Internet governance is a coordination framework that shapes how the global network is developed, managed, and used through technical standards bodies, intergovernmental treaties, and multistakeholder processes. Which model prevails determines whether a single government can fragment the domain name system (DNS), whether treaty organizations gain authority over internet technical standards, and whether the open multistakeholder governance structure built through the WSIS process survives intact.
What Internet Governance Is and Why It Matters

Internet governance spans three distinct coordination layers, each contested by different actors and governance philosophies.
- Technical coordination layer
- Managing critical internet resources as defined in paragraph 35 of the WSIS Tunis Agenda: DNS root zone management, IP address allocation through Regional Internet Registries (RIRs), and protocol parameter registries. coordinated by ICANN under the multistakeholder model, with the IANA functions transition (2016) cementing community accountability in place of US government oversight.
- Policy and regulatory layer
- National and international rules governing internet access, content, and commerce. The contested space between the multistakeholder model, the intergovernmental model, and hybrid frameworks such as the EU Digital Services Act. Laws on data localization and digital sovereignty live here, intersecting with but not controlling the technical layer above.
- Norms and values layer
- The informal principles advancing open standards, the net neutrality principle, and freedom of expression online. Advanced by civil society organizations including the Electronic Frontier Foundation (EFF) and debated at the Internet Governance Forum (IGF). Non-binding but operationally significant: norms shape national regulation and ICANN policy even without formal legal authority.
Understanding which actors control which layer clarifies why jurisdictions reach conflicting conclusions about internet regulation. A government asserting digital sovereignty over content does not automatically gain authority over DNS infrastructure. The separation is structural, not incidental.
The Multistakeholder Model: How ICANN, IETF, and IGF Operate
Internet governance under the multistakeholder model distributes authority across four stakeholder groups: governments, the private sector, the technical community, and civil society. No single group holds a veto. Decision-making follows participation and consensus rather than treaty ratification. Three principal institutions operationalize this architecture.
| Institution | Mandate | Decision-making Process | Binding Authority |
|---|---|---|---|
| ICANN (Internet Corporation for Assigned Names and Numbers, incorporated 1998) | Coordinates global uniqueness of the domain name system, IP address allocation through RIRs (ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC), and protocol parameter registries | Supporting Organizations (GNSO for generic TLDs, ccNSO for country-code TLDs, ASO for address policy) and Advisory Committees (GAC for governments, ALAC for at-large users, SSAC for security); decisions require community consensus | Binding on contracted parties (registries, registrars); not binding on sovereign governments. Post-IANA functions transition, accountability runs through the Empowered Community mechanism, not the US NTIA |
| IETF (Internet Engineering Task Force, chartered 1986) | Develops internet technical standards through the RFC (Request for Comments) process; open to any individual who contributes technically | Rough consensus and running code, not formal votes or treaty ratification; working groups organized around specific protocols (TCP/IP, HTTP, TLS, BGP, DNS protocol) | Voluntary; IETF standards become de facto mandatory through universal adoption. No government approval required. The technical community's consensus model prevents veto rights from entering the standards process |
| IGF (Internet Governance Forum, established 2005 under WSIS Tunis Agenda paragraph 72) | Multistakeholder dialoge under UN auspices; a 12-month intersessional program plus annual global meeting; renewed through 2025 by UNGA Resolution 70/125 | Open participation; produces best-practice forums, dynamic coalition outputs, and chair's summary documents; no formal voting | Non-binding. The IGF's non-binding character is its defining architectural feature and the primary criticism from intergovernmental model advocates seeking treaty-based decision-making authority |
The IANA functions transition (completed October 2016) marks the most significant structural change since ICANN's founding. The US National Telecommunications and Information Administration (NTIA) relinquished its oversight role over the IANA functions, transferring accountability to the global multistakeholder community via the Empowered Community mechanism. Root zone management now operates without a government principal above ICANN in the accountability chain. The transition demonstrated that multistakeholder governance can replace government oversight without fragmenting the DNS.
For the compliance context where national privacy law intersects with these governance structures, see the CCPA vs. GDPR comparison.
