Markdown Version

Session Date/Time: 20 Jul 2026 09:30

[00:00:05] Mallory Knodel: What happened?

[00:00:12] Tara Tarakiyee: Okay.

[00:00:13] Tim Engelhardt: Is that me doing this? Mhmm.

[00:00:15] Mallory Knodel: That's you doing that.

[00:00:16] Corinne Cath: Yep. It's not me. I'm not I'm not touching anything.

[00:00:18] Tim Engelhardt: Yeah. No. No. Just okay. Thanks.

[00:00:23] Mallory Knodel: Right on. Okay. Great. Can you pass it back to me? I think I can I can take back control from you, actually? Okay. I've done that. Okay. Great. So since it's it's half past, I'll go ahead and start introducing welcome everyone, and then it you'll be up next. So you feel free to go off video if you want, and we'll be here.

[00:00:48] Corinne Cath: Well, unless we go off mic, but happy to stay on video and just wave at people.

[00:00:52] Mallory Knodel: Okay. Great. Thank you. So let me see. I'm welcoming everyone who is in the room. Thanks for bearing with us while we who are participating remotely. Just organized everything. Really grateful for those who've shown up. Trying to see the room. It looks like, yeah, a handful of people trickling in after the coffee break. We have a short session this time, just an hour long, and, we have just a couple of presentations today. We'll have a talk from Corinne and a talk from Tim who are both, here on the screen with me. Let's see. Mick Mikhail, I'm not sure. You're on you have your audio on. I'm not sure if you've come on to speak, but you're not on our agenda. So I'm going to go ahead and close your audio for you. But get in the queue if you do have a comment, please. And that actually goes for everyone. You know, we do hope we have some robust discussion today. So make sure you've signed in to the blue sheets. This is the next slide, actually. Make sure you've signed in to this meeting. That will allow you to get into the queue for discussion. Another reminder is that all of these all of the IETF sessions are recorded. They're going to be posted to YouTube. I would really love it if we could have a notetaker for the portion of the discussion after the talks. So if there's somebody who could take notes Laura, are you volunteering to take notes? I think you are. Yeah. Okay. Thank you again, Laura. I think Laura took notes for us last session, which is awesome. So, yeah, only for the portion of the q and a. Don't worry about taking notes on the presentation. And, yeah, well, the slides are available online for that. I've already talked about the Meetecho queue, so we can move to the next piece, which is the note well. It's very important, if this is your first time in an IETF, if this is maybe the first day. It's the first day of the week of the IETF, so you might need to refresh your memory on this. But the IRTF also follows the IETF's intellectual property rights disclosure rules, so please know when to disclose and ask if you don't. We've already talked about the audio and video recordings, so please note that well. And we do the IETF IRTF has a privacy and code of conduct. Everyone, both online and in person, needs to abide by those rules. There's an team that you should know about if it if it comes to that. But, yes, please go ahead and look up more information if you need it. So the human rights protocol considerations research group is where you are now. If that's where you've meant to be, you're in the right place. It is a research group of the Internet Research Task Force. We are interested in long term research issues. We're a parallel organization to the IETF. We are not developing standards. We are conducting research. We do, from time to time, publish documents, and you can learn about the IRTF and all of the other really awesome research groups that are meeting this week, by going to irtf.org. So, we were chartered now over ten years ago, to research how protocols either strengthen or threaten, maybe just generally impact human rights. And, we've, set out some objectives that are in our charter. You can go ahead and, peruse those, through the data tracker if you'd like, But, really, we're just trying to draw connections. We have a specific focus on two of the, major human rights or,

[00:05:01] Corinne Cath: I guess

[00:05:02] Mallory Knodel: do we call them primary human rights anymore? I don't know. Freedom of expression and freedom of assembly. But we've or freedom of association, I guess, is what we should call it because we have a draft on that, where we use the term association. We've also managed to produce in the past guidance, specifically on this in the protocol development process. And, really, a lot of the talks we do every single IETF session are really about raising awareness in both, and it sort of goes both ways. We bring in folks from the human rights community or that know a bit about human rights into into the standards bodies. And then often, we go the other direction where it's helpful, I think, for folks who work in human rights to get a sense of what standardization looks like and what, technical constraints, this community, the IETF and IRTF community are dealing with. So we've just found over the years that having these talks, thank you both Corinne and Tim today for doing them, can just really help, I think, bring some tangible conversations about these issues. So we've had a couple of RFCs. There's there's a film that came out actually more than ten years ago. We I haven't updated this data because it's from the last session in in March, but we've had a lot of meetings. And if every meeting we have two, three, or four speakers, we've just had a ton of experts in human rights folks come come through. So just in aggregate, if you go to YouTube, we have a playlist of all the HRPC sessions. You can see some really awesome talks and just how many there are, which is cool. Right. I like this photo. Corinne, are you in this photo? No. Anyway, from the, UVA folks. We just to update you on, like, where we're at with certain things, we do have existing drafts. I think that maybe they're expired in the system, but I consider them active. I think there are still really interesting lines of inquiry. One is on freedom of association, and the other is on intimate partner violence considerations. Both of these drafts, I think I've shared with Dirk recently. We can maybe talk about them at the end if there's time, if people are interested in the status of those. But we wanna thank all the people who've come through to lead this group. So we have DKG and Melinda Shore who are technical advisers to this group. Nick Doty has been a document shepherd for us, and past chairs are Sofia Celi, Avri Doria, Niels ten Oever. Okay. Let's get into the I think this is the end of my slide. So I'm going to go back to the agenda slide. I'm letting everybody in the research group know that, unfortunately, wasn't able to make it. She had some flight issues. So she's currently, I think, in the air, or she'd be joining us also remotely. She'll be around this week. So if you wanna talk to her about her work on measurement, please do that. I think she will, though, commit to coming or presenting remotely at the next IETF, so in in November in San Francisco. So with that, we're going to start with with Corinne. So, Corinne, we're happy to have you. I'm going to stop sharing these slides, share yours, and then I'll pass them to you.

