Summary

  • NRS's role in this subject is advocacy, research, campaigning, convening and authorized member representation. The operational acts belong to resource holders, RIRs, IANA numbering services, courts and qualified successor operators; citing an NRS position is neither evidence that NRS performs them nor an endorsement by BTW.
  • Internet number resources are globally coordinated identifiers, not political territory. Geography has been a practical way to divide registration responsibility, but it is not an intrinsic property of an address block or autonomous system number and should not become an irrevocable claim over the holder's service relationship.
  • The registry operator should preserve one global authoritative state while allowing a recognized holder to select any qualified registration-service provider. The provider may validate, support and submit changes; it may not create a second allocation history or publish a competing current holder.
  • Choice should follow operational need: multinational footprint, language, time-zone coverage, continuity, accessibility, security capability, governing-law preference and cost. A holder should not have to reorganize its network or invent a local presence merely to obtain suitable service.
  • Jurisdiction still matters, but it should attach transparently to the provider contract, holder, conduct, evidence and affected operations rather than being disguised as geography embedded in the resource. Conflicting legal demands require notice, narrow treatment, review and continuity safeguards.
  • A common authority layer must maintain unique resource identity, ordered versions, holder continuity, transfer history, provider identity, restrictions and verifiable change receipts. Providers compete above that layer and converge on its accepted result.
  • Public institutions, essential services and small networks need portable registration most when a regional provider fails, becomes inaccessible or no longer fits their operating reality. Exit rights, continuity copies and emergency substitution turn service choice into resilience rather than a privilege for large companies.
  • Success is measured by safe switching, record accuracy, provider diversity, continuity and correction quality, not by the number of institutions claiming authority. The registry model ends captivity only if it makes choice real while preventing duplicate recognition, hidden transfer and jurisdictional evasion.

The role boundary is part of the evidence

NRS's own stated positioning supplies the first boundary for this analysis. It is a membership and advocacy organization pressing for decentralization, exit, portability, redundancy and fewer discretionary choke points. Heng Lu's note on why NRS exists says directly that NRS does not sell products or implement commercial solutions; its role is to change the direction of governance. NRS may therefore publish research, organize campaigns, convene affected operators, support members and represent an organization that has granted it authority. It may not turn that representation into registry authority over anyone else.

The implementation layer is separate. resource holders, RIRs, IANA numbering services, courts and qualified successor operators remain responsible for any authoritative registry record, allocation, transfer recognition, RPKI or RDAP operation, technical failover, binding review, insolvency act or legally compelled remedy relevant to this article. The NRO coordinates the five RIRs; it is not another name for NRS. IANA numbering services perform their defined coordination role; they are not an NRS department. Courts and lawful public authorities retain the powers their legal systems actually give them.

BTW's role is separate again. BTW reports the observable structure, checks primary sources and labels proposals as proposals. It does not convert NRS advocacy into fact, campaign on NRS's behalf or infer authority from alignment. That reality-not-advocacy discipline is why the institutional nouns in this article matter: a recommendation from NRS, an act by an RIR and an order from a court are three different things.

Geography was a coordination method, not the nature of the resource

The regional structure of Internet number administration was a rational response to scale. A single global office could not remain close to every network, language, legal environment and community. Regional institutions distributed policy participation and registration work while keeping the address space globally coordinated. They developed operational knowledge, communities of engineers and procedures suited to different stages of network growth.

That history deserves respect, but institutional history is not physical law. An IPv6 prefix does not carry a continental boundary in its bits. A route announcement may originate in one country, reach customers in dozens and be managed by staff elsewhere. A multinational network may use one aggregate across interconnected operations. A cloud service can change the location of active systems without changing the holder's identity. A maritime, satellite or anycast service may resist any simple territorial description.

The Internet Numbers Registry System described in RFC 7020 is concerned with allocation and registration that support uniqueness. Its logic does not turn addresses into sovereign territory. It explains a coordinated hierarchy and acknowledges that operational administration can evolve while the essential requirement remains reliable uniqueness.

