First meeting of the UN Global ICT Mechanism: China proposes new rules for cyber governance.

From 20 to 24 July 2026, a landmark event in the sphere of digital diplomacy took place at the United Nations Headquarters in New York — the first plenary session of the permanent Global Mechanism on Developments in the Field of Information and Communication Technologies (ICTs) in the Context of International Security and Advancing Responsible State Behaviour in the Use of ICTs (1). This round of negotiations officially ended the era of the temporary mandates of the Open-Ended Working Groups (OEWGs) and established a permanent international format under the auspices of the United Nations.

In fact, July 2026 marked the end of the first year of the existence of the Permanent UN Mechanism on Global Cybersecurity, the decision to establish which was agreed upon in July 2025. Prior to this, for more than 20 years, interstate dialogue on ensuring international cybersecurity and developing rules of conduct in the digital sphere was conducted through temporary and successive Groups of Governmental Experts (GGEs, established from 2001–2004 in a closed format for 15–25 countries) and Open-Ended Working Groups (OEWGs, launched in 2018–2019 as an open format for all 193 UN Member States). The UN Global Mechanism on ICT Security was agreed upon in July 2025 at the final session of the UN Open-Ended Working Group, formally established by a UN General Assembly resolution at the end of December 2025, and began its work in March 2026 as the first permanent negotiating forum for all 193 countries (2).

The UN Global Mechanism will operate in several formats. In-person plenary sessions are planned to be held annually within each biennial cycle. The main areas of work will include the analysis of existing and potential threats, the application of international law in the field of ICTs, norms of responsible State behaviour, confidence-building measures, and capacity-building, primarily for developing countries. Every five years, a review conference will be held to assess the progress achieved and determine further areas of work, while intersessional meetings may be convened when necessary. Non-governmental organisations with ECOSOC status (holding consultative status with the United Nations Economic and Social Council) will be eligible for accreditation to participate in plenary sessions and review conferences. Other interested stakeholders will be admitted on the basis of the non-objection principle. The legal basis of the Mechanism was established by UN General Assembly Resolution A/RES/80/16 (3), which endorsed the final report of the Open-Ended Working Group A/80/257 (4), setting out its structure and main areas of activity.

The body of existing agreements forms the framework for responsible State behaviour in cyberspace. It is sometimes referred to by the term acquis communautaire, borrowed from the practice of the European Union, where it denotes the body of common rules, rights, and obligations accepted by all Member States. However, in the context of international cybersecurity, the content of this body of agreements still lacks a single and clearly defined scope (2). It is based on the reports of the UN Group of Governmental Experts of 2010 (5), 2013 (6), 2015 (7), and 2021 (8), as well as the final report of the Open-Ended Working Group for 2021–2025 (9).

For more focused and practical work, two permanent Dedicated Thematic Groups have been established (10). The first group will address specific threats and challenges to international ICT security, drawing on the main pillars of the framework for responsible State behaviour. Its work is intended to contribute to an open, secure, stable, accessible, peaceful, and interoperable ICT environment and provides for the participation of technical experts and other stakeholders. The second group will focus on strengthening States’ ICT security capacity, including the exchange of experience, identification of needs, technical assistance, and training, with the participation of relevant experts, practitioners, and other stakeholders. The first meetings of both groups are scheduled for 7–11 December 2026.

One of the most contentious issues surrounding the launch of the Global Mechanism was the procedure for appointing co-facilitators for the two Dedicated Thematic Groups. These positions carry significant influence, as the co-facilitators will guide discussions, participate in shaping the agenda, and transmit the groups’ recommendations to the plenary session.

The approach proposed by the Chair of the Global Mechanism, Egriselda Aracely González López (11), provides for her appointment of two co-facilitators for each group — one representative from a developed country and one from a developing country — taking into account geographical balance and professional expertise. This approach is supported by a broad coalition of States, including the EU, which spoke on behalf of its Member States and several partner countries, such as France, Germany, Australia, the United Kingdom, the Netherlands, Switzerland, Japan, Egypt, Senegal, Nigeria, Malaysia, Moldova, and others.

China, the Russian Federation, Iran, Belarus, Nicaragua, and Cuba propose that candidates for co-facilitators be approved by consensus among participating States. Thus, the disagreement concerns the choice between the appointment of co-facilitators by the Chair and their collective approval by all States (2).

