On 21 July 2026, the European Union and its Member States presented an initial overview of their efforts to implement the 11 voluntary, non-binding norms of responsible state behaviour in cyberspace during the first substantive session of the UN Global Mechanism on ICTs in international security, held in New York from 20 to 24 July 2026. The EU statement, delivered on behalf of the bloc and aligned candidate countries, detailed the legislation, policies, structures and mechanisms the EU has put in place to give effect to each norm, using the consensus guidance from the 2021 UN Group of Governmental Experts report.

The EU reaffirmed its commitment to the UN framework of responsible state behaviour in cyberspace, emphasising that the 11 norms, first agreed in 2015 and reaffirmed by subsequent Open-ended Working Groups, are central to maintaining international security and stability. The statement noted that adherence to the norms reduces the risk of misperception and escalation, strengthens trust among states, and supports the secure functioning of critical infrastructures and digital services.

As an example, the EU elaborated on its implementation of Norm 13(b), which concerns consideration of all relevant information in the event of ICT incidents. The EU listed the key actors contributing to shared situational awareness: EU member states and their national agencies, the European Commission, the European External Action Service (including its Single Intelligence and Analysis Capacity), the EU Agency for Cybersecurity (ENISA), CERT-EU, and Europol's European Cybercrime Centre (EC3). Under the NIS2 framework, member states and EU actors cooperate at strategic, operational and technical levels through structures such as the NIS Cooperation Group, the CSIRTs Network, and EU-CyCLONe. Based on shared situational awareness, the EU can decide on diplomatic measures under its Cyber Diplomacy Toolbox, including attribution, with responses proportionate to the scope, scale, duration, intensity, complexity, sophistication and impact of the cyber activity.

The EU contribution complements the 2024 Declaration by the EU and Member States on the application of international law in cyberspace, which outlines the common understanding on international law applicable to cyberspace. The EU stressed that voluntary norms sit alongside binding international law, which prohibits, for example, the use of ICTs to interfere coercively in the internal or external affairs of other states. The EU encouraged other states to share their experiences in implementing the norms and highlighted the draft Voluntary Norms Checklist as a valuable living document to facilitate discussions in dedicated thematic groups (DTGs). The EU aims to further detail its efforts, including by providing more insights into individual member states' national implementation, particularly in capacity building and assistance in mitigation and recovery after malicious ICT activity.

← Atlas › News › Foreign affairs