Confusing the method with the entity creates captivity. If regional placement becomes an unchallengeable condition of service, the holder cannot respond when its business, public duty or network architecture changes. It may face poor language support, unsuitable hours, inaccessible payment arrangements, legal uncertainty or an institution under severe operational stress. The holder's only theoretical alternatives may be to move its legal presence, redesign its network or transfer rights that it does not wish to transfer.

The better interpretation is narrower. Geography can inform service, participation and law. It can justify specialist providers and regional forums. It should not make one provider permanently inseparable from a globally useful identifier.

Uniqueness and exclusivity answer different questions

Uniqueness asks whether the Internet number system recognizes one coherent current status for a resource. Provider exclusivity asks whether only one institution may offer registration service to a class of holders. The first prevents collision. The second prevents choice. They have often travelled together, but they are neither identical nor equally necessary.

A globally unique state means that the same address range cannot be concurrently recognized as held by unrelated organizations through separate authoritative histories. It means an autonomous system number cannot have two equally current holders. Changes must be ordered, stale instructions must fail and restoration after error must create a visible successor state rather than erase inconvenient history.

Provider competition can respect all of those rules. Several banks can give customers access to one payment network without each inventing its own currency. Domain registrars can serve registrants while a registry preserves a coherent domain state. The comparison is imperfect because Internet number rights, allocation policies and routing dependencies differ, but it demonstrates a basic institutional point: multiple service relationships need not imply multiple authoritative entities.

Under the registry model, a provider receives bounded authority to serve a recognized holder. It authenticates instructions, maintains contacts, helps assemble evidence, manages service dependencies if contracted to do so and submits signed changes against a specific current version. The common authority layer accepts or rejects those changes under published rules. Once accepted, every qualified provider sees the same successor state.

Exclusivity is therefore moved from the market to the record. There may be many providers, but there is one current holder state and one current serving provider for each defined service role. Historic providers remain visible. Proposed replacements may prepare. Observers may replicate. None can issue a rival current answer.

Choice should follow the holder's operating reality

Operational need is more concrete than a broad claim of consumer preference. A network operator may require support in several languages, round-the-clock incident response, strong RPKI expertise, accessible disability support, public-procurement terms or integration with a particular identity system. A holder operating critical infrastructure may value tested continuity arrangements more than the lowest fee. A small network may need a provider that can explain complex registration duties without selling unrelated services.

Footprint also matters, but not as a prison. A company serving several continents might choose a provider able to coordinate all of its records under one account while retaining regional contacts. A national research network might prefer a non-profit provider with education-sector experience. A public authority may need local data handling and a contract enforceable in its courts. A diaspora media network may value service in the language of its engineering team rather than the official language of its place of incorporation.

The selection criteria should be disclosed. Providers can publish service levels, languages, support windows, continuity design, security certifications, jurisdictions, subcontracting arrangements, pricing and complaint performance. Holders can compare like with like. The registry operator can verify minimum qualification without dictating one ideal service package.

Choice cannot mean evasion. A holder may not select a provider to conceal identity, defeat a lawful and reviewable restriction, obtain duplicate recognition or bypass a valid transfer requirement. Moving service does not change the holder, erase allocation history or cancel obligations attached to the resource. A provider that markets concealment or immunity should lose qualification.

Nor should choice depend on wealth. A meaningful market needs basic service, accessible switching and support for holders whose public role or small scale makes bespoke negotiation unrealistic. The right is to suitable registration service within common rules, not merely the right to purchase premium attention.

The common authority layer must be deliberately narrow

Ending geographic captivity does not require a giant centralized operator that performs every task. It requires a narrow common layer that answers the questions on which providers must not disagree. That layer identifies each resource, recognizes its current holder, records the qualified provider serving it, orders accepted changes and preserves history sufficient to detect conflict and explain decisions.

The layer should also record restrictions that must survive provider changes: active disputes, court orders accepted under the registry operator's rules, security holds, transfer locks, restoration decisions and time-bounded conditions. It should not absorb every customer-service note, invoice, identity document or network configuration. Providers retain protected service records subject to common retention, export and review duties.

Narrowness limits both technical and political concentration. If the common layer can decide commercial pricing, bundle hosting, dictate routing policy and inspect every private document, provider competition becomes cosmetic. If it stores too little, a failing provider can take the evidence needed for continuity with it. The boundary should be drawn around authoritative status, decision proof and portable minimum data.