Alongside organisational matters, the first plenary session of the UN Global Mechanism on ICT Security became a platform for States to present their own approaches to the future international regulation of cyberspace. Against this background, China’s initiative deserves particular attention, as China was among the first countries to seek to provide the new permanent format with a substantive agenda and offered its own vision of the principles of global digital governance.

At the session, the Chinese delegation presented a document devoted to the principles of digital sovereignty and global cyberspace governance in the era of artificial intelligence. The “Position Paper of China on Global Cyberspace Governance in the Era of Digital Intelligence” (12), presented by Beijing, reflects the PRC’s long-term strategy aimed at reshaping and organising the rules of the game in the global technological space.

The PRC formulates three main blocks of proposals: compliance with international law and the prevention of cyber conflicts; protection of digital sovereignty and equal access to technologies; and the formation of a multilateral system for managing new technological risks.

1. Compliance with international rules and the preservation of peace and stability

The starting point of the Chinese approach is the growing conflict potential of the digital environment. According to Beijing, the development of artificial intelligence and other emerging technologies “has heightened cybersecurity risks by lowering the threshold for cyberattacks and conflicts between countries,” while the disruption of technological and production chains has brought the digital world closer to “division and disorder.”

China proposes fully extending the principles of international law to the digital sphere: “Cyberspace is an extension of the real world. All countries should observe the purposes and principles of the UN Charter in cyberspace, particularly the principles of refraining from the use or threat of force, peacefully settling disputes, and non-interference in internal affairs,” the document states.

Beijing regards cyberspace as another sphere of interstate relations in which the same legal restrictions should apply as in the world as a whole. At the same time, the document does not yet establish the criteria under which a cyberattack may be recognised as a use of force or an act of aggression. The definition of these criteria appears to have been deferred to subsequent international negotiations.

Particular attention is devoted to the protection of critical infrastructure. China proposes establishing a list of facilities that should be protected from cyberattacks.

Countries should not use cyber means to damage the critical infrastructure of other countries, particularly critical information infrastructure vital to national well-being and public interests, such as energy, transportation, water resources, finance, public services, e-government, and defence science and technology.”

2. Respect for digital sovereignty and the promotion of development for all

The second block is built around the principle of digital sovereignty, which is central to China: “Countries should respect each other’s digital sovereignty, and each country has the right to independently choose its path for developing digital and intelligent technologies, including AI, as well as to independently select AI technologies, products, and services in accordance with its national conditions. No country should be forced to take sides.”

This formula establishes the right of a State to independently regulate its national information space, data, and digital infrastructure. At the same time, it reflects China’s resistance to the division of the world into competing American and Chinese technological ecosystems. Beijing opposes pressure on third countries aimed at forcing them to abandon Chinese equipment, software, and artificial intelligence systems.

The same position is expressed through criticism of technological restrictions: “It is important to refrain from excessive securitisation, the pursuit of technological monopolies or exclusionary arrangements, as well as the pursuit of digital and intelligent hegemony driven by national priorities.”

This wording reflects opposition to US export controls, restrictions on the supply of advanced semiconductors to China, and the displacement of Chinese companies from international markets under the pretext of national security. As an alternative, Beijing proposes keeping global digital and technological supply chains “open, secure, and stable,” while also strengthening the technological capacity of developing countries. This position allows China simultaneously to protect its own industrial interests and present itself as a representative of the interests of the Global South, which is interested in access to affordable technologies without being required to make a geopolitical choice.

3. Upholding multilateralism and effectively addressing risks

The third block defines China’s proposed architecture for global cyberspace governance: “It is important to strike a balance between development and security, uphold the leading role of governments and the participation of all stakeholders, and work towards establishing a multilateral, democratic, and transparent system of global Internet governance.”

The central role in this system should belong to States, while businesses, technology corporations, and the expert community are regarded as participants rather than independent centres of decision-making: “Government governance should not be replaced by private-sector governance, international governance should not be replaced by governance by a small circle, and no country should unilaterally impose rules on others.”

China also opposes a situation in which the rules of the digital environment are established by the largest Western technology companies or a limited group of States. Moving the negotiations into the UN system allows Beijing to rely on the principle of the sovereign equality of all 193 countries and the support of a significant part of the Global South.

