Note 73: The Multi-Stakeholder Mirage – How the Multi-Stakeholder Model Turned Presence into Mandate
Written by Lu Heng
|
Jul 01, 2026
CEO of LARUS Limited and founder of the LARUS Foundation, he works at the intersection of Internet infrastructure, the IP address market, and global Internet governance, drawing on direct experience across all five Regional Internet Registries. These notes seek to clarify the governance of digital resources and promote a more accountable and resilient framework for critical intellectual-property assets.
The multi-stakeholder model was born as a compromise, not a constitution. It gave the Internet a way to avoid state monopoly, corporate monopoly, and intergovernmental bureaucracy at the same time. It allowed governments, companies, engineers, civil society, academics, registries, and users to appear within a single political representation.
That representation was useful because it was vague. It seemed broader than private control, safer than government domination, more open than bureaucracy, and more democratic than technical administration. But it concealed the only question that mattered. Who, exactly, had the power to authorize binding decisions?
That is the multi-stakeholder mirage. The stakeholders are real; the mandate is not. A stakeholder is affected by a decision, while a principal authorizes that decision. A model unable to distinguish these categories does not solve the problem of legitimacy. It makes legitimacy appear where no authorization exists.
This is not an argument against participation. Participation can provide evidence, expertise, warning, objection, and technical discipline. It becomes dangerous when it is converted into authority over absent parties. Those affected may speak, but they do not thereby acquire the right to bind the party that bears the loss.
The three borrowed sources
The model survives because it borrows from three histories and treats them as one constitutional source. It borrows the prestige of the IETF, ICANN's institutional settlement, and the diplomatic vocabulary of SMSI. Each of these sources is real. None provides the mandate now claimed in its name.
The IETF tradition was a discipline of technical work, not a theory of political representation. RFC 7282 explains rough consensus in opposition to kings, presidents, and voting, and treats implementation experience as a way to test abstract decisions. This is an engineering discipline. It is not authorization for an assembly to govern assets, capital markets, national infrastructure, or operator continuity.
ICANN solved a different problem. The 1998 White Paper moved toward stability, competition, bottom-up private coordination, and representation as part of the DNS transition. That compromise helped prevent states from directly operating essential Internet coordination functions. It did not create a global electorate, a demos of users, or a general public mandate over the Internet.
SMSI supplied the broadest political vocabulary. The Tunis Agenda placed governments, the private sector, civil society, and technical actors within a common Internet governance framework. But it also specified that the FGI would be non-binding, have no oversight function, and have no involvement in the day-to-day or technical operation of the Internet. A microphone was not sovereign power.
The modern model merged these histories into a single narrative of legitimacy. When it needed technical prestige, it invoked rough consensus. When it needed global legitimacy, it invoked SMSI. When it needed protection from governments, it invoked private coordination. When asked about its mandate, it invoked “the community.”
The strongest defense
The strongest defense of the multi-stakeholder model is that it helped prevent intergovernmental capture. That defense carries weight. A government-led or treaty-based system of Internet control might have been slower, more favorable to censorship, and more vulnerable to geopolitical bargaining. The NTIA made support for the multi-stakeholder model a condition of the IANA stewardship transition and stated that it would not accept a government-led or intergovernmental-organization replacement.
This historical defense must be acknowledged, not dismissed. The Internet did need a way to avoid becoming a treaty-based bureaucracy or the instrument of a single state. Private-sector coordination, technical autonomy, and open participation helped preserve speed and flexibility at a crucial stage. The model was not useless at birth.
But avoiding one failure does not justify creating another. The danger of government monopoly does not legalize an undefined community mandate. The risk of treaty control does not make private authority exercised over a choke point accountable. Participation is better than a closed bureaucracy, but it is not equivalent to authorization.
The true lesson is narrower. The Internet's initial settlement avoided direct intergovernmental capture, but it imposed no strict limits on the private control points that replaced it. It confused “non-governmental” with “legitimate.” It confused “open participation” with “legal representation.” It confused “community input” with “authority of the principal.”
The arithmetic of the room
The numbers are not merely weak. They are unsuited to the constitutional work assigned to them. The UIT estimates that about six billion people will be connected in 2025, while 2,2 billion will remain offline. Claims to represent users must be judged at that scale.
ICANN's At-Large Advisory Committee has fifteen members and is described in the ICANN Bylaws as the primary organizational home within ICANN for individual Internet users. Fifteen people can advise the organization on user interests. They can conduct outreach, submit comments, and identify user concerns. They cannot represent six billion users.
