Applications / .aio / TKRC2583-T68712 · published by ICANN 7 October 2026 · snapshot 2026-10-08
§ 1 — Meaning of the string Q118·Q120
aio meaning Ancestral Intelligence Offering - the offering of knowledge from one's ancestors. Representing indigenous belief systems and values; it’s an inherited consciousness that provides ultimate wellbeing for all species. Aio means peace in English
ə aɪ əʊ
§ 2 — Mission and purpose Q133
Te Kāhui Raraunga Charitable Trust (TKR) established in 2019, is an indigenous peoples mandated representative organisation of over 85 iwi-Māori (approximate population 800,000). TKR is entrusted to advocate for indigenous data rights and progress indigenous data practices. TKR recognise that our goals are not unique to our context but part of the wider global Indigenous Peoples pursuit for self-determination.
Indigenous Peoples make up approximately 6.2% of the global population including 90 countries, 5000 cultures and 6000 Indigenous languages with 1500 of those at risk. One of the greatest challenges faced by our community is access to the Internet acknowledged by The United Nations in their UN Agenda for Sustainable Development. They aim to close the digital divide by 2030.
Given the colonial impacts on Indigenous Peoples across the globe, there is a lack of trust in digital ventures that are not Indigenous-led or regulated. The .aio TLD is an opportunity to create a trusted space, have a presence and share, with appropriate care and protections, knowledge and information including ancestral knowledge.
.aio is an acronym for Ancestral Intelligence Offering. Indigenous Peoples are stewards and custodians of the natural world. Indigenous peoples share the belief that knowledge is handed down through generations and kinship. This includes connections to and with the natural world.
This responsibility is a common thread of connection across Indigenous Peoples (The .aio Community) globally and forms a central component to a shared worldview, belief systems and values; celebrating and uniting indigeneity worldwide, since time immemorial.
Aio is also an Indigenous Māori word for peace and tranquility. Peace in this sense is also a destination. From an Indigenous worldview if the planet is in a state of peace, it must be in a state of harmony; where all humans and the natural world are in absolute balance. Given the climate, economic and technological challenges the world is currently faced with, it is becoming increasingly understood that Indigenous knowledge can emancipate the globe from these pressures in pursuit of absolute peace and balance for all nations, and all environments.
TKR recognises that there is value in enabling Indigenous Peoples and their communities, nations and tribes by providing a trusted, clear, and identifiable .aio mark to assert Indigenous self-determination; recognise Indigenous data sovereignty principles to protect Indigenous rights, heritage and aspirations, underpinned by sustainable models of Indigenous governance.
This includes the elevation of Indigenous ways of being, dedicated to bringing trust, equity and peace to Indigenous wellbeing. Across the Internet and its digital ecosystem universally, this is yet to be realised. TKR respects the self-defining and self-organising mechanisms of Indigenous Peoples. The development of an Indigenous Peoples’ Data Trust as an overarching governance body will ensure credibility, equity and access, underpinned by the CARE Principles, promoting collective benefit, authority to control, responsibility and ethics honouring Indigenous rights. The CARE Principles are foundational to achieving and sustaining the intentions of the .aio TLD.
The Data Sovereignty for self-determination of Indigenous Peoples’ honouring ancestral intelligence community (The .aio Community) is longstanding with over 30 years of established and committed global efforts. The .aio TLD is an extension and advancement of this collective movement intended for Indigenous Peoples to assert their self-determination and other value-aligned Peoples who wish to join our efforts in progressing Indigenous data rights, practices and wellbeing.
The Indigenous Peoples’ Data Trust will be a self-organised governance group to ensure credibility and access to .aio Community, accountability with the policy settings and upholding the CARE Principles for Indigenous data governance.
§ 3 — Commitments and safeguards Q164–Q188
| More trustworthy, consumer risk, regulated sector, government reporting, harm, government function Q164–Q169 | No to each |
|---|---|
| Voluntary Safeguard PICs Q170·Q171 | None · 90 applications in the round offer some |
| Registry Voluntary Commitments Q172·Q173 | None · 5 do |
| Community TLD Q131·Q132 | |
| Code of Conduct exemption requested Q185·Q188 | No |
§ 4 — All other published answers
Every other answer ICANN published for this application, in the order of the form. Contact details (Q17–Q24) are left to the ICANN record.
Q212Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.
Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.
Answered with a document. Attachments are not published by ICANN.
Q220Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.
Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.
Answered with a document. Attachments are not published by ICANN.
Q221Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.
Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.
Answered with a document. Attachments are not published by ICANN.
Q119Script of String
Script of String
Latin
Q121As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.
As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.
true
Q134How would you categorize your community?
How would you categorize your community?
