background image blur
background image
  • Blog
    >
  • News
    >
  • The Bodies Quietly Shaping the Future Internet

The Bodies Quietly Shaping the Future Internet

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 24 August, 2026
A woman using a messaging app in her dimly-lit bedroom

Key Takeaways

  • The organizations that most directly shape what the internet can and can't do are not elected bodies — they're standards groups, intergovernmental organizations, and technical committees that operate largely outside public view.
  • Decisions made by bodies like ICANN, the IETF, and the Council of Europe determine what's technically and legally possible years before any national parliament votes on it.
  • When standards processes are captured by commercial or government interests, the consequences get baked into internet infrastructure that's difficult to change later.
  • Participating in public comment periods, consultations, and policy development processes is one of the few ways civil society can shape internet policy before it's finalized.

Most of the internet governance conversation focuses on the visible end of the pipeline: a parliament passes a law, a regulator writes rules, platforms comply or push back. That framing isn't wrong, but it misses most of what's actually happening. 

The internet's real rules, the ones that determine what's technically possible, what's findable, and who gets to participate, are written further upstream, by bodies most people have never heard of, in processes that rarely make the news.

The Layer of Governance Below the Headlines

ICANN — the Internet Corporation for Assigned Names and Numbers — controls domain names and IP address allocation globally. It decides what top-level domains exist, sets policy for how domain ownership records are handled, and negotiates the rules under which registrars operate.

The Governmental Advisory Committee within ICANN allows governments to provide advice, but the system is designed as a multistakeholder model where civil society, business, and the technical community participate alongside governments — not beneath them. That model is under sustained pressure from governments that prefer an intergovernmental arrangement where states have more direct control.

The Internet Engineering Task Force, which operates under the umbrella of the Internet Society, writes the technical protocols that define how data moves across the internet. 

When the IETF standardized Encrypted Client Hello — a protocol that prevents ISPs from seeing which specific site you're connecting to during the initial TLS handshake — it made mass surveillance of web traffic harder without passing a single privacy law.

Russia's response was to block ECH outright. In November 2024, Roskomnadzor (the Russian federal executive agency responsible for monitoring, controlling, and censoring Russian mass media) declared Cloudflare's ECH implementation a violation of Russian law, severing access from Russia to hundreds of thousands of websites in the process. A technical standard, written by a standards body, had geopolitical consequences.

Where Standards Become Policy

The Council of Europe's freedom of expression and internet governance framework operates through binding conventions and non-binding recommendations across 46 member states. In September 2024, the Council of Europe opened its Framework Convention on Artificial Intelligence for signatures — the first binding international treaty on AI. 

It applies to both public authorities and private actors in signatory countries, covers AI systems' effects on human rights, and was open to non-member states including the United States, Canada, and Japan.

UNESCO's role is softer but still significant. Its Recommendation on the Ethics of AI, adopted in November 2021, was the first global normative framework on AI and has since been used by dozens of countries as a reference for national AI policy. Its Internet Universality framework — built around indicators covering rights, openness, accessibility, and multistakeholder participation — has been used in over 60 countries as a self-assessment tool for whether a national internet meets international standards.

Neither instrument has the force of a national law. Both shape what national laws say, what arguments are available to civil society when challenging governments, and what international norms look like before a bill is ever drafted.

What Happens When These Rooms Get It Wrong

The multistakeholder model has genuine strengths. It allows civil society and technical experts to participate in decisions that would otherwise be made entirely by governments or corporations. The IETF's openness — its documents are public, its mailing lists are archived, participation is theoretically available to anyone — has produced privacy-protecting standards precisely because privacy advocates were at the table.

But the model has vulnerabilities too. Commercial interests that depend on data collection have repeatedly shaped technical standards in ways that make privacy harder to achieve by default. ICANN's accountability mechanisms have been tested and found wanting when powerful registrars pushed back against public interest policies.

The Council of Europe AI Convention was criticized by civil society organizations for providing too much flexibility for governments to carve out national security exceptions. The pattern of regulatory frameworks that begin with principled language and end with enforcement gaps is visible in standards processes as well as in legislation — often more so, because the policy processes are harder to track.

These aren't arguments against these bodies. They're arguments for why they need more public attention and more civil society participation than they currently receive.

Why This Belongs in the Public Conversation

I think the gap between how much public attention these governance processes get and how much influence they have is one of the more significant blind spots in the internet freedom conversation.

Most people engaging with questions about internet freedom are reacting to laws that have already passed. By the time a content moderation requirement, an age verification mandate, or an AI governance rule reaches a national parliament, the technical infrastructure it requires has often already been defined somewhere else — in a standards document, a Council of Europe recommendation, or an ICANN policy development process that concluded years earlier.

Online freedom and privacy aren’t policy preferences to be negotiated away in committee rooms without public scrutiny. They're fundamental rights that require defending before the architecture is set, not after.

That defense requires showing up earlier in the process: in the public comment periods of standards bodies, in the consultations of intergovernmental organizations, in the policy development processes of bodies like ICANN. The conversation about what the internet can and can't do doesn't only happen in parliaments. It happens in rooms that are often technically open and practically inaccessible, where drafts that eventually become law are still being written.

Knowing who’s in those rooms, and what they're deciding, isn’t a specialist's concern. It's basic democratic hygiene for anyone who cares about what the internet is allowed to be.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"