Ambassador Gafoor
The fifth meeting of the sixth substantive session of the Open-Ended Working Group, established pursuant to General Assembly resolution 75/240, is now called to order. Distinguished Delegates, we’ll now continue our discussion on the topic of how international law applies, and yesterday we made a good start. Let’s continue with that. I have a list of speakers who have registered from yesterday, and those who wish to speak can still press the button to indicate your desire to speak. The first speaker will be Thailand, to be followed by Mexico. So I give the floor now to Thailand.
Thailand
Thank you, Mr. Chair. Since this is the first time my delegation takes the floor, I would like to thank you and your dedicated team for convening the sixth substantive session on the Open-Ended Working Group. Your leadership has been valuable to our discussion so far. Mr. Chair, Thailand reaffirmed its long-standing position that international law, in particular the UN Charter, is applicable in cyberspace. Thailand believes that the rule-based international order will safeguard the sovereignty and security of states, as well as human rights and fundamental freedoms. Thailand supports the ongoing work of the Open-Ended Working Group and supports the call for states to develop and publish their national views on how international law applies in cyberspace. Thailand believes that articulation of national positions and increase in international dialogue will lead to the development of better common understandings and international consensus on lawful and acceptable state behavior in the cyber domain. Discussion among states also helps reduce the risk of misunderstanding and escalation between states from various cyber activities that are increasingly occurring. With this state objective, Thailand continues to articulate its national positions on how principles of international law apply in cyberspace and wishes to share its current view as follows: On sovereignty, the principles of state sovereignty and sovereign equality of states are fundamental in international law and are applicable to cyberspace, just as they do elsewhere. Within their territories, states have jurisdiction and the exclusive right to exercise the functions of a state. A state’s jurisdiction applies to persons and objects within its territorial borders, including cyber-related activities that yield results inside the state’s territory. At the international level, states are independent and enjoy sovereign equality in relation to other states. State sovereignty also leads to other principles of international law, including the prohibition of the use of force and prohibition of intervention. States also have an obligation to respect the sovereignty of other states, and a breach of this obligation would amount to a wrongful act and would give rise to state responsibility. Thailand is of the view that a cyber operation that causes significant harmful effects within the territory of another state without that state’s consent would amount to a violation of the sovereignty of the affected state. On non-intervention, there is a rule prohibiting interventions in the domestic affairs of other states under Article 2.7 of the UN Charter and in customary international law. Any cyber-related activities which reach the level of such intervention are therefore unlawful. The purpose of this principle is to ensure that all states are free from external coercive intervention in the functioning of government, which is a matter of state sovereignty, such as freedom to choose its own political, social, economic, and cultural system. In practical terms, Thailand considers a cyber operation to manipulate the results of an election in another state to be a breach of the prohibition on intervention. However, Thailand continues to consider internationally accepted thresholds for other instances that may constitute an illegal intervention. On the use of force, the prohibition of the threat or use of force is stipulated in Article 2.4 of the UN Charter and is applicable to cyberspace. Thailand considers that malicious cyber operations attributable to a state that result in or present an imminent threat of death, physical injury, or destruction equivalent to an armed attack may constitute an armed attack, which gives rise to an inherent right to self-defense under Article 51 of the UN Charter. On due diligence, Thailand recognizes that states have an obligation to not knowingly allow their territory to be used for acts contrary to the rights of other states. Nonetheless, unique technical difficulties involved in discovering cyber activities by non-state actors, as well as differences in state cyber capability, should be taken into account when states debate the threshold required to trigger an obligation on states to act or respond, and measures that can be reasonably expected from a state from which the malicious cyber activity originates. On state responsibility, Thailand firmly believes that the law of state responsibility applies in cyberspace and that the injured state is entitled to have recourse to countermeasures which are consistent with international law. Such countermeasures cannot involve the use of force, and they must be both necessary and proportionate to the purpose of inducing the perpetuating state to comply with its obligations under international law. One of the critical issues related to state responsibility in cyberspace is attribution. While it is vital that states avoid false or unsubstantiated accusations, an objective, transparent, evidence-based attribution process requires significant technical and investigative capabilities. This can be very challenging for resource-limited states. Therefore, Thailand believes that capacity-building measures are needed in this regard. And finally, on international humanitarian law, Thailand is of the view that the IHL applies to cyber operations conducted in the context of armed conflict. Therefore, states must adhere to the international legal principles, including the principles of humanity, necessity, proportionality, and distinction. Thailand cautiously notes that infrastructure in cyberspace is often used for both military and civilian purposes. Therefore, states must give special consideration while conducting cyber operations during an armed conflict to ensure compliance with the IHL. Having articulated these points, Thailand is of the view that there remain questions as to how international law applies, as well as whether gaps in the interpretation of the law exist. Therefore, Thailand supports the proposal that states continue to engage in a focused discussion at the OEWG on this issue. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Thailand. Mexico to be followed by Finland.
Mexico
Thank you, Mr. President. The promotion of cooperation and shared responsibility in the digital sphere should consider the tools and current best practices, as well as efforts towards capacity building that have already been initiated by a number of delegations. In this context, I am pleased to inform you that Mexico, in an alliance with the Institute for Law, Innovation and Technology of the University of Temple and together with Microsoft, has organized a series of virtual workshops. These workshops brought together experts from a range of sectors to address the challenges in applying international law to cyberspace and promoting abidance by norms for peaceful and responsible conduct and to reduce the digital divide. The outcome of these workshops was the project entitled Generating Opportunities and Responsibilities for Peaceful, Secure Cyberspace that is Respectful of Rights. This effort, a collective effort, culminates in the creation of a multi-sectorial compendium bringing together all of the recommended practices and contributions of all of the relevant stakeholders in order to forge a better understanding of the application of international law to cyberspace. This compendium was presented officially in parallel to this session, and we trust that it will be of great interest to member states. In addition, last month Mexico participated in a workshop organized by UNIDIR that we heard about yesterday on international law and state behavior in the use of ICTs, challenges, and opportunities. This event stood out because of its practical focus based on case studies, bolstering open and constructive dialogue between the participants. We support the continuity of this dynamic format in our joint initiatives that seek to consolidate a shared understanding on the subject. Both events highlight the valuable contribution of interested parties whose knowledge has enriched the work of regional bodies and the United Nations. They offer a platform for sharing national experiences and also shared concerns, and also in this way feeding back into the discussions of this working group. On another matter, Mexico recognizes the importance of considering the expansion of these dialogues through complementary and informative analysis by the International Law Commission of the United Nations. To conclude, Mexico insists on the need to include specific references on the applicability of international humanitarian law and its principles in future annual progress reports. We reiterate our commitment to the detailed study of the applicability and application of international humanitarian law to cyberspace and the use of emerging technologies. And we align ourselves with the ICRC in that IHL seeks to mitigate human suffering in times of conflict. Thank you.
Ambassador Gafoor
Thank you, Mexico. Finland, to be followed by Brazil.
Finland
Mr. Chair, thank you for giving me the floor. I will speak on behalf of Denmark, Iceland, Norway, Sweden, and my own country, Finland, in our national capacities, focusing on international law. The Nordic countries fully align themselves with the EU statement already delivered by our colleague from the External Action Service. The Nordic countries welcome that a session of the Open-Ended Working Group has again been dedicated to international law, and in particular to how it applies to the use of information and communications technologies by states. Mr. Chair, let us at the outset reiterate that international law, including the UN Charter, applies in cyberspace, as affirmed by the previous Open-Ended Working Group and endorsed by the General Assembly. We welcome that the Annual Progress Report so clearly reaffirms this. The Nordic countries hold the view that the applicability of international law does not depend on the technological means employed but applies across domains. While the Nordic countries are aware that states may hold differing views on how some rules developed for the kinetic world shall be interpreted and implemented in the cyber context, we also acknowledge that many states, including the Nordics, still work on establishing their own national views on specific questions. While the existing rules and principles of international law are applicable in cyberspace, the application of certain provisions may give rise to practical problems due to specific characteristics of cyberspace. Therefore, it is necessary to continue in-depth discussions on the specific questions of the application of international law in the cyber context. Turning now to your question, Mr. Chair, first, I would like to start by addressing the question regarding convergences in states’ perspectives on how international law applies in the use of ICTs. The second annual progress report shows that states have found convergence on a number of core obligations that apply to states’ behavior in cyberspace. This includes the UN Charter-based obligations, such as the prohibition of the use of force, non-intervention, and the obligation to settle disputes peacefully. There also seems to be convergence in the perceived need to understand the consequences of breaches of these obligations. Therefore, we continue to hold the view that it would be useful to discuss the law of state responsibility, as this could help in clarifying, for instance, what options a state has to address an internationally wrongful act committed against it. We have noticed an increase in views that international humanitarian law belongs to the areas of law that this Open-Ended Working Group should discuss. Of course, cyberattacks conducted in the context of an armed conflict are subject to the same restrictions and regulations under international humanitarian law as conventional attacks, including the principles of humanity and military necessity, as well as distinction, proportionality, and precaution. However, the unique characteristics of cyberspace, such as interconnectedness and anonymity, may affect how international humanitarian law is interpreted and applied to certain cyber means and methods of warfare. We are therefore particularly pleased with the increased convergence on the need to address international humanitarian law in our work. Mr. Chair, I would now like to turn to your second question on possible unique features relating to the use of ICTs that require a distinction in terms of how international law applies as compared to other domains. The starting point of the response is the established archy of the successive GGEs and Open-Ended Working Groups that international law applies in cyberspace. However, we need to discuss and achieve common understandings on how the law applies to the shared use of the ICTs. Mr. Chair, now regarding your third question on whether there are gaps in how international law applies to the use of ICTs, and if so, what can be done to bridge those gaps. The answer is clear. Cyberspace is not an unregulated arena or a domain with legal gaps that would need to be filled. All states have agreed that international law is applicable and essential to maintain peace, security, and stability in the ICT environment. However, states are encouraged to develop national positions on the application of international law to the use of ICTs, as this will contribute to common understandings on the interpretation of the law. Mr. Chair, finally, I would like to address your fourth question on capacity building, which is essential in ensuring that all states are able to participate on equal footing in the discussions and contribute towards common understandings on how international law applies to state use of the ICTs. The Nordic countries believe that developing and publishing national positions on how international law applies in cyberspace is particularly helpful for this and should be encouraged. The second annual progress report stressed the urgent need to continue capacity-building efforts on international law. Such a need has also been indicated in the interventions of several states. With a view to cooperating and connecting demand with concrete capacity-building activities and existing initiatives, we would welcome a discussion on what areas of international law and cyber additional capacity would be most needed. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Finland. Brazil to be followed by Switzerland. Brazil, please.
Brazil
Thank you very much, Mr. Chair. International law plays a key role in maintaining peace and stability and promoting an open, secure, stable, peaceful, accessible, and interoperable ICT environment. My delegation takes this opportunity to reaffirm the understanding by the General Assembly that international law, including the United Nations Charter, international human rights law, and international humanitarian law, is fully applicable to States’ use of information and communications technologies. Nevertheless, even though existing rules of international law apply to ICTs, without the need to prove cyber-specific State practice and opinio juris, we must recognize that cyberspace’s unique characteristics have created new scenarios that existing instruments of international law were not originally designed to address. This may increase the risk of unpredictable behavior, misunderstanding, and escalation of tensions. In this context, we recognize the positive contribution that a specific, legally binding instrument should be negotiated and eventually adopted once the international debate on this issue is further developed, could bring to the security and stability of cyberspace. This requires a diverse range of voices on the subject, from a large number of States from different regions. Brazil has published its national position on the applicability of international law in cyberspace in 2021, and we welcome the ever-increasing number of national positions that have been published since then. We hope to see many more in the near future. We are aware of how challenging it has been for all States to develop their national views on this very complex issue. We commend efforts in place that seek to support States in this regard and would like to take particular note of the workshop held by UNIDIR last November, which I had the great pleasure of participating in. We especially welcomed the broad representation of experts from delegations with a diversity of views on the subject, as it is extremely important that such initiatives avoid advocating a single viewpoint, particularly when it comes to divisive issues. In this context, it is very important to point out that the mere fact that a certain State behavior has not been formally protested against cannot be interpreted as acquiescence. That is to say, silence is not necessarily legally significant and therefore does not necessarily amount to the requisite evidence of State practice and nor opinio juris to the emergence of new norms under customary international law. The goal of promoting common understandings on this issue must be a permanent one, given that as technology develops at an ever more rapid pace, States will continue to face new challenges. Given that we are navigating in uncharted waters, the question of how international law applies to cyberspace cannot be rushed, nor can any issues be considered closed at this stage. As an example, we can ask ourselves how diplomatic law can be applied in the context of cyber operations. In the position we presented to UNGA, for instance, Brazil considers an internationally wrongful act the intrusion on the cyber infrastructure of a State for the purposes of intelligence gathering. Thus, we consider the unauthorized interception of telecommunications a violation of State sovereignty, whether or not they cross the threshold of an intervention in the internal affairs of another State. In other words, the element of coercion does not need to be present for this to be an internationally wrongful act. International humanitarian law applies to situations amounting to armed conflict, independently of its classification as such by the parties. It does not matter whether the armed conflict is lawful or not, because its objective is to minimize human suffering and provide a minimum level of protection to civilians in any scenario of hostilities. Therefore, the recognition that international humanitarian law applies to cyberspace does not in any way endorse its militarization or legitimize cyber warfare, but only ensures a minimum level of protection if such a conflict arises. There are two instances where international humanitarian law would apply to cyber activities. First, if they are carried out as part of an ongoing armed conflict, contributing to conventional operations conducted by the parties. Second, if the cyber activities themselves cross the threshold of violence to be characterized as an armed conflict. Chair, Brazil remains open to further engaging with delegations on these and other issues arising from our global goal of continuously building common understandings on how international law applies in cyberspace. As suggested by several delegations on this and in other previous occasions, briefings from international legal experts, particularly from the global south, could be very useful to our work on this issue. I thank you.
