- 部落格專區
- Building Internet Trust in the AI Era: Internet Week 2026 Governance Insights from DNS, IP, and Cybersecurity Resilience
Building Internet Trust in the AI Era: Internet Week 2026 Governance Insights from DNS, IP, and Cybersecurity Resilience
- 2026/05/25
-
分類
Event
-
瀏覽次數
18
Organized by the Taiwan Network Information Center (TWNIC), Internet Week 2026—an annual flagship event for internet governance—served as a multi-stakeholder platform to foster cross-domain dialogues among policy, technology, and industry sectors. In the face of key global trends such as the AI era, internet governance, geopolitical risks, and global supply chain restructuring, this post-event feature report focuses on technical sessions. It synthesizes discussions on Domain Name System (DNS) governance, Internet Protocol (IP) resource management, routing security, DNS abuse mitigation, cybersecurity, AI infrastructure, and the EU's NIS2 (Network and Information Security Directive 2.0) regulations, examining how Taiwan reinforces its internet infrastructure and digital governance capacity.
From DNS to IP: Network Infrastructure as the First Line of Defense for Digital Resilience
At the strategic and foundational levels, TWNIC Chairman and APNIC Executive Council Chair Dr. Seung-Hung Huang noted during the "ICANN APAC–TWNIC Engagement Forum" on the first day that, in an environment where cybersecurity threats and geopolitical risks intersect, traditional defense mindsets limited to the software and logical layers are no longer sufficient to sustain a trustworthy foundation for a digital society.
Using root server architecture as an example, Dr. Huang explained that although the Internet is viewed as a highly decentralized system, its core operations still carry high concentration risks. Should critical nodes fail, global connectivity could be severely impacted. Therefore, future network defense must incorporate physical infrastructure, routing autonomy, and critical node redundancy as core objectives to ensure DNS resolution stability and operational resilience, thereby building a more complete proactive defense framework.
Regarding IP resource governance, attending experts pointed out that the value of IP resources stems not from ownership, but from open, transparent, and trustworthy coordination mechanisms that ensure effective management and allocation. As governments worldwide become increasingly involved in internet resource policy, the technical community must even more actively articulate the operational logic behind governance mechanisms to prevent existing coordination systems from being misunderstood or superseded.
Taiwan's long-term promotion of Internet Protocol version 6 (IPv6) deployment and routing security has shifted network resource management from "reactive response" to "proactive governance." By regularly publishing Internet Number Resource Status Reports, Taiwan enhances transparency in resource usage, serving as a reference for future policy research and industrial applications.
In terms of routing security, a portion of Taiwan's routing traffic remains exposed to Border Gateway Protocol (BGP) hijacking risks. Notably, if the expansion of corporate autonomous routing capabilities lacks corresponding governance norms, it may inadvertently become a source of cybersecurity vulnerabilities.
Furthermore, technical implementation still faces practical bottlenecks. Some corporate firewall rules continue to block User Datagram Protocol (UDP)/443 traffic. As a result, even if both client and server support HTTP/3, Quick UDP Internet Connections (QUIC) cannot be established, forcing systems to fallback to HTTP/2 or HTTP/1.1 and hindering the actual adoption of next-generation network protocols. Enhancing awareness among enterprises and institutions regarding emerging network protocols, while gradually reviewing network equipment and firewall configurations to lower adoption barriers, remains a critical area for ongoing focus.
DNS Abuse Mitigation: Moving from Technical Detection to Cross-Border Trust Collaboration
DNS security and abuse mitigation were key themes in the technical sessions. As network threats continue to evolve, DNS security is no longer merely a matter of technical defense; it encompasses user trust, cross-border policy coordination, and the overall construction of digital governance frameworks. From ICANN policy mechanisms and incident coordination by national CSIRTs to technical deployments on private sector platforms and frontline management by Registrars and Registries, all stakeholders must operate under a unified framework to effectively shorten threat response times.
In malicious domain detection, current technical defenses leverage Passive DNS to analyze massive query records, identifying evasion tactics where scam groups continuously apply for new domains under the same IP, thereby assisting law enforcement in discovering anomalous activities earlier. However, when malicious domains involve cross-border registration management, the core challenge lies not in detection itself, but in inconsistent reporting standards, handling procedures, and takedown efficiencies across jurisdictions. These gaps create time lags in cross-border responses, impacting real-time blocking and subsequent enforcement efficiency.
Consequently, future DNS abuse mitigation requires not only strengthening technical detection capabilities but also establishing more stable cross-border trust collaboration mechanisms. Deepening cooperation with major Registries through trusted two-way reporting mechanisms will significantly improve the handling efficiency of overseas malicious domains. Administratively and educationally, standardized procedures should be established for non-technical law enforcement personnel, and abuse mitigation processes should be integrated into routine training to align policy execution with technical disposition more effectively.
