities.

Citizen Lab examined the links and discovered Pegasus, the government-exclusive spyware developed by Israel’s NSO Group. Had Mansoor clicked, researchers found, his phone could effectively have become a surveillance device against him, allowing access to communications while enabling monitoring through the phone’s microphone and camera and tracking his movements.

Citizen Lab subsequently linked the operation targeting Mansoor to the UAE government.

Mansoor was arrested the following year. He was later sentenced to ten years in prison over his online activities and remains one of the most prominent symbols of political repression in the Emirates.

This history matters because the technological frontier has now moved.

The UAE is no longer merely acquiring spyware capable of penetrating individual devices. It is building the infrastructure required to become a global artificial intelligence power.

At the center of that transformation stands Sheikh Tahnoun bin Zayed Al Nahyan.

Tahnoun is the brother of UAE President Mohammed bin Zayed and serves as the country’s national security adviser. At the same time, he occupies central positions across Abu Dhabi’s enormous financial and technological network, including as chairman of G42, the artificial intelligence conglomerate that has become the flagship of the UAE’s AI ambitions.

He also chairs the Abu Dhabi Investment Authority and First Abu Dhabi Bank, while institutions and companies across his wider sphere connect him to an economic network estimated at around $1.5 trillion in assets.

That concentration is what makes the UAE model exceptional.

Security, sovereign wealth, banking, data infrastructure and artificial intelligence are not developing in entirely separate spheres. They increasingly intersect around overlapping institutions and one of the most powerful members of the Emirati ruling family.

G42 has emerged as the technological centerpiece of that system.

The company operates across cloud computing, artificial intelligence, healthcare, geospatial technologies, data infrastructure and other sectors where access to enormous quantities of information is increasingly valuable. Its chief executive, Peng Xiao, previously held a senior role within the DarkMatter ecosystem.

G42 rejects characterizations presenting it as an extension of DarkMatter and portrays itself as a global AI and cloud-computing company. There is no evidence establishing that G42 itself operates as a spyware program.

But the international-security question goes far beyond whether G42 can be labeled a surveillance company.

The issue is the convergence of capabilities.

The same state whose security establishment developed sophisticated offensive cyber operations is now gaining access to vastly more powerful systems for processing data, recognizing faces, mapping relationships, analyzing behavior, interpreting communications and identifying patterns across enormous populations.

Artificial intelligence changes the scale of surveillance.

Traditional cyber-espionage often begins with a target: a phone number, an email address, an activist, a journalist, an opposition figure or a government official.

AI can reverse that equation.

Instead of beginning with one person and collecting information about that individual, powerful machine-learning systems can process huge datasets first and identify individuals, networks and behavioral patterns afterward.

Facial-recognition technology can search enormous image databases. Automated systems can map social connections. Location data can reconstruct movements. Communications metadata can expose networks of association. Large language models can analyze huge quantities of documents and communications. Machine-learning systems can detect patterns that would require thousands of human intelligence analysts to examine manually.

The transition from spyware to AI is therefore not simply a technological upgrade.

It potentially transforms surveillance from a targeted weapon into infrastructure.

And Europe already knows how vulnerable democratic institutions can become when sophisticated spyware enters political life.

The European Parliament established its PEGA inquiry after Pegasus and similar systems were used against politicians, journalists, activists and other figures across Europe. Its investigation concluded that spyware had been used to monitor, intimidate and discredit political opponents, journalists and civil society and warned that such technologies could threaten democratic institutions themselves.

The crisis did not end with the inquiry.

In July 2026, Amnesty International and other organizations revealed that former European Parliament member and investigative journalist Stelios Kouloglou had been infected with Pegasus while serving as a substitute member of the very parliamentary committee investigating spyware abuse.

Forensic analysis identified infections around October 2022 and again in March 2023, during the period in which the European Parliament was attempting to investigate the spyware industry.

Researchers did not identify the state responsible for infecting Kouloglou.

That distinction is essential. There is no public forensic evidence establishing that the UAE conducted that particular operation.

But the case demonstrates something broader and deeply relevant to Abu Dhabi’s technological rise: the political institutions of Europe are already vulnerable to sophisticated transnational surveillance.

European lawmakers have themselves warned that spyware has been used to target opposition politicians, journalists and activists and that the problem threatens democratic processes.

Now place that vulnerability beside the UAE’s documented history.

Abu Dhabi has already operated a transnational cyber-surveillance system. Project Raven targeted critics, political interests and journalists beyond Emirati territory. Citizen Lab linked the Pegasus attack against Ahmed Mansoor to the UAE. Former American intelligence personnel admitted conduct connected to providing sophisticated hacking services to the Emirati government.

The concern is therefore not based on an imagined future.

The surveillance record already exists.

What is changing is the power of the technology available to the state that built it.

In April 2024, Microsoft announced a $1.5 billion investment in G42. Microsoft president Brad Smith joined G42’s board, while the two companies entered an intergovernmental security arrangement developed in consultation with the U.S. and UAE governments.

The agreement gave Abu Dhabi something far more strategically valuable than another foreign investment: deeper integration into the American AI ecosystem.

Then came Stargate UAE.

OpenAI announced Stargate UAE as the first international deployment of its Stargate AI infrastructure platform. The project brings together OpenAI, G42, Oracle, Nvidia, Cisco and SoftBank and includes a one-gigawatt computing cluster in Abu Dhabi, with the first 200 megawatts expected to become operational in 2026.