Ambassador Gafoor
Thank you very much, Brazil. We’ll go to Switzerland, to be followed by Estonia. Switzerland, please.
Switzerland
Thank you, Mr. Chair. At the outset, I would like to apologize if the statement is maybe a little bit long. However, I have been informed by our legal advisor that I would be held accountable if I do not read it in its entirety, and I don’t wish to get into a conflict with him. So, addressing your first question, Mr. Chair. States have agreed that international law applies to cyberspace. In our view, convergence can be observed in several areas. There is a general agreement that the principle of sovereignty, the cardinal principle of contemporary international law, applies to states’ use of ICTs. Moreover, many states believe that sovereignty is not only a principle but also a primary rule of international law and that cyber operations do indeed have the potential to violate it. Switzerland recognizes that defining what constitutes a violation of the principle of sovereignty in cyberspace is particularly challenging and has yet to be clarified conclusively. There is also general agreement that the principle of non-intervention is applicable in cyberspace. Furthermore, the peaceful settlement of disputes, the prohibition of the use of force, and the right to self-defense should also be mentioned here. Having now said these core obligations, one area of convergence appears to be a desire to understand the consequences of breaching those core international obligations. It would therefore be useful to discuss the law on state responsibility more in depth, like other delegations have mentioned before, in line with the recommendations of the second annual progress report. Such a discussion can help to clarify, for example, what options a state has for seeking redress for an internationally wrongful act committed against it. Another area of convergence appears to be a desire to flesh out those core obligations in order to deepen our collective understanding. Deepening our collective understanding could take the form of states applying those agreed core obligations to fact scenarios. States have had the opportunity to do so in workshop settings, such as the event run by UNIDIR a few weeks ago, about which we have been informed yesterday. We commend UNIDIR for hosting this successful event. These workshops also often result in states recognizing convergence on granular details, as states often raise the same factors to consider when applying the law and often come to similar conclusions on unlawfulness, even if at times the pathway to recognize that unlawfulness may differ. Most importantly, these discussions encourage transparency and understanding, thereby lowering the risk of misinterpretation, miscalculation, or overreaction. As we heard in May and July this year and today, many more interventions raised both international humanitarian law and international human rights law as areas that this open-ended working group should discuss. Of the states that have set out their views on these topics, there appears to be a significant level of convergence, and it would be therefore very useful to harness that convergence in deeper discussions on these topics. Addressing your second and third questions. In your second question, you have asked us whether there are unique features relating to the use of ICTs that require distinction in terms of how international law applies as compared to other domains. Based on the discussion so far, the answer is no. We have long encouraged states to discuss how international law applies in cyberspace, not because the technology requires the law to apply differently, but to clarify how states interpret the law as it applies to this technology. From a systemic perspective, taking a different approach could be a very dangerous step for the international legal order, for it would mean that the emergence of a new technology or a new dimension of state cooperation creates an area of lawfulness until a dedicated treaty is adopted in this regard. The consistent practice of states to date, as expressed inter alia in relation to space exploration, clearly does not accept such a model. Most states that have addressed international law in this group have favored doing the interpretive work to determine whether there are any gaps in existing law that might require additional rules. For now, it is not clear at all that there are gaps. In fact, during the recent workshop hosted by UNIDIR mentioned before, five cross-regional groups of states discussing concrete scenarios agreed on what specific rules applied in each scenario, as well as how they would apply, including what factors states would look to in assessing the lawfulness of the conduct at issue. This remarkable degree of convergence confirms that, in fact, when looking at real concrete situations, states largely agree on how international law applies to the state’s use of ICTs. In our view, the existing international law is sufficient to govern activity in cyberspace. We would nevertheless like to encourage more time to be devoted to discussing the implementation of international law in cyberspace, and therefore support the proposal by the European Union and others to hold an intersessional meeting of two days or more dedicated to international law. Addressing your fourth question, the second annual progress report stresses the urgent need to continue capacity building efforts on international law. Several states have indicated that capacity is needed to develop national positions on the application of international law and in order to engage in substantive discussions on international law. Discussions on capacity building needs have taken place recently in Accra, Ghana, during the Global Conference for Capacity Building. The Accra Call for Cyber Resilient Development recognizes that the demand for cyber capacity building is strong and increasing and needed to promote the rule of law and to uphold human rights. Demand-driven and targeted capacity building initiatives should correspond to nationally identified needs and priorities. We’re therefore interested in hearing views on where additional capacity is most needed with a view to cooperate and to connect demand with concrete capacity building activities on international law. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Switzerland. I also wanted to remind delegations that you could submit your full statement in writing, and these could be put onto the website of the OEWG. You could also choose to deliver an abbreviated version if your lawyers allow you to do that. We also need to be mindful of the time. Thank you very much for your statement, Switzerland. We’ll go now to Estonia, to be followed by Denmark. Estonia, please.
Estonia
Thank you, Mr. Chair, for giving me the floor. Estonia aligns itself with a statement by the European Union and adds the following on its national capacity. Existing international law is the foundation of the framework of responsible state behavior in cyberspace. This includes the Charter of the United Nations in its entirety, customary international law, human rights law, and international humanitarian law, all of which apply in cyberspace. We would like to reiterate that before we decide to develop new rules, we should have a better understanding of how existing rules apply. Our active Open-Ended Working Group (OEWG) discussions on international law are showcasing states’ increasing interest to deepen a common understanding of how existing international law applies in cyberspace, alongside its possible implications and legal consequences. Importantly, states are called upon to avoid and refrain from taking any measures not in accordance with international law. We continue to condemn Russia’s unjustified military aggression against Ukraine, which has been accompanied by a significant increase in malicious cyber activities, including targeting critical infrastructure and conducting information campaigns. We have also expressed support for the UK in calling out Russia for its malicious interference with the UK’s democratic processes. The international community must not accept behavior breaching the obligations stemming from international law and norms of responsible state behavior. In response to your guiding questions, Mr. Chair, we see multiple areas of convergence in the context of states’ perspectives on how international law applies in the use of ICTs. These topics include, but are not limited to, the peaceful settlement of disputes, sovereignty, non-intervention, prohibition of the use of force, international humanitarian law, and the law of state responsibility. In July this year, a group of states – Australia, Colombia, El Salvador, Uruguay, and Estonia – presented a working paper which highlighted some of these topics and serves as an example of cross-regional efforts to identify convergence. Looking back at our previous Open-Ended Working Group discussions, many states have underscored the concept of sovereignty in international law and how the principles that flow from it apply to state conduct of ICT-related activities. Estonia reiterates that states have territorial sovereignty over the ICT infrastructure and jurisdiction over persons engaged in cyber activities on their territory. At the same time, states’ right to exercise sovereignty on their territory is not unlimited. For example, states have a responsibility not to breach the sovereignty of other states, as well as to take reasonable efforts to ensure that their territory is not used to adversely affect the rights of other states. Similarly, the principle of non-intervention is well established in international law, flowing from the principle of sovereignty, and applies to state conduct in cyberspace. Cyber operations that aim to force another nation to act in an involuntary manner or to refrain from acting in a certain manner and target, for example, the other nation’s national democratic processes, such as elections or military, security, or critical infrastructure systems, could constitute an unlawful intervention. Estonia also stresses that if cyber operations are carried out during armed conflict, international humanitarian law applies to them. This was also recently very well iterated by, for example, Brazil and Switzerland. Humanity, necessity, proportionality, and distinction are fundamental principles of international humanitarian law and must be followed when conducting any, including cyber, operation during armed conflict. Underscoring that these IHL principles by no means legitimize or encourage conflict, the Open-Ended Working Group should further study how these principles apply to the use of ICTs by states. Finally, Estonia supports awareness-raising and capacity-building efforts in the domain of international law to ensure all states can participate on an equal footing. We also note that the discussions on international law issues would benefit from the engagement of the expertise from different stakeholders, including the private sector, civil society, and academia. Estonia reiterates that the Program of Action would be well positioned to offer an inclusive venue for continuing our discussions on how international law applies in cyberspace. We also look forward to the opportunity of further focused discussions on international law during our next Open-Ended Working Group sessions. The dedicated inter-sessional meeting, as proposed in this year’s APR, would offer a great opportunity for that. Thank you.
Ambassador Gafoor
Thank you, Estonia. Denmark, to be followed by Ireland. Denmark, please.
Denmark
Thank you, Chair. In addition to the statement already provided by the EU and my Finnish colleague on behalf of the Nordic States, I would like to take this opportunity to present some key elements of relevance to our discussion here today, taken from the Danish position paper that we published this summer, and which we will, of course, make available in its entirety on the OEWG website. With regards to the question of state responsibility, Denmark is of the view that the general rules of state responsibility apply in cyberspace. A state bears international responsibility if it breaches an international obligation owed to another state. The state may be responsible under international law for acts undertaken by an organ of the state, or by actors exercising government authority on behalf of that state. Acts by a non-state actor may be attributable to a state where the non-state actor carries out a cyber operation under the instruction of, or under the direction or control of, that state, or where the state actor acknowledges and adopts the operations carried out by a non-state actor as its own. Each state may decide whether to publicly attribute cyber acts to another state or not. There is no obligation under international law for states to share documentation or other evidence supporting an attribution. The application of international law and state responsibility does not depend on public attribution. On the question of due diligence, Denmark is of the view that a state may bear international responsibility where a state fails to take adequate measures against a non-state actor or third state that conducts harmful cyber operations against another state from its territory or other cyber infrastructure under its effective control. While the precise contours of the due diligence obligation in cyberspace will continue to develop and crystallize in the coming years, it is possible, however, to set out some key features at this time. The state is obliged to take all reasonable measures to stop or prevent a given cyber act from occurring if the harm suffered to another state is significant. On the question of international humanitarian law, Denmark concurs with the view put forward by a number of states that it applies to cyber operations undertaken in the context of armed conflict. This is the case regardless of whether the cyber operation takes place during an international or non-international armed conflict. With regards to the application of international humanitarian law in the cyber domain, one key issue, of course, concerns the definition of attack and under which circumstances a cyber operation can amount to an attack. A cyber attack should be defined within the meaning of Article 49 of Additional Protocol 1. Denmark takes the view that a cyber operation may be considered an attack in the context of an armed conflict where it produces effects akin to those of a kinetic attack. Consequently, a cyber operation will constitute an attack if it can be reasonably expected to cause injury, death, or physical damage to individuals or objects. This definition also includes activity where substantial destruction is caused as a foreseeable secondary effect. Although digital data cannot generally in and of itself be considered an object under international humanitarian law, the destruction of data may have such adverse secondary effects on individuals or physical objects that the operation may nonetheless qualify as an attack. Similarly, an operation targeting data upon which the functionality of an object relies could qualify as an attack depending on the nature and scale of the damage foreseeably resulting from the operation in question. Where a cyber operation amounts to an attack, it is subject to the same rules and requirements as those applicable to attacks conducted in the physical domain. These include, among others, the principles of military necessity, distinction, proportionality, and humanity. Finally, in situations where a cyber operation does not amount to an attack, the relevant rules of international humanitarian law that address conducts or effects falling below the threshold of an armed attack nevertheless apply. This includes, but is not limited to, the obligation of constant care by which states are required to take all reasonable precautions to spare the civilian population as well as civilian individuals and objects when planning or conducting cyber operations in the context of hostilities. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Denmark. Ireland, to be followed by Nigeria.
