LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:regional:au_common_position

African Union Common Position on international law in cyberspace (2024)

As of 30 September 2026. Information only, not legal advice – see the disclaimer.

Full title Common African Position on the Application of International Law to the Use of Information and Communication Technologies in Cyberspace
Type Common position of a regional organisation
Adopted by Peace and Security Council of the African Union (1196th meeting); endorsed by the Assembly of the African Union
Adopted 29 January 2024 (Peace and Security Council); endorsed by the Assembly at its 37th Ordinary Session (February 2024)
Legal status Non-binding statement of the African Union's understanding of existing international law
Official text AU Peace and Security Department – Communiqué of the 1196th meeting · African Union Knowledge Base
Subject area Use of force, intervention and cyber operations; Armed conflict (international humanitarian law); Cybersecurity, cybercrime and critical infrastructure

Overview

The Common African Position (CAP) sets out the understanding of the African Union and its 55 member States of how existing international law applies to the use of ICTs by States. It was prepared under the auspices of the Peace and Security Council, with the African Union Commission on International Law, through consultations and expert meetings in 2023 and January 2024, and was adopted by the Peace and Security Council on 29 January 2024. According to the AU Information and Communication Directorate, it was endorsed by the Assembly of Heads of State and Government at its 37th Ordinary Session. The communiqué of the 1196th meeting encourages member States to develop national positions consistent with the CAP and to participate in the discussions on the subject at the United Nations. The CAP covers sovereignty, non-intervention, peaceful settlement of disputes, the prohibition of the use of force and self-defence, due diligence, international humanitarian law, international human rights law, State responsibility and capacity-building.

Provisions relevant to the cyber and information sphere

  • Sovereignty – Respect for the territorial sovereignty of States is described as a primary rule of international law applying to State conduct in cyberspace. The CAP states that any unauthorised access by a State into ICT infrastructure located on the territory of a foreign State is unlawful, without a threshold of harmful effects.
  • Non-intervention – Coercion is described as the defining element of prohibited intervention, understood as a policy designed to impose restraints on the will of a foreign State; a complete deprivation of choice is not required, and the assessment is made case by case.
  • Peaceful settlement of disputes – The obligation to settle disputes peacefully applies to disputes relating to the use of ICTs.
  • Use of force and self-defence – Cyber operations fall within the prohibition of the use of force when their scale and effects are comparable to those of a conventional act of violence, for example operations causing physical damage, injury or death or destroying critical infrastructure. The right of self-defence is linked to the occurrence of an armed attack.
  • Due diligence – Presented as an obligation of conduct to take measures feasible within a State's capacity, triggered by actual or constructive knowledge; knowledge is not presumed merely because an operation originates from a State's territory. The CAP refers to the capacity constraints of developing States and to international cooperation, including among CERTs/CSIRTs.
  • International humanitarian law – Applies to cyber operations in the context of armed conflict, including the principles of distinction and proportionality and the protection of medical and humanitarian operations.
  • International human rights law – Applies to State conduct in cyberspace, including freedom of expression and privacy; the CAP refers to transnational interception and indiscriminate surveillance, to the responsibilities of business enterprises and to the right to development and the digital divide.
  • State responsibility – Attribution follows customary rules as reflected in the ILC Articles on State Responsibility; a State alleging an internationally wrongful act bears the burden of substantiating the claim.
  • Capacity-building – Must respect State sovereignty and national ownership.

Application to cyber and information operations

The CAP is one of two common positions of regional organisations on the subject, the other being the 2024 Declaration of the European Union and its Member States (see positions). Its view that sovereignty is violated by unauthorised access irrespective of effects differs from the position of States that do not regard sovereignty as a stand-alone rule, and from the approach, reflected in the Tallinn Manual 2.0, that requires a certain level of effects (tallinn_manual). Commentators have noted its implications for cyber espionage (M. Helal, Harvard International Law Journal, 2024) and, as regards non-intervention, for interference in electoral processes (EJIL:Talk!, 2024).

Recent developments

  • 2024-08-16: The AU Information and Communication Directorate referred to the CAP as endorsed by the Assembly at its 37th Ordinary Session (press release 148/2024).

Sources

Change log

  • 2026-09-30: Entry created.
law/regional/au_common_position.txt · Last modified: by lfpo