UN Global Mechanism on ICT Security highlights growing role of stakeholders

The UN’s permanent cyber mechanism devoted a full session to accredited stakeholders, with technical organisations, civil society groups, humanitarian actors, and youth representatives calling for greater participation in shaping international cybersecurity cooperation and urging member states to make stakeholder engagement a practical part of implementing the UN cyber framework.

The sixth meeting of the first substantive plenary session of the Global Mechanism on ICTs in the Context of International Security combined stakeholder interventions with discussions on international law and confidence-building measures (CBMs). Throughout the day, speakers argued that responsible state behaviour in cyberspace increasingly depends on close cooperation with the technical community, researchers, industry, humanitarian organisations, and civil society.

A recurring concern was the exclusion of more than 60 accredited organisations from formal participation. Multiple stakeholders called on member states to adopt transparent, criteria-based accreditation procedures, arguing that meaningful implementation of the UN cyber framework requires inclusive multistakeholder participation.

Technical community highlights operational expertise

Several organisations emphasised that many of the practical tools needed to strengthen cybersecurity already exist outside governments.

ICANN outlined its work on strengthening the resilience of the internet’s domain name system, while the Internet Society highlighted initiatives supporting routing security, internet exchange points, and critical cybersecurity infrastructure. FIRST, representing hundreds of incident response teams worldwide, stressed the importance of international cooperation among technical responders, responsible vulnerability disclosure, and operational collaboration during cyber incidents.

Other stakeholders focused on implementation challenges. Chatham House argued that practical guidance alone is insufficient unless states also possess the institutional capacity to apply it, while Developing Capacity LTD highlighted existing resources and cyber capacity-building initiatives that could support the work of the Dedicated Thematic Groups (DTGs).

Youth, civil society and humanitarian perspectives

The Discover MUN Foundation, speaking on behalf of the UN Major Group for Children and Youth, called for age-disaggregated data on malicious cyber activity, dedicated youth capacity-building initiatives, and recognition of youth engagement itself as a confidence-building measure.

Human rights organisations drew attention to the disproportionate impact of cyber threats on vulnerable communities, while Access Now highlighted the growing number of internet shutdowns during armed conflicts and called for greater attention to the human consequences of cyber operations. The Centre for Humanitarian Dialogue introduced another emerging issue by encouraging states to begin developing confidence-building measures specifically for post-conflict cyber environments.

States back stronger cooperation with stakeholders

During the interactive dialogue, several member states acknowledged the value of stakeholder expertise.

Canada, the European Union, Japan, Chile, Germany, and Mexico encouraged stronger collaboration with technical organisations, academia, and civil society, particularly within the DTGs. Delegations also criticised the exclusion of numerous accredited organisations, arguing that broader participation would strengthen implementation of the UN framework rather than complicate negotiations.

Stakeholders responded by offering practical implementation resources, including policy guidance, technical expertise, training programmes, capacity-building platforms, and operational tools that could support future work under the Global Mechanism.

International law discussions remain implementation-focused

The session also continued discussions on the application of international law to cyberspace.

Switzerland and Australia argued that the mechanism should build on existing areas of legal convergence by examining practical cyber scenarios through the DTGs. The International Committee of the Red Cross called for greater attention to how international humanitarian law protects civilian infrastructure and addresses emerging technologies such as AI in armed conflict.

While Algeria and Nicaragua continued to support the eventual development of legally binding international instruments, the United States maintained that existing international law remains sufficient and that discussions should focus on implementation rather than negotiating new treaties.

Confidence-building measures move towards implementation

The final part of the session focused on operationalising the confidence-building measures agreed during the previous UN Open-ended Working Group.

Many delegations identified the Global Points of Contact Directory as one of the mechanisms’ most practical achievements, describing it as an important tool for crisis communication and incident response. Small island developing states, including Kiribati and Nauru, emphasised that reliable communication channels are essential for countries with limited diplomatic and technical resources.

Regional initiatives such as the Pacific Cybersecurity Operational Network were repeatedly cited as examples of how regular cooperation, information sharing, and practical exercises can build trust before cyber incidents occur.

