Summary

  • Internet Society’s 10 July 2026 resolution did not describe a new fiduciary duty. It added obedience to the policy’s introductory list because the 2016 body already called it a third duty.
  • In the operative policy, obedience means fidelity to Internet Society’s mission and avoidance of acts outside its Articles of Incorporation or applicable law. It does not mean personal obedience to management, a Board chair or a voting bloc.
  • Trustees arrive through four selection channels, but both policy and bylaws say they serve Internet Society as a whole. Selection creates an office; it does not preserve a constituency’s instruction mandate after seating.
  • A public mission-authority receipt could show how a material Board act connects to purpose, governing authority, independent judgment, implementation and later review without publishing privileged advice or pretending to adjudicate legality.

The edit changed the map, not the territory

On 10 July 2026, the Internet Society Board approved four governance-policy actions by unanimous written consent. The part relevant here is Resolution 2026-14. It approved revised Fiduciary Obligations of Trustees with immediate effect. The resolution is unusually precise about what changed: the Governance Committee added the duty of obedience to the introductory paragraph “to align with the body of the policy,” clarified that the enumerated examples of fiduciary duties are illustrative, and made minor copy edits.

That description matters. A headline saying the Board “imposed a new obedience duty” would be more dramatic and less accurate than the institutional record. The current fiduciary policy now says in its opening that D.C. law codifies the common duties of care, loyalty and obedience. But the earlier 5 May 2016 policy PDF already devoted a paragraph to “a third duty” generally called the duty of obedience. Its introductory paragraph named only care and loyalty. The mismatch sat on the same page.

The Board formally accepted that 2016 version through Resolution 2016-32. The institutional lineage reaches farther back: minutes from June 2002 record a presentation on Trustee fiduciary obligations based on D.C. nonprofit law. Those minutes do not expose the old presentation, so they cannot prove its exact wording. They do show that fiduciary duty was not invented for the 2026 editing cycle.

The defensible state history is therefore narrow. In 2016, the public policy’s body included three duties while its opening summary listed two. In 2026, the Board said it corrected that internal asymmetry. A wording alignment can still be consequential: readers who stop at the first paragraph now receive a more complete map. But better discovery of an existing rule is not the same event as creating the rule.

This distinction protects both accountability and institutional memory. If every clarification is narrated as a new power, an organisation can appear to manufacture authority through copy editing. If every clarification is dismissed as cosmetic, a misleading public interface never receives credit for repair. The record should preserve both states: the duty already existed in the body; the opening became accurate on 10 July 2026.

“Obedience” has an object

The term is vulnerable to a familiar linguistic trap. In ordinary speech, obedience suggests a subordinate following the order of a superior. That is not how Internet Society’s policy defines the duty. It says Trustees must act with fidelity to ISOC’s mission and avoid ultra vires acts—actions not permitted by the Articles of Incorporation—or violations of applicable law.

The object of obedience is therefore not a person. It is a bounded institutional purpose and authority perimeter. The Articles of Incorporation organise Internet Society for educational, charitable and scientific purposes. They name Internet-related activities such as supporting technical evolution, educating communities, promoting educational applications and providing a forum for exploration and collaboration. Those clauses leave room for strategy. They do not give every officeholder an unlimited warrant to redescribe any activity as mission-serving.

The distinction becomes clearest where management and fiduciary judgment meet. The current policy says that even if management endorses a proposed action, a Trustee should independently determine and reasonably believe that it is in Internet Society’s best interests before approving it. Obedience cannot mean obeying management when the same policy expressly requires independent judgment about management’s proposal.

Nor does it mean obeying the chair. A chair can organise a meeting, frame an agenda and perform authority granted by bylaws or policy. The chair does not become the beneficiary of every Trustee’s fiduciary duty. A Board majority can produce a corporate act when quorum and voting rules are satisfied; the vote record answers who authorized the act through the corporate mechanism. It does not, by itself, prove that every material fact was known, every conflict handled, every purpose boundary respected or every legal question correctly resolved.

That is not a claim that a particular Internet Society decision failed. It is the architecture of the policy itself. Procedure establishes the act. Fiduciary discipline asks how those holding the office exercised the act-making power.

Four doors into one office

Internet Society’s Board is intentionally assembled through different institutional routes. The current bylaws provide for four Trustees elected by Organizational Members, four elected by Chapters, four appointed by the IETF and up to three appointed by the Board. The selection procedures explain the mechanics of those categories.

Plural selection can improve information and legitimacy. Chapters may surface local experience. Organizational Members may bring operating and institutional knowledge. IETF appointments can carry technical-community perspective. Board appointments can fill a capability gap. But the route into the room does not define the legal beneficiary of the office once the Trustee sits down.

The bylaws state that Trustees serve in the interest of Internet Society as a whole. The fiduciary policy is even more explicit: the duties are owed to ISOC and all its constituents, not just the group that elected or appointed a Trustee. It would be inappropriate, the policy says, to evaluate a proposed decision by considering only the selector’s interests.

This is a subtle separation between input and mandate. A selecting constituency retains every legitimate means to express preferences, evaluate performance and use its next selection opportunity. What it does not receive is a private instruction channel that converts its Trustee into a delegate bound to one caucus. The seat is institutionally sourced but not privately owned.