The Intergovernmental Model: ITU Authority and State-Led Governance
Internet governance through the intergovernmental model concentrates decision-making authority in sovereign governments acting through treaty organizations, with the International Telecommunication Union (ITU) as the primary institutional vehicle. Founded in 1865 as the International Telegraph Union and now a UN specialized agency with 193 member states, the ITU holds mandates over radiocommunication, standardization, and development. Its ITU-T body produces technical recommendations referenced in national regulations, though these differ structurally from IETF RFCs: they require member-state ratification rather than rough consensus from the technical community.
The 2012 World Conference on International Telecommunications (WCIT-12) exposed the model's fault line. Russia, China, and allied states proposed treaty amendments that would extend ITU authority over internet routing and content. The US, EU member states, and the technical community rejected the proposals as an attempt to impose intergovernmental control over a multistakeholder-governed infrastructure. When the revised International Telecommunication Regulations came to a vote, 89 of 193 ITU member states signed; 55 states (including the US and EU members) refused.
Four characteristics distinguish the intergovernmental model from its multistakeholder counterpart:
- Treaty-based authority: International decisions made by sovereign governments through the ITU treaty process, binding on signatory states rather than on contracted technical parties.
- State control emphasis: Member states assert the right to filter, block, or reroute internet traffic under digital sovereignty claims, treating internet infrastructure as an extension of sovereign telecommunications policy.
- Content regulation focus: Intergovernmental proposals frequently include provisions enabling member states to regulate internet content transmitted across borders, a scope the multistakeholder model reserves for national law operating above the technical layer.
- Economic redistribution dimension: Some ITU member states have proposed "Sending Party Network Pays" (SPNP) arrangements requiring large content providers to pay national telecom operators for traffic termination. These proposals are contested as incompatible with the net neutrality principle, which holds that internet service providers must treat all traffic equally regardless of source, destination, or content type.
Russia's 2019 Sovereign Internet Law (RuNet) and China's Great Firewall are national implementations of digital sovereignty that follow the intergovernmental model's logic without requiring a binding ITU treaty. Both assert state authority over critical internet resources operating within national borders, including DNS resolution paths and traffic routing.
Hybrid and Emerging Governance Frameworks
Internet governance increasingly operates through hybrid frameworks that combine elements of the multistakeholder model and intergovernmental authority, producing different balances of openness and state control across jurisdictions. Three approaches have defined governance practice in recent years.
| Approach | Exemplar Jurisdiction / Mechanism | Stakeholder Balance | Key Characteristics |
|---|---|---|---|
| Regulatory multistakeholderism | European Union (GDPR, Digital Services Act, Digital Markets Act) | EU legislative authority over services and platforms; ICANN DNS governance and IETF protocol standards preserved beneath the regulatory layer | Governs outcomes (what platforms may do with data, what content is lawful) rather than infrastructure. Does not challenge root zone management or IP address allocation. Digital sovereignty in the EU context means strategic autonomy from non-EU platforms, not state control of routing |
| Splinternet via national routing controls | Russia, China, Iran | State authority dominates; standards community and civil society operate under licensing and censorship constraints | National DNS filtering, traffic routing through state-controlled chokepoints, and platform licensing create effectively partitioned user experiences. Does not formally exit global internet technical standards but insulates national users from the open internet in practice. The intergovernmental approach operationalized unilaterally |
| Forum-based soft governance | IGF, NETmundial (2014, Sao Paulo), WSIS+10, Global Digital Compact (UN Summit of the Future, September 2024) | Open multistakeholder participation; EFF and civil society coalitions central to norm development | Non-binding outputs (principles, best practices, chair summaries) that shape national regulation and ICANN policy without formal legal authority. The Global Digital Compact attempted to reconcile multistakeholder governance and intergovernmental perspectives on ICANN's DNS coordination mandate, with contested outcomes on scope |
The EU model demonstrates that strong national regulation can coexist with multistakeholder governance of the technical layer. The splinternet model demonstrates that digital sovereignty claims, pursued far enough, produce a partitioned experience even without treaty authorization.
Challenges in Current Internet Governance
Internet governance faces four structural challenges that no single governance model has resolved. The ordered list below maps each challenge to the institutional actors responsible and the mechanisms in use.
- Coordination without enforcement authority. The multi-stakeholder approach's strength is inclusive participation across governments, private sector, the IETF community, and civil society. Its structural weakness is that ICANN and the IGF lack enforcement mechanisms against states that unilaterally override DNS policy or impose data sovereignty controls. Root zone management remains coherent only because major actors comply voluntarily. A sufficiently large state coalition operating alternative root zones would fracture DNS global uniqueness without triggering any formal governance response.