Closing the meeting, the Chair thanked both member states and stakeholders for their extensive contributions and noted that discussions on confidence-building measures would continue the following day.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UN Global Mechanism on ICT security shifts focus to implementing international law in cyberspace

The UN’s permanent cyber mechanism continued its substantive work by focusing on how international law should be applied in cyberspace, with member states broadly agreeing that the priority is no longer whether international law applies, but how to translate that consensus into practical implementation.

During the fifth substantive plenary session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, delegations reaffirmed that international law, including the UN Charter, applies to state conduct in cyberspace. Discussions instead centred on deepening common understanding through scenario-based exchanges, legal capacity development, and practical implementation within the mechanism’s Dedicated Thematic Groups (DTGs).

While some states continued to advocate for new legally binding international instruments, the prevailing view was that the immediate priority should be strengthening the implementation of the existing legal framework and helping all countries participate meaningfully in its development.

From legal principle to practical application

A broad cross-regional coalition led by Switzerland argued that the mechanism should focus on clarifying how international law applies in practice rather than revisiting questions already settled through previous UN processes.

The group identified five priority areas for future discussions, such as sovereignty and non-intervention, state responsibility and due diligence, the prohibition of the use of force and self-defence, international humanitarian law (IHL), and international human rights law. It also encouraged scenario-based discussions examining issues such as cyber operations targeting hospitals, water systems, and energy infrastructure.

The Pacific Islands Forum, represented by Tonga, similarly reaffirmed that international law applies to cyberspace while stressing that legal capacity development should become a cross-cutting priority before discussions turn to new legally binding obligations. The Forum proposed regional workshops, peer exchanges, expert briefings, and practical exercises to help states develop national legal positions.

Practical implementation takes centre stage

The European Union, Australia and several cross-regional coalitions argued that the mechanism should build on the work already undertaken through successive UN Groups of Governmental Experts (GGEs) and Open-ended Working Groups (OEWGs).

Delegations highlighted the growing number of national and regional statements explaining how countries interpret the application of international law in cyberspace, describing these as important confidence-building measures that improve transparency and reduce the risk of misunderstanding.

Many speakers also identified the DTGs as the most appropriate venue for examining practical legal questions through realistic case studies, expert briefings, and exchanges of national experience.

Legal capacity emerges as a central issue

One of the session’s strongest themes was the need to ensure that all states can participate effectively in discussions on international law.

Kiribati offered a particularly candid account of the resource constraints facing many small developing countries, explaining that international law represents their principal means of protection despite having limited legal and technical capacity.

The delegation argued that legal capacity building is not a secondary issue but a prerequisite for meaningful participation, advocating practical, scenario-based exercises to help governments translate legal principles into operational understanding.

This emphasis was echoed by the African Group, Mauritius, Malawi, Singapore, Botswana, Vanuatu, and many other delegations, which called for tailored capacity-building programmes, regional cooperation, and support for the development of national positions on international law.

International humanitarian law remains an important focus

The applicability of international humanitarian law to cyber operations featured prominently throughout the debate.

Numerous delegations argued that recognising IHL in cyberspace does not legitimise cyberwarfare or militarise cyberspace, but instead ensures that civilians and protected infrastructure continue to benefit from established legal protections during armed conflict.

Several countries nevertheless argued that cyberspace presents unique legal challenges requiring greater caution or the future development of additional international rules, reflecting one of the principal areas of continuing disagreement.

Diverging views on future legal instruments

Although there was broad agreement on the applicability of international law, member states remained divided over whether additional legally binding instruments were needed.

Russia, China, Iran, Cuba, and Venezuela argued that the distinctive characteristics of cyberspace justify the development of new international legal frameworks alongside existing commitments. By contrast, a larger group of states, including the European Union, the Pacific Islands Forum, the Republic of Korea, Canada, Ireland, France, and New Zealand, maintained that existing international law provides an adequate foundation, with efforts better directed towards improving common understanding and implementation.

Despite these differences, the discussion revealed broad convergence around the practical direction of the Global Mechanism. Delegations consistently supported greater transparency through national legal positions, stronger legal capacity development, and scenario-based discussions that enable governments to apply international law to real-world cyber incidents.