[00:08:25] Corinne Cath: Perfect. Thank you so much. Good good morning, everyone who is in the room. I'm so sorry I couldn't be there. I really wanted to join in person, but alas. These slides look like they're a little wonky. Could that be, Mallory?

[00:08:45] Mallory Knodel: I can I'm not sure what they're supposed to look like, but I'm sorry about that. You sent me a PowerPoint, and then I uploaded

[00:08:54] Corinne Cath: Oh, lord.

[00:08:55] Mallory Knodel: So I think there was an automatic conversion that happened because they weren't Sorry about that.

[00:08:59] Corinne Cath: That's totally fine. You This is

[00:09:01] Mallory Knodel: You could also share your screen if you were

[00:09:03] Corinne Cath: Let me let me do that because I I think that's gonna be a little cleaner. How do I do request screen share? Alright. Does this work? Can you see my screen now? Mallory, you're muted.

[00:09:48] Mallory Knodel: Sorry. I'm just trying to click the button, and it's not clicking.

[00:09:53] Corinne Cath: So Here

[00:09:54] Carolina Caeiro: tried to

[00:09:55] Mallory Knodel: grant you the screen, but it's working.

[00:09:56] Corinne Cath: That's fine. Here's what we're gonna do. We're just gonna go ahead with very messy slides and make the best of it. And then I can just share the share the original slides with with the list for people

[00:10:10] Mallory Knodel: who You know what I was doing? Let me try one more time. Sorry, Corinne. I will take

[00:10:14] Corinne Cath: That's fine.

[00:10:15] Mallory Knodel: The slides. I will stop the slides, and now I will see if I can grant you screen. There you are. Is that working for you now?

[00:10:21] Corinne Cath: Yeah. It is.

[00:10:23] Mallory Knodel: Thanks for everybody's patience.

[00:10:24] Corinne Cath: Thank you indeed. Entire screen. Just need to quickly change my settings in Brave. Later. Oh, it should work. Come on. Oh, I need to restart. Give me two seconds. Yes. But if I restart now, I drop off the call. So I don't think that's smart. So, Malorie, we're just gonna go with the wonky slides. Got it. But thanks that. No worries. For sure.

