Summary
- The regional internet registries are independent legal organizations, but the Number Resource Organization gives them a permanent coordination layer for global policy, technical projects, public accountability, RPKI work, stability planning, ICANN participation, and mutual support.
- Legal mutual aid is legitimate when it protects uniqueness, service continuity, records, neutral recognition, and defensible common standards. It becomes more dangerous when the same legal theory is used to shield every registry from regional accountability or to turn local reform into a challenge against the whole system.
- The practical test is not whether the registries cooperate. They must cooperate. The test is whether shared legal positions leave room for public reasons, dissenting RIR views, regional comparison, independent evidence, narrow remedies, and exit options for operators who depend on registry records.
The legal memo that changes a market before it reaches court
The most important legal document in the number registry system is often not a judgment. It is the shared position taken before a judgment appears. A transfer lawyer reads it. A cloud platform reads it. A bank officer reads it. A member board reads it. A court may receive it as background. A regulator may treat it as technical consensus. An operator with address space in one region may discover that the answer to a local complaint has already been harmonized across five institutions that present themselves as separate regional registries.
That is why shared legal strategy among the regional internet registries deserves scrutiny. Cooperation is not suspicious by itself. The registries administer a single global numbering system. If they do not coordinate, address uniqueness suffers, inter-registry transfers become uncertain, RPKI trust relationships become harder to validate, and every serious regional crisis can spill into the rest of the Internet. The NRO says it was established in 2003 as a coordinating body for the world's RIRs and that its mission includes a coordinated number registry system, an authoritative voice on bottom-up policy, and joint RIR activities. That is not a side activity. It is the official architecture.
The problem begins when coordination is treated as a reason to stop comparing institutions. A member who challenges a registry in one region may be told, explicitly or implicitly, that the whole RIR system stands behind the contested position. A court that asks whether one registry exceeded its mandate may receive arguments about global stability rather than a narrow explanation of the challenged act. A reform proposal that would make one registry more accountable may be reframed as a threat to all registries.
A resource holder asking for a cure, stay, record correction or proportional remedy may face not only the local service provider but a common legal vocabulary shared through NRO channels.
The distinction is small in wording and large in consequence. Technical and legal mutual aid says: if one registry is hit by operational disruption, the others will help preserve records, services and uniqueness. A power alliance says: if one registry's authority is challenged, the others will help preserve the authority model itself. The first is resilience. The second is institutional self-protection. The first is necessary in a global numbering system. The second needs public limits because it can reduce the benefits of having five separate legal bodies, five regional communities and five opportunities for reform.
The NRO's own public materials show both sides of the line. The five RIRs are independent organizations operating in their regions under their own legal frameworks, with member boards and local policy processes. The NRO also coordinates joint projects, technical activity, global policy, ICANN relations and support during disruption. Its Executive Council acts by consensus from all five regions. Its Memorandum of Understanding contains finance and legal-defense provisions. Its Joint RIR Stability Fund describes long-standing mutual support and a formal emergency commitment.
Its RPKI program aims for more consistent and secure service across the five RIRs.
None of those facts proves improper coordination. They prove that the infrastructure for shared legal posture exists. The governance question is what boundaries prevent that infrastructure from flattening regional independence into a single defensive line.
Independence is valuable only if it can produce different answers
The public justification for the regional registry model has always included local knowledge. Regions differ in market structure, law, currency exposure, geography, public-sector reliance, national registry arrangements, legacy allocation history, political risk and member composition. A registry in the RIPE NCC service region does not face the same institutional environment as LACNIC. APNIC's relationship with National Internet Registries gives it a different service surface from ARIN. AFRINIC's corporate and court environment creates different continuity risks from a mature registry with stable board succession.
The case for regionalization depends on those differences being real.
If every important legal question receives the same answer, regionalization becomes weaker as a governance claim. The registries would still have different offices, fee schedules, staff, member meetings and portals, but the legal boundary of their power would be harmonized by a shared theory. That can be efficient. It can also be anti-competitive in the institutional sense. Operators lose the ability to compare how different registries handle due process, record correction, transfer delay, RPKI custody, appealability, sanctions screening, disclosure, fee incidence or service continuity.
