From 12 to 16 October 2026, 3GPP's four radio working groups meet in Jeju, South Korea, and its system and core-network groups meet in Prague. Most of their agendas concern 6G, which is still in a study. A study is the stage in which options are assessed and narrowed before anyone writes binding specifications. For 6G it sits in Release 20, and specification work is planned for Release 21.

Companies drive the work through contributions. A contribution is a written proposal or analysis submitted to a meeting. Deadlines come from the plenaries. A plenary is the parent body that steers the working groups. In September, the SA plenary asked SA2, the group that designs the core-network architecture, to decide the overall 6G system architecture "as soon as possible and no later than" SA2's November meeting. RAN1, the physical-layer group, said it will strive to settle the basic time and frequency structure of the 6G synchronization signal by October. That would leave RAN4, the group that sets radio requirements, meeting cycles for its follow-up work.

The camps below are counted from explicit proposals: a co-signed proposal counts every signatory, a company can back several options, and the counts are neither votes nor predictions.

1. Where AI lives in the 6G core, and who routes the phone's signalling

The core network carries two kinds of traffic. The control plane transports control messages: registration, authentication, mobility and session set-up. The user plane transports the user's actual data.

The phone's control messages to the core are called Non-Access Stratum (NAS) signalling. The base station passes them on without interpreting them. In 5G, the Access and Mobility Management Function (AMF) handles the mobility part of NAS itself. It forwards the session part to the Session Management Function (SMF), which sets up data sessions.

SA2 must decide whether 6G keeps this pattern. Five companies, among them Honor, Huawei and vivo, want NAS routing moved into a standalone Signalling Routing Function (SRF). In their design, the SRF would also terminate the base station's connection to the core. They argue that this stops the AMF from becoming a routing bottleneck. It also means new NAS functions no longer require AMF upgrades. Five other companies, including Ericsson, Qualcomm and Lenovo, want the AMF to keep routing. They argue that the AMF must know each data session and its SMF anyway. In their view, full separation is not achievable and an extra node adds complexity.

The bigger question is AI. Much of the work revolves around intents. An intent is a goal stated by a user, an application or the operator, which the network then works out how to fulfil. Three models compete:

  • AI in optional network functions inside the core. Intent handling sits in optional 6G functions within the packet-switched domain, the part of the core that provides connectivity. Nine companies back this model, for example NTT DOCOMO, Samsung and LG Electronics. They argue that it reuses existing policy and charging and can be deployed step by step.
  • A separate optional AI domain. This domain calls the connectivity functions through their APIs. Three companies propose it as an overall architecture: NEC, Orange and Qualcomm. In the proposals on AI specifically, a wider group of ten backs the idea, including Ericsson, Nokia and Qualcomm. They argue that deterministic connectivity should stay apart from AI, so that both domains can evolve independently.
  • An agent-based core. A "Connection Agent" runs connectivity through a deterministic module, and a "Planning Agent" handles intents. At least one such system agent is always required. Five companies back this model, including China Mobile, ZTE and Honor.

One principle is shared widely. At least 24 companies state that essential connectivity procedures must stay standardized and deterministic, and must not depend on AI.

How intents reach the core is contested too. Ten companies want them carried mainly over the user plane, with NAS used only for standardized, size-limited intents. Six want NAS as the main carrier and the user plane only for large data.

The timetable is tight. SA2's rapporteurs aim for a first high-level architecture choice at this meeting and further decisions in November. The SA plenary will then discuss next steps in December. The protocol groups are waiting. CT1, which writes the NAS protocol, plans to open its architecture-dependent work by February 2027 at the latest. CT4 keeps its control-plane study to topics independent of SA2. Its work plan calls going further "premature" for now and sets a new check in November.