Every accepted change needs a version reference and a receipt. A provider submits against the current version it observed. Acceptance creates one successor. Two conflicting submissions cannot both succeed. A later correction does not rewrite the earlier result; it records why a new result supersedes it. Independent replicas can verify order and completeness without gaining power to originate changes.

Governance of this layer must be separable from day-to-day service competition. Providers should not be able to vote themselves permanent advantages, and the registry operator's executive should not quietly expand the common layer. Published authority, member oversight, external review and tested continuity are as important as the database design.

Qualification should test capability without recreating a cartel

Provider qualification is necessary because a weak or dishonest intermediary can expose valuable resources to seizure, stale data or prolonged outage. Yet qualification can also become the old monopoly in new clothing if incumbents control admission, standards require excessive capital or applicants must prove a geographic pedigree unrelated to service quality.

The minimum should be functional. A provider must authenticate holders to defined assurance levels; protect credentials and evidence; maintain trained staff; support signed, version-bound changes; separate customer assets; export portable records; carry appropriate insurance or reserves; report incidents; cooperate with review; and demonstrate that its own failure will not trap holders. It must identify its controlling persons and material subcontractors.

Testing should use observed capability. Can the provider complete a clean switch? Can it detect a stale request? Can it restore access through a second verified contact? Can it produce a complete decision record after staff turnover? Can it continue during loss of a primary site? Can it retire authority when replaced? These demonstrations are more relevant than office location or organizational age.

Admission decisions need reasons and appeal. A denied applicant should know which requirement it failed and how to cure the failure. Requirements should be reviewed for disproportionate effects on smaller, community-based and specialist providers. A supervised entry category can permit limited service while controls are tested, but customers must know the limits and retain immediate exit.

Qualification is not an endorsement of every commercial claim. The registry operator verifies common duties; holders still evaluate service. Poor performance should produce comparable public metrics, corrective directions and, in severe cases, orderly removal. The purpose is a contestable field of trustworthy providers, not a protected club.

A holder chooses service, not a new allocation history

The act of selecting a provider must be defined with precision. It changes the organization authorized to deliver registration service for the current holder. It does not allocate the resource again, change the holder or convert a legacy status into a different legal interest. It cannot be used to cleanse a contested transfer or escape an accepted restriction.

The request therefore names the exact resource set, current holder, current provider and proposed provider. It cites the current authoritative version and states which dependent services are included. Both providers receive notice through independently maintained channels. The gaining provider proves readiness; the losing provider may identify a narrow valid objection; and an impartial coordination function commits the ordered substitution.

An objection must concern authority, conflict, provider qualification, a binding restriction or a material continuity risk. Ordinary debt should follow contract remedies rather than become control over a common record. General allegations of risk need evidence and a deadline. Silence cannot last indefinitely as a veto.

The provider substitution produces a before-and-after receipt. It shows that holder identity, resource identity and allocation history remained constant while serving authority changed at a defined time. Dependent services have separate results. If reverse DNS or hosted RPKI remains with the former provider for a transition period, the record says so; if it moves, the tests and activation times are preserved.

This separation defeats a dangerous ambiguity. Without it, an incumbent can describe exit as an unauthorized transfer, while a bad actor can describe theft as mere service switching. Stable invariant fields allow reviewers to distinguish the two.

Jurisdiction does not vanish when territory stops choosing the provider

Critics of portability may argue that regional exclusivity supplies a clear legal home. In reality, modern number-resource disputes already involve several locations: the holder's incorporation, operating sites, users, provider, registry infrastructure, staff, evidence stores and affected networks. Treating the resource as geographically captive can hide that complexity but cannot remove it.

The registry model should make jurisdiction explicit. Before selection, a provider discloses its legal entities, governing law, dispute forum, evidence locations, material subcontractors and circumstances in which service may be affected by official demands. The holder acknowledges those terms. The common authority layer remains governed by the registry operator's constitutive rules and continuity duties.

