Dear SIG Members,
Please find below the Secretariat impact assessment for prop-172-v001: Defining 
Internet Abuse through IP Addresses
 
Dave Phelan
Policy Manager and Senior Network Analyst
--------
1. APNIC’s Understanding of the Proposed Policy
APNIC understands this proposal as introducing a formal definition of ‘Internet 
Abuse through IP Addresses’ into APNIC policy.
The proposal states that it does not create new enforcement powers, reporting 
requirements, or compliance mechanisms. However, the text also says APNIC 
retains responsibility for holding resource holders accountable for responding 
to and addressing abuse.
APNIC Secretariat have noted that this overlaps with the current IRT policy, 
which already requires IRT contacts to be maintained and validated.
2. Impact of Proposed Policy on Registry and Addressing System
No direct registry impact expected
3. Impact of Proposed Policy on APNIC Operation/Services
APNIC Secretariat notes that the main issue is ambiguity about APNIC’s role.The 
proposal says APNIC does not have the power to adjudicate abuse, but also says 
APNIC retains responsibility for holding resource holders accountable for 
responding to and addressing abuse. It is unclear how both can be true without 
creatingn some form of operational enforcement role. APNIC is not currently 
resourced to perform this work, and the associated cost may not be something 
the membership would expect or support.
As of 17 Aug, 2026, 2,359 out of a total of 10,815 active APNIC accounts 
(21.8%) had no validated IRT emails associated with their resources. APNIC 
marks IRT emails as invalid 15 days after sending the validation request and 
restricts MyAPNIC access if the validation is not completed in 30 days.This 
figure does not take into account those that will validate within the 30 day 
window, it is a point-in-time reference. 
4. Legal Impact of Policy
The proposal would define "Internet Abuse through IP Addresses" as the use of 
IP addresses in a way that causes technical harm to the security, stability, or 
trust of the Internet. It would also include facilitating unlawful conduct that 
the resource holder has the practical ability to address.
 Although presented as a definition, the proposal also discusses 
responsibilities, how abuse is determined, and circumstances where a resource 
holder may be protected from further action. These elements appear to go beyond 
a simple definition and could be interpreted as introducing broader operational 
expectations. A number of legal and implementation issues may arise if the 
proposal is adopted.
 The reference to "unlawful conduct" creates uncertainty because APNIC serves 
account holders operating across many different jurisdictions. Conduct that is 
unlawful in one jurisdiction may be lawful in another. In some cases, conduct 
that is unlawful in one jurisdiction may even be required by law in another. 
Resource holders may also be based in, and operate across multiple 
jurisdictions, so the legality of behaviour may differ between those different 
locations.
 The proposal states that APNIC does not have the power to adjudicate abuse. 
However, it also states that APNIC has an existing responsibility to hold 
resource holders accountable for responding to and addressing abuse. We do not 
consider this to be an accurate reflection of current policy. Section 5.3.3 of 
the APNIC Internet Number Resource Policies requires resource holders to 
maintain responsive IRT contacts and requires APNIC to validate those contacts. 
It does not require APNIC to investigate alleged abuse, determine whether abuse 
has occurred, or assess whether a resource holder's response was adequate.
 There also appears to be some conflict between these two statements. 
Determining whether abuse has been "addressed" would generally require first 
determining whether abuse occurred. This would place APNIC in an adjudication 
role, which the proposal expressly states APNIC does not have.  In any case, 
only a competent authority (e.g. – a court) is capable of determining whether 
conduct is unlawful.
 It is also unclear what is meant by "fraudulently ... sub-allocating IP 
address resources" and how such conduct would occur in practice.
 The policy objective states that the definition is intended to serve as a 
foundation for future policy proposals. While we would not normally comment on 
possible future proposals, it is worth noting that any future policy requiring 
APNIC to assess or enforce whether abuse has been addressed would represent a 
significant expansion of APNIC's current role. Historically, APNIC's 
responsibilities have focused on Internet number resource management and 
related technical matters rather than assessing conduct or content. Such a 
change would likely require additional resources, expertise, and risk 
management measures and should be considered expressly in advance of any such 
change.
 If "unlawful conduct" remains part of the definition, several practical 
questions would remain unresolved. For example, when would a finding of 
unlawfulness be considered sufficiently final? Would all appeals need to be 
exhausted? How would conflicting decisions from different jurisdictions be 
handled? These issues could create substantial administrative complexity and 
may affect APNIC's neutrality.
 The Secretariat notes that implementation may benefit from greater clarity 
about the intended scope of the definition. In particular, it may be helpful to 
confine matters to a technical definition of abuse without any operational or 
enforcement expectations that may arise from it. A definition based on 
established technical standards (such as those from IETF) may provide a more 
objective foundation than concepts based on lawfulness, although this would not 
resolve all implementation issues. Terms such as "facilitating", "hosting", 
"phishing", "fraud", "scam", and "impersonation" should also be carefully 
considered to ensure the definition does not unintentionally expand APNIC's 
role into determining questions of unlawful conduct or content.
5. Implementation
Until such point as the above clarifications are made, we are unable to make a 
determination on implementation process and time frames.
_______________________________________________
SIG-policy - https://mailman.apnic.net/[email protected]/
To unsubscribe send an email to [email protected]

Reply via email to