[00:11:21] Mallory Knodel: I'm past the

[00:11:22] Corinne Cath: control. Perfect. This is all par for the course. Alright. Good morning, everyone. Good afternoon, wherever you are this afternoon. Thanks so much for bearing with us. So what I wanna do today is talk about some of the research that I've been doing in my capacity as a postdoctoral researcher at the University of Delft and in my current new role, specifically looking at what is happening now that the hyperscaler cloud is becoming more and more important. Let me see if I can control the slides. And just for a bit of background, my name is Corinne Cath. I'm somewhere between academic practitioner, a recovering academic, someone who likes to really work at the bridge between think tanks, civil society, and academia. Some of you might have come across my work before because I wrote my PhD on the Internet engineering task force. So really excited to to be here today to talk to you about my new work. So what I wanna do today is talk a little bit about a concept that I've called CloudRift, which is also incidentally the the title of the paper that I'm presenting on. And the idea behind CloudRift is that one of the things that, a number of academics are seeing in the field, including myself, is that Internet governance organizations are struggling to fulfill their public interest missions once they move some of their core functions to for profit driven hyperscaler, companies that have, a real possibility of leading to institutional changes within, within Internet governance organizations that can erode technical resilience and also increase institutional dependence on big hyperscalers. And I'm gonna talk through what that might look like. Normally, when I would give this talk, I would also explain a little bit about what the Internet is and and how it works for obvious reasons. I will skip that for this community because I will probably get a lesson in return. So there are a couple of things that I think I wanna put front and center in terms of basics or principles that are very familiar to this community around, like, what makes the Internet the Internet, packet switching, protocols layered architecture, and distributed design. But increasingly, we're also seeing that the that hyperscaler clouds are really important in what makes the Internet the Internet. And as this community also knows is that some of these basics or some of these principles are more alive on paper than in practice. So we're seeing quite a bit of centralization, consolidation, and I know that these are really active discussions in the IETF community. And there are two broad dynamics here that are really interesting for questions of consolidation, but also for questions of privacy, and by extension, also for the resilience of the Internet. One, I know is incredibly familiar in this community is this question of the how cloud computing is changing the Internet's topology, its physical and its logical structure, its business working, etcetera. And the other one, which is one that I wanna focus on a little bit more today because I feel it's less chartered territory, is the question of what happens to infinite governance organizations, especially those with very clear public interest mandates when they become much more dependent on hyperscaler cloud computing for their key operations. Sorry. The click through is not as smooth as I would like it to be. So the first dynamic in terms of, like, what the Internet is doing, what the cloud is doing to the Internet's topology, this is all very familiar work, I'm sure, to everyone in the room. This is also a point that that Jeff Houston has made much more eloquently than I ever could, but it is actually this question of the Internet no longer following the traditional hierarchical topology and and the extent to which we're seeing tier three and tier two deep hearing from their upstream providers and instead connecting directly through big cloud computing networks, which obviously has a number of of implications. But the second one that I really wanna focus on is this question of Internet governance. So what we are seeing or at least what I think I am seeing is that various critical Internet governance organizations are increasingly reliant on large hyperscale cloud computing, providers for their functioning. And at least in where I live in Northern Europe, we're seeing this, dynamic happening from everything to, government, health care, education, media, the gamut. And one of the questions that I had as an anthropologist of Internet governance is what kind of an impact does that have? How should we understand the the changes that this increasing reliance has, especially for resilience and access to information. Or in other words, the the question that I pose both as an academic, but also as a practitioner working for think and do tank article 19 is this question of how is cloud computing transforming Internet governance organizations as well as the industry behind it, and what happens specifically when the cloud captures your operations. And here, also wanna give a shout out to the, programmable infrastructures project at the Technical University of Delft, where I had the great pleasure of working with professor Seida Gerses, who is really, you know, pushing, the debate in terms of trying to understand what cloud computing is doing when it is allowed to essentially become the factory for how a a number of industries are able to produce digital services. So I highly recommend her her work and and checking out the project. So this is the paper. It came out in May of this year. It is all open access as all good research should be. So feel free to to have a look at it. But to spare you all a lot of time and a number of and a lot of words, I'm gonna go through the case study that the research talks about. So, essentially, as we'd already mentioned, numerous Internet governance organizations are increasingly reliant on cloud computing for their functioning. And one such organization is the Dutch Internet infrastructure provider, Stiftung Internet Domain Registratie or SIDN that maintains the .nl domain name, so the country code top level domain. And they made an announcement in 2024 that they were moving part of their operations to Amazon Web Services. And this, for many in the field, myself included, I'm based out of Amsterdam, was quite a surprise. Because for many of us, it felt like that this particular move might transform the nature of their stewardship of the .nl country code top level domain from, you know, locally managed and a public resource with government oversight to a much more black box service partially run on a global corporate cloud computing behemoth. And when this announcement was made, I saw something that I think in the fifteen years that I've been in the field now, which arguably for an IETF trajectory is maybe not that long. But for me, it it is it feels long. I saw something that I've never seen before, which is infrastructure like cloud computing becoming a topic of national debate. So this particular choice by SIDN made the headlines of newspapers, and it also was featured on our equivalent of The Daily Show, which you see here. And this is part because a number of tech critics amongst whom Bert Hubert, who I'm sure some of you might know as he has attended the IETF previously in his capacity as one of the founders of PowerDNS, were quite vocal about how this was perhaps not the best move forward and certainly not the only move forward for SIDN. And