A legal position that should have been tested in one region becomes a global orthodoxy by repetition.
This matters because institutional competition in the RIR system is not ordinary market competition. A resource holder usually cannot choose a different regional registry for the same resource merely because it prefers another governance style. The service region determines the registry. Exit is weak. Transfers can move resources under rules, but they do not allow ordinary members to shop among five legal systems for daily service. When exit is weak, voice and comparison become more important. If comparison is weakened by common legal strategy, the model loses one of its internal checks.
The NRO's RIR Governance Matrix usefully recognizes the differences. It compares bylaws, policy processes, board structures, contractual relationships, terms, due diligence, record auditing, dispute mechanisms, deregistration, Whois privacy, law-enforcement handling, security management, budgets and fee decision processes. That comparative table is a public good because it admits that the five registries are not identical. It gives members and observers a way to ask why one registry protects a right differently from another.
Shared legal strategy can either support that comparison or smother it. It supports comparison when the registries publish a common minimum standard while allowing each region to exceed it, explain its deviations and disclose its own legal constraints. It smothers comparison when the common line becomes a ceiling. If every registry says the same narrow remedy is impossible, the same appeal is inappropriate, the same record is confidential, the same review is discretionary, or the same member claim threatens stability, then local accountability becomes harder even if the regions remain formally separate.
The strongest legal architecture would preserve a double answer. For global uniqueness, security, root allocation, IANA numbering, inter-RIR transfer compatibility and emergency service continuity, a common baseline is necessary. For member rights, evidence access, hearings, publication of reasons, appeal design, fee consent, data correction, board accountability and proportional remedies, regional variation should remain visible unless a global rule has been openly adopted through the proper channels. The line between those categories should be written down before a dispute arises.
The NRO is a coordination device, not a single principal
The NRO's founding documents make the tension plain. The NRO history page records that APNIC, ARIN, LACNIC and RIPE NCC entered into a Memorandum of Understanding on 24 October 2003 to form the NRO, with AFRINIC joining after incorporation. The NRO MoU contains coordination machinery for global policy, technical activity, finance, recognition criteria and amendment. But it also says the MoU does not create a partnership, agency, association or franchise arrangement.
That limitation is not decorative. It is the constitutional hinge of the whole arrangement. The registries wanted a vehicle for coordination without becoming a single entity whose acts automatically bind every region. They wanted global cooperation without making one RIR the agent of another. They wanted common policy processes without turning the NRO into a central registry. The more later practice resembles a collective legal principal, the more important it becomes to explain why the limitation still has practical force.
The NRO Executive Council adds another layer. The NRO says the EC consists of one person from each RIR, appointed by each RIR board, and acts only by consensus from all five RIR regions. Consensus can protect a region from being overruled. It can also turn the absence of dissent into a public signal that all registries stand together. In ordinary technical coordination, that signal is useful. In legal disputes, it can be powerful enough to change how courts, members and counterparties price the issue.
The MoU's finance section is especially revealing. It states that NRO expenses require unanimous EC authorization and are borne by the RIR signatories, and that an RIR subject to legal claims for its role in a duly authorized NRO activity may seek contributions for its defense or resulting judgment on a case-by-case basis with EC authorization. This is a reasonable clause. If a registry is sued because it performed an authorized shared activity, the cost should not necessarily fall on that registry alone. Yet the clause also shows that legal risk can move from one registry into a collective budget decision.
That budget feature is not wrong, but it changes incentives. A local actor challenging a shared NRO act may face a defense cost structure supported by all regions. A registry deciding whether to take an aggressive common position may know that the costs are not purely local. A board may prefer a unified legal position because divergence could weaken a collective defense. A common budget can preserve services, but it can also reduce the economic pressure that would otherwise make one registry rethink a doubtful position.
This is why shared legal positions need a disclosure discipline. When the NRO or all RIRs speak together, the public should be able to tell whether the statement is a technical-operational position, a global policy position, an ICANN-facing institutional position, a litigation-related defense of an NRO activity, or a broader assertion about RIR authority. Those categories carry different legitimacy. They should not be fused by a single letterhead or by generic stability language.
