CoE AI Convention
Council of Europe Framework Convention on AI
First legally binding international AI treaty. Signed by EU, UK, US (Sep 2024), Canada, Japan (Feb 2025) and others. Requires risk/impact assessments, transparency, accountability. National security exemptions apply.
Jurisdiction
International
Enacted
May 17, 2024
Effective
Nov 1, 2025
Enforcement
TBD
Entered into force November 1, 2025
Council of EuropeWhy It Matters
First binding global AI treaty. US signature notable given federal deregulation stance—demonstrates international divergence.
Recent Developments
Adopted May 17, 2024; opened for signature Sep 5, 2024 in Vilnius. Entered into force November 1, 2025 after UK, France, Norway ratifications. European Parliament gave consent to EU accession on March 11, 2026 (resolution TA-10-2026-0071), clearing the way for the EU itself to ratify the Convention. The EP-consent vote is the key 2026 milestone in the Convention's adoption trajectory and is referenced alongside the Digital Omnibus on AI negotiations as part of the EU's broader AI governance posture.
At a Glance
Harms addressed
Who Must Comply
- Public authorities
- Private actors acting on their behalf (or through "other measures")
Obligations fall on:
Safety Provisions
- Risk and impact assessments
- Mitigation measures
- Transparency and oversight
- Accountability principles
- Rights and remedies framework
Compliance & Enforcement
Key Dates
May 17, 2024
Convention adopted by Committee of Ministers
Sep 5, 2024
Convention opened for signature
View on map
International
Focus Areas
General regulation
Cite This
APA
International. (2024). Council of Europe Framework Convention on AI.
Related Regulations
ISO 42001
First certifiable international standard for AI management systems. Uses Plan-Do-Check-Act methodology. Third-party certification available; major AI systems have achieved certification.
ISO 23894
AI risk management guidance complementing ISO 31000. Lifecycle risk management; audit/procurement language.
OECD AI Due Diligence
Non-binding OECD guidance applying the OECD's six-step responsible business conduct (RBC) due-diligence process to enterprises across the AI value chain, providing practical recommendations for identifying, preventing, mitigating, and accounting for adverse human-rights and societal impacts of AI systems.
China Minor Content Classification Measures
Establishes a four-category classification framework for online content that may harm minors' physical and mental health. Prohibits platforms from displaying classified harmful content in prominent positions (homepage, pop-ups, trending, recommendations). Requires preventive measures against content risks from algorithmic recommendations and generative AI.
NZ Biometric Code
Sets specific legal requirements under Privacy Act for collecting and using biometric data such as facial recognition and fingerprint scans. Prohibits particularly intrusive uses including emotion prediction and inferring protected characteristics like ethnicity or sex.
TX Healthcare AI Law
Requires healthcare practitioners using AI for diagnosis to review all AI-generated records and disclose AI use to patients. Mandates EHR data localization (Texas patient data must be physically stored in US). Applies to covered entities and third-party vendors.
Last updated May 10, 2026. Verify against primary sources before relying on this information.