Skip to content

Council of Europe Framework Convention on AI (CETS 225)

Provenance & licence

Source: Council of Europe Treaty Office — chart of signatures and ratifications, CETS 225 · Convention text as published in OJ L 2026/1081 · Explanatory Report (CETS 225) · Last observed: 2026-09-05 · Version: adopted by the Committee of Ministers 2024-05-17, opened for signature Vilnius 2024-09-05; not in force (status as of 2026-09-05: one ratification) · Status: planned · Licence: Council of Europe treaty text and Explanatory Report © Council of Europe — quoted under facts-and-quotation, here via the EU Official Journal (facts-and-quotation)

Summary

The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225) is the first legally binding international treaty on AI. It was adopted by the Committee of Ministers on 17 May 2024 and opened for signature in Vilnius on 5 September 2024 — to the 46 Council of Europe member states, the European Union, and the non-member states that took part in drafting it (Argentina, Australia, Canada, Costa Rica, the Holy See, Israel, Japan, Mexico, Peru, the United States and Uruguay). It is a framework convention: it binds states, not companies, and obliges each Party to "adopt or maintain" legislative, administrative or other measures so that activities across the AI lifecycle are consistent with human rights, democracy and the rule of law (Art. 1). Its scope is activities by public authorities and private actors acting on their behalf; for other private actors each Party must declare how it will address the risks (Art. 3). National security and national defence are carved out (Art. 3(2), (4)). Chapter III sets seven lifecycle principles (dignity and autonomy, transparency and oversight, accountability, equality and non-discrimination, privacy, reliability, safe innovation); Chapter IV requires remedies and procedural safeguards; Chapter V a graduated, documented risk and impact management framework including the assessment of bans or moratoria (Art. 16); Chapter VII a Conference of the Parties, reporting and independent oversight mechanisms (Art. 26). The Convention is not in force: Art. 30(3) requires five ratifications including three Council of Europe member states, and as of 5 September 2026 the treaty chart shows 21 signatures and a single ratification — the European Union, deposited on 15 May 2026 (Council Decision (EU) 2026/1080). The EU implements it exclusively through the EU AI Act; Switzerland has decided to ratify and implement it mainly through sector laws (Switzerland page); the United Kingdom signed on the opening day and has not ratified.

In plain language

Our explanation, not the official text

Plain-language summary in our own words — not the normative text. Treaty provisions are quoted with attribution. This is general information, not legal advice.

Think of CETS 225 as a promise between governments, not a rulebook for your AI system. A country that ratifies it promises to make sure — through its own laws — that AI used by the state (and, depending on its declaration, by companies) respects human rights, does not undermine elections and courts, is transparent and overseen, can be challenged by the people it affects, and is risk-assessed throughout its life. It does not tell a company what to log or which tests to run; that comes from the national law each Party writes to honour the promise. For the EU that law is the AI Act (the EU said so in its ratification decision). For Switzerland it will be a set of sector amendments plus a data-protection backbone, with a draft due at the end of 2026. For the UK there is a signature but, so far, no ratification and no implementing act. Two things matter for anyone citing it: it is not in force yet, so nobody is bound today, and even once it is, you will be audited against the implementing law, not against the Convention itself. What the Convention does give an auditor is a stable checklist of expectations that three of the jurisdictions tracked here have signed up to — useful as the direction of travel, and as the vocabulary regulators will share.

Key terms

  • Framework convention — a treaty that sets objectives and principles and leaves the choice of measures to each Party ("adopt or maintain … measures", Art. 1(2)); it binds states, and reaches companies only through the domestic law that implements it.
  • Party — a state or organisation that has ratified (or acceded to) the Convention. A signatory has only expressed an intention to become a Party; signature creates no obligations under the Convention.
  • Activities within the lifecycle of AI systems — the Convention's unit of scope: the Explanatory Report reads it as the whole chain from design and development through use to decommissioning, not the "AI system" as a product. Art. 2 defines the AI system itself, in terms closely aligned with the OECD definition and with the EU AI Act's Art. 3(1).
  • Art. 3(1)(b) declaration — the statement each Party must make on how it will address AI risks from private actors: by applying Chapters II–VI to them, or by "other appropriate measures". The EU's declaration points to the AI Act.
  • Conference of the Parties — the follow-up body (Art. 23) that will interpret the Convention, receive Party reports (Art. 24) and consider amendments once the treaty is in force.
  • Entry into force — first day of the month after three months have passed since five signatories, including at least three Council of Europe member states, have ratified (Art. 30(3)). The EU counts as a signatory but not as a member state.