The Data Sovereignty for self-determination of Indigenous Peoples’ honouring ancestral intelligence Community (The .aio Community) is categorised as advocating and supporting indigenous data sovereignty for self-determination. This includes the well-being of indigenous peoples and the natural world we live in, advocating for indigenous peoples to assert their rights across all spaces, including data collection, provenance, access, use, management and dissemination, and led by indigenous worldviews, which connects peoples and honours ancestral intelligences. It Includes;
(a) Indigenous representative or governance bodies;
(b) Indigenous community-based, cultural, educational or service organisations;
(c) Indigenous community-benefitting service organisations, projects or enterprises; and
(d) individuals and organisations with a genuine and demonstrable connection to the .aio TLD Community.
Indigenous Data Sovereignty
Indigenous data sovereignty reinforces the rights of indigenous peoples to engage in decision-making in accordance with their indigenous values and collective interests.
Data have important implications for Indigenous Peoples’ ability to exercise their individual and collective rights for self-determination. Indigenous Peoples are often excluded from decision-making fora and their knowledge marginalised when such knowledge exists only as part of an oral tradition.
The UN Declaration on the Rights of Indigenous Peoples (UNDRIP) affirms Indigenous Peoples’ rights to self-governance and authority to control their Indigenous cultural heritage embedded in their languages, knowledge, practices, technologies, natural resources, and territories (including Indigenous data). Indigenous data, includes data about indigenous peoples and about the natural world indigenous peoples connect to, it includes data collected by indigenous peoples, data collected by others including governments and institutions about Indigenous Peoples and their territories, and are intrinsic to Indigenous Peoples’ capacity and capability to realise their human rights and responsibilities to all of creation.
The CARE Principles for Indigenous Data Governance developed by GIDA in 2019 are people and purpose-oriented, reflecting the crucial role of data in advancing Indigenous innovation and self-determination. These principles are an alternative to the existing FAIR principles encouraging data movements to consider both people and purpose in their advocacy and pursuits.
The CARE principles promote collective benefit, authority to control, responsibility and ethics. The CARE principles align to the values of TKR of whakapapa (genealogy), aroha (love) and manaaki (care) and together enable and support the practical expression of indigenous worldviews.
The Data Sovereignty for self-determination of Indigenous Peoples’ honouring ancestral intelligence Community is categorised as a community that develops and progresses Indigenous data sovereignty for self-determination.
Q135What is the applying entity's connection to the community?
What is the applying entity's connection to the community?
Te Kāhui Raraunga Charitable Trust (TKR) established in 2019, is an indigenous peoples and mandated representative organisation of over 85 iwi-Māori (approximate population 800,000). TKR is entrusted to advocate for indigenous data rights and progress Indigenous data practices. TKR recognise that our goals are not unique to our context but part of the wider global Indigenous Peoples pursuit for self-determination.
TKR has been advocating for Māori data governance and Māori data sovereignty rights well-before its formal establishment. It is a regular contributor, leader, collaborator, participant and trusted advocate across the indigenous data eco-system worldwide. This includes capability and capacity programme development, publishing resources and training materials, submitting or providing policy advice and developing bespoke solutions for indigenous communities.
Applying for the .aio TLD on behalf of our Community is an extension of TKR’s advocacy and goal to further embed indigenous ways of thinking, knowing and doing into layers of the internet to give expression to Indigenous Data Sovereignty for self-determination.
Operationally we envisage establishing a global Indigenous Peoples’ ‘Data Trust’ as a governance model to support activities such as a reserved list of domain names for Indigenous Peoples (communities, nations, tribes, commerce, environment etc.). The CARE principles act as a pre-requisite and filter in pre-registration of all domain names.
Advocacy for Indigenous data governance and sovereignty rights and interests is growing worldwide and Indigenous Peoples are active in their communities, nations and tribes across a highly collaborative and participatory environment. One key component to the monitoring and protection approach that the Indigenous Data Peoples’ Trust will ensure is to recognize that Indigenous Peoples are self-organizing and support how the .aio TLD can advance their aspirations across society; cultural, socio-economic, political, environment, technology and commercial needs. It is through an ancestral approach to organizing ourselves that will also show the unique governance model to be established recognizing the provenance and prominence of each of our respective stories, and kinship to our data.
TKR is a member of the Global Indigenous Data Alliance (GIDA) that is an international network that advances Indigenous data sovereignty and governance, asserts Indigenous Peoples rights and interests in data, advocates for data for the self-determined wellbeing of Indigenous Peoples and reinforces the rights to engage in decision-making in accordance with Indigenous values and collective interests.
The three attachments provide evidence of our connection as TKR and relationship to the Community we are part of and serve. Refer:
- Connection to Community: TKR_Speaking Engagements_19Jul26.pdf
- Map of network and tribal nations: TKR_IDSov Global Network Map_11Aug26.pdf
- List of networks: TKR_Indigenous_Data_Sovereignty_Networks_and_Tribal_Nations_11Aug26
Answered with a document. Attachments are not published by ICANN.
Q136How is the community organized? Are there one or multiple organizations ("organizing body") that represent or administer the community?
How is the community organized? Are there one or multiple organizations ("organizing body") that represent or administer the community?
