ICANN’s 2026 expansion, the economics of artificial digital scarcity, corporate control of Internet namespaces, and the emerging competition for AI identity infrastructure.

Executive Summary — Bottom Line Up Front

The 2026 competition for new Internet top-level domains is not fundamentally a competition to create websites. It is a competition to obtain control over a scarce, globally recognized naming resource whose commercial value may derive from exclusion, future strategic flexibility, brand protection and control of digital identity rather than immediate public use.

ICANN’s latest expansion has attracted 1,615 applications from 481 applicants, despite an evaluation fee of $227,000 per standard application. Applying the standard fee to all applications produces a theoretical gross value of $366.6 million, before accounting for reduced fees, special arrangements, refunds and additional evaluation charges. That figure is neither verified net revenue nor profit.

The crucial economic distinction is between the value of a domain extension as a business generating registration income and its value as an instrument of strategic control. A corporation can rationally operate a top-level domain with few registrations if doing so protects a brand, prevents an important competitor from obtaining a strategic naming position, or preserves an option for a future digital ecosystem.

For commercial registry operators, the economics are different. Their investment must ultimately be justified by registrations, premium-name sales, renewal income or complementary services. Many speculative applications therefore face a substantially more demanding commercial test than established corporations seeking to protect their digital identities.

The entry of artificial intelligence into the domain-name debate introduces a further distinction: control over a memorable namespace could become commercially valuable for identifying agents, software services, authenticated organizational resources or future machine-to-machine ecosystems. Yet conventional DNS ownership does not automatically grant authority over AI agents, digital identity standards, or emerging technical protocols.

ICANN is also an economically interested institution, not simply a neutral observer of the market it administers. Its fee structure, historical auction proceeds and recurring registry charges create material financial flows. Nevertheless, its nonprofit status, contractual framework and declared cost-recovery model must be distinguished from the profit-maximizing behavior of a commercial auction house.

The central policy question is therefore whether the expansion increases meaningful competition and utility for Internet users—or primarily increases the cost of defending, acquiring and controlling strategically attractive digital names.

ICANN’s $367 Million Domain Rush: The Price of Controlling an Internet That May Never Exist

The 2026 expansion of Internet domains exposes a contradiction in digital governance: corporations are paying substantial sums for naming rights whose commercial value remains uncertain, while the institution administering the process converts strategic scarcity into a global allocation market.

ICANN’s decision to reopen applications for generic top-level domains after fourteen years has triggered a competition whose economic significance extends far beyond Internet addresses. On 7 October 2026, the organization disclosed 1,615 applications from 481 applicants, each facing a standard evaluation fee of $227,000. Among them are multinational technology companies pursuing corporate identities, artificial-intelligence terminology and future digital ecosystems whose commercial structures have yet to emerge. The contradiction is that companies are prepared to commit millions to naming infrastructure they may never substantially use, while ICANN, a California nonprofit responsible for coordinating Internet identifiers, administers the allocation of resources made scarce by their required uniqueness. The issue is not whether these digital names can be sold profitably. It is whether the global Internet is developing another layer of compulsory strategic expenditure, where the cost of remaining outside the allocation process may appear greater than the uncertain value of participation.

The $366.6 Million Figure Conceals Three Different Economic Markets

The 2026 application figures imply a theoretical gross evaluation-fee value of $366.6 million, calculated by multiplying 1,615 applications by the standard $227,000 charge. That amount is neither ICANN’s verified net revenue nor profit: qualified applicants receive discounts, conditional reviews create additional charges, and withdrawal provisions permit partial refunds. The applications themselves are economically heterogeneous. Of the total, 333 were designated brand applications, while 51 were submitted by participants supported through ICANN’s Applicant Support Program. The same fee structure consequently applies to companies seeking controlled corporate infrastructure, commercial operators intending to sell registrations, and institutions pursuing linguistic or community objectives. Treating their expenditure as a single speculative market would obscure the fundamental differences in how each expects to recover value.

The concentration of applications reinforces those distinctions. North America accounted for 864 submissions, Europe for 506 and Asia-Pacific for 218, while Africa contributed 16 and Latin America and the Caribbean 11. These figures do not establish ultimate corporate ownership, but they reveal the geographical distribution of effective participation. The Applicant Support Program reduces standard evaluation fees by 75–85% for eligible participants, yet application costs represent only part of the capital required to operate a registry. Technical infrastructure, legal services, security, distribution and continuing compliance remain necessary. Financial support may therefore increase access to the application process without eliminating the structural advantages enjoyed by established technology companies and registry operators.

The historical precedent also imposes caution. The 2012 application round produced 1,241 cumulative delegations by 31 August 2026, alongside 653 withdrawn applications. Delegation establishes the technical and contractual operation of a top-level domain; it does not establish profitability. ICANN’s earlier round also generated approximately $225 million through 16 auctions of last resort, according to its March 2026 Board records. That sum illustrates how competition for unique names can produce substantial payments independently of the commercial performance of the resulting registries. The 2026 prohibition on private contention auctions changes the distribution of potential financial benefits, but it does not eliminate the possibility that competing applicants will pay more for an extension than its eventual operations can justify.

The Value of a Domain May Lie in Keeping Others Out

For a multinational corporation, the economic case for acquiring a top-level domain need not involve selling a single registration to the public. Under ICANN’s Specification 13, qualifying brand registries can operate controlled namespaces for authorized corporate entities and trademark licensees. The company acquires a contractual position from which it can organize digital services, support recognizable corporate identities and preserve future deployment options. An extension can therefore remain commercially inactive in the conventional retail sense while providing defensive or organizational value. The relevant financial calculation concerns the incremental costs avoided and flexibility obtained, not the number of websites launched under the new suffix.

This distinction explains why an application can be rational for a large enterprise and financially questionable for an independent registry entrepreneur. The 2024 Base Registry Agreement establishes a standard fixed registry charge of $25,000 annually, before other applicable expenses. Combined with the initial evaluation fee, five years of this fixed charge alone would produce a nominal commitment of $352,000, excluding technical operations, legal services, marketing and conditional evaluation costs. A global company may absorb that expenditure within its infrastructure or intellectual-property budget. A commercial registry must recover its investment through customers whose willingness to register and renew names remains uncertain. The same contractual asset consequently has different economic value depending on the applicant’s existing resources and commercial relationships.

There are limits to defensive acquisition. ICANN’s 2026 framework restricts exclusive operation of generic strings, distinguishing qualified corporate brands from terms associated with broader technological or commercial categories. A company cannot automatically transform a generic expression into an exclusively controlled corporate environment merely by submitting an application. Nevertheless, the competition for desirable terminology creates an incentive to act before commercial demand is established. Because the 2026 application window closed on 12 August, waiting for greater clarity carries the risk that another eligible applicant may obtain the desired string. This is the defining characteristic of the investment: companies pay today to preserve uncertain possibilities tomorrow, even where existing domains might already provide most of the required functionality.

Artificial Intelligence Creates Demand for Trust, Not Necessarily for New Domain Names

Applications involving terms such as .openai, .chatgpt, .agent and .agi place artificial intelligence at the center of the latest naming competition. Their strategic significance lies in the possibility that increasingly autonomous software will require recognizable service identities, authenticated communication and reliable discovery mechanisms. Yet these requirements do not establish that a new top-level domain is technologically necessary. The Model Context Protocol’s November 2025 authorization specification addresses how AI applications interact with protected resources through authorization mechanisms, while the World Wide Web Consortium’s May 2025 Verifiable Credentials Data Model v2.0 provides a framework for verifiable digital assertions. Neither depends upon a particular AI-related domain extension to perform its fundamental function.

The distinction between naming and authority is economically decisive. A domain can identify a network resource, but it cannot independently establish whether an autonomous agent is permitted to transfer funds, approve a purchase or access confidential information. Those operations require authenticated identities, delegated permissions, enforceable policies and reliable audit records. A corporation acquiring an AI-related extension may eventually integrate it into a trusted service ecosystem, but the commercial value would arise from adoption of the surrounding infrastructure. The extension itself does not confer control over AI protocols, digital credentials or the behavior of software operating elsewhere on the Internet.

This creates two opposing possibilities for the companies now acquiring AI-related naming assets. If enterprises and developers adopt recognizable namespaces as part of interoperable agent ecosystems, selected extensions could become valuable organizational and commercial infrastructure. If agents increasingly discover services through existing domains, cryptographic credentials, application directories and platform interfaces, the economic importance of memorable new suffixes may remain limited. Thousands of agents can operate beneath a small number of existing corporate domains without generating corresponding demand for retail registrations. The expansion of machine identity may therefore increase the importance of digital trust while simultaneously weakening the assumption that more software agents require more domain names.

Europe’s Cybersecurity Rules Expose the Cost of Operating What ICANN Allocates

The legal environment further complicates the commercial calculation. Directive (EU) 2022/2555, known as NIS2, expressly addresses top-level-domain registries, DNS service providers and relevant domain-registration services, imposing cybersecurity and related obligations under its applicable provisions. Commission Implementing Regulation (EU) 2024/2690 specifies technical and methodological requirements for covered entities. Successful applicants operating within the relevant European regulatory scope must therefore evaluate responsibilities extending beyond their contracts with ICANN, including risk management, incident handling, continuity, supply-chain controls and registration-data governance. The acquisition of a namespace may be global in technical effect, but the business operating it remains exposed to territorial regulation.

National differences sharpen that exposure. France’s Afnic reported 4,319,120 .fr registrations at the end of 2025, with 853,000 new creations and an 82.2% retention rate, while Germany’s DENIC recorded 17,663,886 .de domains, including more than 2.16 million held by registrants abroad. These established registries demonstrate the scale and international reach attainable through mature naming infrastructure, but they also illustrate why a new extension cannot be valued using registration counts alone. Their operating histories, institutional structures and recognizable national identities are not automatically transferable to speculative generic domains. Italy faces a related question through its .it infrastructure and industrial companies, many of which may obtain greater immediate value from secure existing domains and interoperable identity systems than from independently operating new registries.

The United Kingdom introduces a further constraint through the National Security and Investment Act. Its defined digital-infrastructure categories include qualifying top-level-domain registry acquisitions, with a specific threshold involving at least 14 billion DNS queries from UK devices over a consecutive 168-hour period. Not every registry transaction reaches that threshold, but the provision demonstrates that a domain infrastructure business can acquire national-security significance independently of the commercial appeal of its name. The European Union regulates relevant operating responsibilities, the United Kingdom may examine qualifying changes of control, and ICANN governs the contractual allocation of the extension. These powers coexist without being interchangeable, creating compliance obligations that investors cannot remove simply by choosing a different corporate jurisdiction.

ICANN’s Nonprofit Status Does Not Eliminate the Governance Question

ICANN’s institutional position is frequently misunderstood. The 2016 IANA stewardship transition ended the previous direct U.S. government stewardship arrangement, but ICANN remains a California nonprofit public benefit corporation operating through a multistakeholder governance framework. Its Bylaws, Empowered Community, Reconsideration Process and Independent Review Process establish important accountability mechanisms. The organization also describes the 2026 evaluation-fee structure as cost-recovery based, with provisions addressing possible application-volume refunds. These characteristics distinguish it from a commercial auction house selling unrestricted property rights over Internet terminology. They do not, however, eliminate the need to examine whether the costs imposed on applicants remain proportionate to the public functions performed.

The institutional difficulty is that ICANN administers a resource whose scarcity is partly defined by the need for unique names in the coordinated DNS. Applicants seeking globally recognized generic extensions cannot simply reproduce an identical string through an ordinary registrar purchase. That gives the allocation process economic importance beyond the organization administering it. The appropriate scrutiny concerns how fees are calculated, how evaluation expenses are allocated, how auction proceeds are governed and whether smaller participants can obtain meaningful access to review and objection procedures. The March 2026 Board decision allocating up to an additional $4.9 million for applicant support illustrates an attempt to address participation inequality, but it also confirms that access to naming infrastructure has become a question of institutional financing rather than technical eligibility alone.

The international consequences extend beyond corporate applications. ICANN’s September 2026 reporting identified 151 delegated internationalized top-level domains covering 37 languages and 23 scripts as of June 2026, alongside approximately 4.3 million internationalized second-level registrations. Yet Universal Acceptance limitations continue to affect whether valid names operate correctly across software, websites and email systems. For users whose languages are inadequately supported, the economic obstacle may be less the cost of obtaining a new extension than the inability of existing applications to recognize it reliably. Allocating additional names without securing their technical usability would expand the formal namespace while leaving a substantial portion of its promised utility unrealized.

By 2028, the Cost of Inaction Will Fall on Companies, Registrants and Public Institutions

The next 12–24 months will establish the first meaningful boundaries of the 2026 competition. The replacement period closes on 21 October 2026, String Confirmation Day is scheduled for 17 November, and the relevant comment and objection procedures extend into March 2027. Subsequent evaluation, contention resolution and contracting will determine which applications can progress toward delegation. For applicants, these stages create progressively consequential financial decisions because the recoverable portion of the standard evaluation fee declines as the process advances. Continuing an investment merely because earlier expenditure is no longer recoverable would expose companies to additional costs unsupported by future commercial value.

The immediate risk for corporations is not failing to acquire every attractive namespace. It is committing to registries without a documented reason why existing domains, security infrastructure and identity standards cannot provide equivalent benefits. For commercial applicants, the principal exposure is weak renewal demand combined with continuing technical and regulatory costs. For trademark owners, an expanding naming environment may increase monitoring and enforcement burdens without eliminating impersonation. For smaller institutions, the danger is financing a registry whose continuing obligations exceed available operating resources. These costs will be borne by shareholders, registrants, customers and, where public funding is involved, the institutions financing participation.

ICANN’s corresponding responsibility is to demonstrate, through the financial and procedural outcomes of the 2026 round, that allocation costs and institutional safeguards serve the stability and utility of the global DNS. By October 2028, the number of approved or delegated extensions may offer evidence of administrative progress, but it will not establish that the expansion has created comparable economic value. That judgment will require operating data, adoption, technical performance and eventually meaningful renewal records. The cost of failing to make those distinctions is a market in which companies continue purchasing scarce digital options, regulators inherit additional infrastructure obligations, and Internet users finance greater complexity without receiving commensurate improvements in trust, competition or service.


Navigational Index

PILLAR I — The Economics of Artificial Scarcity and Institutional Control

  • Chapter 1. ICANN’s Economic Architecture: Governance, Fees, Auctions and Financial Incentives
  • Chapter 2. The $227,000 Decision: Scarcity, Option Value, Defensive Acquisition and Corporate Strategy
  • Chapter 3. Commercial Registry Economics: Revenue, Renewal Risk, Market Concentration and Investment Returns

PILLAR II — Technological Power, Digital Identity and Competition

  • Chapter 4. Technology Companies and the Strategic Acquisition of Internet Namespaces
  • Chapter 5. Artificial Intelligence, Autonomous Agents and the Future of Trusted Digital Identity
  • Chapter 6. Cybersecurity, Trademark Protection, DNS Dependence and Structural Market Risks

PILLAR III — International Governance, Regulatory Exposure and the Future of the DNS

  • Chapter 7. ICANN’s Institutional Accountability and the Political Economy of Internet Governance
  • Chapter 8. The United States, European Union, Italy, France, Germany, United Kingdom and Emerging Economies
  • Chapter 9. The 2027–2031 Outlook: Market Scenarios, Regulatory Choices and Strategic Consequences

Master Abstract — Who Is Really Buying What?

A new generic top-level domain is commonly presented as a new suffix available for Internet addresses. That description is technically correct but economically incomplete. Applicants are seeking the opportunity to become registry operators of a particular namespace in the globally coordinated Domain Name System, subject to ICANN’s evaluation, contracting and operational requirements.

The distinction matters because a registry operator occupies a position fundamentally different from an ordinary domain registrant. A business registering company.com acquires contractual rights to use an individual name. A successful applicant for .company could obtain contractual authority to administer an entire top-level namespace, establish permitted registration structures, manage second-level names and develop services based on that naming environment.

This is not ownership of an Internet word in the ordinary intellectual-property sense. Nor is it a grant of unlimited sovereignty over Internet naming. It is a technically and contractually governed position within a globally interoperable infrastructure.

Nevertheless, that position can possess substantial economic value.

A multinational corporation may have little reason to sell thousands of addresses under its own brand. It may instead prefer to ensure that its name is administered within a controlled environment, where affiliated services, approved partners and authorized communications can operate under organizational rules.

An independent registry entrepreneur faces an entirely different incentive. Its opportunity lies in building demand for a category-specific naming product and retaining revenue from registration and renewal transactions. A commercially attractive label can support substantial transaction volumes, but a technically valid extension can also fail to acquire meaningful market demand.

A third category involves strategic uncertainty. Firms operating in artificial intelligence, software infrastructure, digital payments or future online platforms may perceive a domain extension as an option on an ecosystem that has not yet matured. They may be willing to incur a relatively modest initial cost to preserve the possibility of deploying that ecosystem later.

Such behavior is neither necessarily irrational nor necessarily commercially justified. Its rationality depends on the expected value of the opportunities protected, the probability of future deployment, the cost of maintaining the registry and the strategic consequences of leaving the identifier available to others.

The institutional structure adds another layer. ICANN determines eligibility, administers contention procedures and enters into registry contracts. Its contractual and policy framework influences what can be acquired, the financial conditions of participation and the extent to which private economic competition shapes Internet naming resources.

The resulting market therefore combines characteristics of infrastructure governance, regulated contractual allocation, brand strategy, speculative investment and a limited form of positional competition.

The most consequential risk is not simply the emergence of extensions that few people use. It is the possibility that businesses increasingly regard participation in repeated naming rounds as a necessary cost of strategic protection, even where the incremental public benefit of additional namespaces remains difficult to demonstrate.

Key Evidence Table — What the Official Record Establishes

Verified public records available as of 11 October 2026. Monetary figures in nominal U.S. dollars.

IndicatorValue/statusReference dateDefinition/scopeIssuerExact source
Total applications1,6157 Oct 2026Applications, not approved or delegated TLDsICANNApplication Statistics
Distinct applicants4817 Oct 2026Applying entitiesICANNApplication Statistics
Standard evaluation fee$227,0002026 roundPer standard application, exceptions applyICANNEvaluation Fee FAQs
Theoretical fee value$366,605,0002026 round1,615 × $227,000; not actual revenueCalculatedBased on ICANN’s application and fee records
Brand applications3337 Oct 2026Designated brand applicationsICANNReveal Day Release
Supported applications517 Oct 2026Applicant Support Program submissionsICANNReveal Day Release
Applicant support discount75–85%2026 roundQualified applicantsICANNApplicant Support
Delegated TLDs from 2012 round1,24131 Aug 2026Historical cumulative delegations, subject to ICANN’s reporting caveatICANN2012 Program Statistics
Applications withdrawn from 2012 round65331 Aug 2026Withdrawn applicationsICANN2012 Program Statistics
Registry fixed fee benchmark$25,000 annually2024 contract$6,250 quarterly, before other charges; not necessarily every future contractICANNBase Registry Agreement, Article 6.1
Confirmed 2026 delegations07 Oct 2026Applications contracted and delegatedICANNApplication Statistics
Program Economics & Metric Interpretation

The financial magnitude is substantial—but its interpretation requires care

A structural breakdown of headline program economics, application distributions, brand positioning, and portfolio rationalization dynamics.

Standard-fee equivalent
$366.6M
Calculated gross value before discounts and adjustments
Average applications / applicant
3.36
Does not describe the distribution across applicants
Brand applications share
20.6%
333 of 1,615 applications
2012 applications withdrawn
33.8%
653 of 1,930; not an investment failure rate

Analytical Context & Methodological Nuances

1. Gross Theoretical Commitment vs. Realized Capital

The standard-fee baseline of $366.6M reflects raw transactional volume based strictly on statutory initial evaluation price points. Because institutional applicants frequently utilized tiered pricing, contested string auctions, refunds, or procedural offsets, this figure must be evaluated as nominal gross throughput rather than retained programmatic revenue.

2. Skewed Applicant Density

An arithmetic mean of 3.36 applications per applicant masks severe structural inequality across participants. The distribution is heavily bimodal: hundreds of single-string applicants (e.g., individual corporations securing exact trademarks) offset by a concentrated cohort of high-volume portfolio operators and registries holding dozens or hundreds of contested assets.

3. Direct Corporate Defensive Positioning

Brand strings comprised approximately one-fifth (20.6%) of the 1,615 non-withdrawn/evaluated applications. This tranche was driven by brand protection, sovereign corporate identities, and closed-loop defensive registration strategies, representing a completely distinct risk profile from open generic registry plays.

4. String Resolution Dynamics vs. Failure

The withdrawal of 653 applications (33.8%) must not be conflated with commercial default or product failure. A substantial proportion of withdrawals were calculated strategic exits resulting from private string contention resolution, financial settlements between applicants, or tactical concessions to recover statutory refund percentages.

Dataset Source: New gTLD Program 2012 Round Historical Analysis Status: Settled Evaluation Framework

Derived calculations from ICANN’s October 2026 application statistics and August 2026 historical statistics. Percentages rounded to one decimal place.

The theoretical $366.6 million fee figure is economically relevant because it reveals the financial scale of the evaluation process. But it would be incorrect to call that amount ICANN’s confirmed net income or profit.

Qualified supported applicants receive discounted evaluation fees, generally between 75% and 85% below the standard rate. The contractual framework also provides circumstances in which refunds may be available. Other charges and conditional evaluations can increase particular applicants’ expenditure.

The calculation consequently measures the standard-price equivalent of the application volume, not final recognized revenue, retained funds, operating earnings or unrestricted financial resources.

This distinction is fundamental when evaluating whether ICANN has a financial incentive to expand the number of new top-level domains.

The Geography of the 2026 Competition

Applications by applicant region

ICANN Reveal Day snapshot, 7 October 2026. Counts represent applications, not distinct companies.

Source: ICANN, Reveal Day Data Snapshot, 7 October 2026.

North America accounts for approximately 53.5% of applications, Europe 31.3%, and Asia-Pacific 13.5%. Together these three regions represent roughly 98.3% of the total.

This geographic concentration matters more than the absolute number of applications. Although the namespace being allocated is global, the financial and organizational capacity to compete for it is not evenly distributed.

A worldwide addressing system can therefore undergo formal expansion while control of new naming resources remains concentrated among participants based in established economic centers.

There are important qualifications. Applicant headquarters do not necessarily identify ultimate beneficiaries, investment ownership or the geographic communities served. An application originating in North America could finance services operating internationally. Nevertheless, the imbalance creates a legitimate policy question about the distribution of entry opportunities.

The Applicant Support Program reduces some barriers but does not eliminate the underlying costs of operating a registry, developing demand, securing technical services and competing with established businesses.

The Central Economic Mechanism — Why a Namespace Can Be Valuable Without Traffic

The economic rationale for paying substantial amounts can be organized around six distinct sources of value.

Value mechanismEconomic rationaleNeed for substantial public traffic?Principal weakness
Brand protectionControl official naming under an established corporate identityNoCost may exceed incremental protection
Strategic exclusionReduce the risk of an eligible rival obtaining a strategically important namespaceNoExclusion is bounded by eligibility and contention rules
Future option valuePreserve the opportunity to build future servicesNo, initiallyThe expected ecosystem may never develop
Direct registry revenueSell or renew second-level domain registrationsUsually yesDemand and renewal rates may disappoint
Controlled enterprise identityOrganize approved services and digital resources under corporate rulesNoExisting domains may already be sufficient
Platform ecosystem positioningEstablish a naming convention for customers, developers or agentsNot necessarily initiallyDNS naming alone does not create adoption

These mechanisms should not be treated as mutually exclusive. A large technology company may simultaneously perceive defensive, operational and future-option value in the same application.

The decisive issue is the expected incremental value of control compared with the full cost of obtaining and maintaining it.

For a corporate brand with extensive existing operations, the investment may be justified by strategic considerations that never generate an identifiable line of domain-registration revenue.

For an independent commercial applicant, however, the inability to generate sustained demand can turn the same acquisition into a financially unsuccessful investment.

The crucial difference between buying an ordinary domain and operating an entire extension

Consider a hypothetical technology business already operating example.com.

Obtaining payments.example.com, agents.example.com or support.example.com generally requires no new top-level-domain application. These are subdomains created within a name the business already controls.

By contrast, operating .example as a registry would provide a separate naming environment capable of supporting addresses such as payments.example or support.example.

That distinction can have branding and architectural benefits, but it should not be exaggerated. A top-level domain is not inherently more secure, technologically advanced or commercially valuable than a properly administered existing domain.

Its incremental value comes from what the organization can do with the additional namespace that it cannot achieve as efficiently, credibly or strategically within existing arrangements.

An important limitation on defensive control

A company cannot simply apply for any generic word and obtain unrestricted exclusive control over that category.

ICANN’s 2026 framework continues restrictions on closed generic applications. Qualified brand domains can be operated on an exclusive-use basis under applicable requirements, but that is different from granting a company exclusive private control over an entire generic commercial concept.

Consequently, the strategic-exclusion argument must be applied carefully: exclusive control depends on the nature of the string, eligibility, contractual conditions and the outcome of competing applications. ICANN, 2026 Applicant Guidebook, Module 3.

ICANN’s Financial Position — An Institutional Conflict or a Legitimate Cost-Recovery System?

ICANN occupies an unusual institutional position. It helps coordinate a global naming infrastructure while administering a system in which companies must incur substantial expenses to obtain permission to operate new top-level domains.

Unlike an ordinary commercial seller, however, ICANN does not offer unrestricted private ownership of Internet extensions. Its role arises from a multistakeholder governance framework, and registry operators remain subject to contractual and technical obligations.

The organization describes the 2026 evaluation fee as based on cost recovery. Its published fee guidance states that the program is

That is an institutional position, not independent proof that every dollar charged is economically necessary or that the chosen cost structure is optimal.

A meaningful assessment must separate three questions.

First, does administering an expansion of the DNS generate legitimate costs? Yes. Application evaluation, technical scrutiny, objection mechanisms, contractual work, operational infrastructure and continuing oversight require resources.

Second, does ICANN derive substantial financial flows from its administration of the system? Yes. Applicants pay evaluation fees, successful registry operators incur ongoing contractual charges, and auctions can generate additional proceeds.

Third, does the existence of these financial flows establish that ICANN is deliberately expanding the DNS to maximize its financial returns? No. That conclusion would require evidence about institutional decision-making, fee-setting incentives, cost allocation, governance arrangements and the actual destination of the resulting funds.

The strongest economic criticism therefore concerns the possibility of incentive misalignment, rather than an unsupported allegation that ICANN operates as a conventional profit-seeking auctioneer.

The historical auction proceeds deserve particular scrutiny

The previous application round illustrates the significance of competition for scarce labels.

ICANN’s published 2012-round statistics record 234 contention sets, of which 16 were resolved through ICANN auctions. The same historical record reports 1,241 delegated new gTLDs as of 31 August 2026. ICANN, New gTLD Program Statistics.

ICANN’s fiscal-year 2025 financial reporting identified approximately $236 million in net auction-proceeds funds as of 30 June 2025, including accumulated investment returns. Those resources were associated with the historic auction process and directed toward the ICANN Grant Program rather than treated simply as unrestricted commercial profits.

The institutional issue extends beyond profitability. Auction revenues can become a material source of financing for activities considered beneficial to the Internet community.

This creates a governance tension: the same mechanism that allocates contested naming resources can also produce funds for public-interest initiatives.

Whether that arrangement is desirable depends on transparency, expenditure controls, accountability and the extent to which auction-driven outcomes support—or undermine—the public interest.

The auctions are now more tightly constrained

For the 2026 round, applicants competing for the same string cannot freely arrange private settlements or auctions to resolve contention.

ICANN identifies Community Priority Evaluation, where applicable, and ICANN-administered auctions as the permitted resolution pathways. Private auction arrangements, joint ventures and compensation agreements designed to resolve contention privately are prohibited. ICANN, Contention Set Resolution.

This changes the economics of strategic applications.

An applicant cannot safely assume that submitting a competing application will create a privately negotiable financial payoff. Participation now carries the possibility of an expensive auction without an authorized private settlement route.

The prohibition reduces the potential for certain forms of speculative behavior, although it does not eliminate competition-driven escalation in the prices applicants may ultimately pay.

How Much Can an Apparently Unused Domain Really Cost?

The $227,000 evaluation payment is only the beginning of the relevant financial analysis.

Under the 2024 Base Registry Agreement, Article 6.1, the standard registry fixed fee is $6,250 per calendar quarter, equivalent to $25,000 annually. A transaction-based fee also applies under specified thresholds.

This contractual benchmark demonstrates that running a delegated registry can entail recurring obligations regardless of whether the operator has created a large commercial market. Actual applicable terms, negotiated or approved reductions, and future contractual provisions must be checked for each operator. ICANN, Base Registry Agreement, Article 6.

The registry must also address technical services, security, operational continuity, compliance and any relevant outsourced services.

The true economic commitment is therefore best modeled over the entire expected life of the registry rather than by reference to the application payment alone.

Illustrative economics of a new gTLD

The following sensitivity analysis is a model, not a statement of actual applicant financial performance.

It assumes a standard $227,000 application fee, a $25,000 annual ICANN fixed fee based on the 2024 contractual benchmark, unchanged nominal fees, no discount, and no additional auction, technical, operational, financing or transaction costs.

DurationApplication feeCumulative fixed registry feesCombined minimum modeled amount
Initial application$227,000$0$227,000
1 year of delegated operation$227,000$25,000$252,000
5 years of delegated operation$227,000$125,000$352,000
10 years of delegated operation$227,000$250,000$477,000

The ten-year figure is especially important because $477,000 remains substantially below a realistic all-in estimate for some operators once operational and other costs are considered, although the full amount cannot be established without actual supplier contracts and expenditure data.

It also demonstrates that the application fee alone understates the commitment.

For a multinational company, such expenditure may represent an acceptable cost of protecting an internationally recognized brand. For a smaller applicant without an established customer base, the same expenditure could constitute a serious long-term financial exposure.

Commercial Break-Even: The Question Registry Entrepreneurs Cannot Avoid

A commercial registry must assess whether its projected sales volume, wholesale pricing, renewal rates and operating expenses can justify its investment.

For illustration, consider three hypothetical net contribution levels per domain registration or annual renewal. These are assumed contributions after variable costs, not observed market prices or actual registry margins.

The number of annual registration-equivalent transactions needed to cover only the $25,000 illustrative ICANN fixed charge would be:

Net contribution per annual registration-equivalentTransactions needed annually
$55,000
$102,500
$201,250

These thresholds do not cover the original $227,000 evaluation fee, external registry operations, marketing, staff or any auction expenditure. Nor do they establish that a given registry can secure customers at the assumed contribution level.

The economics become more demanding when the registry is expected to recover development costs within a fixed period.

This explains why the same $227,000 payment can be strategically rational for a global brand and commercially questionable for an entrepreneur planning to monetize an unfamiliar suffix.

The first purchases optionality or controlled infrastructure. The second must build a market.

Artificial Intelligence and the Changing Value of Digital Naming

The introduction of increasingly autonomous software systems creates a plausible new source of demand for trusted and recognizable naming structures.

AI agents may need publicly reachable service endpoints, organizational identifiers, discovery mechanisms and authentication systems. A recognizable namespace could potentially help an organization standardize how such resources are presented.

But the underlying technical relationships must be distinguished.

A domain name can identify a network resource. It does not, by itself, verify that an AI agent is trustworthy, legally authorized, acting on behalf of a particular individual or permitted to conduct a financial transaction.

Those properties depend on additional controls: authentication, authorization, cryptographic verification, policy enforcement and application-layer protocols.

There is therefore no established technical basis for assuming that acquiring an AI-related top-level domain automatically confers control over the future AI-agent economy.

The more defensible hypothesis is narrower: organizations may value such domains as part of an identity architecture whose future commercial importance remains uncertain.

Three possible technological trajectories

Under the first trajectory, AI services continue to rely predominantly on existing domains, APIs, application platforms, cryptographic credentials and software registries. Additional top-level domains offer little incremental technical value, even if they remain useful for branding.

Under the second, specialized namespaces become useful for organizing discoverable services, approved agents and commercial ecosystems. Certain extensions could acquire meaningful value because users and developers adopt consistent naming conventions.

Under the third, increasingly important discovery and identity functions move toward structures that are only partially dependent on the traditional DNS. Application ecosystems, cryptographic identifiers and platform-level directories could reduce the strategic significance of particular top-level domains.

These trajectories are not mutually exclusive. Their relative importance may differ across sectors.

The decisive variable is not the number of AI-related names acquired in 2026. It is whether future technical standards and commercial practices generate genuine demand for those names.

Competing Explanations — What Is Driving the 2026 Application Wave?