A lawful demand directed to a provider is not automatically a command to alter the global record. The provider identifies the legal basis, affected resource, requested act, urgency and restrictions on notice. The registry operator evaluates whether the demand reaches the common authority, conflicts with another binding obligation or can be satisfied through a narrower service action. The holder receives notice unless a valid restriction prevents it, and delayed notice should follow when permitted.

Cross-border conflict requires bounded remedies. A demand concerning one holder should not disable unrelated holders served by the same provider. A disputed service relationship should not produce two current records. Emergency action should expire unless confirmed. An independent reviewer must be able to examine protected evidence and issue a reasoned result.

Territorial monopoly is therefore replaced not by lawlessness but by visible legal attachment. Holders can choose among disclosed legal environments, while the shared rules prevent that choice from becoming a route around accountability.

Global uniqueness is protected by ordered convergence

Provider choice becomes dangerous only if providers can make incompatible authoritative claims. The technical and institutional answer is ordered convergence. Every proposed change references one accepted state. A validation function confirms authority and applicable restrictions. A successful decision creates one next state. Replicas distribute that result, and stale competitors are rejected.

This is not a claim that all Internet routing follows one command. Operators continue to make routing decisions, and registration accuracy does not by itself make a route reachable. It is a claim about the recognized administrative record on which allocation history, contacts, delegation and security decisions depend.

The model needs explicit conflict rules. If two providers submit instructions for the same resource, the first valid accepted change advances the version. The other instruction must be revalidated against the successor state. If a holder claims that the first was unauthorized, the resource receives a narrow protective status and rapid review. The system does not publish both answers while the dispute proceeds.

Independent witnesses can strengthen confidence by retaining signed state commitments and change receipts. They can detect omission or inconsistent views. They cannot allocate, recognize holders or choose winners. Their function is to make equivocation evident, not to multiply authority.

Continuity copies should be usable by a replacement operator under predefined conditions. If the primary authority service fails, an authorized continuity mechanism resumes from the last witnessed state. Recovery should be tested regularly. A theory of uniqueness that depends on one institution never failing is less robust than a design that permits substitution without branching.

RDAP can expose coherent service without exposing captivity

Registration data access is one place where users will encounter the new arrangement. RFC 7480 defines HTTP use for the Registration Data Access Protocol, and RFC 9083 defines its JSON responses. These standards support structured discovery and referral; they do not require every service function to remain inside one regional monopoly.

An RDAP response can identify the authoritative resource, recognized holder information appropriate for disclosure, current registration-service provider, relevant contacts and status. Referral can lead users to provider-specific detail while the common authority remains discoverable. A provider change updates the service relationship without changing the resource identity or erasing history.

The response should not confuse the provider with the holder. Nor should a provider's commercial brand become the proof of authority. Signed or otherwise verifiable change receipts, stable identifiers and consistent discovery matter more than visual presentation. If two endpoints differ, users need a clear rule for determining the accepted current version.

Privacy remains necessary. Ending geographic captivity is not an excuse to publish private identity evidence, personal addresses or security contacts. Public data should support operational accountability; protected evidence should be available to authorized reviewers under logged access. The provider's export duty must include both public and protected portable records without making the latter generally visible.

Accuracy metrics should follow the record across provider changes. A gaining provider does not receive a clean slate that hides stale contacts, and a losing provider is not blamed for changes after cutover. Versioned responsibility makes correction performance measurable.

RPKI continuity must be chosen rather than assumed

The Resource Public Key Infrastructure links number resources to cryptographic entities used in routing security. RFC 6480 describes its architecture. Provider portability must respect the distinction between registration service, certificate authority arrangements, hosted publication and network operators' route choices.

A holder may receive hosted RPKI service from its registration provider, operate delegated infrastructure or contract with another qualified specialist. Changing registration provider should not silently revoke valid authorizations, duplicate certificate authority control or leave publication unreachable. The transition request must identify the current arrangement and the intended result.

Where hosted service moves, the parties should stage keys, validate resource coverage, coordinate publication and observe relying-party visibility before retiring the old arrangement. Where it stays, the former registration provider's continuing security role should be explicit and separately terminable. Where the holder operates its own infrastructure, provider change should not be treated as authority to redesign it.