The same agent question appears one layer up. The management group SA5 handles network operation. There, Ericsson and ZTE treat an agent as a role that existing management entities can take on. ZTE wants a separate task-oriented model, because intent models say "what" but not "how". HIPE IP and ETRI propose a common task descriptor, so that agents from different vendors read a delegated task the same way. The operational risk is an agent switched off in the middle of a task. Nine companies want new agent-specific safeguards: lifecycle states with safe transitions, trust levels and a two-phase revocation. For monitoring agents, Ericsson, AsiaInfo and China Mobile would reuse existing fault and performance services, to avoid duplicating data. SA6 builds the APIs that applications use to reach network capabilities. Four companies there would keep the Common API Framework (CAPIF) as the registry and add an AI function that interprets natural-language requests. Samsung, with Nokia as co-signer, proposes a separate intent gateway in front of CAPIF that breaks a goal into API calls. The harder question in SA6 is authorization in a chain of agents. Huawei proposes that every step re-checks the original caller's rights, so that an intermediate agent cannot exceed them. Nokia would bind the agent's authorization to an execution plan, or its individual steps, obtained in advance. China Telecom proposes a different safeguard: before a task starts, the caller checks that it is authorized for every API the task needs, so that a task does not fail halfway.

Assessment. In our reading, the API boundary does not separate the first two models, because both use the core's service-based interfaces. In one, AI functions sit inside the connectivity domain. In the other, they call it from outside. The real differences are four. Who owns intent handling? Whose lifecycle governs upgrades? Which network functions may AI invoke? Who approves an AI plan before it acts? Seven companies want operator control inside the core that applies autonomy levels and can fall back to default procedures. Ericsson prefers the management system as the single source of control. The agent model differs further, because a mandatory system agent cannot simply be switched off. The shared principle of AI-independent connectivity is therefore a floor, not a settlement. A compromise needs agreement on placement, permissions and approval of AI plans. The NAS routing split is harder still, because it fixes where the base station's connection to the core ends.

2. Living with 5G: will your calls stay on the old network?

Registration is how the core learns that a device exists and keeps its context. With single registration, a phone is active in one system at a time. Moving between 5G and 6G then transfers its context. Seven companies call single registration the baseline.

The open question is dual registration, where a phone is registered in both cores at once. In September, the RAN plenary said that only one narrow scenario may be considered. It consists of two separate single registrations: one with the 5G core over NR and one with the 6G core over the 6G radio. The cores do not aggregate traffic and do not split it. Voice over NR (VoNR) runs on the 5G leg and data on the 6G leg, with network-controlled mobility. RAN expects no impact on the radio network. It asks SA2 to judge feasibility by the RAN plenary of 7-11 December. It expects the SA plenary, meeting 8-11 December, to decide no later than then.

  • Support dual registration: seven companies, including China Mobile, China Telecom and EchoStar. China Telecom argues that early 6G voice may be immature, and that 5G voice fallback has caused long call set-up times and failures.
  • Single registration only: Apple, Nokia and ZTE. Apple and Nokia argue that even RAN's scenario needs simultaneous transmission, paging monitoring and two state machines in the phone, which adds complexity, signalling and battery drain. ZTE says the existing dual-registration variant cannot meet RAN's scenario, and that with one SIM it is unclear how network-controlled mobility would work.
  • Two logical devices in one handset: Ericsson, MediaTek and Qualcomm. One handset would hold a "5G voice" device and a "6G data" device, each with its own subscription and registration.

The core design underneath is open too. Ofinno and Rakuten propose one evolved 5G AMF that serves both radios. Four companies, including Lenovo, NEC and Samsung, propose separate 5G and 6G AMFs that exchange context over a new interface. OPPO, ZTE and vivo propose an SRF-based design. Five companies want a shared subscriber database and a shared user-plane function, so that the phone keeps its IP address across systems.

Assessment. In our reading, the voice question pits operational risk against device cost. Dual registration keeps calls on proven VoNR. In return, the handset maintains two core-network relationships, and device and chipset makers absorb that complexity. The two-devices proposal meets RAN's scenario without a new dual-registration mechanism. It shifts the cost to subscriptions and device implementation instead. A compromise is plausible because RAN has already narrowed the case to one scenario with no radio impact. What remains is whether the core can support two independent registrations cheaply.

3. How a phone finds a 6G cell, and how long the network may sleep

A phone that switches on knows nothing about nearby cells. It tunes to candidate frequencies on a grid called the synchronization raster. At each one, it looks for the Synchronization Signal Block (SSB). The SSB has three parts:

  • The Primary Synchronization Signal (PSS) is a known sequence. By correlating against it, the phone finds the symbol timing and a rough frequency.
  • The Secondary Synchronization Signal (SSS), together with the PSS, determines the physical cell identity. NR offers 1,008 identities.
  • The Physical Broadcast Channel (PBCH) carries the minimum information needed to read the next system message.

