AI Governance Institute
Must ComplyRegulationGlobal

Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law

Issued by

Council of Europe

liveCoE AI ConvUpdated October 2026 · Last verified October 1, 2026
Official document →

This Council of Europe treaty is the first legally binding international instrument on AI. It covers AI used by public authorities and private actors acting for them; Parties decide how to address other private actors. It opened for signature on 5 September 2024 and was not yet in force as of mid-2026.

Applies To

Large enterpriseSMBPublic sectorAI developerAI deployer

Overview

The Framework Convention establishes binding obligations for signatory states to ensure that AI systems deployed in their jurisdictions comply with human rights standards, democratic values, and rule-of-law principles. It covers the full lifecycle of AI systems, from design through deployment and decommissioning, and requires states to put in place legal and institutional safeguards. Key provisions include transparency and explainability obligations, requirements for human oversight mechanisms, and protections for individuals affected by AI-driven decisions. The Convention permits regulatory sandboxes (supervised settings for testing new AI under regulator oversight) to allow controlled innovation while maintaining rights-based safeguards. Enforcement is channeled through national implementation: states must adopt domestic laws and designate competent authorities to monitor compliance. The treaty opened for signature in Vilnius on 5 September 2024. Signatories include the EU and non-member states such as Canada, Israel, Japan, the United States, and Uruguay. It enters into force after five ratifications, including three Council of Europe members. The EU became the first Party on 15 May 2026, and the treaty was not yet in force as of mid-2026. Other non-member states can accede only after it enters into force.

Key Requirements

  • •Parties must apply the Convention to AI used by public authorities and private actors acting for them, and address other private-sector risks in the way they declare.
  • •AI system operators must implement transparency measures, including disclosing to individuals when they are interacting with or subject to decisions made by an AI system.
  • •Documented human oversight mechanisms must be established for AI systems that can materially affect individuals' rights or interests.
  • •States must provide accessible remedies for persons whose rights are affected by AI systems, including redress and review procedures.
  • •Regulatory sandboxes are permitted but must include rights-protection conditions and time-limited scope.
  • •States are required to conduct or require impact assessments addressing human rights, democratic processes, and rule-of-law risks before deploying high-impact AI systems.

What Your Organization Must Do

  • →Track ratifications, since the treaty needs five, including three Council of Europe members, to enter into force.
  • →Monitor domestic implementing laws in countries where you operate, as obligations reach you through national rules.
  • →Map which of your AI systems serve public authorities or act on their behalf, the Convention's core scope.
  • →Draft transparency notices telling people when they interact with, or are decided about by, an AI system.
  • →Document human oversight and escalation paths for AI that can materially affect people's rights or interests.
  • →Build human rights, democracy and rule-of-law impact assessments into procurement before national rules land.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Which countries are bound by the Council of Europe AI Convention and can non-EU states join?
It is open to Council of Europe members, the non-member states that helped draft it, and the EU. Canada, Israel, Japan, the United States, and Uruguay have signed. Other non-member states can accede only once it is in force, which had not happened as of mid-2026.
Does the CoE AI Convention apply to private companies or only government agencies?
It covers public authorities and private actors acting on their behalf. For other private actors, each Party decides how to address risks in line with the Convention's purpose, and declares its approach.
What disclosure obligations does the CoE AI Convention impose on AI system operators?
Operators must inform individuals when they are interacting with or subject to decisions made by an AI system, and must implement documented technical controls enabling that disclosure. Transparency and explainability requirements run across the full AI lifecycle, from design through decommissioning. These obligations apply wherever a signatory state's domestic implementing law reaches.
What human oversight requirements does the Convention impose for high-impact AI systems?
States must ensure that AI systems capable of materially affecting individuals' rights or interests have documented human oversight mechanisms in place, including a clear escalation path for human review of AI-driven outcomes. Operators should formalize these protocols and maintain records demonstrating they are operational, not merely nominal.
Are regulatory sandboxes permitted under the CoE AI Convention, and what conditions apply?
Yes, the Convention explicitly permits regulatory sandboxes to support controlled innovation. However, sandboxes must include rights-protection conditions and are restricted to a time-limited scope. Organizations relying on sandbox arrangements should document how those conditions are satisfied to avoid compliance gaps if the sandbox period expires or conditions change.
What impact assessment obligations does the CoE AI Convention require before deploying high-impact AI systems?
Signatory states must conduct or require impact assessments that address human rights, democratic process, and rule-of-law risks prior to deploying high-impact AI systems. The specific procedural requirements will vary by jurisdiction based on domestic transposition. Compliance teams should build assessment workflows into their AI procurement and development pipelines now, rather than waiting for national implementing rules to finalize.