The ASO MoU with ICANN illustrates the same point from another angle. Under the ICANN Address Supporting Organization MoU, the NRO fulfills the ASO role defined in ICANN's bylaws. The MoU defines global policy development, recommendations to the ICANN Board on recognition of new RIRs, selection procedures for ICANN roles, and advice on number resource allocation policy. It also says nothing in the MoU creates a partnership, joint venture, trust, agency, principal relationship or franchise among the parties, beyond the MoU's terms.
That text supports coordination. It does not support unlimited collective authority. The legal meaning of the RIR system remains bounded by the documents, regional corporate law, member agreements, global policy processes and ICANN arrangements. If a shared legal strategy claims more than those sources allow, the fact that all RIRs agree does not by itself make the claim legitimate.
Mutual aid is strongest when it is narrow
The best case for shared legal strategy is emergency continuity. Number registry services cannot fail casually. Records must remain available. IANA allocations must remain unique. Reverse-DNS delegations must not be lost. RPKI repositories and trust materials must remain reliable. Transfer states, public registration records and member service data must not become inaccessible because one legal entity suffers a crisis. In that setting, mutual aid is not a conspiracy; it is a fiduciary habit for a shared infrastructure layer.
The Joint RIR Stability Fund is the clearest public example. It says the RIRs have long had mutual support among CEOs and staff, but a serious threat to a registry's integrity or operations needs a more formal board-endorsed agreement. It frames the fund as a commitment to safeguard stability, guarantee continued operation of all five RIRs and support policy development communities. It lists possible scenarios such as financial distress, sudden loss of critical staff, natural disasters, military conflict, political instability, criminal activity and serious infrastructure problems. It says support could be financial or in-kind, including operational staff support to continue service provision.
That is the proper center of mutual aid: continuity of registry services. It is practical, narrow and tied to operational necessity. It does not say the other registries will decide the affected registry's local election dispute. It does not say they will select the winning faction in a member conflict. It does not say they will defend every exercise of local discretion. It says the system needs a way to keep services running if a registry encounters serious difficulties.
The fund also contains safeguards that should be copied into legal coordination more generally. The request for support must be a formal documented request by the affected RIR's board, with reasons and requested support. Fund access requires unanimous NRO EC agreement. Funds are managed and accounted for jointly by the CFOs of the RIRs, coordinated by the NRO EC treasurer. Use of funds is tied to expenses that alleviate the affected condition. RIR activities that are not registry or policy-development related generally do not qualify.
Those limits are important because they separate support from control. A legal mutual-aid rule should do the same. It should say what kind of legal support may be shared, who approves it, whether the affected registry requested it, whether the support concerns an NRO activity or a local registry act, whether public reasons will be given, whether dissenting views can be published, whether members can see enough to understand the effect, and whether support stops at continuity rather than becoming governance substitution.
The continuity case is especially strong when a registry crisis threatens third parties who have no role in the dispute. A small ISP, public hospital network, university, exchange point, bank, cloud customer or government service can depend on address records without caring who wins a board argument. If the registry's account system, reverse-DNS support, RPKI publication or transfer record becomes unstable, ordinary networks pay the price. Mutual aid can protect them.
But the same third-party reliance can be misused as a shield. A registry facing valid criticism can say every challenge threatens continuity. A common legal letter can say global stability requires deference. A court can be warned that ordinary remedies could have Internet-wide consequences. Those claims may sometimes be true. They may also be exaggerated. The answer is not to forbid stability arguments. It is to require them to identify the exact service at risk, the probability of disruption, the least intrusive remedy, the records to be preserved and the reason a narrower order would not work.
Narrow mutual aid therefore has five marks. It protects a named service. It is time-limited. It preserves records rather than reallocating power. It publishes enough reasons for affected users to understand the risk. It distinguishes technical continuity from legal victory. When those marks are absent, mutual aid drifts toward alliance.
The common defense problem
A common defense is tempting because the RIRs face similar structural claims. Members challenge fees, elections, data accuracy, revocation, transfer delay, RPKI authority, contractual terms, sanctions screening, privacy limits, appeal rights and record disclosure. If one challenge succeeds in one region, another member may try a similar claim elsewhere. Registries therefore have an incentive to resist not only the local demand but the precedent.
