Future Proofing Surveillance Law in Israel: On Emerging Technologies and the ISA Law Amendment Memorandum

By July 18, 2026Developments

Amir Cahane, PhD student, Hebrew University of Jerusalem, faculty of law; Doctoral Researcher, Three Generations of  Digital Human Rights (3GDR) (ERC); Doctoral Researcher,Max Planck Center for Democracy, Security, and Human Rights

In December 2023, the Amendment Memorandum to the ISA Law was published. It proposes to confer a number of far-reaching powers on Israel’s Security Agency (the ISA, also known as Shin Bet or Shabak), including not only the power to conduct remote searches (that is, to use spyware) but also to run remote interference (that is, to engage in offensive cyber operations). Press coverage of the Memorandum’s publication, against the backdrop of the Gaza war, occasionally raised concerns that the Agency was exploiting the state of emergency to seize broad surveillance powers, akin to those acquired by the US intelligence community after September 11 under the PATRIOT Act. That said, when the Agency has needed new powers during an emergency, it has shown that it knows how to request, and obtain, them.

The actual background to the Memorandum is a still-pending petition by the Association for Civil Rights in Israel (ACRI), challenging the constitutionality of section 11 of the ISA Law, under which the Agency collects metadata into the database known as “the Tool.” The State has presented the Memorandum as a response to ACRI’s claims regarding section 11. The Memorandum also incorporates further amendments to the ISA Law, some of which had been pending for over a decade, others entirely new.

Drawing on a recently published paper, this post examines aspects of the deployment of future-proofing strategies in the Amendment Memorandum, and argues that the attempt to resolve the dual uncertainty pertaining both to national security as well as the nature of emerging technologies generates a partial democratic deficit in which legislative discretion is transferred to the executive branch.

On Future-Proofing

Future-proofing is an interdisciplinary perspective that offers a systematic framework for dealing with future requirements and uncertainties while accommodating innovation. This approach seeks solutions resilient to future change, ensuring that a product or system does not become obsolete on account of developments that could not have been foreseen at the design stage, or because it was not designed to be flexible and adaptive. The academic literature abounds with writing on future-proof crops, infrastructure, or legal systems. And, likewise, future-proof legislation.

“Future-proof legislation” is an elusive concept, since legislation by its nature aspires to endure without change. Legislation is a forward-looking act of legal creation (unlike judge-made law, which draws on precedent and remains in dialogue with the past). As a system, law aims to preserve its own temporal inertia — to remain effective over time without changing.

Emerging technologies constrain that inertia, since they result in socio-technological change that may render laws obsolete. We should also remember that legislative processes are slow and cumbersome, and legislators often lack the incentive to revisit the same issue frequently; the law accordingly responds slowly to technological change, a phenomenon identified in the literature as the pacing problem. The EU Artificial Intelligence Act illustrates this: the first expert committee convened in 2018; the first substantive draft followed three years later, in 2021. In the interval, the major “boom” in generative AI forced the European legislature to further address “foundation models,” later folded into “general purpose AI models.”

Given this uncertainty, on the one hand, and protracted legislative processes, on the other, a legislator wishing to effectively regulate emerging technologies will prefer to design the law so as to preserve its temporal inertia — finding a flexible, preferably technologically neutral arrangement, so as “to regulate behaviour, not technology.

In national security legislation, the motivations differ. Where the regulation concerns how intelligence and law-enforcement agencies use emerging technologies, generally for surveillance, the legal framework must be even more flexible, because the uncertainty has doubled: neither the technologies intelligence targets will use, nor the counter-technologies the agencies will deploy to track or thwart them are fully known during the legislative proceedings which seek to produce rules that endure over time.

A further, not necessarily technological, dimension relates to these organizations’ culture of secrecy. They often refrain from publicizing their activities (hence the common designation of “the secret service”) and have little appetite for public debate about the scope and nature of their powers, particularly the manner these powers are internally interpreted. From their perspective, it is preferable that the legislature revisits their governing legislation as rarely as possible. Indeed, the substantive proceedings on the ISA Law were conducted largely behind closed doors, and once the statutory text was published, the Agency appears to have preferred to avoid further deliberation that might expose its methods and means, or narrow its operational latitude.

Future-Proofing Techniques

There are several strategies for future proofing legislation. Firstly, the use of suitable language. The wording of a future-proof law must be as abstract as possible, and in particular technologically neutral, so as “to regulate behaviour, not technology.” The Israeli Wiretapping Law, for example, is built around the concept of a “conversation” and “eavesdropping”, allowing the Agency to extend the range of its operations from the use of listening devices through telephone interception to the interception of computer communications — and, per the Merari Report, to spyware as well.

The vagueness inherent in such drafting, using techno-intelligence terminology intelligible to practitioners, also helps conceal methods and capabilities — a further motivation for this language in security contexts. A common sign of failed future-proofing is when later amendments are explained as mere “clarification”: the bill, heaven forbid, proposes no new power, but merely “clarifies” a power that has long existed — amounting to codification of an internal, at times classified, interpretation.

Secondly, futureproofing strategies tend to prefer principles over rules. Abstract statutory language naturally tends toward the principle end of the rule-principle spectrum. A flexible framework articulates a general principle and avoids descending into detail, leaving the executive or regulator to give that principle concrete content.