As the session concluded, the Chair confirmed that discussions on international law would continue before the mechanism moved to its next agenda item on confidence-building measures.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Singapore expands AI governance training partnership with IAPP

Singapore’s Infocomm Media Development Authority (IMDA) and the International Association of Privacy Professionals (IAPP) have signed a three-year agreement to expand AI governance training, reflecting growing demand for professionals who can oversee the safe and responsible deployment of AI.

The Memorandum of Intent aims to equip regulators, industry leaders and practitioners with the skills needed to address increasingly complex issues related to AI governance, responsible data use and emerging technology regulation.

Under the partnership, professionals in Singapore will gain broader access to training and certification, including the IAPP’s AI Governance Professional programme. The organisations said demand is growing for specialists who can help organisations manage AI risks while supporting innovation.

IMDA and the IAPP will also continue integrating the Singapore Data Festival with the IAPP Asia Forum for another three years. The joint event will bring together policymakers, regulators and industry experts to discuss developments in AI governance, data protection and digital responsibility, reinforcing Singapore’s position as a regional hub for trusted digital governance.

The agreement was signed by Denise Wong, Commissioner of Singapore’s Personal Data Protection Commission and IMDA Assistant Chief Executive, and IAPP President and CEO J. Trevor Hughes.

Wong said the partnership would equip regulators and industry leaders with practical skills while attracting more international expertise to Singapore, while Hughes emphasised the growing importance of trained professionals as AI transforms industries.

The partnership will also promote discussions on ethical AI, trustworthy systems and organisational accountability, with both organisations aiming to help practitioners translate high-level governance principles into operational practice.

Why does it matter?

As AI regulation becomes more sophisticated, organisations increasingly need professionals who can translate legal requirements and ethical principles into practical governance processes. Training and certification programmes are becoming an important part of building the institutional capacity needed for responsible AI deployment.

The partnership also reinforces Singapore’s ambition to position itself as a regional centre for AI governance and digital trust. By combining international certification with local policy initiatives, it aims to strengthen the expertise needed to support AI adoption across both the public and private sectors.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Singapore expands AI strategy to accelerate enterprise adoption and workforce skills

Singapore is sharpening its AI strategy with a stronger emphasis on accelerating business adoption, expanding AI skills and strengthening governance, as the country seeks to translate AI capabilities into broader economic impact.

Speaking at IBM Think on Tour Singapore, Minister Josephine Teo said the updated approach builds on the National AI Strategy by narrowing the gap between widespread individual AI use and slower enterprise adoption.

Initiatives include the National AI Impact Programme, AI training for digital leaders, support for AI ‘bilinguals’ who combine domain expertise with AI knowledge, and expanded compute resources for organisations developing tailored AI applications.

Singapore is also working to make AI adoption more inclusive by helping professionals and SMEs access AI tools, skills and computing resources. Partnerships with technology companies will support organisations in identifying practical use cases and integrating AI into their operations.

Alongside expanding AI adoption, Singapore is strengthening governance frameworks to address risks associated with increasingly capable agentic AI systems. The country is also investing in quantum technologies as part of its broader ambition to position itself as a global AI innovation hub.

Why does it matter?

Singapore’s updated strategy reflects a broader shift in national AI policies from developing technical capabilities to accelerating adoption across the economy. Increasingly, governments are focusing not only on creating AI technologies but also on ensuring that businesses, workers and public institutions have the skills, infrastructure and support needed to use them effectively.

The strategy also demonstrates how AI competitiveness is becoming closely linked with governance and workforce development. By combining investment in AI adoption, talent and risk management, Singapore aims to strengthen its position as a regional AI hub while preparing for more advanced technologies such as agentic AI and quantum computing.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

India expands Ayush Grid digital health infrastructure

India’s Ministry of Ayush has reported progress in expanding the Ayush Grid, a digital public infrastructure designed to support healthcare delivery, research, regulation, education and public services across the country’s traditional medicine sector.

The ministry said it has developed 24 e-governance platforms, including the My Ayush Integrated Services Portal, which brings together ministry services within a single digital ecosystem and features a beta AI chatbot to assist users.

The Ayush Hospital Management Information System supports patient registration, electronic health records, referrals and continuity of care. As of 15 July 2026, the platform had been adopted by 5,386 Ayush healthcare facilities.

