The European Union and its Member States have presented an initial overview of their efforts to implement the 11 voluntary, non-binding norms of responsible State behaviour in cyberspace, during the first substantive session of the UN Global Mechanism on ICTs in international security, held in New York from 20 to 24 July 2026. The overview, delivered on 21 July, details the EU's legislation, policies, structures and mechanisms aligned with the norms, which were first agreed in 2015 by a UN group of governmental experts and later reaffirmed by subsequent Open-ended Working Groups. The EU contribution is intended to support actionable work by UN Member States on norm implementation under the Global Mechanism.
The EU statement, delivered on behalf of the bloc and its Member States, reaffirms commitment to the UN framework of responsible State behaviour in cyberspace, emphasising that adherence to the norms reduces the risk of misperception and escalation, strengthens trust among States, and supports the secure functioning of critical infrastructures. The EU elaborated on each norm using the consensus guidance from the 2021 UN Group of Governmental Experts report. For example, regarding Norm 13(b) – which calls on States to consider all relevant information in case of ICT incidents – the EU outlined its shared situational awareness mechanisms involving Member States, the European Commission, the European External Action Service (including its Single Intelligence and Analysis Capacity), the EU Agency for Cybersecurity (ENISA), CERT-EU, and Europol's European Cybercrime Centre (EC3). Under the NIS2 Directive, cooperation structures such as the NIS cooperation group, the CSIRTs Network and EU-CyCLONe facilitate comprehensive assessment of cyber incidents, and the EU can decide on diplomatic measures under its Cyber Diplomacy Toolbox, including attribution, based on shared situational awareness and proportionality.
The EU contribution complements the 2024 Declaration by the EU and Member States on the application of international law in cyberspace, which outlines the common understanding on binding international law applicable to cyberspace. The EU stressed that voluntary norms sit alongside international law, which prohibits, for instance, the use of ICTs to interfere coercively in the internal or external affairs of other States. The EU encouraged other States to share their experiences in implementing the norms, and expressed support for the draft Voluntary Norms Checklist as a living document to facilitate discussions in dedicated thematic groups (DTGs). The EU aims to further detail its efforts, including by providing more insights into individual Member States' national implementation, particularly in capacity building and assistance in mitigation and recovery after malicious ICT activity.