AI Governance Institute

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
Must ComplyRegulationGlobalHigh riskLimited riskMinimal risk

Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law

Issued by

Council of Europe

liveEffective 2024-09-05CoE AI ConvUpdated September 2026
Official document →

This treaty is the first internationally legally binding instrument dedicated to AI governance, adopted under the auspices of the Council of Europe. It applies to AI systems deployed by public authorities and private actors operating within signatory states. Parties are required to protect human rights, uphold democratic principles, and ensure the rule of law throughout the AI lifecycle.

Applies To

Large enterpriseSMBPublic sectorAI developerAI deployer

Overview

The Framework Convention establishes binding obligations for signatory states to ensure that AI systems deployed in their jurisdictions comply with human rights standards, democratic values, and rule-of-law principles. It covers the full lifecycle of AI systems, from design through deployment and decommissioning, and requires states to put in place legal and institutional safeguards. Key provisions include transparency and explainability obligations, requirements for human oversight mechanisms, and protections for individuals affected by AI-driven decisions. The Convention permits regulatory sandboxes to allow controlled innovation while maintaining rights-based safeguards. Enforcement is channeled through national implementation: states must adopt domestic laws and designate competent authorities to monitor compliance. The treaty was opened for signature in September 2024, and non-Council-of-Europe states, including the United States and Japan, may also accede, giving it a genuinely global reach.

Key Requirements

  • Signatory states must integrate the Convention's obligations into domestic law, covering both public-sector use and private-sector AI deployment where national law applies.
  • AI system operators must implement transparency measures, including disclosing to individuals when they are interacting with or subject to decisions made by an AI system.
  • Documented human oversight mechanisms must be established for AI systems that can materially affect individuals' rights or interests.
  • States must provide accessible remedies for persons whose rights are affected by AI systems, including redress and review procedures.
  • Regulatory sandboxes are permitted but must include rights-protection conditions and time-limited scope.
  • States are required to conduct or require impact assessments addressing human rights, democratic processes, and rule-of-law risks before deploying high-impact AI systems.

What Your Organization Must Do

  • Map all AI systems in use against the Convention's lifecycle obligations to identify compliance gaps, particularly for systems operating in signatory-state jurisdictions.
  • Implement disclosure mechanisms that notify individuals when an AI system is involved in decisions affecting their rights, and document the technical controls enabling that disclosure.
  • Establish or update human oversight protocols for high-impact AI deployments, ensuring a documented escalation path for human review of AI-driven outcomes.
  • Conduct cross-border compliance reviews to determine which domestic implementing laws apply to your operations, as obligations will vary by signatory state transposition.
  • Update procurement and vendor-management contracts to require suppliers to provide documentation demonstrating lifecycle compliance with the Convention's principles.
  • Engage legal counsel to monitor accession status of key operating jurisdictions, since non-Council-of-Europe states can join and trigger new compliance obligations.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Which countries are bound by the Council of Europe AI Convention and can non-EU states join?
The Convention is open to all Council of Europe member states plus non-member observer states, including the United States, Japan, Canada, and others. Non-CoE states may formally accede, which would trigger binding obligations in those jurisdictions. Compliance officers should monitor accession status closely, as each new signatory creates fresh compliance obligations for organizations operating there.
Does the CoE AI Convention apply to private companies or only government agencies?
The Convention covers both public authorities and private actors, though the precise scope of private-sector obligations depends on how each signatory state transposes the treaty into domestic law. Organizations should not assume they are exempt simply because they operate in the private sector. Reviewing the implementing legislation of each relevant jurisdiction is essential to determine actual exposure.
What disclosure obligations does the CoE AI Convention impose on AI system operators?
Operators must inform individuals when they are interacting with or subject to decisions made by an AI system, and must implement documented technical controls enabling that disclosure. Transparency and explainability requirements run across the full AI lifecycle, from design through decommissioning. These obligations apply wherever a signatory state's domestic implementing law reaches.
What human oversight requirements does the Convention impose for high-impact AI systems?
States must ensure that AI systems capable of materially affecting individuals' rights or interests have documented human oversight mechanisms in place, including a clear escalation path for human review of AI-driven outcomes. Operators should formalize these protocols and maintain records demonstrating they are operational, not merely nominal.
Are regulatory sandboxes permitted under the CoE AI Convention, and what conditions apply?
Yes, the Convention explicitly permits regulatory sandboxes to support controlled innovation. However, sandboxes must include rights-protection conditions and are restricted to a time-limited scope. Organizations relying on sandbox arrangements should document how those conditions are satisfied to avoid compliance gaps if the sandbox period expires or conditions change.
What impact assessment obligations does the CoE AI Convention require before deploying high-impact AI systems?
Signatory states must conduct or require impact assessments that address human rights, democratic process, and rule-of-law risks prior to deploying high-impact AI systems. The specific procedural requirements will vary by jurisdiction based on domestic transposition. Compliance teams should build assessment workflows into their AI procurement and development pipelines now, rather than waiting for national implementing rules to finalize.