Indigenous self-definition centres on a deep, continuous connection to ancestral knowledge and lands predating colonisation. Indigenous peoples define themselves through specific tribal names, genealogical ties to family and homelands, creation stories, and a collective will to protect their unique cultures and distinct societies centred on their natural environments. Self-identification is a core pillar of indigeneity and self-determination.
The core elements of Indigenous Self-Definition are acknowledged by international frameworks, such as those discussed by the United Nations Permanent Forum on Indigenous Issues, stating that Indigenous communities possess the inherent right to define their own identities. Key aspects of how Indigenous individuals and groups express this identity include: Genealogy and Kinship, Land and Creation, Cultural Distinctiveness and Self-Determination.
The .aio Community is founded on self-identification, and this includes its organisation. Various topics and issues that are presented to the .aio Community are voiced and acknowledged as they appear and form focal points of discussion and forums to collectivise efforts and address challenges. Such efforts include international-led initiatives as well as localised and or regional lead work. They include self-organising bodies built on high trust, value alignment, and a connection to indigeneity.
While there is no single organising body. The community are united by their experiences and historical impacts on their indigeneity. The .aio Community is self-administrative and is represented by its self-defining processes and ancestral heritage.
Today, there are multiple organisations that support the Community, with three prominent organisations paving the way;
i) First Nations Information Governance Centre (FNIGC), established in 2009 with a mandate from the Assembly of First Nations’ Chiefs-in-Assembly to strengthen First Nations data sovereignty in Canada in alignment with their distinct worldview. FNIGC support the First Nations Data Governance Strategy and steward the First Nations Principles of OCAP®; ownership, control, access and possession of First nations information by First Nations. CEO Jonathan Dewar and FNIGC have provided their support for this TLD application in the attached Letter of Support.
ii) Local Contexts, established in 2010, is a non-profit with global reach in indigenous communities across Aotearoa New Zealand, Australia, Canada, the Cook Islands, Colombia, Ecuador, French Polynesia, Guatemala, Sierra Leone, and the United States. It supports indigenous data sovereignty and cultural authority providing training, resources and tools to communities, nations and tribes. Executive Director Hop Hopkins and Local Contexts have endorsed this TLD application in the attached Letter of Support.
iii) the Global Indigenous Data Alliance (GIDA), established in 2019 is an international leader in Indigenous Data Sovereignty; a global network of regional and nation state-based Indigenous Data Sovereignty networks and collectives. Through the GIDA biannual conferences, opportunities for knowledge sharing, policy advocacy and collaboration on statements and topics of interest affecting indigenous data governance and data sovereignty. Chair of the Executive Committee, Stephanie Russo Carroll and GIDA have endorsed this TLD application in the attached Letter of Support.
The three attachments provide evidence of these organisations and their advocacy of indigenous data governance and indigenous data sovereignty rights for self-determination and support for this TLD application. Refer:
- FNIGC, TKR_Letter of Support_FNIGC_22Jul26.pdf
- Local Contexts, TKR_Letter of Support_Local Contexts_01Aug26.pdf
- GIDA, TKR_Letter of Support_GIDA_03Aug26.pdf
Answered with a document. Attachments are not published by ICANN.
Q137Does the community have defined membership requirements, such as registration, licensing, or use of specific communication? Or, do community members self-identify as part of the community?
Does the community have defined membership requirements, such as registration, licensing, or use of specific communication? Or, do community members self-identify as part of the community?
There is no formal membership process, members will self-identify into one of the following four categories within the community named in Q132:
a) Indigenous representative or governance bodies
b) Indigenous community-based, cultural, educational or service organisations
c) Indigenous community-benefitting, service organisations, projects or enterprises
d) Individuals and organisations with a genuine and demonstrable connection to members of categories A through C.
Example evidence for self-identifying members of the above categories could include but is not limited to: proof of standing, recognition, mandate, registration documents, a trust deed, constitution, an endorsement, support letter, a form of confirmation from a recognised representative body or agreed community authority, supporting evidence from a recognised representative body, adviser, partner, or other relevant source.
This approach leverages existing high-trust models of self-identification across the indigenous data sovereignty network today such as event and conference participation, collaborations, and research.
This is also in accordance with UNDRIP, the right for indigenous peoples striving for recognition of indigenous identities, their ways of life, their right to traditional lands, territories, natural resources, including their data.
Members can join the Community by exercising their right to self-determination and their active participation.
Q138Where is the community located?
Where is the community located?
Te Kahui Raraunga Charitable Trust (TKR), the steward of .aio TLD is based in Aotearoa, New Zealand. It is one location of many communities, nations and tribes across the world (Canada, USA, Sth America, Australia, NZ, northern Europe, Asia).
Q139What is the estimated size of the community? This should take into account any regions listed in Question 138.
What is the estimated size of the community? This should take into account any regions listed in Question 138.
120,442. This is a minimum of the international network of networks of indigenous nations, collectives, businesses and individuals. With 476M indigenous peoples, our Community includes Canada, USA, Sth America, Australia, NZ, northern Europe, Asia.
Q140What portion of the community do any organizing bodies represent or administer to?
What portion of the community do any organizing bodies represent or administer to?