ICANN's corporate structure is more honest than the rhetoric surrounding it. ICANN has sixteen voting directors, and its legal architecture does not function as a membership-based global democracy. The ICANN Bylaws state that ICANN shall not have members and that the Empowered Community is not a member of ICANN. This may be functional corporate governance. It is not popular sovereignty.
ICANN85 makes the participation gap visible. The official report states that ICANN85 brought together 2 195 participants, including 1 517 in person and 678 remotely, and says that ICANN Public Meetings are a central pillar of ICANN's multi-stakeholder model. The same report records average in-person attendance of 47 people per session, based on counts taken midway through sessions. A room of 47 people can be useful. It does not constitute a mandate.
The compression ratio is absurd if treated as representation. Fifteen ALAC members are presented as the representative layer for users. Sixteen voting directors make up the Board. Forty-seven people can become the average physical audience for a session. The multi-stakeholder model turns a mismatch of scale into moral vocabulary.
The permanent-forum problem
The FGI shows the same distinction at the global level. It can bring together governments, companies, engineers, civil society, and academics. It can surface issues, broaden access, and build capacity. It can be useful precisely because it is a forum.
Recent FGI statistics show that a substantial discussion layer exists. In 2024, the Riyadh FGI recorded more than 10 143 participants in total, including 7 343 onsite and more than 2 800 online. In 2025, the Lillestrøm meeting recorded more than 9 435 participants in total, including 3 435 onsite and more than 6 000 online. These are large meetings. They still do not constitute a demos.
The SMSI+20 process made this forum permanent. The FGI states that the United Nations General Assembly confirmed it as a permanent United Nations forum under resolution 80/173, and that the 2026 FGI will be the first meeting following that decision. This development matters institutionally. It does not solve the problem of the execution layer.
A permanent forum remains a forum. It can make dialogue durable, but it does not create portability, fallback mechanisms, symmetry of responsibility, or operator authorization. Governments may feel included because they have a permanent microphone. But a microphone is not a lever.
That is the SMSI+20 alibi. The discussion layer becomes permanent while the operational layer remains elsewhere. Names, numbers, registry records, RPKI, reverse DNS, transfer compatibility, and continuity mechanisms remain in private or quasi-private structures. Governments get a forum. Administrators keep the switch.
The missing ledger
The strongest evidence lies not only in what the data show. It also lies in what they cannot show. A model that constantly invokes openness should be able to produce comparable long-term data on attendance, voting, remote participation, mailing-list activity, and participation in decisions. Much of the system cannot do so.
ICANN produces relatively clear meeting statistics. APNIC60 also provides a useful snapshot: 451 in-person participants, 60 online-only participants, 40 economies represented, 127 APNIC member organizations represented, and three policy proposals reaching consensus. These are useful operational data. They do not constitute regional authorization.
Across the RIR system, public data are less standardized. Some sources provide totals for the whole meeting week rather than the policy forum alone. Some provide participant lists that are only lower bounds. Some combine multiple events, obscure remote participation, or fail to publish the denominator needed to assess representativeness.
This strengthens the critique. If legitimacy rests on open participation, that participation must be auditable. When the table says “not specified,” the claim to representation should weaken, not strengthen. A model of legitimacy unable to show its denominator should not be treated as a constitutional model.
Votes without mandate
A formal vote is better than vague consensus. It creates a clearer internal act and a more readily auditable record. But voting still does not automatically turn a stakeholder process into a structure of principals. A vote can authorize what the voting body legally has power to decide; it cannot authorize everything later described as community policy.
The RIPE NCC illustrates this limit. Turnout at its May 2025 General Meeting fell to 5,3 %, with 1 039 effective votes out of 19 713 eligible members, according to the RIPE NCC's own post-election analysis. Those votes count within the association. They do not become a public mandate over the economic fate of digital resources.
ARIN's figures look stronger, but they raise another problem. ARIN's 2023 election page reported 959 votes from 6 197 eligible organizations. ARIN's official 2024 page reports 862 votes and a turnout rate of 43,91 % in one section, while its Voter Statistics section says that 959 General Members voted out of 1 963 eligible organizations. This inconsistency must be reported, not smoothed over.
The argument is not that RIPE or ARIN has no internal legitimacy. The issue is scope. Voting within an association can authorize that association's decisions. It does not turn a registry into a public-law governor responsible for scarce resources, operator continuity, or national-infrastructure risks.
Lists are not legislatures
Mailing lists remain useful. They preserve objections, reduce travel costs, and enable asynchronous technical discussion. They are often preferable to physical meetings because they leave an archive. But they are not legislatures.