The periodicity is the interval between SSB bursts. It sets the spacing between detection opportunities. A phone that has just tuned to a raster point may wait up to one period for the next burst. It waits longer if it misses a burst or must combine several. For the base station, the period caps uninterrupted sleep. That gain only materialises in a lightly loaded cell, and only if the other mandatory broadcasts, such as system information and paging, can be grouped around the same bursts. Seven companies propose exactly that grouping.

The options for the default period:

  • 160 ms: seven companies, for example Samsung, KDDI and ETRI. They cite the longest deep sleep. They note that 160 ms already exists in NR for satellite access and that PBCH detection is close to 80 ms performance.
  • 80 ms: three companies, including Sony and InterDigital. They see real sleep time with lower access delay than 160 ms.
  • 40 ms, with phones combining copies within and across periods: four companies, including Xiaomi and MediaTek.
  • Keep NR's 20 ms, or at most 40 ms: Google, Nordic Semiconductor and Qualcomm. One variant keeps 20 ms below 3 GHz and allows longer periods only on higher bands. This camp argues that search complexity, delay, buffering and measurement delay grow linearly with the period. They add that the saving is small in loaded cells and that repetition does not speed up recovery after a dropped link.

Long periods come with repetition: the base station sends several copies within one period, and the phone combines them to gain coverage. Thirteen companies want the base station to set the actual number of copies within a per-band maximum. Restrictions would keep the number of possibilities the phone must test small. Google and Sony want a fixed number, so that phones need no blind testing.

On block size, eight companies, for example Samsung, ZTE and vivo, keep NR's four symbols. They say extra symbols give only about 2 dB, while repetition gives more. Tejas Networks backs five symbols, citing a 1.5 dB PBCH gain at a 1% block error rate in a noise-only channel model. Five want more than four, up to six or seven symbols, to meet coverage targets at 7 GHz and for IoT devices. On the sequences, nine companies keep NR's design. Others want a single PSS or chirp-like sequences that cope better with large frequency offsets, such as at 7 GHz.

Two complements address the phone's side. Ten companies support on-demand or lightweight sync signals. Eight want to study a sparser raster, which leaves the phone fewer frequencies to search.

Assessment. In our reading, this is the clearest network-versus-device trade-off of the week. A longer period can save energy in quiet cells. Phones pay in search time, buffer memory and power, most of all at switch-on and after a dropped connection. The proposals themselves contain the compromise. Band-dependent periods, a sparser raster and on-demand signals all cut the phone's cost of a longer period. The October target covers only the basic structure, so values may still move later.

4. The radio pipe: bandwidth, MIMO layers, coding and protocols

Bandwidth. In the new band around 7 GHz, downlink carriers wider than 200 MHz and up to 400 MHz are planned. A phone may receive that span with one RF chain or split it between two chains of 200 MHz each. An RF chain is one set of mixer, filter and converters. This splits the bandwidth, not the antennas: each chain covers half of the spectrum. At the seam between the two halves, phase, timing and gain do not match.

Nine companies, including Huawei, MediaTek and Samsung, want the specification to fix that boundary, with sync and control signals kept off it. Compensating the mismatch costs the phone power, delay and calibration, they argue. Eight companies, including Apple, Ericsson and Qualcomm, want the phone to hide the seam. In their design, the network sees one clean 400 MHz carrier. They counter that signals common to the whole cell cannot be placed differently for each phone, and that per-phone restrictions fragment scheduling. Twelve companies support having no guard band between the chains as the baseline.

A transport block is the unit of data passed to the radio in one transmission; it is split into code blocks for coding. Six companies, including Huawei and MediaTek, keep each transport block within 200 MHz. Nine, including Ericsson, Qualcomm and Nokia, allow one block across 400 MHz, some with each code block confined to one 200 MHz half.

For sub-6 GHz spectrum used in Time Division Duplex (TDD), uplink and downlink share one frequency and take turns in time. For these bands, eight companies propose a 200 MHz maximum. Samsung, Nokia and Apple would allow a wider downlink later if operators hold more spectrum. One contribution signed by four operators asks for 300 MHz in the downlink, citing US and European holdings. For the minimum at about 7 GHz, six companies argue for 20 MHz. The four operators say 100 MHz would likely exceed their holdings, and LG points to low-cost IoT devices. Samsung proposes 100 MHz.