A high proportion of existing indigenous data sovereignty networks. An estimated community size of 13 regions, 10 nations, 7 US federal state, 85 tribes, 350+ member collectives, organisations, individuals and un-recognized tribes, and peoples.
Q141Do the organizing bodies demonstrate active and consistent efforts to engage and connect with the identified community and its members?
Do the organizing bodies demonstrate active and consistent efforts to engage and connect with the identified community and its members?
Our community is founded on active and consistent efforts to engage and connect with The Data Sovereignty for Self-Determination of Indigenous Peoples’ Honouring Ancestral Intelligence Community (The .aio Community).
The .aio Community is significant because of its values underpinned by the CARE Principles. These principles, together with the unique self-identification process of Indigenous Peoples, extend the community's efforts to potential members interested in joining.
It is important to acknowledge that not all Indigenous Peoples are resourced to access, participate and lead and this, while being a disadvantage to our growing community, is an encouragement for our community aspirations to include all of the world's Indigenous Peoples. The .aio TLD presents that opportunity to create a safe space for our community to learn about resources, efforts and access to develop and or inform self-determination.
Active and consistent efforts to engage and connect with not only our community but those yet to join are critical to the well-being of our practises as Indigenous Peoples. A unique part of many Indigenous Peoples is our uniqueness for sharing and retaining our ancestral knowledge offerings. It is through engagement that our connection to each other is strengthened and united. Such efforts include the self-organising groups, collectives, alliances and initiatives formed to create engagement on Indigenous challenges and/or opportunities.
Te Kāhui Raraunga Charitable Trust (TKR) is a regular contributor, leader, collaborator, participant and trusted advocate across the indigenous data eco-system worldwide. This includes capability and capacity programme development, publishing resources and training materials, submitting or providing policy advice and developing bespoke solutions for indigenous communities. Evidence of examples demonstrating active and consistent efforts to engage and connect with the .aio Community are included as attachments. Refer:
- Offering Support: Iwi Data Roadshows, TKR_Iwi Data Roadshow Pamphlet_p1_01Jul25 and TKR_Iwi Data Roadshow Pamphlet_p2_01Jul25
- Sharing Information: TKR Māori Data Governance Model, Te Kahui Raraunga_Maori Data Governance Model_2023
- Responding to Specific Community Needs: - GIDA IDGov and Universities, GIDA+Communique+IDGov+Universities_FINAL_2023
- Fostering and strengthening relationships with Community, TKR_Speaking Engagements_19Jul26.pdf.
Answered with a document. Attachments are not published by ICANN.
Q142What is the role of the applying entity in the engagement efforts listed in Question 141?
What is the role of the applying entity in the engagement efforts listed in Question 141?
The evidence provided to support Question 141 includes a list of speaking engagements held across our community that were attended by representatives of TKR. On numerous occasions, TKR were invited to share and address topics at many of these events. This includes sharing capability and capacity programme development (Te Mana Whakatipu), knowledge sharing (GIDA IDSov and AI Workshop), publishing resources (Māori Data Governance Model and Māori AI Governance A Framework for Ethical Governance of AI) and developing bespoke solutions for indigenous communities (Te Pā Tūwatawata - Self-Sovereign Data Storage Network).
The Global Indigenous Data Alliance (GIDA) for example is an international network of networks advancing Indigenous Data Sovereignty and Governance, asserting Indigenous Peoples rights and interests in data, advocating for data for the self-determined wellbeing of Indigenous Peoples, and reinforcing the rights to engage in decision-making in accordance with Indigenous values and collective interests. TKR has collaborated with GIDA member networks from Aotearoa New Zealand to the US Indigenous Data Sovereignty Network. GIDA considers Te Kāhui Raraunga to be a trusted partner, with the technical, governance, and relational skills that has been invited to share ancestral knowledge offerings in joint efforts to advance our community. TKR’s role is to be that trusted member of our community that helps lift and advance The Data Sovereignty for Self-Determination of Indigenous Peoples’ Honouring Ancestral Intelligence Community (The .aio community).
Evidence of role of TKR in fostering and strengthening relationships and engagement with Community. Refer:
- TKR_Speaking Engagements_19Jul26.pdf.
- Māori AI Governance – A Framework for Ethical Governance of AI, TKR_AI Governance Framework 2025
- GIDA IDSov and AI workshop_Mexico_2026
- Te Pā Tūwatawata, TKR_Te Pa Tuwatawata Brochure_2026
Answered with a document. Attachments are not published by ICANN.
Q143Are community members aware of the identified community and each other?
Are community members aware of the identified community and each other?
Yes. The Data Sovereignty for Self-Determination of Indigenous Peoples’ Honouring Ancestral Intelligence Community (The .aio Community) is aware of itself, members and the international network of networks that are part of the Community.
Again, through self-defining processes, Indigenous Peoples will make themselves known and or participate in their own right. The use of surveys conflicts with Indigenous Peoples' rights to their own data and is not aligned with the CARE Principles.