The APNIC Policy SIG charter covers policies for managing number resources and related services, including allocation, recovery, transfer, WHOIS, reverse DNS, and RPKI. Its public activity pages are useful as snapshots, not constitutional proof. Even where list data exist, they show a channel for participation. They do not demonstrate regional consent.
RIPE's published history of mailing lists is more nuanced. It shows that RIPE mailing lists remain embedded in the community's working infrastructure, while their level of activity has changed with issue cycles such as IPv4 exhaustion and transfer disputes. This is useful sociological evidence. It does not turn list activity into legal representation.
The deeper problem lies in the confusion of roles. The RIR system mixes company representatives, database contacts, technical contacts, consultants, staff members, proxies, policy participants, and regular speakers. Only some can legally bind a principal, and only within the limits of their authority. A database contact is not a corporate agent holding power of attorney.
The operator disappeared
The missing principal is the operator. The operator signs customer contracts, deploys routers, pays for transit, announces prefixes, maintains abuse-handling services, responds to regulators, and bears availability obligations. When a registry policy delays a transfer, compromises RPKI, reduces an asset's value, or creates registry uncertainty, the operator bears the cost.
The multi-stakeholder model treats the operator as one voice among many. That may be tolerable for limited technical advice. It is not tolerable when the issue concerns revocation, transferability, leasing, capital value, customer geography, security assertions, or the continuity of running networks. These questions affect the operator's balance sheet and customers.
This is where Lu Heng's broader argument becomes fully important. The operator is the central actor in Running-Code Primacy because running networks are not merely symbolic participants in a room. They are the system the registry layer was originally meant to serve. The operator also explains why LARUS treats IPv4 not as a moral token but as operational infrastructure.
Civil society can raise legitimate concerns. Governments can regulate under public law. Engineers can identify genuine technical invariants. Consultants can explain market dynamics. None of them thereby becomes the operator. A policy room can advise, warn, criticize, and provide evidence to operators. It cannot replace them.
When identifiers became capital
The old registry model was designed for a low-value world. Number resources seemed abundant, administrative, and largely uncontested. An informal community process seemed sufficient because the coordinated object resembled an address book. That premise no longer holds.
IPv4 scarcity transformed that object. Number resources became scarce, leased, transferred, financed, disputed, and embedded in operations. Database registration began to affect capital value, transferability, customer continuity, routing credibility, and security assertions. An administrative entry became a gateway to economic use.
This development is explored in the notes on registry power and accountability, number resources as non-political assets, and thick governance as double extraction. The point is not simply that IPv4 has a price. It is that an administrative registration now sits above capital, continuity, and operator trust.
This change should have reduced registry authority. Instead, the language expanded. Stewardship became control over scarcity. The community became a claimed principal. The region became political property. Need became a mechanism for allocating capital.
That is the economic failure of the multi-stakeholder model. It retained the legitimacy language of an advisory technical world after the governed object became asset-like infrastructure. A model designed for discussion cannot govern capital without authorization from the principal, accountability, and the ability to exit.
The capital discount
Economics matters because prices reveal power. A choke point need not formally own an asset to extract value from it. It only needs to create dependence. If a holder cannot leave, registry control over records becomes leverage.
Costs are visible and invisible. Visible costs include fees, documentation requirements, compliance work, and delays. Invisible costs include reduced liquidity, weakened collateral value, uncertainty around leasing, transfer friction, legal risk, and the possibility that registry discretion may impair assets without bearing a proportional loss. Invisible costs are often greater because they are embedded in prices as uncertainty.
When an input becomes capital, its governance must change. The system needs clearly defined rights, low transaction costs, predictable registration, reliable transfers, dispute isolation, and symmetry of responsibility. If these elements are absent, the asset is discounted. Operators, customers, and regions bear that discount.
That is why the multi-stakeholder mirage is not only a legitimacy problem. It is a cost-of-capital problem. It delays transactions while invoking stewardship. It reduces liquidity while invoking equality. It destroys price discovery while invoking the public interest.
The poverty argument
Restrictions are often defended in the name of poor regions and small networks. The argument says that transfer limits, needs tests, and leasing restrictions protect weaker actors from market extraction. It sounds moral. It is economically contrary to reality.
Scarcity controls do not create more IPv4. They create illiquidity, raise transaction costs, reduce collateral value, discourage the arrival of new resources, and reward insiders who know how to navigate procedures. Wealthy networks can hire lawyers, structure operations to work around restrictions, and survive delays. Poor networks cannot.