The evidence supports three analytically distinct but overlapping explanations for the observed demand.

HypothesisDiagnostic supportCountervailing evidenceObservable indicatorsCurrent assessment
Strategic corporate protection333 designated brand applications; established exclusive-use arrangements for qualified brandsAn existing domain can already serve many operational needsCorporate deployment, long-term renewals, controlled second-level useStrong structural explanation for brand applicants
Speculative commercial investmentCompetition for scarce strings; availability of registry-based revenue modelsSignificant costs, uncertain demand and restrictions on private contention resolutionPremium pricing, registrations, renewal rates, registry transfersPlausible for commercial applicants; profitability unestablished
Future ecosystem positioningInterest in technology-oriented naming and future digital identitiesNo demonstrated requirement that future AI systems adopt new gTLDsAgent standards, enterprise deployments, developer adoptionStrategically plausible but technologically uncertain

The observed application count cannot, by itself, establish applicants’ motivations.

A larger number of corporate applications is consistent with strategic defensive behavior, but some enterprises may genuinely plan extensive operational deployments.

Likewise, an unfamiliar generic extension may appear speculative while actually targeting an established professional community or a narrowly defined commercial use case.

An assessment of particular applicants requires their disclosed application objectives, business models, ownership structures, and subsequent deployment behavior.

The 2012 Precedent — Why Historical Numbers Do Not Prove Success

ICANN’s previous expansion remains the most useful historical reference, but it cannot be interpreted as proof that the 2026 applicants will achieve comparable commercial results.

The 2012 round attracted 1,930 applications. By 31 August 2026, ICANN reported 1,241 cumulative delegations, 653 withdrawals, 32 applications that would not proceed or were otherwise unsuccessful or terminated, and four still proceeding.

A delegated TLD is a technical and contractual milestone. It is not equivalent to a profitable registry.

Similarly, withdrawal does not necessarily mean that an applicant lost its entire investment. Withdrawals may reflect strategic decisions, contention outcomes, eligibility issues or other circumstances, and ICANN’s program has included specified refund arrangements.

The commercial performance question must instead be answered through registration volume, genuine end-user adoption, renewal rates, pricing, registry costs, abuse exposure and long-term economic sustainability.

The historical precedent establishes that ICANN can oversee the introduction of large numbers of extensions. It does not demonstrate that every new naming resource creates proportionate consumer value.

Principal Gaps and Watch Indicators

The opening assessment identifies several records and events that will determine whether the 2026 expansion is primarily an economically productive enlargement of the DNS or an expensive exercise in strategic positioning.

Watch indicatorWhat it would establishDecision relevance
Final string and contention data, 17 Nov 2026Actual contested names following replacement decisionsPotential auction exposure and scarcity premiums
Evaluation and objection outcomesWhich applications survive formal scrutinyDifference between demand for a string and actual delegation
Registry agreements and special provisionsEffective rights, obligations and operating costsRealistic lifetime financial exposure
Actual registry launches and usageWhether successful applicants put namespaces into operationDistinction between strategic holding and productive deployment
Renewal rates and registration concentrationDurability of demand beyond initial promotionsCommercial sustainability
AI naming and identity standardsWhether specialized namespaces become technically significantValidity of future-option strategies
ICANN financial reportingProgram costs, collections, liabilities and use of fundsInstitutional accountability and cost-recovery assessment
Regulatory and competition developmentsWhether ownership concentration or exclusive-use rules attract interventionLong-term legal and governance risk

The decisive evidence will emerge after application review, contention resolution and operational deployment. As of 11 October 2026, none of the 1,615 applications in the new round has reached contracted or delegated status according to ICANN’s published statistics.

This limits what can legitimately be concluded about the financial success of the round today.

Preliminary Net Assessment

The 2026 gTLD application round is best understood as a market in controlled strategic options over Internet naming infrastructure, rather than a conventional retail market for domain names.

The economics differ sharply among participants. Brand owners may purchase defensive protection and organizational flexibility. Commercial registries seek recurring customer revenue. Technology companies may purchase positions in future identity ecosystems. Communities may pursue linguistic, cultural or institutional objectives that cannot be evaluated solely through financial return.

ICANN’s economic role requires particular scrutiny because it combines technical coordination, policy implementation, contractual oversight and the administration of substantial financial flows. Its nonprofit purpose and stated cost-recovery obligations are material safeguards, but they do not remove the need to assess program efficiency, transparency and the consequences of fee-based entry.

The most important structural concern is that a system intended to expand competition can also generate a new category of defensive expenditure. When firms believe that failing to participate today may foreclose important naming options tomorrow, willingness to pay can rise independently of demonstrated consumer demand.

The expansion may therefore produce both genuine innovation and economically unproductive duplication.

The ultimate measure of success will not be how many new suffixes ICANN approves or how much applicants spend to obtain them. It will be whether those namespaces create measurable utility, strengthen trustworthy Internet services, support sustainable competition and justify the financial and institutional costs of their introduction.

Institutional intelligence dashboard | October 2026

THE $366.6M DOMAIN RUSH

The economics of Internet naming scarcity: why applicants may pay to control a top-level domain even when public traffic is negligible. Financial, strategic and institutional perspectives on ICANN’s 2026 gTLD round.

2026 application roundGlobal DNS governance2027–2031 strategic outlook
1,615Applications filed
481Distinct applicants
$227KStandard fee per application
$366.6MTheoretical standard-fee total; not confirmed revenue

Geography of Demand

Application counts by applicant region, 7 October 2026

North America
864
Europe
506
Asia-Pacific
218
Africa
16
Latin America & Caribbean
11

North America and Europe together account for 84.8% of applications. Applicant location does not necessarily establish beneficial ownership or final service geography.

Source: ICANN — 2026 Application Statistics

Who Is Competing?

333
Brand applications
16
Community
15
Geographic

Selected reported application categories, not a complete partition of all applications. Column heights use a common linear scale.

Source: ICANN — Application Statistics

What Does an Applicant Actually Acquire?

A top-level registry position is distinct from owning an ordinary second-level domain. It is subject to evaluation, contracting and continuing technical obligations.

01 — APPLICATION

Seek a particular gTLD string; pay a standard evaluation charge. Approval is not automatic.

02 — EVALUATION

ICANN applies eligibility, technical, objection and contention procedures.

03 — CONTRACT & DELEGATION

A successful applicant may obtain contractual registry operating rights, not unrestricted ownership of a word.

04 — VALUE CAPTURE

Brand control, enterprise organization, registration revenues or future ecosystem optionality.

Framework: ICANN — New gTLD Program: 2026 Round

Interactive Cost Exposure Model

Illustrative nominal cash-cost model for one standard application. Change the years of delegated operation and optional auction spending. The benchmark annual fixed registry fee is derived from the 2024 Base Registry Agreement; it is not a quote for every 2026 contract.

Combined illustrative expenditure
$352,000

$227,000 application + $125,000 fixed ICANN fees

Excludes conditional evaluations, transaction fees, financing, inflation, refunds and other items not explicitly modeled.

Cost composition
Application fee
64.5%
Registry fixed
35.5%
Auction
0.0%
Other operations
0.0%

Source: ICANN — 2024 Base Registry Agreement, Article 6.1; 2026 standard evaluation fee from ICANN fee guidance.

Six Sources of Strategic Value

Economic mechanismReason to acquire a gTLDHigh public traffic required?Critical limitation
Brand protectionControl a corporate naming environmentNoExisting domains may suffice
Strategic exclusionPrevent certain competing uses when permittedNoPolicy eligibility and closed-generic restrictions
Future option valueReserve an opportunity for future servicesNo, initiallyFuture demand may not materialize
Registry salesEarn registration and renewal incomeTypically yesAcquisition and renewal economics
Enterprise identityStandardize internal or approved public servicesNoOperational benefits may be modest
Platform positioningSupport a developer, customer or agent ecosystemUncertainNamespace ownership does not guarantee adoption

Commercial Break-Even Sensitivity

Annual transaction equivalents required solely to recover an illustrative $25,000 fixed ICANN registry charge. Assumed net contribution per transaction, not actual quoted prices or verified margins.

Assumed net contributionRequired annual transactionsCoverage
$55,000Only $25,000 annual fixed fee
$102,500Only $25,000 annual fixed fee
$201,250Only $25,000 annual fixed fee

The break-even illustration excludes initial application recovery, operational providers, distribution, marketing and other costs. It is not evidence of profitable registry operation.

Three Competing Strategic Pathways

Corporate Defensive Control

Ownership-like contractual control supports branding and organizational policy even with limited public traffic. Watch: deployment and long-term renewal behavior.

Commercial Speculation

Independent operators depend on registration sales, premium inventory, customer acquisition and renewal economics. Watch: organic demand and attrition.

AI Ecosystem Option

Future machine-readable identities may benefit from consistent naming, but DNS control alone does not authenticate agents. Watch: protocol adoption and real deployments.

Institutional Governance Watchlist

Milestone or indicatorWhy it mattersInterpretation
17 November 2026 final-string publicationClarifies strings and contention after replacement periodIdentify auction exposure
Evaluation, objections and contentionSeparates attempted acquisition from authorizationDo not equate applications with delegated TLDs
Registry contracts and actual launchesReveal operating commitments and deploymentTest genuine utility
Registration and renewal performanceTests lasting market demandDistinguish durable adoption from promotions
AI identity and agent standardsDetermine any actual DNS dependencyTest future-option hypotheses
ICANN audited financial reportingClarifies collections, expenditures and auction fundsAssess cost recovery and accountability
Analytical bottom line: A new gTLD can be valuable as a strategic control position despite negligible direct traffic, but value is contingent on contractual rights, feasible deployment, competing uses and ongoing costs. The $366.6 million figure is a gross standard-fee equivalent, not audited ICANN income or profit.

PILLAR I — THE ECONOMICS OF ARTIFICIAL SCARCITY AND INSTITUTIONAL CONTROL

Chapter 1. ICANN’s Economic Architecture: Governance, Fees, Auctions and Financial Incentives

The central institutional paradox: a nonprofit organization administering a market for scarce digital resources

The economic architecture of the Domain Name System rests on a structural contradiction that deserves considerably greater attention than the price of individual Internet extensions. ICANN, the Internet Corporation for Assigned Names and Numbers, is a California nonprofit public benefit corporation whose mission includes coordinating the stable and secure operation of the Internet’s unique identifier systems. Yet the mechanism through which new generic top-level domains are introduced requires applicants to pay substantial fees, compete for desirable naming resources, and assume long-term contractual obligations within an infrastructure whose global interoperability depends on centralized coordination.

This arrangement should not be confused with a conventional commercial monopoly. ICANN does not own every word that can appear to the right of the final dot in an Internet address, and it cannot simply sell unrestricted property rights over dictionary terms. Nevertheless, its position in the globally coordinated DNS creates an institutional gatekeeping function of considerable economic importance.

An applicant cannot obtain an ordinary globally recognized new gTLD merely by registering a company, establishing a web server or creating a proprietary database. It must satisfy the applicable program rules, undergo evaluations, resolve objections and contention, execute a registry agreement, and complete technical delegation procedures.

The resource being allocated is therefore not a physical asset whose quantity is determined by geological or industrial constraints. It is a position in a globally coordinated logical infrastructure.

Although the DNS could technically accommodate many additional labels, the number of operationally delegated, commercially recognizable and contractually authorized top-level domains remains limited by technical standards, policy decisions, the application process and market conditions.

The resulting scarcity is institutional and positional rather than simply physical. A particular top-level string must be unique within the relevant DNS root. Multiple applicants can compete for .example, but they cannot all independently operate the identical extension in the same coordinated root.

That uniqueness gives even an otherwise inexpensive sequence of characters the potential to acquire substantial strategic value.

The central institutional question is whether the process allocates this resource in a manner that maximizes public utility, technical stability and fair competition—or whether the administrative structure unintentionally encourages businesses to spend increasingly large sums defending positions whose social value remains uncertain.

The distinction matters because these two outcomes can coexist. A technically successful expansion could generate considerable administrative revenue and many new registry agreements while producing a much smaller increase in actual Internet utility.

ICANN’s authority is contractual and institutional, not absolute digital sovereignty

ICANN’s influence is frequently overstated in public discussions. It is neither a world government for the Internet nor a conventional governmental licensing authority exercising unlimited jurisdiction over online activity.

Its governance architecture combines corporate authority, community-developed policy, contractual obligations, technical coordination and accountability mechanisms.

The organization coordinates the DNS naming system within a broader institutional environment involving the Internet Assigned Numbers Authority functions, the DNS root zone, standards bodies, registries, registrars, infrastructure providers and national authorities.

The U.S. jurisdictional connection remains consequential. ICANN is incorporated in California and operates under applicable U.S. law. However, the 2016 IANA stewardship transition ended the earlier contractual supervisory arrangement under which the U.S. National Telecommunications and Information Administration exercised a specific stewardship role over the IANA functions.

ICANN’s authority consequently cannot accurately be described as an ongoing U.S. government franchise to sell Internet names. Nor does the end of direct NTIA stewardship eliminate the relevance of U.S. law, judicial jurisdiction, sanctions requirements or political influence.

The foundational institutional framework is established through ICANN’s Articles of Incorporation, Bylaws, community policy processes and agreements with contracted parties.

Primary institutional reference: ICANN — Articles of Incorporation, Bylaws and Governance Documents.

For economic analysis, the institutional architecture can be divided into distinct functions.

Institutional actorFunctionEconomic influenceStructural limitation
ICANN BoardCorporate governance and major institutional decisionsProgram authorization, funding policies, oversightBylaws, accountability mechanisms, applicable law
ICANN organizationProgram execution, contracts and complianceEvaluation costs, fee administration, implementationApproved policies, contracts and budget controls
Generic Names Supporting OrganizationGeneric-name policy developmentPolicy rules shaping market entry and competitionCommunity procedures and Board consideration
Governmental Advisory CommitteePublic-policy adviceGovernmental concerns, sensitive strings, public-interest safeguardsAdvisory role within ICANN’s governance framework
Registry operatorsAdministration of delegated TLDsWholesale registration revenue, namespace policyRegistry agreements and applicable consensus policies
ICANN-accredited registrarsRegistration services for customersRetail pricing, distribution and customer relationshipsAccreditation and registry-registrar agreements
Registry service providersTechnical back-end servicesInfrastructure costs, scale economies, switching dependenceTechnical, contractual and program requirements
RegistrantsRegistration and use of second-level domainsDemand, renewals, actual economic utilityContractual rights rather than ownership of the DNS
Governments and courtsNational legal and regulatory authorityCompetition, intellectual property, sanctions and complianceJurisdictional and international legal constraints

The distinction between ICANN, registry operators, registrars and end users is essential because each occupies a different position in the financial chain.

A dollar paid by a consumer for a domain registration does not become a dollar of revenue for ICANN. A dollar paid to ICANN for application evaluation does not represent a domain registration. An auction payment does not create a retail product or demonstrate market demand.

These separate financial flows must be reconciled before drawing conclusions about institutional profitability, sector investment or consumer welfare.

The 2026 program establishes an unusually revealing financial experiment

The application window opened on 30 April and closed on 12 August 2026. The program’s latest authoritative Applicant Guidebook was published on 7 October 2026 as version V3-2026.10.07.

That version governs the application procedures, evaluation conditions and contractual pathways relevant to the current round.

Source: ICANN — 2026 Round Applicant Guidebook, Version V3-2026.10.07, 7 October 2026.

A critical numerical distinction arises from the sequence of official disclosures.

On 22 September 2026, ICANN reported that 1,663 applications had been submitted and 1,616 had satisfied the payment condition necessary to proceed. On Reveal Day, 7 October, its public application statistics reported 1,615 active applications associated with 481 applicants.

The September and October figures therefore represent different reporting dates and process states; they should not be treated as interchangeable observations or averaged.

Sources: ICANN — Confirmation of Applications Proceeding, 22 September 2026 and ICANN — 2026 Application Statistics, 7 October 2026.

The sequence establishes three commercially important facts.

First, submitting an application and successfully entering the paid evaluation population are distinct events.

Second, application counts can change as eligibility, payment and administrative processes advance.

Third, the number of applicants does not equal the number of independent economic decision-makers, because individual corporate groups may control multiple applying entities and a single applicant may pursue several strings.

Without a verified ultimate-ownership reconciliation, concentration cannot be measured accurately merely by dividing applications by applicants.

The real economic structure of ICANN’s application fees

The $227,000 standard evaluation fee is not a simple purchase price. It finances a defined package of evaluations and program administration.

ICANN identifies activities including background screening, DNS stability evaluation, financial and operational evaluation, geographic-name identification, legal compliance, reserved-name checks, name-collision analysis, registry-service-provider review, safeguard assessment, string similarity review and variant evaluation.

Conditional or elective procedures fall outside the standard fee and may require additional payments.

Source: ICANN — gTLD Evaluation Fee Frequently Asked Questions, 2026.

The published cost structure is especially useful because it reveals that the program is not uniformly priced once the different procedural pathways are considered.

Table 1.1 — Selected verified evaluation charges

ProcedurePublished feeTrigger or conditionFinancial implication
Standard application evaluation$227,000Ordinary applicationPrincipal initial entry cost
.Brand eligibility evaluation$500Specification 13 eligibility assessmentAdditional classification cost
Code of Conduct exemption evaluation$400Applicable exemption requestAdditional compliance assessment
Community Priority Evaluation$52,936Eligible voluntary community-priority processSignificant incremental evaluation expense
Geographic Names ReviewUp to $12,000Applicable geographic-name reviewConditional public-authority-related expense
Registry Commitments Evaluation$15,000Applicable voluntary commitments or community registration policiesAdditional contractual compliance expense
High-risk name-collision mitigation evaluationEstimated $100,000–$150,000Qualifying high-risk mitigation submissionPotentially material increase in application cost
Re-evaluation following qualifying changesActual applicable costCertain changes after evaluationVariable, case-dependent exposure

Source: ICANN — Official 2026 gTLD Evaluation Fee Schedule and Conditional Evaluation FAQs. The fees are conditional, not universally additive; estimates are not final invoices.

A major analytical consequence follows: two applicants paying the identical standard evaluation fee may face very different total costs by the time their applications reach contracting.

One may require only relatively straightforward evaluation. Another may encounter contested geographic status, registry commitment reviews, a community-priority proceeding, name-collision mitigation, objections or an auction.

The headline price therefore understates the dispersion of actual capital requirements.

Refund provisions change the risk structure of an application

One of the most important and least appreciated components of the 2026 economic framework is the declining refund schedule.

A standard applicant does not necessarily lose the entire $227,000 immediately upon filing. However, its recoverable amount declines substantially as the application progresses.

Table 1.2 — Application withdrawal economics

Withdrawal stageEligible refundIrrecoverable portion of standard feeIrrecoverable share
First refund window$147,500$79,50035.0%
Second refund window$79,500$147,50065.0%
Third refund window$45,400$181,60080.0%
No applicable refund entitlement$0$227,000100.0%

The first window extends to ten days after String Confirmation Day. The second runs from eleven days after that event until the beginning of applicant and application evaluation. The third extends from the start of that evaluation until the applicant enters a registry agreement, subject to the program’s specific conditions.

Calculated percentages use the $227,000 standard fee and exclude other costs.

Source: ICANN — Evaluation Fee Refund Windows and Withdrawal Conditions, 2026.

This schedule has a significant behavioral consequence.

An application becomes progressively more financially committed as it advances.

At the outset, the applicant can terminate its participation while recovering a substantial portion of the standard evaluation fee. Later, the refundable balance contracts, increasing the sunk cost associated with withdrawal.

In classical economic reasoning, sunk costs should not determine whether an applicant proceeds with an investment whose expected future return has become negative. The relevant decision is whether the benefits of continuing exceed the additional costs and risks from that point forward.

In practice, however, escalation of commitment may occur. Applicants may become reluctant to abandon a project after investing substantial sums in evaluation, legal advice, management attention and commercial planning.

ICANN’s rules do not necessarily cause that behavior, but they create a financial sequence in which governance quality at the applicant level becomes increasingly important.

The volume-refund provision is economically consequential

ICANN’s 2026 fee guidance provides for a possible application-volume refund where the program receives more than 1,000 applications and implementation costs have been recovered.

The announced application volume exceeds that threshold. This does not automatically establish a particular refund amount or guarantee that a refund will be paid, because the relevant cost-recovery conditions still apply.

Nevertheless, the provision is material to any assessment of ICANN’s institutional financial incentives.

It indicates that the standard fee has not been structured as an unconditional entitlement to retain the same amount per application regardless of total participation.

The relevant questions become whether projected costs were reasonable, whether actual expenses are properly allocated to the program, how common costs are treated, and whether any resulting surplus is returned or otherwise managed according to the approved framework.

Source: ICANN — Application Volume Refund and Cost-Recovery Provisions, 2026.

A meaningful financial audit should distinguish anticipated program expenditure, actual expenditure, fee collections, refunds, restricted funds, program reserves and transfers between designated funding categories.

An accounting presentation that groups these components together without reconciliation could seriously distort the program’s actual economics.

Auction proceeds and the financial consequences of contested strings

Auction activity introduces a separate dimension that cannot be understood through evaluation fees alone.

The auction mechanism does not establish the intrinsic commercial value of a top-level domain. It establishes a competitive allocation price among eligible participants under the applicable rules.

That distinction is fundamental.

If several applicants believe a particular string has strategic importance, their willingness to pay can exceed the present value of foreseeable domain-registration income. An auction can consequently produce a high price even where the eventual registry is expected to have limited public use.

Auction proceeds are not equivalent to ordinary application fees because they arise from contention, depend on competitive bidding and may be subject to different financial treatment.

The historical record demonstrates the amounts involved.

In its 26 March 2026 Board proceedings, ICANN reported that the 2012 application round had involved 16 auctions of last resort, generating approximately $225 million in auction proceeds.

Those proceeds have been treated as designated funds, with decisions about their use subject to institutional processes.

The same Board record confirms the earlier authorization of up to $5 million to support eligible applicants in the new round and an additional allocation of up to $4.9 million, approved in March 2026, to expand available support.

Source: ICANN — Minutes of the Special Board Meeting, 26 March 2026.

This makes it necessary to distinguish at least four different financial aggregates.

Table 1.3 — Financial quantities that must not be confused

Financial measureEconomic meaningAppropriate interpretationInappropriate interpretation
Gross evaluation fees invoicedCharges assessed to applicantsProgram billing volumeNet income
Evaluation fees ultimately retainedFees after applicable refunds and adjustmentsRetained program resources before expensesOperating profit
Gross auction proceedsWinning payments in ICANN auctionsProceeds generated by contention allocationRecurring revenue
Auction-proceeds fund balanceRemaining designated funds, including relevant financial activityAvailable fund stock at a reporting dateTotal historical auction receipts
Registry fixed feesPeriodic charges under applicable registry agreementsContractually generated operating inflowsProfit from a particular registry
Registry transaction feesCharges associated with qualifying registration transactionsActivity-linked contractual inflowsConsumer retail spending
Investment earningsReturns on funds under managementFinancial income attributable to held assetsNew application demand

The allocation of historical auction proceeds to support future applicants reveals an unusual financial relationship between application rounds.

Competition in an earlier round generated funds that can help reduce participation costs in a later round.

From a public-interest perspective, such recycling may improve access to the naming system. From an economic-governance perspective, it raises questions about whether the financing of entry assistance should depend on revenues generated by scarcity-based competition.

Neither conclusion is automatic. The relevant issue is the institutional design of financial allocation, not simply the existence of auction receipts.

The 2026 prohibition on private contention settlements changes the allocation market

The rules governing contested strings have materially changed the strategic options available to applicants.

Under the 2026 framework, private auctions, joint ventures and other arrangements designed to resolve contention privately are prohibited. Contention must be resolved through the mechanisms authorized by ICANN, including Community Priority Evaluation where relevant and ICANN-administered auctions where required.

Source: ICANN — Can Applicants Resolve Contention Privately?, June 2026.

The economic significance is considerable.

A system permitting privately negotiated contention settlements can create opportunities for applicants to obtain compensation for withdrawing. Such arrangements may give certain applicants a reason to enter disputes primarily for the possibility of receiving a settlement.

Restricting these arrangements reduces the ability to monetize a losing position through a private settlement, although it does not eliminate the incentives for strategic bidding.

The reform also changes the distribution of financial benefits from contention. Instead of allowing parties to allocate all settlement value privately, the authorized auction mechanism can produce proceeds governed by ICANN’s financial arrangements.

This is not proof that the reform was designed to increase institutional receipts. There are independent policy reasons for prohibiting private contention settlements, including concerns about fairness, gaming and transparency.

Nevertheless, the destination of auction proceeds remains an economically important consequence of the policy.

Community priority introduces a non-price allocation mechanism

An ordinary auction allocates the contested resource according to the applicable bidding process. Community Priority Evaluation introduces a different principle.

An eligible community-based applicant can seek priority by demonstrating that it satisfies specified criteria relating to community establishment, the relationship between the proposed string and the community, registration policies and community support.

The stated evaluation fee is $52,936 under the 2026 schedule.

A qualifying community-priority outcome can eliminate the need for an auction against other standard applicants in the relevant contention set.

This means financial bidding capacity is not the only possible determinant of allocation.

That distinction is especially important for linguistic, cultural, professional and community applicants that may have a legitimate interest in a namespace but lack the resources to compete against large commercial organizations.

Community priority does not eliminate the financial burden of applying. It introduces a qualified institutional exception to allocation purely through price.

Source: ICANN — 2026 Conditional Evaluations and Community Priority Evaluation Fees.

Applicant support as an instrument of market-access policy

The Applicant Support Program represents an attempt to reduce entry barriers for qualifying participants.

Supported applicants can receive evaluation-fee reductions ranging from 75% to 85%, together with specified forms of nonfinancial assistance. ICANN has also identified possible bid credits and reduced or waived base registry fees for qualifying successful applicants.

These measures address different components of the entry problem.

A reduction in application fees helps an applicant enter the evaluation process. Technical assistance helps it understand and satisfy the program’s requirements. A bid credit addresses disadvantage in an applicable contention auction. Reduced recurring registry charges can improve post-delegation economic sustainability.

It would therefore be analytically incorrect to describe applicant support as merely a discount on the initial application price.

The published support architecture recognizes that disadvantage can persist through evaluation, competition and operation.

Source: ICANN — Board Resolution and Rationale on Applicant Support Funding, 26 March 2026.

At the same time, eligibility for institutional assistance does not guarantee a sustainable business model.

A supported applicant may still need financing for technical services, marketing, professional advice, ongoing compliance and customer acquisition.

The proper measure of program effectiveness is therefore not simply the number of supported applications admitted into evaluation.

It is the extent to which supported participants ultimately achieve technically sound, financially sustainable and genuinely useful registry operations.

The fiscal incidence of the $227,000 charge

The legal payer of an application fee is generally the applicant. Its ultimate economic incidence, however, depends on the applicant’s business model.

A corporate brand owner may absorb the charge within its marketing, technology, risk-management or intellectual-property budget.

A commercial registry operator may attempt to recover the expenditure through future domain registrations, premium-name transactions or associated services.

An organization financed by investors may capitalize the expected strategic value of the application, subject to applicable accounting rules and the uncertainty of eventual delegation.

A consortium or community institution may rely on contributions or grants.

The cost can therefore be borne by different economic stakeholders even when ICANN charges an identical nominal fee.

Table 1.4 — Who ultimately bears application and operating costs?

Applicant modelInitial funding sourcePossible ultimate cost bearerPrincipal financial exposure
Corporate brandCorporate treasury or business-unit budgetShareholders, indirectly customersExpenditure without measurable incremental benefit
Commercial registryEquity, debt or sponsor fundingInvestors and future registrantsFailure to recover capital
Community registryInstitutional funds, grants, contributionsSupporting organizations or membersLong-term sustainability
Government-linked entityPublic or authorized institutional resourcesRelevant public institutionPublic-value accountability
Venture-backed naming businessInvestment capitalEquity investorsValuation and exit-risk exposure
Applicant supported by ICANN mechanismsApplicant plus eligible support resourcesMultiple stakeholdersDependence on continuing finance and operational capability

The consequences differ for each category. The evaluation charge is a sunk investment for a successful company that does not use its extension. For a commercial operator, it is part of a capital-recovery problem. For a publicly funded applicant, it may be an expenditure requiring justification through cultural, institutional or economic-policy objectives.

This is why applying a single profitability criterion to all applications would produce misleading conclusions.

The institutional incentive problem: where scrutiny should be directed

ICANN’s declared cost-recovery model creates an important counterargument to claims that it necessarily benefits from maximizing application numbers.

Under an effectively enforced cost-recovery arrangement, surplus collections should be addressed according to applicable rules rather than automatically distributed as commercial earnings.

But nonprofit status does not eliminate every potential institutional incentive.

Organizations can face incentives to expand operational programs, justify staffing, develop administrative capacity, preserve institutional relevance or pursue activities viewed by their governing bodies as strategically desirable.

These incentives do not establish misconduct. They are common questions in institutional economics and nonprofit governance.

The appropriate scrutiny concerns whether financial decisions are transparent, proportionate and demonstrably related to institutional functions.

A credible review would examine the following distinctions.

Table 1.5 — Institutional accountability test

Governance questionEvidence requiredPotential concernInterpretation if controls are effective
Is the evaluation fee cost-based?Approved budgets, allocation methods and actual expendituresExcessive or poorly allocated chargesEconomically defensible cost recovery
Are external vendor contracts efficient?Procurement records, deliverables and paymentsOverpriced administrationProportionate execution costs
Are refunds calculated consistently?Applicable policy, reconciliation and payment recordsRetention beyond justified amountsPredictable and auditable refunds
Are auction funds segregated?Financial statements, Board resolutions and fund recordsUnclear use of exceptional receiptsTransparent designated financing
Are affiliated interests disclosed?Conflict-of-interest records and governance documentationUndue influence over allocation rulesDocumented recusals and accountability
Are entry barriers proportionate?Cost evidence, participation data and applicant outcomesUnnecessary exclusion of smaller participantsFinancial standards tied to operational risk
Is competition actually improved?Operator ownership, registration demand and distribution dataMore suffixes without more effective competitorsDemonstrable increase in meaningful choice
Are security obligations effective?Compliance findings, incident data and remediationAdministrative expansion exceeding oversight capacityTechnical growth accompanied by enforceable safeguards

One major evidentiary limitation should be preserved: the 2026 program has not progressed far enough to establish its final costs, net fee retention, auction proceeds or financial outcomes.

Consequently, a conclusion that ICANN has already earned a particular profit from the 2026 round would be unsupported.

Chapter 1 — Key judgments

ICANN administers a global naming allocation system in which technical uniqueness, contractual eligibility and institutional policy produce economically valuable positions.

Its income streams cannot be assessed as a single undifferentiated category. Evaluation payments, auction proceeds, recurring registry charges and investment returns have different accounting and governance characteristics.

The refundable portion of the standard application fee declines through the evaluation process, increasing the importance of staged investment governance.

The 2026 prohibition on private contention settlements materially changes the incentives and possible financial outcomes associated with contested strings.

The Applicant Support Program can reduce entry barriers, but its success must ultimately be evaluated through operating outcomes rather than participation counts alone.

The central institutional risk is not the mere existence of substantial fees. It is the possibility that the economic burden of participation becomes increasingly disconnected from demonstrable public benefits, while administrative complexity and financial dependence reinforce one another.

What would change the Chapter 1 assessment?

The assessment would change materially if the program’s audited financial reconciliation demonstrated substantial unexplained surpluses, systematic cross-subsidization inconsistent with approved policies, or cost allocations that could not be supported by actual program activities.

It would also change if transparent audited evidence demonstrated that program expenses, refunds and financial safeguards functioned consistently with the adopted cost-recovery framework and that participation generated measurable benefits for competition and DNS utility.

The relevant official record consists of final program expenditure reports, Board financial decisions, relevant audited statements, conditional-evaluation expenditures, auction proceeds and refund reconciliations.

Chapter 2. The $227,000 Decision: Scarcity, Option Value, Defensive Acquisition and Corporate Strategy

Why an unused namespace can be a rational corporate investment

For a large corporation, the economic value of a top-level domain may be highest precisely when it is not made broadly available to the public.

That proposition initially appears counterintuitive because conventional Internet business models associate domain value with traffic, registrations, customers, transactions or advertising.

A controlled corporate namespace operates under a different financial logic.

The business may have no intention of selling domain names. Its priority may be to limit ambiguity about which digital resources are authorized, preserve corporate naming flexibility, establish a distinctive hierarchy for future services or prevent another eligible participant from obtaining a strategically important position.

The correct question is therefore not whether the extension will attract substantial public traffic.