Our awareness of our own networks, members and broader relationships is maintained by active engagement, collaboration and attendance at events and or activities.
The need to demonstrate membership and awareness of the community itself is not prescribed by official paperwork; rather, it is sustained through high trust, shared needs, interests, and active participation.
The .aio Community aspires to include all Indigenous Peoples and/or value-aligned groups who want to join and require no permanent or official registration other than meeting the pre-registration requirements set out in the various policies described inQ151-Q155.
The .aio Community is a growing one and will in time grow larger as more Indigenous Peoples become resourced and the world's population grows.
The three attachments provide evidence that i) demonstrates that community members are aware of the identified community, the different member groups or segments within the identified community, ii) provide documentation of the following practices, which should have occurred within the two years leading up to application submission such as records of activities involving a diversity of community groups, segments, or members. Refer:
- Map of network and tribal nations: TKR_IDSov Global Network Map_11Aug26
- List of networks: TKR_Indigenous_Data_Sovereignty_Networks_and_Tribal_Nations_11Aug26
- Connection to Community: TKR_Speaking Engagements_19Jul26.pdf
Answered with a document. Attachments are not published by ICANN.
Q144Are community members aware of the applying entity and its intention to apply for a community gTLD?
Are community members aware of the applying entity and its intention to apply for a community gTLD?
Yes, the .aio Community members are aware that TKR is applying for a Community TLD. Letters of support from our .aio Community for the TLD application are attached. In addition to letters received, TKR has also received verbal support from across the Community. Refer:
- TKR_2026 All Support Letters_ICANN Application_10Aug26
Answered with a document. Attachments are not published by ICANN.
Q145Was there an established presence of the identified community prior to the opening of the application submission period?
Was there an established presence of the identified community prior to the opening of the application submission period?
Yes
Answered with a document. Attachments are not published by ICANN.
Q146Are individuals and groups outside of the identified community aware of the existence of the identified community?
Are individuals and groups outside of the identified community aware of the existence of the identified community?
Yes, individuals and groups outside of the identified community are aware of the existence of the Community.
Indigenous Peoples have many relationships with governments, state-like departments and/or leadership, organisational groups, companies, etc., that they interface with and/or connect with on various subjects and/or topics. Evidence includes;
- TKR have two Mana Ōrite Relationship Agreements with New Zealand government agencies; Statistics New Zealand (30 October 2019) and the Department of Internal Affairs (22 June 2021). These Agreements are unique to TKR and are a pathway for continuous advocacy for indigenous data sovereignty for self-determination. Available online here:
Refer: StatsNZ: https://www.kahuiraraunga.io/manaorite?lightbox=dataItem-llbq8hzi1
Refer: DIA: https://www.kahuiraraunga.io/manaorite?lightbox=dataItem-llbq9yxa1
- TKR Major Media releases, TKR_Ngā Pāpāho_TKR Major releases_07Jul26
- Discussion of the community as above.
- Evidence of partnerships or collaborations with groups outside the identified community, TKR_Environmental impacts of hyper data centres_2026 and TKR_Speaking Engagements_19Jul26.pdf (ANZSOG Deputies Leadership Program, UNDP Global Flagship Event, Canterbury Tech Summit, CA ANZ IT, BIO AI, Embassy of Ireland, Genomic Standards Consortium).
Answered with a document. Attachments are not published by ICANN.
Q147Are the pursuits of the identified community enduring and sustainable?
Are the pursuits of the identified community enduring and sustainable?
The pursuits of The Data Sovereignty for Self-Determination of Indigenous Peoples’ Honouring Ancestral Intelligence Community (The .aio community) are enduring and sustainable as the issues, needs and challenges of Indigenous Peoples are long, enduring and self-identified.
Accounting for 6.2% of the global population, recognition of Indigenous Peoples by UNDRIP, in the UN Sustainability Agenda 2030 and International Day of the World’s Indigenous Peoples on August 9th every year are indicators that indigenous peoples are recognised and through the United Nations, there is a permanent forum to raise issues of importance to indigenous peoples.
Events of a recurring nature relating to indigenous data sovereignty include the Global Indigenous Data Sovereignty Conference - a biannual conference hosted by GIDA which marked 10 years at the most recent Conference in Ngunnawal and Ngambri Country (Canberra) Australia, 31March-3 April 2025. This was followed by an IDSov and AI workshop in Mexico 25-27 February 2026. TKR has participated in all conferences, events and workshops and is actively involved in a range of activities from facilitating masterclasses, to drafting communiques, knowledge sharing and strategic planning. Refer GIDA+Communiqué-+CARE+Directs+Us+Home-+Prioritizing+Indigenous+Peoples’+Community+Standards_2025 and GIDA IDSov and AI workshop_Mexico_2026.
Upcoming events with an indigenous data sovereignty component include Indigenous Genomics Standards Consortium (Aug 2026), Ngā Pae o Te Māramatanga International Indigenous Research Conference (Nov 2026), IAPP ANZ Summit 2026 (Dec 2026) and Global Indigenous Data Sovereignty Conference (Feb 2027) to name a few.