I had seen another thing that I've never seen before, which is in the process of this particular debate, there was a vote in our parliament where, all of the the the parliamentarians unanimously voted to temporarily halt the move from SDN to AWS. So this really, really played up in the in the public imagination, and it was really, interesting to finally see these questions of infrastructure get the kind of, attention that I think it warrants, but it was also really worrying to see the tone of the debate and where that took us. So a bit of a an overview of what we saw. So in January 2024, we saw the initial announcement by SIDN. In February 2024. We saw a lot of, concerns raised. And then there was almost a year of of public debate before the intervention to temporarily halt the mark migration. And what we are seeing now is that the end result is that, SIDN has been allowed to move some of their, operations to AWS, but they are mandated to keep, other parts of it considered to be critical, with local providers. But what was also very key in this debate is that there were a number of concerns that I think are top of mind for myself and and for the Programmable Infrastructures Group and others who really care about this question of of having an open Internet and and free access to information that were missing from the debate. So it focused very much on surveillance and digital sovereignty, although it wasn't entirely clear what that means. But what we didn't discuss sufficiently in-depth is what happens to the mission of an organization, especially a public institution when they move to a more profit driven cloud computing company? And this is the question that I focused on for my research. It was really to try and figure out when you migrate from, you know, a local provider that is trusted, that you know well, where you have quite a bit of control to a more distant cloud computing provider, what happens? How does it change your internal operations? And what I saw, at least in this particular case study, is that even when you're just preparing for a migration like this because in the end, SIDN is not not it's not they were never going to full on fulfill, take everything to the cloud. They were always going to take only a part of it. But even in their preparation for that, we saw a restructuring within the within the organization, and this is what I refer to as CloudDrift. So we saw expertise shift from really full stack technical knowledge to more focused on vendor management. So at CDN, you know, full stack nerds being replaced with people who had AWS specific knowledge, but maybe not the the full stack expertise. We saw some of the decision making priorities internally align with the commercial provider's business model, I e, what do we move from what do SIDN's client need to what does AWS need. And one, really poignant example of that is that SIDN has always been a very, vocal defender of a decentralized Internet, and that is something that came up in their annual report. It's something that they're very, known for also, and that is a much harder position to take now that they are, reliant on one of these, central providers. And one of the other things that I saw the the start of is that the organizational culture within, absorbs commercial values over public interest mandates. So you shift from being focused on trying to make, you know, make the Internet work better to maybe making, money or increasing your revenue streams, which, again, was never the intended mandate of this organization. And what I found really interesting to see is that these changes occur regardless of data center location or applicable jurisdiction. So the question that that raises for me, does this mean that we're slowly turning the Internet into someone else's cloud, to put a familiar phrase upside down? You might be wondering right now, like, why why should I care? What what how does this matter for, for the industry at large? What we are seeing or what, I think we are seeing is that, there are some bigger questions for the incident's foundational principles. Principles. Right? If you operate from the notion that there should be no single point of control, well, there's a change in that. If you are operating through a we need resilience through redundancies, this potentially changes that. Right? And we've seen that through the various cascading effects of outages in even, like, a single cloud region of a single cloud provider. It raises questions for autonomous administration, you know, who manages your own infrastructure, who has control over that. And it also matters for bottom up governance because there obviously is no no no ITF for for cloud computing or for bringing that together. Oops. Went too fast. And so why does this matter for the IETF, for IRTF, for HRPC in particular? I mean, in here, I've just, grabbed the one of the quotes from the mission of the ITF, but I could have also focused on IRTF or HRPC, because it comes down to the same thing. Like, we we care about a certain number of things, decentralized control, end user empowerment, sharing resources, etcetera, because that is how the ITF believes the best Internet is possible. But the question is, like, is it is it possible to maintain those values whilst we all collectively become more reliant on these cloud computing providers? Can you have an open Internet when you see the replacement of diverse locally managed systems with standardized hyperscaler solutions? Can you have a decentralized Internet when Internet governance organizations become much more beholden to cloud providers' business priorities? Priorities? Can you have fairness when as as clients of the cloud, you become just another customer in a vast commercial commercial ecosystem? And these are all questions to to be answered. And, also, each one of these should be taken within their in their proper context, but I'm really putting this out there as as questions that we should all be raising. And this also brings me to the wider implications for future research, and I'm hoping that some of that can be taken up by the Internet Research Task Force and the excellent researchers that this community attracts. What is very clear is that this transformation is not unique to SIDN. Not long after this debate, numerous academics at multiple Dutch universities wrote, an open letter to halt the cloud migration to Microsoft that was happening, saying, we're really worried about how it transforms universities from being a source of technical innovation and knowledge distribution to just being a consumer of services. And this is another thing that people are worried about losing. Similarly, as I'd already mentioned, we see Internet governance organizations as well as broader institutions, hospitals, media outlets, government agencies all face the same risk that their core missions become secondary to the requirements, the business models, and the priorities of their cloud providers, which brings me to two sets of conclusions, which I will share also on the list. But, we need to keep in mind that, it is really hard for internal governance organizations to maintain their core function and services and mandate when they move to hyperscaler clouds. And on that note, thank you very much for allowing me to to speak to you today. On the final slide, I have a picture of my baby, and there is a good cloud related story to that. So feel free to ask me about that or anything else that is top of mind for you in the question and answering. Thank you so much.