It is whether the present value of the incremental corporate benefits exceeds the cost and risk of acquiring and operating it.

The economics are analogous to certain defensive intellectual-property and infrastructure investments, but the analogy has limits. A gTLD is not an ordinary trademark, and ICANN’s allocation of a registry does not grant unlimited exclusivity over a commercial concept.

Nevertheless, a company may rationally invest in an asset that produces no direct cash revenue if it avoids larger expected costs elsewhere in the enterprise.

The economic distinction between use value, option value and exclusion value

Three components require separate valuation.

Use value arises from actual or planned operational deployment. An organization may create a naming system for products, customer services, regional operations or affiliated entities.

Option value arises from preserving the ability to deploy such services in the future, even if the business does not yet know whether they will be required.

Exclusion value arises from reducing the possibility that another eligible applicant will control the relevant top-level label.

These sources of value can overlap, but they must not be added indiscriminately.

For example, an applicant may claim that a registry protects its brand and preserves future operational freedom. If both benefits depend on avoiding the same underlying threat, assigning the full value of that avoided threat to both components would double-count the investment’s benefit.

A rigorous valuation must identify the underlying economic events, estimate their incremental consequences and avoid attributing the same future cash flow to multiple categories.

.Brand eligibility creates a distinctive class of controlled infrastructure

ICANN’s Specification 13 establishes special contractual provisions for qualifying brand top-level domains.

The qualification requires, among other conditions, a connection with a registered trademark and restrictions under which the registry operator, its affiliates or trademark licensees are the registrants of names within the TLD.

The applicable provisions distinguish a brand namespace from an ordinary open commercial registry.

Source: ICANN — Base Registry Agreement Specification 13, Updated 30 April 2023.

This has several practical consequences.

A qualifying corporation can maintain a controlled registration environment rather than competing for retail domain-registration volume.

It can establish policies governing which corporate entities or authorized licensees receive names.

It can deploy a structured naming hierarchy aligned with organizational control, subject to the governing agreements and applicable technical standards.

It can also decline to create a large population of publicly accessible websites without necessarily undermining the economic purpose of its registry.

However, qualification under Specification 13 does not create immunity from technical failure, phishing, misleading communications, compromised infrastructure or contractual responsibilities.

Nor does it mean every name appearing under a brand TLD is automatically trustworthy. Trust still depends on operational security, authentication and governance.

The first corporate decision: how much is future flexibility worth?

A company considering a new gTLD should separate the acquisition decision from the deployment decision.

The acquisition decision asks whether preserving the opportunity to obtain and operate the namespace is worthwhile.

The deployment decision asks when, whether and how the company should use that namespace operationally.

These decisions may occur years apart.

That separation is especially important for technology businesses facing uncertain product development.

A business may reasonably expect that future activities will require a more formal namespace architecture but may be unable to identify the exact structure today.

The investment then resembles a real option: the company pays an initial amount for a conditional future opportunity.

But the real-option analogy does not imply that every application has positive value.

The option has value only if the expected opportunities and avoided disadvantages outweigh the acquisition and carrying costs, taking into account the possibility that the option expires, the application fails or the proposed infrastructure becomes obsolete.

A structured real-option model

Consider the following simplified expression for the decision to apply:

Capital Allocation & Decision Theory

Stochastic Net Present Value (NPV) Framework for String Application

Evaluation of multi-period cash flows, regulatory gate risk, post-delegation operating overhead, and probability-weighted expectation paths.

Capital Valuation Identity
NPVapply = −C0 + ∑t=1T 𝔼[Bt − Ct](1 + r)t
Discounted expected value model explicitly conditioned on contingent operational states and non-guaranteed string delegation pathways

Model Parameters & Variable Specifications

−C0
Sunk Front-End Commitment

Total capital outlay disbursed at inception (t=0). Encompasses statutory evaluation fees, legal vetting, consulting, community objection defenses, and technical application design.

Bt
Gross Periodic Inflows

Incremental corporate value realized in period t, including internal security efficiencies, avoided third-party defensive registrations, brand positioning, and commercial registry revenues.

Ct
Ongoing Maintenance Costs

Post-delegation recurring costs incurred in period t: annual ICANN registry maintenance fees, Registry Service Provider (RSP) technical infrastructure, escrow contracts, and compliance operations.

r & T
Hurdle Rate & Horizon

r: Cost of capital adjusted for programmatic, regulatory, and technical risk.
T: Bounded life-cycle appraisal window (typically 5 to 10 years aligned with the initial Registry Agreement term).

⚠ State-Contingent Expectation Dynamics (𝔼)

A common capital budgeting failure is treating delegation as a deterministic state. The expectation operator 𝔼[Bt − Ct] requires calculating the weighted mean across mutually exclusive terminal pathways:

Path A: Successful Delegation P(Success) = p

Clears initial evaluation, resolves contention (if any), executes agreement, and enters root zone. Generates intended operational and commercial stream (Bt − Ct).

Path B: Rejection, Loss, or Withdrawal P(Failure) = (1 − p)

String contention loss, string similarity review failure, GAC consensus advice block, or strategic withdrawal. Yields zero downstream operating cash flows, resulting in a net loss equal to unrefunded C0.

Analytical Takeaway: Valuing an unapproved registry candidate without explicit risk-weighting overstates project NPV by systematically ignoring sunk contention settlement outlays and procedural rejection probability.
Corporate Finance Model: Strategic Intangible Asset Appraisal Governance Scope: gTLD Delegation Lifecycle Analysis

For strategic investments, some benefits may not be directly observable in revenue accounts. A defensible valuation can still be constructed using bounded scenarios, counterfactual operating costs and explicitly stated assumptions.

However, qualitative strategic importance should not be converted into fabricated dollar values merely to produce a favorable net present value.

An illustrative five-year decision case

Assume a hypothetical multinational company considers applying for a brand TLD with the following purely illustrative financial assumptions.

The company pays the standard $227,000 application fee. It also expects $500 for the relevant brand eligibility evaluation and $5,000 in preparatory external expenditure. These assumed amounts exclude contingent objection or auction costs.

After successful delegation, the company expects annual registry-related expenditure of $60,000, comprising the standard $25,000 ICANN fixed-fee benchmark and an assumed $35,000 for other incremental operations and administration.

The company adopts a five-year operating horizon and a nominal discount rate of 10%.

The annual benefits are uncertain. The relevant decision is therefore the value of avoided corporate expenditures or strategic opportunities that must be realized to justify the investment.

The present value factor for a five-year annuity discounted at 10% is approximately 3.7908.

Initial investment: $232,500.

Present value of five years of assumed operating costs: approximately $227,447.

Total modeled present-value cost: approximately $459,947.

The equivalent annual benefit required over the five operating years is approximately $121,332.

These are calculations from illustrative assumptions, not ICANN forecasts or observed costs.

The result is analytically revealing.

A company does not need a commercially successful registration business to justify this investment. It needs to demonstrate that the namespace is expected to create or preserve approximately $121,000 per year in incremental corporate value under the modeled assumptions.

For a global organization operating complex digital infrastructure, that threshold may be modest relative to the scale of its business.

For a small enterprise, it could be financially prohibitive.

The relevant comparison is not the absolute size of the fee but the expected benefit relative to the company-specific counterfactual.

Table 2.1 — Sensitivity of the five-year investment case

The table below retains the assumed initial expenditure of $232,500, five years of operation and a 10% nominal discount rate. Annual costs and benefits are illustrative.

Annual operating costPresent-value total costRequired equivalent annual benefit
$40,000$384,132$101,334
$60,000$459,947$121,333
$100,000$611,579$161,333
$150,000$801,119$211,333

The table demonstrates a structural result: once an applicant commits to operating a registry, the initial evaluation charge may be only one element of a longer-term operating obligation.

For companies with substantial digital infrastructure, the investment decision should be connected to an integrated technical and commercial plan rather than treated as an isolated branding exercise.

Defensive acquisition is not automatically valuable

The defensive argument is often presented too broadly.

A company may argue that it should apply for a string because another party might acquire it. However, the economic relevance of that possibility depends on whether another party would actually be eligible to operate the string and whether such operation would produce a material adverse consequence.

A legally protected brand string is different from a generic word.

Under the 2026 program, closed generic applications are prohibited unless an approved public-interest methodology and criteria are established. The rules therefore constrain a company’s ability to obtain a generic label for exclusively private operation.

Source: ICANN — Applicant Guidebook, Module 3: Application Submission and Closed Generic Restrictions.

This means the maximum defensive value of a proposed TLD cannot be inferred solely from the attractiveness of its wording.

For a qualified brand, the relevant comparison may involve the costs of future identity protection, organizational control and potential brand-related disputes.

For a generic string, the relevant analysis must account for the public registration model, competition, legitimate third-party interests and the inability to obtain unrestricted private exclusive control.

The distinction is particularly important when assessing applications for technology-related terms.

A recognizable word such as an AI category name may be commercially desirable, but desirability does not establish that a single company can transform the entire category into an exclusive corporate naming environment.

The opportunity cost of not applying

In financial analysis, strategic decisions must consider the value of alternatives.

A company that decides not to apply may preserve capital and avoid considerable operating obligations.

It may continue using an established domain. It may deploy subdomains, acquire relevant ordinary domain names, adopt standardized digital credentials or invest in cybersecurity and brand enforcement.

In other words, the decision is not necessarily between acquiring a new gTLD and losing control of corporate Internet identity.

There are often several technically valid approaches to achieving the same business objective.

Table 2.2 — Alternative digital identity strategies

StrategyPrincipal investmentOperational controlDistinctive benefitImportant limitation
New brand gTLDApplication, evaluation and registry operationControlled top-level namespaceIndependent branded naming hierarchyHigh initial and recurring costs
Existing corporate domainDomain operation and securitySubdomains and associated resourcesEstablished architecture and recognitionNo separately delegated TLD
Defensive second-level registrationsRegistration and renewal feesPortfolio of names across existing TLDsBroad protection against selected naming conflictsPortfolio growth and management complexity
Trademark enforcementLegal monitoring and proceedingsRemedies against qualifying misuseRights-based protectionEnforcement costs and legal uncertainty
Digital certificates and identity controlsSecurity engineering and lifecycle managementAuthentication of services and resourcesTechnical verification independent of a new TLDDoes not itself provide a new namespace
Application or platform identityProduct and ecosystem expenditurePlatform-mediated service identitiesIntegration with existing users and developersDependence on platform operators

This comparison prevents the valuation of a new registry from becoming circular.

A company should not assume that every benefit of improved digital identity requires a new top-level domain when a less expensive architecture could potentially provide the same result.

The strategic significance of irreversibility and timing

The application window creates a timing problem.

A company may prefer to delay investment until the economic value of a namespace becomes clearer. Yet delaying may mean losing the opportunity to apply for the desired string during the current round.

The benefit of waiting must therefore be compared with the possibility of later unavailability.

That is the core real-options tension.

Waiting preserves information and capital. Applying preserves a conditional opportunity to obtain a particular string.

The optimal choice depends on the likelihood of future commercial relevance, the possibility of competing eligible applicants, the availability of alternatives and the expected timing of future application rounds.

The existence of a limited application period can make early commitment rational even when commercial deployment remains uncertain.

But the effect should not be exaggerated. An applicant has no guarantee of acquiring the name merely because it files within the window.

Application review, objections, contention and contracting remain consequential uncertainties.

Corporate portfolio strategy: multiple applications and marginal value

A company filing multiple gTLD applications should not value each one in isolation.

Several strings may protect overlapping brands, products, customer communities or service categories.

The relevant financial question is the incremental portfolio value created by each additional application.

Suppose a company considers five extensions. The first may provide a new corporate identity architecture. The second may protect a separate product brand. The third may offer a limited linguistic variation. The fourth and fifth may duplicate opportunities already covered by the first three.

The marginal value of additional applications can therefore decline even while total nominal expenditure rises linearly.

A suitable portfolio analysis should assess overlap, substitution and correlation among outcomes.

Table 2.3 — Hypothetical initial fee exposure by portfolio size

ApplicationsStandard evaluation feesAdditional modeled $500 brand evaluation per applicationCombined modeled evaluation expenditure
1$227,000$500$227,500
3$681,000$1,500$682,500
5$1,135,000$2,500$1,137,500
10$2,270,000$5,000$2,275,000
15$3,405,000$7,500$3,412,500
20$4,540,000$10,000$4,550,000

These are hypothetical fee calculations, not estimates of actual expenditure by identified applicants. They assume all applications qualify for and incur the $500 brand evaluation, with no discounts, refunds or other charges.

The table highlights the scale of portfolio-level decisions.

For a technology group, a collection of 15 applications implies more than $3.4 million in standard evaluation fees alone. The relevant investment committee should determine whether those applications support sufficiently distinct strategic objectives.

A uniform argument that every domain is essential for brand protection would not satisfy a rigorous marginal-value test.

Corporate governance should distinguish authorization, deployment and abandonment

The strongest corporate decision framework is a staged process.

An application should be authorized based on its expected option value and downside exposure.

Continuation through evaluation should require updated information about competition, eligibility, likely technical complexity and other costs.

Contracting should require a validated operating model, compliance ownership, service-provider arrangements and adequate long-term funding.

Operational deployment should require a genuine business or organizational use case.

Continued operation should be reviewed against benefits, risks, costs and available alternatives.

Table 2.4 — Investment gates for corporate applicants

Decision gateCore questionRequired evidenceAppropriate decision criterion
Application authorizationWhy acquire the option?Strategic rationale and alternativesExpected incremental value exceeds entry cost
Post-reveal assessmentHow has competition changed?Contention and eligibility informationContinuing remains superior to withdrawal
Pre-evaluation commitmentAre technical and financial conditions acceptable?Cost and operational diligenceFuture expected benefits exceed future costs
Pre-contract approvalCan the company responsibly operate the TLD?Supplier contracts, funding and compliance planSustainable operating capacity
Deployment authorizationWhat specific uses justify operation?Business cases and technical architectureMeasurable or defensible organizational benefit
Periodic portfolio reviewShould the registry continue?Actual cost, utilization and strategic relevanceContinuation exceeds alternatives and exit consequences

The refund schedule creates an additional reason to conduct these reviews before financially consequential program milestones.

When acquisition becomes value-destroying

Several conditions can make a strategically attractive name a poor investment.

The first is overestimation of competitor threats. An applicant may pay to prevent a scenario that is legally impossible, commercially implausible or adequately addressed by existing rights.

The second is duplication of infrastructure. A new namespace may reproduce functionality already available through existing domains without meaningful improvements.

The third is insufficient governance. The company may obtain a registry but fail to assign durable responsibility for operations, security, compliance and renewal decisions.

The fourth is technological obsolescence. A future product ecosystem may adopt discovery and identity mechanisms that do not materially benefit from the new extension.

The fifth is an escalation of commitment. Once the evaluation fee becomes largely unrecoverable, management may continue to spend because it is unwilling to recognize the loss on the original investment.

The sixth is auction-driven overpayment. A strategically attractive string can become economically unjustifiable if competitive bidding raises the acquisition cost above its expected incremental value.

These are different failure mechanisms and require different controls.

The existence of financial resources to pay an application fee does not demonstrate that the expenditure is economically rational.

Chapter 2 — Key judgments

A brand gTLD can be valuable without significant registration volume because its economic purpose may be operational control, corporate identity, defensive protection or future strategic flexibility.

The correct valuation is incremental and counterfactual. It must compare the expected benefits of the new namespace with what the organization could achieve through existing domains, technical identity mechanisms and other protective measures.

The application fee alone is insufficient for investment appraisal. Future operating costs, contingent evaluation expenses, the probability of unsuccessful allocation and the possibility of withdrawal must be included.

Multiple applications create portfolio-management problems. Their strategic benefits may overlap, and nominal expenditure grows faster than marginal value.

The decisive corporate discipline is to treat a gTLD application as a conditional infrastructure investment rather than a collectible digital asset whose value is presumed to appreciate.

What would change the Chapter 2 assessment?

Evidence of extensive operational deployment among brand registries would strengthen the proposition that independent corporate namespaces can create sustained organizational utility.

Evidence of persistent nondeployment, repeated abandonment or systematic reliance on existing domains despite substantial acquisition costs would weaken many operational-value claims.

The relevant records include executed registry agreements, registry operating histories, corporate deployment disclosures, disclosed registry terminations and comparable costs of alternative identity architectures.

Chapter 3. Commercial Registry Economics: Revenue, Renewal Risk, Market Concentration and Investment Returns

A registry is not a domain name: it is a regulated wholesale infrastructure business

The economics of a commercial top-level-domain registry are fundamentally different from those of a corporate brand namespace.

A commercial registry is not primarily seeking the right to use a name for its own activities. It seeks to operate a naming environment in which customers may register second-level domain names, subject to the registry’s eligibility rules, ICANN requirements and relevant contractual arrangements.

Revenue can arise from initial registrations, renewals, premium names, qualifying transfers and complementary services.

The registry’s commercial challenge is to establish durable demand while financing a combination of fixed infrastructure obligations, variable transaction costs, distribution expenses, marketing, compliance and customer retention.

The presence of a delegated TLD does not guarantee a commercially viable registration market. Technical availability is a necessary condition for sales, not sufficient evidence that buyers will value the product.

This produces a two-sided commercial challenge. Registry operators must persuade registrars and distribution partners to carry and promote their products while simultaneously persuading end users that the proposed extension is worth registering.

A new entrant may therefore face a difficult coordination problem: registrars have limited incentives to emphasize a product with little demonstrated demand, while customers may struggle to discover an extension with limited retail visibility.

The wholesale and retail distinction determines profitability

The price paid by a registrant is not necessarily the price received by the registry.

A registrar may charge retail fees incorporating its own costs, margins, payment-processing charges and bundled services.

The registry receives the wholesale amount specified by its commercial arrangements, subject to applicable fees and terms.

A useful simplified expression is:

Domain Channel Distribution & Retail Price Formation

Retail Price Structural Decomposition Model

An analytical breakdown of vertical value-chain cost allocations, downstream channel margins, and statutory surcharges across registrar distribution layers.

Retail Cost Formation Equation
Pretail = Pwholesale + Mdistribution + T
Additive model establishing final end-user subscription pricing across wholesale, channel, and statutory fiscal tranches

Decomposed Vector Elements

Pretail
Final Consumer Tariff

The total realized cash outflow incurred by the registrant at point of checkout, encompassing all renewal, initial creation, or renewal billing periods.

Terminal Transaction Value
Pwholesale
Registry Upstream Base

The statutory unit fee levied by the Registry Operator (RO), encompassing backend registry infrastructure maintenance, ICANN transaction fees ($0.18), and DNS operations.

Fixed COGS / Transfer Cost
Mdistribution
Channel Margin Aggregate

The gross economic rent captured by registrars and white-label resellers to absorb acquisition cost (CAC), merchant gateway fees, WHOIS compliance, and operating profit.

Intermediary Gross Spread
T
Taxes & Fiscal Levies

Statutory value-added tax (VAT), regional sales taxes, digital services taxes (DST), and mandated localized regulatory levies applied at point of invoicing.

Statutory Pass-Through

Channel Distribution & Economic Mechanisms

Asymmetric Loss-Leading Dynamics

In competitive initial registrations, registrars frequently set Mdistribution < 0 (loss-leading) to capture market share, subsidizing initial registration fees to secure downstream renewals or attach high-margin recurring services like hosting, workspace email, and SSL configurations.

Wholesale Floor Inelasticity

Unlike standard consumer retail goods where wholesale volume discounts are variable per unit, Pwholesale in generic TLDs is constrained by ICANN Registry Agreements and uniform volume pricing covenants, creating a non-negotiable marginal cost baseline for channel actors.

Jurisdictional Tax Elasticity

The surcharge term T varies dynamically based on registrar establishment nexus and registrant geolocation (e.g., standard EU VAT ranging from 17% to 27%), introducing cross-border price dispersion for an otherwise identical digital coordinate.

Model Framework: Registry-Registrar Direct Value Chain Modeling Scope: Standard gTLD & ccTLD Retail Pricing Structuring

This is an analytical identity, not a claim that all registrars use a uniform pricing formula.

The registry’s profitability must be calculated from the revenue it actually receives and the costs it actually incurs.

A domain sold to an end user for $30 may provide substantially less than $30 of revenue to the registry. Conversely, premium transactions may produce revenue far above ordinary registration prices.

Using retail website prices to estimate registry revenue without accounting for wholesale terms would therefore introduce a material valuation error.

ICANN’s contractual charges introduce both fixed and volume-related cost components

The 2024 Base Registry Agreement provides an important reference for the economics of registry operation.

Article 6.1 specifies a fixed registry fee of $6,250 per calendar quarter, equivalent to $25,000 annually.

It also provides for a registry-level transaction fee of $0.25 per qualifying annual increment of an initial or renewal domain registration. The transaction fee is subject to a threshold involving more than 50,000 qualifying transactions in a quarter or within four consecutive quarters.

The same agreement provides for additional fees in specified circumstances, including a $5,000 one-time Trademark Clearinghouse access fee under Article 6.4 and $0.25 for qualifying Sunrise and Claims registrations.

These are contractual provisions in the cited 2024 agreement and should not be interpreted as proof that every individual registry will face identical effective terms.

Source: ICANN — Base Registry Agreement, Articles 6.1–6.4, Approved 21 January 2024.

The economic significance of the transaction threshold is that the marginal ICANN cost associated with registrations can change as volumes increase.

For smaller commercial registries, fixed expenses may dominate the cost structure.

For registries with larger registration volumes, transaction-based charges, distribution economics and operational scale become increasingly important.

However, an increase in volume is beneficial only if contribution per transaction remains positive.

The principal revenue models

Commercial gTLD operators can adopt substantially different economic models even when they use the same underlying DNS infrastructure.

Table 3.1 — Commercial registry business models

ModelPrimary revenue mechanismRequired market behaviorMain risk
Mass-market registrationHigh registration and renewal volumeBroad consumer and business adoptionLow differentiation and pricing pressure
Sector-specific registrySales to defined industry or professional usersRecognition within the target sectorInsufficient addressable market
Premium-name strategyHigher-priced desirable second-level domainsBuyers attribute substantial value to specific namesConcentrated and irregular revenue
Geographic or community registryRegistrations connected to place or community identitySustained affinity and actual useLimited market size or eligibility restrictions
Portfolio operatorShared infrastructure across multiple TLDsSuccessful allocation and management of several extensionsCorrelated demand and portfolio complexity
Enterprise-oriented registryRegistrations linked to organizational applications or servicesInstitutional adoption and long-term useSlow sales cycles and concentrated customers
Promotional-growth registryDiscounted initial registrations followed by renewalsStrong customer conversion to standard pricingHigh first-year churn

These models should not be evaluated using a single registration-count benchmark.

A premium-name registry may produce meaningful revenue from a relatively small number of transactions.

A mass-market registry may require hundreds of thousands of registrations to achieve the same result.

A community-oriented registry may legitimately operate at a scale that would be unattractive to a venture-backed commercial investor.

The defining issue is the relationship between unit economics, customer retention and fixed operating obligations.

Domain registrations are a stock; renewals and new registrations are flows

A common error in evaluating the domain-name business is to confuse the number of domains currently registered with the number of domains purchased during a given period.

The active domain base is a stock measured at a particular date.

New registrations, renewals, expirations, deletions and transfers are flows or events occurring over time.

The distinction is essential because reported growth can conceal weak retention.

A registry can add a large number of new domains during a promotional campaign while simultaneously experiencing significant losses among previously acquired registrants.

The resulting active domain count may grow, remain stable or decline depending on the relative magnitudes.

A simplified annual registration-stock equation is:

Domain Registry Dynamics & Formal Inventory Accounting

Domain Stock-Flow Conservation Identity

Formalization of the discrete-time inventory balance for top-level domain registry assets, accounting boundaries, and inter-registrar transfer equilibrium.

Full Boundary Model Equation
Nt = Nt−1 + At − Dt + It − Ot
Discrete-time active domain registration state balance over interval (t−1, t]

Structural Parameters & Variable Definitions

Nt Terminal Active Stock

The total stock of active domain registrations existing at the exact closure of evaluation epoch t.

Nt−1 Base Period Inventory

The active baseline portfolio inventory carried forward from the close of prior epoch t−1.

At Gross Additions

Newly created registrations during window t, strictly excluding secondary transfers already accounted for.

Dt Permanent Deletions

Expirations, non-renewals, policy purges, and drop deletions permanently removed from the active stock.

It − Ot Net External Migration Flow

Applicable inward (It) and outward (Ot) cross-boundary migration vectors. For closed registry environments, this term resolves symmetrically to zero.

Boundary Mechanics: Individual TLD Zero-Sum Transfer Invariance

For any single autonomous Top-Level Domain (TLD), transfers occurring between retail accredited registrars do not modify registry-wide aggregate stock. An inbound transfer into Registrar A represents an identical outbound departure from Registrar B:

Transfer Equilibrium
It − Ot = 0
⇒
Reduced Registry Identity
Nt = Nt−1 + At − Dt
Registrar Micro-Level Scope When isolating a single registrar balance sheet, It ≠ Ot as transfers create direct market-share expansion or churn.
Registry Macro-Level Scope At the TLD registry level, domain migrations represent zero-sum internal reallocations that leave total registered stock Nt invariant.

The appropriate reconciliation depends on the registry’s reporting definitions.

A registration stock can also contain multiple-year registrations, while ICANN transaction measures may count annual registration increments. These quantities are not automatically equivalent.

Renewal quality is a better indicator of durable demand than promotional acquisition

A registry that registers one million names through deeply discounted promotions does not necessarily have a more valuable business than a registry with 100,000 customers paying sustainable renewal prices.

The economically relevant variables include:

  • Net revenue per customer or registration.
  • Renewal probability by acquisition cohort.
  • Gross and contribution margin.
  • Customer acquisition cost.
  • Distribution costs.
  • Average registration duration.
  • Premium-name concentration.
  • Domain usage and customer engagement.
  • Exposure to promotional pricing.
  • Actual cash conversion.

The most useful renewal metric is cohort-based retention.

A domain acquired in January should be tracked through subsequent renewal opportunities rather than aggregated with entirely different cohorts.

This permits analysis of whether new customers acquired through promotions behave differently from customers purchasing at standard prices.

Table 3.2 — Hypothetical renewal sensitivity

Assume a registry begins with a cohort of 100,000 one-year registrations and receives no new registrations. The following table illustrates the remaining registration stock if every annual renewal opportunity has a constant cohort-retention rate.

Annual retention rateAfter 1 renewalAfter 2 renewalsAfter 3 renewalsAfter 5 renewals
50%50,00025,00012,5003,125
65%65,00042,25027,46311,603
80%80,00064,00051,20032,768
90%90,00081,00072,90059,049

Illustrative mathematical model: 100,000 × retention rate raised to the number of renewal cycles. No claim is made that these are observed retention rates for the 2026 applicant population.

This simple sensitivity illustrates why the first renewal cycle can be decisive.

At 50% annual retention, only 3.1% of the original cohort remains after five consecutive renewal opportunities.

At 90%, approximately 59% remains.

A registry may therefore report impressive initial sales while having a much weaker future recurring-revenue base than those sales suggest.

The economic benefit of high retention is compounded over time.

Renewal behavior also reveals whether registrants have genuine use cases

There are several reasons why a registered domain might not correspond to an actively used website.

A domain may support email, internal services, redirection, defensive protection, future development or technical functions that are not visible through ordinary web browsing.

A domain without an active public website is therefore not necessarily commercially worthless.

Nevertheless, use indicators can help distinguish durable utility from purely speculative registration behavior.

A registry with high renewal rates and substantial operational use may demonstrate sustainable demand even if its growth is modest.

A registry with rapidly increasing registrations but poor retention and extensive short-lived promotional activity may instead be accumulating nominal volume without building a durable business.

ICANN’s competition and consumer-trust measurement programs have historically recognized the relevance of registration counts, resolving domains, market choice and other indicators.

Source: ICANN — Competition, Consumer Trust and Consumer Choice Metrics.

The principal methodological caution is that resolution is not the same as economic productivity. A resolving domain can serve spam, parking or automated content; a nonresolving domain can still perform a legitimate defensive function.

Multiple indicators are required.

A full commercial cost model

A registry’s cost structure extends beyond ICANN fees.

The operator must obtain and maintain the technical capacity to run the registry and fulfill contractual obligations. It may perform these functions itself or obtain them from a registry service provider.

External services may include DNS infrastructure, registry database administration, provisioning interfaces, operational monitoring, data escrow, incident response and compliance support.

Additional expenses may arise from registrar relationships, customer service, marketing, legal advice, insurance, finance, corporate administration and cybersecurity.

The correct model distinguishes fixed costs, costs that vary with registrations, customer acquisition expenditure and contingent liabilities.

Table 3.3 — Commercial registry operating-cost architecture

Cost categoryPredominant behaviorPrincipal driverFinancial planning consequence
Application evaluationOne-time or contingentNumber and type of applicationsPre-revenue investment
Auctions and objectionsEvent-dependentContention and legal/procedural disputesPotentially substantial uncertainty
ICANN fixed registry feesRecurring contractualNumber of applicable registry agreementsCost even at low volume
ICANN transaction feesVolume-related above applicable thresholdQualifying registration incrementsIncreasing variable cost at scale
Registry back-end servicesContract-dependentTLD count, volume, service levelFixed minimums and scaling
DNS infrastructureMixedTraffic, redundancy and service requirementsAvailability and resilience
Security and abuse mitigationMixedThreat exposure and compliancePotentially nonlinear operating burden
Registrar distributionCommercial arrangementSales channels and volumeMarket access and margins
MarketingDiscretionary but commercially necessaryAcquisition strategyCash burn before recurring revenue
Staff and professional servicesFixed and semi-variableComplexity and organizational scaleOperating leverage
Customer supportVolume-dependentRegistrants, complaints and service needsService costs
Legal and intellectual-property exposureContingentDisputes, rights claims, enforcementTail-risk exposure
Registry wind-down or transitionEvent-dependentExit circumstancesPotential closure liabilities

This architecture explains why nominal registration revenue is a poor proxy for profitability.

A registry with substantial gross receipts may still lose money if acquisition expenses, infrastructure commitments or customer churn consume the available contribution.

A hypothetical commercial registry financial model

To demonstrate the mechanics without inventing actual operator results, consider a hypothetical registry with the following assumptions.

It pays the standard $227,000 evaluation fee and incurs a further $173,000 in launch preparation, legal work, technical integration and initial market development.

Total initial cash expenditure is therefore $400,000.

During operations, assume annual fixed costs of $250,000, inclusive of the modeled ICANN fixed fee and other fixed business expenses.

Assume the registry earns a net contribution of $10 per annual registration-equivalent transaction after directly attributable variable costs but before fixed costs.

Cost Accounting & Unit Economics

Operational vs. Capital Cash-Recovery Volume Thresholds

Comparative volume modeling evaluating recurring annual operational coverage against five-year straight-line capital recovery requirements.

Operating Break-Even Model
Qbreak-even = 250,00010 = 25,000
Recurring Overhead Floor: Absorbs annual fixed operational burn ($250,000) at an assumed $10 unit margin contribution. Leaves the initial $400,000 capital asset unamortized.
5-Year Straight-Line Recovery
Qrecovery = 250,000 + 80,00010 = 33,000
Full Cash Recoupment Target: Incorporates an annualized $80,000 capital return layer ($400,000 ÷ 5 years), lifting required throughput by +32.0% (+8,000 units/year).

Model Parameters & Cash Requirements

Fixed Operational Cost
$250,000/yr

Baseline recurring annual expenditures including platform operations, core administrative overhead, compliance fees, and registry support.

Assumed Unit Contribution
$10.00/txn

Net operational margin captured per transaction after upstream wholesale registry fees, ICANN levies, and direct payment processing.

Initial Outlay (Sunk)
$400,000

Initial establishment capital comprising evaluation fees, legal counsel, application buildout, and setup costs requiring multi-year recoupment.

Capital Tranche (5-Yr)
$80,000/yr

Linear, undiscounted annual cash target ($400,000 ÷ 5) required to return original principal within a standard 5-year operating window.

⚠ Methodological Scope & Sensitivity Drivers

Simplified Cash-Recovery vs. Discounted Appraisal This model operates purely as a nominal, undiscounted cash-recovery illustration. It intentionally omits the time value of money, opportunity costs, cost of debt/equity, and risk-adjusted discount rates ($r$) necessary for formal net present value (NPV) decision-making.
1. Wholesale Contribution Volatility

If the effective contribution compresses from $10 to $8 due to distributor discounting, the 5-year recovery threshold expands significantly from 33,000 to 41,250 transactions.

2. CAC & Channel Erosion

Customer Acquisition Cost (CAC) and registrar marketing co-ops directly reduce net realized contribution, shifting operating break-even deeper into high-volume bands.