Emergency restrictions must be narrow. A provider that detects account compromise can pause a high-risk instruction while independent verification occurs. It should not gain permanent control over the resource by asserting security concern. Every hold needs scope, reason, owner, review path and expiry.

Portability can improve security because it allows holders to leave a provider with weak controls. It can also create switching attacks if identity checks are poor. The answer is stronger authorization and ordered handoff, not geographic imprisonment. Security rests on verifiable control, constrained roles and recoverable continuity.

Public-sector continuity makes exit a resilience requirement

Public institutions often operate networks whose failure affects residents who never chose the registration provider. Hospitals, universities, emergency services, municipalities and national agencies may depend on stable addressing, reverse delegation and route authorization. Procurement law, budget cycles and records duties can make service changes slower than those of a private company.

Geographic captivity can be especially harmful when the assigned institution becomes inaccessible, politically contested or operationally weak. A public holder may have no credible remedy short of diplomatic pressure or network redesign. The concentration is obscured because the registration fee may be small compared with the public service at risk.

The registry operator should permit a public institution to select a provider that meets its continuity, accessibility, evidence retention and governing-law requirements. The institution should maintain at least two verified control contacts, an offline recovery method and a dependency inventory. Its provider should support procurement-compatible export and tested emergency substitution.

Emergency substitution must not become political seizure. A government cannot claim every resource used in its territory, and a provider cannot transfer a holder merely because a ministry requests it. The relevant public institution must establish authority over its own recognized resources, or a competent decision must receive review under the common rules.

Continuity planning should include provider insolvency, prolonged outage, sanctions that make payment or support impossible, natural disaster and loss of critical staff. A prequalified fallback can assume service after a witnessed trigger while holder and resource identity remain unchanged. The exercise turns portability from a market feature into infrastructure resilience.

Small and cross-border networks need usable choice, not formal choice

Large network groups can hire counsel, maintain staff in several regions and negotiate exceptional treatment. Smaller holders cannot. They may depend on one engineer, one language and one payment channel. A portability right that requires months of bespoke correspondence will reproduce captivity through cost.

Standard requests, transparent fees and bounded time limits are therefore essential. A clean switch should be understandable without specialized legal advice. Providers should publish plain explanations of identity evidence, dependencies, objections and likely timing. Assisted channels must exist for holders with disabilities or limited connectivity.

Cross-border community networks and non-profits face another difficulty: their legal home, equipment, volunteers and users may sit in different places. Forcing one geographic answer can misrepresent how they operate. Selection by operational need permits them to choose support that actually fits, while the common record still identifies the accountable holder.

The registry operator should monitor whether providers refuse low-revenue or high-support customers. A universal basic-service fund, shared assistance desk or provider-of-last-resort duty may be needed. Such support must be financed transparently and should not give the fallback provider control over admission rules.

Community participation also matters. Ending regional assignment could weaken familiar forums if membership follows only commercial provider choice. The registry operator can preserve regional assemblies and language communities independently of exclusive service territories. A holder might receive service from one provider while participating in policy through operational regions relevant to its network.

Membership must not become a substitute form of captivity

Regional registration often links service, fees and institutional membership. Portability requires these relationships to be unbundled. A holder should not lose its policy voice merely because it changes provider, and a provider should not manufacture voting power by enrolling passive customers.

The registry operator needs a verifiable membership basis. Holders can participate directly, with safeguards against duplicate votes across providers. Providers can have a separate constituency reflecting operational responsibility. Technical and public-interest entities can contribute without pretending to hold resources. No single class should be able to rewrite qualification, switching or fee rules for its own advantage.

Fees should reveal what they purchase. A common authority charge funds unique state, continuity, review and shared data access. A provider charge funds customer service and optional dependencies. Policy participation should not be conditional on buying a premium bundle. Cross-subsidy may be legitimate, but it should be explicit and reviewed.

Provider changes must not alter a holder's governance identity. The holder's verified membership record carries across, subject to ordinary updates. Otherwise an incumbent can threaten loss of voice as a retention tactic. Conversely, a departed provider cannot keep voting on behalf of former customers.