That incentive is normal for any institutional family. Universities, banks, utilities, standards bodies and trade associations all learn from litigation against peers. They share counsel, monitor cases, file comments, fund studies and adapt contracts. The RIRs are not unique in that sense. What makes them different is the combination of monopoly-like service regions, global uniqueness dependence, ICANN recognition, shared technical infrastructure, weak user exit and public-interest language. A common defense in this environment can shape the legal boundary of operational life for thousands of networks.
The problem is most acute when the common defense is about the nature of registry authority itself. If all registries converge on the view that number resources are merely permissioned entries subject to broad institutional discretion, then resource holders lose room to argue that particular acts require due process, compensation, notice, proportionality or independent review. If all registries converge on the view that community processes supply sufficient legitimacy, then nonparticipating cost bearers may find their absence used against them.
If all registries converge on a narrow view of court remedies, domestic judicial checks may be treated as dangers rather than constraints.
The registries may have good reasons for some of those positions. Address space is not land. A registry is not a county recorder. Routing security cannot wait for every commercial dispute to finish. Fraud control is real. Public records must remain accurate. A registry must not be forced by one court order into double registration or broken uniqueness. These are serious arguments. They should be made in a disciplined way.
The discipline is to avoid converting the strongest technical necessity into the broadest legal defense. Uniqueness requires one current public registration state. It does not automatically require every revocation rule to be unreviewable. RPKI reliability requires that certificates and repositories correspond to recognized resources. It does not automatically require every RPKI service change to be immune from appeal. Fraud control requires identity checks. It does not automatically justify indefinite transfer delay without reasons. Regional policy requires community process.
It does not automatically mean silent downstream operators consent to every rule.
A shared legal strategy becomes dangerous when it collapses these distinctions. The public hears "stability" while the actual dispute concerns evidence access. The court hears "global uniqueness" while the actual remedy could be a notation, stay or limited correction. The member hears "community consensus" while the actual question is whether the registry provided reasons. The operator hears "security" while the actual issue is who can change a ROA during a transfer. The result is not stronger law. It is a fog in which institutional authority benefits from the prestige of technical necessity.
The antidote is a separation table. Every shared legal position should identify the registry fact at issue, the document that grants authority, the service affected, the local legal question, the global coordination consequence, the least intrusive remedy, the evidence source and the uncertainty. If the position cannot fill that table, it is probably too broad.
Legal coordination can reduce institutional competition
Institutional competition in the RIR system is subtle but real. One registry can publish better minutes. Another can design clearer appeals. Another can make RPKI handover easier. Another can provide stronger fee justification. Another can disclose more about board conflicts. Another can separate enforcement from record correction more carefully. Operators and policy communities can compare those choices and push their own registry to improve.
Shared legal strategy can reduce that competition by making defensive positions portable. If a registry adopts a restrictive interpretation and the others endorse it, the policy community loses a useful contrast. Reformers can no longer point to another region and say: this is possible there, so why not here? The common answer becomes: the system has considered the matter. That is efficient for incumbents and expensive for members.
The risk is not theoretical. The NRO governance materials already show a move toward common lifecycle rules for recognition, operation and derecognition. The 2025 draft RIR Governance Document says it succeeds ICP-2 and sets rules for recognizing new RIRs, operating obligations and criteria and procedures for derecognition. It requires ongoing operational independence, good corporate governance, open membership, member-elected governing bodies, open policy development, impartial policy application, records, audits and service delivery.
It also states that each RIR shall independently consider recognition and derecognition proposals and publish recommendations and reasons.
That draft contains both concentration and safeguard. The concentration is a shared rulebook for all RIRs, including derecognition. The safeguard is independent consideration and published reasons. The safeguard matters because it preserves some institutional competition inside a shared process. A registry may recommend against a proposal, explain why and let the public compare its reasoning with the others. If that independence is real, common standards need not become common defense.
The same idea should govern legal strategy. When the RIRs coordinate, the public should know whether each registry independently reviewed the position. If the position concerns a shared technical service, consensus may be appropriate. If it concerns legal power over members, fees, records, elections, resource remedies or court interaction, a registry should be able to publish a concurring or limiting statement. The absence of dissent should be earned by visible reasoning, not presumed from silence.