3. Retention vs. Gross Churn Mix

Renewals carry near-zero acquisition drag compared to first-time domain registrations. High retention cohorts widen unit contribution margins beyond the baseline nominal $10 assumption.

Financial Model: Simplified Amortization & Unit Economics Application Scope: Registry/Registrar Portfolio Hurdle Feasibility

Table 3.4 — Break-even sensitivity by contribution margin

Illustrative fixed annual operating costs: $250,000. Initial investment: $400,000. Five-year simple recovery: $80,000 per year. Transaction counts rounded up.

Net contribution per annual registration-equivalentAnnual operating break-evenAnnual transactions required including simple capital recovery
$383,334110,000
$550,00066,000
$831,25041,250
$1025,00033,000
$1516,66722,000
$2012,50016,500
$308,33411,000

The table provides an important explanation for why certain specialized registries may be viable at relatively low volumes, while mass-market registries can struggle despite attracting substantial registrations.

If a registry can retain a high net contribution per customer, its required volume falls materially.

However, higher prices can reduce demand. A financial projection cannot assume that wholesale contribution increases without affecting acquisition and renewal behavior.

The relevant economic task is to estimate a feasible combination of price, demand and retention rather than simply selecting the most attractive margin.

Five-year operating scenarios

A more informative financial test allows the active business volume to vary over time.

Consider three illustrative scenarios, each using the same initial $400,000 investment and $250,000 annual fixed operating expenses.

Assume annual transaction-equivalent volumes and contribution margins as follows.

Model assumptionWeak adoptionStable nicheSuccessful scale
Year 1 transactions10,00020,00040,000
Year 2 transactions12,00028,00065,000
Year 3 transactions11,00035,00090,000
Year 4 transactions9,00040,000115,000
Year 5 transactions8,00045,000140,000
Net contribution per transaction$8$12$10
Five-year cumulative transactions50,000168,000450,000
Five-year contribution$400,000$2,016,000$4,500,000
Five-year fixed operating costs$1,250,000$1,250,000$1,250,000
Initial investment$400,000$400,000$400,000
Undiscounted five-year net result−$1,250,000+$366,000+$2,850,000

All amounts are hypothetical nominal U.S. dollars, without inflation, taxes, additional working capital or terminal value. The modeled contribution is assumed to have already accounted for directly attributable variable costs.

The stable-niche scenario is particularly revealing.

A registry need not become a mass-market phenomenon to generate a positive five-year cumulative operating result. It can succeed by serving a narrower market at sufficient contribution.

The weak-adoption scenario demonstrates the opposite. Even moderate cumulative registration volume is insufficient when fixed costs materially exceed the resulting contribution.

The successful-scale case demonstrates the operating leverage available when infrastructure and administrative costs rise more slowly than contribution revenue.

These figures should not be confused with actual 2026 applicant forecasts. Their purpose is to identify the variables that determine financial outcomes.

Discounted investment returns and the importance of timing

An undiscounted five-year surplus does not establish an acceptable investment return.

Capital committed before launch has an opportunity cost. Revenue generated several years later is worth less in present-value terms than the same nominal amount received immediately.

The appropriate measure for an investment-oriented registry operator is therefore a discounted cash-flow calculation, with explicit assumptions about launch timing, revenue realization, operating expense and risk.

Capital Allocation & Portfolio Appraisal

Five-Year Horizon Discounted Cash Flow (NPV) & Contention Economics

Quantitative evaluation of multi-period cash timing asymmetries, cost-of-capital hurdles, and the asymmetric balance-sheet drag of private or ICANN string auction premiums.

Five-Year Capital Valuation Identity
NPV = −I0 + ∑t=15 CFt(1 + r)t
Strict cash-generation discounting framework mapping multi-year lifecycle returns across a 5-year initial contractual term

Core Valuation Variables

−I0
Total Sunk Upfront Outlay

Initial capital deployed at period zero ($t=0$), comprising ICANN application fees, registry system onboarding, technical evaluation, legal preparation, and any string contention auction settlements.

Unrecoverable Sunk Baseline
CFt
Realized Cash Flows

Actual net operating free cash flow generated during year $t$. Isolates liquid cash collections from non-cash accounting accruals, deferred revenue amortizations, or raw domain registration tallies.

Operating Free Cash Flow (FCF)
r
Risk-Adjusted Hurdle Rate

Discount rate reflecting the cost of capital, technological execution uncertainty, commercial market penetration friction, and ICANN compliance risk specific to top-level registry operations.

Hurdle / Opportunity Rate
t ∈ [1, 5]
Appraisal Window

Standard five-year primary investment horizon, mirroring the intermediate performance baseline prior to registry agreement renegotiation, renewal, or terminal steady-state transition.

Finite Horizon Lifecycle

Methodological Divergence: Realized Cash vs. Nominal Stocks

Metric Category Analytical Nature Capital Budgeting Limitation
Active Registration Stock (Nt) Physical count of unexpired domain records Ignores pricing concessions, deep introductory discounts, channel rebates, payment processor delays, and payment defaults.
Accounting Earnings (GAAP/IFRS) Linear revenue recognition over 1–10 year registration terms Distorts actual liquid availability via non-cash amortization, working capital swings, and deferred revenue balances.
Free Cash Flow (CFt) Net liquid cash collected less cash operating expenses & CapEx The correct input for NPV: directly captures the real timing of liquidity available to service debt or return equity.

The Cumulative Cash Paradox: Late-Arriving Liquidity vs. Negative NPV

A domain registry venture may yield a positive cumulative undiscounted cash balance over five years, yet still result in a sharply negative Net Present Value:

∑t=15 CFt > I0  ⇔  NPV < 0

When cash generation is heavily back-loaded toward years four and five (common in slow-growing namespaces) and the discount rate r is elevated, the denominator factor (1+r)t heavily penalizes terminal cash flows. The registry produces capital too late to recover the early cost of carry on initial funds.

⚖ Contested-String Dynamics: The Asymmetric Auction Multiplier

In contested string allocations, competing applicants frequently enter private auctions or ICANN last-resort auctions to secure sole delegation rights. This introduces a structural capital imbalance into the investment identity:

1. Severe Capital Base Expansion (ΔI0 >> 0)

Auction clearance prices escalate initial investment outlays from hundreds of thousands of dollars into multi-million dollar commitments. Every incremental dollar paid at auction increases I0 on a 1:1 nominal basis at day zero.

2. Zero Operating Revenue Enhancement (CFt Inelastic)

Winning an auction expands the baseline investment without augmenting the downstream addressable market. A string’s consumer demand, registration volume, and premium pricing elasticity remain unchanged regardless of whether the applicant paid $185,000 or $15,000,000 to win it.

3. Hurdle Rate Amplification (Δr)

Elevated upfront leverage and capital concentration increase project financial risk, requiring a higher weighted average cost of capital (WACC). This lifts the discount rate r, compounding the downward pressure on five-year NPV.

Strategic Takeaway: In contested portfolio evaluations, an auction payment acts purely as a capitalized transfer payment to competitors or ICANN. Because it provides no commercial revenue synergies, it exponentially steepens the operational cash-generation slope needed to avoid equity destruction over the 5-year investment window.
Valuation Methodology: Discrete Multi-Period Free Cash Flow Discounting Application: Contested gTLD Registry & Intellectual Asset Appraisal

Acquisition cost versus commercially recoverable value

A registry investor should establish its maximum willingness to pay before entering a contention auction.

The relevant ceiling is not determined by how desirable the string appears or by the estimated financial resources of rival applicants.

It should be derived from the additional value the business can reasonably extract from operating that particular extension instead of its next-best alternative.

Suppose a company expects a specialized registry to generate an illustrative present value of $2 million in future operating cash flow before acquisition expenditures and has $600,000 in other unavoidable setup costs.

The maximum economically justifiable acquisition-related expenditure under that simplified calculation would be $1.4 million before allowing for additional required investment return, uncertainty and downside protection.

This is an illustrative valuation boundary, not a verified price for any actual TLD.

A rational applicant should generally set a lower bidding ceiling when the forecast is uncertain, because losing an auction can be financially preferable to winning an overvalued asset.

Premium names generate revenue but introduce concentration risk

Registry revenue does not always follow a uniform annual subscription pattern.

Some operators identify desirable second-level names and apply premium pricing. These names can potentially generate substantial initial receipts or higher continuing renewal income, depending on the registry’s rules and commercial terms.

The economic advantage is the ability to monetize differentiated willingness to pay.

The principal disadvantage is concentration.

A small number of high-value transactions may account for a substantial share of revenue, making annual financial performance volatile.

A registry reliant on premium initial sales may also face a challenge if the stock of its most desirable names is progressively sold and replenishment is limited.

Premium pricing therefore requires separate analysis of initial sales and recurring income.

Table 3.5 — Premium revenue concentration example

Assume a hypothetical commercial registry produces $1 million in annual wholesale revenue.

Revenue segmentRevenueShare
Ordinary initial registrations$250,00025%
Ordinary renewals$350,00035%
Premium initial registrations$300,00030%
Premium renewals$100,00010%
Total$1,000,000100%

In this illustrative case, 30% of revenue comes from premium initial registrations.

If those sales are nonrecurring, the apparent revenue base may be materially less stable than the headline total suggests.

The valuation should assign different persistence assumptions to ordinary renewals, premium renewals and one-time premium transactions.

Treating every dollar of current revenue as an equally durable annuity would overvalue the business.

Registration concentration and customer concentration are different risks

A registry can exhibit concentration in several different ways.

Registration concentration arises when a small number of registrants control a large proportion of active names.

Revenue concentration arises when a small number of customers or commercial arrangements contribute disproportionately to revenue.

Distribution concentration arises when a small number of registrars generate most registrations.

Technical concentration arises when several registries rely on the same infrastructure providers.

Ownership concentration arises when a limited number of ultimate corporate groups control numerous TLDs.

These forms of concentration are related but not identical.

For example, a registry may have tens of thousands of nominal registrations while relying on only a small number of registrars for most of its business.

A technical infrastructure company may support hundreds of TLDs without owning any of them.

A corporate group may own several registry operators whose nominally separate applications appear under different legal entities.

Concentration must therefore be measured at the level relevant to the question being investigated.

The distinction between legal entities and economic control

The published number of 481 applicants does not establish that 481 independent economic groups are competing in the 2026 round.

Some applicants may be subsidiaries, special-purpose vehicles or related entities.

Others may represent genuinely independent operators relying on common technical suppliers.

Ownership mapping is necessary before calculating the true concentration of applicants by beneficial economic control.

A robust ownership assessment should distinguish direct applicant entities, ultimate parent companies, common control, registry operating platforms, technical service providers and registrar relationships.

Without that reconciliation, a market assessment may overstate competitive diversity.

ICANN’s market indicators provide a starting point, not a complete competition assessment

ICANN publishes Domain Name Marketplace Indicators addressing registrant choice, domain adoption and the service-provider ecosystem.

These indicators provide an official measurement framework for examining whether the market offers meaningful options to registrants and opportunities for service providers.

Source: ICANN — Domain Name Marketplace Indicators: Robust Competition.

However, the addition of more TLDs does not necessarily imply a proportional increase in independent competition.

A market could contain more domain extensions while becoming more concentrated in ultimate ownership, registrar distribution or technical infrastructure.

Conversely, an expansion could improve competition by creating viable opportunities for new operators serving previously underserved communities.

The appropriate assessment must therefore distinguish product variety from economic independence.

A competition measurement framework

IndicatorMeasurementWhat it revealsLimitation
Number of delegated TLDsCount of operationally delegated extensionsProduct varietyDoes not measure economic independence
Number of ultimate registry ownersBeneficially controlled operating groupsOwnership concentrationRequires ownership reconciliation
Share of registrations by operatorActive names by economic groupMarket concentrationCan be distorted by short-lived registrations
Registry renewal rateRenewals relative to eligible renewal opportunitiesDurability of demandCohort and term definitions matter
Registrar channel concentrationRegistrations or sales by distribution partnerDependence on major channelsPublic data may be incomplete
Back-end provider concentrationTLDs and registrations supported by each platformTechnical dependenceTLD count and operational load differ
Wholesale price distributionEffective registry prices by productCompetitive positioningPremium and promotional pricing complicate comparison
DNS abuse outcomesValidated incidents under comparable definitionsSecurity externalitiesReporting practices and exposure vary
Effective entry costsApplication plus launch and operating expendituresContestabilityContract-specific private data may be unavailable
Registry closures and transitionsExit events and operational continuityIndustry sustainabilityExit does not automatically imply failure

The challenge is to convert these indicators into comparable measurements across operating models.

A brand registry with only ten controlled second-level names should not be evaluated as a failed commercial retail business when retail sales were never its objective.

A public commercial registry with substantial promotional registrations should not be declared successful simply because its initial registration count is large.

The economics of shared registry infrastructure

Registry service providers can create economies of scale by supporting multiple TLDs on common technical platforms.

This can reduce the minimum operating cost for individual registry owners.

However, shared infrastructure can also introduce dependence on specialized suppliers.

A small registry may lack the technical and financial resources to operate an independent back end, making outsourcing commercially attractive or operationally necessary.

The resulting supplier relationship influences the registry’s cost base, resilience and ability to change providers.

A registry investor should therefore examine more than the quoted annual infrastructure fee.

Relevant contractual provisions include service-level commitments, security responsibilities, data portability, transition assistance, change-control costs, termination rights and continuity obligations.

A low-cost agreement with substantial switching barriers may be less attractive over the long term than a more expensive contract with stronger portability and clearer exit protections.

The distribution bottleneck: registrar incentives

Registrars occupy an important commercial position because many registrants encounter the domain-name market through registrar search interfaces and product recommendations.

A new registry must compete for visibility within these distribution environments.

If the product is unfamiliar, the registry may need to finance awareness campaigns, commercial promotions or registrar integrations.

That expenditure can materially alter customer acquisition economics.

A TLD that appears highly attractive in an abstract market-demand survey may perform poorly if registrars do not actively distribute it or customers fail to recognize it.

The relevant financial variable is not merely consumer interest.

It is the number of customers who actually complete registrations at prices sufficient to support a profitable wholesale contribution.

This creates a commercial advantage for operators with established distribution relationships and portfolios that can be sold through existing channels.

The problem of artificially inflated demand

Promotional registrations can generate attractive headline statistics without creating durable underlying demand.

A registry may subsidize initial registrations to accelerate adoption. That strategy can be rational if acquired customers subsequently renew at profitable prices.

It becomes problematic when the initial volume is supported by customers who have little intention of maintaining the registration.

The registry then faces an unfavorable combination of acquisition expense, low renewal rates and weak revenue persistence.

A rigorous investigation should examine acquisition cohorts and their behavior over at least one complete renewal cycle, with longer observation where multi-year terms are material.

The data should distinguish standard-price registrations, promotions, premium sales, defensive purchases and genuine end-user adoption.

Domain parking, speculative ownership and the limits of registration data

A registration can be held for resale, advertising, defensive protection, future development or another purpose.

These uses have different implications for economic welfare.

A speculative domain market can facilitate the allocation of desirable names to buyers who value them more highly. It can also generate holding costs, disputes and pricing barriers for new entrants.

A defensive registration may prevent consumer confusion, but extensive defensive portfolios can impose continuing costs without creating directly productive services.

Consequently, gross domain counts cannot serve as a sufficient measure of social or economic value.

A credible registry assessment must consider both private financial returns and external effects on users, competitors and Internet security.

Operational risk can overwhelm the apparent economics of a name

A registry operates within critical naming infrastructure. Its obligations are not comparable to maintaining an ordinary promotional website.

Technical or administrative failures can affect multiple registrants and dependent services.

The operator must therefore assess cybersecurity, DNS availability, abuse mitigation, continuity and compliance as core operating responsibilities rather than optional enhancements.

The direct financial consequences can include remediation costs, contractual disputes, reputational damage, interrupted sales and expenditures required to restore compliance.

The indirect consequences may affect registrants and third parties.

These externalities are one reason why allocation purely according to willingness to pay would be an incomplete governance model.

An applicant’s financial capacity to win an auction does not by itself establish technical competence.

ICANN’s evaluation and contracting mechanisms are intended to address this distinction.

The economics of exit

A registry is not necessarily a permanent investment.

Its operator may face a commercial environment in which continued operation no longer creates sufficient value.

The resulting decision must account for contractual obligations, registered-name holders, service continuity, transition procedures and potential alternative operators.

A registry cannot assume it can simply abandon technical services without consequences.

A sound investment model should include plausible exit pathways and associated obligations before submitting the application.

Potential outcomes include continued operation under a revised business plan, changes in ownership subject to applicable approval requirements, negotiated transitions or termination under governing procedures.

The possibility of exit creates another difference between a gTLD and a conventional perpetual property asset.

The operator has a contractual position whose continuation depends on compliance and operational performance.

A registry acquisition is not equivalent to buying ordinary intellectual property

A buyer of a successful operating registry acquires or obtains control over a business subject to ICANN contractual arrangements, not an unrestricted exclusive right to a word.

The transaction’s value depends on the underlying contractual position, active registrant population, renewal revenue, premium-name inventory, supplier agreements, technical capability and regulatory obligations.

A registry with a commercially attractive string but poor renewal behavior may have less value than a smaller, well-managed registry with durable customers.

The valuation should therefore rely on expected distributable cash flows and contractual risks rather than on the perceived prestige of the extension.

A practical investment-return framework

Before investing in a commercial registry, management should separate financial assumptions into five categories.

The first concerns allocation probability and acquisition costs, including the application fee, conditional evaluations, contention and any auction expenditure.

The second concerns the operating model, including technical infrastructure, staffing, security and compliance.

The third concerns revenue formation, including pricing, registrar distribution, acquisition rates and premium-name sales.

The fourth concerns persistence, including renewals, customer concentration and changing market demand.

The fifth concerns exit, including transferability, operational continuity and potential terminal value.

Table 3.6 — Required investment analysis

Analytical componentPrincipal variablesMajor downsideRequired evidence
AllocationEligibility, contention, evaluation and auction costsInvestment before obtaining rightsICANN application and contention records
LaunchTechnical setup, integration and marketingCost overruns and delaySupplier quotations and launch plan
Market demandAddressable customers, pricing and conversionLow sales volumeValidated customer research and comparable registrations
Unit economicsWholesale receipts, variable costs, distributionNegative contribution marginsCommercial terms and cost data
RetentionRenewal cohorts and durationRevenue collapse after promotionsRegistration and renewal histories
OperationsRegistry fees, RSP services, complianceHigh fixed-cost burdenContracts and operating budgets
RiskTechnical failure, disputes and abuseContingent lossesRisk assessments and compliance records
ExitContractual transfer and transition obligationsIlliquidity and closure costRegistry agreement and applicable procedures

The investor should also conduct sensitivity analysis around variables that are genuinely uncertain.

For most commercial registries, customer acquisition, wholesale pricing, renewals and fixed cost absorption are likely to be more consequential than small variations in administrative fees.

For heavily contested strings, however, the auction price can become a dominant determinant of investment return.

Why the market can expand while individual registries fail

A fundamental characteristic of differentiated markets is that aggregate growth does not guarantee profitability for every participant.

The number of available domain extensions may increase, while registrations and spending remain concentrated in established names or a relatively small set of successful alternatives.

New registries may compete by lowering prices, increasing promotions and targeting narrower customer segments.

Some will achieve sustainable differentiation.

Others may discover that users do not attach sufficient value to the new suffix to justify its ongoing costs.

A market with many unsuccessful entrants is not necessarily evidence that expansion itself is harmful. Entry and exit can be normal components of competitive discovery.

But a high incidence of costly, low-utility projects would warrant examination if it were associated with avoidable entry barriers, misleading demand assumptions, insufficient disclosure or institutional incentives disconnected from user welfare.

The distinction is between productive experimentation and structurally wasteful duplication.

The 2026 round cannot yet establish commercial success

As of the October 2026 reporting cut-off, the new applications have not generated an observable post-delegation operating history.

There are no verified 2026-round renewal cohorts, no mature operating margins and no demonstrated long-term registration demand attributable to the newly proposed extensions.

Any numerical forecast purporting to establish how many of these registries will be profitable would therefore require explicit assumptions, a defensible historical comparison population and suitable adjustments for changes in the program rules and market environment.

The existence of successful registries from earlier rounds is not sufficient to forecast that the same proportion of applicants will succeed in 2026.

The applicant population, competitive environment, pricing strategies, technological conditions and selection mechanisms may differ.

The most defensible current assessment is consequently structural rather than probabilistic.

Commercial registry profitability will depend on sustainable contribution margins, renewal behavior, distribution access and disciplined capital expenditure—not simply on obtaining a desirable word in the DNS root.

Chapter 3 — Key judgments

The commercial registry sector is characterized by significant fixed commitments, differentiated products, recurring customer relationships and uncertain long-term demand.

Registration volume is an inadequate measure of success unless it is reconciled with wholesale revenue, cohort retention, variable costs and customer acquisition expenditure.

Premium-name sales can improve revenue but may increase volatility and concentration risk.

Shared technical infrastructure can lower costs while introducing dependencies on specialized suppliers.

Ownership concentration must be measured at the level of ultimate economic control rather than applicant names or the number of delegated extensions.

A profitable registry can exist at modest scale when unit economics are favorable. Conversely, a registry with very high registration volume can remain financially unsuccessful when promotional expenditure, churn and operating costs exceed contribution revenue.

What would change the Chapter 3 assessment?

Evidence of consistently high cohort renewal rates, increasing legitimate end-user deployment and positive contribution margins across a broad sample of newly introduced registries would support a stronger assessment of commercial sustainability.

Evidence of large-scale promotional registrations followed by poor renewals, significant operator exits or systematic dependence on unsustainable subsidies would indicate weaker underlying demand.

Relevant official evidence includes ICANN’s registry reports, domain marketplace indicators, relevant contractual compliance disclosures and registry agreement records. Financial statements, audited operator accounts and supplier contracts would be necessary for stronger conclusions about actual profitability.

Pillar I — Consolidated Financial and Institutional Assessment

The analysis across the three chapters establishes a central distinction between the economics of the institution administering the allocation process, the economics of a corporation acquiring strategic control, and the economics of an independent commercial registry attempting to recover its investment.

These three economic systems interact, but their financial interests are not identical.

Economic actorPrimary objectivePrincipal source of economic valuePrincipal exposureAppropriate performance measure
ICANNAdminister the naming system consistently with its missionFunding for authorized coordination, evaluation and contractual functionsGovernance, cost efficiency and accountabilityAudited cost recovery, procedural integrity, security and public-interest outcomes
Corporate brand ownerControl an organizational namespaceStrategic flexibility, brand identity and avoided costsLong-term carrying costs and limited incremental useMeasurable or defensible incremental corporate benefits
Commercial registry operatorBuild a sustainable registration businessWholesale registrations, renewals and premium transactionsDemand, churn, margins and acquisition costsRisk-adjusted cash-flow returns
Institutional or community applicantServe a defined community or public-interest purposeCommunity access, identity and organizational utilityFunding and operating sustainabilityMission outcomes combined with financial viability
Registry service providerSupply technical operating capacityContracted infrastructure and support revenueCustomer concentration, operational failures and service obligationsContract profitability, resilience and service quality
RegistrarDistribute domain products to end usersRetail sales and recurring customer relationshipsPricing competition, acquisition and retention costsCustomer lifetime value and contribution margin

The broader market’s performance should not be judged through the number of applications, total evaluation fees or the eventual number of delegated strings alone.

The decisive question is whether the new infrastructure creates sufficiently durable economic and organizational benefits to justify the capital employed across the entire system.

That question cannot be settled by the willingness of applicants to spend $227,000, or even significantly more, to pursue a name.

Willingness to pay establishes perceived private value. It does not establish realized financial returns, technological necessity or net public benefit.

The next analytical stage, Pillar II, must therefore examine the sources of technological power that could transform a namespace from an expensive strategic option into an operationally important asset—and, equally, the technologies that could make such an investment unnecessary.

The relevant distinction will be between control of a DNS label and control of the underlying digital ecosystems, authentication mechanisms, agent infrastructures and commercial relationships that determine whether the label is actually useful.


PILLAR II — TECHNOLOGICAL POWER, DIGITAL IDENTITY AND COMPETITION

Chapter 4. Technology Companies and the Strategic Acquisition of Internet Namespaces

Principal judgment: control of Internet naming is becoming a strategic layer in the competition between digital platforms, but ownership of a top-level domain is not equivalent to control of the technology operating beneath it

The participation of major technology companies in ICANN’s 2026 expansion is significant because it introduces a new competitive dimension into the relationship between Internet addressing, corporate digital infrastructure and emerging artificial intelligence platforms. The principal issue is no longer whether an enterprise requires a distinctive web address. It is whether a company operating an increasingly complex ecosystem of software products, cloud infrastructure, intelligent agents, data services and commercial interfaces can obtain additional strategic advantages by administering a globally recognized naming environment.

The distinction is important. The Domain Name System was developed to provide distributed resolution of human-readable names to information needed by network applications. Its hierarchical structure allows names to be organized, delegated and resolved across different administrative authorities. It was not originally designed to allocate commercial jurisdiction over technological categories or to determine which companies may develop particular forms of artificial intelligence.

Nevertheless, a namespace can become economically consequential when it is integrated into a larger technological ecosystem. Organizations that control widely adopted software platforms can influence how customers discover services, how developers connect applications, which identifiers become familiar to users and which technical interfaces become conventional.

A top-level domain may reinforce these relationships by providing an independently recognized naming hierarchy. It does not create the underlying platform power, but it can complement it.

The strategic significance of a proposed extension therefore depends less on the linguistic attractiveness of the string than on the technological and commercial infrastructure to which the applicant intends to connect it.

For a company controlling a major cloud platform, software ecosystem or AI service, a registry can be one additional component in a broader system of customer relationships, authentication, developer tools, service discovery, infrastructure control and brand governance.

For an independent applicant without comparable capabilities, the same extension may remain little more than a commercially attractive label requiring substantial expenditure to establish market recognition.

The competitive asymmetry arises because the economic value of a namespace may depend on assets and relationships located outside the domain-registration market.

That is the central issue examined in this chapter.

The 2026 application record reveals competing corporate approaches

ICANN’s Application Publication and Statistics system recorded 1,615 active applications associated with 481 applicants in its 7 October 2026 snapshot. These are applications, not approvals or delegated top-level domains.

Publicly reported applications include proposed strings associated with established technology companies, AI-related terminology and existing digital brands. Examples include .openai, .chatgpt, .facebook, .agent and .agi.

The official application database is the appropriate record for identifying the applicant, applied-for string, application category and subsequent procedural status. Its initial publication is not a final allocation decision, and the database warns that information is not updated in real time.

Sources: ICANN — 2026 Round Application Statistics, 7 October 2026 and ICANN — Application Publication System, About and Data Publication Rules.

The significance of these applications is not uniform.

A proposed extension matching an established corporate trademark has a different potential function from a generic expression associated with artificial intelligence.

A product-related label can operate as a controlled corporate identifier.

A generic technological expression may be intended for a broader registration market, subject to applicable ICANN restrictions.

A community or professional identifier may be designed to support a group of users, developers or organizations rather than a single enterprise.

Confusing these categories would obscure the commercial and regulatory consequences.

Table 4.1 — Strategic classification of technology-related namespace applications

Naming categoryIllustrative strings appearing in the 2026 discussionPotential strategic functionPrincipal regulatory or technical constraint
Corporate identity.openai, .facebookRecognizable organizational namespaceBrand eligibility, registry contracting and applicable rights
Product identity.chatgptProduct-specific addresses and service organizationTrademark rights and relevant contractual conditions
AI technology category.agent, .agiPotential commercial or developer-facing naming marketGeneric-name treatment, contention and nonexclusive access requirements
Software interfaces.apiDeveloper-oriented naming and technical brandingActual use must be implemented above the DNS layer
Wider AI concepts.intelligence, .superintelligenceCommercial positioning around emerging categoriesApplicant eligibility, competition and practical market adoption
Enterprise ecosystemCorporate or platform-specific labelsSegmentation of approved products and servicesOperational and contractual control, not universal technical authority

The table classifies naming strategies rather than asserting that any application has been approved or that its applicant has established a functioning service. Applicant-specific facts should be verified against ICANN’s published applications before being used as definitive corporate portfolio totals.

The presence of AI-related vocabulary in the applications is evidence of interest in these labels. It is not proof that applicants share a single technological strategy.

Some may be positioning themselves for future applications; others may be seeking retail registration businesses, brand extensions or developer communities.

The exact commercial purpose cannot be inferred from the string alone.

The five layers of technological power that must be distinguished

An analysis of technology companies’ namespace strategies must distinguish the control of names from control of the systems to which those names refer.

A company can possess substantial influence in one layer while having limited influence in another.

Table 4.2 — Digital power and control across the Internet technology stack

LayerCore asset or capabilityPrincipal form of controlRelevance of a new gTLDWhat gTLD control does not provide
Root-level namingDelegated TLD stringContractual authority to operate a registryDirectOwnership of Internet protocols
DNS operationAuthoritative DNS and recordsResolution configuration and delegationDirect or strongGuaranteed authenticity of applications
Network deliveryHosting, routing, CDN and connectivityService availability and performanceIndirectOwnership of physical networks
Application interfacesAPIs, services and protocolsSoftware functionality and access policiesPotentially usefulAuthority over universal API standards
Identity and authorizationCredentials, certificates, identities and permissionsVerification and access decisionsSupporting roleAutomatic authentication or legal authorization
Platform ecosystemUsers, developers, data, distribution and commercial relationshipsNetwork effects, standards adoption and market accessComplementaryAutomatic user adoption or commercial dominance

This separation identifies the conditions under which a new namespace could matter.

The namespace becomes operationally valuable when the applicant can connect it to reliable services, establish adoption by relevant users and implement coherent security and identity policies.

Without those complementary capabilities, the extension’s strategic value remains contingent.

Technical standards governing DNS service binding and encrypted transport demonstrate this separation. DNS can help clients discover connection information, but additional protocols determine encrypted communication, service authorization and application behavior.

Source: IETF — RFC 9460: Service Binding and Parameter Specification via the DNS, November 2023.

Control of the DNS root is different from control of an individual registry

An important institutional distinction concerns the scope of delegated authority.

A corporation operating a TLD does not control the DNS root or other TLDs.

Its administrative authority concerns its own delegated namespace and is subject to the registry agreement, applicable policies and technical requirements.

The registry can establish or administer relevant second-level naming arrangements. It cannot unilaterally redefine how the global DNS resolves all names.

It also cannot compel unrelated operating systems, browsers, software developers or AI platforms to adopt applications associated with its extension.

This boundary limits the geopolitical and commercial significance of individual acquisitions.

A particular name could become influential if the market adopts it extensively, but that influence must arise through deployment and use rather than from delegation alone.

Platform complementarity can magnify the private value of a namespace

A large technology company may extract value from a new TLD through existing relationships with users, enterprise clients, developers, advertising customers or software partners.

The underlying mechanism is complementarity.

A naming resource that would require substantial marketing by an independent operator might gain immediate visibility when integrated into an established product.

Similarly, a domain extension associated with an existing enterprise software platform could potentially be deployed across affiliated services without requiring a separate consumer-facing registration market.

This creates an economic advantage not fully captured by comparing application fees or registry operating costs.

The advantage comes from the applicant’s complementary assets.

A simplified conceptual relationship is:

\[ V_{\mathrm{namespace}}=V_{\mathrm{standalone}}+V_{\mathrm{integration}}+V_{\mathrm{strategic}} \]

The three terms represent standalone commercial value, incremental value from integration with existing assets, and other defensible strategic value.

This is a valuation framework, not an established accounting identity. Its components must be defined to avoid double-counting.

In particular, the value of existing customer relationships cannot simply be assigned to a new namespace if those relationships would remain valuable without it.

A rigorous counterfactual asks what additional value the new naming environment produces compared with continued use of existing Internet domains and platforms.

Technology-company scale changes the competitive meaning of identical expenditures

The same investment amount can have radically different consequences across applicants.

A large corporation may finance multiple applications from an established technology or intellectual-property budget and rely on existing infrastructure to support implementation.

A smaller independent applicant may need outside capital, contracted technical services, market development and additional financing before it can achieve equivalent operational readiness.

This produces a differential capacity to tolerate delays, failed applications, competing bids or prolonged periods before deployment.

However, financial scale should not be confused with guaranteed strategic success.

Major technology companies can misallocate capital, overestimate adoption and acquire infrastructure that their users never meaningfully adopt.

The competitive concern is narrower: large firms may be better positioned to absorb uncertainty and develop complementary services, potentially strengthening existing market advantages.

Whether that produces anticompetitive effects depends on actual market behavior, access conditions, interoperability and the existence of effective alternatives.

