Policy & Regulation

Policy & Regulation / Recently Commented

The EU Cyber Resilience Act Regime: A Failure to Know Your Limitations

A cybersecurity historian argues the EU Cyber Resilience Act overreaches through unworkable mandates, sprawling jurisdiction and outdated assumptions, urging a streamlined successor that embraces AI, existing standards and practical enforcement instead of bureaucratic complexity today. more

Who Registers the Domain That Steals Your Data? The Registrar Accountability Gap in India’s DNS Abuse Crisis

India's DNS abuse crisis exposes a registrar accountability gap: malicious domains remain online while vulnerable users bear the cost. Concentrated abuse patterns suggest stronger oversight and faster mitigation could significantly reduce predictable harms nationwide today. more

The Algorithmic Ceiling: How AI Surveillance Criminalizes Disability

AI surveillance systems increasingly classify human differences as algorithmic risk, leaving persons with disabilities vulnerable to exclusion, misclassification, and invisible barriers that threaten decades of progress in accessibility, accountability, and digital inclusion throughout public infrastructure. more

The Question Isn’t Whether the Harm Is Real - It’s Who Should Act

Measuring online abuse can reveal its scale, but not who should intervene. Effective policy must distinguish harm from contractual responsibility, identify the actors best placed to act, and target remedies where they can work effectively. more

Community Networks Offer a Durable Route Across the Digital Divide

An ITU report finds that community-owned networks, backed by reliable technology, flexible financing and supportive regulation, can bring affordable, meaningful internet access to remote populations that traditional providers have struggled to reach at lasting scale. more

Shaping the Future of the IGF: Integration, Relevance and Impact in the Post-WSIS+20 Era

The Internet Governance Forum has secured its permanent place in the UN system. Its next challenge is to strengthen its relevance, deepen multistakeholder collaboration, and deliver greater impact across an increasingly complex and fragmented digital governance landscape. more

UK Unveils AI Cyber Shield to Counter Machine-Speed Digital Threats

Britain is developing Cyber Shield, an AI-powered national cyber defense program designed to detect threats, automate responses and protect critical infrastructure as increasingly sophisticated attacks challenge conventional security and strain existing defensive capabilities. more

IP Geolocation: The New Infrastructure for Internet Interoperability

IP geolocation has evolved from routing metadata into essential Internet infrastructure, enabling compliant content delivery, cybersecurity, and digital governance while raising urgent questions about transparency, interoperability, and fragmentation risks worldwide for policymakers and providers alike. more

Spain to Require Four Hours of Mobile Service During Power Blackouts

Spain will require telecom operators to keep mobile networks running for up to four hours during power outages, introducing phased resilience standards, stronger emergency communications safeguards and stricter backup requirements for critical digital infrastructure. more

When AI Writes the Scam: How Artificial Intelligence Is Making DNS Abuse Harder to Detect

Artificial intelligence is transforming phishing and DNS abuse, erasing the linguistic clues that once exposed scams. As attacks become personalised, automated and multilingual, governance frameworks are struggling to keep pace with a rapidly expanding threat surface. more

CENTR Warns Against Excessive Burdens in EU Cybersecurity Overhaul

Europe's national domain registries support the EU's Cybersecurity Act 2 but warn that supplier restrictions, overlapping compliance rules and broad supply chain definitions could undermine critical internet infrastructure and burden essential service operators. more

UDRP Review Is a Test of the MSM

As ICANN confronts a harsher geopolitical era, its long-delayed review of the UDRP has become a defining test of whether the multistakeholder model can still deliver legitimate, effective Internet governance and sustain confidence in its future. more

Starlink and Amazon Could Gain Access to Europe’s Satellite Airwaves

The European Union plans to reserve most future satellite spectrum for regional firms while still allowing Starlink and Amazon to compete, reflecting Brussels' attempt to balance technological sovereignty with market openness in a strategically sensitive communications sector. more

dotBrand Domains as Trust Infrastructure in the Age of AI

As AI agents automate phishing, impersonation and domain abuse at machine scale, the Brand Registry Group argues that dotBrand domains are evolving from marketing assets into trust infrastructure underpinning cybersecurity, identity and interactions across the internet. more

Time Sovereignty: Internet Policy and Defense Frameworks for Critical Infrastructure Synchronization Under Geopolitical Conflict

As power grids depend on microsecond precision, states must treat time synchronization as sovereign infrastructure, hardening satellite, fiber and orbital defenses against hybrid attacks that could trigger catastrophic blackouts through resilient sovereign time defense frameworks. more