Other digital platforms include the Ayush Research Portal, containing more than 43,000 curated publications, the Ayush Anudan funding portal, the Ayush Nivesh Saarthi investment gateway and the e-Charak medicinal plant marketplace.

Additional services support yoga programmes, health assessments and infrastructure planning. More than 760,000 organisations registered for Yoga Sangam during the International Day of Yoga 2026, while 6,002 facilities have been mapped through the PM GatiShakti Ayush Asset Mapping Tool.

The Swasthya Assessment Scale has also enrolled 1,335 doctors across 221 facilities.

The ministry plans to strengthen interoperability, multilingual services and data-driven governance while expanding the use of AI and machine learning. Future work will also focus on closer integration with national digital health initiatives, including the Ayushman Bharat Digital Mission, to improve access to Ayush services, particularly in rural and underserved areas.

Why does it matter?

The Ayush Grid demonstrates how India is extending its digital public infrastructure approach beyond conventional healthcare into traditional medicine. By integrating clinical services, research, funding and citizen-facing platforms, the initiative aims to improve coordination, transparency and continuity of care across the sector.

The planned expansion of interoperability, AI and multilingual digital services also reflects a broader shift towards data-driven health governance. Closer integration with national digital health programmes could improve access to healthcare while strengthening the role of traditional medicine within India’s wider digital health ecosystem.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

South Korea expands AI diplomacy through new development package

South Korea has unveiled the ‘K-AI Package’, a development cooperation strategy that combines AI infrastructure, digital capacity development and development finance to support AI adoption in developing countries while expanding international opportunities for Korean technology companies.

The strategy was presented on 20 July during a ministerial meeting on global economic affairs chaired by Deputy Prime Minister and Minister of Economy and Finance Koo Yun Cheol.

The initiative combines AI solutions, AI data centres and renewable energy facilities with infrastructure projects financed through the Economic Development Cooperation Fund. It covers seven sectors, including water management, healthcare, energy, transport, agriculture, culture and education, with projects ranging from AI-supported dam management and medical diagnosis systems to smart farming, renewable energy technologies and AI education programmes.

South Korea plans to integrate the package with existing development cooperation mechanisms, including the Knowledge Sharing Program, trust funds, development finance and joint financing with multilateral development banks.

Alongside infrastructure projects, the government will support partner countries in developing AI legislation, standards and institutions while investing in technical education, workforce training and local capacity development.

From the second half of 2026, South Korea will identify partner countries’ priorities and propose tailored K-AI projects before moving to implementation. AI will also become a priority under the Knowledge Sharing Program in 2027, while a proposed global AI hub will support technology adoption and skills development in emerging economies.

Why does it matter?

The K-AI Package illustrates how development cooperation is becoming an increasingly important instrument of AI diplomacy. Rather than focusing solely on technology exports, South Korea is combining infrastructure, policy advice, skills development and financing to help partner countries build AI capacity.

The initiative also reflects growing international competition to shape the global AI ecosystem through development partnerships. By linking development assistance with industrial strategy, South Korea aims to expand opportunities for its AI industry while strengthening long-term digital cooperation with emerging economies.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

ILO supports digital workplace safety tool in Malaysia

The International Labour Organization (ILO) has supported the launch of a digital occupational safety and health (OSH) assessment tool in Malaysia to help employers strengthen workplace safety, improve regulatory compliance and better protect workers.

Developed by the Malaysian Employers Federation (MEF) with support from the EU-funded PROTECT project, the tool was introduced during practical training for more than 80 employers in Port Klang.

The MEF–ILO OSH Digital Assessment Tool enables employers to conduct occupational safety and health assessments through a structured digital platform, while the accompanying OSHAWA Handbook provides practical guidance on implementing workplace safety measures.

Together, they aim to improve risk identification, strengthen compliance with Malaysian legislation and promote a stronger workplace safety culture across industries.

The initiative builds on Malaysia’s strengthened occupational safety framework following amendments to the Occupational Safety and Health Act 1994, which expanded workplace coverage and introduced more robust risk assessment requirements.

It also supports responsible business practices by helping employers meet growing international expectations on labour rights, human rights due diligence and workplace safety within global supply chains.