The significance of generic AI terminology

Strings such as .agent and .agi merit particular attention because they are associated with concepts extending beyond one company’s established trademark or product line.

The terms refer to potentially broad classes of technologies and services.

An applicant may perceive commercial opportunities in creating a registration market around these concepts.

A technology company may also believe that administering a recognizable category-oriented namespace would strengthen its position in emerging software ecosystems.

But a commercially attractive generic term is not automatically eligible for exclusive corporate use.

ICANN’s 2026 Applicant Guidebook and Registry Agreement framework impose restrictions on exclusive operation of generic strings. The applicable mandatory public-interest commitments prohibit registry operators of generic strings from restricting registrations exclusively to one entity and its affiliates.

This limits an attempt to transform broad terminology into a privately closed naming category.

Source: ICANN — 2026 Applicant Guidebook, Module 7, Mandatory Public Interest Commitments.

This rule has important consequences for competition analysis.

An applicant may gain the position of registry operator for a generic term while remaining unable to deny the entire market access merely to reserve the terminology for its own business.

Nevertheless, actual registration rules, pricing, registrar access, technical arrangements and contract enforcement will determine how meaningful that openness becomes.

Formal nondiscrimination requirements and effective competitive access are related but distinct questions.

The possibility of platform-driven standards capture

A more consequential form of market power could arise if a large platform encourages or requires third parties to use naming conventions associated with an infrastructure it controls.

For example, a software ecosystem could establish technical procedures under which developers publish designated service information beneath approved domain names.

Such a practice may create legitimate benefits by improving discoverability and consistency.

The competition concern would arise if access to commercially important services became dependent on registration arrangements controlled by a company with significant market power.

The relevant mechanisms include compatibility requirements, default configurations, certification rules, privileged discovery arrangements and discriminatory API access.

No generic DNS string automatically acquires these capabilities.

They would have to be implemented through software, contracts, developer policies or technical standards.

Table 4.3 — Conditions under which naming control could become a competitive bottleneck

ConditionMechanismPotential consequenceNecessary evidence
Platform mandates a naming formatAccess conditional on a designated domain structureHigher switching or entry costsPublished developer requirements
Registry discriminates in accessDifferential eligibility or commercial treatmentCompetitor disadvantageRegistration rules and transaction evidence
Exclusive service discoverySoftware resolves preferred namespace by defaultSteering toward affiliated servicesTechnical specifications and implementation
Developer ecosystem concentrationWidely adopted APIs rely on controlled conventionsNetwork effects and lock-inDeveloper adoption and dependency data
Pricing discriminationDifferent effective prices for comparable registrantsForeclosure or rent extractionWholesale contracts and pricing records
Portability constraintsServices depend on identifiers difficult to transferHigher switching costsMigration and interoperability testing
Bundled infrastructureRegistry use combined with hosting or platform servicesPotential tying or efficiency gainsCommercial terms and market assessment

These are analytical possibilities, not findings of anticompetitive conduct by a particular applicant.

The distinction is necessary because vertical integration can create efficiencies as well as competition risks.

A unified naming and service architecture may reduce integration costs and improve operational consistency.

The policy question is whether such benefits can be achieved without unduly restricting third-party participation or interoperability.

The special position of cloud and API platforms

Cloud infrastructure providers already operate naming systems for hosted services, developer endpoints and managed applications.

They routinely allocate subdomains within existing namespaces and can make those identifiers part of product workflows.

A new top-level domain offers an alternative naming structure, not a technological prerequisite for these activities.

The strategic test is whether it materially improves service organization, customer-facing identity, portability or operational control beyond what existing domains provide.

For example, a developer-oriented namespace may make an API service easier to recognize. But its use does not ensure that the API follows an interoperable specification.

Likewise, a cloud company might operate a consistent namespace for authorized tenants or services, but authorization must still be implemented through appropriate security systems.

Thus, the public-interest value of a technology-related TLD should be evaluated through demonstrated technical and commercial improvements rather than branding claims.

Domain extensions cannot substitute for open technical standards

The competition between open standards and proprietary ecosystems is especially relevant.

Open technical standards enable independently developed systems to communicate using commonly specified methods.

Domain names can support these systems, but the semantic meaning of a particular suffix is generally not sufficient to guarantee interoperability.

For example, the availability of a domain ending in a term associated with software interfaces does not establish that a service supports a recognized API schema, security mechanism or protocol.

A developer must still examine service documentation, capabilities, authentication requirements and applicable technical standards.

A new extension can signal intent. It does not certify implementation.

This distinction should guide procurement decisions by public institutions and enterprises.

Technical compliance must be verified at the level of the actual protocol and service, not inferred from a memorable domain ending.

Competition may develop between namespaces rather than only within them

The market for domain extensions can involve competition at two levels.

At the first level, multiple registry operators compete to attract registrations for different extensions.

At the second level, applications and digital ecosystems compete to establish which naming systems users consider meaningful.

A technology-related TLD could become prominent because developers adopt it.

Another could fail because existing naming practices remain entrenched.

A third could obtain a sustainable specialized audience without becoming dominant.

These outcomes depend on network effects, user expectations, distribution and technical integration.

The number of available extensions is therefore an incomplete measure of effective competition.

The more consequential measure is whether customers and developers can choose among substitutable naming and identity arrangements without unreasonable switching costs or access restrictions.

Decision consequences for technology companies

A large technology company assessing a gTLD portfolio should distinguish at least four governance responsibilities.

Its intellectual-property function must establish legal eligibility and brand implications.

Its infrastructure function must establish technical requirements and operational responsibilities.

Its product organization must identify actual deployment or future-option use cases.

Its competition and regulatory function must examine whether the contemplated registration policies, commercial arrangements or platform integrations create exclusionary effects.

These responsibilities should not be collapsed into a single marketing decision.

A technically valid and contractually permissible registry can still create commercial or reputational risks if its operating model conflicts with customer expectations or interoperability principles.

Chapter 4 — Key judgments

Technology companies can derive strategic benefits from top-level domains through their integration with existing platforms, customer relationships, software infrastructure and brand systems.

The economic value of a new namespace may therefore be substantially greater for an applicant possessing complementary assets than for an independent registry entrepreneur.

However, DNS delegation does not confer ownership of underlying technical standards, AI technologies, software protocols or related commercial categories.

Generic-name restrictions limit attempts to reserve broad technological terminology exclusively for one enterprise.

Potential competition concerns arise from actual platform integration, access restrictions, discriminatory treatment and switching costs—not from the mere existence of a corporate application.

The decisive evidence will concern deployment, developer adoption, registry access policies and the extent to which new naming conventions become necessary to participate in important digital ecosystems.

Chapter 5. Artificial Intelligence, Autonomous Agents and the Future of Trusted Digital Identity

Principal judgment: artificial intelligence will intensify the problem of digital identity, but domain ownership alone cannot establish that an autonomous agent is genuine, authorized or safe

The emerging market for autonomous artificial intelligence systems introduces a structural change in how Internet identity must be understood. Conventional websites primarily facilitate interactions between people and digital services. Agentic software increasingly introduces interactions in which one software system discovers, communicates with, delegates tasks to, or requests operations from another system.

The critical difference lies in the operational consequences of an identity claim.

When a person visits an unfamiliar website, the immediate question may be whether the site genuinely represents the organization it claims to represent. When an autonomous agent selects a service and initiates an action, the identity problem becomes more complex. The requesting system may need to establish which organization operates the service, whether the service is authentic, which principal authorized the agent, what operations the agent may perform, whether that authorization remains valid, and how responsibility for the resulting action can be reconstructed.

A recognizable domain name can support this process by providing a consistent identifier for a network location or service. It does not answer all of these questions.

The difference between a name, a cryptographically authenticated identity and a delegated authorization is therefore central to understanding the potential commercial value of AI-related top-level domains.

The emergence of agentic software could increase demand for stable organizational naming structures. Equally, it could accelerate adoption of identity frameworks that rely on existing domains, signed credentials, cryptographic keys and application-level directories without requiring additional TLDs.

The technological future of AI-related domain extensions consequently remains conditional on a development that has not been demonstrated: widespread adoption of naming conventions in which the new suffix itself provides a material advantage.

The architecture of machine identity

A networked AI agent can participate in multiple identity relationships.

It may have an infrastructure identity identifying the service or workload through which it communicates.

It may have an organizational identity identifying the enterprise responsible for its operation.

It may have an application identity identifying the software environment or service account in which it runs.

It may act under delegated authority from a user or another software system.

It may possess credentials allowing it to interact with a specific API.

It may also require transaction-specific approval before executing sensitive operations.

These relationships are not interchangeable.

A valid TLS certificate for a service endpoint does not prove that the service is authorized to transfer funds on behalf of a user.

A valid access token does not necessarily establish that the underlying software behaves safely.

An organizational domain does not prove that a particular AI model has been certified or that the individual issuing an instruction possesses legal authority to do so.

Modern security architecture therefore separates network identity, authenticated principals, authorization policies and continuous enforcement.

The National Institute of Standards and Technology’s Zero Trust Architecture establishes the broader security principle that access decisions should not rely solely on implicit trust associated with network location. Authentication and authorization should be evaluated in relation to resources, identities and applicable policy.

Source: NIST — Special Publication 800-207, Zero Trust Architecture, August 2020.

This principle becomes especially consequential when software agents operate across organizational boundaries.

Six independent questions every trustworthy agent ecosystem must answer

Security questionRequired assuranceRelevant technical mechanismsCan a TLD answer it alone?
Where is the service?Reachable and correctly resolved endpointDNS, service discovery, routingPartially
Who operates the endpoint?Authenticated service identityTLS, certificates, signed assertionsNo
Which agent is making the request?Authenticated workload or client identityTokens, keys, workload identityNo
Whose authority does the agent exercise?Valid delegation from a principalOAuth, policy-bound credentialsNo
What actions are permitted?Resource-specific authorizationScopes, access control, transaction policyNo
Can the action be trusted and audited?Integrity, accountability and enforceable controlsLogging, signatures, monitoring, approvalsNo

The table exposes the limitation of describing a proposed .agent registry as a universal identity system for autonomous agents.

An extension may provide a useful naming convention, but the security guarantees arise from protocols and governance mechanisms outside the TLD itself.

Agent-to-agent interactions create multiple trust boundaries

Consider an enterprise purchasing agent instructed to obtain replacement industrial components.

The agent searches approved suppliers, retrieves product information, compares prices, checks inventory, creates a purchase proposal and submits an order for authorization.

This process may involve several independent digital systems.

The enterprise must know that the supplier endpoint is genuine. The supplier must determine that the requesting agent is authenticated. The enterprise must constrain the agent’s purchasing authority. Any final order must conform to budgetary and approval limits. Transaction records must establish what was requested, authorized and executed.

A top-level domain could help organize supplier or agent endpoints, but it cannot independently provide the entire trust architecture.

The relevant operational model is therefore multidimensional.

Table 5.1 — Trust requirements across an autonomous procurement transaction

Transaction stagePrincipal riskRequired controlRelevant evidence
Supplier discoveryFalse supplier or malicious endpointValidated directory and authenticated endpointSupplier registry and certificates
Service connectionTraffic interception or endpoint impersonationSecure transport and service authenticationTLS validation and configuration
Agent identificationUnknown or impersonated software clientAgent or workload credentialsCredential issuer and validation logs
User delegationAgent acts without legitimate authorityExplicit delegated permissionsSigned or auditable authorization
Price and inventory retrievalManipulated informationSource integrity, consistency checksSupplier records and transaction logs
Purchase proposalUnauthorized or unsuitable expenditurePolicy enforcement and spending limitsApproval policy
Order submissionExcessive or unintended transactionTransaction-specific authorizationSigned order and confirmation
Post-transaction reviewInability to reconstruct responsibilityAudit trail and nonrepudiation controls where appropriateLogs, receipts and relevant signatures

The distinction between identification and authorization deserves particular emphasis.

A service can be genuine while the action requested from it is unauthorized.

An agent can be genuinely operated by a recognized company while acting beyond its assigned permissions.

Consequently, security cannot be inferred from the trustworthiness of the organization appearing in the domain name alone.

Model Context Protocol demonstrates why agent infrastructure does not depend on a new TLD

The Model Context Protocol is a particularly relevant example because it establishes conventions through which AI applications can interact with tools, resources and external systems.

The protocol’s authorization specification describes mechanisms for protected resources, authorization servers and client access, including OAuth-related processes.

Its security architecture operates at the protocol and application layers rather than relying on a special top-level-domain suffix.

The November 2025 authorization specification establishes relevant discovery and authorization arrangements for HTTP-based MCP interactions, demonstrating that agent interoperability and access control can be standardized independently of whether a service operates under .com, .org, a corporate namespace or a future AI-related TLD.

Source: Model Context Protocol — Authorization Specification, 25 November 2025.

This has direct implications for investment decisions.

An investor acquiring an AI-related TLD cannot assume that MCP-compliant software will need to use that extension.

The protocol does not establish such a requirement.

A registry may attempt to build useful complementary services for developers, but it must create demand through integration, tooling, governance or market adoption rather than through a technical monopoly inherent in the DNS string.

DNS service discovery already supports extensible connection mechanisms

The IETF’s RFC 9460 defines SVCB and HTTPS DNS resource records for communicating information used when connecting to network services.

These records can express service endpoint information and relevant connection parameters.

Such capabilities can support modern service discovery without requiring the creation of a new top-level domain.

Source: IETF — RFC 9460, Service Binding and Parameter Specification via the DNS, November 2023.

The competitive consequence is important: the DNS architecture already permits organizations to publish structured information beneath existing domains.

For instance, an enterprise can place service-discovery records and agent endpoints within a domain it already controls.

The commercial case for a dedicated AI-related TLD must therefore demonstrate benefits not already available through the combination of existing DNS records and application-layer standards.

These benefits could include sector-specific governance, recognizable naming conventions or a commercially adopted registration ecosystem.

They should not be confused with technical capabilities that the extension itself does not create.

The importance of cryptographically verifiable credentials

In May 2025, the World Wide Web Consortium published Verifiable Credentials Data Model v2.0 as a W3C Recommendation.

The framework describes a standardized model for expressing verifiable claims and supports an ecosystem involving issuers, holders and verifiers.

The significance for autonomous AI systems is that a credential can communicate an assertion about an entity in a format whose authenticity and integrity can be verified using appropriate cryptographic mechanisms.

Source: W3C — Verifiable Credentials Data Model v2.0, Recommendation, 15 May 2025.

Such credentials may help establish that an organization has issued a statement about a software agent, that a professional holds a particular qualification, or that an enterprise has delegated a defined capability.

However, cryptographic verification establishes that a credential is authentic relative to its issuer and proof mechanism. It does not automatically establish that the issuer is trustworthy or that every claim is substantively correct.

A reliable ecosystem therefore requires governance concerning recognized issuers, credential validity, revocation, authorization and liability.

A domain name can be used as an identifier or associated resource within such a system, but a separate AI-specific top-level domain is not a necessary component of the W3C credential model.

The emerging distinction between identity registries and DNS registries

A DNS registry administers names within a delegated top-level namespace.

An identity registry or trust registry, by contrast, may maintain information about authorized issuers, recognized organizations, public keys, software identities or accreditation status.

These functions can be combined within a broader service, but they are not equivalent.

The difference matters because an applicant might present a new gTLD as the foundation for a trusted AI ecosystem.

Such an ecosystem would require a governance layer determining who can make trustworthy assertions and under what conditions those assertions are accepted.

A TLD registry could establish registration eligibility criteria where permitted, but control of registration would not automatically guarantee the correctness of claims made by registrants.

For example, registering a domain associated with medical AI would not establish regulatory authorization to provide clinical services.

Likewise, a domain used by a financial agent would not independently establish permission to handle regulated financial transactions.

The relevant supervisory and professional requirements would continue to apply.

Table 5.2 — DNS registration versus trustworthy digital identity

PropertyConventional domain registrationCredential-based identity systemRegulated authorization system
Identifies a named resourceYesMay do soMay do so
Establishes DNS controlYes, within applicable arrangementsNot necessarilyNo inherent DNS function
Supports cryptographic assertionsThrough associated technical systemsYes, where implementedDepends on legal and technical design
Validates professional qualificationsNot inherentlyOnly where qualified issuers attest themMay be part of the authorization process
Establishes legal permission to actNoNot automaticallyDepends on competent legal authority
Supports revocationRegistration and DNS mechanismsCredential status and revocation mechanismsLegal and administrative procedures
Creates transaction-specific authorityNoPossible with suitable delegation designSubject to applicable requirements
Provides universal trustNoNoNo

The central conclusion is that digital identity depends on the relationship between identifiers, credentials, authorized issuers and relying parties.

Naming is only one part of the system.

Why autonomous agents may actually reduce the commercial importance of memorable extensions

The traditional commercial value of a domain name partly depends on human recognition, memorability and ease of communication.

Autonomous software often selects destinations through structured data, configured endpoints, authenticated directories or application integrations.

An agent may not care whether a service is located under a memorable generic extension, provided that the endpoint is discoverable, authenticated, permitted and operationally suitable.

This creates a potential long-term challenge for speculative AI-related TLDs.

If machine-mediated interactions increasingly rely on verified service metadata rather than human interpretation of Internet addresses, semantic naming premiums may decline for certain use cases.

At the same time, organizational trust and stable identifiers may become more important.

These opposing effects must be considered together.

The emergence of AI does not automatically increase the value of every AI-related domain. It may increase the value of stable enterprise identifiers while reducing demand for some generic, human-oriented naming products.

Machine identity may become more abundant than human-facing domain names

Autonomous systems can be deployed dynamically and in large numbers.

A cloud service might instantiate software workloads, short-lived processes or specialized agents that operate for limited periods.

Assigning a separately registered second-level domain to every such instance would often be unnecessary and operationally inefficient.

Existing domain hierarchies, service accounts, certificates and workload identity systems can support large populations of software entities without requiring a corresponding number of retail domain registrations.

This creates a significant difference between the growth of agent populations and the potential growth of the domain-registration business.

More agents do not necessarily mean proportionately more domain registrations.

A single organization may operate thousands of agents beneath a small number of domains.

The registry’s opportunity therefore lies less in selling one name per agent than in providing differentiated trust, discovery, governance or ecosystem services that enterprises are actually willing to adopt.

A hypothetical AI identity infrastructure market

A specialized registry might seek to serve an ecosystem of verified software agents.

The business model could theoretically include standardized naming conventions, registrant eligibility procedures, integration with verifiable credentials, developer tooling and directory services.

However, these features would have different legal and technical foundations.

The registry would administer the naming system under ICANN’s contractual framework.

A separate credential authority or approved identity provider would issue identity assertions.

Applications would evaluate authorization and permitted operations.

Independent security systems would monitor misuse.

Without these additional components, marketing a domain as a certified or inherently trusted agent identity could create misleading expectations.

The investment case must therefore include the costs of maintaining the trust framework and the liability implications of any assurances offered to customers.

The problem of delegated authority in multi-agent systems

Agentic applications may involve one agent instructing another to perform a task.

This introduces delegation chains.

Suppose an enterprise employee authorizes a procurement agent to purchase equipment up to a specified limit. That agent may request information from a supplier agent, invoke a payment service and communicate with a logistics provider.

The system must preserve the boundaries of the original authorization.

An agent should not infer that because a supplier’s endpoint is authentic, the supplier may modify the purchaser’s spending authority.

Similarly, the possession of a valid service credential should not automatically permit the receiving service to delegate unrestricted powers to another party.

This creates requirements for audience-restricted credentials, explicit authorization scopes, expiry, revocation and controls against privilege escalation.

The relevant security distinction is between a validated identity and the right to execute a particular action under a defined context.

The problem of agent impersonation

Malicious software may claim to represent a trusted corporation, customer or automated service.

Attackers may use misleading domain names, forged messages, stolen credentials, compromised APIs or manipulated service-discovery information.

A genuine domain can even host a compromised or malicious service.

Consequently, checking whether a domain name resembles the expected organization is insufficient.

A robust system needs authenticated connections, carefully validated credentials, authorization checks and monitoring capable of detecting abnormal activity.

Where financial or legally consequential actions are involved, additional approval requirements may be necessary.

The objective is not simply to prevent an agent from communicating with an impostor, but to ensure that no single misleading trust signal becomes sufficient authority for a sensitive transaction.

The liability problem of autonomous digital identity

A further complication arises when an AI system causes harm.

The technical identity of the software does not necessarily identify the legally responsible party.

Relevant actors may include the developer, deploying organization, operator, user, service provider and third-party systems involved in the action.

Legal responsibility depends on applicable law, contractual arrangements, causation, control and the circumstances of the incident.

A domain name can help identify a service operator or provide evidence linking infrastructure to an organization.

It cannot, by itself, resolve legal responsibility for an autonomous decision.

This limits claims that the future of AI governance can be secured through a new class of Internet domain extensions.

The governance of AI agents requires rules governing accountability, human oversight, auditability and permitted actions in addition to stable technical identifiers.

Three technologically distinct futures for AI-related namespaces

Rather than assuming one inevitable outcome, the market should be assessed through alternative adoption pathways.

Table 5.3 — Alternative AI identity architectures, 2027–2031

PathwayDominant identity methodRole of specialized AI gTLDsPrincipal technical dependencyConsequence for registry investment
Existing-domain continuityEnterprise domains, APIs and conventional credentialsOptional branding and organizationExisting Internet infrastructureLimited incremental demand
Federated verifiable identityDomain-associated and independent credentialsOptional issuer or service identifierTrusted issuers and verificationValue depends on integration
Platform-controlled agentsPlatform identities and proprietary directoriesSecondary or absentPlatform governance and APIsPotential concentration outside DNS
Open agent ecosystemsStandardized agent protocols and interoperable credentialsPossible recognizable ecosystem labelsOpen standards and adoptionOpportunity without guaranteed exclusivity
Sector-regulated agent networksQualified identities under supervisory requirementsPossible restricted naming environmentLegal accreditation and sector rulesSpecialized markets with compliance costs
Hybrid architectureSeveral identity mechanisms operating togetherUseful in selected applicationsCross-system interoperabilityDifferentiated and uncertain opportunities

These pathways are not mutually exclusive and should not be assigned fabricated numerical probabilities.

Different sectors may select different architectures.

Financial services may place exceptional emphasis on legal authorization and auditability.

Industrial applications may prioritize machine identity, operational integrity and integration with existing enterprise systems.

Consumer applications may rely heavily on platform accounts and familiar product ecosystems.

The diversity of these requirements reduces the plausibility of a single DNS suffix becoming a universal identity authority for autonomous software.

Measuring actual demand for AI-related TLDs

A useful assessment should avoid promotional measures such as the number of press mentions or the nominal popularity of a proposed word.

More consequential indicators would include production deployments, active developer integrations, recurring registrations, verifiable service usage, interoperability, credential adoption and customer willingness to pay.

Table 5.4 — Decision-useful indicators for AI namespace adoption

IndicatorWhat it measuresStronger evidence of successWeak or misleading signal
Production service deploymentsOperational AI services using the namespaceIndependent production deploymentsDemonstrations without sustained use
Developer adoptionApplications using standardized integrationsActive integrations across unrelated organizationsSign-ups without implementation
Authenticated machine transactionsVerified service interactionsRecurring validated transactionsRaw DNS query counts
Credential interoperabilityCross-system identity verificationIndependent issuers and verifiersProprietary credentials accepted by one platform
Commercial renewalsPersistent customer demandHigh retention at sustainable pricesDiscounted first-year registrations
Security performanceResistance to abuse and impersonationComparable validated incident measuresUnsupported claims of inherent trust
Enterprise integrationUse in operational systemsContracted deployment and documented outcomesMarketing announcements
Governance opennessFair ecosystem participationPublished and enforced access criteriaNominal openness with restrictive implementation

These indicators provide a basis for distinguishing actual technological adoption from speculative anticipation.

Chapter 5 — Key judgments

Artificial intelligence is increasing the importance of trustworthy service identities, delegated authorization and auditable machine-to-machine transactions.

The technical challenge extends far beyond DNS resolution.

Open standards already provide mechanisms for service discovery, credential verification and authorization without requiring new generic top-level domains.

A specialized AI namespace can become useful if it supports an adopted ecosystem of interoperable services and trustworthy governance.

The growth of autonomous agents does not imply proportional growth in paid domain registrations, because many agents can operate under existing domains and identities.

The economic prospects of AI-related extensions will depend on actual deployment, interoperability, sustainable demand and the credibility of any accompanying trust framework.

The strategically valuable asset of the agentic Internet may ultimately be the infrastructure that verifies authority and enforces permissions, rather than the domain suffix through which an agent is discovered.

Chapter 6. Cybersecurity, Trademark Protection, DNS Dependence and Structural Market Risks

Principal judgment: expanding Internet naming increases the number of possible identity arrangements, but the security consequences depend on registry governance, registration practices, technical controls and the behavior of malicious actors—not on the number of extensions alone

The security implications of new top-level domains are frequently reduced to two opposing arguments. Proponents emphasize competition, innovation and greater choice. Critics emphasize phishing, brand impersonation, speculative registrations and new opportunities for deception.

Neither position is sufficient as a complete technical assessment.

An increase in available top-level domains expands the universe of names that can potentially be registered, subject to the policies governing each registry. This can create additional opportunities for legitimate users, businesses, communities and software developers.

It can also increase the number of potential naming combinations that trademark owners and security teams may need to consider.

However, the introduction of a new TLD does not automatically generate malicious activity. Nor does operating a controlled or restricted registry automatically guarantee that no malicious activity can occur.

The actual security outcome depends on the interaction between registration eligibility, identity verification, pricing, abuse detection, registrar behavior, infrastructure security, enforcement and user awareness.

The most consequential issue is therefore not simply the expansion of the namespace. It is the effectiveness of the governance arrangements supervising the names created within it.

ICANN’s contractual definition of DNS abuse establishes a narrower enforcement universe than the full range of online harms

ICANN’s contractual approach to DNS abuse is important because it determines the categories of harmful activity for which specific mitigation obligations have been established.

The organization identifies five categories within the relevant DNS abuse definition: malware, botnets, phishing, pharming and spam when used to deliver other forms of DNS abuse.

This is not an exhaustive definition of everything harmful that may occur online.

Online fraud, misleading commercial practices, unlawful content, intellectual-property violations, privacy breaches and other misconduct may engage different laws, contractual provisions or institutional responsibilities.

The distinction matters because ICANN’s competence is concentrated on coordinating Internet unique identifiers and enforcing contractual obligations within its remit.

It is not a general-purpose international regulator of all content and activity accessible through domain names.

Source: ICANN — DNS Abuse Mitigation Program, Institutional Definition and Contractual Scope, Updated November 2025.

This institutional boundary affects how new registry security should be evaluated.

A registry can meet certain DNS-specific contractual obligations without becoming an effective regulator of every possible unlawful activity conducted through its domains.

Conversely, failures in DNS abuse mitigation can have consequences extending far beyond the commercial domain-registration market.

The April 2024 amendments established stronger contractual obligations

On 5 April 2024, amendments to the Base Registry Agreement and Registrar Accreditation Agreement became effective, expanding contractual requirements relating to DNS abuse.

The amendments strengthened expectations concerning mitigation of well-evidenced abuse and established specific obligations for contracted parties.

Under the applicable arrangements, registrars and registries must take appropriate action in response to relevant abuse within the scope of their contractual responsibilities.

Importantly, the requirements do not mean that every reported allegation mandates an identical response.

Evidence, proportionality, the nature of the abuse and the technical position of the responsible party remain material.

The contractually available responses and obligations depend on whether the issue concerns an individual registration, registrar conduct, registry-level activity or wider infrastructure.

Source: ICANN — DNS Abuse Mitigation Program and 2024 Contractual Amendments.

The 2026 round will operate under the subsequently approved 2026 Base Registry Agreement, which was adopted by the ICANN Board on 12 March 2026.

That agreement defines the contractual requirements applicable to successful applicants, including relevant technical, security, operational and public-interest obligations.

Source: ICANN — Board Approval of the 2026 Base Registry Agreement, 12 March 2026.

The important consequence is that proposed registries are not entering an entirely unregulated technical environment.

They must satisfy an established contractual framework.

Nevertheless, effective protection depends on implementation and compliance rather than contractual language alone.

DNS abuse must be differentiated by attack mechanism

Different attacks exploit different weaknesses.

A phishing attack may use a misleading domain name to impersonate a recognized organization.

Pharming may manipulate name resolution or redirect a user toward an unintended destination.

Malware distribution may rely on a registered domain for delivery, command infrastructure or related functions.

Botnets may use domain names as components of their control infrastructure.

Spam may serve as a delivery mechanism for phishing or malware.

The countermeasures differ accordingly.

A trademark monitoring service may detect names resembling a brand, but it cannot substitute for technical investigation of malware infrastructure.

DNSSEC may protect the authenticity of DNS data under its trust model, but it does not prove that a website itself is legitimate.

TLS may encrypt a connection to an authenticated endpoint under its certificate-validation model, but it does not guarantee that the endpoint’s operator is honest.

Abuse mitigation therefore requires layered controls.

Table 6.1 — Threat mechanisms and relevant protections

ThreatAttack mechanismRelevant protectionsImportant limitation
Domain-based phishingDeceptive names and impersonated servicesRegistration monitoring, browser protections, takedown, authenticationLegitimate-looking names can still be abused
PharmingManipulation of resolution or redirectionSecure resolution, DNSSEC validation, infrastructure controlsDNSSEC does not secure every component
Malware distributionMalicious software hosted or distributed through named servicesThreat detection, domain suspension, endpoint protectionMalware may move between domains and infrastructure
Botnet infrastructureDNS used for command or rendezvous servicesThreat intelligence, coordinated mitigation, sinkholing where authorizedAttackers can adapt infrastructure
Spam-enabled phishingMalicious links or payload deliveryEmail authentication, filtering, abuse reportingDomain registration controls alone are insufficient
Credential theftDeceptive interfaces or compromised servicesPhishing-resistant authentication, least privilegeUsers and services remain exposed to other attacks
Brand impersonationSimilar names, counterfeit sites or unauthorized representationsTrademark enforcement, monitoring, user educationExact-brand protection does not prevent all deception
Registry compromiseUnauthorized changes or disruption to registry systemsAccess control, monitoring, continuity and recoverySystemic consequences may affect many registrants
Registrar compromiseUnauthorized domain-management actionsAccount security, registry locks where available, audit logsControls vary by service and threat
Supply-chain compromiseAbuse of shared infrastructure or providersVendor security, independent controls, segmentationShared dependencies can increase correlated risk

A credible cybersecurity assessment should determine which controls are preventive, which are detective, which support response, and which improve recovery.

It should also distinguish technical protection from legal enforcement.

DNSSEC protects DNS data integrity, not the legitimacy of an organization

The Domain Name System Security Extensions provide mechanisms for authenticating DNS data using cryptographic signatures and chains of trust.

These mechanisms can help a validating resolver determine whether DNS responses have been altered and whether the data can be authenticated through the relevant delegation hierarchy.

The technical framework includes RFC 4035 and related DNSSEC specifications.

Source: IETF — RFC 4035, Protocol Modifications for DNS Security Extensions, March 2005.

DNSSEC does not establish that a commercial organization is honest or that an AI service is authorized to perform a particular transaction.

A malicious party controlling a legitimately registered domain can publish validly signed DNS records.

The signatures may establish integrity of the DNS data without establishing the legitimacy of the underlying activity.

That distinction is fundamental when discussing supposedly trusted or secure new domain extensions.

A registry should not present DNSSEC deployment as equivalent to universal identity assurance.

TLS certificates do not eliminate impersonation risk

Transport Layer Security provides mechanisms for encrypted communication and authentication of endpoints, normally through certificate validation.

Certificate issuance and validation involve separate institutional and technical processes from the allocation of generic top-level domains.

An attacker may possess a valid certificate for a domain it legitimately controls while using that domain to conduct phishing.

Accordingly, the presence of HTTPS cannot serve as independent proof that a website is an authorized representative of the organization it resembles.

DNS Certification Authority Authorization records provide an additional mechanism through which domain administrators can specify which certificate authorities are authorized to issue certificates for their domains.

Source: IETF — RFC 8659, DNS Certification Authority Authorization Resource Record, November 2019.

CAA is useful for constraining certificate issuance under the applicable ecosystem, but it is not a general fraud-detection mechanism.

It does not prevent all compromises, misleading registrations or abuse of otherwise valid credentials.

Email authentication introduces another security dependency

Domain names are also central to email identity and authentication.

Enterprise security teams must consider whether names under a newly introduced TLD will be used for legitimate corporate communication, phishing or impersonation.

The relevant controls include SPF, DKIM and DMARC, each serving a distinct function within the email authentication architecture.