The same logic prevents the word obedience from being weaponised in the opposite direction. A Trustee cannot answer a mission question merely by saying that the group which selected the Trustee demanded an outcome. Nor can management answer it by saying that the Board majority approved. Neither selection provenance nor vote success replaces the purpose-and-authority analysis.

What the public law record does—and does not—say

Internet Society’s policy attributes its framework to the District of Columbia Non-Profit Corporation Act and related D.C. cases. The public text of D.C. Code § 29-406.30 requires a director to act in good faith and in a manner reasonably believed to be in the nonprofit corporation’s best interests. It establishes an appropriate-care standard, a duty to disclose material information to fellow decision-makers subject to protected exceptions, and conditions under which a director may rely on officers, experts or committees.

That section does not use the phrase “duty of obedience.” It would be inaccurate to put those words in the statute’s mouth. The current Internet Society policy describes the broader legal foundation as the Act plus related cases, then supplies its own concise formulation. This Article reports that formulation; it does not issue a legal opinion about the full content of D.C. fiduciary law.

Federal tax guidance adds another, separate perimeter. The Internal Revenue Service’s Form 1023 guidance explains why a charity should manage conflicts and operate consistently with its charitable purposes rather than serve private interests. That is useful context for understanding why mission fidelity is not decorative. It is not evidence that Internet Society has violated tax law, endangered its status or misclassified any programme.

These source limits are part of sound governance analysis. A public policy is evidence of the rule Internet Society says governs its Trustees. A resolution is evidence that the Board adopted specified wording. A statute is evidence of its enacted text. None of those records, alone, establishes the facts and legal outcome of a hypothetical dispute.

A mission is a boundary, not a magic word

Mission language can constrain power only if a decision record connects it to an actual mechanism. Otherwise, “consistent with mission” becomes a ceremonial phrase appended to any proposal after the choice has already been made.

The problem is not solved by demanding that every Board resolution publish counsel’s advice. Legal privilege, personnel privacy, contractual confidentiality and security needs can all justify withholding particulars. The more useful demand is smaller: make the public institutional reasoning joinable without pretending that protected material does not exist.

A material act could carry a mission-authority receipt. The receipt would name the corporate actor—Internet Society Board, a delegated committee, an officer or another body—and the decision route used. It would identify the operative versions of the Articles, bylaws and relevant policy. It would cite the purpose clause relied upon and the source of decision authority. Where advice is protected, it could record that advice was obtained and its authority class without disclosing content.

The receipt would then separate proposal from judgment. Management, a committee or a constituency may originate the proposal. The Board’s record should identify its own decision state rather than letting the proposer’s recommendation impersonate approval. Conflict, recusal and abstention states should be recorded at the level that policy and privacy permit. Implementation belongs to a named office with an effective date, while later review belongs to a clock and a competent reviewer.

Most importantly, the receipt should permit unknown, not public and not applicable. An omitted legal rationale must not be invented. A confidential record must not be described as nonexistent. A purpose clause cited by the Board proves the Board’s classification, not a court’s final agreement. If a later decision corrects the classification, the new receipt should link to the old one instead of silently overwriting it.

This is the practical application of Lu Heng’s Policy Mirror: public labels should mirror bounded authority and real state rather than expand them. In this case the first mirror is the policy’s own opening. The 2026 edit made that mirror more faithful by naming the third duty already present below. The next mirror is decision-level: show how an act passes from mission and authority to approval, execution and review.

Independence is not isolation

Requiring independent judgment does not require Trustees to ignore expertise. D.C. law permits bounded reliance on reliable officers, employees, counsel, accountants and committees when the director has no knowledge making that reliance unwarranted. Internet Society’s policy similarly tells Trustees to consider expert legal, financial or other advice.

Independence means that the officeholder remains responsible for the judgment the office requires. It does not mean becoming one’s own lawyer, auditor and technical specialist. A Trustee may depend on expertise without transferring the identity of the decision-maker to the expert. The expert supplies analysis; the competent organ decides.

This distinction also disciplines public criticism. A consultant’s report does not prove that the consultant controlled the Board. A unanimous vote does not prove that every question was uncontested. A dissent, if one existed, would not itself prove that the majority acted outside the mission. Governance evidence should show roles and transitions before assigning motives.

Eleven sources, eleven limits

The evidence chain for this analysis is deliberately finite: the 2026 written-consent record, the current policy, the 2016 PDF, the 2016 adoption minutes, the 2002 minutes, the bylaws, the Articles, the selection procedures, the D.C. statute, the IRS guidance and the Policy Mirror.

They support a textual and institutional conclusion, not a misconduct finding. The public record does not expose the Governance Committee’s full comparison draft, every legal memorandum, each Trustee’s individual reasoning or a case in which the amended wording was applied. Those gaps weaken any claim about intent or effect. They do not erase the visible before-and-after difference.

The restrained conclusion is stronger than the dramatic one. Internet Society did not publicly announce that Trustees had suddenly acquired a command to obey. It repaired an opening paragraph so it would acknowledge a mission-bounded duty already described in the policy’s body. Reading the word with its stated object turns an authoritarian-sounding label into a control on institutional power.