In depth: what the Convention obliges, and what it leaves open

Object and scope (Chapter I). Art. 1 states the purpose — AI lifecycle activities "fully consistent with human rights, democracy and the rule of law" — and the method: measures "graduated and differentiated" by the severity and probability of adverse impacts. Art. 2 defines an AI system in terms closely aligned with the EU AI Act's definition. Art. 3 draws the line that matters most for scope: the Convention applies to activities of public authorities and of private actors acting on their behalf (3(1)(a)); for all other private actors a Party must "address risks and impacts" and declare how (3(1)(b)). Activities for national security are exempt if conducted consistently with international law (3(2)); pre-market research and development is outside scope unless testing can interfere with rights (3(3)); national defence is outside scope entirely (3(4)).

General obligations and principles (Chapters II–III). Art. 4 (human rights) and Art. 5 (integrity of democratic processes, judicial independence, access to justice, fair access to public debate) are the two general obligations. Chapter III then lists the principles each Party must give effect to across the lifecycle: human dignity and individual autonomy (Art. 7), transparency and oversight, expressly including identification of AI-generated content (Art. 8), accountability and responsibility (Art. 9), equality and non-discrimination, including gender equality (Art. 10), privacy and personal-data protection (Art. 11), reliability (Art. 12), and safe innovation through controlled environments (Art. 13).

Remedies and safeguards (Chapter IV). Art. 14 requires accessible and effective remedies and, concretely, that information about AI systems that can significantly affect human rights is documented, provided to authorised bodies and, where appropriate, to affected persons — sufficient for them to contest the decision. Art. 15 adds procedural safeguards and the duty to notify people that they are interacting with an AI system rather than a human.

Risk and impact management (Chapter V). Art. 16 is the operational core: a graduated framework that considers context and intended use, severity and probability, stakeholder perspectives, applies iteratively across the lifecycle, includes monitoring and documentation of risks, impacts and the management approach, and requires testing before first use and after significant modification "where appropriate" (16(2)). Adverse impacts must be "adequately addressed" and documented (16(3)), and each Party must assess the need for a moratorium or ban on uses it considers incompatible with human rights, democracy or the rule of law (16(4)).

Implementation, follow-up, oversight (Chapters VI–VII). Non-discrimination in implementation (Art. 17), rights of persons with disabilities and children (Art. 18), public consultation (Art. 19), digital literacy (Art. 20) and a safeguard clause that nothing limits existing human-rights protection (Art. 21–22). Chapter VII establishes the Conference of the Parties (Art. 23), a reporting duty — a first report within two years of becoming a Party (Art. 24) — international cooperation (Art. 25), and effective oversight mechanisms that act "independently and impartially" with the powers, expertise and resources to do so (Art. 26).

Final clauses (Chapter VIII). Art. 30 governs signature and entry into force (see above), Art. 31 accession by other states after entry into force, Art. 33 a federal clause, and Art. 34 permits no reservations other than the federal-clause one.

What it is not. The Explanatory Report (which "does not constitute an instrument providing an authoritative interpretation") stresses that the Convention creates no new individual rights and does not prescribe a regulatory model; the flexibility is deliberate so that Parties with very different legal systems — including non-European observer states — could join. That flexibility is also the auditor's caution: two Parties can both be compliant with entirely different domestic rules.

How the three watched jurisdictions map onto it.

  • European Union — approved the Convention on 21 April 2026 (Council Decision (EU) 2026/1080) and deposited its instrument on 15 May 2026. Art. 3 of the Decision: the Convention "shall be implemented in the Union exclusively through Regulation (EU) 2024/1689 and other relevant Union acquis". Because the Union claims exclusive external competence, the EU member states do not sign individually — their blank rows on the treaty chart are by design, not an omission. The EU's Art. 3(1)(b) declaration applies Chapters II–VI to private actors through the AI Act.
  • Switzerland — signed 27 March 2025 after the Federal Council's decision of 12 February 2025 to ratify and to implement mostly through sector laws, with a consultation draft due by the end of 2026. Detail on the Switzerland page.
  • United Kingdom — signed on the opening day, 5 September 2024; no ratification and no implementing statute as of the observation date. The UK's principles-based model is on the UK AI White Paper page.