DMARC associates authentication results with the domain presented in the visible message sender identity and enables domain owners to publish policies concerning the handling of messages that fail the applicable checks.

The governing technical specification is RFC 7489, although implementation practices and subsequent technical developments must also be considered.

Source: IETF — RFC 7489, Domain-based Message Authentication, Reporting, and Conformance, March 2015.

A brand owner introducing a new namespace should not assume that the mere existence of the extension will reduce email fraud.

It must establish whether email is permitted under the new domain, which systems are authorized to send, which authentication records will be deployed and how unauthorized or spoofed messages will be handled.

Some enterprises may choose not to use a namespace for email at all.

Such a policy can simplify certain aspects of risk management, but the actual protections still depend on technical configuration and enforcement.

Trademark protection becomes more complex when the namespace expands

A company operating internationally may own registered trademarks in multiple jurisdictions and commercial categories.

The introduction of new gTLDs can create additional naming combinations that may resemble those trademarks.

The resulting concern is not simply the number of newly available domains.

It is whether the new naming combinations create meaningful opportunities for consumer confusion, impersonation, cybersquatting or other rights violations.

A systematic trademark strategy must distinguish registered intellectual-property rights, legitimate third-party uses of similar words, protected geographic or community identifiers, and genuinely abusive domain registrations.

An overly broad assumption that every domain containing a brand-related word constitutes infringement would be legally unsound.

Trademark rights vary by jurisdiction, class of goods or services, use, reputation and other legal circumstances.

Generic or descriptive terms can also possess legitimate uses unrelated to a particular trademark owner.

ICANN’s rights-protection mechanisms address different stages of risk

ICANN’s established rights-protection framework includes the Trademark Clearinghouse, Sunrise processes, Trademark Claims services, the Uniform Rapid Suspension system and additional dispute-resolution mechanisms.

These mechanisms serve different functions.

The Trademark Clearinghouse supports validation and use of trademark information within defined rights-protection services.

Sunrise processes provide eligible rights holders with an opportunity to seek registrations during a designated launch period.

Trademark Claims mechanisms provide relevant notices associated with potentially conflicting registrations.

The Uniform Rapid Suspension procedure addresses qualifying clear-cut cases of infringement.

The Uniform Domain-Name Dispute Resolution Policy provides a separate established process for qualifying domain-name disputes.

Post-delegation procedures can address specified forms of registry conduct or noncompliance.

Source: ICANN — Rights Protection Mechanisms and Dispute Resolution Procedures.

These protections should not be described as interchangeable.

A warning mechanism does not automatically prohibit registration.

An expedited suspension process does not replace every possible trademark remedy.

A domain-name dispute procedure does not necessarily resolve broader damages claims or all questions of intellectual-property ownership.

Table 6.2 — Trademark and registry protection mechanisms

MechanismPrincipal purposeStage of applicationPrincipal limitation
Trademark ClearinghouseValidated trademark records supporting specified rights protectionsBefore and during registry launchNot a universal trademark enforcement authority
Sunrise registrationPriority registration opportunity for eligible rights holdersRegistry launch periodDoes not guarantee every desired name
Trademark ClaimsWarning and notification mechanismRelevant registration periodNotice does not automatically determine infringement
Uniform Rapid SuspensionExpedited relief for qualifying clear-cut casesAfter an abusive registrationNarrower than general litigation
UDRPAdministrative resolution of qualifying domain disputesAfter registrationDefined eligibility and remedy framework
Trademark PDDRPAddresses specified registry-level involvement in infringementPost-delegationNot a remedy for every individual dispute
PICDRPAddresses relevant public-interest commitment compliancePost-delegationLimited to applicable commitments
RRDRPAddresses specified community registration restrictionsPost-delegationRelevant to qualifying community-based arrangements

The economic impact of these protections should be examined through the costs of monitoring, enforcement, disputed registrations and successful remediation.

Their existence does not demonstrate that every rights holder can economically protect every conceivable variation of a trademark.

The problem of defensive-registration proliferation

A large trademark owner may consider registering names under multiple extensions to reduce the risk of impersonation or future disputes.

This can create recurring expenditure across a large portfolio.

However, expanding defensive registrations indefinitely is not necessarily an effective strategy.

The number of possible variations involving brands, products, geographic references, abbreviations, spelling errors and newly delegated extensions can be extremely large.

An enterprise cannot reasonably assume that buying every conceivable related name will eliminate impersonation.

Attackers can use misleading words, compromised legitimate sites, subdomains, social media, messaging systems and non-DNS identifiers.

The most economically effective strategy is therefore likely to combine prioritized domain registration with monitoring, authentication, legal enforcement and incident response.

The marginal security benefit of each additional defensive registration should be assessed against its cost.

A practical defensive-domain decision matrix

Domain categoryDefensive registration rationalePriority determinantAlternative or complementary control
Exact corporate trademarkStrong brand associationBrand criticality and legitimate availabilityTrademark enforcement and monitoring
Major product namesCustomer familiarityCommercial significance and impersonation riskCustomer communication and official directories
Common typographical variantsPotential user misdirectionObserved attack patternsBrowser protection and takedown
Geographic variantsRegional market relevanceActual operations and legal rightsRegional brand enforcement
Generic industry expressionsPossible commercial confusionDistinctiveness and legitimate third-party rightsMonitoring rather than universal acquisition
AI-agent-themed variantsPossible future impersonationActual agent deployment and expected user behaviorAuthenticated directories and credentials
Unrelated speculative stringsLow immediate protective valueDemonstrated risk rather than conjectureNo registration absent specific rationale

This framework should be applied dynamically.

A name that was low priority before a major product launch could become important if customers begin to associate it with an official service.

Conversely, a proposed extension with no demonstrated use case may not warrant extensive defensive registrations merely because it is newly available.

AI amplifies the consequences of domain impersonation

Autonomous software can create new operational risks when it retrieves instructions or data from external services.

An agent may encounter a malicious web page, forged service description or compromised endpoint that attempts to influence subsequent actions.

This differs from conventional phishing because the immediate target may be software behavior rather than a person’s decision to enter credentials.

An attacker may attempt to induce a system to reveal sensitive information, use unauthorized tools or change the interpretation of a legitimate task.

The security problem involves the separation of untrusted content from privileged instructions and authorized operations.

Domain validation can reduce some uncertainty about the source of content, but it does not establish that all content from an authenticated source is safe.

A compromised or maliciously controlled legitimate domain can still deliver adversarial instructions.

The security design must therefore assume that externally retrieved content can be untrusted even when the network endpoint is correctly authenticated.

This is an important limitation on proposals to use specialized domain extensions as a broad solution to agent safety.

The emergence of machine-speed abuse response

Automated software can generate requests, register names where commercial interfaces permit, deploy content and interact with services much faster than human-operated processes.

Defensive systems can also automate detection and mitigation.

The result is a competition between automated abuse and automated security controls.

A registry serving high-volume machine-oriented applications must consider the speed at which suspicious registrations, compromised services or malicious changes can affect users.

The operational requirements may include automated monitoring, validated reporting pathways, proportionate intervention and evidence preservation.

However, excessive automation can also create false positives.

Legitimate domains may be suspended incorrectly, causing disruptions to lawful businesses and users.

The governance challenge is therefore to balance rapid intervention with accountability, consistent procedures and mechanisms for correction.

The risks of concentrated technical infrastructure

The operation of multiple TLDs through shared technical suppliers can reduce cost and improve professional management.

It can also create common dependencies.

If numerous registries rely on a single technical provider, certain infrastructure failures, software vulnerabilities or operational errors could affect many extensions.

The relevant risk is not determined solely by the number of TLDs using the provider.

It depends on architecture, segregation, redundancy, operational controls, geographic distribution and the capacity to contain failures.

A platform supporting hundreds of TLDs can be highly resilient if it has appropriate controls.

A smaller platform may be fragile if its operations depend on a limited number of systems or personnel.

The concentration analysis must therefore examine both market share and failure correlation.

Table 6.3 — Shared infrastructure and systemic risk

DependencyPotential failureTransmission channelPrincipal resilience measure
Common registry back endDatabase or provisioning failureMultiple TLD operationsSegmentation, replication and recovery
Authoritative DNS providerResolution disruptionDomain availabilityDiverse infrastructure and monitoring
Cloud providerRegional or platform outageHosted registry servicesMulti-region resilience and tested recovery
Registrar integration platformProvisioning interruptionRegistration and updatesInteroperable interfaces and contingency arrangements
Credential infrastructureCompromised privileged identitiesUnauthorized changesStrong authentication and least privilege
Software supply chainVulnerable shared componentCross-registry exposurePatch governance and supply-chain assurance
Data escrow and recoveryIncomplete restoration capabilityProlonged service disruptionTested escrow and transition processes
Abuse-response providerDelayed or incorrect mitigationSecurity and availabilityOversight, escalation and auditability

The practical implication is that a diversified list of registry owners does not necessarily imply diversified infrastructure risk.

Likewise, consolidation among registry operators does not automatically mean inadequate resilience.

A technically sound assessment must examine the operational architecture.

DNS availability is an economic security issue

A domain registry supports services that may include commerce, communications, customer authentication and critical organizational processes.

A DNS disruption can therefore produce economic effects for registrants and third parties beyond the registry operator’s own financial losses.

The magnitude depends on the role of affected domains, incident duration, available alternatives and the ability of dependent applications to recover.

A top-level domain used mainly for experimental websites could have a different systemic consequence from one supporting essential enterprise services.

A sector-specific registry associated with financial, health or industrial activities may require particular attention to continuity, although the sensitivity of the domain label alone does not establish that its actual registrants perform critical functions.

Risk assessment must be based on real dependencies.

Name collisions and unintended technical consequences

New TLDs can introduce risks where a proposed name conflicts with naming conventions already used in private networks or internal software environments.

This is the problem of name collision.

A label intended for global DNS delegation may already be used informally within corporate networks, development environments or other private naming arrangements.

When the corresponding TLD becomes globally resolvable, certain queries may produce unexpected results.

The consequences depend on the technical configuration, affected applications and the nature of the collision.

ICANN’s 2026 evaluation framework includes name-collision analysis and procedures for addressing relevant risks.

Source: ICANN — 2026 Applicant Guidebook, String and Application Evaluation Procedures.

This is an example of a security and stability issue that cannot be inferred from commercial demand or trademark status.

A string can be commercially attractive and legally permissible while still requiring technical risk mitigation.

The existence of these procedures demonstrates why delegation is more complex than the sale of a name.

Homographs and internationalized domain names

Internationalized Domain Names permit the use of scripts beyond the basic Latin-letter domain-name repertoire, expanding the Internet’s ability to support linguistic diversity.

This has substantial inclusion and accessibility benefits.

It also introduces security challenges associated with visually similar characters, mixed scripts and representations that users may confuse with other names.

Not all internationalized names are deceptive. The problem arises when differences in underlying character sequences are not readily apparent to users or when software presents identifiers ambiguously.

Effective protection may involve registry policies, technical standards, script-specific rules, browser display practices and user-interface design.

A security strategy based solely on prohibiting non-Latin scripts would be both technically crude and inconsistent with the objective of a globally multilingual Internet.

The appropriate approach is to manage confusability while preserving legitimate linguistic participation.

The distinction between registry security and registrant security

A registry operator can maintain excellent technical infrastructure while individual registrants operate vulnerable websites.

Conversely, a registrant can implement strong application security while depending on a poorly administered registrar account.

The different layers require different controls.

Registry security concerns authoritative infrastructure, registration systems, contractual compliance and operational continuity.

Registrar security concerns customer account management, registration modifications and authorized transfers.

Registrant security concerns websites, email systems, application infrastructure, credentials and organizational policies.

These responsibilities overlap, but their allocation must remain explicit.

A security failure should be attributed to the relevant mechanism rather than automatically to the entire TLD.

The need for comparable DNS abuse statistics

Security comparisons between TLDs can be misleading when they use incompatible denominators or detection methods.

An extension with a large registration base may have more detected incidents in absolute terms simply because it has more domains.

A small registry may show a high incident rate because a limited number of cases have a large proportional effect.

Threat feeds differ in detection coverage, reporting delay, classification and false-positive behavior.

Some domains may be registered specifically for abuse, while others are legitimate sites that become compromised.

These distinctions affect prevention and enforcement responsibilities.

A defensible comparison should identify the observation period, registration population, abuse category, detection methodology and whether measurements involve unique domains, incidents or malicious URLs.

Table 6.4 — Security measurement requirements

MetricAppropriate numeratorDenominator or exposure measureMajor interpretation risk
Phishing-domain prevalenceUnique validated phishing domainsComparable active registration populationInconsistent detection coverage
Malware-domain prevalenceUnique validated malicious domainsComparable active registration populationCompromised versus maliciously registered domains
Incident frequencyValidated eventsAppropriate time and exposure periodMultiple incidents involving one domain
Abuse-report response timeTime from qualifying report to responseConsistently defined incidentsDifferent report quality
Mitigation effectivenessQualifying cases effectively remediatedVerified actionable casesAction does not guarantee permanent removal
False-positive suspension rateIncorrect qualifying interventionsTotal relevant interventionsMissing appeals and correction data
Registry availabilityMeasured DNS service availabilityDefined service and observation periodDifferent monitoring methodologies
Recovery timeDuration of defined service interruptionsComparable incidentsDependency on external infrastructure

Security evaluation should prioritize independently reproducible measurements where possible and transparently identify limitations.

A low recorded abuse rate may reflect strong security controls, but it could also reflect weak detection or reporting.

A high measured rate may indicate genuine problems, improved detection or concentration of particular attack types.

The raw number requires context.

ICANN’s compliance architecture and the limits of contractual enforcement

ICANN Contractual Compliance enforces relevant obligations contained in registry agreements, registrar accreditation agreements and applicable policies.

The organization conducts complaint-driven and proactive compliance activities, including audit processes.

However, ICANN’s authority derives from the applicable contractual and policy framework.

It cannot automatically exercise every power available to national police, courts, consumer-protection authorities or cybersecurity agencies.

Cooperation among different actors is therefore necessary when abuse extends beyond DNS-specific contractual matters.

The distinction is particularly important for incidents involving financial fraud, unlawful content, cross-border cybercrime or regulated services.

A registry may possess the technical ability to suspend a domain, but that does not mean it is the institution best positioned to determine every underlying legal dispute.

The response must consider competence, evidence, proportionality and applicable law.

The danger of overbroad domain suspension

Domain suspension can be an effective response to certain forms of abuse.

It can also cause collateral disruption.

A single domain may support multiple services, users or organizational functions.

Suspending it could interrupt legitimate communications, applications and transactions unrelated to the reported misconduct.

The consequences are particularly severe where organizations have concentrated numerous services under a small number of domains.

This creates a governance challenge for both registries and registrars.

Security interventions should be capable of responding quickly to well-evidenced threats while considering the scope of the action and the possibility of unintended harm.

The relevant operational framework should also preserve evidence, document decisions and enable appropriate review or remediation.

Structural market risks beyond individual cyber incidents

The expansion of DNS naming may introduce broader risks involving market concentration, infrastructure dependencies and identity fragmentation.

Identity fragmentation occurs when users and organizations must navigate an increasingly large number of naming systems without clear, consistent trust signals.

Market concentration can occur when a small number of corporate groups control significant naming portfolios or essential distribution and infrastructure functions.

Infrastructure dependence can arise when many nominally separate registries rely on a limited number of technical service providers.

These concerns are not reducible to phishing statistics.

They concern the architecture and governance of the domain-name ecosystem.

Table 6.5 — Structural risks and their economic transmission

Structural riskCausal mechanismPossible economic consequenceRelevant evidence
Naming fragmentationMore naming environments with inconsistent user expectationsConfusion and additional compliance expenditureAdoption and user-behavior research
Portfolio concentrationMultiple TLDs under common controlReduced competitive independenceUltimate ownership records
Distribution concentrationHeavy reliance on major registrarsEntry barriers and channel dependenceRegistrar registration shares
Technical supplier concentrationShared infrastructure supporting many registriesCorrelated operational failuresRSP relationships and resilience testing
Rights-enforcement inflationLarger set of potentially conflicting registrationsHigher monitoring and legal costsTrademark enforcement expenditure
Identity assurance gapsNames mistaken for verified authorizationFraud and misplaced trustSecurity incident records
Cross-border enforcement frictionDifferences among applicable legal regimesDelayed or inconsistent responsesJurisdictional and compliance evidence
Registry failureUnsustainable or noncompliant operationService transition and registrant disruptionContractual termination and transition records

The relevant policy objective should not be the elimination of every risk through restrictions on new TLDs.

It should be the creation of a system in which legitimate entry remains possible while security, consumer protection and systemic resilience are proportionately maintained.

The public-interest trade-off between openness and restriction

Strict registration eligibility can reduce certain forms of abuse, particularly when applicants are subject to meaningful verification.

It can also restrict legitimate participation and increase compliance expenses.

Open registration policies can encourage competition and accessibility, but they may require greater investment in monitoring, detection and response.

Neither arrangement is inherently superior for every category of registry.

A professional or sector-specific namespace may have a defensible reason to impose eligibility requirements compatible with its contractual obligations.

A broad generic registry may need to provide nondiscriminatory access consistent with the rules governing generic strings.

The appropriate security architecture depends on the purpose of the registry, the permitted registration model and the risks associated with its actual users.

Security obligations must be incorporated into the investment decision

A registry applicant should not treat cybersecurity as a technical appendix added after winning the naming resource.

The security architecture influences initial costs, operational complexity, supplier selection, contractual obligations and potential liability.

A project whose financial model assumes minimal security and compliance expenditure may materially underestimate the capital required for responsible operation.

Similarly, a company seeking to use a new brand registry for important business services should assess business continuity and incident response before deploying those services.

The economic and security analyses must be integrated.

Chapter 6 — Key judgments

The expansion of generic top-level domains can increase the range of available digital identifiers and possible brand-confusing combinations, but it does not mechanically determine the volume of DNS abuse.

Security outcomes depend on registration practices, technical safeguards, contracted-party behavior, detection quality and effective enforcement.

ICANN’s DNS abuse definition and contractual remit are narrower than the full range of harmful online activities.

DNSSEC, TLS, CAA and email authentication provide important but distinct protections. None transforms a domain suffix into a universal certificate of legitimacy.

Trademark protection requires selective registration, monitoring and enforcement rather than indiscriminate acquisition of every possible domain variation.

Registry and registrar concentration can create correlated operational dependencies even where individual TLD ownership appears diversified.

AI introduces further security challenges because authenticated software can still process malicious instructions or execute actions beyond legitimate authority.

The strongest security outcome will come from combining reliable naming infrastructure with independent identity verification, narrowly scoped authorization, resilient operations and accountable enforcement.

Pillar II — Integrated Technological and Competitive Assessment

The defining strategic issue: which part of the digital identity infrastructure will create lasting value?

The three chapters establish that Internet naming, software platform power, autonomous agent identity and cybersecurity operate through related but distinct mechanisms.

A top-level domain can provide a stable naming environment. A technology platform can provide access to users and developers. A credential framework can establish verifiable assertions. An authorization system can determine permitted actions. A security architecture can detect abuse and protect operational continuity.

An enterprise seeking to establish a trustworthy digital ecosystem may need several of these components, but no single component automatically supplies all the others.

This has major implications for the valuation of technology-related gTLD applications.

The principal commercial uncertainty concerns where value will accumulate as software interactions become more automated.

If users and developers continue relying predominantly on established domain names combined with portable credentials and open protocols, the incremental value of many new AI-oriented extensions may remain modest.

If particular naming conventions achieve widespread adoption through genuine interoperability and reliable governance, some specialized registries could become important components of digital infrastructure.

If proprietary platforms dominate service discovery and agent identity, economic power may concentrate in platform accounts, credentials, software directories and APIs rather than in the DNS extensions themselves.

These are alternative structural outcomes, not established forecasts.

Cross-chapter evidence and implications

Strategic questionDocumented technical baselineEconomic implicationPrincipal uncertainty
Can a TLD identify a service?DNS provides naming and resolution mechanismsUseful organizational and discovery functionActual adoption
Can a TLD authenticate an AI agent?Additional credentials and verification are necessaryNaming alone has limited assurance valueTrust-framework deployment
Can a TLD confer transaction authority?Authorization requires separate controlsNo automatic financial or legal authorityGovernance and delegation standards
Can a platform benefit from a controlled namespace?Names can integrate with existing servicesPossible complementary economic advantageIncremental value versus existing domains
Can a generic TLD be operated as a closed corporate category?ICANN imposes applicable generic-string restrictionsLimits exclusive appropriation of broad termsApplication classification and enforcement
Can DNSSEC prevent all domain abuse?DNSSEC authenticates DNS data under its trust modelValuable infrastructure protection, not universal trustConfiguration and attack type
Will AI agents generate more domain registrations?Agents can use existing domains and credentialsNo necessary proportional relationshipFuture product architectures
Will additional TLDs increase market competition?More naming products can be introducedPotentially greater choiceUltimate ownership and effective access
Will additional TLDs increase cybersecurity costs?More names may require monitoring, but risks varyPossible additional protection burdenActual abuse and defensive behavior

Five decision consequences for the 2027–2031 period

The first consequence concerns corporate digital sovereignty. Organizations should determine whether administering their own top-level domain creates materially greater control than operating secure, well-governed namespaces beneath existing domains. Control should be evaluated through deployable technical and contractual capabilities, not the symbolic appearance of the suffix.

The second concerns AI identity governance. Enterprises building agentic systems should give priority to verifiable identities, delegated authority, revocation, transaction controls and auditability. A recognizable namespace can complement these arrangements but cannot replace them.

The third concerns competition policy. Supervisory authorities should examine actual access restrictions, platform dependencies, vertical integration and economic concentration rather than treating every technology-related TLD application as evidence of market foreclosure. The distinction between potential and exercised market power must remain explicit.

The fourth concerns registry security and resilience. Infrastructure assessment should examine common suppliers, administrative privileges, continuity capabilities and compliance performance. Formal diversity of registered TLDs is not necessarily evidence of technical independence.

The fifth concerns capital allocation. Investors should require evidence of adoption and sustainable economic demand before valuing AI-oriented registry assets as indispensable future infrastructure. Technological relevance and investor expectations are not substitutes for demonstrated product-market fit.

Final net assessment — Pillar II

The 2026 expansion reflects a growing perception that the organization of digital identities may become strategically important as artificial intelligence and automated services develop.

That perception is credible. The transition toward more autonomous software creates new demands for service authentication, machine identity, delegated authority and cross-platform interoperability.

But the economic significance of these developments for new generic top-level domains is substantially less certain.

Existing technical standards already permit secure service discovery, encrypted communications, machine identities, credential verification and authorization using established Internet domains.

A new TLD may offer a commercially useful convention, a distinctive organizational identity or an adopted community framework. It does not inherently create technological exclusivity, cybersecurity assurance or regulatory authority.

The most significant competitive developments may therefore occur outside the registry business itself—in the standards, software platforms, identity systems and trust frameworks that determine how machines recognize and authorize one another.

The decisive strategic question is not who controls the most attractive word after the final dot. It is who controls the trusted mechanisms through which people, organizations and autonomous systems establish identity, delegate authority and execute consequential digital actions.

The DNS will remain a fundamental component of that infrastructure. Whether individual new extensions become indispensable assets or largely unused strategic holdings will depend on observable technological adoption, interoperability and durable economic utility.


PILLAR III — INTERNATIONAL GOVERNANCE, REGULATORY EXPOSURE AND THE FUTURE OF THE DNS

Chapter 7. ICANN’s Institutional Accountability and the Political Economy of Internet Governance

The governance of Internet naming is becoming an increasingly consequential question of international economic power

The central institutional issue raised by the expansion of generic top-level domains is not simply whether ICANN administers its application process efficiently, whether evaluation fees reflect legitimate expenditure, or whether competing applicants receive procedurally equitable treatment. Those questions remain essential, but they form only one part of a broader problem: an institution incorporated under the law of one country coordinates an indispensable component of global digital infrastructure while making decisions that can influence international commerce, corporate identity, linguistic representation, technological competition and the distribution of opportunities among organizations operating under very different legal and economic conditions. The authority exercised through the allocation and contractual governance of Internet naming resources does not constitute governmental sovereignty in the conventional sense, yet its economic consequences can resemble those associated with the administration of strategically important infrastructure. The distinction between formal institutional competence and practical influence is therefore indispensable. ICANN cannot legislate for sovereign states, issue generally binding international regulations or determine the legal rights of every Internet user, but the policies implemented through its contractual ecosystem can affect which organizations gain access to particular globally recognized namespaces, the conditions under which those namespaces operate and the technical requirements necessary for their participation in the coordinated DNS.

The political economy of this arrangement emerges from the fact that the DNS is both a common technical infrastructure and a framework within which private economic actors can establish differentiated commercial positions. A domain-name registry is not an ordinary public utility in the same legal category as an electricity transmission operator or telecommunications concessionaire, but certain aspects of its operation share the characteristics of network infrastructure: technical interoperability is essential, service continuity affects third parties, and the value of individual naming resources depends upon widespread reliance on a common system. These characteristics distinguish Internet naming from markets in which unsuccessful suppliers can withdraw without affecting dependent users. If a registry becomes responsible for names used by enterprises, institutions or public services, its operational reliability and contractual continuity acquire importance beyond the registry operator’s own financial position. Conversely, the existence of a technically functioning registry does not establish that its commercial model generates meaningful innovation, that its registrants obtain lasting utility or that the wider Internet benefits from the introduction of its extension. The challenge for international governance is to reconcile the legitimate commercial interests of registry operators with the stability, accessibility and trustworthiness of the infrastructure upon which their businesses depend.

ICANN’s formal mission provides the legal and institutional starting point for that assessment. Its current Bylaws establish responsibilities relating to coordination of the allocation and assignment of names in the root zone, development and implementation of policies within its defined remit, and the security and stability of the Internet’s unique identifier systems. They also impose limitations intended to prevent the institution from extending its authority into general regulation of Internet content or services outside its mission. Consequently, assessments of ICANN’s behavior should identify the precise policy, contractual provision or governance mechanism through which authority is exercised, rather than assuming that technical coordination confers unrestricted jurisdiction over digital commerce. The relevant constitutional framework is established in ICANN — Bylaws for the Internet Corporation for Assigned Names and Numbers, Articles 1–6, which provides the authoritative basis for distinguishing its mission, commitments, accountability arrangements, policy-development functions and community powers.

The transition from American stewardship to multistakeholder accountability

The contemporary governance structure cannot be understood without recognizing the institutional consequences of the 2016 IANA stewardship transition. Before that transition, the United States government, through the National Telecommunications and Information Administration, exercised a specified stewardship role in relation to the IANA functions, while the technical and operational activities associated with unique Internet identifiers were carried out through established institutional arrangements. The transition ended the historical NTIA stewardship arrangement and replaced it with a structure designed to strengthen accountability through the global multistakeholder community rather than continuing direct governmental contractual oversight. This did not transform ICANN into an intergovernmental organization, transfer its incorporation to a neutral international jurisdiction or eliminate the applicability of United States law. It changed the institutional relationship between the U.S. government and the coordination of IANA functions, while preserving the broader operational objective of a unified and interoperable Internet naming system.

The significance of this transition is particularly evident when governments question who ultimately possesses authority over Internet infrastructure. Multistakeholder governance rests upon the participation of businesses, technical experts, civil society, governments and other interested parties in the development of relevant policies. Its legitimacy derives partly from the technical expertise and participation of those constituencies, partly from the institutional mechanisms through which decisions can be challenged, and partly from its capacity to maintain an interoperable naming system across national boundaries. It does not derive from direct election by the world’s Internet users, and its legitimacy therefore cannot be evaluated using precisely the same criteria as those applied to sovereign parliaments. At the same time, participation by numerous stakeholder groups cannot by itself establish that economic influence is evenly distributed, that less-resourced participants can intervene effectively, or that highly technical deliberations are equally accessible to every affected community. The quality of multistakeholder governance must be evaluated through actual opportunities for participation, the treatment of competing interests, transparency of decision-making and the effectiveness of remedies when those decisions are challenged.

This produces a fundamental distinction between procedural representation and effective influence. A developing-country organization may have a formal opportunity to participate in a consultation while lacking the specialized personnel, technical expertise, legal resources or financial capacity necessary to intervene at the same level as a multinational technology company. An established registry operator may possess substantial institutional knowledge accumulated through years of participation in policy-development processes, whereas an applicant entering the system for the first time may struggle to understand the procedural consequences of a particular rule. An institution may therefore satisfy formal requirements for open participation while still exhibiting a substantial imbalance in practical negotiating capabilities. The appropriate response is not to assume that every decision favoring an established participant is illegitimate, but to examine whether procedural rules are accessible, consistently applied and supported by mechanisms capable of correcting consequential disparities.

ICANN’s accountability mechanisms are significant, but they are not substitutes for every form of democratic or judicial control

ICANN’s institutional architecture includes mechanisms intended to constrain the Board and organization, subject decisions to review and provide the community with defined powers. The Empowered Community can, under the conditions established by the Bylaws, exercise powers relating to budgets, operating and strategic plans, certain Bylaw amendments, Board composition and specified accountability processes. These powers are important because they distinguish the organization from a private corporation whose governing board can ordinarily change major strategic policies without equivalent community-based intervention. The framework creates institutional channels through which defined community bodies may challenge or block certain decisions, although the exercise of those powers depends upon procedural thresholds, escalation requirements and participation by designated actors. The operative structure is documented in ICANN — Empowered Community and Its Powers and ICANN — Empowered Community Process Documentation.

The Reconsideration Process and Independent Review Process perform different accountability functions. Reconsideration allows materially affected parties, within the applicable requirements, to seek review of certain Board or organizational actions or omissions. Independent Review provides a means through which qualifying claimants may contest covered actions alleged to violate ICANN’s Articles of Incorporation or Bylaws, with the matter considered through the prescribed independent review framework. Neither mechanism should be confused with a general international administrative court possessing unlimited authority to reconsider the economic wisdom of every naming decision. Their function depends upon the governing instruments, admissibility requirements, standards of review and available remedies. A decision may be economically controversial without necessarily violating ICANN’s Bylaws; conversely, a decision with plausible commercial justification may still be procedurally defective if it contravenes controlling obligations.

The practical strength of an accountability system also depends upon the cost and accessibility of obtaining a remedy. Sophisticated applicants can employ specialized legal and technical advisers to prepare objections, preserve evidence and challenge institutional decisions. Smaller organizations may face difficulties even when the same formal review procedures are available to them. Independent review is meaningful only if affected parties can identify potential violations, obtain relevant records, meet procedural deadlines and sustain the costs associated with a contested proceeding. This creates a further political-economic concern: rights that are formally equal may produce unequal outcomes when their exercise requires materially different levels of financial and institutional capacity. ICANN’s current accountability framework and its documented reconsideration and independent review mechanisms provide the primary reference for examining these issues, including the relevant standards of material harm and the distinction between internal reconsideration and independent review. See ICANN — Accountability Mechanisms and ICANN — Governance Guidelines.

Table 7.1 — Accountability mechanisms and their institutional limitations

MechanismAuthority or participantsPrincipal functionPractical strengthStructural limitation
Board oversightICANN BoardInstitutional direction and compliance with governing obligationsCentralized accountability for corporate decisionsDoes not itself provide external review
Empowered CommunityDesignated community bodies under the BylawsExercise specified community powersAbility to challenge important institutional decisionsProcedural thresholds and coordination requirements
ReconsiderationQualifying materially affected applicants or other partiesReview specified actions and omissionsInternal corrective pathwayAdmissibility, scope and procedural requirements
Independent Review ProcessEligible claimants and independent review panelistsAssess covered actions against governing instrumentsIndependent examination of qualifying disputesNot general judicial review of every policy outcome
OmbudsmanICANN OmbudsmanFairness assessment and conflict-resolution functionsInformal and institutional redress opportunitiesRole and remedies are defined by governing provisions
Public commentCommunity participantsScrutiny of proposed policies and institutional actionsOpportunity for open participationComments do not necessarily determine the final decision
Contractual ComplianceICANN organizationEnforce relevant contracted-party obligationsOperationally enforceable requirementsLimited to applicable contractual and policy jurisdiction
Governmental Advisory CommitteeGovernments and governmental participantsPublic-policy adviceDirect communication of governmental concernsAdvice is not equivalent to sovereign legislation

The existence of these mechanisms should neither be discounted nor treated as proof of complete accountability. Their effectiveness must be established through actual decision records, disclosure practices, case outcomes and the ability of affected parties to obtain meaningful correction. Particularly relevant is the 2026 process examining ICANN’s wider review architecture. On 25 June 2026, ICANN published a draft report on the Review of Reviews, following work initiated in 2025 to consider whether existing periodic review arrangements remain fit for purpose. That process demonstrates that institutional accountability is itself the subject of continuing reform rather than an issue permanently resolved by the 2016 transition. The supporting record is ICANN — Review of Reviews Draft Report, 25 June 2026.