This community has existed to protect and advocate for Indigenous data rights and its needs are ever-growing and evolving. The .aio Community is an opportunity to safeguard Indigenous Peoples, their self-determination and their ancestral intelligence offerings. TKR has been actively involved as evidenced in the TKR_Speaking Engagements_19Jul26.pdf which documents involvement from 2023-2026.
Indigenous Peoples have an enduring presence, and their cultural significance makes up their uniqueness as peoples. TKR’s collaborations are far reaching; whether with communities, nations, tribes and/or with global collectives, the letters of support from the .aio Community of indigenous peoples for this TLD application is testament to the confidence of indigenous peoples in the ability of TKR to continue to have an enduring presence, from promoting and advocating for indigenous data sovereignty for self-determination to managing a Community TLD and establishing an Indigenous Peoples’ Data Trust as a governance model for the TLD. Refer TKR_2026 All Support Letters_ICANN Application_10Aug26.
Answered with a document. Attachments are not published by ICANN.
Q148Does the string match the name of the identified community?
Does the string match the name of the identified community?
Yes. The .aio string references the acronym - Ancestral Intelligence Offering - in the Community name, Data Sovereignty for Self-Determination of Indigenous Peoples’ Honouring Ancestral Intelligence.
Q149Will the general public instinctively think of the community when thinking of the applied-for string?
Will the general public instinctively think of the community when thinking of the applied-for string?
Yes, when people read the .aio string, acronym (A.I.O) and its meaning (Ancestral Intelleigence Offering), there is a natural connection between the .aio string, the acronym and the Community name. Data Sovereignty for Self-Determination of Indigenous Peoples’ Honouring Ancestral Intelligence.
Q150Are you proposing to include one or more Community Registration Policies in the Registry Agreement (RA) that are unique to the applying entity's applied-for community gTLD?
Are you proposing to include one or more Community Registration Policies in the Registry Agreement (RA) that are unique to the applying entity's applied-for community gTLD?
Yes
Q151.1Please state a specific Community Registration Policy with respect to registration eligibility for community members.
Please state a specific Community Registration Policy with respect to registration eligibility for community members.
Registry Operator shall restrict registrations in the .aio TLD to applicants that satisfy at least one eligibility category stated in the Community Registration Policy.
Registry Operator shall limit eligibility to:
(a) Indigenous representative or governance bodies;
(b) Indigenous community-based, cultural, educational or service organisations;
(c) Indigenous community-benefitting service organisations, projects or enterprises; and
(d) individuals and organisations with a genuine and demonstrable connection to the .aio TLD Community.
Registry Operator shall publish the eligibility categories, required registration attestations and verification processes on its public website no later than the date on which the .aio TLD is delegated in the DNS.
Registry Operator shall maintain an eligibility validation system under which every applicant must pass a pre-registration eligibility review before a domain name registration is activated.
Registry Operator will include a provision in its Registry-Registrar Agreement that requires Registrars to include in their Registration Agreements a provision requiring each applicant, at the time of registration, to select one eligibility category and provide a binding attestation that the applicant satisfies that category and that the registration and intended use of the domain name will comply with the Community Registration Policy.
Registry Operator will include a provision in its Registry-Registrar Agreement that requires Registrars to include in their Registration Agreements a provision requiring each applicant to provide sufficient information for Registry Operator or its nominee to determine the applicant’s eligibility and to acknowledge that Registry Operator or its nominee shall decline the application if the information provided is insufficient to establish eligibility.
Registry Operator shall require each applicant to provide, at the point of registration, sufficient documentary evidence to establish that the applicant satisfies a published eligibility category and that the proposed registration complies with the Community Registration Policy.
Registry Operator or its nominee shall validate each application before registration by reviewing the applicant’s selected eligibility category, attestation, registration data, documentary evidence and any supporting information requested for the review.
Registry Operator shall not approve a registration unless the evidence provided establishes that the applicant satisfies the attested eligibility category.
Registry Operator will include a provision in its Registry-Registrar Agreement that requires Registrars to include in their Registration Agreements a provision requiring each registrant, throughout the registration term, to maintain accurate registrant data, respond to eligibility enquiries and provide supporting information when requested, and acknowledging that failure to re-establish eligibility is grounds for suspension, lock, transfer denial or deletion.
Q152.1State a specific Community Registration Policy with respect to name selection criteria or rules for the applied-for string.
State a specific Community Registration Policy with respect to name selection criteria or rules for the applied-for string.
Registry Operator shall require every second-level domain name registered in the .aio TLD to have a clear and reasonable connection to the registrant’s selected eligibility category or attested intended use.
Registry Operator shall not permit registration of a domain name that implies authority, representation or affiliation that the registrant does not possess.
Registry Operator shall maintain a Reserved and Restricted Names Policy and a Reserved and Restricted Names List covering names required to be reserved under ICANN requirements, names subject to legal restrictions, names of specific cultural significance or cultural sensitivity, and names identified under the policy as misleading, impersonating, offensive, abusive or inconsistent with the .aio TLD mission.