The most concrete proposal concerns the regulation of artificial intelligence: “Countries should promote the establishment of global standards and systems for testing and assessing the risk levels of large AI models and ensure that AI becomes a new shield for cybersecurity rather than a new instrument for the unilateral pursuit of hegemony.”

China proposes moving from general declarations to the international standardisation of the security of large AI models. At the same time, the document does not yet specify who should conduct the testing or to what extent its results would be binding.

Another area is the regulation of cross-border data flows: “It is important to strengthen cross-border cooperation on data, facilitate cross-border data flows, develop global principles and norms governing them, and ensure the data security of all countries.”

Beijing seeks to combine the openness of the global digital economy with the right of States to control national data. This entails seeking an international compromise between the free movement of information and the principle of digital sovereignty.

In its concluding section, China declares its readiness to use the UN Global Mechanism to “build a fairer, more equitable, and more effective international order in cyberspace.” Overall, the document advances a State-centred model of digital governance based on the leading role of the UN, the sovereign equality of countries, and limitations on the influence of individual States and technology corporations. At the same time, Beijing is also protecting its own strategic interests: preserving global supply chains, countering technological containment, maintaining Chinese companies’ access to international markets, and ensuring the PRC’s participation in shaping the future rules of the digital era.

Overall, the Chinese document sets the discussion in the right direction: the digital environment needs clearer international rules, and their development should take place on a universal platform with the participation of developed and developing countries. China was among the first countries, following the launch of the Permanent UN Mechanism, to propose a comprehensive vision of the future digital order, bringing together within a single concept the application of international law, the protection of critical infrastructure, digital sovereignty, the regulation of artificial intelligence, cross-border data flows, and developing countries’ access to technology.

The relevance of this initiative is confirmed by the assessments presented directly at the first plenary session of the UN Global Mechanism on ICT Security. The International Committee of the Red Cross (13) reported that modern cyber operations are already causing disruptions to electricity and water supplies, transport, banking systems, and food production, while also affecting medical and humanitarian organisations. The International Committee of the Red Cross separately warned that the use of artificial intelligence increases the speed, scale, and potential harm of cyber operations, creating risks of damage to civilian infrastructure.

European data also point to the growing complexity of these threats. According to the CERT-EU report on cyber threats in 2025, published in April 2026 (14), the number of identified actors engaged in malicious activity against EU institutions and related organisations increased from 110 in 2024 to 174 in 2025. CERT-EU recorded attacks on 198 software products, compared with 110 a year earlier, as well as the growing use of artificial intelligence for voice cloning, personalised phishing, and the creation of deepfakes. In one identified case, an autonomous agentic AI system was used to attack 30 organisations across various sectors. These data demonstrate that the existing regulatory system is developing more slowly than the technologies themselves and the methods of their malicious use.

The practical value of the Chinese initiative lies in its attempt to move the discussion from the general identification of threats towards the formation of a comprehensive system of international regulation. However, the next stage should involve a more detailed legal and technical elaboration of the proposed principles. First of all, it is necessary, for example, to clearly agree on definitions of such concepts as cyberattack, cyberaggression, critical infrastructure, digital sovereignty, excessive securitisation, and technological hegemony. Without common assessment criteria, influential States will be able to freely classify similar actions: treating an operation against their own infrastructure as an act of aggression while regarding a comparable operation against another country as a permissible security measure or a retaliatory operation.

Agreed mechanisms are also needed to determine the source of a cyberattack, verify evidence, and establish the responsibility of States for the activities of non-State groups linked to them or operating from their territory. Without common rules for identifying the responsible party, accusations of cyberattacks may become an instrument of political pressure, while individual States may gain the opportunity to deny their own involvement and assign responsibility to their competitors on the basis of classified or unverified information.

The boundaries of critical infrastructure protection require separate clarification. The inclusion of defence science and industry in this category raises the issue of dual-use enterprises that simultaneously serve civilian and military needs. Future rules should clearly define which facilities enjoy special protection, under what conditions that protection is maintained, how indirect harm to the civilian population is assessed, and where the line lies between a cyber operation, sabotage, and the use of force.

The principle of digital sovereignty must also be clearly aligned with the free exchange of data, the openness of the Internet, and international human rights obligations. States have the right to protect their information infrastructure and national data, but the limits of such control should be clear and uniform for all. Otherwise, digital sovereignty could be used to justify virtually any restrictions on the Internet.