Institutional legitimacy depends on these details. Choice in the service market will ring hollow if incumbents dominate the rules that define choice. Published conflicts, independent election oversight, member-initiated review and stable supermajority limits for constitutional changes can keep the registry operator answerable to the resource community rather than to its largest vendors.

Competition should improve service rather than loosen recognition

Providers will compete on responsiveness, language, continuity, security expertise, integration, price and sector knowledge. They must not compete by promising easier recognition of weak holder claims, concealment of control or disregard of valid restrictions. The common authority layer sets the floor that no provider may sell away.

Comparable performance information can discipline the market. Useful measures include median clean-switch time, correction time, support availability, authentication failure rate, unauthorized-change incidence, continuity-test results, complaint outcomes and export completeness. Measures need context so providers serving complex or vulnerable holders are not punished for their customer mix.

Portability reduces the value of lock-in. A provider that raises prices or neglects service risks losing customers without taking their resources with it. That threat can improve behaviour even when switching remains infrequent. The value lies in credible exit, not constant churn.

There are limits. Excessive switching can create risk, especially if a holder seeks to outrun investigation. A recently changed provider, active high-impact dispute or material identity update may justify enhanced verification. Any delay must be reasoned, narrow and reviewable. Security cannot become an indefinite waiting room.

Market concentration also requires attention. If a few global firms acquire most holders, geographic monopolies may simply become commercial ones. Interoperability, data portability, transparent fees and proportionate qualification lower entry barriers. Merger review and structural remedies may be needed when a provider also controls critical shared functions.

Legal demands should attach to acts, not imagined territory in an address

An address block can be used in many jurisdictions at once. Attempts to locate it as if it were land create unstable conclusions. A court's authority normally follows persons, organizations, contracts, conduct, property interests and effects. The record should reveal those connections where appropriate rather than declare that a prefix belongs politically to one region.

When a legal demand seeks correction, preservation or restraint, the receiving provider records the exact act requested. Is the request to preserve evidence, prevent a holder change, suspend one credential, disclose protected data or alter public registration? Each has different consequences and authority. Broad language should not automatically receive the broadest technical interpretation.

The registry operator should maintain a conflict framework. It checks authenticity, jurisdictional basis, notice rules, proportionality, duration and available challenge. It distinguishes a provider-directed service obligation from a command that reaches the common authoritative state. Where two demands conflict, an independent forum can preserve the current state temporarily while deciding the narrow issue.

No provider should advertise itself as beyond law. Equally, no provider should be able to apply its home government's demands worldwide without scrutiny merely because it serves foreign holders. Disclosure and review make cross-border choice defensible.

The holder's ability to switch during a dispute needs care. A valid restriction follows the resource across providers; an unrelated contractual conflict does not. The switch record carries the restriction reference without publishing protected details. This prevents jurisdiction shopping while denying incumbents a private right to immobilize customers.

A transition from regional exclusivity must preserve accumulated trust

The existing regional institutions hold expertise, records, relationships and operational credibility. Reform should not discard them. They can become qualified providers, participate in shared authority, operate regional forums and offer continuity services. Their experience may make them preferred by many holders when preference becomes voluntary.

Transition should begin with portable service for willing holders under a limited, observed phase. The first cases should include multinational networks, cross-border non-profits, public institutions and ordinary small holders rather than only sophisticated companies. Results should test identity, data export, dependencies, legal conflict and complaint handling.

Existing allocation history must remain intact. Records move by authenticated reference, not by re-creation. Historic regional identifiers can persist as provenance while a stable registry operator-wide identifier links the resource and holder. Users should be able to understand the lineage without treating the old provider as current.

No regional institution should be forced to accept unlimited new obligations overnight. Qualification defines the service it chooses to offer. If it declines to compete outside its former area, current holders still receive a bounded period and support to choose another provider. Shared continuity copies protect against delay or withdrawal.

Financial transition also matters. Institutions built around compulsory service may carry public functions that fees currently support. Those functions should be identified and financed directly through common charges or commissioned services. Captive customers should not be retained merely because the old budget is opaque.

Failure modes reveal whether the design is genuine

The first failure mode is duplicate authority. Two providers each claim to be current, or a continuity site advances independently. The defence is version-bound acceptance, witnessed order and one recovery authority. Detection should trigger immediate publication of the last uncontested state and expedited review.

