Council of Europe - AI and Human Rights (CETS No. 225)
Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225)
Council of Europe
RAI-XE-GO-CECAIXX-2024CETS No. 225
The first legally binding international treaty on AI, human rights, democracy, and the rule of law.
Summary
Read full text ↗Plain English
Overview
The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, designated as CETS No. 225, represents the first legally binding international treaty designed to ensure that the deployment and use of artificial intelligence (AI) systems are fully consistent with human rights, democracy, and the rule of law. Developed by the Committee on Artificial Intelligence (CAI) between 2022 and 2024, the Convention was formally adopted by the Council of Europe Committee of Ministers on May 17, 2024. Its primary objective is to fill the legal vacuum in international law regarding the specific challenges posed by AI, providing a high-level framework that signatories must transpose into their domestic legal systems. The treaty is unique in its 'open' nature, meaning it is available for signature not only by the 46 member states of the Council of Europe but also by non-European states and international organizations, reflecting the global nature of AI technology and its cross-border implications. This instrument is the culmination of years of diplomatic negotiation and technical drafting, aimed at creating a 'common legal space' where innovation does not come at the expense of fundamental human dignity. By establishing a set of core principles, the Convention seeks to prevent the fragmentation of international law and provides a baseline for national legislation across diverse legal traditions, from civil law to common law systems.
Definitions
The Convention provides a foundational definition of an 'artificial intelligence system' that is intentionally aligned with other international efforts, particularly the OECD's definition, to ensure global interoperability. It defines an AI system as a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This broad definition is intended to be 'future-proof,' capturing current machine learning techniques as well as future iterations of autonomous systems. By focusing on the 'lifecycle' of these systems, the Convention ensures that legal responsibility is not limited to the end-user but extends to the developers and designers who shape the system's capabilities and constraints. Furthermore, the document defines 'Parties' as the states or international organizations that have consented to be bound by the treaty. It also introduces the concept of 'stakeholders,' emphasizing a multi-stakeholder approach to AI governance that includes civil society, the private sector, and the technical community. Key terms related to 'adverse impacts' are central to the treaty's operation, referring to any negative effects on human rights, the functioning of democracy, or the rule of law. The explanatory report accompanying the Convention further clarifies these terms, noting that 'human rights' encompasses the full spectrum of rights protected under the European Convention on Human Rights (ECHR) and other applicable international instruments, ensuring a comprehensive protective shield against algorithmic discrimination, privacy violations, and threats to freedom of expression. This definitional clarity is essential for legal certainty, allowing developers and regulators to understand exactly which technologies fall under the treaty's purview.
Governance and Institutional Framework
The institutional framework established by the Convention is centered on the 'Conference of the Parties,' a body composed of representatives from every signatory state. This Conference is tasked with monitoring the implementation of the Convention, facilitating cooperation between parties, and considering any proposals for amendments. It serves as a forum for the exchange of information on legal, policy, or technical developments in the field of AI. The Conference of the Parties is also responsible for evaluating the effectiveness of the treaty over time, ensuring that it remains relevant as AI technology evolves. This governance model reflects the Council of Europe's traditional approach to 'living' treaties, where the collective oversight of member states ensures ongoing compliance and adaptation. In addition to the Conference of the Parties, the Convention mandates that each party establish or designate independent mechanisms to oversee compliance with the treaty's provisions. These domestic oversight bodies must have the necessary powers and resources to monitor AI systems within their jurisdiction and provide remedies for individuals whose rights have been violated. The Secretary General of the Council of Europe also plays a vital administrative role, acting as the depositary of the treaty and facilitating the communication of reports and assessments between the parties. This dual-layered governance—combining international peer review with domestic independent oversight—is designed to create a robust accountability loop that prevents the Convention from becoming a mere 'paper' commitment. The framework also allows for the participation of observers, including non-party states and international organizations, ensuring that the governance of AI remains a global and inclusive dialogue.