Regional competition also requires data. If one registry says a remedy would be too costly, it should disclose the cost class. If one registry says appeal rights would delay security action, it should disclose ordinary delay metrics. If one registry says disclosure would threaten privacy, it should state what can be redacted and what can be summarized. If one registry says a legal rule would endanger global coordination, it should identify the exact coordination point. Comparative governance improves when claims are measurable.
A system that says "trust us because all five agree" is not regional governance. It is pooled legitimacy. Pooled legitimacy is sometimes necessary for IANA-facing policy and emergency continuity. It should not become the ordinary answer to local accountability.
The AFRINIC lesson is continuity, not collective veto
AFRINIC's long crisis made the value of mutual support visible. It also made the danger of common legal posture visible. A registry without ordinary board continuity, under court pressure, with contested elections and member-rights concerns, creates risk for more than its own officers. Its records, services and trust relationships affect operators across a region and counterparties outside it. The NRO and ICANN could not simply ignore that risk.
At the same time, the appropriate external role was not to decide every domestic claim. The external role was to preserve service continuity, require records, state the criteria for recognized registry operation, distinguish verified facts from allegations, protect ordinary resource holders and keep any emergency step within a defined mandate. The strongest public positions are those that name the service risk and the limited remedy. The weakest are those that treat any external concern as proof that one faction should prevail or that all local remedies must defer to registry stability.
The 2025 draft governance document points in the right direction by defining recognition, derecognition, emergency continuity and emergency operator concepts. It requires written proposals and published reasons. It gives ICANN a decision role after RIR recommendations and includes reconsideration. It also limits ICANN's power to recognize or derecognize an RIR unless it has received a proposal approved by the RIRs under the procedure. Those provisions are not final law in the ordinary sense; they are draft architecture. Their value is that they name the steps that cannot be left to improvisation.
For shared legal strategy, the AFRINIC lesson should be this: a crisis can justify collective attention, but it does not justify collective overclaiming. Other registries may help preserve records, lend staff, share expertise, support emergency services and advise ICANN. They should be cautious about turning an affected registry's local dispute into a global referendum on RIR authority. They should be equally cautious about letting a local court order fragment the numbering system. The middle position is hard, but that is why written boundaries matter.
One useful test is whether the common legal position would still make sense if the same fact pattern appeared in a stronger registry. If a remedy is rejected only because AFRINIC is fragile, the rejection should be framed as emergency continuity, not general RIR doctrine. If a cure is accepted only because the affected registry is politically sensitive, the acceptance should be framed as case-specific, not a global precedent. If a rule is said to apply to all RIRs, every registry should be willing to explain how it would affect its own members.
Another test is whether the position leaves room for operator rights. A registry crisis is not only an institutional event. It is an operator dependency event. Members and resource holders need to know whether services continue, whether records are safe, whether transfers are paused, whether RPKI changes are possible, whether reverse DNS remains stable, whether fees are due, whether disputes will be noted, and whether emergency actions can be reviewed. A legal strategy that centers only the registry's survival misses the infrastructure user's perspective.
The strongest mutual-aid model would therefore publish a continuity statement in any major crisis. It would identify stable services, frozen services, review services, emergency contact points, record-preservation measures, evidence boundaries and expected next updates. It would not require disclosure of confidential member data or litigation strategy. It would give operators enough to distinguish real continuity risk from institutional rhetoric.
How to tell mutual aid from a power alliance
The difference between mutual aid and power alliance can be tested without accusing anyone of bad faith. The first test is scope. Mutual aid names a narrow service: public registration, reverse DNS, RPKI repository operation, transfer record preservation, billing continuity, account access, security response or IANA coordination. A power alliance speaks in broad institutional terms: the RIR model, community authority, registry discretion, global stability, system integrity. Broad terms are not always wrong, but they should be connected to named services.
The second test is duration. Mutual aid is temporary. It supports a registry through a disruption and then hands authority back to ordinary governance. A power alliance has no end date. It converts emergency logic into standing doctrine. The longer a common legal position lasts, the more it needs regular public review.
