France's licensed cyber-surveillance exports doubled to about 65 million euros in 2025, its report to parliament shows

12.09.2026 7 min 27

France licensed about 65 million euros of cyber-surveillance exports in 2025, more than double the previous year, according to the government's own report to parliament on dual-use goods. The report, the fifth of its kind, was published on 14 August 2026 and gives the figure only indirectly: surveillance goods were "around 11 percent" of everything approved in the two categories that cover computers and telecommunications, up from 8 percent a year earlier. Who bought them is not in the document.

In brief

  • Individual export licences for dual-use goods reached 21.6 billion euros in 2025, up 37 percent, driven by nuclear and aerospace deals.
  • Within that, cyber-surveillance technology went from roughly 30 million euros in 2024 to roughly 65 million in 2025, by the report's own percentages applied to its own category totals.
  • The report lists category-5 buyers such as Mexico, Saudi Arabia, Morocco, the UAE, China, Iraq and Egypt, but does not say which of them received surveillance goods rather than encryption hardware.
  • The safeguard the report points to is the Pall Mall Process, a France-UK initiative against the mercenary spyware that Apple keeps warning its users about; it remains a voluntary code with no enforcement.

How the 65 million is arrived at

The report never prints a euro figure for surveillance exports. It says that cyber-surveillance goods, which fall "mostly under part 1 of category 5 (telecommunications) and, to a lesser extent, category 4 (computers)", represented "around 11 percent of the amount of licences granted in 2025 across categories 4 and 5". Annex 5 gives those categories: 2.3 million euros for category 4 across 11 licences, and 589.5 million euros for category 5 across 729 licences. Eleven percent of the combined 591.9 million is about 65 million euros. The previous report used the same construction for 2024: 8 percent of 27.1 million plus 347.6 million, or roughly 30 million. The French outlet Next, which first did the arithmetic, put the average for 2021 to 2024 at around 30 million a year.

  1. Category 4 (computers), 2025: 2,303,744 euros, 11 licences.
  2. Category 5 (telecommunications and information security), 2025: 589,546,506 euros, 729 licences.
  3. Report's stated share for cyber-surveillance goods: about 11 percent of the two combined.
  4. Result: about 65 million euros, against about 30 million on the same method for 2024.
21.6 bn €individual dual-use licences granted in 2025, up 37 percent on 15.7 billion in 2024
~65 M €cyber-surveillance share of categories 4 and 5, from 11 percent stated in the report
70licence refusals France notified to other EU states in 2025, all categories
0destination countries named for surveillance goods specifically

What the country table does and does not say

Annex 4 breaks the top 25 destinations down by category, and category 5 is where the surveillance goods sit. The largest category-5 amounts in 2025 went to Mexico (233.9 million euros, 45 licences), Saudi Arabia (88 million, 35), Morocco (32.6 million, 17), the United Arab Emirates (26.2 million, 36), China (21.1 million, 56), Iraq (17.4 million, 11), Brazil (16.9 million, 10) and Egypt (13.3 million, 14). The catch is that category 5 also contains cryptography products, firewalls, routers and modems, which the report says account for 92 percent of the category's value. A licence to sell encrypted routers to Mexico and a licence to sell interception gear to Egypt land in the same row. The report does not separate them, and the number of licences is shown only as "fewer than 10" wherever it is small, on confidentiality grounds.

The document's own framing is that surveillance goods are "subject to strict control" because of the "risk of diversion for internal repression or the commission of serious and systematic violations of human rights", and that their use "can also be legitimate in the fight against crime and terrorism". The safeguard it cites is the Pall Mall Process, launched by France and the United Kingdom in 2024 to curb "the proliferation and irresponsible use of commercial cyber intrusion capabilities". That process produced a voluntary code of practice for states in Paris in April 2025, backed at the time by 25 governments. It binds nobody, and the report presents it as the framework under which exports with adequate "guarantees and supervision mechanisms" can proceed.

Worth separating: a licence is a ceiling, not a shipment. The report says so itself: not every authorisation is used in full. The 65 million is what the state agreed to let out, which is the number that matters for policy, and it is the number that doubled.

Why an export line is a privacy story

French companies have a long record in this market. Amesys sold Libya's Gaddafi government the Eagle interception system in the 2000s and its successor Nexa faced charges over sales to Egypt; Qosmos was investigated for years over deep packet inspection technology tied to a Syrian interception project. The EU rewrote its dual-use rules in 2021 partly because of those cases, adding a catch-all clause that lets a state require a licence for unlisted goods when human rights risks appear. The 2026 report notes that the Commission is now evaluating that regulation until at least early 2027 and that it published due-diligence guidance for surveillance exporters in October 2024. What the report shows is a licensing system that works as designed: France approved more, refused 70 times, and disclosed the outcome in percentages.

For people on the receiving end the categories are concrete. Part 1 of category 5 covers lawful interception systems, mobile monitoring and the deep packet inspection equipment that identifies and throttles VPN traffic on national networks. Category 4 covers intrusion software of the kind that ended up on the phone of the European Parliament's own spyware investigator. A 65 million euro line does not say which of these was sold or to whom. It does say that, in a year when France co-chairs the diplomatic effort against spyware proliferation, the state signed off on twice as much of the technology as the year before.

Does the report say France exported 65 million euros of surveillance technology?
Not in those words. It says surveillance goods were about 11 percent of licences in categories 4 and 5, and gives those categories' totals in an annex. Applying the one to the other gives about 65 million euros in licences, not confirmed shipments.
Which countries received the surveillance goods?
The report does not say. Its country table mixes surveillance goods with encryption products in category 5. The largest category-5 destinations were Mexico, Saudi Arabia, Morocco, the UAE, China, Iraq, Brazil and Egypt.
What counts as cyber-surveillance under EU rules?
Goods specially designed to enable covert surveillance by monitoring, extracting, collecting or analysing data from information systems: interception systems, monitoring centres, intrusion software and related equipment listed under the Wassenaar Arrangement and EU regulation 2021/821.
What is the Pall Mall Process?
A diplomatic initiative launched by France and the UK in February 2024 against the proliferation and irresponsible use of commercial cyber intrusion tools. Its April 2025 code of practice for states is a set of voluntary political commitments with no enforcement mechanism.
Did France refuse any exports?
The report says France notified 70 licence refusals to other EU member states in 2025, across all categories of dual-use goods, and also issued partial or conditional approvals. It does not break refusals down by category.

francesurveillanceexport controldual-use goodsspywaredpilawful interceptionhuman rightseulegislationprivacypall mall process

Read also