This is the logic of The Poverty Penalty. Poor networks need access, liquidity, financing, transparent transfer records, and low transaction costs. They do not need an institutional gatekeeper using moral language while preserving its discretion. A price can be compared, budgeted, and financed. Discretion cannot.
A bad market can harm the poor. A discretionary anti-market regime can harm them more. It gives them fewer exit options, less information, and greater dependence on institutional favor. That is not equality; it is a penalty imposed on poverty.
The user as a ghost
The end user is constantly invoked and almost never represented. Most users do not know these meetings exist, do not vote in them, do not authorize the speakers, and do not understand transfer policies, registry contracts, RPKI, or address scarcity. They experience the results. The service works or fails. Access becomes cheaper or more expensive. Networks remain reachable or cease to be.
That makes the user politically useful. Every institution can claim to speak for the user because the user is absent from the chain of authorization. Boards, registries, companies, governments, and civil-society groups can all insert the user into their own narrative. The user becomes a ghost that legitimizes institutional speech.
The real test is not who says the word “user.” It is whether the rule lowers the cost of access, improves reliability, preserves security, increases portability, reduces dependence, and protects the networks on which users rely. Outcomes matter more than invocations. A model that invokes users without allowing them to authorize anything is not representative; it is symbolic.
This is also why a reality layer is necessary. BTW.Media and the note on why BTW.Media exists are useful here because the first task is not to produce activist language. It is to make the hidden institutional structure visible so that users, operators, governments, and markets can understand what is being done in their name.
The technical alibi
The technical community's original legitimacy came from competence and restraint. It solved problems of protocols, naming, numbering, routing, security, and interoperability. It persuaded because operators could test the results. Its authority was practical, not sovereign.
The multi-stakeholder model borrowed that legitimacy. It retained the language of consensus while weakening the discipline of running code. A rule could become binding not because operators had voluntarily adopted it, but because registry records, contracts, transfer recognition, or security assertions made noncompliance costly.
This is the Running-Code Betrayal. Running code once disciplined consensus. Consensus then justified the multi-stakeholder model. The model then claimed the power to override running code. The child claimed power over its parent.
Technical experts must remain central to technical questions. They must define invariants, expose implementation risks, and test deployment reality. They must not be turned into a substitute demos for asset governance. Technical competence is not a blank check authorizing the enforcement of institutional rules.
The corporate layer tells the truth
Corporate law often speaks more honestly than governance rhetoric. ICANN has a Board, Bylaws, advisory structures, and accountability mechanisms. It does not have members in the ordinary corporate-law sense, and the Empowered Community is not a member of the corporation. This is a legal architecture, not a global electorate.
The same clarity should be applied to the RIR world. A registry can be a useful record keeper. A membership association can make internal decisions. A policy community can offer advice. None of those facts creates sovereign authority over number resources.
The danger comes from combining legal modesty with rhetorical grandeur. The institution acts through boards, staff, contracts, and policies. When challenged, it invokes the community, the region, and multi-stakeholder legitimacy. Enforceable power travels through a cloud of diffuse legitimacy.
That is the mirage in legal form. Everyone is invoked upstream. A small institution acts downstream. The principal's place remains empty.
The state's bad bargain
Governments accepted the multi-stakeholder compromise because the alternatives seemed worse. A treaty-governed Internet might have been slower, more favorable to censorship, and more fragmented. An Internet dominated by a single state was politically unacceptable. Private coordination seemed the least dangerous path.
But governments retained the adverse public consequences. They remain responsible for economic disruption, security exposure, communications risks, and political pressure when essential coordination systems fail. Yet the main operational levers remain embedded in private or quasi-private structures: numbering, naming, registry records, RPKI, reverse DNS, transfer compatibility, and continuity mechanisms.
This is the Sovereignty Inversion. The state bears public responsibility while the private administrator holds the operational lever. The multi-stakeholder room then supplies the language that makes this inversion appear consensual. A government gets a microphone while the gatekeeper keeps the switch.
The answer is not to hand control to governments. States can censor, fragment, and politicize infrastructure. But rejecting state monopoly does not validate private sovereignty over choke points. The right answer is thinner common layers, portability, auditability, accountability, fallback mechanisms, and replaceable administration.
The stress test
Recent RIR crises should be treated as stress tests, not as the center of the argument. Their value is diagnostic. They show what happens when registry discretion collides with resources embedded in operations, ordinary courts, the absence of portability, and system-wide efforts to preserve institutional independence. The lesson is structural, not personal.