A particular focus of the project is improving protection for migrant workers, who make up a significant share of the workforce in sectors including manufacturing, construction, plantations and services.

By integrating the digital assessment tool into MEF’s long-term advisory and training services, the ILO aims to expand its use across Malaysia and support lasting improvements in workplace safety..

Why does it matter?

The initiative illustrates how digital tools are increasingly being used to strengthen labour governance by making workplace risk assessments more systematic, consistent and accessible. Digital platforms can also help employers monitor compliance more effectively and respond more quickly to occupational safety risks.

The project further reflects growing international expectations that businesses demonstrate responsible labour practices throughout global supply chains. By supporting compliance with both national legislation and international standards, digital workplace safety tools can improve worker protection while helping companies meet evolving regulatory and due diligence requirements.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UNESCO and Egypt introduce AI framework for teachers

UNESCO and Egypt’s Ministry of Education and Technical Education have launched a national Artificial Intelligence Competency Framework for Teachers, marking a major step in integrating AI into teacher training and education reform.

Based on UNESCO’s global framework and adapted to Egypt’s national priorities, the initiative makes Egypt one of the first countries to introduce a nationally tailored AI competency framework for teachers.

Developed through collaboration between the Ministry of Education and Technical Education, the Ministry of Communications and Information Technology and UNESCO, the framework aims to equip teachers with the knowledge, practical skills and ethical understanding needed to integrate AI into teaching and learning.

Its development was informed by consultations involving government institutions, universities, teacher training organisations, civil society, development partners and the private sector to ensure it reflects Egypt’s educational priorities and supports the Sustainable Development Goals.

The framework promotes a human-centred approach to AI, emphasising ethics, inclusion, critical thinking and human agency. UNESCO stresses that AI should enhance rather than replace teachers, helping to personalise learning, improve classroom experiences and increase efficiency while supporting responsible use.

The initiative aligns with UNESCO’s broader guidance, including the Beijing Consensus on Artificial Intelligence and Education, the Recommendation on the Ethics of Artificial Intelligence and the Santiago Consensus on Teachers.

During the implementation phase, UNESCO and the Egyptian government will introduce capacity-building programmes, develop Arabic-language AI learning resources, train AI master trainers and establish teacher training hubs.

The framework is also intended to serve as a national policy reference for integrating AI into teacher education, professional development and wider education reform.

Why does it matter?

The initiative illustrates how AI governance is increasingly moving from high-level principles to practical implementation in national education systems. Rather than focusing solely on AI technologies, the framework emphasises preparing teachers to use AI responsibly, ethically and effectively in the classroom.

It also demonstrates how international AI governance frameworks can be adapted to national contexts. By combining teacher training, policy development and locally relevant learning resources, Egypt is creating institutional capacity to support the long-term integration of AI into education while maintaining a human-centred approach.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UN Global Mechanism on ICT security begins translating cyber norms into practice

The UN’s permanent cyber mechanism has begun shifting from identifying cyber threats towards implementing the international commitments already agreed by member states, with delegations broadly calling for practical action under the existing UN framework for responsible state behaviour in cyberspace.

During the fourth meeting of the first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, member states concluded discussions on the evolving cyber threat landscape before turning their attention to the implementation of the 11 voluntary and non-binding norms first agreed by the UN Group of Governmental Experts in 2015.

While views differed on whether additional norms may eventually be required, a broad range of delegations agreed that the immediate priority should be helping countries apply the existing framework through practical cooperation, capacity development, and exchanges of national experience.

From agreement to implementation

The discussion reflected a broader evolution in international cyber diplomacy.

Rather than negotiating new principles, many delegations argued that the Global Mechanism should now concentrate on translating existing commitments into national legislation, operational practices, and international cooperation.

The Pacific Islands Forum, speaking through Tonga, noted that many countries, particularly small island developing states, are still developing the institutional and technical capacity needed to implement the agreed norms. It called for the mechanism to support this work through practical guidance, peer learning, and contributions from technical experts, regional organisations, academia, civil society, and the private sector.

The European Union similarly presented an overview of how its member states are implementing the norms through legislation, institutional arrangements, and operational cooperation, encouraging other countries to share their own experiences. The EU also described the Dedicated Thematic Groups (DTGs) as the appropriate forum for developing practical approaches linked to specific cybersecurity challenges.

