Sanctions and the Contradiction of Restricting a Global Network

Economic sanctions are a foreign-policy blunt instrument aimed at governments, but the Internet is an open ecosystem built for global communication. The sweeping, multilateral packages imposed on Russia after its invasion of Ukraine — and the separately authorized expansions of Internet services in Iran — highlight a persistent engineering and policy tension: how to cut off bad actors without cutting off ordinary citizens or fragmenting the network itself.

For infrastructure providers, compliance is only part of the challenge. The real difficulty is that legal exceptions for communications services exist precisely to preserve a free and open Internet, yet the practical ambiguity of those exceptions often pushes companies toward overly cautious — and restrictive — behavior.

The Intent Versus the Implementation

Sanctions are designed to raise the cost of violating international norms and force behavioral change. They are not, in theory, intended to punish citizens. Indeed, the free flow of information is often a key driver of political change. The US government points to an exemption in its primary sanctions law for “any postal, telegraphic, telephonic or other personal communication” that does not transfer anything of value. For decades, it has supported this with General Licenses that authorize specific telecommunications and Internet services in embattled jurisdictions.

But the incentive structure for private companies cuts the other way. The financial and reputational penalties for even inadvertent sanctions violations are severe. Spending the time and money to legally parse every General License is risky; simply blocking an entire region or user base is much simpler. Cloudflare states it has made the investment to understand these exceptions, but acknowledges that many companies will not, choosing blanket restrictions over nuanced compliance.

The legal landscape itself makes this worse. There are two primary categories of sanctions: country-based and party-based, and the rules differ meaningfully across US, UK, and EU jurisdictions.

Country-Based Restrictions Vary By Region

The US maintains comprehensive sanctions against Cuba, Iran, North Korea, Syria, and the Crimea, Luhansk, and Donetsk regions of Ukraine. Within that framework, General Licenses authorize peering, VPNs, SSL certificates, and other services “incident to the exchange of communications.” Yet even where these compile, the terms differ sharply:

  • In Cuba, Iran, and the Donetsk/Luhansk regions, some free and some paid services are authorized.
  • In Crimea and Syria, all authorized services must be provided at no cost to the user.
  • Some licenses explicitly list authorized services; others require companies to self-determine eligibility.

The US recently broadened its Iran license to cover more products and services, a move praised by Cloudflare. However, such changes take time to implement on the ground. Entering a market with years of accumulated restrictions is technically and logistically fraught. Regulators may also be slow to act — the UK and EU, notably, have issued no Internet-related General Licenses for Russia, which positions them as restrictive outliers.

The List-Based Problem of Domains and Emails

Party-based sanctions require screening customers against specific lists of designated individuals and entities. The US list includes identifiers such as aliases, addresses, emails, and domain names. The UK adds its own lists, but the entries often don’t align with the US ones.

For infrastructure companies, this creates a unique operational burden. Standard sanctions-screening platforms rarely triage email addresses and domains automatically. Yet these are the most critical pieces of data for onboarding a customer. Companies must therefore build their own proprietary blocks on sanctioned domains and emails. Even then, ambiguity persists: receiving an abuse report claiming a domain is operated by a sanctioned party is not confirmation. Absent a listing on an official list, companies lack clear guidance for how to evaluate such reports, balancing the need for enforcement with fair, consistent policy.

Practical Risks for the Global Network

Without clarity from governments, tech firms of all sizes are exiting high-risk markets entirely. Over-compliance is the rational business response to vague regulations. This has direct consequences for network health: it fragments the global Internet and cedes digital ground to authoritarian governments monitoring and controlling their citizens' access.

To shore up the policy goals of sanctions — rather than undermine them — Cloudflare recommends regulators take three specific steps:

  • Engage stakeholders on the practical implications of sanctions before they are introduced, explicitly requesting guidance on ambiguous areas.
  • Harmonize exemptions and authorizations across the US, UK, and EU jurisdictions to simplify multinational compliance.
  • Establish clear guidelines for when a domain or user is subject to sanctions, coordinating new list entries across national governments.

Compliance as a Feature, Not a Friction

Navigating these rules is mandatory for a company aiming to operate in both compliant and connected ways. Cloudflare states it remains fully committed to applicable sanctions while continuing to provide services that support secure, open communications — even in the most challenging jurisdictions. The market outcome, however, depends on a regulatory environment that makes legal provided services a defensible, clear choice.