MIMO layers. Multiple-Input Multiple-Output (MIMO) sends parallel data streams, called layers, over the same frequencies. To separate N layers, the receiver needs at least N independent receive branches. The channel must also have a rank of at least N. Rank is the number of independent paths the channel offers. Each layer also uses its own reference-signal port. A port is a logical pilot pattern for channel estimation, not a physical antenna.

At least fourteen companies keep NR's maximum of eight layers. They argue that high-rank channels are rare at about 7 GHz and that serving several users at once is the better capacity tool. ETRI proposes 12 layers. Huawei and Jio Platforms propose 16 layers as a device capability, aimed at fixed-wireless receivers with 16 receive antennas. In Huawei's simulations against 512-antenna base stations, 12 layers give up to 51% more spectral efficiency than 8 at high signal-to-noise ratio, and 16 layers a further 13%.

A codeword is an independently coded block with its own modulation and retransmission. NR uses one codeword for 1-4 layers and two for 5-8. Seven companies keep this. Qualcomm and Samsung want a single codeword for all ranks from 1 to 8. Samsung cites up to 58% extra channel-quality feedback otherwise. Ofinno and Sony want two codewords from rank 2, Sony only when the network configures it. That would reduce the penalty when layers differ in quality.

Coding and modulation. Low-Density Parity-Check (LDPC) codes protect user data. A base graph is the template from which codes of a given size and rate are built. A new third graph would serve high code rates. Nine companies would select it by code rate and block size, as NR does. Nokia and LG put the thresholds at a code rate of at least 2/3 and a block size of at least 8,448 bits. Most want it designed to converge in few decoder iterations. CATT and HFCL name ten or fewer, while Apple wants it tuned for 5 to 15. In the uplink, seven companies back spectrum extension and seven back spectrum truncation. Both shape the signal to lower its power peaks, so the phone's amplifier can run closer to full power at the cell edge. The RAN plenary has already limited uplink 1024QAM to fixed wireless access.

Radio protocols. Above the physical layer, RAN2 debates two layers that number packets. The Packet Data Convergence Protocol (PDCP) runs in the central unit of the base station and handles ciphering and reordering. Radio Link Control (RLC) runs in the distributed unit and handles segmentation and retransmission. Six companies, among them Honor, Sony and ZTE, propose one shared sequence number. It saves up to about 2 bytes per packet. Eight companies, among them Apple, Qualcomm and Samsung, propose keeping independent numbers. They point to unresolved problems: gaps in numbering, numbering of control packets and initialising RLC's receive window. The shared-number camp proposes fixes for them, such as reports of skipped numbers. For battery life, ten companies want network-controlled adaptation of connected-mode discontinuous reception (C-DRX), with input from the phone. C-DRX is the schedule by which a connected phone switches its receiver off. China Telecom supports adaptation controlled by the network, but would postpone adaptation requested or triggered by the phone and first reuse the traffic reports already planned for scheduling. vivo opposes adapting the cycle: its simulations show little gain, and it expects a wake-up signal to save more. Six companies want such a downlink wake-up signal even without C-DRX.

Assessment. In our reading, the layer and bandwidth debates separate the mandatory baseline from optional capabilities. The 16-layer and 1024QAM proposals target fixed equipment as device capabilities. Phones that skip them pay mainly in specification and test complexity, not in hardware. The RF seam is different, because it touches every phone that uses two chains at 7 GHz. A specified boundary moves the cost to the scheduler. A hidden one moves it into the phone's power and calibration. The zero guard band is already agreed. One proposed bridge is a 400 MHz transport block with code blocks kept within 200 MHz halves, which Huawei rejects as too complex. Where cell-wide signals may sit remains a binary choice.

5. The link between base station and core

The 6G base station needs a control link to the core. In 4G and 5G, it runs over the Stream Control Transmission Protocol (SCTP), secured with IPsec. SCTP preserves message boundaries and supports several network paths.