Common and measurable criteria are required to assess the risks of large AI models: who conducts the testing, what data developers must disclose, and how an adopted decision may be appealed. It is important that security requirements are not used to displace competing technologies or restrict individual countries’ access to digital development. Therefore, the concepts of “hegemony,” “excessive securitisation,” and “exclusionary arrangements” require precise definitions that make it possible to distinguish necessary security measures from politically motivated technological pressure.

Thus, China is raising the issue of bringing order to the digital space in a timely manner, as a dangerous gap is already emerging between technological capabilities and international rules. The implementation of the Chinese initiative requires maintaining a very delicate balance between protecting digital sovereignty and preserving the openness of the Internet, ensuring State security and respecting human rights, regulating technology and maintaining free competition. With precise definitions, transparent verification procedures, and universally applicable norms, this initiative could become a practical foundation for the work of the UN Global Mechanism, as well as an effective instrument for implementing international law and protecting human rights in the digital environment, while simultaneously limiting the scope for double interpretations of the rules by the most influential actors in the international system. If the key provisions remain insufficiently specific and legally developed, the new norms may become an instrument of political manipulation and the advancement of the technological interests of certain major global actors.

 

 

Oksana Krasovskaya, Political Analyst at the Ukrainian Institute of Politics

 

 

 

List of references.

 

  1. First substantive session of the UN Global Mechanism on cybersecurity. https://dig.watch/event/first-substantive-session-of-the-un-global-mechanism-on-cybersecurity

2. UN Global Mechanism on ICT security. https://dig.watch/processes/un-gge

  1. Resolution adopted by the General Assembly on 1 December 2025. https://docs.un.org/en/A/RES/80/16

  2. Developments in the field of information and telecommunications in the context of international security https://docs.un.org/en/A/80/257

  3. Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security. https://docs.un.org/en/A/65/201

  4. 2013 UN GGE report (A/68/98). https://dig.watch/resource/un-gge-report-2013-a689

  5. 2015 UN GGE – Report of the group of governmental experts on developments in the field of information and telecommunications in the context of international security (A/70/174) https://dig.watch/resource/un-gge-report-2015-a70174

  6. UN GGE 2021 report. https://dig.watch/resource/un-gge-2021-report

  7. UN OEWG 2021-2025 Final Report. https://dig.watch/resource/oewg-report-2021-2025

  8. Global Mechanism on ICTs in the Context of International Security — Dedicated Thematic Groups. https://meetings.unoda.org/meeting/76829

  9. Chair’s Non-Paper: Organization of Work of the Dedicated Thematic Groups of the Global Mechanism. https://docs-library.unoda.org/Global_Mechanism_on_ICTs_in_the_Context_of_International_Security_-Plenary_%282026%29/2026.06.08_GMech05_Letter_from_the_Chair._Non-paper_DTGs._Townhall_consultation.pdf?utm_source=chatgpt.com

  10. China’s Position Paper on Global Cyber Governance In the Digital Intelligent Age. https://www.fmprc.gov.cn/eng/wjb/zzjg_663340/jks_665232/kjlc_665236/qtwt_665250/202607/t20260722_11989699.html

  11. (4th meeting) Plenary Session, Global Mechanism on ICTs in the Context of International Security (20-24 July). https://transcripts.un.org/en/asset/k14/k14hbvhuvt?utm_source=chatgpt.com

  12. Threat Landscape Report 2025: A Year in Review. https://cert.europa.eu/blog/threat-landscape-report-2025?utm_source=chatgpt.com

 

 

Аналитические материалы УИП

  • ​​​​​​​Crumbling of American security guarantees. Why is South Korea asking for peace?
  • Negotiations between Ukraine and Russia: the parties are betting on the continuation of a protracted war.
  • WEEKLY REVIEW: THE UKRAINIAN DIMENSION (17–24 June 2026).
  • WEEKLY REVIEW: THE UKRAINIAN DIMENSION (3–10 June 2026).
  • Weekly Review. Overview of the Situation Around Ukraine (May 20–27, 2026).
  • Weekly Summary. Overview of the situation around Ukraine (May 6–13, 2026).
  • Results of the week. Overview of the situation around Ukraine. 22 – 29 April 2026
  • The Franco-German concept of Ukraine's interim status in the EU is a "waiting room" with delayed integration.
  • Підсумки тижня. Огляд ситуації навколо України. 8 – 15 квітня 2026