- Accountability gaps in technical bodies. IETF and ICANN have internal accountability mechanisms (the IANA Stewardship Transition Coordination Group, the Empowered Community for ICANN, the NomCom process for IETF leadership selection) that are opaque to non-specialist stakeholders. Developing-country civil society groups and governments lack the technical capacity and organizational resources to participate effectively in Supporting Organizations or IETF working groups, raising representational legitimacy questions that the state-led approach exploits in treaty forums.
- Jurisdictional fragmentation of the regulatory layer. National legislation (GDPR, CCPA, China PIPL, India DPDPA, Russia 242-FZ) imposes conflicting requirements on globally operating services. The technical internet remains globally interconnected while the regulatory layer fractures by jurisdiction. Protections for biometric data and digital rights illustrate the gap: the governance architecture has no mechanism for resolving conflicts between internet technical standards and national content or data law.
- Cyber norm development running in parallel. States dispute what norms should govern offensive cyber operations, infrastructure protection, and surveillance. The UN Group of Governmental Experts (UNGGE) and Open-Ended Working Group (OEWG) processes represent intergovernmental norm development running alongside the multistakeholder internet governance forums. Both the 2021 OEWG report and the 2021 UNGGE report produced non-binding frameworks governing state behavior in cyberspace without resolving the underlying governance model question: whether ICANN's coordination authority over critical internet resources should be expanded, contracted, or placed under treaty supervision.
Best Practices and the Path Forward for Internet Governance
Internet governance reform proposals converge on several operational principles even where advocates of the multistakeholder approach and treaty-based approach disagree on institutional structure. The five principles below draw from EFF policy positions, IGF best-practice forums, and ICANN accountability frameworks.
- Preserve DNS technical coordination under multistakeholder accountability. The IANA functions transition demonstrated that multistakeholder governance can replace government oversight without fragmenting root-zone control or IP address allocation. Extending this model to emerging coordination challenges (IPv6 deployment, new gTLD policy rounds) is more structurally stable than expanding ITU treaty authority into the technical coordination layer.
- Expand meaningful participation from underrepresented stakeholders. Developing-country civil society, indigenous communities, and non-English-speaking technical communities are structurally underrepresented in ICANN Supporting Organizations and IETF working groups. The IGF's intersessional national and regional IGF program is the current capacity-building mechanism; its mandate and resourcing should reflect that gap.
- Align national regulation with the net neutrality principle and open internet protocol standards. National content regulation and data localization laws are legitimate state prerogatives but should not require technical changes to DNS infrastructure or BGP routing that fragment the global network layer. The EU regulatory multistakeholder approach offers a workable template: regulate services, not infrastructure protocols.
- Use forum-based processes for norm development rather than ITU treaty expansion. Non-binding dialoge through the IGF and NETmundial-style forums produces faster, more adaptive outputs than treaty ratification processes. The Global Digital Compact model and the IGF successor mandate beyond 2025 should be evaluated against this criterion before any scope expansion into ICANN's coordination mandate.
- Maintain the IETF's open participation and rough-consensus standard. Routing IETF technical standards through ITU-T treaty processes would introduce government veto rights incompatible with the engineering community's consensus model and slow standardization in ways that benefit incumbent operators over open protocols. The ICANN accountability structure and IETF's open process remain the most tested mechanisms for coordinating global digital infrastructure.
For the compliance dimension where these governance principles meet national privacy law enforcement, see the CCPA vs. GDPR analysis.
Further reading
- ICANN: How ICANN Works and the Multistakeholder structure
- ITU: About the International Telecommunication Union
- IETF: The Internet Standards Process
- UN Internet Governance Forum: About the IGF
- Electronic Frontier Foundation: Internet Governance and Digital Rights
- WSIS Tunis Agenda for the Information Society (paragraphs 35 and 72)
- Challenges in Implementing Right To Be Forgotten: GDPR Article 17 in Practice
- Digital Divide: Policy Solutions For Internet Access
- EU AI Act vs US AI Regulation: A Compliance Framework Comparison
See also NIST Cybersecurity Framework (internet governance touchpoints).