Existing norms remain the foundation

Many delegations stressed that the 11 voluntary norms continue to provide a sufficient framework for responsible state behaviour.

Countries, including the Republic of Korea, Vanuatu, Portugal, Botswana, Nigeria, Ireland, New Zealand, and Costa Rica, argued that implementation should take precedence over negotiating additional commitments.

Several delegations highlighted the voluntary implementation checklist developed through previous UN processes as a practical tool for helping governments assess progress and exchange good practices. Others suggested that publishing national implementation experiences could improve transparency and strengthen mutual confidence.

Capacity development emerged as a recurring theme throughout the discussion, with many speakers emphasising that successful implementation depends on strengthening national institutions, technical expertise, incident response capabilities, and regional cooperation.

Some states support further normative development

Although implementation attracted broad support, several delegations argued that the framework should continue evolving alongside technological change.

China, Morocco, Armenia, Thailand, Brazil, Iran, and Cuba suggested that emerging issues, including AI, data security, supply chain resilience, and new forms of cyber activity, may eventually require additional voluntary norms or, in some cases, legally binding international instruments.

Rather than presenting these approaches as mutually exclusive, several countries argued that implementation and discussions on possible future norms could proceed in parallel, provided decisions continue to be reached through consensus.

Threat discussions reinforce implementation priorities

Before moving to the norms agenda, delegations completed their discussion on the evolving cyber threat landscape.

Countries highlighted ransomware, attacks on critical infrastructure, AI, disinformation, supply chain vulnerabilities, and cybercrime as continuing challenges requiring closer international cooperation.

Ghana described efforts to strengthen the protection of critical information infrastructure following the disruption caused by damage to a submarine cable, while Pakistan warned that cyber threats are increasingly intertwined with geopolitical competition and emerging technologies. Institutional participants, including the International Committee of the Red Cross, Interpol, and the African Union, contributed perspectives on cyber operations during armed conflict, organised cybercrime, and the importance of strengthening cyber resilience across developing countries.

Summarising the discussion, the Chair highlighted recurring calls for greater information sharing, cooperation, capacity development, incident response, and resilience, noting that these priorities would help shape the future work of the mechanism.

Dedicated Thematic Groups move to the centre of the process

Throughout the session, delegations repeatedly pointed to the Dedicated Thematic Groups as the mechanism’s primary vehicle for turning broad political agreement into practical cooperation.

States proposed using the groups to exchange implementation experiences, discuss specific cyber challenges, develop scenario-based exercises, refine the voluntary implementation checklist, and strengthen cooperation across the five pillars of the UN cyber framework.

Alongside these substantive discussions, several rights of reply reflected wider geopolitical tensions among some member states. However, the majority of interventions remained focused on practical implementation and strengthening the shared framework for responsible state behaviour in cyberspace.

The session, therefore, marked an important transition for the Global Mechanism. Having identified many of the principal cyber threats facing states, delegations increasingly turned their attention to the practical question of how existing international commitments can be translated into national action and international cooperation.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UN Global Mechanism on ICT security shifts towards practical cybersecurity cooperation

The UN’s permanent cyber mechanism continued its substantive discussions by identifying shared priorities for international cooperation, with member states highlighting ransomware, AI, critical infrastructure protection, and capacity development as areas requiring practical action.

During the third plenary of the first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, delegations repeatedly stressed that discussions should move beyond mere description of cyber threats to developing practical tools to help states prevent, detect, and respond to them.

The discussion reinforced a trend already visible during earlier meetings, that despite differing national perspectives on specific cyber incidents, broad agreement is emerging on the issues likely to shape the mechanism’s future work.

From identifying threats to supporting implementation

Several delegations argued that the mechanism’s success should be measured by its ability to translate years of international negotiations into practical cooperation.

Kiribati captured this approach by observing that discussions on cyber threats should not end with mere descriptions but lead to concrete measures that enable countries of all sizes to strengthen their cyber resilience. Cameroon and Morocco similarly encouraged the mechanism to prioritise practical implementation through the Dedicated Thematic Groups (DTGs), which are expected to become the forum’s primary venue for detailed technical cooperation.