Ireland
Chair, Ireland aligns itself with the statement delivered on behalf of the European Union earlier in this session, and we want to thank you and your team for the useful questions to guide our discussions here today, which we will endeavor to address as best we can in our national statement. It is clear that considerable progress has been made in the last few years in advancing our collective understanding of how international law applies in cyberspace. This is particularly evident from the growing number of national position papers that have been published and their increasingly sophisticated and detailed content. Several dozen such papers have been published to date, and we understand that more will be issued in the near term, including a contribution from the African Union, which we feel is a particularly significant and welcome development. It is clear from these papers, as well as from contributions in this and other fora, that substantial areas of convergence can be identified. The applicability of international law, including the UN Charter, to cyberspace at this stage is beyond question. Moreover, in the second APR, we saw convergence with regard to the prohibition on the use of force, the principles of non-intervention, and the peaceful settlement of disputes. Examining States’ positions, it is clear there are good levels of convergence on many other issues, including the principle of sovereignty, international human rights law, and international humanitarian law, even though, regrettably, some States refused to engage in discussions on some of these issues. It is notable, however, that the 2015 and 2021 GGE reports acknowledge the relevance of the core IHL principles of humanity, necessity, proportionality, and distinction to the use of ICTs by States. Chair, at this juncture, Ireland is not at all convinced that any unique features relating to the use of ICTs cannot be accommodated by the existing body of international law. Indeed, our discussions of international law to date demonstrate numerous examples of how States consider well-established rules and principles conceived in a pre-digital age are applicable in the cyber context. Likewise, we are not convinced at this stage that there are clear gaps in existing international law, and we consider any proposals for new legally binding rules to be premature. Without question, there are areas that merit further discussion and consideration as regards how existing international law applies in cyberspace. In our view, the due diligence obligation and the parameters of this obligation in the cyber context is one such area. Further discussion is also required on how existing international law and mechanisms can provide for attribution and accountability for malicious cyber operations, in particular through the application of the law on State responsibility and the peaceful settlement of disputes. Chair, the second APR correctly stresses the urgent need to continue capacity-building efforts in international law. It is clear that a lot of very positive initiatives have been and continue to be pursued at the multilateral, bilateral, and regional levels, as well as initiatives led by the private sector. While these are welcome, there remains much to be done. In this regard, we will be interested in hearing from developing States on what priority capacity-building needs are presently being met in the areas of international law. Ireland would like to extend an invitation to any developing States interested in speaking to us and learning from our own experience in preparing our national position paper, which we issued earlier this year. We would be more than happy to share our experience. Thank you very much.
Ambassador Gafoor
Thank you, Ireland. Nigeria, to be followed by Kenya. Nigeria, please.
Nigeria
Thank you, Mr. Chair. Still under international law, we believe that the laws are there. The principle of applying this law is what matters. To this end, permit me, on behalf of my delegation, to thank you, the Chair, and your team for the hard work since the inception of the Open-Ended Working Group on the security of and the use of information and communication technology. To welcome the adoption of the second HANA report by consensus, we also believe there is a need to close some gaps and intensify efforts to improve the document. It is clear that only through multilateral mechanisms and dedicated efforts can we address the malicious use of ICT by state and non-state actors. Nigeria assures you of its support for a successful outcome, for universal principles and guidelines on the security of and the use of information and communication technologies. Nigeria urges all inclusivity to address most of the concerns raised by different delegations. This is crucial to enhancing global cooperation on international security as it relates to ICT. As we forge ahead in our negotiations, common ground must be found to streamline divergent opinions that will effectively capture the peculiarities of all member states. This is because national laws on cyber security and cybercrime vary. My delegation remains deeply concerned over the increase in incidences of the malicious use of ICT by state and non-state actors, including terrorists, violent extremism, and criminal groups. It is important to state that it is no longer news that some states are developing ICT capability for military purposes and these have been used in conflict in different regions. The need to urgently address the new evolving trend should be treated as an optimal priority. Mr. Chair, within the context of existing and potential threats, we express worry on the rise of violent extremism in cyberspace, particularly the recruitment of children and youth by terrorists, human traffickers, and other criminal groups. These nefarious acts have evolved over the years and have spread across the globe due to ineffectual regulation of the web. The negative impact of the malicious use of ICT on critical infrastructure and critical information infrastructure in society needs to be tackled head-on. Similarly, the spread of misinformation and disinformation on the internet is generating a deepening mistrust as it brews avoidable conflicts. It is therefore pertinent to address this menace holistically without undermining fundamental human rights. We must work together to reach a consensus on how to regulate unfettered digital abuse. On this note, we echo other countries’ voices on the urgent need to secure the use of cyberspace against existing and emerging threats of ransomware, malware, misinformation, disinformation, identity theft, extremism in all facets, and all other cyber activities that undermine peace and security at both national and international levels. On international law, my delegation is also of the opinion that to prevent the malicious use of ICT, a global legal architecture that will ensure the peaceful use of cyberspace by state and non-state actors also needs to be advanced for the common good of humanity. This could be achieved by strengthening the existing international law and continuing the sharing of national views on international law, including on the state practices related to the use of ICTs. As we all know, a society can only thrive on the application of law and order. Hence, the use of international law is pertinent to guide cyber activities for a peaceful and beneficial relationship among sovereign states. Mr. Chair, sovereignty presupposes the right of states to conduct their internal and external affairs, including their cyberspace, without external interference through malicious cyber activities. The onus, therefore, falls on states to enforce relevant laws against nefarious cyber activities within their territory. This would deter non-state actors from perpetrating belligerent actions against other states, individuals, or organizations. States must also uphold high standards against cyber attacks. When attacks occur, we urge proportionate self-defense. Cyber attacks against critical infrastructure and critical information infrastructure are a red line for Nigeria, and culprits are made to face the full wrath of the law. Mr. Chair, in conclusion, Nigeria is open to learning from others while also sharing its experiences. Furthermore, Nigeria will continue to support the ongoing process until a consensus is reached on the application of international law to cyberspace. I thank you all.
Ambassador Gafoor
Thank you, Madam Chair. Kenya, to be followed by Austria. Kenya, please.
Kenya
Thank you, Chair. The UN regional and sub-regional organizations provide important platforms for Member States to exchange views and share information on international law and how it applies to the use of ICTs by States. My delegation recognizes the work done by the African Union towards developing a common position on the applicability of international law in cyberspace. On areas of convergence of how international law applies in the use of ICTs, my delegation wishes to reiterate the important role played by regional bodies in developing common understanding and continues to call for the publication of national position papers on the interpretation of international law and its applicability to the use of ICTs. Discussions by Member States at the regional level on the applicability of international law shall raise awareness and act as a confidence-building measure, guiding nations in their interactions. In addressing the question of unique features of ICT that may require distinction in how international law applies, discussions on this topic should be guided by the general purpose of international law, which is to ensure cyberspace is used for peaceful purposes, prevention of malicious and criminal use of cyberspace, promotion of greater cooperation between States, guaranteeing that cyberspace remains open, safe, secure, stable, and accessible, protection of human rights and fundamental freedoms of individuals, and advancing the common interests of humankind. On capacity building in the area of international law, efforts should be directed at helping Member States acquire the necessary capacity to develop national positions on the issue as a drive towards common understanding. Such efforts can be driven from the regional level, as has been done through the African Union. However, caution must be taken to ensure that capacity building assistance is only used to guide. I thank you, Chair.
Ambassador Gafoor
Thank you, Kenya. I give the floor to Austria, to be followed by Nicaragua. Austria, please.
Austria
Thank you so much, Chair. My delegation would like to thank you for all your efforts, especially for providing us with guiding questions to help our discussions. Austria fully aligns itself with the statement on behalf of the European Union and would like to make some further remarks in our national capacity. Firstly, regarding your question on the convergence of views of states, Austria would like to stress that previous GGEs, Open-Ended Working Groups, and in fact the entire UN membership of the General Assembly, have affirmed repeatedly that international law as a whole applies to cyber activities of states. In the second annual progress report negotiated under your able leadership, states reaffirmed central principles of international law to be applicable in the cyber context, in particular sovereignty, peaceful settlement of disputes, prohibition of the use of force, and non-intervention. Strong convergence of states’ views in the affirmation of these principles is therefore clearly visible. These core rules of international law, and most importantly the UN Charter in its entirety, are applicable in the cyber context. In addition, the protection of human rights in the cyber context is of particular importance and, as has been reaffirmed many times and mentioned by many other delegations, the rules of international humanitarian law apply to cyber activities and are highly relevant in current times. As to your second question, whether there are any unique features relating to the use of ICTs that require a distinction in terms of how international law applies, we do not see cyberspace to constitute a separate domain like outer space or high seas. Since cyber activities do not take place in a separate virtual space, but in the real world through real infrastructure and real persons, international law in its entirety is applicable. Thus, they do not constitute a new domain that requires its own new rules. We think that discussions as to how international law applies in the cyber context need to be deepened. In Austria’s view, international law as such does not contain gaps with regard to cyber activities, but against the background of special technical aspects of cyber activities, the modalities of the application of international law require further clarification through continuing discussion. In this context, Austria highly welcomes the various position papers on international law and cyber activities that several states have already published. These position papers help to understand and consolidate the states’ legal views and practice. I’m pleased to report that Austria is currently finalizing its national position paper, and we will present it early next year. Mr. Chairman, I would like to thank other delegations for the very thoughtful and interesting statements from which we all, I think, learn a lot, and we can see that it would be very useful if we would have the time to go deeper in our discussions on this basis. Austria therefore welcomes the outcome of the second annual progress report to convene a dedicated international meeting on how international law applies. For such an international meeting to contribute to the deepening of our common understanding, we should encourage legal advisors from capitals to actively participate. For legal advisors to come to New York to such a meeting, it should last several days and be well prepared, with expert briefings and the background paper as a basis for our discussions. Finally, also since you want to have an interactive discussion, I would also like to briefly address two issues which were raised by other delegations in our discussions so far. One is where we heard that, we would like to stress in our view, there is no legal basis for the argument that was made that the law of state responsibility could only be applied to malicious cyber activities of states if we have a specific treaty. As we have all agreed that existing international law is applicable to this in the cyber context, the existing law of state responsibility also fully applies. In other words, existing international law provides clear rules for the responsibility of states for malicious cyber activities. Some states also question whether a cyber attack can constitute an armed attack under international law. As we have agreed repeatedly that the UN Charter applies to the cyber context, this also includes Article 51 on self-defense. Consequently, a cyber attack can constitute an armed attack in the sense of Article 51 of the UN Charter if the cyber attack causes significant death or injury to persons or substantial material damage or destruction. Although such instances might be rare and hopefully don’t happen, we have seen in some past incidents that it is very much possible that cyber operations can have kinetic effects. For them to constitute an armed attack, such effects need to be particularly severe. Mr. Chairman, my delegation remains committed to this issue, and we thank you very much for this opportunity to exchange views on these important topics with other delegations. Thank you.
Ambassador Gafoor
Thank you very much, Austria. Before we go to the next speaker, I wanted to address this particular point about the submission of national positions. I think the previous speaker, Austria, referred to it, and also Kenya, and quite a number of you also raised the question of capacity building with regard to international law and that you needed a better understanding of what aspect of capacity building precisely would be needed with regard to international law. Can we think in terms of how we can have more and more countries submitting national position papers on their perspective about how international law applies in the ICT domain? It’s very good that we are hearing statements here today, but I understand that maybe about 27 countries have made submissions of their position papers to the Secretariat, as is visible on the OEWG website. So the question is, how do we get more countries to put forward their position papers and share them with the international community? What capacity building would they need to prepare these position papers? And as Kenya also mentioned, capacity building with regard to the preparation of position papers at the national level could also be channeled through regional organizations. And of course, one has to be careful that the capacity building is to guide delegations in terms of how these position papers are prepared. Ultimately, it’s also a national responsibility for each country to decide on their own positions with regard to how international law applies. So I thought I would inject that element here, and if we can have some reactions and other comments to that, that will be useful for all of us. I have quite a list, so we’ll start with Nicaragua to be followed by Spain. And do keep in mind that you can submit your fuller statements, so don’t feel obliged to read every line and paragraph that your lawyers have prepared for you because we love lawyers, but I’m also looking at the time constraint. Yeah, thank you. Nicaragua followed by Spain.