[00:29:36] Mallory Knodel: Yeah. Thank you, Corinne. Yes. Appreciate the presentation. Lars, you're up first in the queue.

[00:29:43] Lars Eggert: Yeah. Hi, Lars. Corinne. That was a very cute baby on the screen.

[00:29:48] Corinne Cath: Thank you.

[00:29:51] Lars Eggert: So so this isn't really my area, and and and I'm trying to sort of absorb what you what you presented. And and I think there's sort of two buckets of problems if I wanna, like, oversimplify this to to to death. Right? So so one problem I think you you called out is that infrastructure that previously was maintained and and run by an organization, maybe in house, is now going somewhere where it's, like, leased as a service, and that causes some issues. And and then I think you also alluded to problems from a European perspective that the the place you lease it from is is an organization outside The US because all the hyperscalers are, like, not in Europe. Right? And and they're mostly in The US. And that causes problems. And I'm I'm kinda wonder if you could give me an easy answer to what is the bigger source of problems. Is it the going from in house to somewhere in the cloud where you lease capacity, or is it the that place is run by, like, a non European entity?

[00:30:51] Corinne Cath: Hi, Lars. Thanks so much. I love it when you throw me a question that I can actually easily answer. So and this and this is contentious. But from from the perspective of the programmable infrastructures project and from my own perspective, the concern here really is that we're outsourcing, and I wouldn't even use the word outsourcing, but that the cloud is capturing operations and not necessarily that the current cloud computing companies are all American based. Although there is a whole set of debates, and I'm sure you're intimately familiar with that in in Europe of people who are focused on digital sovereignty. However, there's some of their solutions to this is, well, if we just build our own equivalent, if we build our own European hyperscalers, we solve all of the problems. And I actually think that the if you build an EU AWS, you will still have some of these concerns around the hollowing out of public interest mandates of certain organizations. So for me, the the the bigger question is what happens when you outsource? Like, what makes you you to an organization that is for profit driven and that sort of peers into you and that that asks you to standardize how you do your work based on their priorities versus on yours. Irrespective of that if that behemoth is, a European behemoth or, an American one.

[00:32:20] Lars Eggert: Okay. Thanks. That is interesting because that was actually the opposite of what you thought you were gonna say. So so I learned something. Thank you.

[00:32:31] Mallory Knodel: Thanks. Tara, you're up next.

[00:32:33] Corinne Cath: Hey, Tara.

[00:32:35] Tara Tarakiyee: Tara Sovereign Tech Agency. Thank you for this talk. Like, one thing I've been grappling with is I feel, like, the implications of hyperscalers on standards work on OpenStandard's work in the ITF are clear to me. But for me, what's unclear is, like, what are sort of, like, the levers that are available

[00:32:55] Mallory Knodel: to

[00:32:56] Tara Tarakiyee: something something like that you have to because in many ways, I feel like with OpenStats and maybe also, like, open source in general, it appears to be indefensible because all the things that could defend it are, like, by definition, not open. So Mhmm. And, like, outside of, like, things like industrial policy or anti monopoly law and all those things, I are there I guess, like, to make it to stop rambling, are there things in, like, inherent to the architecture of the Internet or how the ITERP works that could, in a way, help alleviate this, or is it just, like, not something that it can has has agency to defend itself against?

[00:33:38] Corinne Cath: So can I ask you because this is not rambling at all? But can I before I answer the question, can I ask you to say a couple of words about how you see the impact of the hyperscalers on standardization? Because I think that would also help ground my answer for people who are maybe less familiar with that.

[00:33:55] Tara Tarakiyee: Well, I think, like, with increasing, like, consolidation of, like, infrastructure, like, the I mean, you can have open standards, but you need people to participate and use those open standards. And if the only people using those standards or could or have the equipment to use those standards are big corporations, then we lose all the independent and smaller operators. And, like, not only don't they have they lose their skin in the game, they also lose their voice because they can't run those standards, like, I guess.

[00:34:26] Corinne Cath: Yep. No. I mean, so there absolutely is a role for for this community. It is David versus Goliath, and we need to be really realistic about that. I think the other thing that, I mean, most people in this room will know as will you, Tara, is that part of this is is the politics and the economics behind it. For many organizations and taking, for example, my own government, they will outwardly say, oh, we're moving, in our case, all to Microsoft because it's technically superior, blah blah blah. It is a very smart way for them to initially reduce a lot of costs. Right? And and we're operating under, you know, politics in in in which that is seen as really important. And that is a dynamic that you perhaps cannot, you know, stop by making really good open standards, but it is necessary if insufficient. And the way that the professor that I work with, talks about this is that we need to keep in mind that this is not the only future we could be building. And that if we want to show other futures, we also need to build them. Right? We need to make what she calls transition infrastructures. And I think that is exactly what, I mean, you are doing, what the sovereign tech agency are doing, what so many people in HRPC and IRTF are doing. And we just need to be very mindful of, you know, what we can and cannot achieve through that work, but it is incredibly important.

[00:36:07] Tara Tarakiyee: Thank you.

[00:36:11] Curtis Heimerl: Hi. Curtis Heimerl, University of Washington. This talk reminds me of Tim Wu's The Master Switch, which makes the case that there's sort of a cyclical nature to the centralization and decentralization of infrastructure. And I wonder how that narrative lands with you and personally. If you feel like that's kind of just you know, there's just a never ending battle, you know, and and there's you on the decentralized side, or if there's something more foundational happening in the architecture that won't be reversible.

[00:36:45] Corinne Cath: Yep. Thank you so much for the question, Kurt. Big fan of the work of of Tim Wu. So I see this as more foundational than cyclical. And the reason why, again, comes back to the work of the programmable infrastructure project who have really shown that this is a financial move as much as it is a technical move. And some of the research that they are putting out right now demonstrates that once you start to or you stop maintaining your own infrastructure and you start to, you know, use the cloud instead, it changes your budget. So it means that you reduce your capital expenditure significantly. And so for instance, if you're the government of a small country like The Netherlands, you do that, it becomes very hard to undo it because you have now written off all of this capital expenditure, right, that you had planned for every five years. And to write that back into a budget is a huge lift. And I know that there's quite a bit of, like, sort of talk about the cyclicalness of the cloud in the start up scene and that people have, like, said, oh, you know, we were on the cloud, and now we've decided to do it all ourselves. And people taking that, as scalable. And for a lot of big institutions that we are seeing turning to hyperscaler clouds, it's not. That is not a simple financial or political maneuver to make. So in that sense, I do think it is more foundational than cyclical, at least for some of the industries that I'm interested in, which is, like, mostly cloud provision of business to government and business to business when it's bigger, more ingrained institutions. I hope that answers

[00:38:41] Mallory Knodel: your wrap up with this last question really quickly

[00:38:43] Corinne Cath: Hi, Colin.