The problem of institutional independence in a system financed by participating market actors

The political economy of Internet governance is shaped by a difficult financing problem. ICANN must possess sufficient financial and professional resources to perform technical coordination, administer evaluations, enforce contracts, support relevant policy processes and maintain institutional independence from individual commercial participants. A system relying exclusively on voluntary contributions could create obvious risks of dependence on donors, while direct financing by one or several governments could undermine the multistakeholder character of the organization. Contractual fees and program-based charges provide an alternative mechanism that distributes costs across businesses and organizations participating in the naming ecosystem. Such arrangements may create operational stability, but they also require careful examination of how program costs are determined, how financial reserves are managed and whether the institution’s funding arrangements create incentives to preserve administrative complexity or expand activities beyond demonstrable public need.

The problem is more subtle than a simple accusation of profit-seeking. A nonprofit organization does not distribute earnings to private shareholders in the manner of an ordinary commercial company, but it can accumulate reserves, expand employment, commission external services, undertake new programs and exercise discretion over resource allocation. The appropriate financial question is consequently whether the organization deploys resources efficiently and consistently with its stated mission, rather than whether it records any positive annual financial result. The distinction between institutional financial sustainability and economic rent extraction is particularly important when a program operates in an environment where applicants have limited alternatives to the recognized allocation mechanism. If a participant needs a globally recognized new gTLD, the administrative process is not substitutable with an ordinary commercial registrar purchase. This institutional position creates a heightened responsibility to justify procedural costs and make allocation decisions subject to proportionate scrutiny.

For this reason, a comprehensive review of financial accountability should go beyond examination of the evaluation fee charged to each applicant. It should assess the separation of ordinary institutional funding from round-specific costs, the treatment of auction proceeds, external procurement practices, assumptions used in determining the size of financial reserves, and the extent to which program expenditures can be linked to necessary evaluation and oversight activities. Procurement contracts and administrative costs should be assessed according to delivered services and reasonable comparators rather than assumed to be excessive merely because they are substantial. Similarly, financial reserves should be evaluated against legitimate operational continuity, litigation exposure, technical obligations and foreseeable liabilities. The public-interest criterion is whether the costs imposed on participants are proportionate to the functions required to preserve an open, secure and stable DNS.

Policy development can produce forms of regulatory capture without conventional corruption

In specialized international governance environments, regulatory capture need not involve illegal payments or explicit favoritism. It can emerge when the technical vocabulary, institutional knowledge and procedural assumptions of an organization increasingly reflect the perspectives of participants with the greatest capacity to influence its deliberations. Large contracted parties may possess detailed experience of operational requirements that genuinely improves the quality of technical regulation. The same expertise can also give established participants an advantage in shaping compliance obligations, evaluation methodologies and implementation timetables. A requirement that appears neutral may impose relatively modest incremental costs on an established operator while creating a substantial entry barrier for a smaller applicant. Conversely, relaxing an operational requirement to facilitate entry may impose unacceptable stability or security risks. The proper analysis must therefore identify the objective served by each rule, the evidence supporting it, the availability of less burdensome alternatives and its differential impact across participant categories.

This question becomes more important as the domain industry develops overlapping relationships among registry operators, registrars, technical back-end providers, intellectual-property service companies and investors. Corporate structures can allow a limited number of economic groups to participate in several parts of the value chain, creating legitimate opportunities for scale economies and integrated service delivery while potentially increasing influence over industry standards and contractual practices. Ownership concentration alone does not establish anticompetitive behavior, and participation in governance is not improper merely because a company has a financial interest in the outcome. However, sound institutional governance requires disclosure of material interests, appropriate recusal rules, transparent policy-development records and access to participation for parties whose economic interests are not already represented through established industry organizations.

A rigorous examination would therefore compare policy participation and the distribution of benefits arising from specific decisions. If a compliance measure improves technical security but also strengthens incumbents, both effects should be recognized. If an evaluation rule excludes certain applicants, the key question is whether exclusion follows a technically necessary criterion or an avoidable administrative burden. The most defensible approach is to assess individual governance mechanisms rather than to infer capture from the existence of commercial participation. ICANN’s policy-development and institutional structure is described in its 2026 Applicant Guidebook — Executive Summary, which explicitly connects the current round to the community-developed Subsequent Procedures policy recommendations.

Governments participate in ICANN without replacing its multistakeholder structure

The Governmental Advisory Committee provides a channel through which governments can communicate public-policy concerns within ICANN. This is particularly significant for proposed strings with potential implications for geographic names, sensitive public interests, consumer protection, national identity or other issues extending beyond ordinary commercial competition. The framework nevertheless preserves a distinction between government advice, ICANN’s internal procedures and binding national law. A government participating in the GAC does not thereby obtain unrestricted authority to determine every registry allocation, just as ICANN’s approval of a string cannot exempt a registry operator from applicable national legislation.

The 2026 program permits a range of interventions, including public application comments, singular/plural notifications, GAC Member Early Warnings and collective GAC Consensus Advice, while formal objections are reserved for parties satisfying the applicable standing requirements. These channels should be treated separately because their legal and procedural effects are not identical. Public commentary can alert evaluators to concerns but does not automatically establish a ground for rejection. An early warning indicates governmental concern but is distinct from collective advice. A formal objection must proceed through the authorized dispute-resolution mechanism and satisfy its governing requirements. This architecture reflects the attempt to incorporate public-policy considerations without transforming each application into an unrestricted intergovernmental negotiation. The operative distinction is explained in ICANN — Who Can Provide Input on New gTLD Applications?, 2026.

Alternative naming systems introduce a new kind of institutional competition

The long-term authority of the globally coordinated DNS rests substantially on interoperability and adoption. Alternative naming systems, including blockchain-related naming environments and private resolution arrangements, may attempt to provide identifiers that are not necessarily recognized through the ordinary DNS root. Their existence does not imply that the coordinated root has lost its importance, but it introduces a strategic distinction between technical monopoly and network-based coordination. Users obtain substantial benefits when a name resolves consistently across browsers, applications and networks. Competing naming systems may offer different ownership or governance arrangements, but they can also generate collisions, inconsistent resolution and additional security burdens if identical labels have different meanings in different environments. The economic question is therefore whether alternatives create genuinely useful capabilities without undermining interoperability, or whether they reproduce naming scarcity within smaller and less universally recognized ecosystems.

The issue became sufficiently important that ICANN sought community feedback in August 2026 on a Technical Study Group report concerning gTLD integrations with alternative naming systems. That development is significant because it demonstrates institutional recognition that the DNS increasingly interacts with naming technologies developed outside the traditional registry model. The implications extend beyond competition between registry businesses. If software platforms begin resolving names according to different local priorities, users could encounter environments in which the apparent identity of a service depends upon the resolution system used. Such fragmentation would increase the importance of resolver behavior, authentication mechanisms and clear technical governance. The relevant institutional record appears in ICANN — 2026 Program News and Announcements, including the 11 August 2026 alternative naming systems consultation.

Chapter 7 — Institutional findings and decision consequences

The evidence supports a conclusion that ICANN’s legitimacy depends on a combination of technical performance, institutional restraint, transparent financial administration and enforceable accountability rather than on any single legal characterization of the organization. Its California incorporation creates a continuing connection to U.S. law, while its multistakeholder governance framework seeks to prevent the coordination of Internet identifiers from becoming an exclusive governmental or commercial prerogative. The two characteristics are not mutually exclusive, but they create tensions whenever international participants perceive asymmetry in legal exposure, representation or access to resources. The 2026 expansion intensifies these tensions by allocating naming opportunities to applicants with unequal financial capabilities, institutional experience and access to complementary technology infrastructure.

The decisive reform priority is therefore not the elimination of fees, auctions, governmental participation or commercial interests. It is the establishment of demonstrably proportionate procedures, transparent decision records, effective conflict-of-interest controls, comparable opportunities to participate, and remedies accessible to materially affected parties. A system that produces technically stable delegations but cannot explain its allocation decisions or financial burdens risks weakening its institutional legitimacy. Conversely, a system that maximizes procedural participation while compromising technical stability would also fail its public mission. ICANN’s principal governance challenge for the coming years will be to preserve the efficiency of coordinated naming infrastructure while demonstrating that economic power does not translate automatically into procedural privilege.

Chapter 8. The United States, European Union, Italy, France, Germany, United Kingdom and Emerging Economies

The territorial regulation of a globally coordinated naming system is creating differentiated legal exposure for registry operators

The principal international development affecting the governance of domain-name infrastructure is the increasing divergence between the geographical reach of Internet naming services and the territorial authority of the institutions responsible for regulating them. A top-level domain may be delegated through a globally coordinated process, administered by a company incorporated in one jurisdiction, technically operated through infrastructure distributed across several countries, sold through registrars located elsewhere and used by registrants whose activities are subject to still other legal systems. The technical unity of the DNS therefore coexists with a fragmented regulatory environment. This fragmentation is not necessarily evidence of institutional failure: states retain legitimate responsibilities for cybersecurity, privacy, competition, consumer protection and national security, even when relevant services operate across borders. The difficulty arises when different legal obligations overlap, impose incompatible requirements or create uncertainty about which authority can demand particular information or operational measures from an internationally active registry.

The 2026 application round makes these questions more important because successful applicants will enter an operating environment different from the one faced by many participants in the 2012 round. The European Union has developed a more comprehensive framework for regulating digital infrastructure, platform conduct and cybersecurity. The United Kingdom has continued to develop its own post-Brexit cyber-resilience legislation and national-security investment controls. The United States retains jurisdictional connections to ICANN while applying its own competition, sanctions, cybersecurity and national-security laws. European national registries possess mature infrastructures whose financial and operational models provide important comparative evidence, while developing economies confront different combinations of infrastructure needs, financing constraints and linguistic accessibility.

These distinctions prevent any meaningful assessment from treating the international market as a single regulatory jurisdiction. A registry operating a new generic extension may be subject to ICANN’s contractual requirements and national cybersecurity obligations simultaneously. Whether a particular obligation applies depends on the nature of the service, the location and legal status of the operator, the rules governing jurisdiction and any applicable exceptions. The analysis must therefore distinguish between the legal status of ICANN, the regulatory treatment of a registry operator and the obligations of registrars and other service providers. These are related but legally distinct issues.

United States — institutional jurisdiction, technology concentration and the strategic value of interoperability

The United States occupies a distinctive position in Internet governance because ICANN is incorporated in California and major American technology companies possess substantial capabilities in cloud infrastructure, software platforms, online services and digital identity. These two sources of influence should not be collapsed into a single governmental strategy. ICANN’s multistakeholder governance framework is institutionally distinct from the commercial objectives of American technology enterprises, and the U.S. government does not possess an unrestricted right to allocate every generic top-level domain. Nevertheless, corporate jurisdiction, national legal authority, sanctions compliance and the concentration of important technology assets create practical channels through which developments in the United States may affect the wider naming ecosystem.

American jurisdiction is especially relevant where institutional decisions, contractual obligations or corporate transactions create disputes subject to U.S. law. ICANN’s incorporation exposes it to the applicable legal framework of its domicile, while registry operators and other businesses may independently be subject to U.S. law through incorporation, assets, transactions, counterparties or other jurisdictional connections. The resulting legal exposure does not mean that every non-American registry is automatically governed by all American legislation, but neither can globally distributed technical operations be assumed to eliminate the consequences of U.S. jurisdiction. Questions involving sanctions, contractual enforcement, competition and national security require examination of the specific legal relationship rather than a general appeal to the borderless character of the Internet.

The economic dimension is equally important. Established American technology companies can integrate naming resources into businesses operating at considerable scale, including cloud platforms, enterprise software, developer ecosystems and AI services. A new domain extension may therefore support corporate activities whose competitive significance lies outside the market for domain registrations. Under conventional U.S. antitrust principles, the relevant issue would not ordinarily be the acquisition of a desirable word alone, but whether conduct involving that resource contributes to unlawful exclusion, maintenance of monopoly power or other prohibited restraints under applicable law. Such questions are fact-specific and require analysis of market definition, competitive effects, business justification and the conduct of the parties concerned. It would be premature to infer an antitrust violation from the submission of an application, even by a company already possessing substantial market power in an adjacent technological sector.

The United States also has an important interest in preserving globally interoperable technical infrastructure. An Internet in which alternative naming roots, national restrictions or incompatible resolution systems become increasingly prevalent could impose costs on American businesses and international users alike. Conversely, reliance on a globally coordinated naming environment can raise concerns among states that perceive the institutional concentration of Internet infrastructure as a potential source of external dependency. The American strategic interest therefore combines the commercial advantages of global interoperability with the diplomatic and institutional challenges of preserving confidence in governance arrangements that remain connected to U.S. jurisdiction. The relevant starting point remains ICANN’s current Bylaws and institutional governance framework, rather than an assumption that Internet naming is administered directly as an instrument of American foreign policy.

European Union — cybersecurity obligations transform DNS infrastructure into a directly regulated sector

The European Union’s regulatory position is particularly consequential because Directive (EU) 2022/2555, commonly known as NIS2, expressly addresses top-level-domain registries, DNS service providers and entities providing domain-name registration services. The directive establishes an EU framework for cybersecurity risk management, incident reporting, supervision and enforcement, subject to the responsibilities of the Member States and the detailed provisions of the instrument. Importantly, its scope is not determined solely by the conventional size thresholds that apply to many other entities. Article 2 includes specified categories of DNS and domain-registration operators irrespective of size, while the directive defines the relevant types of entities and their roles. This means that a small operator cannot safely assume it falls outside the framework merely because it has limited revenue or a small number of employees. At the same time, applicability to a particular corporate brand registry or other special-purpose operator must be assessed carefully against the definitions, exceptions and applicable national implementing provisions.

The controlling instrument is Directive (EU) 2022/2555, Articles 2, 21, 23, 26–28 and Annex I. Its importance extends beyond the introduction of ordinary cybersecurity obligations because the directive addresses the collection and maintenance of domain-registration data. Article 28 requires Member States to ensure that TLD registries and entities providing domain-name registration services maintain accurate and complete registration data, subject to the applicable data-protection framework, and establish policies and procedures concerning accuracy and access. This creates an important relationship between infrastructure resilience, the traceability of domain registrations and the protection of personal information. The legislation does not authorize indiscriminate disclosure of all registrant information to every requester, nor does data protection eliminate the need to maintain relevant information and respond to lawful requests. Compliance requires systems capable of reconciling both objectives.

The regulatory framework was further specified by Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, which establishes technical and methodological requirements for cybersecurity risk-management measures and further defines significant incidents for specified digital infrastructure and service categories, including DNS service providers and TLD registries. The regulation addresses matters such as information security policies, incident handling, business continuity, supply-chain security and other organizational controls. Its operational significance lies in reducing the extent to which covered organizations can rely on broad, self-defined claims of adequate cybersecurity without demonstrating compliance against specified measures. This does not mean that every covered company must deploy an identical technical architecture, but it materially strengthens the basis for supervisory comparison. The operative legal instrument is Commission Implementing Regulation (EU) 2024/2690, 17 October 2024.

Table 8.1 — European regulatory obligations affecting domain infrastructure

Legal instrumentRelevant provisionsMain area of controlConsequence for relevant operators
NIS2 Directive, EU 2022/2555Articles 2, 21, 23, 26–28Cybersecurity, registration data, reporting and jurisdictionMandatory risk governance and applicable supervisory obligations
Implementing Regulation EU 2024/2690Technical and methodological requirementsSecurity controls and significant incident criteriaMore specific operational expectations
GDPR, EU 2016/679Articles 5, 6, 12–22, 32Personal-data processing and securityLawful processing, protection and accountability
Digital Markets Act, EU 2022/1925Gatekeeper-specific obligationsContestability and fairness in specified platform marketsPotential relevance where naming is integrated with designated core platform services
Digital Services Act, EU 2022/2065Applicable intermediary-service provisionsOnline intermediary obligationsDepends on the actual services provided; registry status alone does not establish all obligations
EU and national competition rulesArticles 101 and 102 TFEU and corresponding frameworksAgreements and abuse of dominanceScrutiny of conduct with established competitive effects

The Digital Markets Act requires particular precision. It is not a general law requiring every domain registry to provide open access under identical terms, nor does it automatically make an operator subject to gatekeeper duties because that operator has obtained an attractive technology-related extension. Its relevance arises where a designated gatekeeper provides covered core platform services and the integration of naming arrangements forms part of conduct subject to the specific obligations of the regulation. In such circumstances, naming-related arrangements may become relevant evidence concerning access, interoperability or discriminatory treatment, but the legal inquiry must remain grounded in the actual provisions and designated services. The source is Regulation (EU) 2022/1925 — Digital Markets Act.

The strategic consequence is that the European Union may exercise considerable influence over internationally active registry businesses without controlling ICANN’s global allocation process. It can regulate covered operators and services within the relevant scope of EU law, establish cybersecurity and personal-data requirements, and investigate conduct falling within its competition framework. This is a different form of power from authority over the DNS root. The Union’s influence arises through access to its market, supervisory jurisdiction and the legal obligations applicable to entities serving or operating within that jurisdiction. Such influence may improve resilience and trust, but it can also create additional compliance burdens for smaller entrants, making proportional implementation and consistent interpretation especially important.

Italy — the strategic distinction between national naming infrastructure and dependence on international digital platforms

Italy’s position should be assessed through two related but different institutional environments. The first is the established country-code domain .it, administered through Registro .it, the registry associated with the Institute of Informatics and Telematics of the Italian National Research Council. The second is the broader digital economy, in which Italian companies, universities, public institutions and technology providers use generic domains, international platforms and externally supplied infrastructure. The national domain provides a recognizable framework for Italian digital identity and an operational registry ecosystem, but it does not create general national control over every DNS service used by Italian citizens or businesses. Similarly, the acquisition of a new generic extension by an Italian company would not transfer the corresponding registry into the legal or technical category of the national country-code domain.

Italy’s industrial structure makes the economic implications of naming policy particularly relevant for small and medium-sized enterprises. A large multinational may treat a new gTLD as one component of a wider intellectual-property or infrastructure portfolio, whereas a specialized Italian manufacturer, professional association, regional industry consortium or digital service provider may need to justify any such expenditure against competing investments in production, cybersecurity, international distribution and software modernization. The practical question is whether the additional namespace creates measurable benefits for export activity, identity assurance, professional collaboration or sector-specific services. For many companies, strengthening established domains, securing customer-facing communications and improving verifiable digital identities may deliver greater immediate value than attempting to operate a new registry. For a sufficiently organized industrial or professional community, however, a dedicated namespace could support common identification or coordination arrangements if accompanied by appropriate governance, technical capability and sustainable financing.

The Italian institutional framework also creates responsibilities beyond commercial branding. Operators that fall within the applicable scope of the national legislation implementing NIS2 must satisfy the relevant cybersecurity requirements, while personal-data processing remains subject to GDPR and the corresponding national supervisory environment. Responsibility for technical operations cannot necessarily be avoided merely by outsourcing infrastructure to a foreign service provider. Contractual arrangements must identify which party performs which function and how evidence of compliance, incident reporting and continuity is maintained. For industrial enterprises considering registries that might support production systems, machine identities or supplier networks, these obligations should be incorporated into investment appraisal from the beginning rather than treated as administrative requirements arising after delegation.

Italy also has a distinct interest in the internationalization of domain names and the preservation of linguistic and cultural accessibility. The value of an Internet naming system should not be measured solely by its compatibility with English-language commercial brands. Regional languages, cultural institutions, research communities and specialized professional sectors may derive benefits from well-governed naming structures that are not adequately captured through conventional retail registration economics. Nevertheless, the existence of a culturally recognizable label cannot establish technical interoperability or commercial sustainability. Successful deployment requires that browsers, mail systems, application software and associated digital services correctly process the names. The relevant institutional reference for the wider problem is ICANN — Universal Acceptance and Internationalized Domain Names.

For Italy, the principal policy opportunity is therefore not to compete indiscriminately for new extensions, but to develop a coherent evaluation framework separating corporate branding, industrial interoperability, community identity and strategic infrastructure requirements. National institutions can encourage technical preparedness, support digital security and promote effective participation in Internet governance without assuming that each sector needs its own top-level domain. The decisive success criterion would be demonstrable utility for Italian users and enterprises, rather than the nominal number of strings associated with Italian applicants.

France — national domain governance, digital sovereignty and measurable registry performance

France offers particularly useful evidence because Afnic publishes detailed information about the operation of the .fr namespace. According to Afnic’s review of 2025 activity, the registry had 4,319,120 registered .fr domain names at 31 December 2025, recorded 853,000 new creations during the year, achieved 2.4% growth in the domain stock and reported an 82.2% retention rate. These figures are valuable because they measure different aspects of an operating registry rather than treating the existence of domain registrations as a complete indicator of economic health. New creations represent a flow of registrations; the year-end count represents the active stock; and retention helps assess whether customers continue to maintain names after acquisition. The data also demonstrate that a mature national domain can sustain meaningful demand without relying primarily on the introduction of new suffixes. The official record is Afnic — 2025 Review of the .fr, 31 March 2026.

France’s strategic approach to digital sovereignty is relevant because it emphasizes the importance of infrastructure, institutional responsibility and the capacity to enforce domestic and European law over critical digital services. In the domain-name context, however, sovereignty must be defined precisely. Operating the national country-code registry provides a degree of organizational and technical control over the .fr namespace within its applicable governance arrangements. It does not mean that France can unilaterally control global DNS root coordination or prevent all French businesses from depending on foreign platforms. Similarly, a French company acquiring a generic extension obtains contractual authority over that extension rather than sovereign jurisdiction over its terminology or users.

The relationship between national registry resilience and European regulatory obligations is particularly important. Afnic’s operational experience illustrates the scale at which registry organizations must administer registrations, work with distribution partners and support ongoing technical reliability. Such experience can be relevant to the development of shared technical services, participation in standards processes and industry cooperation. But its economic success cannot simply be transferred to an unfamiliar new generic extension. A national domain benefits from a recognizable geographical identity and an established market position, whereas a new commercial registry must establish its value proposition within a crowded global naming environment. The distinction is essential when comparing projected investments with historical registry data.

For French policymakers and enterprises, the central issue is how to preserve trusted national infrastructure while ensuring that domestic companies remain capable of participating in international naming and identity systems. Regulatory oversight should focus on resilience, lawful registration-data handling, supply-chain dependence and fair market access rather than assuming that domestic ownership of a particular extension automatically creates sovereignty. France’s established .fr statistics provide a useful empirical benchmark, but they also show why the durability of registrations and the quality of services matter more than the number of newly introduced labels.

Germany — cooperative registry governance, infrastructure resilience and international demand

Germany provides another important comparative model through DENIC, the cooperative organization responsible for the .de country-code registry. DENIC’s 2025 activity reporting recorded 17,663,886 .de domains at year-end, with 15,496,399 held by registrants in Germany and 2,167,487 held by registrants abroad. The international component represented approximately 12.3% of the recorded domain stock in the detailed activity report, demonstrating that a country-code extension can attract substantial demand beyond its domestic market. The figures also illustrate a methodological point: a domain’s country-code designation does not mean that all registrations, commercial activities or technical dependencies associated with that namespace are located in the corresponding country. The evidence appears in DENIC — 2025 Activity Report and DENIC — 2025 Domain Statistics.

DENIC’s cooperative governance structure is significant because it differs from the straightforward model of a privately owned registry pursuing shareholder returns. Its institutional arrangements and operational responsibilities create a distinct relationship between participating industry members, technical infrastructure and the broader stability of the national namespace. This should not be interpreted as proof that cooperative ownership is necessarily superior to every commercial alternative. Its relevance lies in demonstrating that large-scale registry services can be organized through different ownership and governance structures while remaining dependent on common technical standards and international coordination. The effectiveness of each structure must be judged by service quality, resilience, financial sustainability, transparency and the treatment of users and market participants.

Germany’s industrial economy introduces further considerations. Enterprises active in manufacturing, automotive systems, industrial automation, software engineering and business-to-business services increasingly depend on machine identities, secure software interfaces and reliable network services. New naming conventions could support some of these functions, particularly where they provide consistent identifiers across complex organizational environments. Yet the decisive security and interoperability requirements generally arise from engineering standards, authentication systems, operational governance and the management of digital credentials rather than from the top-level suffix alone. A German industrial consortium considering a specialized namespace should therefore evaluate whether the proposed registry improves interoperability across independent suppliers and customers or merely adds another proprietary naming layer.

Germany’s regulatory environment also makes NIS2 implementation and the European cybersecurity framework directly relevant to registry operators and service providers. The key compliance issue is whether companies can demonstrate effective security risk management and continuity across outsourced and interconnected infrastructure. DENIC’s scale illustrates the importance of mature operational processes, but new entrants should not assume that access to a shared technical provider automatically resolves their own governance duties. The distinction between outsourced execution and retained responsibility is central to the European regulatory model.

United Kingdom — national-security screening introduces a distinct investment dimension

The United Kingdom’s position combines an established national domain industry with cybersecurity and foreign-investment controls that can have direct implications for strategically important digital infrastructure. Nominet administers the .uk namespace and publishes operational and domain-registration statistics. Its 2025 records distinguish among several second-level registration categories, including .co.uk, direct .uk registrations, .org.uk and others. This matters because the commercial and regulatory behavior of these categories cannot be captured accurately by treating .uk as a single undifferentiated retail product. Domain usage, customer profiles, registration patterns and market demand vary among the categories even though they operate beneath the same country-code extension. The relevant primary source is Nominet — Reports and Statistics.

The United Kingdom has a particularly notable approach to national-security screening of certain infrastructure acquisitions. Official guidance under the National Security and Investment Act identifies acquisitions involving top-level-domain registries and other digital infrastructure among categories potentially subject to mandatory notification when the specified conditions and thresholds are met. For qualifying TLD registry activities, the guidance identifies a threshold involving 14 billion or more DNS queries from UK devices during a consecutive 168-hour period. Other thresholds apply to specified DNS resolver, authoritative hosting and Internet-exchange activities. These conditions should not be generalized to every registry acquisition, because the mandatory-notification rules depend on the defined activity and the relevant statutory thresholds. Nevertheless, they demonstrate that a state’s national-security investment regime can attach strategic significance to DNS infrastructure based on its operational role rather than the commercial attractiveness of its domain names. The governing guidance is UK Government — National Security and Investment Act: Notifiable Acquisitions in Defined Sectors.

This introduces an additional dimension to registry valuation. A transaction involving a significant infrastructure operator may face regulatory scrutiny unrelated to the nominal price of its domain portfolio. The acquirer’s ownership structure, the nature of the services, the scale of UK exposure and the potential consequences for security or resilience may become relevant. Such scrutiny does not establish that an acquisition will be prohibited, but it can influence transaction timing, due diligence, contractual conditions and the assessment of execution risk. An investor evaluating a registry business should therefore distinguish the value of the registration portfolio from the legal and security implications of controlling the infrastructure through which it operates.

The UK’s Network and Information Systems Regulations 2018 also provide a cybersecurity framework for relevant digital infrastructure. The government has pursued legislative changes through the Cyber Security and Resilience (Network and Information Systems) Bill, intended to update aspects of the regime and extend or strengthen relevant obligations. At the October 2026 analytical cut-off, the proposed changes should be treated as a legislative development rather than automatically as operative law unless enacted and commenced. This distinction is especially important for financial projections: businesses should prepare for foreseeable regulatory change without describing proposals as already binding. Sources include the UK Network and Information Systems Regulations 2018 and UK Government — Cyber Security and Resilience Bill, Summary of Proposals.

Comparative European and transatlantic regulatory exposure

JurisdictionPrincipal institutional focusRelevant infrastructure modelMajor regulatory exposureInvestment consequence
United StatesICANN domicile, technology platforms and federal legal jurisdictionGlobally significant corporate and technical ecosystemsCompetition, sanctions, contracts and applicable cybersecurity lawJurisdictional and corporate concentration considerations
European UnionDigital infrastructure resilience and personal-data governanceCross-border regulated marketNIS2, Implementing Regulation 2024/2690, GDPR and applicable competition rulesCompliance obligations extending beyond registry contracts
ItalyNational naming infrastructure and SME digital transformation.it registry and international service dependenciesNational implementation of EU cybersecurity and data rulesNeed for proportionate investment and domestic capability
FranceNational registry resilience and digital sovereigntyAfnic and established .fr marketEU cybersecurity framework and national supervisionStrong emphasis on reliable infrastructure and lawful governance
GermanyCooperative registry operations and industrial infrastructureDENIC and extensive .de registrationsEU cybersecurity obligations and national enforcementOperational continuity and complex industrial dependencies
United KingdomNational DNS infrastructure and security of ownershipNominet and wider digital infrastructureNIS regulations and qualifying national-security investment screeningPotential acquisition scrutiny and evolving cyber obligations

The principal conclusion from this comparison is that global naming coordination and national regulation are not alternative systems of authority. They operate simultaneously over different aspects of digital infrastructure. ICANN administers the internationally coordinated allocation and contractual governance of generic top-level domains, while states and regional institutions exercise legal authority over businesses, services, personal information, cybersecurity and competition within their jurisdiction. Conflict arises when actors attempt to convert one category of authority into another: when commercial applicants assume that obtaining a string confers unrestricted control over its economic use, when governments treat technical coordination as a substitute for domestic legal processes, or when registry operators underestimate the application of national legislation to globally accessible services.

Emerging economies — the difference between formal access and effective participation

The geographical distribution of the 2026 applications demonstrates the continuing concentration of participation in economically advanced regions. ICANN’s 7 October 2026 data record 864 applications associated with North America, 506 with Europe, 218 with Asia-Pacific, 16 with Africa and 11 with Latin America and the Caribbean. These regional labels identify the classification of applications in the published dataset; they do not necessarily establish ultimate ownership, beneficiary nationality or the location of all future services. Nevertheless, the distribution provides strong evidence that the financial and institutional capacity to participate is unevenly concentrated. According to ICANN’s own figures, Africa and Latin America and the Caribbean together accounted for just 27 applications, approximately 1.67% of the global total. The published basis is ICANN — Reveal Day Data Snapshot, 7 October 2026.

The geographical imbalance should not automatically be interpreted as evidence that applications from every region ought to be proportionate to population or national income. Commercial demand, the maturity of digital markets, the presence of relevant institutions and the availability of suitable business models differ substantially. However, the very low number of applications from some regions raises a legitimate question about whether the process provides accessible opportunities for organizations capable of generating public value but lacking the resources to compete on conventional commercial terms. The relevant barriers can include application expenditure, legal advice, language, technical expertise, operating capital, access to registrars, international marketing and the ability to sustain financial commitments through a lengthy evaluation process.

ICANN’s Applicant Support Program is intended to address part of that problem through financial and nonfinancial support for eligible applicants. The organization reported that 56 entities qualified for assistance in August 2026, after receiving 78 support applications by the earlier deadline. The subsequent Reveal Day statistics recorded 51 applications submitted by supported applicants; these figures describe different stages and units of measurement and must not be treated as contradictory counts of the same population. The qualification of an organization for support does not necessarily imply that it ultimately submitted a paid application or obtained a delegated registry. The relevant sources are ICANN — Applicant Support Program Results, 26 August 2026 and ICANN — Applicant Support Program.

A further source of inequality concerns software compatibility. Linguistic participation depends not only on permission to use non-Latin scripts but also on whether applications, websites, email systems and identity services correctly accept and process those names. ICANN reported in September 2026 that 151 internationalized top-level domains representing 37 languages and 23 scripts had been delegated as of June 2026, alongside approximately 4.3 million internationalized second-level domain registrations. These figures demonstrate that the technical framework already supports significant multilingual activity, while the accompanying report identifies continuing Universal Acceptance gaps. The relevant evidence is ICANN — IDN Implementation and Universal Acceptance Adoption Report Announcement, 22 September 2026.

The development-policy implication is important. Funding a community or linguistic TLD may create limited public benefit if major applications cannot correctly process the resulting addresses. Conversely, improving software compatibility can generate substantial benefits for existing and future internationalized domains without requiring a large number of new registries. The efficient allocation of public and institutional resources should therefore consider technical acceptance, local-language support, developer education and digital identity inclusion alongside application financing. This shifts the emphasis from counting new namespaces toward enabling their effective use.