Nicaragua
Mr. President, Chair, we extend to you our gratitude and thanks for your leadership and to the Secretariat for all of their support. Nicaragua expressed its full support for the OEWG on the security of ICTs in use in 2025. We maintain our availability to continue participating actively in these discussions during this sixth session. Every day, we are facing new, changing, and increasingly complex challenges. The politicization of cyberspace is another of the existing threats. This goes hand-in-hand with the lack of clarity in attributions in order to identify perpetrators, be they individuals, states, or organizations, which actually carry out IT attacks against third countries. It is important to recognize the need for greater preparation and capacity building in developing countries in order to prevent and respond to misuse of ICTs directed at affecting states and actions that are a violation of the Charter of the United Nations and international law, especially when improper use has an impact that affects the economy and critical infrastructure and interferes in the internal affairs of states. Therefore, the international community should make a global commitment to cooperate and agree on the use of ICTs being peaceful and beneficial to the development agenda of our peoples. For this, we must have a serious commitment that opposes the militarization of cyberspace. Unilateral coercive measures are obstacles in terms of getting access to the technologies that are required in order to be better prepared for the various threats and in order to have access to the benefits surrounding the secure ICT environment. For this reason, it is urgent that we eliminate these unilateral measures that are imposed against countries affected by such aggressions. We think that it is urgent that we move towards concluding an international legally binding instrument on questions related to cybersecurity and the use of ICTs and that will regulate the responsible behavior of states in cyberspace. To conclude, it is indispensable that we strengthen cooperation and international solidarity in order to develop different measures to share knowledge and best practices that contribute to national and international security of information and also to tackle other threats including disinformation, the protection of personal data, and the monopolization of the market of ICTs amongst others. I thank you.
Ambassador Gafoor
Thank you, Nicaragua. Spain, to be followed by Italy.
Spain
Thank you, Chair. Spain aligns itself with the statement delivered by the European Union and wishes to add the following elements. In its national capacity, it is imperative that we move forward in the substantive debate related to the application of existing international law to cyberspace, especially as regards sovereignty and responsibility of states and international humanitarian law. We must have greater detail. We believe also that, as other countries have mentioned in their statements, cyberspace is not an exception or a unique case in international law. Regulation on the responsibility of states applies to this as in other domains. Despite the fact that many countries have now published their national positions and Spain is currently developing its own, we believe that we could go deeper in guidance on an issue of notable complexity such as this. We also feel that the commendable work of many countries and institutions and the organization of side events alongside main sessions is valuable, and we would welcome special meetings in the inter-sessional period to go into greater depth on the precepts of international law that may require greater clarity in terms of how they are applied to cyberspace. We also feel that the creation of capacity building through national training of national experts and raising awareness amongst government representatives is essential in order to move towards more detailed national positions and as a necessary step prior to developing the necessary norms and standards. Thank you.
Ambassador Gafoor
Italy, to be followed by the Russian Federation.
Italy
Thank you, Chair. Good morning, all. Italy aligns itself with the statement of the EU and is also fully convinced that because there are no doubts that international law in its entirety applies to cyberspace, our work must focus on deepening our understanding of how it is applied. That is why we have been doing this steadily, and there has been incredible progress over the past years. As we have heard several times this morning, numerous states, including Italy, have published their views on the applicability of international law to cyberspace. This is heartening and a sign that we are indeed on the right track and should continue to pursue it. Another element that supports this view is the fast development of new technologies that require immediate certainty of law and principles to ensure they are designed and used for good and do not constitute a risk for international stability. As we have heard from other delegations, technology is neutral and one more sector of human activity, albeit a very complex one. That is why not only does international law provide the necessary common discipline, but we should also hold on tight to its fundamental rules to avoid uncertainty at a time of such fast-paced technological developments. You asked us about convergences, Chair, and here I would like to refer to UNIDIR’s first workshop on how international law applies to cyberspace, which was held in Geneva last month and where I had the privilege to participate. It was an excellent step in the direction of further understanding how international law applies. Its final report provides us with a faithful picture of its discussions and highlights. Participation was active and engaged, and as the report states, there was an extremely good level of convergence on many of the topics considered, such as the principle of sovereignty that many states, including Italy, consider a primary rule, the prohibition of the use of force, the applicability of the law of peaceful settlement to disputes arising from state use of ICT, and the centrality of the principle of good faith thereto, just to name a few examples. Of course, there were some questions and differences of opinion as we delved into the specifics where case-by-case interpretations are needed, which allow me to say that it is simply and barely the nature of law that is general by definition and is applied and interpreted on a case-by-case basis. So rather than gaps, I would therefore speak about the need for interpretation, and cyberspace does not differ from other realms. From the Italian perspective, there is scope for further discussion on specific areas such as due diligence obligations, the law of responsibility of states, or the concept of cohesion, just to name a few of them, and with a case-study approach. Also, I agree with UNIDIR that the number of countries involved in similar future workshops can be increased. In fact, our conclusion after the workshop is that we need more exercises like the one organized by UNIDIR, and I thank the states that have supported the exercise because that will tremendously help to consolidate our general understanding and convergences and to be able to look for further articulations at a later stage if needed. We also look forward to the dedicated inter-sessional meeting next year so that legal experts can further deepen our discussions. And we also see a lot of merit in the proposal of Mexico about the role of the International Law Commission to accompany this important task of ours. So there are several avenues that could be practically pursued to deepen our common understanding of how international law applies to cyberspace. Finally, a comment on international humanitarian law. The second APR recognizes that ICTs have been used in armed conflicts. These issues are more than ever pressing in the current challenging geopolitical environment. It is our view that international humanitarian law, like all international law, is applicable in cyberspace and must therefore be part of our discussions and reports and also possible workshops. Also, and as a complement to our earlier remarks on norms, we think that we need to better discuss the application of human rights law to cyberspace. That becomes increasingly important as our societies become more digitalized. States need to protect the rights of the citizens as they protect the security of their systems. Of course, there is a need for capacity building on these topics. And we believe that workshops like the one organized by UNIDIR can be adapted also to become a capacity building exercise, and capacity building activities on international law and other topics will also probably greatly benefit from the establishment of the Program of Action that will be discussed later this week. Finally, Italy has been supporting the activities of UNIDIR and the ICRC and is proudly continuing to do so. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you. Italy, Russian Federation, to be followed by Kiribati.
Russia
Mr. Chair, international legal regulation of information space is one of the most important and at the same time most complex aspects of the Working Group, and the 25 years of discussion of this matter under the UN auspices of the world community has reached consensus only regarding the applicability of generally accepted principles of international law to the ICT. And these include primarily sovereign equality, non-use of force and threat of force, respect for the territorial integrity of states, resolving international disputes by peaceful means, non-interference in internal affairs, good faith discharging of obligations under international law, and interstate cooperation. At the same time, the application even of these principles in the field of ICT should not be carried out automatically because of the specific legal and technical nature of the information environment. I refer to, in particular, such features that it has as a cross-border and all-pervasive nature of ICT, the anonymity of their use, and their potential use for dual purposes. What should a state do, for example, in a situation when the information infrastructure located on its territory and used to carry out computer attacks belongs to a foreign company? How do you ensure the sovereignty of a state in its information space when global communication networks are under the control of some specific countries? How, under such circumstances, can we guarantee compliance with the UN Charter, compliance with the principles of international law concerning the sovereign equality of states, and non-interference in their internal affairs? And these are only some of the questions that need to be answered so as to exclude the so-called political attribution of computer attacks from international relations. Another important aspect of this discussion is the problem of reliably identifying the source of harmful activities. It is necessary to adhere here to the principle which is enshrined in the UN General Assembly Resolution 73-27 and in the reports issued by the Group of Governmental Experts in 2015 and 2021. All accusations, that is, of organizing and committing illegal acts brought against states should be substantiated. It is unacceptable to assign responsibility for incidents in information space to anyone without evidence, and to an even greater extent, it is unacceptable to introduce unilateral restrictions at one’s discretion. It is necessary to agree on organizational and technical de-anonymization mechanisms, such mechanisms that will enable objective identification of the sources of computer attacks and of the dissemination of illegal information. It is obvious that there are many gaps in international law with regard to information space. In this respect, we believe that the point repeated by a number of states about the sufficiency and the full applicability of the current international law to regulate the digital environment is completely groundless, and that is exactly the conclusion that was voiced at a recent seminar organized by the United Nations Institute for Disarmament Research, UNIDIR. Without disclosing the details of the event—it was held under Chatham House rules—I will only say that the consideration of specific scenarios has clearly demonstrated that it is impossible to comprehensively regulate information space on the basis of existing norms. The only way to fill the gaps in international law is to develop it progressively through developing new norms which would take into account the specific nature of ICTs and ideally to work towards agreeing on a universal legally binding instrument. In our view, this is the only way to ensure the exclusively peaceful use of ICTs and the prevention of conflicts in this area. In the absence of relevant international legal obligations, states cannot be held accountable for wrongful acts. Russia, together with a group of countries, presented as a prototype of a future international treaty, a concept of a UN Convention on ensuring international information security. We dwelled upon it in detail during the discussion on rules, norms, and principles of behavior of states, and the documents published on the Working Group website are open for discussion. I thank you.
Ambassador Gafoor
Thank you, Russian Federation. Kiribati, to be followed by New Zealand.
Kiribati
Thank you, Chair. As this is the first time we are taking the floor, we would like to convey our appreciation to you, Chair, and your team for convening this sixth substantive session on the Open-Ended Working Group on security of, and in the use of, information and communication technologies. Coming from the Blue Pacific, the delegation of Kiribati appreciates the opportunity to discuss how international law applies to the use of information and communication technologies by states at the sixth substantive session. Chair, Kiribati remains concerned about the continuing increase in incidences involving the malicious use of information and communication technologies by both state and non-state actors, including during armed conflict. Specifically, we are concerned about belligerents who use cyber operations not only against their adversaries but also to target civilian infrastructures. In this regard, we are proposing focused exchanges at the OEWG on the limits that international humanitarian law imposes on such operations. Our additional concern is with the growing involvement of civilians, individuals, hacker groups, and companies in hostile digital operations related to armed conflicts. The potential risks that arise from civilian digital infrastructures used for military purposes must be addressed. Therefore, as proposed by the ICRC and other entities in previous sessions, we recommend that states, the tech sector, and civil society should collaborate on developing a common understanding of the limits on the military use of civilian digital infrastructures during armed conflicts. I thank you, Chair.
Ambassador Gafoor
Thank you, Kiribati. New Zealand, to be followed by El Salvador.
New Zealand
Thank you, Chair. Recent advances in cyber capability and a rise in malicious activity online raise novel questions about how international law applies to state activity in cyberspace. However, cyberspace is not a lawless space. New Zealand’s consistent position is that international law applies online as it does offline. While there is consensus amongst states that international law applies to state activity in cyberspace, the question of how it applies is nuanced. Activities in cyberspace involve at least, first, a human component, the real people operating in the physical world, some of whom may be state agents or acting on the instructions of, or under the direction or control of, a state, and who use and misuse information and communications technology. Second, a tangible physical component, the cyber infrastructure and hardware physically located in the sovereign territory of the state. And third, an intangible virtual component, the data, operating systems, software, information, and content of cyberspace. These elements can operate with a transboundary character, including through cyber personas. Applied appropriately, existing international law, as part of the framework of responsible state behavior in cyberspace, provides an effective toolkit to regulate state behavior online. This includes the ability to identify breaches of international law in cyberspace, attribute state responsibility for those breaches, and guide responses from victim states. Therefore, in our view, we do not see cyberspace being unique that would require distinct terms or rules, but rather continue to develop further common understanding on application and interpretation of international law. In response to your question, Chair, about identifying further areas of convergence on how international law applies in the use of ICTs, we share the view that these include the law of state responsibility, international human rights law, including the right to freedom of expression and the right not to be subject to arbitrary and unlawful interference with privacy, international humanitarian law, as well as the UN Charter in its entirety, particularly the prohibition on use of force under Article 2.4, and the requirement to settle disputes by peaceful means. We would welcome further dedicated discussions on these topics. Finally, we see a need for the OEWG to further discuss breaches of international law and accountability for wrongful acts before moving to the question of whether there are any possible gaps in the legal and normative framework. Thank you.