[00:38:44] Mallory Knodel: Move to the next. Go ahead, Colin.

[00:38:46] Colin Perkins: Hi. Colin Perkins, University of Glasgow. Interesting talk. I fully agree with your concerns, and I I work for an organization which is busy losing its expertise in exactly the way you're talking about. However, I would slightly wonder whether what we are seeing is the governance organization is actually starting to reflect the Internet as it is rather than the Internet we

[00:39:17] Mallory Knodel: would like to have.

[00:39:20] Corinne Cath: Mhmm.

[00:39:21] Colin Perkins: And is is this just the natural evolution of the governance to match what we have?

[00:39:28] Corinne Cath: I I love that question. I think it contains its own beautiful critique. The only thing where I would hesitate is to ever call technical development a natural evolution. Because in my limited experience with those over the last fifteen years, all technical evolutions are political. And as you just did, we should, you know, recognize and and name those for what we are so that it remains possible to build alternatives that are decentral and open and the Internet that we do truly wanna see. Thank you so much.

[00:40:08] Colin Perkins: Thank you.

[00:40:10] Mallory Knodel: Thanks, everyone. Thanks again, Corinne, for your talk. Really appreciate the conversation that's also happening in the chat and for the folks who came to the mic. And, also, I'm sure thank you to Laura who took excellent notes. So we're passing it now to Tim. Tim is going to come on and give, his talk, and we will use remaining time after this, for discussion about this, talk for any questions. So please get in the queue or, any other business. So go ahead, Tim.

[00:40:41] Tim Engelhardt: Hello. Good morning. Can you hear me?

[00:40:45] Mallory Knodel: We can hear you great. Yes.

[00:40:46] Tim Engelhardt: Okay. Great. I just got an alert that you anyway. Yeah. Good morning. Good afternoon. Great to be here. And thanks, Corinne, for for an amazing presentation. And those who haven't checked out her PhD, please do so. It was for me an important stepping stone on my journey through the standardization world. So yeah. I'm to to do sorry. So my I'm Tim Tim Engelhardt. I work at the office of the high commissioner for human rights at the United Nations on on various take issues on human rights and technology. And it's been a couple of years since I I was here at the HRPC first. I'm very glad to be back. And today, I wanted to give you a bit of an update from our perspective of what has happened in the space of standards and human rights more broadly in our own work. And the final aim from my side is to to hear from you, if not today, then at least via email, via calls, etcetera, to get feedback on some of the initiatives we are working on. As mentioned, I'm at OHCHR. It's the UN organizations within the UN Secretariat tasked with human rights work. We monitor the the the status of human rights in the world. We give advice. We call out abuses, etcetera. We are present in almost a 100 countries in the world. Work with states, accountable to states, work with many other stakeholders, civil society, technical communities, and and businesses. And over the last few years, we've got more and more involved in in in the world of tech standards and protocols simply well, for a similar reason why the HRPC exists. The decisions about, the design of of of technology shapes how people enjoy and exercise their human rights. So in 2023, we published a report to the Human Rights Council of the United Nations. That's a subsidiary body of the general assembly dealing with these questions in the in the first overview and possible solutions. Since we don't have much time, I will go to that a little later on the questions, on challenges. But would like to highlight that in the last year or two years, at least at the international global level, we've seen quite a bit of movement when it comes to the recognition of the interplay between standards and human rights. The Global Digital Compact, which is an annex to the pact for the future, directly refers to AI standards, standards development organizations, and the needs to integrate human rights, in their work. A aforementioned Human Rights Council has resolutions addressing standardization. The WSIS plus 20 outcome document refers refers to our work and the need to have Internet governments in a human rights based way. And just a few months ago, ISO, IEC, and ITU released the sole statement at the International AI AI Standard Summit, the Global AI Standard Summit, I believe, which highlighted not only the need to incorporate a sociotechnical lens into standards development, but also as a single standing principle human rights. At the global dialogue on the governance of AI that finished, not last week, the week before here Geneva. The intersection of human rights and technology was very high on on the agenda, and we saw multiple discussions, events also at at the AIR for GOOD summit that focused specifically on the standardization question. Last year in October, we published a follow-up report following up on on on the Human Rights Council report I mentioned earlier. Mallory supported us in in in amazing ways. So thank you there, Mallory. The report built on on a on a number of consultations we had in Geneva, New Delhi, London at the sidelines of of important events, the WTSA on the air for good summit, the AI standards have global summit, etcetera. And what I'm presenting now builds on these consultations and what we drew from it in in in the report. One major priority that came out was the question of inclusive and meaningful participation in standardization processes. First of all, the still prevalent problem of excluding intentionally or not rather unintentionally large parts of stakeholders from civil society, specifically in the global majority world, small, medium enterprises, still existing gender gaps, etcetera. What also can odd very clearly, it's we can't solve these problems with a one size fit all approach. It's extremely context specific. And let me use that moment to to to underscore what I'm saying here is not necessarily specific to the IETF, but speaks to a much broader picture. And in fact, many of the problems that have been addressed first or discussed in the world of the IATF. So I I wanted to to clarify that. Solutions to to to these barriers to to participation included that came out very strongly in in in our discussions, was the need to have funds, create funding mechanisms to to to to increase participation, to to for organizations to undertake deliberate, concrete, and sustained outreach efforts, to create spaces for peer learning and networking, and in addition, forums for discussing pressing topics concerning human rights and standards were recommended many, many times. Another aspect that came out very strongly are questions around the design of institutions, Structure reforms were brought up with the need for high level commitments within organizations. The creation possibly of human rights focal points that participants can consult with the integration in a systematic way of human rights and then the governing fora, etcetera. The procedural side, how is equally important Ideas that came up included the review processes to flag standards that may have salient human rights impact. Also, the need to be specific about the rights we are talking about and the considerations that triggers human rights due diligence processes. We have a huge body of work on that in the business and human rights field in particular. But we also just a few weeks ago released a new study on human rights due diligence in the technology sector with a focus on states' duties and tools for states. And the human rights due diligence question leads me directly to the question of private sector responsibilities under the guiding principles of business and human rights that were adopted by the UN a decade ago. Private sector actors have at least some of them have vast experience in carrying out human rights due diligence that can be built on, it needs to be expanded. Checklists, tools for human rights due diligence, rigor mortemanded many times. The lack of coordination, the need to increase coordination between different teams, product development, standardization, human rights was also mentioned many, many times. I see we are approaching the end of my talk. So let me speed up a little more. The need to strengthen multi stakeholder, multi stakeholder collaboration, was the third stream we identified in our consultations, finding good models to share knowledge, to coordinate, to avoid duplication of efforts in in times of very limited resources, also to identify opportunities where to to have a better impact, build network networks and research partnerships between academia, civil society, standards organizations, etcetera. And all this to underscore, should should keep in mind that human rights don't just come as a as a as a nice set of values, but come with human rights duties for for states and responsibilities, which have influenced what states can do when they delegate and designate national standardization bodies. It has a lot to say when it comes to the role of standards in regulation to identify behavioral standards and many, many other questions. Etsy recently adopted a checklist on on human rights and and and checkpoints. Also, would like to highlight the work of the Australian Human Rights Commission that works very closely with and within Standards Australia. And, finally, a few weeks ago, a number of member states of ITU-T submitted with our support a proposal to to the Rapporteur Group on working methods at ITU-T as part of a of a TSAC process for a checklist on human rights. We're very happy. I would be very happy to share more about that because we would like to get feedback from as many people as possible on these efforts, on the sort of questions of the processes, etcetera, on practical examples. Although the proposal the contribution contains practical examples and also illustrative profiles of of common personas to to demonstrate how standardization may be seen and be impact by by different types of personas, how they may be impacted, etcetera. So looking forward to hear from you, and I'm very, very grateful to have had this opportunity and wish you a very nice day. Thank you.