The second is hidden transfer. An attacker changes both provider and holder while calling the act portability. Stable invariant fields, independent holder notice and separate holder-change authority expose the attempt. High-risk changes require delay sufficient for a second channel to respond.

The third is soft captivity. Switching is formally allowed, but the losing provider delays export, claims vague security concerns, bundles essential RPKI service or charges punitive exit fees. Time limits, portable minimum records, dependency separation and review are the remedies.

The fourth is jurisdictional flight. A holder moves service to defeat a valid restriction. Restrictions follow the authoritative resource state, and a gaining provider must acknowledge them before acceptance. The holder can challenge the restriction, but cannot erase it through selection.

The fifth is provider failure. Staff disappear, credentials are lost or systems become unreachable. Continuity copies, verified fallback contacts and a preauthorized substitution path preserve service. Failure should remove the provider, not destabilize holder recognition.

The sixth is central overreach. The common layer expands until it controls routing, commercial terms and private evidence. Purpose limits, member approval, external audit and enforceable deletion rules keep shared authority narrow.

The seventh is exclusion by complexity. Only large holders can exercise choice. Standard forms, assistance, transparent pricing and a provider of last resort make the right practical.

A multinational continuity scenario shows the boundaries

Consider a humanitarian communications organization incorporated in one country, operating terrestrial links in several regions and supporting emergency sites through satellite connectivity. Its current regional provider offers competent registration but limited support during the organization's critical hours. The holder wants a provider with multilingual continuous response and tested RPKI transition capability.

The organization does not claim a new allocation. It submits its current holder reference, exact prefixes and autonomous system numbers, authority evidence, current state versions and dependency inventory. The proposed provider discloses its legal terms and demonstrates qualification. The current provider receives independent notice and exports portable records.

One prefix is subject to a pending correction about a technical contact. That issue does not justify freezing the entire portfolio. The correction is resolved or isolated. The remaining resources move on schedule. The provider substitution receipt shows that holder and resource history did not change.

Hosted RPKI service moves in a coordinated window. New publication is observed before old service retires. Reverse DNS for two ranges remains temporarily with the former provider under a separate service agreement, clearly recorded. Public registration identifies the new provider and correct operational contacts without exposing emergency personal details.

Months later, a court directs preservation of records concerning one site. The provider preserves relevant evidence but does not alter holder recognition or unrelated resources. The organization remains free to challenge the demand under disclosed law. This is choice with accountability, not a claim that borders have ceased to exist.

Evidence and metrics must test both freedom and coherence

The registry operator should publish whether holders can actually leave. Median and tail switching times, objection reasons, withdrawn requests, export failures, emergency substitutions and complaint outcomes reveal practical captivity. Results should be disaggregated by holder size, language, region and public-interest role without exposing protected cases.

It must also measure coherence. Conflicting-current-state incidents, stale accepted requests, duplicate credentials, inconsistent RDAP answers, RPKI continuity failures and restoration events show whether competition is weakening uniqueness. Zero reported conflicts is credible only when independent witnesses and incident channels can detect them.

Provider diversity is not a sufficient success measure. Ten providers controlled by two companies do not create robust exit. Market share, common subcontractors, shared infrastructure and correlated failure should be visible. Continuity tests should include the loss of a dominant provider and a shared technical vendor.

Holder outcomes matter. Are contacts more accurate after switching? Are security incidents corrected faster? Can small organizations obtain support? Do public bodies maintain service during provider failure? Has the cost of basic registration become clearer? These questions connect institutional design to operational value.

Every metric needs an owner, method and review date. Providers should be able to correct factual errors but not suppress unfavourable results. Independent researchers can receive privacy-preserving data. Evidence gives members a basis to change rules before captivity or fragmentation becomes entrenched.

Regional knowledge can survive without regional compulsion

Ending compulsory regional service does not require flattening every regional distinction. Networks still operate amid different languages, legal systems, infrastructure conditions, procurement customs and security threats. Local knowledge can improve registration support and policy. The mistake is to assume that preserving this knowledge requires exclusive control over every holder associated with a territory.