AI Enters Infrastructure: New Challenges from Performance Upgrades to Governance Risks
In his keynote speech at the "APNIC–TWNIC IP Policy and Resource Management Meeting," JPNIC Chairman Dr. Hiroshi Esaki presented the "AI-Native Digital Infrastructure" framework, pointing out three structural shifts in global networking: network architectures moving from client-server models to distributed edge AI, the Internet of Things (IoT) evolving into an "Internet of Functions," and IPv6 officially entering Operational Technology (OT) domains. He also highlighted that the massive energy consumption of AI is forcing digital infrastructure to integrate into energy grid planning, a challenge the Asia-Pacific technical community must address proactively.
This AI trend is extending from foundational architecture into network identity systems and cybersecurity practices. As blockchain domains and Web3 alternative domain technologies (Alternative DNS) mature, defining and identifying "the location and name of network resources" is no longer confined to traditional DNS and IP addresses. Nevertheless, current architectures remain the core foundation of the global internet in the short term; alternative systems and existing frameworks do not stand in opposition but evolve in parallel across different dimensions.
Building on this, the proliferation of AI Agents has amplified identity and authorization challenges. Traditional identity systems were designed to identify servers, domains, or devices, but have not fully adapted to scenarios where "non-human actors" interact autonomously across networks. Verifying the authorization sources of AI Agents, identifying the entities they represent, and preventing attackers from using AI Agents to conceal their identities will become new topics in internet trust governance. While the industry has begun exploring multi-identifier trust mechanisms across platforms using phone numbers and device IDs, corresponding governance frameworks have yet to be fully established.
Additionally, AI challenges extend to cybersecurity practices and engineering culture. AI-generated deepfake content continuously drives up human verification costs, rendering traditional review processes insufficient. Speaking from an engineering culture perspective, experts warned that over-reliance on AI Agents could diminish engineers' deep understanding of their own systems. Thus, the technical community needs to foster a healthy debate culture and embed "Security by Design" from the earliest system architecture stages.
From Containment to Recovery: Network Resilience Requires Multi-Layered Defense
Sessions focusing on technical community and network infrastructure capacity building brought the discussion back to practical requirements for local cybersecurity and network resilience in Taiwan. According to data shared at the event, Taiwan recorded a peak single Distributed Denial-of-Service (DDoS) attack reaching 2 to 3 Tbps this year, underscoring large-scale cyberattacks as a major challenge to infrastructure protection.
Faced with massive attacks, single enterprises or isolated network operators cannot stand alone. Effective defense relies on a three-tiered collaborative line of defense involving international providers, local telecommunications carriers, and the target organization. Cybersecurity protection is thus no longer solely an individual organization's responsibility, but the outcome of cross-layered, cross-organizational collaboration.
This collaborative logic extends to underlying communications infrastructure. Security gaps in SMS transmission have driven operators to push for full-channel encryption. Speakers emphasized that underlying infrastructure security is a prerequisite for all digital governance; without a resilient network environment, establishing a trustworthy information ecosystem is impossible.
Beyond structural defense deployments, the rapid algorithmic spread of AI-generated misinformation requires joint responses from governments, platforms, and telecom operators. In this context, the mindset around network resilience must shift from "pursuing zero downtime" to "rapid recovery," ensuring services remain operational and recover swiftly following attacks or anomalies.
From routing to communications infrastructure, all session discussions pointed toward a unified trend: internet trust is no longer merely an application-layer issue—it must be redesigned at the infrastructure, identity system, and governance framework levels. The rapid development of AI further amplifies this imperative.
From Regulation to Sustainability: Internet Governance Enters Institutionalization and Green Transformation
Beyond cybersecurity and resilience, the technical sessions addressed the impact of regulatory compliance and sustainable transformation on internet governance.
At the international regulatory level, the EU's NIS2 Directive officially entered its audit phase in April this year, expanding applicable entities from roughly 10,000 to over 160,000 and exerting extraterritorial impacts on Taiwanese manufacturers through supply chain provisions. European experts highlighted that because Taiwan's internet relies heavily on submarine cables, routing security has elevated from a technical option to a regulatory requirement.
Alongside regulatory pressures, energy-saving transformations emerged as a key agenda item, deeply aligned with cybersecurity objectives. Currently, 60% to 80% of telecom operators' network power consumption comes from wireless networks. Practical experience demonstrates that integrating hardware upgrades, software energy-saving mechanisms, and AI automation tools can effectively reduce power consumption without compromising service quality.
Domestically, cases already exist where AI predictive maintenance models manage 5G base stations. By building individual training models for each cell base station and monitoring neighboring traffic shifts, prediction accuracy reaches 90% to 93%, facilitating the shift toward autonomous, uncrewed network operations.
Moreover, significant invalid traffic—such as advertisements and malicious attacks—traverses the internet. Embedding security mechanisms directly into automated operations and deploying them locally via DNS servers to reduce unnecessary traffic will align cybersecurity with green transformation, driving a more sustainable internet governance model.
Charting the New Contour of Internet Governance via Internet Week 2026
In an environment characterized by rapid AI development, rising geopolitical risks, and increasingly stringent international regulations, internet governance is no longer the domain of a single technology or department. It demands the active participation of the public sector, technical community, industry, and international partners to continuously build an integrated defense and collaborative capability across infrastructure, identity systems, and institutional frameworks.