Key Provisions
The core of the Convention is found in its general obligations, which require parties to adopt or maintain appropriate legislative, administrative, or other measures to give effect to the treaty. Article 7 focuses on the protection of human rights, mandating that the use of AI systems must not lead to discrimination or the infringement of fundamental freedoms. Article 8 addresses the integrity of democratic processes, requiring parties to ensure that AI is not used to undermine the independence of the judiciary, access to justice, or the fairness of elections. This includes measures to combat the use of AI for the manipulation of public opinion or the spread of disinformation that could interfere with the right of citizens to form opinions freely. Another critical provision is Article 16, which mandates 'risk and impact management' frameworks. Parties must ensure that AI systems are subject to assessments that identify, evaluate, and mitigate potential risks to human rights, democracy, and the rule of law. These assessments must be conducted throughout the system's lifecycle and must be transparent to the public. The Convention also includes provisions on 'remedies,' ensuring that individuals have access to effective legal and administrative avenues to challenge AI-driven decisions. This includes the right to know that one is interacting with an AI system and the right to an explanation of how a specific decision was reached, particularly in high-stakes areas like social benefits, employment, or law enforcement. These provisions are designed to be 'technology-neutral,' focusing on the outcomes and impacts of AI rather than the specific underlying algorithms, which allows the law to remain applicable even as technical methods change.
Scope and Application
The scope of the Convention was one of the most intensely negotiated aspects of the treaty. Under Article 3, the Convention applies to the activities within the lifecycle of AI systems undertaken by public authorities or by private actors acting on their behalf. Regarding the private sector, parties have a choice: they can either apply the Convention's obligations directly to private actors or take other appropriate measures to ensure that private sector AI activities remain consistent with the treaty's objectives. This 'flexible' approach was designed to accommodate different legal systems and to ensure that the treaty could be signed by a wide range of countries, including those that prefer a more market-led approach to private sector regulation. Crucially, the Convention includes specific exemptions. Article 4 states that the Convention does not apply to AI systems used for the protection of national security interests, provided that such activities are conducted in a manner consistent with international law and democratic processes. Similarly, the treaty does not apply to research and development activities for systems not yet placed into service, unless those activities involve testing that could interfere with human rights. Despite these exemptions, the Convention emphasizes that no AI system should be used in a 'legal vacuum' and that the fundamental principles of the Council of Europe must always be respected, regardless of the system's application area. This balanced scope ensures that while national security and innovation are protected, the core values of democratic societies are not compromised by the unchecked use of AI in sensitive public or private domains.
Implementation Framework
Implementation of the Convention requires parties to integrate its principles into their domestic legal frameworks. This is not a 'self-executing' treaty; rather, it sets out the standards that national laws must meet. Parties are encouraged to use existing regulatory structures, such as data protection authorities or human rights commissions, to enforce the Convention's requirements. The implementation framework emphasizes a 'risk-based approach,' where the level of regulatory scrutiny is proportional to the potential harm posed by the AI system. For high-risk systems, such as those used in the administration of justice or migration control, the implementation requirements are more stringent, involving mandatory impact assessments and human oversight. To support implementation, the Convention encourages international cooperation and the sharing of best practices. Parties are expected to collaborate on technical standards, the development of sandboxes for safe AI testing, and the creation of public awareness programs. The explanatory report highlights that implementation should also involve the private sector through 'co-regulation' or 'self-regulation' mechanisms, provided these are backed by effective state oversight. The goal is to create a 'culture of compliance' where AI developers and users proactively consider the human rights implications of their technology from the earliest stages of design, often referred to as 'Human Rights by Design.' This proactive approach is intended to reduce the need for reactive litigation and to build public trust in AI technologies by ensuring they are developed with ethical and legal safeguards from the outset.
Monitoring and Evaluation
The monitoring mechanism of the Convention is designed to be transparent and participatory. Parties are required to submit periodic reports to the Conference of the Parties detailing the measures they have taken to implement the treaty. These reports are reviewed by the Conference, which can then issue recommendations to specific parties or general guidance to all signatories. This 'peer review' process is a hallmark of Council of Europe conventions and serves to exert diplomatic pressure on states that may be lagging in their obligations. The Conference of the Parties is also empowered to consult with civil society and international organizations during the evaluation process, ensuring a diverse range of perspectives. Evaluation also extends to the technical effectiveness of the treaty. As AI technology evolves—for example, with the rise of generative AI and large language models—the Conference of the Parties will assess whether the Convention's provisions remain adequate. If significant gaps are identified, the Conference can initiate the process for drafting protocols or amendments. This ensures that the Convention is not a static document but a dynamic instrument capable of responding to the rapid pace of technological change. The monitoring process also includes a 'follow-up' mechanism where parties can be asked to provide additional information on specific areas of concern identified during the review cycle. This continuous feedback loop is essential for maintaining the treaty's relevance in a field characterized by exponential growth and unforeseen societal impacts.
