AI Policy Wiki
Dashboard

Council of Europe Framework Convention on AI and Human Rights, Democracy, and the Rule of Law

high confidence · updated 2026-06-06

The first international legally binding treaty on AI. Adopted by the Council of Europe in May 2024, opened for signature September 2024; requires 5 ratifications (including 3 CoE members) to enter into force. General principles, significant signatory latitude, no binding AI-capability or compute thresholds.

The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy, and the Rule of Law is the first international legally binding treaty on artificial intelligence. It was adopted by the Council of Europe's Committee of Ministers on 17 May 2024 and opened for signature at Vilnius on 5 September 2024. The treaty sets out general principles for AI systems whose lifecycle activities may affect human rights, democracy, and the rule of law, while leaving signatories substantial latitude in domestic implementation.

Status and timeline

The text was negotiated over several years in the Council of Europe's Committee on Artificial Intelligence (CAI), adopted on 17 May 2024, and opened for signature at Vilnius on 5 September 2024.

Initial signatories at opening included the EU, the UK, the US, Israel, Andorra, Iceland, Norway, Moldova, San Marino, and Georgia. The inclusion of the US makes it one of the few binding international instruments the US has signed on technology governance, though signature is not ratification and domestic ratification processes vary.

The convention requires five ratifications to enter into force, including at least three Council of Europe member states. As of the 2024 G'sell report cutoff, the ratification count was below this threshold, with a handful of states having signed without ratifying.

Scope and definitions

The treaty was drafted by the Council of Europe — a 46-member intergovernmental organization that is distinct from the European Union and includes the UK, Switzerland, and Turkey. Non-CoE states, notably the US, Canada, Japan, Israel, Australia, and Argentina, participated in negotiations as observers and can sign.

The convention focuses on AI systems whose lifecycle activities have the potential to affect human rights, democracy, and the rule of law. Per G'sell (2024), the covered activities are the design, development, use, and decommissioning of AI systems within the scope of the convention. Public-sector actors are clearly covered; private-sector coverage depends on signatory implementation. Signatories may limit full obligations to public-sector AI and apply softer commitments to private-sector AI, a carve-out that G'sell notes reduces the treaty's binding force.

Key provisions

Per G'sell (2024), signatories commit to the treaty's core principles: human dignity and individual autonomy; equality and non-discrimination; privacy and data protection; transparency and oversight; accountability and responsibility; reliability; and safe innovation.

Signatories must take "graduated and differentiated" measures appropriate to risk, in accordance with these principles, and establish "iterative risk and impact management" across the AI lifecycle. The treaty also requires effective procedural guarantees, safeguards, and rights — remedies and redress — for persons affected by AI systems. Beyond these general obligations, detailed implementation is delegated to signatories, and the treaty establishes enforcement mechanisms only in the sense that signatories commit to creating them in domestic law.

G'sell (Ch. 7) identifies several limitations typical of international framework instruments. The provisions are deliberately general, with broad latitude left to signatories. The treaty sets no binding AI-capability or compute thresholds: it does not limit model training compute, capability levels, or systemic-risk categories, so the EU AI Act's substantive obligations are not replicated at the treaty level. There is no international compliance commission; enforcement is domestic, with no cross-border tribunal or monitoring body holding binding authority. There is no mutual recognition, so a system certified as safe in one jurisdiction is not automatically recognized in others. The private-sector carve-out option allows signatories to choose weaker private-sector application, narrowing the treaty's scope.

Comparison with the EU AI Act

DimensionCoE Framework Convention[[eu-ai-actEU AI Act]]
Binding forceInternational treaty; binding on ratifying statesDirectly applicable EU regulation
Geographic scope46 CoE members + observer/signatory statesEU member states (+ extraterritorial reach to products sold in EU)
Substantive specificityGeneral principles, broad discretionDetailed risk-tier obligations, specific articles
EnforcementDomestic implementationEU AI Office + national authorities + fines up to €35M / 7% turnover
GPAI/frontier coverageNone specificallyDetailed GPAI Chapter V + systemic-risk tier
SignatoriesEU, UK, US, Israel, othersEU only (extraterritorial reach affects others)

G'sell characterizes the Framework Convention as a floor — a statement of shared international principles — rather than a ceiling, with the EU AI Act and domestic legislation doing the operational work.

Reception

G'sell (2024) describes the convention as the first binding AI treaty, setting a precedent that binding international instruments on AI are politically achievable. The joint signature by the US and EU is unusual for a technology-governance instrument. The treaty centers human rights, democracy, and the rule of law, a framing G'sell suggests may prove useful if future negotiations aim at more substantive commitments, and it provides a soft-law reference point that domestic regulators can cite when justifying AI-specific legislation.

The convention sits alongside parallel soft-law instruments: the non-binding The Bletchley Declaration (AI Safety Summit, 1–2 November 2023) (Nov 2023) from the AI Safety Summit, the voluntary Frontier AI Safety Commitments (Seoul, 2024) (May 2024) by frontier labs, and the G7 non-binding G7 Hiroshima Code of Conduct for Advanced AI (2023) (Oct 2023).

Relationships

See also