As of 30 September 2026. Information only, not legal advice – see the disclaimer.
| Full title | Common African Position on the Application of International Law to the Use of Information and Communication Technologies in Cyberspace |
|---|---|
| Type | Common position of a regional organisation |
| Adopted by | Peace and Security Council of the African Union (1196th meeting); endorsed by the Assembly of the African Union |
| Adopted | 29 January 2024 (Peace and Security Council); endorsed by the Assembly at its 37th Ordinary Session (February 2024) |
| Legal status | Non-binding statement of the African Union's understanding of existing international law |
| Official text | AU Peace and Security Department – Communiqué of the 1196th meeting · African Union Knowledge Base |
| Subject area | Use of force, intervention and cyber operations; Armed conflict (international humanitarian law); Cybersecurity, cybercrime and critical infrastructure |
The Common African Position (CAP) sets out the understanding of the African Union and its 55 member States of how existing international law applies to the use of ICTs by States. It was prepared under the auspices of the Peace and Security Council, with the African Union Commission on International Law, through consultations and expert meetings in 2023 and January 2024, and was adopted by the Peace and Security Council on 29 January 2024. According to the AU Information and Communication Directorate, it was endorsed by the Assembly of Heads of State and Government at its 37th Ordinary Session. The communiqué of the 1196th meeting encourages member States to develop national positions consistent with the CAP and to participate in the discussions on the subject at the United Nations. The CAP covers sovereignty, non-intervention, peaceful settlement of disputes, the prohibition of the use of force and self-defence, due diligence, international humanitarian law, international human rights law, State responsibility and capacity-building.
The CAP is one of two common positions of regional organisations on the subject, the other being the 2024 Declaration of the European Union and its Member States (see positions). Its view that sovereignty is violated by unauthorised access irrespective of effects differs from the position of States that do not regard sovereignty as a stand-alone rule, and from the approach, reflected in the Tallinn Manual 2.0, that requires a certain level of effects (tallinn_manual). Commentators have noted its implications for cyber espionage (M. Helal, Harvard International Law Journal, 2024) and, as regards non-intervention, for interference in electoral processes (EJIL:Talk!, 2024).