The emphasis on implementation reflected a broader shift from developing international norms towards helping governments apply them in practice through information sharing, capacity development, and operational cooperation.

Critical infrastructure protection gains momentum

Protection of critical infrastructure emerged as one of the strongest areas of convergence during the session.

Small island developing states offered particularly compelling examples of how digital infrastructure has become essential for national resilience. Kiribati described how its first submarine cable has transformed public services while simultaneously increasing its exposure to cyber risks. Tonga recalled the 2022 volcanic eruption that severed its only submarine cable, leaving the country isolated during a national emergency, and warned that a malicious cyber operation could deliberately produce similar consequences.

Delegations from Australia, Tuvalu, Chile, Ghana, Zimbabwe, and other countries similarly highlighted the growing importance of protecting undersea cables, telecommunications infrastructure, government networks, and other critical systems that underpin economic activity and essential public services.

Rather than treating these as purely national concerns, speakers increasingly framed critical infrastructure resilience as a shared international challenge requiring cooperation across borders.

Ransomware remains a global priority

Ransomware was once again identified as one of the most significant cyber threats facing governments and critical services worldwide.

Delegations described attacks affecting healthcare systems, humanitarian organisations, government institutions, municipalities, telecommunications providers, and energy infrastructure.

National experiences illustrated the scale of the challenge. Tonga described how a ransomware attack encrypted its national health information system, forcing hospitals to return temporarily to paper records. Germany cited estimates placing annual cyber-related economic damage at approximately US$230 billion, while several countries highlighted the growing sophistication and transnational nature of ransomware operations.

Many speakers emphasised that responding effectively will require stronger international information sharing, coordinated incident response, public-private cooperation, and support for countries with more limited cybersecurity capacities.

AI increasingly shapes cybersecurity discussions

AI continued to feature prominently throughout the session as delegations examined its growing influence on the cyber threat landscape.

Countries from different regions observed that AI is lowering barriers to entry for malicious actors while increasing the speed and sophistication of cyber operations. Among the risks identified were AI-generated phishing campaigns, automated vulnerability discovery, deepfakes, large-scale disinformation, and attacks targeting AI systems themselves.

Several delegations also pointed to emerging challenges related to frontier AI models, quantum computing, commercial cyber intrusion capabilities, and digital supply chain security, suggesting these issues should continue to receive attention within the Global Mechanism.

While views differed on how these developments should be governed internationally, there was broad agreement that the mechanism provides an important forum for exchanging experience and improving collective understanding of rapidly evolving technologies.

Capacity development remains central to cyber resilience

Developing countries consistently stressed that discussions on cyber threats should be matched by practical support.

Delegations highlighted the importance of strengthening national institutions, expanding technical expertise, improving incident response capabilities, and ensuring that developing countries can participate fully in the mechanism’s work.

Small island developing states noted that limited resources often magnify the consequences of cyber incidents, while African, Asian, Caribbean, and Pacific countries called for sustainable, demand-driven capacity-building programmes tailored to national priorities. Several speakers also encouraged greater regional cooperation and more structured exchanges of operational experience.

These interventions reinforced the view that improving global cybersecurity depends not only on reducing threats but also on ensuring that all countries have the capabilities needed to address them.

Dedicated Thematic Groups move into focus

Attention also turned to the role of the Dedicated Thematic Groups as the mechanism’s principal vehicle for translating discussions into practical outcomes.

Delegations proposed using the groups for scenario-based discussions, expert briefings, exchanges of operational experience, and the development of practical recommendations on issues such as critical infrastructure protection, supply chain security, ransomware, and implementation of agreed voluntary norms. Several countries argued that the groups should focus on a limited number of concrete priorities that could produce measurable results.

Alongside these substantive discussions, some delegations continued to express differing views regarding state attribution of cyber incidents and recent geopolitical developments. While these exchanges reflected broader international tensions, the majority of interventions remained focused on strengthening cooperation within the Global Mechanism and identifying practical areas where progress can be achieved.

As the session concluded, the Chair confirmed that discussions would continue with the remaining speakers before the mechanism moved to its next agenda item on voluntary norms for responsible state behaviour in cyberspace.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!