BTW.Media's public coverage of the AFRINIC/Cloud Innovation dispute is useful in this limited sense: not as the center of this article, but as evidence of how registry theory behaves when it meets running assets, courts, governance failure, and system-wide defensiveness. The broader conceptual argument is developed in The Stability Fallacy and The Registry Continuity Fallacy. The point is not that one registry crisis explains everything. It is that stress reveals what ordinary rituals conceal.
If a registry claims broad discretion over high-value resources while there is no binding portability, no clear fallback mechanism, no proportional liability, and no precise theory of representation, the conflict will not remain administrative. It will become existential. The registry sits at the intersection of law, markets, routing, security, and customer continuity. A small institution can therefore create a large blast radius.
The essential distinction is between continuity of the data registry and continuity of the gatekeeper. Registry continuity requires accurate records, RDAP or WHOIS, reverse DNS, RPKI, transfer history, dispute metadata, and operational continuity. It does not require institutional immortality. Protect the data registry, not the throne.
The transition layers
The answer cannot stop at criticism. A defective institutional order may still support real operational dependencies. That is why transition must be staged: first visibility, then continuity, then coordinated protection, and only afterward a lighter post-RIR architecture. Romantic rupture is not architecture.
BTW.Media belongs to the visibility layer. It makes registry risk understandable beyond the small procedural class that usually controls the vocabulary. A reality layer is necessary because a mirage survives only while the public cannot see the mechanisms.
LARUS belongs to the continuity layer. Its relevance is not simply that it is another market actor, but that it treats IP resources as operational-continuity assets rather than administrative residue. LARUS One extends this idea to network identity: the delivery provider may change, but the network's public identity should not have to be interrupted. The corresponding note, On LARUS One, states the economic argument directly.
i.LEASE belongs to the execution layer. Traditional brokerage treats registry risk as a documentation issue. The note on why i.LEASE exists treats brokerage as execution under registry-level uncertainty. That is the right frame once IPv4 is capital and registry discretion can become transaction risk.
NRS belongs to the coordinated-protection layer. Its purpose is not to create a new sovereign above operators. It is to give resource holders a way to resist registry risk collectively rather than remain isolated targets. The note on why NRS exists presents decentralization as systems engineering, not ideology.
The demotion
The solution is not to abolish participation. It is to demote it. Participation should be evidence, not authority. Consensus should be a technical judgment, not sovereignty. Community should be a description, not a principal.
The common layer should contain only what must be common: uniqueness, proof of control, registry accuracy, reachability, transfer records, security assertions, dispute metadata, auditability, portability, fallback mechanisms, and replacement paths. Everything else should remain closer to the operator, contract, market, or public law. Commercial use, leasing, customer geography, financing, routing practices, and the business model should not, by default, belong to a mandatory regional policy layer.
This is the logic of Minimal Initial Specification, Local Future Decisions, and Voluntary Adoption. It is also the logic of the Uniqueness Coordination Bill of Rights. The registry can record. It can coordinate. It can protect uniqueness. It cannot govern.
The test is severe. What stops working in the operational Internet if this rule is not centralized? If the answer does not concern uniqueness, interoperability, registry accuracy, security integrity, or operational continuity, the rule is not coordination. It is power.
Final judgment
The multi-stakeholder model was useful as a language of transition. It helped resist crude state capture, broadened access, and preserved a measure of technical autonomy. But that transitional language became a constitutional illusion when it claimed to represent everyone without representing anyone as a principal. The numbers now make that failure visible.
Fifteen ALAC members become the organizational home of billions of individual users. Forty-seven people become the average in-person audience for an ICANN85 session. One hundred twenty-seven APNIC member organizations become a regional policy event. A 5,3 % turnout at a RIPE General Meeting is a fact of internal governance, not a public mandate.
The SMSI+20 process did not correct this defect. It made the forum permanent while leaving the execution layer unreformed. Governments gained a permanent forum, but not portability, fallback mechanisms, symmetry of responsibility, or control over private choke points that affect national infrastructure.
None of this is problematic if these elements are treated as advice, procedure, or administration. All of it becomes absurd if treated as a mandate. The Internet should stop asking only who was in the room. It should ask who can bind the party that bears the loss.
Let stakeholders speak, let engineers define technical invariants, let operators decide what they operate, let states apply public law, let markets price scarce assets, let courts decide disputes, and let registries record. But do not let a process claim that it embodies the people. Do not let a policy room become a legislature. Do not let a database become a throne.
That is the lie of the multi-stakeholder model. Not that the stakeholders did not exist. They did. The lie was that their existence created the mandate of a single administrator.
Publication source notes