Ambassador Gafoor
Thank you. New Zealand, El Salvador, to be followed by the Republic of Korea.
El Salvador
Thank you, Chair. We thank you for this opportunity to refer to the discussion on the applicability of international law to cyberspace. At the previous session, El Salvador, together with a group of countries, presented a document – a working document – with the aim of seeking convergences and promoting a shared understanding of how international law applies in cyberspace. A decade ago, some people did not agree that international law was applicable to cyberspace, and now this notion enjoys consensus. In the questions that you asked, I wish to highlight that El Salvador has adopted a progressive approach as regards international law. We support the construction of understanding through voluntary normative approaches while discussions are going on. We recognize that some states may advocate for binding agreements, and this is legitimate nevertheless. A basic principle is that all states should share a shared conception in order to facilitate agreements that would benefit the majority. In the area of ICT security, this is extremely complex as a result of the disparity in capacity, an issue that we have addressed at some length. From the perspective of El Salvador, we cannot identify gaps in the applicability of international law in the use of ICTs. However, we do recognize that swift technological advances of our age require constant development and evolution of the doctrine because it is in this process where possible gaps may arise, which I mean that there are no gaps in applicability, but rather in the understanding of approaches. As regards the recommendation of the annual progress report on capacity building in international law, we welcome the list of topics that has been the subject of debate already. We urge you to go deeper in this discussion, considering the possibility of future questions such as the obligations of states derived from the Charter of the United Nations, international law, attribution, responsibility to submit evidence, and other obligations that emanate from international humanitarian law and international human rights law. Thank you very much for this opportunity to contribute, Chair.
Ambassador Gafoor
Thank you, Salvador. Republic of Korea, to be followed by Israel.
South Korea
Thank you, Chair. The Republic of Korea reaffirms that existing international law, including the UN Charter in its entirety, is applicable in the use of ICTs. The application of international law in the use of ICTs is necessary to protect the cyber domain from malicious actors and provide a mechanism to hold perpetrators accountable for their actions. But there may be some areas that can be elaborated and clarified through the exchange of views and a series of capacity-building efforts. For instance, we have agreed that states should refrain from the threat or use of force in general and in cyber domains specifically, as stated in the UN Charter. However, we still have tasks to develop convergence of views on technical and legal issues in identifying who is responsible for a cyber attack that might qualify as an armed attack given the nature of cyberspace. We also need to work together to find common elements in the application of international humanitarian law in the use of ICTs. The goal is to establish minimal safeguards in situations of armed conflict. We note that this endeavor to enhance our understanding is not an endorsement or justification for armed conflict. In this context, my delegation believes that convening a dedicated international meeting on the application of international law, as recommended in the second APR, could assist us in identifying further convergences. We also recognize the value in the effort by the UNIDIR and other sponsoring countries to organize a workshop focusing on specific questions and scenarios. This approach can facilitate robust and candid discussions regarding the application of international law. My delegation emphasizes the importance of conducting more such exercises with experts and states, which can bring new ideas to our discussions in the OEWG. We also support the idea to take a two-track approach, with one dedicated to in-depth discussion and another focused on knowledge sharing for countries less familiar with this topic. Engaging in extensive discussion with legal experts and also ICT specialists in various formats can contribute to the progress of our deliberations. Thank you.
Ambassador Gafoor
Thank you, Republic of Korea. Israel, to be followed by the Netherlands.
Israel
Thank you, Chair, for giving me the floor. As we have already presented Israel’s perspective on the issue of the application of international law to cyberspace, please allow me to reiterate certain key points. I’ll do my best to be as concise as possible. Israel supports discussions on the application of international law to cyberspace. We believe, however, that deepening our understanding of how international law applies is a continuing and long-term process, one that involves states forming national views and exchanging positions, as we witness that the threat landscape continues to develop. Israel’s position on the application of international law to cyberspace has been consistently expressed over the years in these OEWG discussions as well as in other international forums. We are also happy to mention that we have recently presented the UNODA Secretary with an official legal paper dealing with Israel’s perspective on key legal and practical issues concerning the application of international law to cyber operations. We reiterate our fundamental position that international law is applicable to cyberspace. However, given the unique features of cyberspace and the fact that many traditional rules of international law have been developed and adopted in a domain-specific context, it is necessary to evaluate whether and how certain rules of international law relate or apply to the cyber domain in order to understand whether adjustments and clarifications are necessary. For example, data travels globally across networks and infrastructure located in multiple jurisdictions, transcending national borders and lacking meaningful physical manifestations. Moreover, cyber infrastructure is, to a large extent, privately owned and decentralized, both at the domestic and international levels. The cyber domain is also highly dynamic, with technological developments and innovation advancing at a rapid pace. When considering the applicability of specific rules of international law to cyberspace, it is important to be mindful of such distinctive features and to carry out a meticulous examination of the rules at play and the context in which these rules emerged. Mr. Chair, the OEWG has played a key role in enabling states to present and publish their views on the application of international law. As the landscape continues to evolve, states will no doubt seek to continue to make their views known, relate to international law aspects of new threats that are emerging, refine previous positions, and perhaps revise and update previous statements. In Israel’s view, the OEWG can and should continue to play a role in facilitating discussions on international law by continuing to provide a platform for states to present and publish their views on a voluntary basis. Finally, Mr. Chair, we feel that building a common understanding of how international law applies to the use of ICTs by states should be the first step before moving to the creation or adoption of any new rules and norms. Additionally, we wish to echo other speakers and reiterate again that Israel does not see any need for the development or the adoption of a legally binding instrument in this context. Thank you.
Ambassador Gafoor
Thank you, Israel, for your statement. Netherlands, to be followed by Pakistan.
Netherlands
Chair, distinguished delegates, the Netherlands aligns itself with the statement delivered by the European Union, and I would like to add the following remarks in a national capacity. Let me start by recalling what we have agreed on by consensus: that international law, and in particular the Charter of the United Nations in its entirety, is applicable in the ICT environment. Over the past year, a lot of our discussions have focused on the UN Charter, resulting in convergence on a number of core obligations that apply to state behavior in cyberspace. This includes the principle of sovereignty, the prohibition on the threat or use of force, the prohibition of intervention, and the obligation to settle disputes peacefully. To keep this momentum going, we should also focus our attention on other areas of law that equally apply in cyberspace. This includes the law on state responsibility, international human rights law, and in situations of armed conflict, international humanitarian law. Let me say a few words on each of these bodies of law. First, on the topic of international humanitarian law, the second APR recognizes that ICTs have already been used in conflicts in different regions. This further underscores the need to engage in substantive discussions on how international humanitarian law applies. International humanitarian law applies to cyber operations conducted in the context of armed conflict and places important limits on these operations by protecting civilians, civilian objects, and those who are no longer taking part in the hostilities. On the topic of international human rights law, the Netherlands is of the view that a safe, secure, and stable cyberspace not only serves the interests of states but is first and foremost in the interest of its citizens. Cyber operations that disrupt essential services and sectors, such as the provision of health care or the energy supply, have a large-scale impact on humans. This is why human rights law has been recognized as applicable to state conduct in cyberspace. And states do not only have a negative obligation to respect human rights but also have a positive obligation to protect their citizens against human rights violations. Thirdly, Chair, we believe it is important to discuss accountability for the malicious use of ICTs. In this regard, the Netherlands considers that the law of state responsibility and existing means of peaceful settlement of disputes provide effective means to ensure accountability in cyberspace. For instance, the law on state responsibility and the case law of the International Court of Justice provide specific rules and guidance on legal attribution, which concerns the decision of an affected state to attribute an act or omission with the specific aim of holding that state legally responsible for violating obligations of international law in this context by means of a cyber operation. The law on state responsibility also provides states with different options to respond to wrongful conduct in cyberspace. Chair, the Netherlands is of the view that the features of ICTs do not require distinction in terms of how international law applies. Just as states do in every other area of international law, a process of interpretation and clarification can result in agreement on how existing rules apply to activities in cyberspace. In this sense, interpretation is a standard process of international law, not unique to cyberspace. To aid the process of interpretation and clarification, it is critical for states to continue to engage in focused discussion on how international law applies, and such substantive discussions have taken place within the context of the OEWG, and these discussions have also continued to take place outside of this context. Excellent examples include the Senior European Dialogue, an expert working group, and a workshop organized by UNIDIR that was presented to us yesterday. When applying international law to specific scenarios, the cross-regional group of states that participated in this workshop showed convergence in their national views on how a number of existing international legal obligations apply in cyberspace, and these discussions also demonstrate that there is sufficient scope for future convergence on existing rules before considering any new rules. We welcome the organization of additional workshops with a wider selection of states. Chair, finally, let me say a few words on the importance of capacity building. The Netherlands recognizes that in order for all states to be able to partake in substantive discussions, capacity building in collaboration with existing organizations remains essential. As mentioned by many here today, capacity is needed for the development of national positions, and as stated by Thailand, for the purposes of attribution. This was also the outcome of the Global Conference on Cyber Capacity Building held recently in Ghana, where the Netherlands partnered with Costa Rica and Canada to organize a dedicated session on how international law can strengthen cyber resilience. We are interested in hearing the views of states on where additional capacity is most needed, and note that a number of existing capacity building initiatives are already being undertaken by states, regional organizations, and by the private sector. These include courses, trainings, and seminars on international law, and continued discussions within the form of the OEWG. I thank you, Chair.
Ambassador Gafoor
Thank you, Netherlands. Pakistan, to be followed by the United States.
Pakistan
Thank you, Chair. Pakistan believes that one of the important tasks of this group is to agree on defining how the existing international law can be applied in cyberspace. In this regard, Pakistan supports the idea of continued discussion on specific topics related to international law, with particular focus on identifying areas of convergence and consensus. It was heartening to see that during previous sessions, particularly in the fourth and fifth, as well as in formal sessions of the OEWG, states had focused discussion on this important agenda. While Pakistan appreciates the reaffirmation by states that international law, in particular the Charter of the United Nations, is applicable and essential to maintaining peace, security, and stability, and promoting an open, secure, stable, accessible, peaceful ICT environment, Pakistan’s position on the application of international law in cyberspace has remained quite clear. Pakistan believes that the principles of non-use of force, sovereign equality of all nations, non-intervention, and peaceful settlement of disputes, as enshrined in the UN Charter, apply to cyberspace. However, considering the unique attributes of cyberspace and the transnational nature of cyber technology, international law has certain gaps which must be addressed. For example, the concepts of sovereignty, self-defense, use of force, and attribution demand further in-depth discussion within the UN and this group. Global peace and security rest on the formulation of a legally binding mechanism to regulate global cyberspace, a mechanism which promotes responsible behavior by holding actors responsible for their acts and prohibits the use of cyberspace for destructive purposes. In this regard, Pakistan has submitted its position paper on the application of international law in cyberspace in March this year. Pakistan proposes to get definitional clarities of terms like cyber attacks, cyber terrorism, critical infrastructure, critical information infrastructure, and to conduct further discussions on the application of international law for cyber operations. As outlined in the second annual progress report, Pakistan supports neutral and objective debate on this topic to build common understanding of how international law applies to the use of ICTs by states. The group must discuss and find ways to solve the problem of cyber attribution. Chair, in conclusion, Pakistan reiterates the urgent need to continue and expand capacity building efforts, including with the aim of ensuring that all states are able to participate on equal footing in the development of common understanding on how international law applies to the use of ICTs. I thank you, Chair.
Ambassador Gafoor
Thank you, Pakistan. United States, followed by Germany.