Regional forums can remain strong communities within the registry operator. They can study local deployment, support training, develop proposals and elect representatives to shared bodies. Participation can follow meaningful operational connection rather than the address of a provider. A holder active in several regions may join several discussions but should not multiply its constitutional vote merely by opening service accounts.

Providers can specialize regionally without receiving a territorial franchise. A provider may offer exceptional service for African research networks, Pacific islands, European public authorities or Latin American community operators. Its advantage comes from language, trust and competence. A holder chooses it because those qualities fit, not because all alternatives are forbidden.

The distinction also protects less powerful regions. A fully global market could draw service and expertise toward large commercial centres. The registry operator should monitor where support staff, decision makers and continuity capacity are located. Common fees can fund regional public goods, language access and technical development under transparent mandates. Portability should distribute opportunity rather than drain it.

Regional evidence should inform decisions without becoming a conclusive territorial label. Place of operation may be relevant to fraud checks, sanctions, public duties or route-security support. A provider can request evidence proportionate to that purpose. It should not demand a fictional single home for an anycast service or a network spread across borders.

The regional institutions themselves can become continuity anchors. Their established facilities and communities may host witnessed replicas, provide emergency support or serve holders that prefer a non-profit model. Those roles should be awarded and reviewed on published terms. Historic position is valuable experience, not an unlimited entitlement.

Freedom of provider does not mean freedom to choose the facts

A holder may choose who serves it, but it cannot choose whichever account of reality is most convenient. The recognized legal person, organizational continuity, resource history and current restrictions are factual and adjudicative matters governed by common rules. A provider cannot offer a more favourable version as a commercial product.

This limit should be stated at the start of every service relationship. If the holder's name changes, the provider submits evidence of the change. If a merger creates a new holder, the separate holder-change rules apply. If control is disputed, the provider preserves service and seeks a reasoned decision rather than accepting the first claimant willing to pay.

The same principle governs policy eligibility. A holder cannot move to a provider that promises to treat ineligible conduct as valid. Rules attached to conservation, accuracy, abuse handling or a defined class of resource remain common until lawfully changed. Competition concerns administration, advice and support within those rules.

Providers also cannot choose their own authoritative view. They may challenge a registry-operator decision through review and publish reasoned criticism. Until a decision is stayed or replaced, they must serve the accepted state. This duty prevents institutional disagreement from becoming technical fragmentation.

At the same time, the common authority cannot use factual discipline as a pretext for immobilizing holders. Decisions must identify evidence, rule, responsible body and review route. A disputed fact receives a bounded status and a timetable. The holder can continue unaffected operations unless a specific risk justifies narrower restraint.

This balance is central to legitimacy. Choice is real because the incumbent cannot retain a customer by controlling the facts. Coherence is real because the gaining provider cannot purchase that customer by inventing new facts. Both sides submit to the same visible authority and the same opportunity for correction.

The constitutional bargain is exit under one authoritative truth

The registry operator should make a narrow promise. No holder is permanently bound to a registration-service provider because an Internet number has been treated as political territory. No provider, including the registry operator itself, may answer that freedom by creating a competing allocation history. Exit and uniqueness are coequal duties.

That bargain changes institutional incentives. Providers must earn continued service through capability and trust. Holders gain leverage without gaining power to erase obligations. Regional communities can keep expertise and policy voice without owning customers. Courts and public authorities receive clearer information about the act, person and contract within their reach.

The hardest work lies in boundaries: what remains common, what moves with the provider, which restrictions follow the resource, how protected evidence travels, when emergency action expires and who reviews the registry operator. Those are governable questions. Geographic captivity merely postpones them behind a territorial assumption that fits fewer networks each year.

IP resources are not detached from society. They support services, markets, governments and communities. They are subject to contracts, laws and duties. But they are not land, and the institution assigned by historic geography need not possess a permanent service franchise over them.

The mature alternative is selectable registration inside a globally coherent authority. One resource, one recognized current state and one accountable holder can coexist with many qualified service providers. That is how the registry operator can end geographic captivity without sacrificing the uniqueness on which the Internet depends.

NRS and BTW role sources