Chapter 8 — International findings and strategic implications

The international regulatory environment is moving toward more explicit treatment of DNS infrastructure as a matter of cybersecurity, resilience and, in certain circumstances, national security. The European Union has established binding requirements that directly address relevant TLD registries and registration-service providers, including cases where ordinary size thresholds do not determine coverage. The United Kingdom applies national-security screening to qualifying digital infrastructure acquisitions, while the United States remains central to ICANN’s corporate jurisdiction and to the wider technology economy. Italy, France and Germany operate within the European framework but possess different institutional structures, registry histories and industrial requirements. Emerging economies confront a separate problem of effective participation, in which application assistance is necessary but insufficient without technical capability, operational sustainability and wider software compatibility.

These developments do not demonstrate an inevitable transition toward fragmented national naming systems. On the contrary, they show how states increasingly seek to regulate the businesses and infrastructure operating within a common global DNS while preserving the practical advantages of interoperability. The long-term risk arises when incompatible national obligations, unequal access to infrastructure or proprietary resolution systems reduce the consistency on which the global naming environment depends. The most credible strategic response is therefore to preserve global technical coordination while strengthening jurisdictionally appropriate cybersecurity supervision, competition safeguards and mechanisms for equitable participation.

Chapter 9. The 2027–2031 Outlook: Market Scenarios, Regulatory Choices and Strategic Consequences

The coming five years will determine whether the 2026 expansion produces useful infrastructure or a larger inventory of underutilized digital naming assets

The period from 2027 through 2031 will be decisive because the economic, institutional and technological consequences of the 2026 application round cannot be established through application counts or expressions of interest. The relevant transformation will occur as applications undergo evaluation, contested strings are resolved, registry agreements are executed and successful operators confront the practical requirements of launching and sustaining their namespaces. At that stage, strategic expectations will encounter operational reality. Applicants that currently describe their proposed extensions as valuable opportunities will have to demonstrate whether those extensions generate registrant demand, support organizational functions, improve digital trust or deliver other identifiable benefits. At the same time, ICANN will have to demonstrate that the new round can be administered consistently with its stated objectives of technical stability, competition, procedural transparency and public-interest governance.

The process will take place against a technological background that differs materially from the environment of the 2012 round. Autonomous software, cloud-based digital services, cryptographic identity systems and increasingly complex platform ecosystems create potential new uses for naming infrastructure, but they also provide substitutes for some of the functions traditionally associated with memorable domain names. A company may find value in an independent corporate namespace even if only a small number of addresses are publicly visible. A commercial registry may develop a viable specialized market without achieving mass-market scale. Another registry may discover that users prefer existing domains, platform accounts or application-specific identifiers. Consequently, the market is unlikely to produce a uniform outcome in which all technically delegated strings become valuable or all unfamiliar extensions fail.

The appropriate forecasting framework must therefore distinguish three different outcomes: successful delegation, sustainable operation and realized public or commercial value. These are separate events. A registry can satisfy technical requirements and remain commercially unsuccessful; a corporate namespace can have few registrations and nevertheless support a valuable internal function; and a technically attractive extension can fail to obtain delegation because of eligibility, contention or other procedural circumstances. An evidence-based assessment should measure each stage separately and avoid interpreting an increase in the number of delegated extensions as automatic evidence of economic growth.

The next institutional milestones matter because uncertainty is being resolved in stages

The 2026 round’s published schedule provides several immediate indicators that will affect the post-2026 outlook. Reveal Day occurred on 7 October 2026. The Replacement Period runs from 8 October through 21 October 2026, during which applicants meeting the relevant criteria may choose eligible alternate strings. String Confirmation Day is scheduled for 17 November 2026, when the finalized strings and updated contention information will become available. The period for applicable comments, notifications and objections extends into March 2027, subject to the program’s specific procedural deadlines. These events do not mark completed delegation; they progressively clarify the population of strings that will undergo subsequent procedures. The current schedule is documented in ICANN — 2026 Round Milestones, 29 September 2026 and ICANN — Reveal Day and Next Steps, 7 October 2026.

The economic significance of String Confirmation Day is particularly important because the preliminary application universe may not correspond to the final set of unique strings proceeding through evaluation. Replacement decisions can change the number and composition of contested groups, although the relevant program restrictions prevent arbitrary substitution. The resulting contention structure will provide a more useful basis for assessing potential auction exposure than the headline application count alone. Nevertheless, the existence of multiple applicants for one string does not establish the final auction price, and applicants’ financial capacity should not be inferred from the mere fact that they entered a contention set. Auction valuations require information about business models, expected commercial benefits and the availability of alternative strategies, much of which may remain private.

The later stages are equally important. Evaluation findings can reveal technical weaknesses, disputed legal eligibility, name-collision concerns or other conditions that alter the expected value of obtaining a string. Contracting will establish the operative obligations of successful applicants, while delegation and subsequent operation will provide the first meaningful evidence of deployment. As the process advances, the appropriate question should change from whether a company can obtain a namespace to whether it can operate that namespace responsibly and extract value from it. This distinction will become increasingly consequential for investors financing applicants that have no established registry operating history.

Table 9.1 — Milestones, evidence and decision consequences

PeriodOfficial or expected processPrincipal evidence producedMain economic consequenceImportant qualification
8–21 October 2026Eligible replacement-string selectionsChanged string choicesAltered potential contentionNot unrestricted substitution
17 November 2026String Confirmation DayFinalized proceeding strings and updated contention informationClearer competitive exposureNot an allocation decision
Through March 2027Relevant public input and objection proceduresComments, warnings, notifications and objectionsLegal and procedural uncertaintyDifferent procedures have different legal effects
Subsequent evaluation stagesApplicant, string and technical evaluationsEligibility and evaluation outcomesCosts and continuation decisionsTiming depends on program processes
Contention resolutionApplicable priority and auction mechanismsResolution of competing claimsPotential acquisition-cost escalationAuction amounts are not predictable from applications alone
Registry contractingExecution of applicable agreementsContractual terms and commitmentsLong-term operating obligationsContracted does not necessarily mean delegated
Technical delegationIntroduction into coordinated DNSOperationally delegated TLDLaunch readiness and technical responsibilityDoes not establish market demand
First operating yearsRegistry launches and customer adoptionRegistrations, technical performance and deploymentInitial revenue and utility evidencePromotions can distort adoption measures
Renewal cohortsRegistrant continuation decisionsRetention and realized revenueSustainability assessmentMust account for registration duration
2030–2031 review horizonMature performance observation where availableMulti-year usage, exits and financial trendsMore defensible evaluation of program outcomesLater-delegated TLDs will have shorter histories

The table deliberately distinguishes official scheduled milestones from later events whose exact timing and outcomes cannot yet be established. It would be inappropriate to insert invented launch dates or assume that all successful applicants will begin operating during the same calendar year.

Three plausible market pathways

The most useful forecasting approach is to analyze structurally different pathways rather than assign numerical probabilities unsupported by observed outcomes. The first pathway is selective commercialization, in which a limited number of new extensions develop meaningful economic or organizational utility while many others remain specialized, lightly used or commercially unsuccessful. This pathway is consistent with the existence of heterogeneous applicant objectives and differentiated demand. Its defining characteristic would be a substantial gap between the number of delegated extensions and the number achieving meaningful registration revenue or independent operational value. Such an outcome would not necessarily constitute institutional failure, provided that unsuccessful experiments did not impose disproportionate systemic costs and the program produced worthwhile innovations.

The second pathway is ecosystem-driven differentiation, in which specific namespaces achieve stronger adoption through integration with established software platforms, professional communities, organizational systems or emerging technical workflows. Under this pathway, value would concentrate in registries connected to genuine complementary capabilities rather than being distributed evenly among appealing words. A successful AI-oriented namespace, for example, would require adoption by developers and enterprises through actual products, interoperable interfaces or trusted services. Its commercial value would arise from those applications rather than from the inherent technological meaning of the suffix. This pathway would potentially increase the strategic importance of some naming assets while also creating competition concerns if essential ecosystem participation became dependent upon discriminatory registration or platform-access conditions.

The third pathway is identity substitution and limited incremental demand, in which advances in machine identity, cryptographic credentials and platform-mediated service discovery reduce the importance of acquiring new top-level labels. Under this pathway, businesses would continue operating secure digital services predominantly through existing domains, while AI agents and software systems would rely on protocols and trusted directories that do not require specialized naming extensions. Some corporate applicants might retain their registries for defensive or organizational reasons, but commercial expectations associated with broad technological terminology could weaken. This pathway would be particularly consequential for investors valuing AI-related strings on the assumption that autonomous software will necessarily require independently registered domain names.

These pathways can coexist across sectors. An industrial consortium may adopt a specialized naming scheme while a consumer software platform relies on proprietary identity systems and a financial institution continues using established domains with stronger credentials. Accordingly, the objective of forecasting should be to identify the conditions under which each pathway becomes economically important, not to impose an artificial global winner.

Table 9.2 — Competing market pathways and observable evidence

PathwayMain value mechanismEvidence supporting its developmentEvidence weakening itPrincipal beneficiaries
Selective commercializationSpecialized registries establish limited but sustainable demandPositive retention and contribution margins in identifiable segmentsWidespread failure even among targeted servicesEfficient niche operators
Ecosystem-driven differentiationPlatforms and communities integrate naming with valued servicesProduction integrations and independent third-party adoptionReliance on marketing without practical deploymentOperators possessing complementary capabilities
Identity substitutionExisting domains and credentials satisfy new requirementsOpen protocols and widespread deployment without specialized TLDsTechnical standards begin requiring particular new naming arrangementsIdentity, security and platform providers
Defensive holdingOrganizations preserve control without major public deploymentContinued operation with documented organizational rationaleHigh carrying costs without identifiable benefitsLarge brand owners
ConsolidationWeak operators transfer or exit while larger groups expandOwnership transactions and increasing common controlSustained independent entry and competitive scaleEstablished registry platforms
Regulatory differentiationCompliance and jurisdiction shape operating modelsDivergent national enforcement and rising cross-border costsEffective harmonization and mutual operational compatibilityOperators capable of managing regulatory complexity

The evidence available in October 2026 does not support assigning reliable probabilities to these pathways. The decisive information will be produced through application outcomes, registry operations, customer behavior and technical adoption during the subsequent years.

The danger of mistaking nominal domain growth for increased economic productivity

One of the most important risks in evaluating the 2026 expansion is the use of aggregate registration statistics as a proxy for the Internet’s economic development. More domain names may reflect increased business activity, broader digital participation and new organizational needs. They may also reflect promotional pricing, defensive acquisition, speculative holding or registration practices that generate limited productive use. Even a high renewal rate requires interpretation because registrants may maintain unused names for protective or speculative reasons. Conversely, a restricted corporate registry may have very few registrations while supporting a commercially important operational architecture.

A meaningful program assessment should therefore combine several distinct measures. Commercial registries should be evaluated through registration demand, renewal behavior, contribution margins and sustainable cash generation. Corporate registries should be assessed according to the operational benefits attributable to their independent namespaces, including any measurable improvements in organizational administration, brand governance or service delivery. Community and linguistic registries should be evaluated against their intended public or organizational purposes, including accessibility, actual adoption and operating sustainability. System-wide outcomes should include resilience, abuse control, concentration, participation opportunities and technical interoperability.

The need for this multidimensional approach is illustrated by the existing national registry market. France’s .fr data show the value of examining both creation flows and retention, while Germany’s .de statistics demonstrate the importance of distinguishing domestic and international registrants within a single namespace. Neither set of figures can be used to infer that a new generic extension will achieve comparable results. Established national domains benefit from long histories, recognizable identity and institutional structures that new entrants cannot simply replicate. A forecasting model treating all registry types as economically interchangeable would consequently produce misleading conclusions.

Market concentration may increase even as the number of extensions expands

The proliferation of new top-level domains can coexist with increasing economic concentration because the number of products does not determine the number of independent businesses controlling them. Larger registry groups may manage multiple extensions, operate shared technical platforms, establish preferred registrar relationships and finance marketing across portfolios. These capabilities can produce efficiency gains through economies of scale, common security infrastructure and lower marginal operating costs. They can also make competition more difficult for smaller independent operators, particularly when access to distribution or premium registration services depends on arrangements controlled by established industry groups.

The relevant concentration analysis must therefore extend beyond counting delegated strings. It should identify the ultimate economic owners of registry businesses, distinguish registry operation from outsourced technical services and examine distribution relationships with registrars. Market-share calculations should be based on comparable measures of registration activity or revenue rather than treating every delegated TLD as equivalent. A registry with millions of active names and one with a few thousand controlled registrations do not possess comparable commercial scale merely because each operates one extension.

Concentration should also be assessed through its effect on customers and infrastructure. Consolidation could reduce costs and improve security by allowing professional operators to maintain resilient technical systems. It could also reduce the diversity of commercial offerings or increase dependency on a small number of infrastructure providers. The public-interest analysis must consider both mechanisms. A policy that seeks to preserve a large number of nominally independent registry companies without regard to operational competence could weaken resilience, while unrestricted consolidation could create dependencies that become difficult to supervise or replace. The relevant objective is effective contestability and technical resilience, not a predetermined ideal number of market participants.

Regulatory compliance could become a more important investment determinant than the original allocation fee

The evolving regulatory environment creates a significant change in the economics of registry operation. In jurisdictions where operators fall under cybersecurity and data-management requirements, compliance expenditure may become a recurring component of the operating model. The costs may include risk assessments, incident response, business continuity testing, supplier oversight, access controls, registration-data governance and supervisory engagement. These activities are not necessarily new to responsible operators, but statutory requirements can increase the importance of documentation, formal accountability and evidence that controls operate as intended.

The effect will vary by operator. A mature infrastructure company may integrate new obligations into established compliance systems, while a small entrant may require substantial external assistance. Outsourcing can reduce the need for internal technical infrastructure but does not necessarily transfer all legal responsibility to the service provider. Contracts must establish which party carries out required activities, which records are available for supervisory review and how incidents are escalated. This can alter the relative attractiveness of business models built around independent technical operations, shared registry-service platforms or corporate internal deployment.

The European framework is particularly consequential because Directive (EU) 2022/2555 and Implementing Regulation (EU) 2024/2690 impose defined requirements on relevant infrastructure categories. Operators evaluating the European market should therefore avoid treating ICANN contractual compliance as the full extent of their obligations. The correct regulatory analysis must identify the entities and services involved, the Member States exercising jurisdiction, the applicable implementation measures and the specific activities giving rise to obligations.

Internationalized domains and Universal Acceptance could create more public value than many commercially attractive new English-language strings

The internationalization of Internet naming offers a strategically distinct category of potential benefits. A domain extension serving a language community may improve the ability of individuals and organizations to use familiar scripts, communicate digital identities and participate in online commerce without relying exclusively on Latin-character naming conventions. Such benefits may be difficult to capture through immediate registration revenue, particularly where communities face lower purchasing power or limited availability of compatible software. A narrow financial comparison with established English-language commercial registries would therefore underestimate potential social utility.

However, the technical effectiveness of internationalized naming depends on Universal Acceptance. A valid domain that fails in registration forms, email systems, identity applications or business software may have limited practical value even after successful delegation. ICANN’s September 2026 reporting identified continuing acceptance gaps despite progress in the delegation and use of internationalized domains. The appropriate response is to connect namespace policy with application compatibility, software testing, developer education and email internationalization. A multilingual Internet requires more than the availability of additional strings: it requires systems capable of recognizing and processing them reliably. The institutional evidence is contained in ICANN — IDN Implementation and Universal Acceptance Adoption Report Announcement, 22 September 2026.

The economic implications extend beyond linguistic inclusion. Poor acceptance creates costs for registrants whose names fail during authentication or communication, discourages adoption and reduces the expected return on registry investment. Improving compatibility can increase the usefulness of both established and future extensions. Consequently, the most productive investment may sometimes be in software interoperability rather than new allocations. This is particularly relevant for policymakers considering support for regional, linguistic or community registries, because the success of a naming initiative may depend more heavily on downstream technical adoption than on the initial ability to finance an application.

Cybersecurity and fragmentation may become the principal constraints on further expansion

The global DNS achieves its utility through predictable resolution and broad technical acceptance. If incompatible naming environments multiply, users and software systems may encounter different meanings for the same apparent identifier depending on the resolver, application or platform. Such fragmentation can increase security uncertainty, complicate identity verification and create additional costs for developers and organizations. It can also undermine confidence in the consistency of Internet naming, particularly where users are unable to determine which naming authority a particular application relies upon.

This does not mean that alternative naming technologies should be prohibited or that the existing governance framework must remain unchanged indefinitely. Innovation in distributed naming, cryptographic identities and application-level discovery may provide valuable functionality. The relevant technical standard is whether such innovation preserves clear semantics, reliable authentication and interoperability where necessary. A new system that provides genuinely useful capabilities but operates only in a defined environment may be appropriate, provided that its users understand the limitations. A system presenting itself as universally recognized while depending on proprietary resolution could create misleading expectations.

The principal security challenge for ICANN and national authorities will be to manage the interaction between naming diversity and common operational safeguards. Registries must maintain reliable infrastructure; software developers must correctly handle valid domains; identity providers must establish trustworthy verification mechanisms; and regulators must avoid imposing incompatible demands that jeopardize continuity. The resulting governance problem cannot be solved by a single institution because the relevant responsibilities are distributed across multiple technical and legal layers.

Regulatory and institutional choices for 2027–2031

The principal policy choices should be evaluated according to the authority responsible for implementation, the expected public or commercial benefit, the cost of compliance, the reversibility of the decision and the possibility of unintended consequences. Stronger governance is not automatically achieved by imposing more restrictions, just as greater competition is not automatically achieved by delegating more extensions. An effective framework must distinguish risks that require common technical rules from those better addressed through commercial competition, national legislation or voluntary standards. It should also account for the differences between established registries, small commercial entrants, corporate brand operators and community institutions, because uniform obligations can have materially unequal effects even when they appear formally neutral.

One approach would prioritize improved financial and procedural transparency within ICANN’s existing governance framework. This could include more systematic publication of program cost reconciliations, clearer disclosure of how evaluation and contingency expenses are allocated, and improved reporting of application outcomes. Such measures fall primarily within ICANN’s institutional governance and contractual administration, subject to its Bylaws and policy processes. Their expected benefit would be greater confidence in the proportionality of program fees and a stronger basis for assessing the economic consequences of allocation rules. The principal burden would concern implementation, confidentiality protection and the preparation of comparable data, while the main risk would be disclosure demands that exceed legitimate public-interest needs or expose sensitive applicant information.

A second approach would concentrate on effective market competition. Competition authorities and relevant institutional bodies could examine ownership concentration, cross-market relationships, access conditions and the potential effects of integrating registries with dominant software or distribution platforms. Such scrutiny should be based on evidence of actual or reasonably foreseeable competitive effects rather than an assumption that ownership of multiple strings is inherently unlawful. The benefit would be more informed enforcement against genuinely exclusionary conduct, while the risk would be regulatory intervention based on poorly defined markets or an incorrect understanding of the technical differences among naming, hosting, identity and platform services.

A third approach would strengthen operational resilience through compliance, supplier oversight and verified continuity planning. This is particularly relevant to the European Union and other jurisdictions already treating certain DNS-related activities as regulated infrastructure. The expected benefit would be reduced operational risk and more consistent treatment of serious incidents, but implementation must account for the burden on smaller operators. Excessively prescriptive requirements that offer little additional security could discourage entry and increase dependence on a small number of large compliance-service providers, potentially reinforcing the concentration they are intended to control.

A fourth approach would emphasize international participation and interoperability. Application support, technical assistance, multilingual software readiness and transparent community processes could reduce barriers without requiring the reservation of valuable strings for particular countries or organizations. The principal implementation challenge would be to distinguish projects capable of producing durable public value from those that cannot sustain operations after initial assistance ends. Financial support should therefore be connected to credible governance, technical capability and observable outcomes, rather than evaluated solely by the number of applications subsidized.

Table 9.3 — Strategic policy options and implementation trade-offs

Policy optionCompetent authorityIntended effectImplementation burdenTime to measurable effectReversibilityPrincipal downside
Enhanced program financial reconciliationICANN Board and organization under governing processesGreater accountability for costs and retained fundsFinancial reporting and audit designOne or more reporting cyclesHigh for reporting arrangementsExcessive reporting and confidentiality risks
Improved beneficial-ownership analysisApplicable ICANN processes and competent national authoritiesBetter visibility into concentrationData collection and legal reconciliationMedium termModerateIncomplete disclosures or privacy conflicts
Risk-based registry supervisionNational and regional regulators under applicable lawImproved resilience and complianceTechnical assessments and enforcementMedium termModerateDisproportionate burden on small operators
Interoperability requirements for covered platformsStandards bodies and competent regulatorsLower switching and integration barriersTechnical standards and testingMedium to long termModeratePremature technical standardization
Expanded Universal Acceptance implementationICANN, software providers and technical communityBetter usability of valid names and email addressesSoftware remediation and educationProgressiveHighSlow adoption and fragmented implementation
Targeted participation supportICANN and authorized funding bodiesBroader access for qualified applicantsEvaluation and assistance administrationMulti-yearHigh for future program designFunding projects without sustainable demand
Consistent contention transparencyICANN under approved program rulesGreater predictability and reduced information asymmetryProcedural disclosureDuring allocation stagesModerateRelease of commercially sensitive information
Supplier concentration monitoringCompetent regulators and infrastructure operatorsIdentify correlated operational dependenciesOwnership and technical-dependency mappingMedium termHighMisclassification of efficient shared infrastructure

Decision thresholds should be tied to observable evidence, not arbitrary risk scores

A decision-grade monitoring system should establish what evidence would justify intervention before the relevant event occurs. The threshold for investigating suspected discriminatory access should be a documented pattern involving comparable applicants or registrants, relevant market conditions and the applicable rules, rather than the simple fact that a technology company owns several extensions. The threshold for reviewing technical concentration should involve identifiable common dependencies and credible failure pathways, rather than a fixed number of registries supplied by one provider. Financial scrutiny should intensify when audited program expenditure, fee retention or reserve allocations exhibit material inconsistencies requiring explanation, rather than whenever an institutional activity produces a positive accounting balance. Such distinctions are necessary because arbitrary numerical thresholds can create an appearance of scientific precision while failing to identify the underlying economic or operational risk.

The monitoring framework should also account for the maturity of each registry. An operator immediately after delegation may reasonably exhibit low registration volumes while preparing a launch, whereas a mature commercial registry with persistent operating losses and declining renewals presents a different financial situation. A corporate brand registry may require a wholly different measurement system because retail registration volume is not its primary objective. Community registries may create linguistic, cultural or organizational value that cannot be fully measured through commercial revenue, but their continued operation still requires sound financing and technical responsibility. Evaluation criteria should therefore be appropriate to the operator’s stated objectives, while system-wide security and contractual obligations should remain enforceable according to the applicable framework.

Table 9.4 — Priority indicators for monitoring the 2027–2031 transition

IndicatorRelevant observationInterpretation if improvingInterpretation if deterioratingDecision relevance
Evaluation completionApplications completing required proceduresIncreasing procedural throughputPersistent unexplained delaysProgram execution
Contention resolutionSets resolved under applicable rulesGreater allocation certaintyProlonged unresolved disputesInvestment and legal exposure
Delegation-to-launch intervalTime between technical delegation and operational launchEffective readinessRepeated operational delayImplementation capacity
Active commercial registrationsComparable registration stocks and flowsPossible demand developmentWeak product adoptionMarket sustainability
Renewal cohortsPersistence of eligible registrationsDurable customer valuePromotional churnFinancial viability
Corporate deploymentVerified services using brand namespacesOrganizational utilityNondeployment without defensible purposeCapital efficiency
Registry financial performanceOperating cash flows and relevant costsSustainable operationsPersistent financing gapsInvestment risk
Ultimate ownership concentrationControl of operators and portfoliosMore effective competition if balancedPotential consolidation concernsCompetition policy
Back-end infrastructure dependenceCommon technical suppliers and dependenciesDiversified and resilient operationCorrelated failure exposureCybersecurity
DNS abuse measuresComparable validated incidentsEffective mitigationIncreasing unmanaged abusePublic trust
Internationalized-domain compatibilityCorrect application and email processingGreater digital inclusionPersistent acceptance failuresAccessibility
Cross-border complianceComparable implementation and supervisory outcomesLegal predictabilityConflicting obligationsInternational governance
Registry exits and transitionsCompleted or failed operational transitionsManaged market adjustmentRegistrant disruptionSystemic resilience

These indicators are useful only if their definitions and observation periods are preserved. A reduction in reported abuse cannot be interpreted as improved security without examining changes in detection coverage. Increased domain registrations cannot be interpreted as stronger demand without considering pricing and renewal behavior. A rise in the number of technically delegated TLDs cannot establish that ICANN’s expansion has generated equivalent increases in competition or public utility. The discipline of preserving these distinctions will become more important as the program moves from administrative milestones to operational and financial outcomes.

The ultimate economic question: who captures value and who bears the costs?

The distribution of benefits and costs across the DNS ecosystem will be one of the most consequential dimensions of the 2026 expansion. Registry operators may capture revenue through registrations and complementary services. Technology companies may capture value by integrating namespaces with established digital platforms. Registrars may gain new products to distribute, and infrastructure providers may obtain additional operating contracts. Users and organizations may benefit from new forms of identity, branding or community participation. At the same time, applicants may incur unrecovered investment costs, trademark owners may face additional monitoring burdens, software providers may need to improve compatibility, and regulators may incur greater supervisory responsibilities. The aggregate economic outcome cannot therefore be established by adding the gross revenues of participating businesses, because some of those revenues correspond to costs borne elsewhere in the system.

A complete welfare assessment would examine whether the newly introduced naming opportunities provide benefits that exceed the resources devoted to creating, administering, operating and protecting them. This does not imply that every registry must demonstrate a positive social return through an immediately measurable financial calculation. Innovation involves uncertainty, and unsuccessful experiments can produce knowledge about demand and technology. Nevertheless, institutional policy should avoid systematically encouraging expenditure that serves primarily to transfer value among applicants without creating corresponding improvements in services, competition or infrastructure. The distinction between private willingness to pay and social utility is particularly important where allocation mechanisms operate within a globally coordinated system and where applicants may perceive participation as strategically necessary even when the underlying commercial opportunity is uncertain.

The problem becomes more complex when names are acquired defensively. A company may spend substantial sums to prevent a potential competitive or reputational disadvantage, even though the resulting registry generates little public activity. From the company’s perspective, that investment may be rational if the avoided risk is material. From the perspective of the wider economy, the expenditure may represent a transfer of resources into defensive protection rather than the creation of new digital services. Yet defensive investments should not automatically be classified as wasteful, because they can reduce consumer confusion, support institutional continuity and preserve trustworthy identities. The appropriate judgment depends on the realistic alternative: whether the same protection could have been achieved more efficiently through existing domains, legal rights and security mechanisms.

The strategic position of ICANN after the 2026 expansion

By 2031, ICANN’s institutional performance will be judged not only by whether it completed application processing and maintained a technically stable DNS, but also by whether the resulting allocation framework demonstrates continuing legitimacy under the pressures of technological change and competing national regulatory expectations. Successful administration would require clear procedural outcomes, coherent contractual obligations, transparent management of financial resources and effective coordination with the wider technical community. It would also require an ability to distinguish genuine naming innovation from demands that can be satisfied more effectively through other layers of the Internet architecture. The rise of autonomous software and alternative identity systems makes that distinction more important because the future organization of digital trust will not necessarily follow the commercial assumptions underlying traditional domain registration.

A particularly important institutional risk would arise if stakeholders increasingly regard ICANN’s application rounds as expensive opportunities that must be pursued defensively, regardless of the likely operational value of the resulting registries. Such a perception could create pressure for further protective applications, additional administrative complexity and growing disputes over attractive terminology. The opposite risk would arise if ICANN discouraged legitimate innovation through excessive procedural burdens or failed to accommodate multilingual and community-based naming needs. The balance must be established through evidence about actual use, technical compatibility and market outcomes rather than an assumption that expansion is inherently beneficial or harmful.

The political sustainability of the multistakeholder model will also depend upon its treatment of concerns expressed by governments and regional institutions. States are unlikely to abandon their responsibilities for cybersecurity, privacy, consumer protection and national security merely because naming infrastructure is globally coordinated. ICANN’s institutional credibility will therefore depend partly on maintaining clarity about the boundaries between technical coordination and national legal authority. Where those boundaries are respected, the two systems can reinforce one another. Where they are misunderstood, disputes may encourage unilateral restrictions or alternative arrangements that weaken global interoperability.

Chapter 9 — Final strategic judgments

The 2027–2031 period will likely produce differentiated outcomes among the new registries rather than a single uniform market result. Commercial operators will face demands for sustainable customer acquisition and renewal economics, corporate applicants will have to justify continuing expenditure against actual strategic use, and community or linguistic registries will need to demonstrate both mission relevance and operational sustainability. These outcomes will be shaped by technological adoption and regulatory conditions that cannot be determined from the October 2026 application statistics alone.

The most important market risk is that the number of naming assets expands more quickly than the effective demand for differentiated naming services. The most important institutional risk is that administrative processes and defensive expenditure become increasingly difficult to justify through measurable public benefit. The most important technological risk is that investors mistake the growing importance of machine identity and AI service discovery for a corresponding requirement to own AI-related top-level domains. The most important geopolitical risk is that competing regulatory and technical arrangements impair the interoperability that gives the DNS much of its value.

The most constructive policy response is to maintain reliable global naming coordination while strengthening the evidence used to assess market outcomes, financial accountability, technical resilience and equitable access. Regulatory intervention should target demonstrated problems rather than the mere existence of new extensions, while investment decisions should distinguish speculative positioning from verified demand and enforceable technological capabilities.

Final Net Assessment — The Economics and Governance of Internet Naming, 2026–2031

The three pillars of this assessment establish that the expansion of generic top-level domains is not merely an administrative event within the domain-registration industry. It is an allocation process occurring at the intersection of institutional governance, commercial competition, digital identity, critical infrastructure and international jurisdiction. Applicants may be purchasing opportunities to operate profitable registries, preserve corporate naming options, serve communities or reinforce wider technology ecosystems. These objectives are materially different, and the validity of each investment depends upon its own operational, financial and institutional circumstances. Consequently, no credible evaluation can treat all 1,615 applications as equivalent financial bets or infer that their eventual success will be determined primarily by the attractiveness of their strings.

The broader economic concern is that Internet naming combines technical uniqueness with institutionally controlled allocation, allowing individual strings to acquire private strategic value that may not correspond to equivalent public utility. The allocation framework can support valuable innovation, but it can also encourage defensive expenditure and competition for positions whose future use remains uncertain. ICANN’s responsibility is to administer the process according to its mission and governing instruments, preserving technical stability and procedural integrity while demonstrating that the costs and institutional burdens imposed on participants remain proportionate. Its nonprofit status does not eliminate the need for financial scrutiny, just as the existence of substantial application charges does not establish improper profit-seeking. The decisive standard is accountable administration supported by verifiable evidence.

Technological developments make the long-term outcome particularly uncertain. Artificial intelligence may increase the value of stable organizational identities and reliable service discovery, but authenticated machine interactions depend upon credentials, authorization protocols, governance and security controls that operate beyond the DNS. New domain extensions can support such arrangements without becoming their indispensable foundation. The possible emergence of agent-based economic systems therefore creates opportunities for specialized naming products but does not justify assuming that every AI-related string will become a valuable infrastructure asset. The principal beneficiaries may instead be organizations that control trusted identity systems, interoperable protocols, established developer networks and secure transaction infrastructure.

International regulation introduces a final constraint. The United States remains significant through ICANN’s corporate jurisdiction and the scale of its technology economy; the European Union has established detailed legal obligations for relevant DNS-related infrastructure; the United Kingdom combines cyber regulation with specific national-security screening powers; and Italy, France and Germany possess distinct national registry and industrial environments. Emerging economies face barriers that cannot be overcome solely through reductions in application fees, particularly where technical resources, software compatibility and access to distribution remain limited. These differences will increasingly affect registry operating models and investment decisions, but they need not undermine global coordination if institutions preserve the distinction between the technical unity of Internet identifiers and legitimate territorial regulatory authority.

The ultimate strategic issue is not how many new Internet endings can be created, how much applicants are willing to pay for them, or how many corporations succeed in obtaining attractive labels. It is whether the governance of Internet naming converts scarce contractual positions into durable economic, technological and public value without compromising interoperability, competition or trust.

By 2031, the strongest evidence of success will be found in sustainable registry operations, meaningful deployment, transparent institutional administration, inclusive technical standards and resilient infrastructure. The strongest evidence of failure would be a large inventory of costly but underutilized namespaces, persistent defensive expenditure, limited independent competition and growing complexity unsupported by corresponding benefits to Internet users.

The future of the DNS will therefore be determined less by the number of names added to its root than by the quality of the technical, economic and institutional relationships built upon them.


Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.