United States
Thank you, Chair. Chair, I would like to thank you for your guiding questions on this topic, which, as always, are very useful for shaping our discussion. I wish to also express my thanks to UNIDIR for its briefing on the productive workshop it recently organized. Your first question, Chair, asks us whether we can identify areas of further convergence among states on international law. We have been very encouraged by discussions in the OEWG and in other UN fora demonstrating significant convergence among states on a number of topics, including the prohibition on the use of force, non-intervention, and the peaceful settlement of disputes. At this point in our discussions, we believe it would be useful for the OEWG to have focused discussion on the law of state responsibility, including on how states can seek relief when they are injured by internationally wrongful acts involving the use of ICTs. This is a logical next step to the discussions we have had about the core obligations under the UN Charter and customary international law, and would complement our discussions of other elements of the framework, including the need for cooperation among states in response to cyber incidents. Separately, we note the use of ICTs by states in ongoing armed conflict and take this opportunity to join others we’ve heard from this morning, including Thailand, Brazil, Mexico, Finland, and Switzerland, in calling for focused discussions on how IHL, including the principles of distinction, necessity, proportionality, and humanity, applies in cyberspace. We believe engaging on this question could promote international peace and security by providing additional clarity on how IHL regulates state conduct in cyberspace. As others have pointed out, the goal of IHL is to mitigate human suffering, not to promote or endorse armed conflict in any domain. Some states have asserted that discussing IHL would somehow endorse the use of ICTs in armed conflict, but unfortunately, as others have repeatedly observed over the course of this OEWG, we are already seeing ICTs being used in armed conflicts that are ongoing right now, this week. Discussing IHL under these circumstances is part of the responsibility of this group to promote international peace and stability in the use of ICTs. It would remind states of their obligations under IHL and provide an opportunity for all states to further clarify and reach common understandings on how IHL applies to the use of ICTs when armed conflict does occur. The Chair has also asked us whether there are unique features relating to the use of ICTs that require a distinction in terms of how international law applies as compared to other domains. States agree and have confirmed in multiple consensus GA resolutions that existing international law applies in its current form to states’ use of ICTs. The question of how it applies, of course, requires further discussion among states. It also requires associated capacity building on relevant technology concepts, international law, or both. These capacity building programs, such as the recent UNIDIR workshop, have demonstrated both keen interest from states on these issues and the need for additional programming. Therefore, we believe it is premature for the OEWG to expend time and resources focusing on whether there are gaps in existing law that require additional rules. In fact, during UNIDIR’s event, five cross-regional groups of states discussed concrete scenarios, agreed on which specific rules applied in each scenario, as well as how they would apply, including what factors states would look to in assessing the lawfulness of the conduct at issue. This remarkable degree of convergence confirms that, in fact, when looking at real concrete situations, states largely agree on how international law applies to states’ use of ICTs. We are pleased that UNIDIR plans to host more of these events so that as many states as possible have the opportunity to participate. In support of these efforts, the United States is pleased to have recently signed a cooperative agreement with UNIDIR to fund its training on the framework, including international law, how it applies in cyberspace, and how countries can develop national positions on this important issue. Thank you, Chair.
Ambassador Gafoor
Thank you, United States. Germany, to be followed by the UK.
Germany
Thank you, Mr. Chair. Please allow Germany to present an abbreviated version of our statement. The full statement will be online. Germany would like to commend UNIDIR for hosting the workshop on international law in November, where delegates and legal experts from a wide set of UN member states had the opportunity to engage in in-depth discussions on cyber-related scenarios that require legal solutions. Approaching the applicability of international law through such concrete scenarios or case studies and involving the relevant legal experts has provided a tangible contribution to the emerging convergence across regional groups and to fostering a culture of responsible state practice. If such scenario discussions could be used as an element of the Open-Ended Working Group’s inter-sessional meeting on international law, this might lend new dynamism to the legal deliberations in this group. Germany welcomes the concrete questions that have been shared by the Russian delegation in today’s session, which could be addressed, among others, in such future scenario discussions. It would be helpful to the work of this Open-Ended Working Group if all states advocating for a legally binding convention could share the exact situations and developments in the cyber domain, as well as the exact features of ICTs that, in their view, require new rules. This will lend more substance to the exchanges under this agenda item and help us to answer the question in how far legal gaps exist. In view of current trends, besides many others, Germany is very concerned by some of the challenges posed by ongoing international armed conflicts and their cyber dimension. Just to mention three examples. One, the involvement of civilian hackers, which play an active role on all sides of current international armed conflicts, bringing in a new level of unpredictability with regards to the selection of targets. Two, the extension of the area of armed conflict beyond the battlefield, as civilian cyber actors typically don’t engage in cyber operations from a military platform, but may do so from their private homes or from a country that is not involved in the conflict in any conventional way. This practice may potentially lead to a geographic escalation of conflict and to turning predominantly civilian sites into military targets, contributing to a dangerous blurring of lines when it comes to defining theaters of conflict. Three, the role played by private sector actors in international armed conflict. Germany has been host to an expert discussion focusing on these questions at the Internet Governance Forum in Kyoto and at the Berlin Shaping Cyber Security Conference. Germany believes that the legal challenges of cyber and armed conflict and the application of international humanitarian law in cyberspace should also keep being addressed by this Open-Ended Working Group. This would also contribute to advancing our discussion on state responsibility, as has been suggested by a number of delegations today. It is also urgent that states engage in deeper discussions on how the rules of international humanitarian law apply in cyberspace in order to mitigate the effects of cyber threats and conflict. Germany would like to recognize the pioneering role played by the International Committee of the Red Cross in developing legal solutions to these novel challenges, including with the final report of the ICRC’s Global Advisory Board on digital threats during armed conflicts. Thank you.
Ambassador Gafoor
Thank you. Germany. United Kingdom, to be followed by Malaysia.
United Kingdom
Thank you, Chair. The United Kingdom welcomes these opportunities for states to discuss how international law applies in cyberspace. It is through focused discussions on this important issue that we are able to deepen our common understanding. We are grateful for your guiding questions. You asked us to consider opportunities for the views of states to converge further. The starting point when considering your question is that all states have agreed by consensus that international law, in particular the UN Charter, applies in cyberspace. Further convergence will materialize as states continue to develop their views on precisely how international law applies. In the intersessional meeting of May 2023, the United Kingdom set out our detailed views on the law relating to the peaceful settlement of disputes, the prohibition on the threat or use of force, the law of self-defense, the rule of non-intervention, and the principle of sovereignty. In particular, we explained our understanding of what amounts to coercion for the purposes of the non-intervention rule. These rules and principles apply in cyberspace just as they apply in any other domain. There are no unique features relating to the use of ICTs that require a distinction in terms of how international law applies. International law has always existed in a technological era. The existence of technology today does not automatically require changes to existing law. We agree with the arguments put forward by Canada, Finland, Ireland, Austria, and Italy in this regard. The exercise states are engaged in, including in this OEWG, is one of interpreting the law as it applies to cyberspace. This process of interpreting and crystallizing existing international law does not make international law any less applicable. Chair, for similar reasons, the UK is unconvinced that there are any gaps in how international law applies to the use of ICTs. We would also like to highlight the value of the recent workshop convened by UNIDIR. As you heard from UNIDIR, this workshop saw a cross-regional group discuss how international law applies to cyber incident scenarios involving states. Participating states found substantial areas of agreement, not only on which specific rules applied to the scenarios, but also on how those rules applied. States were able to discuss the factors that would be considered when assessing the lawfulness of state conduct. Chair, we continue to encourage states to share their interpretations of how international law applies, and we continue to underline the importance of scheduling dedicated sessions in the OEWG and elsewhere for such focused discussions. Having witnessed firsthand how much progress can be made in our common understanding of international law when we dedicate time to discussing how international law applies in practice, we would welcome future scenario-based discussions. As you suggested in your guiding questions, expert training and education also have a critical role to play in furthering these discussions. As you heard from the examples given by Canada, Mexico, and the Netherlands in particular, multistakeholders are already making important contributions in this area. The United Kingdom continues to support such training initiatives, and, Chair, we agree with Kenya that training and advice should be provided in a neutral and impartial manner. We feel the Program of Action could present a valuable opportunity to deepen and expand the availability of expert dialogue and training on international law. Finally, Chair, we would like to join the very wide number of states who have already spoken in emphasizing the applicability of international humanitarian law and IHL’s importance to our discussions. We hope this will be recognized in the annual progress report. International humanitarian law applies to operations in cyberspace conducted in furtherance of hostilities in armed conflict, just as it does to other military operations. In this context, early reports of a cyber incident impacting Ukraine’s national telecommunications operator are concerning. As ever, we stand in support of Ukraine. Operations directed against civilian infrastructure are unacceptable in all conflicts, in addition to being inconsistent with the norms of responsible cyber behavior. Thank you, Chair.
Ambassador Gafoor
Thank you, United Kingdom. Malaysia, to be followed by Bangladesh.
Malaysia
Thank you, Chair, for giving me the floor. Malaysia reiterates the importance of a rule-based cyberspace. We acknowledge the pivotal role of international laws, including the UN Charter, in maintaining international peace and security, while fostering a culture of responsibility and accountability. My delegation reaffirms our commitment to the principles enshrined in the UN Charter, including state sovereignty, the prohibition of the threat or use of force, respect for the territorial integrity and political independence of other states, and the peaceful settlement of international disputes. We support continued discussions on the application of these principles in the cyber domain, as suggested by many states. Targeted capacity building is required to enhance Member States’ knowledge and expertise vis-Ã -vis the application of international law in cyberspace. This will allow us to leverage our cumulative experience and facilitate the active participation of the UN membership as a whole, with a view to reaching a common understanding. This approach is critical in fostering meaningful cooperation and achieving shared objectives for an open, secure, stable, accessible, and peaceful ICT environment. As noted by Brazil, the evolving global discourse in this field should feature diverse perspectives, including the states and experts from the global South. At the regional level, workshops and training programs bringing together legal, diplomatic, security, and cyber policy officials can help develop shared understandings of prevailing cybersecurity challenges and the applications of international law thereto. Further, Malaysia welcomes the proposal for additional informal international meetings for this OEWG to build on the progress made thus far and to encourage further productive exchanges in the coming years. We hope these meetings can be held in a hybrid manner to allow greater participation by capital-based delegates, particularly from developing countries. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Malaysia, for your statement. You know, I think you raised the point about hybrid meetings, and I think it’s something that we all need to reflect collectively on. The advantage of a hybrid meeting, of course, is that it’s very inclusive. It includes people from capital, and it certainly is helpful in terms of enabling countries who may be constrained by bringing legal experts to New York. On the other hand, this kind of very interactive discussion or workshop also requires human contact, discussions, and understanding. So I think this is something that we need to think about in terms of when and how we use hybrid as a possibility and when and how we need these kinds of in-person meetings. So let’s keep that question in mind, and I thank Malaysia for raising that. I don’t have a ready answer, but I think we may need to work with different options at different times as we go deeper and deeper into some of the legal issues that are coming up today. The other thing I want to point out is that I have a long list of speakers, and I’m wondering whether we can finish it today. We did begin the discussion on international law yesterday. I know it’s somewhat late, and we had to start later than expected yesterday. This afternoon, we will continue meeting after the dedicated stakeholder discussion. But I hope that we can finish the speakers on international law today. So do submit your statements in writing, and if you can present an abbreviated version, that will also be helpful. But I’m not going to clamp down on anyone or cut off the microphone because I think it’s important that at this very early stage of our cycle, which is the third cycle, we listen to each other so that we can see where there are common points emerging. On that note, I’ll give the floor to Bangladesh, to be followed by India.
Bangladesh
Thank you, Mr. Chair. Bangladesh believes that international law, and particularly the Charter of the United Nations in its entirety, international human rights law, and international humanitarian law are applicable to maintain peace, stability, and promote an open, secure, stable, accessible, and peaceful ICT environment. We reiterate that principles of international law encompass respect for sovereign equality, the settlement of international disputes by peaceful means, non-aggression, the prohibition of the threat or use of force in any manner inconsistent with the purpose of the UN Charter, respect for human rights and fundamental freedoms, as well as non-intervention and non-interference in the internal affairs of states applied in the cyber domain. Second, APR, previous Open-Ended Working Group, and GGEs recognize that a number of states are developing ICT capabilities for military purposes, and that the use of ICTs in future conflict between states is becoming more likely. This truth is further amplified by the rapid development of AI, including generative AI and emerging technologies. We believe that the Open-Ended Working Group process can expedite clarity and enhance common understanding on how international law and international humanitarian law apply to state conduct in cyberspace. It also has the potential to contribute to the development of customary international law that is applicable to the unique challenges of the cyber domain. For example, the duty of non-intervention protects a state’s internal and external affairs from coercive intervention by other states. Yet there’s no consensus on which affairs the duty protects, let alone what differentiates coercive from non-coercive cyber activity. In this regard, we are of the view that the group should leverage the expertise of all relevant bodies and stakeholders, including the International Law Commission, legal experts from the Global South, as proposed by Brazil, and on how and where international law, including IHL, applies to cyber operations. Perhaps engaging in global cyber exercises, simulating real-world scenarios to test the effectiveness of the existing legal frameworks and response protocols, could help us better understand the applicability of international law and also identify the gaps. Furthermore, creating a readily available online repository of legal resources translated into multiple languages, providing a comprehensive knowledge base for all states, could also be helpful. Mr. Chair, given the unique characteristics of the ICTs, including their borderless nature, speed and anonymity, dual-use potential, and constant evolution, we emphasize the existence of legal gaps in the applicability of international law to the cyber domain, such as the lack of clear understanding of the attribution of cyber attacks, the state responsibility threshold, the use of force in cyberspace, ambiguity of definitions, among others. Consequently, we recognize the merit of developing a dedicated international legal framework tailored to the distinct characteristics of the ICT environment. It is imperative that any such framework addressing ICT-related issues be universal, inclusive, and non-discriminatory in nature. Finally, Mr. Chair, capacity building remains critical, not only in international law but also across all pillars of the Open-Ended Working Group. And just to conclude, this statement has been prepared without the involvement of any lawyer, yet another example of the need for capacity building. Thank you.