Relationship to Other Instruments
The Framework Convention is designed to complement, not replace, existing international and regional legal instruments. It explicitly references its relationship with the European Convention on Human Rights (ECHR) and the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108+). For member states of the European Union, the Convention is intended to work in harmony with the EU AI Act. While the AI Act provides detailed market regulations and technical requirements for the internal market, the CoE Convention provides the overarching human rights and rule of law obligations that apply regardless of market status. Furthermore, the Convention aligns with the UN's efforts on AI, including the UNESCO Recommendation on the Ethics of Artificial Intelligence and the UN General Assembly resolutions on AI. By establishing a binding legal baseline, the CoE Convention provides the 'legal teeth' that many of these non-binding instruments lack. It also maintains a close relationship with the OECD AI Principles, particularly in its definitions and its emphasis on trustworthy AI. This web of interconnected instruments ensures that there is a global 'floor' of protection, preventing a race to the bottom where AI developers seek out jurisdictions with the weakest human rights protections. The Convention acts as a bridge between different regulatory philosophies, providing a common language for human rights that can be understood and applied globally.
International Alignment
International alignment is a core objective of the Convention, evidenced by the participation of non-European states in its drafting. Countries like the United States, Japan, Israel, and Australia were active observers in the CAI, ensuring that the treaty's provisions were compatible with diverse legal traditions, including common law and civil law systems. This alignment is crucial for the global AI industry, as it reduces the burden of complying with conflicting regional regulations. The Convention's emphasis on 'interoperability' means that a risk assessment conducted in one jurisdiction could potentially be recognized in another, provided the underlying standards are equivalent. The Convention also serves as a model for other regions considering AI legislation. By providing a clear roadmap for how to balance innovation with the protection of democratic values, the Council of Europe has set a global benchmark. The 'open' nature of the treaty allows it to function as a global platform for AI governance, fostering a shared understanding of what constitutes 'responsible AI.' This international alignment is further supported by the Council of Europe's cooperation with other international organizations, such as the ITU and the G7 (through the Hiroshima AI Process), ensuring that the Convention remains a central pillar of the emerging global AI governance architecture. By inviting non-member states to sign, the Council of Europe is effectively exporting its human rights standards to the global stage, creating a unified front against the misuse of AI.
Implementation Timeline
| Milestone | Date | Status |
|---|---|---|
| Establishment of the Committee on Artificial Intelligence (CAI) | 2022-01-01 | Completed |
| Adoption of the Convention by the Committee of Ministers | 2024-05-17 | Completed |
| Opening for Signature (Vilnius, Lithuania) | 2024-09-05 | Completed |
| First Meeting of the Conference of the Parties | TBD (Post-Entry into Force) | Pending |
| Entry into Force (Requires 5 ratifications) | TBD | Pending |
Adoption and Endorsement
| Entity | Date | Status |
|---|---|---|
| Council of Europe Committee of Ministers | 2024-05-17 | Adopted |
| European Union | 2024-09-05 | Signed |
| United States of America | 2024-09-05 | Signed |
| United Kingdom | 2024-09-05 | Signed |
| Andorra, Georgia, Iceland, Norway, Moldova, San Marino | 2024-09-05 | Signed |
Sources and References
| Source | Type |
|---|---|
| CETS 225 - Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law | International Organization |
| The Framework Convention on Artificial Intelligence - The Council of Europe | International Organization |
| CETS No. 225 - Full list - Treaty Office | International Organization |
| Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225) (2025) | International Organization |
The Council of Europe's new Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law is the first legally binding international treaty designed to ensure that AI systems are developed and used in line with fundamental human rights, democratic principles, and the rule of law. It applies to signatory states and international organizations, requiring them to integrate its principles into their domestic laws, impacting both public authorities and, potentially, private companies.