Application timeline (as it stands)

Date What Status
2024-05-17 Convention adopted by the Committee of Ministers (133rd Session) adopted
2024-09-05 Opened for signature in Vilnius; signed that day by Andorra, Georgia, Iceland, Norway, Republic of Moldova, San Marino, the United Kingdom, Israel, the United States and the European Union signatures only
2024-11-05 → 2025-03-27 Further signatures: Montenegro, Canada, Japan, Liechtenstein, Switzerland signatures
2025-05-15 → 2026-06-15 Further signatures: Ukraine, Uruguay, Bosnia and Herzegovina, Armenia, North Macedonia, Albania signatures
2026-04-21 Council Decision (EU) 2026/1080 — EU approves the Convention; implementation exclusively via the AI Act adopted
2026-05-13 Convention text and Decision published in OJ L 2026/1080–1081 published
2026-05-15 EU deposits its instrument of approval first and only ratification as of 2026-09-05
open Entry into force — five ratifications incl. three CoE member states, then the first day of the month after three months (Art. 30(3)) not in force
open Conference of the Parties adopts its rules of procedure within 12 months of entry into force (Art. 23(4)) not started

Status figures are read from the Treaty Office chart and are valid only for its "status as of" date; re-read the chart before quoting them.

Key Sections

Audit-Relevant Anchors

Auditor Checklist

Evidence-oriented checks whenever a client, a policy or a report invokes the Convention:

  • The report states the treaty chart's "status as of" date and says plainly whether the Convention is in force (as of 2026-09-05: it is not).
  • "Signed" and "ratified" are not conflated — a signatory has no obligations under the Convention yet.
  • For an EU client, Convention compliance is evidenced through the EU AI Act (Council Decision (EU) 2026/1080, Art. 3) — no separate "CETS 225 control set" is invented.
  • For a Swiss client, the Convention is cited as the direction of travel behind the sectoral approach, not as binding Swiss law (Switzerland page).
  • For a UK client, the signature of 2024-09-05 is noted together with the absence of ratification and implementing legislation.
  • If the client is a public authority or acts on behalf of one, Art. 3(1)(a) scope is flagged — this is where the Convention will bite first once in force.
  • Risk and impact management evidence (NIST AI RMF, ISO/IEC 23894 records) is mapped to the Art. 16(2) elements: context, severity/probability, stakeholders, iteration, monitoring, documentation, pre-release and post-change testing.
  • Contestability: affected persons can obtain documented information about a rights-affecting AI decision and challenge it (Art. 14(2)); people are told when they interact with an AI system (Art. 15(2)).
  • The Party's Art. 3(1)(b) declaration has been read before assuming the Convention reaches private-sector activity.

Cross-Framework Mapping

Indicative cross-references, not authoritative equivalences — confirm against the source texts before relying on them.

CETS 225 EU AI Act NIST AI RMF ISO/IEC 42001 ISO/IEC 23894
Art. 2 (definition of AI system) Art. 3(1) AI system definition (AI 100-1) Cl. 3 terms Cl. 3 terms
Art. 8 (transparency and oversight, AI-generated content) Art. 13, Art. 50 GOVERN 1.x, MAP 1.x Cl. 7.4, Annex A (transparency) Cl. 6.4 (communication)
Art. 10 (equality and non-discrimination) Art. 10 (data governance, bias) MEASURE 2.11 Annex A (fairness) Annex B (bias as risk source)
Art. 14–15 (remedies, contestability, notification) Art. 26 (deployer duties), Art. 86 (right to explanation) MANAGE 4.x Annex A (human oversight, impact on individuals) Cl. 6.5 (risk treatment)
Art. 16 (risk and impact management, moratoria) Art. 9 (risk management), Art. 27 (FRIA), Art. 5 (prohibitions) MAP, MEASURE, MANAGE Cl. 6.1.2–6.1.4 (risk and impact assessment) Cl. 6 (whole process)
Art. 24 (Party reporting) Art. 112 (Commission evaluation and review) Cl. 9 (performance evaluation) Cl. 6.6 (monitoring and review)
Art. 26 (independent oversight mechanisms) Art. 70 (national competent authorities) GOVERN Cl. 5 (leadership)

Recent Changes (rolling, last 5)

Date Severity What changed
2026-09-05 baseline Initial baseline: Convention text (OJ L 2026/1081), Explanatory Report, Council Decision (EU) 2026/1080, treaty chart as of 2026-09-05 (21 signatures, 1 ratification, not in force), EU/Swiss/UK implementation paths captured.

Sources