Summary

  • The IGF's 2026 Policy Network on Cybersecurity carries forward a 2025 proposal to explore a multistakeholder mechanism that could help deploy, restore and maintain civilian Internet access during conflicts and crises.
  • The official event record scheduled the network's first planning meeting for 4 September to discuss its focus, working methods and annual work plan. The checked public record does not establish that an operating mechanism has been created.
  • The IGF convenes discussion and transmits outputs; it does not produce negotiated decisions. Any executable act still needs authority from the government, operator, humanitarian body, funder or technical institution that controls it.
  • Daniel Kade proposes an activation ledger joining the request, evidence, authority, offer, decision, execution result, redaction and exit. A refusal or an inability to identify authority is a reportable outcome, not an empty space.
  • Transparency must be safe. Live routes, facilities, credentials and vulnerable people may need restricted annexes or delayed disclosure, while the existence and reason for each redaction remain visible.

The request arrives before the mechanism exists

Imagine an aid organisation reports that hospitals in a conflict-affected district have lost data links. A satellite provider can offer capacity. A local operator knows which towers still have power. A civil-society group can document affected communities. A government controls spectrum and border permissions. A donor can pay for terminals, but only under its own conditions.

That is enough to hold a meeting. It is not yet enough to reconnect anyone.

Who authenticates the request? Does it cover a hospital network, humanitarian staff or the wider civilian population? Who decides whether publicizing the outage will help or expose repair crews? Can the offered capacity lawfully operate in the territory? Who possesses the credentials, equipment and local relationships needed to turn bandwidth into usable access? If an actor declines, who records the reason and searches for another route? And when the immediate danger passes, who removes equipment, transfers service and deletes sensitive data?

The IGF's 2026 Policy Network on Cybersecurity has inherited precisely this class of problem. Its public page describes an effort to protect civilian access, strengthen core Internet infrastructure, connect human-rights and humanitarian-law considerations, and improve multistakeholder responses. One of its three strands is the exploration of a rapid-response mechanism to secure or restore connectivity in crisis settings.

The news is the continuation, not completion, of that work. The official event record for the first planning meeting scheduled a call for 4 September 2026 at 12:00 UTC to discuss thematic focus, agree working modalities and begin an annual work plan. The network page displayed 3 September when this Article was researched. That discrepancy should not be inflated into a governance failure, but neither date authorizes a claim about a meeting outcome. No reviewed source says that a mechanism was adopted, housed, funded or activated.

A Best Practice Forum became a Policy Network

The institutional change is real. The Multistakeholder Advisory Group approved four Policy Networks for 2026 after reviewing more than 60 community proposals. They cover artificial intelligence, cybersecurity, digital inclusion and open digital infrastructure. The MAG also supported bringing the Policy Network and Best Practice Forum formats into one Policy Network framework with a best-practice component.

For crisis connectivity, that means the 2025 Best Practice Forum's unfinished design question now has a year-round home. The final 2025 BPF report concluded that disruptions can cut civilians off from vital information, health services, emergency assistance and livelihoods. It said unclear roles and responsibilities hinder response and identified three areas for further work: an emergency-connectivity mechanism, a closer account of human-rights and humanitarian-law frameworks, and a stronger understanding of multistakeholder responsibilities before, during and after crises.

The proposed mechanism is deliberately plural. The report names governments, humanitarian agencies, technical experts, private providers and civil society. It says no single actor can solve the political, regulatory, administrative, safety, technical and funding problems. It also says current approaches differ in mandate and reach: some focus on natural disasters, some serve humanitarian organisations rather than mass civilian access, and some small civil-society interventions distribute tools or eSIMs.

That diagnosis is stronger than a promise to coordinate. It recognizes that the missing object is not another universal command centre. It is a way to join distinct capabilities without pretending that participation in a coalition transfers the powers behind them.

The IGF can design the table, not operate every lever

The IGF's own institutional description is unusually clear: it brings stakeholder groups together for digital-policy discussion, does not produce negotiated outcomes, and transmits its outputs to public and private actors with decision-making power.

This boundary protects the proposed work from two opposite errors. The first is dismissal: because the IGF cannot order a network to reconnect, its process is said to be useless. That misses its capacity to place governments, operators, humanitarian bodies, affected communities and technical institutions around one design problem before the next emergency.

The second error is inflation: because the IGF convened the design, a future coalition is treated as though it already possesses the authority of every participant. It does not. A regulator can authorize spectrum within its law. An operator can configure assets it controls. A humanitarian body can act under its mandate and access arrangements. A donor can commit its own funds. A registry can protect the integrity of its records. None receives the other's power merely by joining the same call.

An activation record should therefore attach a separate authority to every executable verb. Discuss, recommend, offer, license, fund, deploy, route, repair, measure and terminate are not synonyms. A mechanism that leaves this distinction implicit will discover it at the worst time: after urgency has compressed review and after an unsuccessful intervention has created harm that no participant believes it owned.