This Convention broadly defines an "artificial intelligence system" as any machine-based system that infers from input to generate outputs like predictions or decisions influencing environments. It primarily covers AI activities by public authorities or private actors working on their behalf. Crucially, countries can choose how to apply its obligations to the broader private sector – either directly or through other measures. Exemptions exist for national security AI and early-stage research and development, provided they respect international law.
Key obligations for signatory countries include: - Ensuring AI use does not lead to discrimination or infringe on human rights. - Preventing AI from undermining democratic processes, judicial independence, or fair elections. - Implementing risk and impact management frameworks to identify, assess, and mitigate potential harms throughout an AI system's lifecycle, with transparency. - Providing individuals with effective legal remedies, including the right to know they are interacting with AI and to receive explanations for AI-driven decisions.
The Convention was adopted in May 2024 and opened for signature in September 2024. It will officially take effect once five states have ratified it, which is still pending. This isn't a self-executing law; countries must create or adapt their own national legislation to meet its standards. Enforcement relies on a "Conference of the Parties" that monitors compliance through peer review and reports, alongside domestic independent oversight bodies.
A practical surprise for businesses is the varied approach to the private sector. While the Convention sets a high bar for public AI use, its direct impact on private companies will depend on how each signatory country chooses to implement it. This means your obligations could differ significantly based on your operating jurisdiction, even among countries that have signed the same treaty.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 14 marked completePlain-English obligations under Council of Europe - AI and Human Rights (CETS No. 225). Not legal advice — verify against the official text before relying on it.
- #1CriticalOverview
Applies to: Signatory states and international organizations.
“signatories must transpose into their domestic legal systems.”
- #2CriticalGovernance and Institutional Framework
Applies to: Signatory states and international organizations.
“each party establish or designate independent mechanisms to oversee compliance”
- #3CriticalArticle 7
Applies to: Signatory states and international organizations.
“Article 7 focuses on the protection of human rights, mandating that the use of AI systems must not lead to discrimination”
- #4CriticalArticle 8
Applies to: Signatory states and international organizations.
“Article 8 requires parties to ensure AI does not undermine democratic processes, judiciary independence, or election fairness.”
- #5CriticalArticle 16
Applies to: Signatory states and international organizations.
“Article 16, which mandates 'risk and impact management' frameworks. Parties must ensure that AI systems are subject to assessments”
- #6CriticalKey Provisions
Applies to: Signatory states and international organizations.
“ensuring that individuals have access to effective legal and administrative avenues to challenge AI-driven decisions.”
- #7CriticalKey Provisions
Applies to: Signatory states and international organizations.
“the right to know that one is interacting with an AI system”
- #8CriticalKey Provisions
Applies to: Signatory states and international organizations.
“the right to an explanation of how a specific decision was reached”
- #9CriticalArticle 3
Applies to: Signatory states and international organizations.
“parties have a choice: they can either apply the Convention's obligations directly to private actors or take other appropriate measures”
- #10CriticalArticle 4
Applies to: Signatory states and international organizations.
“provided that such activities are conducted in a manner consistent with international law and democratic processes.”
- #11CriticalImplementation Framework
Applies to: Signatory states and international organizations.
“For high-risk systems... mandatory impact assessments and human oversight.”
- #12ImportantImplementation Framework
Applies to: Signatory states and international organizations.
“The implementation framework emphasizes a 'risk-based approach,' where the level of regulatory scrutiny is proportional to the potential harm”
- #13ImportantMonitoring and Evaluation
Applies to: Signatory states and international organizations.
“Parties are required to submit periodic reports to the Conference of the Parties detailing the measures they have taken to implement the treaty.”
- #14RecommendedImplementation Framework
Applies to: Signatory states and international organizations.
“create a 'culture of compliance' where AI developers and users proactively consider the human rights implications of their technology”
Related Regulations
Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225)
Uruguay94% similar
Council Decision (EU) 2024/2218 of 28 August 2024 on the signing, on behalf of the European Union, of the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law
European Union93% similar
Council of Europe Framework Convention on AI, Human Rights, Democracy, and Rule of Law
Ukraine93% similar
Recommendation on the Ethics of Artificial Intelligence
UNESCO93% similar
Principles for the Ethical Use of Artificial Intelligence in the United Nations System
United Nations93% similar
© Regulations.AI — created on 18-Jun-2026 using Gemini 3 Flash Preview