Ambassador Gafoor
Thank you very much, Bangladesh. I think sometimes, well, maybe that’s why your statement is also very succinct. The lawyers usually get involved, and in a good way, the statement usually gets longer, because lawyers have a lot to put across, especially on this important discussion. But I think your point is well taken. And I’m also wondering, for those missions and representatives here, I mean, there is a Sixth Committee process here. There are legal counsellors. Many missions have legal counsellors. And I think it’s also time for us to ask the question, how do we get our legal counsellors in our own missions to be involved in the work of the OEWG? My own legal counsellor is not here. But I think that’s something that we can think about as well. Thank you, Bangladesh. India, to be followed by France. Thank you.
India
Mr. Chair, adherence to international law is important to prevent conflicts and maintain international peace and security. The international community recognizes that existing international law, and in particular the UN Charter in its entirety, is applicable to state conduct in cyberspace and is essential in maintaining peace and stability and promoting an open, secure, peaceful, and accessible ICT environment. These include, in particular, the principles of sovereign equality of states, non-use of force and threat of force, settlement of international disputes by peaceful means, and non-interference in internal affairs of states. This understanding is reflected in the 2013 and 2015 reports of the UNGGE and the 2021 and 2023 reports of the OEWG. Even after consensus among states that a particular international legal rule or regime applies in cyberspace, substantial interpretative questions remain muddled due to lack of capacity. The dynamic nature of cyberspace creates ambiguity in the application of international law. A state as a subject of international law can exercise its rights and obligations through its organs, and in some instances by natural and legal persons. The attribution of an internationally wrongful act, including an internationally wrongful cyber operation, requires careful assessment of whether and how malicious activity conducted by a person, a group of persons, or legal persons can be considered as the act of a state. This may involve consideration of the intended or reasonably expected direct and indirect consequences of the cyber activity, including, for example, whether the activity could reasonably be expected to cause serious or extensive damage or destruction in the form of injury or death to persons, or damage or destruction to objects or critical infrastructure. States should act reasonably while drawing conclusions based on the facts before them. A cyber activity will be attributable to a state under international law where, for example, the activity was conducted by an organ of the state, by persons or entities exercising elements of governmental authority, or by non-state actors operating under the direction or control of the state. The cyberspace regime involves non-state actors, and therefore the application of international law in cyberspace necessitates identification of who is responsible for the activity in question, which is challenging given issues of technical attribution. The question of how international law applies in cyberspace still remains a challenge, as many states lack the personnel or resources to understand the issues involved in applying international law to cyberspace. Hence, it is important to address the question of legal capacity for all states to have a voice in shaping the applicability of international law in cyberspace. States must be encouraged to utilize all opportunities to develop expertise in this field and also support countries which are in need of such capacity. Paragraph 36 of the second APR takes cognizance of this aspect. The borderless and dynamic nature of cyberspace creates gaps in understanding the application of international law to cyberspace. Further discussions are required to identify these gaps and explore means to bridge them, including through drafting new norms. As the question of how international law applies to the use of ICTs by states is concerned, this aspect is paramount in maintaining international peace and security, and it is important that the international community should continue to undertake an in-depth study of all non-consensual international legal regulation of ICTs under the auspices of the UN. In this regard, India looks forward to the conclusion of a convention on countering the use of ICT technologies for criminal purposes, which is mutually agreed upon by all UN member states, at the concluding session of the Ad Hoc Committee in January 2024. It would be useful if all member states continue to voluntarily share with the UN Secretary-General the national views and assessments on the issue of application of international law to cyberspace. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, India. France, to be followed by Japan.
France
Thank you, Mr. Chair. My delegation associates itself with the statement made by the European Union, and we would like to make the following comments in our national capacity. Preliminary, during the 75th anniversary of the Universal Declaration of Human Rights, I would like to recall the constant position of my country. The offline rights of people should be protected online as well, and international human rights also apply to cyberspace. I’m going to concentrate on three points in my statement. First, the importance of exchanges on the applicability of international law. Second, the usefulness of the opinion of experts, which was organized by UNIDIR last month. And third, the need to continue and broaden this format of discussion. First of all, my delegation would like to reiterate its commitment to international law as an essential element for the development of reports and also to maintain the stability of cyberspace. We think it’s fully applicable when it comes to ICT. The existing consensus on this point has to be maintained, and it is on this basis that the Open-Ended Working Group (OEWG) should continue its work. We wish the OEWG to allow an in-depth exchange on this topic. France encourages states to share their positions on the way international law is applied to the use of ICT by states, as was recommended by the OEWG and the most recent Group of Governmental Experts (GGE). Secondly, with this in mind, we welcome organizing at the mid of November by UNIDIR of an experts workshop. France co-sponsored this event. It brought together a broad group of participants, which came from various regional groups. The report by UNIDIR underscores, and rightly so, the existence of many areas of convergence among states. These areas of convergence include, inter alia, the recognition that international law is applicable in cyberspace, and in particular, the principles having to do with the peaceful settlement of disputes, non-interference, and the ban on the use or the threat of use of force. Within this vein, the definition of new binding rules specific to cyberspace at this stage seems to be premature. We do not notice a legal void that would require adopting such new rules. Our work should rather concentrate on the general understanding of how these principles apply in cyberspace, in particular, on the basis of specific scenarios. My third and last point has to do with the need to continue these discussions of ours, including in other formats such as the one that was proposed by UNIDIR. We hope that we will see similar workshops in the future, but also and especially that they will be broadened and widened to other participants. The importance of capacity building also needs to be underscored here. Capacity building brings in the necessary needs to develop and deepen international positions. It is under this condition that the discussions on the rules as they apply to cyberspace will continue strengthening confidence among states. I thank you.
Ambassador Gafoor
Thank you very much, France. Japan, to be followed by Vietnam.
Japan
Thank you, Mr. Chair. Japan would like to reiterate its position that existing international law, including the United Nations Charter in its entirety, applies in cyberspace. We should deepen the understanding of how existing international law applies in cyberspace, including focusing on the application in specific issues, rather than create new legally binding obligations. In this regard, Japan funded the research at Oxford University for deepening the discussion on the application of international law to cyber operations, targeting the healthcare sector as a part of our efforts. We also place great importance on a dedicated inter-sessional meeting on how international law applies in cyberspace. In addition, we welcome and appreciate UNIDIR’s efforts in convening their workshops. Mr. Chair, Japan considers that we should fight against cyberattacks to critical infrastructure, short of armed conflict, given the increase in their number. A better understanding of how international law applies in cyberspace will help these efforts. In this regard, we should be able to clarify the application and foster a common understanding that serious cyberattacks, such as those that cause physical damage or loss of control of critical infrastructure, are unacceptable under international law. Mr. Chair, Japan hopes that the announcement of a basic position on international law applicable to cyber operations by the governments of many states and the application of international law in international and domestic courts and tribunals will deepen the shared international understanding on how international law applies to cyber operations. Mr. Chair, while it is not easy to refer specifically to the capabilities that are most urgently required, it is important to deepen our discussions and to increase the number of experts in international law. In this regard, one of Japan’s efforts to support capacity building in the field of international law applicable in cyberspace is the Japan International Cooperation Agency’s training course on enhancing international law and the policy capacity to strengthen cyber security measures. Japan will continue to support the enhancement of capabilities of states to formulate a basic position and to implement existing international law for the pursuit of a free, fair, and secure cyberspace. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Japan. Vietnam, to be followed by Czechia.
Vietnam
Thank you, Mr. Chair, for giving us the floor. Our delegation highly values the opportunity to discuss how international law applies to the ICT environment. We underline the critical importance of establishing a robust framework to govern the application of generative AI technologies, which have presented massive and unprecedented risks of misinformation, disinformation, and fake news that may incite violence, hatred, xenophobia, or terrorism. The framework should provide well-balanced norms and principles to ensure that the development, use, and dissemination of AI-generated content are transparent, accountable, and ethical through appropriate safeguards and content moderation tools. Mr. Chair, our delegation welcomes the proposal put forth by some delegations regarding the development of an international legally binding instrument on ensuring international information security. We believe this proposal would contribute to the progressive development of international law and the strengthening of the international rule of law in cyberspace, so that states may discuss and agree on the international obligations and responsibilities in both the global and national cyberspace. However, we are mindful that this process depends on many factors, especially the consensus of the international community, as well as the preparedness and readiness of member states to facilitate, manage, and regulate cyberspace activities and infrastructure. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Vietnam. Czechia to be followed by China.
Czechia
Mr. Chair, thank you for giving me the floor. I am in the same situation as some of my colleagues. Our legal advisors sent me a very long statement, but due to my time, I will now answer only two out of four of your guiding questions, and I will send the rest in writing. Firstly, Czechia aligns itself with the EU statement and wishes to deliver additional comments in its national capacity. In response to your first question, the 2023 APR revealed a significant agreement among states on a number of fundamental obligations that apply to all states’ behavior in cyberspace, including non-intervention, prohibition of the use of force, and the obligation to settle disputes peacefully. While this progress is commendable, Czechia believes there are still numerous areas where further convergence can be identified regarding states’ perspectives on how international law applies in the use of ICTs. Another area of convergence emerges in the shared need to elaborate on these core obligations, aiming to enhance our collective understanding. This can be achieved by applying these agreed-upon obligations to concrete scenarios, as witnessed in workshops such as the recent one conducted by UNIDIR this November. Czechia was one of the co-sponsors of this event. This gathering, which can serve as an exemplary capacity-building exercise, led to states recognizing convergence on specific details, fostering transparency and comprehension, thereby mitigating the risk of misinterpretation or overreaction in the future. Another commendable effort was conducted by the Ministry of Foreign Affairs of Mexico, Temple University’s Institute for Law, Innovation, and Technology, and Microsoft by a series of conversations that concluded in a Compendium, published just recently. In these workshops, where international lawyers and various cybersecurity experts were brought together to discuss the role of international law in cyberspace, Czechia was honored to participate, as well as at the UNIDIR November workshop. Concerning the applicability of international humanitarian law and international human rights law to cyberspace, interventions of a large number of states, including Czechia, in various sessions this year have consistently raised these areas for consideration within this OEWG. Notably, where states have shared their views on these matters, a significant level of convergence appeared. It would therefore be useful to harness that convergence in deeper discussions on these topics. And now regarding your second question on unique features pertaining to the use of ICTs that might require a distinction in the application of international law compared to other domains, we must say there are not. The ongoing discussion revolves around interpreting existing laws in the context of this new technology, and definitely not suggesting that the technology requires the law to apply differently. Nearly all states that have addressed this issue in our discussions agree that existing international law applies as it is to states’ use of ICTs. Furthermore, viewing it from a systematic angle, taking a different approach might pose significant risk to the international legal order.
Ambassador Gafoor
Thank you very much Czechia. China to be followed by Singapore.
China
China’s delegation is not here at this moment, so we’ll do the comments later.
Ambassador Gafoor
Sure, let’s go to Singapore and then South Africa.