The third test is reversibility. Mutual aid preserves options. It keeps records intact, maintains services, prevents double registration and avoids irreversible changes while facts are tested. A power alliance uses the crisis to entrench one interpretation of authority. It may discourage courts from ordering even narrow remedies, discourage members from pursuing appeals or discourage other registries from experimenting with better accountability.
The fourth test is transparency. Mutual aid can explain itself without revealing privileged advice: what service is protected, who requested help, who approved it, what is excluded, what costs are involved, when it will be reviewed. A power alliance relies on opaque consensus. It says the institutions agree and expects that agreement to carry the issue.
The fifth test is dissent. Mutual aid can tolerate a dissenting view about legal theory because the technical service still needs support. A power alliance treats dissent as a threat. If one registry cannot publish a narrower interpretation without being seen as undermining the whole system, the coordination layer has become too tight.
The sixth test is remedy. Mutual aid asks for the least disruptive remedy. It accepts notations, stays, independent audits, record preservation, temporary service limits, redacted disclosure, staged handback and time-limited review. A power alliance asks for deference. It frames outside remedies as destabilizing before proving that narrower remedies would fail.
The final test is who benefits. Mutual aid benefits resource holders and Internet operations. A power alliance benefits institutional incumbents first, with operators treated as reasons rather than as beneficiaries. If an operator cannot tell how the common position protects its service, the position may be more about authority than continuity.
These tests are not anti-RIR. They are pro-registry in the thin, defensible sense. A registry that separates mutual aid from power alliance is harder to attack because it can show that its legal position tracks operational necessity. It can tell a court: here is the record we must preserve, here is the update we can perform, here is the update we cannot perform without risking double registration, here is the appeal path, here is the handback point. That is more persuasive than invoking stability in the abstract.
What a disciplined shared legal position should disclose
The RIRs do not need to publish privileged communications. They do need a public-facing format for common positions that affect members, resource holders, courts and markets. The format should start with authority. Which document supports the position: the NRO MoU, ASO MoU, a global policy, a regional policy, a membership agreement, an RIR bylaw, an ICANN recognition document, an IANA services agreement, an RFC-defined technical role, or emergency continuity terms? A common statement should not rely on institutional habit when a written authority exists.
Second, it should identify the protected interest. Is the interest uniqueness, record accuracy, RPKI validity, reverse-DNS continuity, member voting integrity, financial independence, policy consistency, privacy, fraud control, auditability, recognition integrity or service availability? Each interest points to different remedies. Uniqueness may require one public current state. Privacy may require redaction. Fraud control may require evidence checks. Voting integrity may require an audit. Financial distress may require support. Mixing them weakens the analysis.
Third, it should state the affected service. Legal strategy is too broad unless it tells operators what changes. Does it affect new allocations, transfers, ROAs, delegated RPKI, hosted RPKI, reverse DNS, Whois or RDAP updates, membership standing, fee collection, account access, dispute notation, public minutes, election certification, or ICANN advice? If no service changes, the statement should say that too.
Fourth, it should describe the regional variation. If all five registries take the same position despite different local law, the public should know why. If one registry has a local-law constraint, the common position should not hide it. If a standard is only a floor, the statement should say which regions may exceed it.
Fifth, it should state the review path. A member or resource holder affected by a common legal position needs to know whether it can ask its local registry for reasons, appeal internally, seek independent review, ask the NRO to publish a clarification, raise the issue through a policy process, or go to court. If the answer is that the position is not directly appealable because it is only a public statement, that should be clear.
Sixth, it should define the expiration or review date. Legal positions age badly. A statement drafted for a crisis can become precedent after the crisis ends. A statement tied to a draft governance document should be revisited when the document changes. A statement tied to a court proceeding should be reviewed after judgment. A statement tied to an emergency continuity event should end when handback occurs.
Finally, it should separate continuity support from legal endorsement. Other RIRs may provide staff, infrastructure help or continuity funding without endorsing every act of the affected registry. That distinction is essential. If assistance is treated as endorsement, registries will hesitate to help troubled peers. If endorsement is hidden inside assistance, members will distrust mutual aid. The public format should make clear that support can be operational, legal, financial or advisory, and that each kind carries a different meaning.