Activation is a distribution decision

The word emergency can make activation sound mechanical. A threshold is crossed; the team responds. In connectivity crises, the threshold is itself a decision about distribution and risk.

Restoring one hospital link may be feasible while mass access is not. A link to a humanitarian compound may protect aid workers yet leave surrounding residents offline. A technically open service may be unaffordable, unsafe to approach or usable only with devices that residents do not have. Providing a new route may improve civilian access while also changing the information or security position of parties to a conflict. Publishing the route may attract attack. Hiding every detail may make claims impossible to test.

The 2025 BPF report acknowledges that the basic terms still need refinement. Civilian access may mean access to particular essential services rather than an abstract Internet connection. Safe access and reliable access are separate dimensions. Core Internet resources can refer narrowly to DNS, addressing and routing, or more broadly to the institutions and supply chains that sustain continuity. Conflicts, natural disasters and local crises bring different actors and constraints.

An activation rule cannot make those differences disappear. It can make the judgment visible. It should state what harm is alleged, whose access is at issue, what service is requested, which facts are verified, what remains unknown and what trade-off the decision maker accepted. That record disciplines urgency without pretending to eliminate it.

Seven entries in the activation ledger

I would require seven linked entries before a future coalition describes itself as operational. This is an editorial proposal, not an adopted IGF requirement.

1. Request receipt. Record the requesting party, the people it is authorized to represent, the time, affected geography, claimed disruption, essential services at risk, evidence sources and exact assistance requested. A message from a well-known institution is still not proof that it speaks for every affected user.

2. Triage record. Separate observed facts from reports and estimates. Record confidence, urgency, likely civilian benefit, foreseeable harm, technical feasibility, local knowledge, objections, safety constraints and jurisdictional questions. If direct consultation with affected people is impossible, say so instead of manufacturing consent.

3. Authority map. For each proposed act, name the principal that controls the necessary permission or asset, the executor, and the statute, licence, contract, operating policy or mandate relied upon. No competent authority identified must be available as a conclusion. An honest stop is safer than authority inferred from attendance.

4. Offer and conflict register. Capacity, terminals, fuel, power, transport, engineers, funding and measurement can arrive from different parties. Record scope, expiry, provider conditions, data access, relevant interests and dependencies on parties to the crisis. An offer is not an authorization and a donation is not control of the response.

5. Decision receipt. Mark the request accepted, declined, deferred or referred. Identify the decision maker, time, reasons, safeguards, review deadline and next responsible actor. Silence matters: a system that publishes successes but loses refusals cannot reveal whether its bottleneck is law, money, risk, capacity or institutional caution.

6. Execution and outcome record. State what was actually done, by whom and when. Separate equipment delivered, capacity made available, service activated and access used. Report the intended population, coverage conditions, reliability, safety, affordability, outages and independent observations. Correct earlier claims rather than overwrite them.

7. Exit and handoff. Define the termination condition, reauthorization interval, custody of equipment and credentials, local handoff, data retention, removal obligations and post-action review. Emergency coordination must expire. Otherwise a temporary response can become an unreviewed transfer of operational control.

These entries need stable identifiers and a change history. A later action should point back to the request and authority it claims to satisfy. If an institution substitutes a different action, the record should preserve both the original request and the reason for divergence.

Public does not mean exposed

A crisis ledger that reveals a live backhaul route, terminal position, repair movement, administrator credential or vulnerable person's identity could convert accountability into targeting information. Safe transparency therefore needs at least two layers.

The public layer can show that a request exists, its broad geography and service purpose, its state, the institutions responsible, the kind of authority used, aggregate outcomes, the reason class for any refusal, and the next review. A protected annex can hold precise topology, personal information, security analysis and evidence whose release would create a foreseeable danger.

Redaction should leave its own receipt: which field is withheld, who holds it, why, when the restriction will be reviewed and what condition permits release. A hash can later show that the protected record was not rewritten to suit the outcome. Delayed disclosure can expose the reasoning after the operational risk passes. Aggregation can report performance without identifying households or facilities.

This is not maximal transparency. It is accountable restraint. The alternative choices—publish everything or publish nothing—both serve the institution better than the affected public.

Measure access, not equipment

A response can succeed logistically and fail socially. Ten terminals may arrive but remain boxed at customs. Capacity may be donated but lack local power. A network may become reachable but too dangerous to use, too expensive, congested at essential hours or inaccessible to people with the wrong device or language.

The result record should therefore distinguish inputs from civilian outcomes. Useful measures include the population and services intended, service hours, practical availability, latency and loss for the named application, full user cost, device availability, safety constraints, complaint routes, repair time and the number of attempted activations that failed. No single global threshold fits a hospital circuit, community access point and household service. The measurement contract can vary while the evidence categories remain comparable.

The proposed IGF 2026 workshop on connectivity in crises is framed around unpacking, building and validating the idea. That is the right posture. Before selecting hardware or an institutional host, the network can test the ledger against past cases: could the record have distinguished a legitimate request from an unauthorized one, found the actual blocker, protected sensitive facts, and shown whether civilians obtained usable access?

Sources