The project sits within an even larger UAE-U.S. AI infrastructure initiative.

Washington has also authorized G42 to acquire computing capacity equivalent to as many as 35,000 Nvidia Blackwell GB300 chips, subject to security and reporting requirements.

The transformation is extraordinary.

A country with a population of roughly ten million is positioning itself to control computing infrastructure powerful enough to serve AI systems operating across governments, businesses and entire economic sectors.

The question for Europe and other democracies is therefore no longer simply whether Emirati intelligence services can hack a politician’s phone.

The question is what becomes possible when a state with Abu Dhabi’s surveillance history controls enormous computing capacity and increasingly sophisticated artificial intelligence.

AI could make intelligence gathering cheaper, faster and more scalable.

A surveillance operation that once required teams of analysts examining hundreds of targets could potentially use automated systems to process millions of records. Instead of manually identifying relationships between dissidents, journalists, politicians and organizations, AI could map those relationships automatically. Instead of analysts watching hours of video, facial-recognition systems could identify individuals across enormous archives. Instead of reading thousands of communications, language models could classify, summarize and connect them.

That does not mean every AI system deployed by the UAE will be used for surveillance.

It means the technical barrier separating ordinary data infrastructure from extraordinary intelligence capability is shrinking.

That is precisely why the identity and political structure of the state controlling such infrastructure matters.

In a democracy, intelligence services theoretically operate under layers of judicial, parliamentary and institutional oversight. Those safeguards can fail, as Europe’s own spyware scandals have demonstrated.

In the UAE, meaningful political opposition is effectively prohibited. Independent civil society is severely restricted. Human rights defenders have been imprisoned. The ruling family controls the political system, while some of the country’s largest pools of capital and most strategically important technology institutions sit within networks closely connected to the same leadership.

The concentration of AI capacity inside such a system creates a problem that cannot be solved merely through corporate assurances about responsible technology.

It is a question of power.

Microsoft says its relationship with G42 contains extensive security safeguards. OpenAI presents Stargate UAE as part of an effort to expand secure and beneficial AI infrastructure. Washington has imposed security and reporting conditions on advanced chip exports.

But these arrangements are being constructed around a state whose security apparatus has already demonstrated a willingness to use advanced cyber capabilities against dissidents, journalists and political targets.

The danger therefore extends beyond privacy.

It reaches international security.

Intelligence obtained through digital surveillance can influence diplomacy, political negotiations, business transactions and international alliances. Information about politicians can provide leverage. Access to private communications can reveal negotiating positions. Surveillance of journalists can expose sources. Monitoring dissidents can extend repression beyond national borders.

At sufficient scale, information becomes geopolitical power.

Artificial intelligence magnifies that power.

This is why the UAE’s transformation from a buyer of surveillance tools into a major owner of AI infrastructure deserves far more scrutiny than it has received.

The international debate has largely focused on another question: whether American technology transferred to the UAE might eventually reach China.

That concern has dominated Washington’s discussions about G42, advanced chips and security restrictions.

But it risks obscuring another question.

What if the danger is not only where American technology might be transferred, but how it could eventually be used by the government receiving it?

Project Raven should make that question unavoidable.

The United States already watched former members of its own intelligence community take capabilities developed in the American security system and place them at the service of the UAE. Those capabilities were then used within an apparatus that targeted dissidents, journalists and foreign political interests.

Years later, Washington is helping Abu Dhabi acquire computing power on a completely different scale.

The technologies are different. The companies are different. The infrastructure is different.

The state remains the same.

And the central figure connecting national security to the new AI economy is Tahnoun bin Zayed.

His rise captures the transformation of Emirati power itself.

Yesterday, power meant oil reserves, sovereign wealth and military relationships.

Then it meant cyber capabilities capable of penetrating a target’s phone.

Today, it increasingly means control over chips, data centers, cloud platforms, algorithms and the electricity required to run them.

Tomorrow, geopolitical power may belong to governments capable of combining all of those resources.

The UAE is attempting to become one of them.

That is why the story does not end with G42, Microsoft or Stargate.

It ends with a much darker question.

Project Raven showed what Abu Dhabi was prepared to do when it gained access to elite hacking expertise. Ahmed Mansoor showed what sophisticated surveillance could mean for someone who challenged the Emirati state. Europe’s spyware crisis showed how easily digital weapons can penetrate journalists, opposition figures and even the institutions supposed to investigate surveillance itself.

Artificial intelligence now offers capabilities exponentially larger than those available during the early years of Project Raven.

The UAE is accumulating the chips.

It is building the data centers.

It has the capital.

It has the partnerships.

And it already has the surveillance experience.

The international community should therefore stop treating Abu Dhabi’s AI expansion as merely another story about Gulf investment and technological modernization.

The real issue is whether some of the world’s most powerful artificial intelligence infrastructure is being concentrated inside a political system with a documented history of using advanced digital capabilities against critics and foreign targets.

Yesterday, Abu Dhabi could penetrate a phone.

Tomorrow, AI could give it the capacity to analyze entire networks, institutions and societies.

That is no longer merely a human rights concern.

It is a question of international security, democratic sovereignty and how much digital power the world is prepared to place in the hands of the UAE.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button