Dear SIG Members,
Please find below the Secretariat impact assessment for prop-172-v001: Defining
Internet Abuse through IP Addresses
Dave Phelan
Policy Manager and Senior Network Analyst
--------
1. APNIC’s Understanding of the Proposed Policy
APNIC understands this proposal as introducing a formal definition of ‘Internet
Abuse through IP Addresses’ into APNIC policy.
The proposal states that it does not create new enforcement powers, reporting
requirements, or compliance mechanisms. However, the text also says APNIC
retains responsibility for holding resource holders accountable for responding
to and addressing abuse.
APNIC Secretariat have noted that this overlaps with the current IRT policy,
which already requires IRT contacts to be maintained and validated.
2. Impact of Proposed Policy on Registry and Addressing System
No direct registry impact expected
3. Impact of Proposed Policy on APNIC Operation/Services
APNIC Secretariat notes that the main issue is ambiguity about APNIC’s role.The
proposal says APNIC does not have the power to adjudicate abuse, but also says
APNIC retains responsibility for holding resource holders accountable for
responding to and addressing abuse. It is unclear how both can be true without
creatingn some form of operational enforcement role. APNIC is not currently
resourced to perform this work, and the associated cost may not be something
the membership would expect or support.
As of 17 Aug, 2026, 2,359 out of a total of 10,815 active APNIC accounts
(21.8%) had no validated IRT emails associated with their resources. APNIC
marks IRT emails as invalid 15 days after sending the validation request and
restricts MyAPNIC access if the validation is not completed in 30 days.This
figure does not take into account those that will validate within the 30 day
window, it is a point-in-time reference.
4. Legal Impact of Policy
The proposal would define "Internet Abuse through IP Addresses" as the use of
IP addresses in a way that causes technical harm to the security, stability, or
trust of the Internet. It would also include facilitating unlawful conduct that
the resource holder has the practical ability to address.
Although presented as a definition, the proposal also discusses
responsibilities, how abuse is determined, and circumstances where a resource
holder may be protected from further action. These elements appear to go beyond
a simple definition and could be interpreted as introducing broader operational
expectations. A number of legal and implementation issues may arise if the
proposal is adopted.
The reference to "unlawful conduct" creates uncertainty because APNIC serves
account holders operating across many different jurisdictions. Conduct that is
unlawful in one jurisdiction may be lawful in another. In some cases, conduct
that is unlawful in one jurisdiction may even be required by law in another.
Resource holders may also be based in, and operate across multiple
jurisdictions, so the legality of behaviour may differ between those different
locations.
The proposal states that APNIC does not have the power to adjudicate abuse.
However, it also states that APNIC has an existing responsibility to hold
resource holders accountable for responding to and addressing abuse. We do not
consider this to be an accurate reflection of current policy. Section 5.3.3 of
the APNIC Internet Number Resource Policies requires resource holders to
maintain responsive IRT contacts and requires APNIC to validate those contacts.
It does not require APNIC to investigate alleged abuse, determine whether abuse
has occurred, or assess whether a resource holder's response was adequate.
There also appears to be some conflict between these two statements.
Determining whether abuse has been "addressed" would generally require first
determining whether abuse occurred. This would place APNIC in an adjudication
role, which the proposal expressly states APNIC does not have. In any case,
only a competent authority (e.g. – a court) is capable of determining whether
conduct is unlawful.
It is also unclear what is meant by "fraudulently ... sub-allocating IP
address resources" and how such conduct would occur in practice.
The policy objective states that the definition is intended to serve as a
foundation for future policy proposals. While we would not normally comment on
possible future proposals, it is worth noting that any future policy requiring
APNIC to assess or enforce whether abuse has been addressed would represent a
significant expansion of APNIC's current role. Historically, APNIC's
responsibilities have focused on Internet number resource management and
related technical matters rather than assessing conduct or content. Such a
change would likely require additional resources, expertise, and risk
management measures and should be considered expressly in advance of any such
change.
If "unlawful conduct" remains part of the definition, several practical
questions would remain unresolved. For example, when would a finding of
unlawfulness be considered sufficiently final? Would all appeals need to be
exhausted? How would conflicting decisions from different jurisdictions be
handled? These issues could create substantial administrative complexity and
may affect APNIC's neutrality.
The Secretariat notes that implementation may benefit from greater clarity
about the intended scope of the definition. In particular, it may be helpful to
confine matters to a technical definition of abuse without any operational or
enforcement expectations that may arise from it. A definition based on
established technical standards (such as those from IETF) may provide a more
objective foundation than concepts based on lawfulness, although this would not
resolve all implementation issues. Terms such as "facilitating", "hosting",
"phishing", "fraud", "scam", and "impersonation" should also be carefully
considered to ensure the definition does not unintentionally expand APNIC's
role into determining questions of unlawful conduct or content.
5. Implementation
Until such point as the above clarifications are made, we are unable to make a
determination on implementation process and time frames.
_______________________________________________
SIG-policy - https://mailman.apnic.net/[email protected]/
To unsubscribe send an email to [email protected]