Another strategy is using mechanisms for regulatory experimentation. Various regulatory techniques create space for real-time experimentation, allowing a regulator to test a technology’s implications while it is still developing. Such approaches seem less relevant in security contexts, however. While regulatory sandboxes are an existing policy tool in Israel , for example, it is doubtful that they could be deployed in a national security context, given the high stakes risks to human rights and the lack of a designated regulatory authority for these matters.

A different approach would be to rely on general powers. Authorities often assume that they possess a power to use a given technology by virtue of a general power to fulfil their function — as occurred in the Hawkeye ALPR system affair and in the deployment of an AI profiling system at Ben Gurion Airport. Given the requirement under Israeli constitutional law for explicit statutory authorization before rights may be infringed, however, this strategy rests, under Israeli law, on a broken reed.

Sunset provisions are somewhat of a less intuitive example of future-proofing techniques. However, they are futureproof in a dual sense: the law’s temporal inertia is fixed in advance, reducing uncertainty, and because the law has a known expiry point, there is less appetite for judicial or parliamentary intervention, which contributes to its resilience.

Finally, there is second-order future-proofing. National security legislation contains many instances of delegating parliamentary decision-making to the executive: basket clauses conferring on a minister (sometimes subject to committee approval) the power to amend the law in emergencies, or skeletal arrangements implemented through internal guidelines or administrative rules. These allow the regulator, or the authority on the ground, to respond to developments in real time.

It should be clear, however, that taken together these techniques amount to a transfer of power from the legislature to the executive or regulator: whether through explicit delegation, the conferral of interpretive authority over general principles or neutral language, or the creation of discretional pockets within regulatory experimentation.

Future Proofing Techniques in the Amendment Memorandum

This post cannot review the Memorandum in full, but several examples illustrate its employment of future-proofing techniques. Even in its present form, the ISA Law uses technologically neutral language. For example, its broad definition of “information” (“including communications data but excluding the content of a conversation as defined in the Wiretapping Law”) potentially enabling the collection of almost any data from telecommunication providers. A further example is the delegation of authority to set concrete data protection related arrangements for such information by means of classified “rules.” Controls of this kind (retention periods, deletion, data security) ought in principle to be regulated at the statutory level rather than delegated to administrative rules; and because the rules themselves are classified, what is involved is not mere delegation, but concealment of how that authority is exercised.

The Memorandum appears to narrow the definition of “information” to communications data as defined in the rules, including internet usage data that is not the content of a conversation between persons. This ostensibly clarifies that “information” means communications data, yet the nature of communications data is itself defined in classified rules, alterable by written order of the Prime Minister with ministerial and parliamentary committee approval. Despite the amendment, the definition remains subject to future-proof interpretation.

The proposed section 8A offers new powers concerning the collection or receipt of databases, with exceptions for particularly sensitive ones. This high level of abstraction, using technologically neutral language, however leaves unclear what constitutes “collection” or “receipt,” or the operative significance of either.

Particular attention is warranted regarding the Memorandum’s residual-powers arrangement concerning information. Under the proposed rule, where an essential need arises to exercise a power over information to prevent offences within the Agency’s core domains, and existing statutory powers provide no adequate response, the Ministerial Committee for ISA Affairs, with the Knesset’s Intelligence Subcommittee’s approval, may confer such a power on the ISA. This is a Rumsfeldian uncertainty, an “unknown unknown”. The legislature does not know what future needs will arise, yet has agreed to create an authorizing mechanism subject to only limited parliamentary oversight: a form of second-order future-proofing that expands the Agency’s powers not on a purposive basis (as under section 7(b)(6), which allows to task the ISA with mission beyond its statutory remit), but with respect to the very nature of the power itself. It is doubtful whether an external reader of the Memorandum could envisage the scenarios this provision is meant to cover. Perhaps that is precisely what is troubling about it.

Concluding Remarks

Future-proofing is a structural feature of every piece of legislation, since all laws are forward-looking. It divides the task of confronting future uncertainty between the legislature and the executive, transferring to the latter powers of rulemaking — whether through interpretation or through deferred discretion.

In national security legislation, particularly where emerging technologies are concerned, the level of uncertainty may be so high that legislative proceedings trying to capture it in detail would waste legislative resources. This may justify the cautious deployment of these techniques in this particular domain, particularly given that, in light of Israel’s tumulus political situation, there is no telling whether the legislature will be able to revisit the matter again in four or five years.

Nevertheless, the need for future-proof legislation makes democratic control over post-enactment decision-making essential. Absent an adversarial actor capable of challenging the system’s interpretation and internal rules, episodes such as the deployment of spyware by the Israel Police, or the use of license-plate recognition systems without statutory authorization, are liable to recur. Addressing the resulting democratic deficit requires transparency, reporting obligations, and proper oversight mechanisms with real teeth, capable of scrutinizing secret legal interpretations and internal rules and guidelines, to serve as the citizenry’s own future-proofing against future-proof legislation.

Suggested citation: Amir Cahane, Future Proofing Surveillance Law in Israel: On Emerging Technologies and the ISA Law Amendment Memorandum, Int’l J. Const. L. Blog, Jul. 18, 2026, at: http://www.iconnectblog.com/future-proofing-surveillance-law-in-israel-on-emerging-technologies-and-the-isa-law-amendment-memorandum/

Leave a Reply