Nine companies keep SCTP, among them AT&T, Huawei and Samsung. They cite reuse of 5G equipment, minimal testing and measured lower stack latency. Deutsche Telekom, Lenovo and Qualcomm lean towards QUIC with its built-in TLS 1.3 encryption. QUIC is a newer Internet transport. They point to connection identifiers that support migration and scaling in cloud deployments, and to poor SCTP support on container platforms. The caveat is general. A connection identifier helps route packets and survive address changes. Moving a live connection to another server instance still requires moving its state. QUIC streams also carry bytes, so message boundaries must be handled by the layer above. NTT DOCOMO lists QUIC's advantages but wants to study first how SCTP's features would map onto it. Six companies want the evaluation method fixed first, with a choice at a later meeting such as RAN3#135. RAN3's work plan asks for analysis of the stack options "with the objective of establishing a clear timeline for a final decision".

For new services such as AI data collection and sensing, nine companies explicitly favour a Service-Based Interface (SBI), among them China Mobile, Qualcomm and T-Mobile. An SBI is the web-style API framework of the 5G core. Its supporters argue that it suits discovery, multiple consumers and high data volumes. Huawei wants one point-to-point interface for all services, so the base station does not carry two interface frameworks. Ericsson wants point-to-point at least for sensing. CATT, Xiaomi and ZTE propose a point-to-point hybrid. Direct links from the base station to core functions would carry signalling not tied to a specific phone. Phone-related signalling would still go through the AMF. For SBI, the work plan asks only for further analysis.

Assessment. In our reading, the SBI question hangs on SA2's open question of where signalling ends. Samsung assesses the services beyond connectivity this way. If they all end at one core node, point-to-point is clearly favoured. If they reach many core functions directly, neither option leads, and growth in their number favours SBI. Because the SBI choice depends on SA2 and the work plan asks only for a timeline on the transport stack, we expect a schedule this week rather than a protocol.

6. A side track: 256-bit encryption for 5G-Advanced

This item concerns 5G-Advanced, not 6G. The SA plenary approved a Release 20 work item to support 256-bit encryption and integrity algorithms. It asked SA3, the security group, to finish by December 2026. SA3 must also decide whether the AES- and Snow-based variants are mandatory or optional. The ZUC-based variants will be optional in any case. Orange proposes making AES and Snow mandatory for phones, base stations and the AMF, citing agency recommendations for long-lived systems. One contribution with 12 co-signers, including Ericsson, Nokia and Qualcomm, makes all variants optional. The phone would signal support, and the network would select an algorithm per connection.

Assessment. In our reading, mandatory support guarantees that the capability exists on both ends. It does not guarantee use, because the network still selects the algorithm. Optional support means 256-bit protection only where both sides implement it. The trade-off is common availability against implementation cost for every vendor.

What to watch

  • Core architecture: Does SA2 record a first high-level choice among AI in core functions, a separate AI domain and agents, and between SRF and AMF routing? Or does all of it go to November? And is the result precise enough for CT1 to plan its architecture-dependent NAS work?
  • Cell search: Does RAN1 fix the SSB symbol count and a default period of 160, 80, 40 or 20 ms? Does the period become band-dependent, or does the basic structure miss the October target?
  • Voice on 5G: Does SA2 produce a feasibility view the December plenaries can decide on? Would it favour dual registration, two logical devices or single registration only?
  • Seam and transport: Does RAN4 choose a specified or a phone-handled boundary for 200-400 MHz carriers? Does RAN3 set a date for choosing between SCTP and QUIC?

What this round will not settle

No 6G specification will be written this week: the first version of the 6G work-item description is due for discussion in November, with approval planned for February 2027. Comparisons with 5G for energy efficiency, spectral efficiency and coverage are only starting to be recorded, and sensing remains an open study. The 256-bit decision for 5G-Advanced is due by December.

Sources

Contributions submitted to RAN1#126-bis, RAN2#135-bis, RAN3#133-bis, RAN4#120-bis (Jeju) and SA2#177, SA3, SA5, SA6, CT1, CT4 (Prague), 12–16 October 2026, as listed in the public 3GPP TDoc lists on 8 October 2026; plenary liaison statements SP-260999 (S2-2609379), RP-262264 (S2-2609339) and SP-260991 (S3-264205); working-group work plans S2-2610191, C1-265105, C4-264137, R3-264401 and R1-2606891. Company counts include every co-signer of a proposal; a company can appear under several options. Counts describe the contributions, not votes or likely outcomes.