Registry Operator shall publish its Name Selection Policy and Reserved and Restricted Names Policy on its public website no later than the date on which the .aio TLD is delegated in the DNS.
Registry Operator will include a provision in its Registry-Registrar Agreement that requires Registrars to include in their Registration Agreements a provision requiring each applicant, at the time of registration, to attest that the selected domain name complies with the Name Selection Policy and the Reserved and Restricted Names Policy.
Registry Operator will include a provision in its Registry-Registrar Agreement that requires Registrars to include in their Registration Agreements a provision requiring each registrant, on request, to provide information demonstrating the connection between the selected domain name and the registrant’s eligibility category or intended use.
Registry Operator or its nominee shall examine, before allocation, each applied-for name that appears on the Reserved and Restricted Names List or otherwise matches the criteria specified in the published Name Selection Policy.
Registry Operator shall approve a restricted name only where the applicant provides sufficient information to establish that the proposed registration satisfies the eligibility and name-selection requirements.
Registry Operator shall investigate each credible complaint alleging that a domain name is misleading, impersonating, culturally harmful, inconsistent with the registrant’s attestations, or otherwise contrary to the published Name Selection Policy or Reserved and Restricted Names Policy.
Registry Operator shall suspend, lock, delete or decline renewal of a domain name where the registrant fails to establish compliance with the published Name Selection Policy or Reserved and Restricted Names Policy.
Q153.1State a specific Community Registration Policy with respect to an additional commitment besides registration eligibility for community members and naming selection criteria or rules for the applied-for string.
State a specific Community Registration Policy with respect to an additional commitment besides registration eligibility for community members and naming selection criteria or rules for the applied-for string.
Registry Operator shall require each domain name to be used in a manner consistent with the Community Registration Policy, the registrant’s selected eligibility category, the registrant’s attestation of intended use and the published Acceptable Use Policy.
Registry Operator shall publish the Acceptable Use Policy on its public website no later than the date on which the .aio TLD is delegated in the DNS.
Registry Operator will include the following provision in its Registry-Registrar Agreement: Registrar shall require each registrant to comply with the Community Registration Policy and Acceptable Use Policy throughout the registration term.
Registry Operator will include a provision in its Registry-Registrar Agreement that requires Registrars to include in their Registration Agreements a provision requiring registrants to maintain accurate contact information, use each registered domain consistently with the eligibility attestation and stated intended use, respond to compliance enquiries, cease prohibited use when notified, and acknowledge that breach of the Community Registration Policy or Acceptable Use Policy is grounds for suspension, lock, deletion, non-renewal or another proportionate enforcement response.
Registry Operator shall operate a published complaints process covering DNS abuse, eligibility, name selection and acceptable-use concerns.
Registry Operator shall acknowledge receipt of a complaint within five business days where the complainant provides contact details.
Registry Operator shall provide the registrant not less than 14 calendar days to respond to notice of an alleged breach, unless immediate action is required to address DNS abuse, legal harm or material community harm.
Registry Operator shall maintain records of complaints, investigations, determinations and enforcement actions for the applicable retention period specified in its privacy policy.
Q154Explain the rationale for any limitations to the Community Registration Policy proposed by the applying entity in Questions 151-153.
Explain the rationale for any limitations to the Community Registration Policy proposed by the applying entity in Questions 151-153.
The proposed .aio Community Registration Policies are limited in scope because .aio will operate a dedicated community namespace, rather than a general-purpose open top-level domain, and must apply its commitments in a practical, measurable and resource-conscious manner.
The limitations proposed in Questions 151–153 are necessary to protect the mission of .aio. They recognise and seek to address challenges associated with administering the .aio namespace and its broad, globally diverse community membership. The limitations establish a framework for registration and use that supports the authority of .aio community members while remaining responsible, ethical, measurable and enforceable.
The limitations reflect a deliberate decision by the .aio applicant, in consultation with prospective community members, to require evidence at the point of registration. The .aio applicant recognises that universal pre-registration validation may impose an additional administrative burden compared with a less restrictive post-registration validation model. The applicant has considered this risk, including the operational demands of the proposed approach. Prospective members of the .aio community have nevertheless expressed a firm preference for pre-registration validation, and the .aio applicant has adopted it as a core feature of this application.
The proposed model requires every applicant to make a mandatory eligibility and use attestation and provide sufficient evidence before a domain name registration can be activated. It requires registrars to collect registrant information and flow down the required obligations. It also enables the .aio registry operator or its nominee—likely a dedicated, formally constituted Indigenous Peoples-led forum—to assess eligibility and name selection before registration. Tailored review will apply to restricted names within specified categories, including names of cultural significance or that are otherwise culturally sensitive. Complaint investigation and risk-based post-registration audits will remain available as supplementary safeguards. Acceptable-use compliance will be complaint-based, risk-based and evidence-based to avoid impractical content-monitoring obligations. Enforcement will focus on objective policy breaches, including impersonation, false claims of authority, material community harm and DNS abuse.