Watchpoints for the next phase
The first watchpoint is the draft RIR Governance Document. It will define how recognition, operation and derecognition are handled after ICP-2. The key question is whether independent RIR recommendations remain real or become ceremonial. Published reasons, dissent, evidence standards and reconsideration rights will determine whether the document creates disciplined lifecycle governance or simply formalizes peer control.
The second watchpoint is legal-defense funding. The NRO MoU permits case-by-case contributions when an RIR faces claims for a duly authorized NRO activity. That clause should remain narrow. Public reporting should distinguish ordinary NRO activity defense from local registry litigation. Otherwise common funds could become a hidden subsidy for broad authority claims.
The third watchpoint is the Stability Fund. Its stated purpose is continuity. If it is ever activated, the public should be able to see the affected service, the requested support, the approval basis, the reporting cadence and the handback plan. That would preserve the fund's legitimacy and prevent it from being mistaken for political control.
The fourth watchpoint is ICANN-facing representation. The ASO arrangement gives the NRO a role inside ICANN, including global policy and recognition advice. When the NRO speaks to ICANN on a legal or governance issue, it should state whether it is speaking as ASO, as NRO, as five RIRs collectively, or as a coordination secretariat. Those are not the same voice.
The fifth watchpoint is RPKI. RPKI legal questions are likely to become more serious because certificate state can affect routing acceptance. If the RIRs adopt common terms for hosted service, delegated service, TAL changes, revocation, outage response or emergency operator behavior, they should separate security baseline from liability shield. Operators need reliable routing evidence, not a black box.
The sixth watchpoint is procurement pressure. Banks, insurers, cloud platforms, public agencies and large customers increasingly ask whether registry records, route-origin evidence, dispute status and account authority are dependable. If all RIRs answer those diligence questions with one broad legal theory, private contracts can start importing that theory as a market standard before any policy community has debated it. A common answer may be useful where it states a narrow fact, such as one-current-record uniqueness or the need to preserve RPKI continuity.
It is riskier where it becomes a warranty about institutional discretion, member consent, appeal limits or the absence of property-like reliance. Procurement language travels quietly. Once repeated in credit files, insurance questionnaires and cloud onboarding reviews, it can discipline operators more effectively than a public rule. The RIRs should therefore keep diligence-facing legal statements short, factual and source-bound, and should avoid using customer dependence as evidence that the institutional model itself has been accepted.
The seventh watchpoint is precedent recycling. A sentence written for a stability fund, an ICANN consultation, a court letter, an RPKI incident note or a draft governance document should not be reused in another setting without stating the original context. Legal systems often change meaning when language moves from emergency support to ordinary enforcement. The registry system should treat that movement as a review event, not as copyable institutional memory.
Every reused common position should ask: was the original claim about service continuity, recognition criteria, member obligations, security practice, cost sharing or litigation defense? If the category changes, the public explanation should change with it.
The final watchpoint is language. "Community," "stability," "integrity," "bottom-up," "coordination" and "global system" are useful words only when tied to a decision. In shared legal strategy they can become mandate multipliers. A serious registry system should make the legal theory smaller, not larger, as it moves closer to an individual resource holder's service.
The RIRs should cooperate. They should help one another survive disasters, preserve records, maintain RPKI and reverse-DNS services, coordinate IANA-facing policies and protect uniqueness. But independence is not proven by five letterheads. It is proven when the five institutions can reach different reasoned conclusions, publish those reasons, let members compare them and keep legal mutual aid from becoming a single shield for regional power. That is the line between a resilient registry system and a cartel of legal positions.
Sources and limits
This analysis relies on public NRO and ICANN-facing materials: the NRO description of its mission and coordination role, the NRO MoU, the ASO MoU, the NRO Executive Council description, the RIR Governance Matrix, the Joint RIR Stability Fund description and the 2025 draft RIR Governance Document. These sources show formal coordination, mutual support, accountability comparison and draft lifecycle governance. They do not prove secret legal coordination, shared counsel in any specific litigation, or improper collusion.
The article therefore treats "shared legal strategy" as a governance risk and design problem, not as a factual allegation that any particular RIR acted unlawfully.