[00:55:50] Mallory Knodel: Thank you, Tim. Thanks very much for your presentation and for joining us. I also, like Ted, had a question about the document. I I think I've seen the document you referred to. I was under the impression because it's a working document in the ITU. It's not actually public. So is there a way that we can maybe share this with folks on the HRPC list for feedback?

[00:56:16] Tim Engelhardt: Very good question. My colleague, Michelle, is responsible for that. So I will be a bit careful to to promise too much, but we have shared it with many others in the drafting process to to get ideas, to have a clearer picture of what's possible. So I think the best way would be to reach out to me, and we we can discuss this bilaterally. And then in the meantime, we work out what's actually public and what's not public. It's an official contribution that's been made, so I don't see personally larger problems there.

[00:56:59] Mallory Knodel: Okay. And just for everyone's awareness, there's the Plenipotentiary this year of the ITU that's happening in a few months. So it's an important time to be thinking about higher ordered questions like this. So let's turn to the queue with the few minutes we have left. Lars, welcome back. You're up.

[00:57:17] Lars Eggert: Yeah. Lars, I I just wanna quickly reply on on the point whether the ITU materials are available. So the IETF and the ITU have a standing agreement to make each other materials available to all participants. We might need to clarify that iRTF participants are also IETF participants, but we can get ITU materials already.

[00:57:38] Mallory Knodel: That's awesome to know. I think that's a great use. If we can publish it on a public mailing list, might be a separate question, but nonetheless. Tara, welcome back as well.

[00:57:47] Tim Engelhardt: Thanks to you.

[00:57:49] Tara Tarakiyee: My question relates to particular like, one thing we've seen from GDC the WSIS process is that when it comes to economic culture and social rights, they often get relegated to this development lens. And when it comes to, for example, the tech issues that individual world is facing, like labor and water rights and and such, they often do not get the attention that they deserve. So do you see pathways to integrating these concerns into standards work as well?

[00:58:24] Tim Engelhardt: Should I reply immediately?

[00:58:27] Mallory Knodel: You you could do. You could try.

