The Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law is the first international legally binding treaty devoted to artificial intelligence. Opened for signature in Vilnius on 5 September 2024, it was ratified by the European Union on 15 May 2026. This overview sets out its origin, scope, principles and the state of accessions.
Origin and nature of the treaty
Preparatory work dates back to 2019, when the Council of Europe set up an ad hoc committee on artificial intelligence (CAHAI) tasked with assessing the feasibility of a legal instrument. In 2022 the mandate passed to the Committee on Artificial Intelligence (CAI), which drafted and negotiated the text. The drafting involved the 46 member states of the Council of Europe, the observer states (Canada, Japan, Mexico, the Holy See and the United States), the European Union and several non-member states (Argentina, Australia, Costa Rica, Israel, Peru and Uruguay), together with 68 representatives of civil society, academia and industry. The Convention is deliberately a “framework” instrument and is technology-neutral: it does not regulate technology as such, but sets common principles designed to last over time and to complement existing human rights standards, filling any legal gaps.
Scope and definition
Article 2 defines an artificial intelligence system as a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that may influence physical or virtual environments. Article 3 delimits the scope: each party applies the Convention to activities carried out by public authorities and by private actors acting on their behalf; for the activities of private actors, parties choose whether to apply the treaty’s principles directly or to take other appropriate measures, stating this in a declaration to the Secretary General of the Council of Europe. National defence matters fall outside the scope, while national security activities are excluded provided they respect international law and democratic processes. Research and development is excluded, except where testing may interfere with human rights, democracy or the rule of law.
Principles and obligations
The body of the Convention (Chapters II to VI) lists the general obligations and the principles that parties must implement. The obligations include the protection of human rights (Article 4) and the safeguarding of the integrity of democratic processes and the rule of law (Article 5). The common principles cover human dignity and individual autonomy, transparency and oversight, accountability and responsibility, equality and non-discrimination (including gender equality), privacy and personal data protection, reliability and safe innovation. On safeguards, the Convention provides for accessible and effective remedies (Article 14), procedural guarantees and the right to be notified when interacting with an artificial intelligence system rather than a person (Article 15). The chapter on risk assessment (Article 16) requires iterative measures to identify, assess, prevent and mitigate impacts, with documentation and monitoring, and provides that each party assess the need for moratoria or bans on uses deemed incompatible with human rights, democracy or the rule of law.
Follow-up mechanism and relationship with Union law
Implementation is entrusted to a Conference of the Parties (Article 23), composed of representatives of the parties, which adopts its own rules of procedure within twelve months of entry into force and issues recommendations on the interpretation and application of the treaty. Within the first two years of accession, and periodically thereafter, each party submits a report on the measures taken (Article 24). The Convention also requires independent and impartial oversight mechanisms (Article 26) and promotes international cooperation (Article 25). For member states of the European Union, Article 27 specifies that in their mutual relations the Union rules governing the matters covered by the treaty apply: within the Union legal order, the Convention’s objectives therefore intertwine with Regulation (EU) 2024/1689 (the Artificial Intelligence Act). In the period preceding the establishment of the Conference of the Parties, the Council of Europe has entrusted the custodian function of the treaty to a new steering committee dedicated to new and emerging digital technologies (CDNET), operational since 1 January 2026 and tasked, among other things, with promoting signatures and ratifications.
Signatures, ratifications and entry into force
The Convention has been signed by numerous member states of the Council of Europe and by five non-member states (Canada, Israel, Japan, the United States and Uruguay), as well as by the European Union. The European Union deposited its instrument of ratification on 15 May 2026, on the occasion of the 135th session of the Committee of Ministers held in Chișinău (Republic of Moldova), becoming the first Party to have ratified the treaty. Article 30 makes entry into force conditional on the consent of five signatories, at least three of which are member states of the Council of Europe: that threshold has not yet been reached, so the Convention is not yet in force. The text has been published, in the Union languages, in the Official Journal of the European Union (Series L, 2026/1081, of 13 May 2026).
Outlook
The Convention’s entry into force depends on reaching the threshold set by Article 30: five ratifications, at least three of them by member states of the Council of Europe. After entry into force, the Conference of the Parties will have to adopt its rules of procedure within twelve months and define the format of the periodic reports provided for in Article 24. Until then, the CDNET committee acts as custodian and follows signatures and ratifications. What remains to be specified, at the implementation stage, are the declarations by which each party will indicate how it intends to regulate the activities of private actors and the coordination with existing sectoral instruments, including, for the European Union, Regulation (EU) 2024/1689.
In dialogue with the 2030 Agenda
- Goal 16 (Peace, Justice and Strong Institutions). The treaty anchors artificial intelligence activities to human rights, democracy and the rule of law, with remedies, procedural safeguards and independent oversight mechanisms.
- Goal 9 (Industry, Innovation and Infrastructure). The Convention promotes responsible and safe innovation, providing for controlled testing environments without regulating technology as such.
- Goal 10 (Reduced Inequalities). The principles of equality and non-discrimination aim to prevent artificial intelligence systems from creating or aggravating disparities, including gender-based ones.
- Goal 17 (Partnerships for the Goals). As the first treaty in the field also open to non-member states, it rests on international cooperation and dialogue with a plurality of stakeholders.
Sources
- Council of Europe, Framework Convention on Artificial Intelligence (CETS No. 225)
- Council of Europe, the European Union ratifies the Framework Convention on Artificial Intelligence (15 May 2026)
- Council of Europe, establishment of the new CDNET committee
- Official text of the Convention, Official Journal of the European Union (Series L, 2026/1081, 13 May 2026)