Singapore
Thank you, Chair. It is heartening to note the growing consensus in states’ views on how international law applies to the use of ICTs. We recall that in this OEWG, states have already reaffirmed the application of certain international law principles and rules in cyberspace. These include state sovereignty and sovereign equality, the peaceful settlement of international disputes, the prohibition of the use of force, and the principle of non-intervention. In Singapore’s view, this working group can consider if there are now further areas of convergence in the application of the law on state responsibility in the cyber context. Singapore’s position is that the law on state responsibility applies in the assessment of whether an internationally wrongful act has been committed, which entails the responsibility of a state, including by cyber means. Thus, for example, the rules of attribution under customary international law apply in the assessment of whether a cyber operation can be attributed to a state. This includes where an act was conducted by an organ of the state, by persons or entities exercising elements of governmental authority of the state, or under the direction or control of the state. Based on the interventions we have heard both yesterday and today, we believe that many states would be able to agree that at a minimum, the law on state responsibility applies to a use of ICTs which constitutes an internationally wrongful act. On the question of whether there are unique features relating to the use of ICTs requiring distinctions in how international law applies as compared to other domains, there should be in principle no difference whether in the physical realm or in the cyber realm. In every case of application of international law, the facts pertaining to that case must be ascertained. This is because this need not always be more complicated or uncertain in the cyber context than in the physical realm. Rather, it will depend on each individual case. On the question of gaps in how international law applies, we would like to emphasize at the outset that there is existing consensus based on the work of the present OEWG and its predecessor that international law applies to the use of ICTs. As the OEWG has itself been mandated to study with a view to promoting common understandings, the issue of how international law applies to states’ use of ICTs, we could prioritize this as a first and necessary step towards any efforts to identify potential gaps in common understandings. On capacity building, my delegation would like to stress the importance of capacity being built not only with respect to international legal rules and principles in and of themselves, but more crucially in developing understandings on how these rules and principles apply to concrete scenarios. One capacity building program which does just that is the International Law of Cyber Operations program that Singapore hosts at the ASEAN-Singapore Cyber Security Centre of Excellence in partnership with Australia and the Netherlands. The program promotes conversations between policymakers and international lawyers on simulated case studies and allows states to exchange and develop views leading to the further development of common understandings of how international law may apply to states’ use of ICTs. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Singapore. South Africa, and then we’ll go to China. South Africa, please.
South Africa
Chairperson, South Africa has consistently expressed its commitment to promoting a peaceful and stable cyberspace underpinned by international law, including human rights law, and consistent with the 11 norms of responsible state behavior. We believe that it can be seen as a convergence that the United Nations Charter applies in its entirety to cyberspace, and that the principles of the UN Charter apply to cyberspace, such as sovereign equality, the settlement of international disputes by peaceful means, respect for human rights and fundamental freedoms, and non-intervention in the internal affairs of other states. Chairperson, when discussing this matter, we should consider that a cyber operation may, depending on its scale and effects, violate the prohibition on the threat or use of force in Article 2.4 of the UN Charter. When a cyber operation constitutes an armed attack under Article 51 of the UN Charter, states may exercise their inherent right of individual or collective self-defense recognized in the Charter, while customary international law principles of necessity and proportionality remain applicable. Furthermore, the cyber operation could be deemed an internationally wrongful act when it is attributable to a state under international law and involves a breach of an international obligation of the state. Therefore, states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. If a state is notified of harmful activity emanating from its territory, it must take reasonable steps to address such activity. If a situation amounts to an armed conflict and cyber operations are carried out during that conflict, international humanitarian law applies to these cyber operations as it does to all operations with a nexus to an armed conflict in general. Next is our understanding that IHL prohibits the use of cyberspace to attack civilian infrastructure, for example. During war and peacetime, states are required to take all feasible precautions to protect civilians and civilian objects. Chairperson, with this understanding in mind, we should encourage states to forge closer cooperation in developing and applying measures to increase security in the use of ICTs and to avoid ICT practices that could endanger the maintenance of international peace and security. South Africa believes that we should develop a common understanding of the applicability of international law, including international humanitarian law, in cyberspace based on existing legal frameworks. Identifying any gaps in these frameworks would thus emerge from these discussions and understandings. We believe that capacity building should be the result of deepening understanding among experts and not necessarily a transfer of knowledge based on one side’s perspective. I thank you.
Ambassador Gafoor
Thank you, South Africa. China, to be followed by Australia.
China
Thank you, Mr. Chair. The OEWG and other processes have reached a consensus in terms of the application of international law, especially the UN Charter and the principles of sovereign equality, prohibition of the use of force, peaceful settlement of disputes, and non-interference in internal affairs, which are applicable in cyberspace. This is the cornerstone for ensuring a fair and reasonable international order for cyberspace. China supports prioritizing the study on how to implement the principle of sovereign equality. Respecting sovereignty in cyberspace is the manifestation of respect for the purpose and principles of the UN Charter and is the foundation and precondition for safeguarding peace, security, and stability in cyberspace. Specifically, the following should be included, or can be included. States should exercise jurisdiction over the ICT infrastructure, resources, data, as well as ICT-related activities within their territories. They have the rights to protect their information systems and important data from damages resulting from threats, interference, attacks, and sabotage. States have the right to make ICT-related public policies, laws, and regulations to protect the legitimate interests of their citizens, enterprises, and social organizations in cyberspace. States should refrain from using ICTs to interfere in the internal affairs of other states and undermine the political, economic, and social stabilities of other countries, or to conduct activities that undermine other states’ national security and public interest. States should participate in the management and distribution of international internet resources on an equal footing and build a multilateral, democratic, and transparent global internet governance system. Secondly, in terms of the application of other international laws, China’s well-known position has been consistent. China will not support any elements that will not be conducive to international peace and stability in cyberspace. In addition, I want to add that cyberspace is very closely connected with the physical world. However, cyberspace has its unique features. Otherwise, there is no need for us to have this discussion. Russia proposed the International Convention on International Information Security. The draft version provides a solid basis for our discussion, and parties should start from protecting international peace and stability and focus the discussion based on the unique nature of cyberspace as well as the future and development of ICT on developing new laws. Lastly, as one of the hosts, China congratulates UNIDIR for organizing the workshop in November, and we hope that UNIDIR can continue to organize workshops on how to make detailed recommendations about the application of the UN Charter in cyberspace. Hopefully, the future workshops can be well-designed so as to contribute to safeguarding peace and stability in cyberspace. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, China. Australia, please.
Australia
Thank you, Chair. In the past two years since this group has been convened, Australia is delighted to see how much progress and how much this OEWG has successfully achieved on its mandate on international law. The application of international law in cyberspace is not itself sensitive or difficult; it is core to our mandate and our work. While sometimes our discussions on how international law applies can be complex, we consider that this is a reflection of how important these discussions are. The success of this group’s deliberations is reflected in our 2023 second annual progress report, in particular, which contains significant granularity on obligations that states have in cyberspace. You’ve asked us now, Chair, to consider whether there are further convergences that can be identified. Australia has quite carefully studied the statements made in this group and elsewhere, and we consider that there are a number of other areas in which convergences are appearing. In particular, having now set out in detail the obligations from the UN Charter and other principles of international law that govern state conduct in cyberspace, we have listened to states that wish to come to a common understanding on what happens if a state does not comply with those obligations. For Australia, we understand the question of consequences through the law of state responsibility, and like many who have spoken before me, we would like to see if this could be an area of further convergence amongst us. The law of state responsibility provides a state with means to seek redress for an internationally wrongful act if it legally attributes that conduct to another state and the elements of the alleged wrongful act are made out. That redress can be to seek reparations, for example, through submitting a dispute to a court or tribunal or to take countermeasures where appropriate and subject to particular limitations. The decision to attribute conduct or take countermeasures is a sovereign decision, and it must be a decision that is made very carefully. If a state mistakenly attributes conduct and then takes countermeasures on that basis, its mistake does not absolve that state of responsibility. Instead, the state taking the purported countermeasure will have committed an internationally wrongful act itself. In July, many states called for the discussion of international humanitarian law. This was also echoed this week by Mr. Ebo, the Director and Deputy to the High Representative of Disarmament Affairs, in his opening remarks on Monday, recommending enhanced pursuit of work on international humanitarian law’s application to cyberspace. Australia agrees with many others who’ve spoken this morning and yesterday and in our earlier sessions that, in line with the 2021 GGE report, international humanitarian law, including the principles of distinction, necessity, proportionality, and humanity, apply in cyberspace in situations of armed conflict. The argument that exploring this topic in more depth militarizes cyberspace fundamentally misinterprets the purpose of international humanitarian law, which is to impose limits on warfare. I’m not the first to come up with this analogy, but I will repeat it: applying IHL in cyberspace is like having a speed limit on a highway. The speed limits protect pedestrians and drivers alike. International humanitarian law protects civilians and civilian objects in armed conflict. To say IHL militarizes cyberspace is like saying that speed limits encourage speeding. International human rights law is another topic worthy of our discussion. In particular, the right to privacy, freedom of expression, the right to non-discrimination, and freedom of association are all relevant rights and freedoms states owe to individuals under their jurisdiction when those rights are exercised or realized through cyberspace. When it comes to capacity building, we strongly support the recommendations of the 2021 OEWG and GGE reports to build the capacity of all states to contribute to building common understandings on how international law applies to state conduct in cyberspace. We commend an example of capacity building in the two courses run by Cyber Law International on how international law and how international human rights law apply in cyberspace. As part of our capacity building efforts, Australia has funded these programs for countries in the Indo-Pacific. You also asked, Chair, about specific capacity building efforts to assist countries to develop their own national positions on the application of international law in cyberspace. An example, in addition to the example that was just given by Singapore, which we very much support: Australia’s government lawyers were very jealous of the Cyber Law International programs that we were providing across the Indo-Pacific, so we tailored a one-off Cyber Law International course for our own government lawyers to come together with academics and experts to try to add some additional detail to Australia’s position papers. The result of this was our input into the 2021 GGE international law annex. I also wanted to thank you for providing space yesterday for a briefing on the recent UNIDIR workshop on international law and the behavior of states and use of ICTs. This indicated there were a number of convergent national views on how existing international law applies across a diverse and quite cross-regional group of participants. We commend UNIDIR for this workshop, and we welcome the announcement of further workshops. We think that these build capacity and provide a unique opportunity for states to consider the practical application of existing law together. In July this year, Australia, Uruguay, and the Philippines co-hosted a similar side event which enabled legal and policy delegates to consider international law as a toolkit and apply the law to hypothetical scenarios. The discussion during all these types of scenario-based workshops demonstrates that existing international law provides the tools that states need to address unlawful cyber activities and provide another avenue to build the capacity to understand and develop national positions on how existing international law applies. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Australia. Syrian Arab Republic.
Syria
Thank you, Mr. President. On international law, we would like to make the following points. The OEWG discussions have highlighted persistent divergent views on the automatic and comprehensive application of international law in its entirety on cyberspace. They have also shown that the unique features of ICT technology should be taken into account. Cyberspace differs from the physical world. As such, the application of the precepts of international law on ICT issues requires legally binding frameworks that respect the privacy of cyberspace and institute a comprehensive and inclusive global approach. For example, there are serious questions about the concept of legitimate self-defense and about attribution in the bilateral aspects. In our opinion, there aren’t clear criteria on the practical application of these concepts in cyberspace. There is no universal and comprehensive approach either. This, as a result, leads to unilateral interpretations that could backfire and undermine international peace and stability. We are against non-consensual language adopted by GGE reports because the groups of global experts are of limited composition. Further discussions should be undertaken also as part of the group in order to build a common understanding leading to a legally binding instrument. A UN Convention on International Information Security, as put forward by Russia and other like-minded countries, serves as a good basis. There should not be an exaggerated focus on the application of international law and on the importance of the standard framework for responsible behavior in ensuring international information security, as this is not fully consistent with the OEWG mandate. All initiatives should be considered, and the OEWG mandate should be approached in a balanced and equal manner to guarantee inclusivity and complementarity and to address the concerns and interests of all states. Thank you, Mr. President.
Ambassador Gafoor
Thank you very much, Syrian Arab Republic. It’s almost one. I have five speakers left, including two stakeholders, ICRC and the Organization of American States. So I propose that we resume this afternoon. And just to remind, at 3 p.m. is the dedicated stakeholder session, which is part of the modalities of this working group. So 3 to 6 p.m. is the session today, but we’ll start with the stakeholders. And I would urge all delegations to be present for the session with stakeholders, because it’s important that we also listen to what they have to contribute. And then after we finish the list of speakers who are registered for the stakeholders, I think there are about 15 speakers who have registered from the stakeholder community. After that, we’ll continue with the discussions on international law. And hopefully, we can also begin the discussions on CBMs later this afternoon. So I wish you a pleasant lunch and see you back here at 3 p.m. Thank you.
Leave a Reply