[00:58:30] Tim Engelhardt: Yeah. Okay. No. No. Thanks for for for bringing this up. This is, I think, a major issue to to to integrate the ESCR perspective in in these processes. It can be more complex than than maybe other questions. But I agree that limiting ESCR, so economic, social, and cultural rights, to a development angle diminishes the importance and diminishes the human rights. Yeah. The the the the impact the human rights perspective can have on on on in these processes.

[00:59:24] Mallory Knodel: I'll just plus one to talking more about economic, cultural, and social rights in this research group. We are chartered to cover that, and I found it useful to take that frame in the age verification draft I worked on. For example, it was far more persuasive to talk about economic and cultural issues than it was to talk about free expression and privacy, for example. Okay. Moving along. Andrew, quickly.

[00:59:50] Andrew Campling: Yeah. Hi, Tim. Andrew Kupling speaking. Thanks for the presentation. Just responding to your list of questions about what was working well. I think the work on Charter Online Protection in ITU-T is still early days, but that's beginning to work well. That shows signs of promise, which is quite encouraging. It's an area which is good to see being addressed because I think we struggle to deal with that type of topic here in the ITF more so, whereas the ITU seems prepared to grapple with it. But thank you for the presentation.

[01:00:25] Corinne Cath: Excellent.

[01:00:27] Tim Engelhardt: Yeah. Thank you.

[01:00:27] Simone Onofri: Simone. Okay. Thank you. So Simone from W3C. I have two two questions for team. So for first one, so thank you also for all the work. That's also the report was an inspiration for the work in W3C. And we are working on translation and integration, in particular translation, which is my also topic for my doctoral dissertation, so also from a research perspective. And so we are using as a framework the pretty much the last two pages of the study study report. And so we we can discuss also later if you like some experiments, but Michelle knows pretty well about the our experiments. And just last point was a question on the child protection because also we have a lot of discussion like the r r c nine nine nine eight, if I remember well, and that's more focusing on technical solution. But question is that in your opinion, this can be also a solution on a higher level of human rights. Like, we are probably compromising or, like, say, trading off privacy for child protection. So even if this can be valuable for a for a discussion in your opinion.

[01:01:47] Tim Engelhardt: So the the

[01:01:48] Simone Onofri: So so sorry to ask that difficult question for a few minutes.

[01:01:53] Tim Engelhardt: It it's it's a super pertinent question because from what I see, nothing has gotten more traction in the last year than child protection issues or as we would prefer to frame them as a as a rights question, the rights of the child question, which is a far less which which puts children in the centers, people with their own human rights, rather than something that needs to be protected from so so we under stress they're the agency of it. So so, yes, I I think that working on on these issues is maybe not maybe. It's it's for sure one of the most important and pressing ones for children, of course, for the effects on the broader ecosystems of of of technology for political reasons because this is where traction is. We have vast alliances, vast coalitions of states and others coming together to to to speak about these questions. So how to address now the many tensions we have there between what you already referred to, privacy, security questions, rights of the child is is is immensely complex, and we need to address this. And I'm I'm very happy to hear that you are thinking about this in your work. Right.

[01:03:49] Mallory Knodel: And good to remind everyone that this is a tension that exists outside of the, like, technical standards community that are being asked to just come up with solutions when really, like, the human rights level tensions haven't even been resolved. Sorry. We're overtime. But if folks are still in the room, I appreciate you. Carolina, thank you for coming to the queue. Go ahead.

[01:04:09] Carolina Caeiro: Hi. Thank you, Mallory, and thank you, team, for for that presentation. Team, I I think I recall your last presentation in this group, a couple of ITFs back. Someone stood out in the crowd and asked you, what is the ask of ITF as a space? I really like your presentation of the building blocks, and there were two things that really sort of resonated with me, this notion of institutional design and procedural mechanisms and understanding human rights as guiding policy. I think those are two sort of very concrete areas we could be sort of working with as a sort of ITF community. So I've been sort of thinking about, you know, what that means for us as a community, and maybe this is a question even for, you know, Mallory about what we do with this group, how this community also sort of engages outside of this group with the rest of IETF, you know, to sort of get, you know, traction on the consideration of human rights when when designing protocols. So really sort of open question, you know, what do we do as a community? How do we transcend, you know, preaching to the choir within this group as well and engaging others, in in IETF itself?

[01:05:20] Mallory Knodel: I would I would love to take that question to the list. And if you wanna work with me a bit, Carolina, to formulate it so that we can get some feedback on it and then also make sure, you know, Tim and others are are on the list. I think you are, Tim. I think that's a really good question, and I think it's a timely question for right now in this moment, both for the the research group and for, you know, where we're at politically. I'll use the word political climate because we were talking about it in the chat, now people know what I mean when I say it. With that, though, I, unfortunately, need to close this meeting. It's been really great. I just I wanna affirm that I think we're used to at least 1.5, two hour meetings for HRPC, and one hour just did not feel like enough even with only two presentations. So we missed, but we certainly, capitalized on her, her time very well. Thank you so much to Tim and Corinne who spoke today. Thank you for all of you who stayed a little longer, and we'll see you online. We'll see you on the list. Have a really good week, everyone, in Vienna. Wish wish we were all there together. Take care.

[01:06:30] Tim Engelhardt: Thank you. Bye. Bye.