Summary

  • On 13 August 2026, the Common Good Cyber Fund’s first global application window had closed and applications were under review. At least USD 3.5 million in two-year grants was expected; no checked source announced the final 2026 cohort.
  • The same update described anti-scam resources under development, a Hub being prepared for September, community projects and policy advocacy. Those activities involve different decision-makers, standards, executors and correction routes.
  • A versioned responsibility-and-evidence map should accompany each action. Shared purpose can remain; authority, review, execution and evidence should not be compressed into the initiative’s brand.

On 13 August, the Internet Society published a progress report about its Safer Internet Initiative. The report was a useful status document because it placed several kinds of work on the same date. The Common Good Cyber Fund had closed applications on 4 August and moved into review. An anti-scam toolkit, curriculum, e-learning course and train-the-trainers model were being designed and implemented with Google.org funding. An Online Trust and Safety Hub was being prepared for a September launch while chapters, members and partners reviewed an early version. Chapter projects and policy advocacy completed the picture.

That picture is coherent as strategy. It is incomplete as an accountability map.

The central mistake would be to treat “Safer Internet Initiative” as the name of an authority that makes all of those decisions. It is a programme identity. A funding decision, a resource-release decision, a local training adaptation and a policy position can support the same public goal without borrowing one another’s mandate. The stakeholder who comments on an early Hub does not therefore select a grantee. A donor to a pooled fund does not therefore approve a lesson plan. A chapter that adapts training does not therefore authorize a global policy brief.

The funding chain already contains distinct offices

The Common Good Cyber Fund programme page makes some institutional roles unusually clear. The Internet Society Foundation is the grantmaking organization: it manages applications, reviews applicants and prospective grantees, selects grantees and oversees grant management and reporting. Global Cyber Alliance chairs a Strategic Advisory Committee that provides strategic advice. An Independent Program Review Committee supports the open-call review process.

Those verbs matter. Advice is not selection. External review is not the same as grant management. A pooled donor contribution is not proof that a donor decided an individual award.

The 2026 call ran from 23 June to 4 August. It expected at least USD 3.5 million in two-year operating grants, generally between USD 100,000 and USD 300,000. The Fund strategy set November 2026 as the target for completing reviews, seeking any necessary revisions and finalising the cohort. The August status was therefore review, not award. No applicant should acquire the public status of grantee merely because an initiative update says applications are under review.

The result side needs the same restraint. The Fund’s evaluation framework distinguishes outputs, outcomes and a long-run goal. It includes estimated beneficiary numbers, self-reported organizational changes and contribution indicators. The guide itself says that a funding-source indicator is not meant to prove that the Fund alone improved a grantee’s finances. Feeling safer is identified as a perception measure, not a direct safety measure. An activity count can be useful without becoming causal proof.

A responsible grant record should therefore preserve four separate moments: eligibility and screening, independent review, selection and award, then reported results with their method and denominator.

The Hub needs a release history, not a single status word

The Hub shows why versioning matters before a product even has stable public status. The February launch article said a vetted, multilingual Hub would arrive in the second half of 2026. The August update said Internet Society was preparing to launch it in September and that chapters, members and partners were reviewing an early version. The current initiative landing page says the Hub is launching in 2026.

The publicly available minutes for Board meeting No. 196 add a complication. One management report lists launching the Hub among priorities for the second half of the year. The next activity report says the Hub was launched and that scaling it is a priority. These statements do not establish whether “launched” meant an internal release, an early community version, a soft launch or a public product, and they do not identify a release date.

The answer is not to choose the most convenient sentence. It is to publish a release history: version, audience, owner, resource-vetting rule, languages and accessibility state, reviewers, comments received, comments accepted or rejected, publication decision, corrections and retirement policy. Consultation can improve a resource. It does not become approval unless the institution identifies an approval power and records its exercise.

Training transfers discretion to the delivery edge

The anti-scam work has a different operating surface. The August update described a toolkit, global curriculum, e-learning and a train-the-trainers model. It also promised targeted support for local organizations to adapt and implement resources for their communities. That local discretion is not a defect. It is the mechanism by which a global resource can become usable across language, culture, bandwidth and risk context.

But adaptation changes responsibility. The central team owns the base material and its evidence. A trainer programme owns preparation and competency checks. A local partner owns choices about examples, language, venue, safeguarding and delivery. Participants supply feedback and may report whether a practice changed. None of those records should be collapsed into “the initiative trained a community.”

The distinction is visible in current material. Internet Society already offers an Introduction to Online Trust and Safety course with nine short videos and practical objectives. That proves a course exists. It does not prove the course is identical to every planned Google.org-funded anti-scam component, that local adaptations have been reviewed, or that participants experienced fewer losses.

Chapter projects make the same point. The August report names activities in Ghana, Lesotho, Hong Kong, Mexico, Zimbabwe and Rwanda, several supported through the Foundation’s Beyond the Net programme. The examples demonstrate work in different settings. They do not establish a single implementation standard or comparable outcome. A local project should keep its own owner, grant source, adaptation record, safeguarding route, feedback channel and evidence of change.

Advocacy needs a representation label

The fourth chain is policy. Internet Society advocates safety, privacy, secure communications, encryption and VPN use, and has published material such as Solving Crime Without Breaking Encryption. Advocacy has a legitimate role: it can collect evidence, test proposals and state an institutional view.

The responsibility error begins when an institutional position is read as the consent of everyone connected to the programme. Members, chapters, partners, donors, grantees and users are not one principal. Participation can provide evidence and warning. It does not silently transfer the right to speak for all participants.

A policy record should name the drafting owner, evidence reviewed, internal approval body, consultation scope, conflicts, publication date, legal or factual assumptions and revision route. It should state plainly that the published position belongs to the institution unless a separate mandate says otherwise.

Four maps, one public purpose

The proposed responsibility-and-evidence map is not another central committee. It is a disclosure layer. For each action it should show:

  1. the decision and the body entitled to make it;
  2. the money or institutional resource behind it;
  3. the reviewer, evidence standard and conflicts rule;
  4. the feedback received and its disposition;
  5. the executor and the population or system affected;
  6. the correction, complaint or appeal route;
  7. the version and current status; and
  8. the result measure, denominator, method and uncertainty.

This is an editorial recommendation, not a system Internet Society has promised. It follows a narrower principle from Heng Lu’s notes: participation, advice and institutional ritual should not be inflated into mandate. The point is not to accuse people working under one programme of acting in bad faith. It is to make the structure legible before a common label begins doing the work of authorization.

The Safer Internet Initiative can remain one strategy. Its accountability should remain plural.

Sources