These limitations are proportionate because they give effect to the community’s expressed preference for pre-registration validation while focusing validation, review, subsequent monitoring and compliance enforcement on evidence relevant to eligibility, name selection and intended use.
The policies will apply for the life of the .aio TLD unless amended through ICANN-approved processes.
Q155Explain how the proposed Community Registration Policies of the applying entity meets the Registry Commitments Evaluation criteria 4 and 5?
Explain how the proposed Community Registration Policies of the applying entity meets the Registry Commitments Evaluation criteria 4 and 5?
The proposed .aio Community Registration Policies meet Registry Commitments Evaluation criteria 4 and 5 because they are specific, additional and operationally feasible. They are capable of enforcement through the Registry Agreement, the Registry-Registrar Agreement, Registrar Registration Agreements and the .aio published policies.
The .aio Community Registration Policies are not duplicative of requirements under applicable law, ICANN agreements, ICANN Consensus Policies or Temporary Policies. ICANN’s baseline requirements address matters including registry operations, DNS abuse, registration data accuracy and registrar obligations, but they do not determine who is eligible to register a .aio domain name; how a .aio name must relate to the registrant or community purpose; or how .aio’s mission is protected through eligibility attestations, targeted review, complaint handling and audits. To the extent that a policy overlaps with DNS abuse or legal-compliance obligations, that overlap is necessary and appropriate because the policy applies those obligations in a TLD-specific community context and provides additional contractual consequences for conduct inconsistent with the .aio mission.
The policies are not contrary to applicable law, ICANN agreements, ICANN Consensus Policies or Temporary Policies. They do not require registrars or registrants to act unlawfully, do not require discriminatory treatment, and do not require disclosure of information beyond what is reasonably necessary for eligibility verification, name selection and complaint handling.
The policies are compatible with ICANN’s Bylaws and mission because they operate through aio’s domain name registration rules and registry compliance mechanisms. The .aio registry operator or nominee, rather than ICANN, will administer the eligibility, name-selection, acceptable-use, complaints and enforcement policies under published rules. The policies do not require ICANN to regulate website content or make subjective cultural determinations. ICANN’s role will be limited to enforcing commitments incorporated into the Registry Agreement.
The policies do not require an additional Registry Service. They can be implemented using ordinary registry functions and compliance processes, including registrar flow-down commitments, EPP registration management, reserved-names administration, and industry-recognised abuse and compliance processes. The .aio registry operator can demonstrate compliance through publication of its policies, and retention of complaint and enforcement outcome .
If the .aio applicant later proposes a new technical registry service outside the approved Registry Services, it shall engage its selected Registry Service Provider and obtain any evaluation or approval required by ICANN before implementation.
Answered with a document. Attachments are not published by ICANN.
Q156From where does the applying entity have the support to run the applied-for string on behalf of the identified community?
From where does the applying entity have the support to run the applied-for string on behalf of the identified community?
Te Kāhui Raraunga Charitable Trust (TKR) has support from across The Data Sovereignty for Self-Determination of Indigenous Peoples’ Honouring Ancestral Intelligence Community (The .aio community) to apply for and operate the .aio TLD from Aotearoa, New Zealand.
Refer evidence in the letters of support attached.
- Communities, Nations, Tribes, Global Collectives: TKR_2026 All Support Letters_ICANN Application_10Aug26.
- Mandate and Authority through Data Iwi Leader’s Group of the National Iwi Chairs Forum: TKR_2026 RetaTautoko_TeHikuMedia_30Jul26.
Answered with a document. Attachments are not published by ICANN.
Q157Is there any opposition to the applying entity, application, or applied-for string that the applying entity is aware of? If yes, please explain.
Is there any opposition to the applying entity, application, or applied-for string that the applying entity is aware of? If yes, please explain.
No.
Q222If the applying entity wishes to provide any additional information or supporting materials that the applying entity believes may be of interest to the public or relevant to the application, please include them here.
If the applying entity wishes to provide any additional information or supporting materials that the applying entity believes may be of interest to the public or relevant to the application, please include them here.
Additional supporting policy documents for this .aio TLD application include:
-TKR Policy Suite Introduction and Full Policy - .AIO TLD Registration Policy_11Aug26
-TKR Policy Suite Introduction and Full Policy - .AIO TLD Reserved & Restricted Names Policy_11Aug26
-TKR Policy Suite Introduction and Full Policy - .AIO TLD Acceptable Use Policy_11Aug26
-TKR Policy Suite Introduction and Full Policy - .AIO TLD Internationalised Domain Name Policy_11Aug26
-TKR Policy Suite Introduction and Full Policy - .AIO TLD Launch Policy_11Aug26
One policy document not uploaded due to space constraints includes:
-TKR Policy Suite Introduction and Full Policy - .AIO TLD Sunrise and Alternative Dispute Resolution Policy_11Aug26
Answered with a document. Attachments are not published by ICANN.
Q223By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
true
Q224By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
true