Council of Europe AI Convention: A Compliance Guide
The Council of Europe AI Convention (Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law) is the first legally binding international treaty on AI. It sets principles-based obligations on human rights, oversight, transparency, and remedy, applying directly to public authorities and, more narrowly and by state discretion, to private-sector AI systems.
The Council of Europe AI Convention is the first legally binding international treaty on AI. It establishes principles-based obligations on human rights, oversight, transparency, and remedy for public authorities, with narrower, state-discretionary coverage for private-sector systems.
Framework Convention at a Glance
- Adopted
- Adopted by the Council of Europe Committee of Ministers on 17 May 2024.
- Opened for Signature
- Opened for signature on 5 September 2024 in Vilnius, Lithuania.
- Legal Status
- First legally binding international treaty addressing AI’s impact on human rights, democracy, and the rule of law.
- Entry into Force
- Requires ratification by five signatories, including at least three Council of Europe member states.
What the Convention Is and Why It Matters
The Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law is the first legally binding international treaty focused on AI. Unlike product-centric technical regulations, it is principles-based. It centers obligations on human rights protections, meaningful oversight, transparency about AI use, and access to remedy when AI-supported decisions affect people.
For enterprises, the Convention matters because it shapes how Council of Europe member states will write and enforce national AI rules over time. Even before every implementing law is final, organizations that serve public authorities, bid on public contracts, or operate critical decision systems in those jurisdictions should treat the Convention’s principles as design constraints for governance programs.
Scope of Application: Public and Private Sector Obligations
The Convention applies directly to public authorities. AI systems used by or on behalf of public authorities in Council of Europe member states are the clearest trigger for Convention-aligned obligations. Private-sector coverage is narrower and depends on how each state chooses to extend the framework; it is not automatically identical to public-sector duties.
In practice, portfolio scoping should start with systems that support public-sector decisions, deliver services under public mandate, or influence rights-related outcomes. Teams should then track how national implementing measures treat private operators in their markets.
Framework Convention vs. EU AI Act: Structural Differences
The EU AI Act is a detailed, risk-tiered product and systems regulation. The Council of Europe Convention is a human-rights and rule-of-law framework. Documentation written only for EU AI Act conformity will not automatically satisfy the Convention’s broader democracy and rights scope.
Enterprises already investing in EU AI Act programs can reuse much of that work. The efficient path is gap analysis: map existing risk assessments, oversight models, and transparency controls against the Convention’s principles, then close gaps with rights-focused impact assessments, clearer ownership, and remedy pathways rather than rebuilding governance from scratch.
Ratification Status and Compliance Timeline Uncertainty
The Convention was adopted by the Council of Europe Committee of Ministers on 17 May 2024 and opened for signature on 5 September 2024 in Vilnius, Lithuania. Entry into force requires ratification by five signatories, including at least three Council of Europe member states. Until enough ratifications land and national implementing laws settle, exact compliance calendars will vary by country.
That uncertainty does not justify delay. Organizations can put durable controls in place now: inventory systems in scope, document rights impacts, assign ownership, and retain decision evidence so future national rules can be met without a scramble.
What Enterprises Should Operationalize
The following actions translate Convention principles into concrete governance work. They prioritize evidence, ownership, and runtime traceability over policy text alone.
- Identify which AI systems in your portfolio are used by or on behalf of public authorities in Council of Europe member states, since these trigger direct Convention obligations.
- Document AI risk and human rights impact assessments as a standalone artifact distinct from EU AI Act conformity documentation, addressing the Convention’s broader democracy and rule-of-law scope.
- Establish notification and remedy mechanisms so individuals affected by AI-supported decisions can be informed and can contest outcomes.
- Assign clear internal ownership for the human rights impact of each AI system to support the Convention’s accountability principle.
- Map existing EU AI Act risk assessments and oversight controls against the Convention’s principles to identify governance gaps rather than starting from scratch.
- Maintain runtime audit logging and decision records that can produce evidence of risk assessment, human oversight, and transparency if requested under future national implementing laws. Runtime governance platforms such as Trussed AI support this by enforcing policy controls and producing audit logs at the point AI agents take action, which can help demonstrate the oversight and traceability the Convention’s principles call for.
Preparing Governance Programs for Implementing Legislation
Enterprises operating across Council of Europe member states need governance and runtime controls that can produce evidence of risk assessment, oversight, and decision transparency as implementing legislation develops. Programs that already capture who approved a system, how humans oversee it, what individuals were told, and how outcomes can be challenged will adapt more cleanly when national laws crystallize.
Focus on durable records: impact assessments that speak to rights and democracy, clear role ownership, notification and contest paths, and runtime logs that show policy enforcement at the moment AI systems act. Those artifacts remain useful whether a future rule is principles-heavy or procedure-heavy.
Prepare Your AI Governance Program for Emerging Legal Obligations
Enterprises operating across Council of Europe member states need governance and runtime controls that can produce evidence of risk assessment, oversight, and decision transparency as implementing legislation develops.
Talk to an Expert