Most AI governance analysis focuses on the EU AI Act, national legislation, or sector-specific regulatory guidance. CETS 225 sits above all of these as the first instrument to create legally binding international standards for AI at the treaty level. It does not replace the EU AI Act or national laws. It creates a baseline that signatory states must achieve and maintain, and it requires states that have ratified it to ensure both their public sector and private sector AI activities meet the Convention's human rights, democracy, and rule of law standards. For operators active across multiple signatory states, understanding CETS 225 is necessary to understand the minimum floor that national implementing measures must reach.
Key takeaways
- CETS 225 is the first legally binding multilateral treaty on AI. It covers AI systems used in the public and private sectors in the jurisdictions of all signatory states, not only EU member states.
- The Convention imposes obligations on Parties (states) to adopt measures implementing its principles. Operators face those obligations through national implementing legislation, not through the Convention text directly.
- The obligations the Convention pushes into national law include risk and impact assessment across the AI lifecycle, transparency to affected persons, a route to complain and to have a decision reviewed, and non-discrimination safeguards. They reach a broader scope of AI activity than the EU AI Act high-risk category. Specific article numbers previously given on this page have been withdrawn; take them from the Convention text at coe.int.
- CETS 225 is consistent with the EU AI Act for in-scope systems but may require additional compliance steps in non-EU signatory states that implement stricter requirements than the EU minimum.
- The Convention was open to signature by non-member observer states as well as Council of Europe members. The specific list of signatories previously given here could not be read at the Council of Europe treaty office on 17 August 2026 and has been withdrawn. Operators should take the current list from the treaty office directly.
The origins and structure of CETS 225
The Council of Europe began formal work on a binding AI convention in 2019 through the Ad Hoc Committee on Artificial Intelligence (CAHAI), which was subsequently replaced by the Committee on Artificial Intelligence (CAI). The drafting process involved Council of Europe member states alongside non-member observer states. The resulting text was adopted by the Committee of Ministers on 17 May 2024 and opened for signature in Vilnius, Lithuania, on 5 September 2024.
Sourcing note, 17 August 2026: this guide previously mapped the Convention's eight chapters to specific subject matter and attributed specific obligations to Articles 3, 14, 15 and 16. The Convention text could not be read at coe.int from this session on that date, and several of those attributions did not survive internal review. The chapter map and the article attributions have been reduced to what does not depend on the numbering. Read the Convention text at coe.int before citing any article number, and do not rely on the numbering used in an earlier version of this page.
The Convention's scope is defined at Article 3. It applies to activities within the lifecycle of AI systems that affect human rights, democracy, and the rule of law. A key structural choice is that the Convention applies its obligations to Parties at the state level, requiring those Parties to implement equivalent measures in their jurisdictions through domestic law. This is in contrast to the EU AI Act's direct applicability as Union law.
Core obligations: what Parties must implement
Chapter II of the Convention requires Parties to adopt measures addressing six core areas. The measures must be implemented through domestic legal instruments, which may include new legislation, regulatory guidance, sectoral frameworks, or administrative measures. No specific implementation form is required.
The first core area is assessing the potential impacts of AI on human rights, democracy, and the rule of law throughout the system's lifecycle. This is an impact assessment obligation that applies before deployment and on an ongoing basis. The Convention does not prescribe a specific impact assessment methodology, leaving Parties to determine the appropriate form for their legal tradition and administrative capacity.
The second core area is measures to prevent, detect, and address adverse impacts on fundamental rights, including the right to privacy, freedom of expression, freedom of assembly, the right to a fair trial, and the right to non-discrimination. This is broader in scope than the GDPR's data protection framework and addresses AI effects that do not involve personal data processing.
The third core area is measures ensuring that AI use respects the integrity of democratic institutions, processes, and deliberation. The election influence subcategory in this area is of direct relevance to operators providing AI tools used in political advertising, voter contact, or public information contexts.
The fourth core area is ensuring that AI does not undermine the rule of law, access to justice, or the accountability of public bodies. This targets AI used in judicial and administrative settings and reinforces the obligations already present in the EU AI Act's Annex III Category 8 for justice administration systems.
The fifth core area is transparency measures ensuring that persons affected by AI decisions receive meaningful information about the AI's role and about their right to seek review. This is a transparency obligation that applies broadly to AI affecting individuals, not only to high-risk AI in the EU AI Act sense.
The sixth core area is establishing or designating independent oversight mechanisms to monitor compliance with the Convention's implementing measures. Parties must ensure that these mechanisms have adequate powers and resources, and are operationally independent from the entities they oversee.
Private sector application: the design choice at the heart of the Convention
The Convention's treatment of private sector activities is its most consequential design choice, and it is the reason this treaty does not translate directly into duties on a company. The scope provision lets a Party address the public sector directly and deal with private sector AI activity in a manner conforming with the object and purpose of the Convention, which in practice means through instruments the Party already has. Sourcing note, 17 August 2026: an earlier version of this guide described this as Article 3(1) and Article 3(2) and characterised it as an opt-in with an equivalent safeguards test. The Convention text could not be read at coe.int from this session on that date, so the subparagraph references and the "equivalent safeguards" formulation have been withdrawn. Read the scope article at coe.int before relying on either.
In practice this produces two patterns among Parties. Some apply the Convention across both public and private sectors. Others apply it to the public sector and rely on existing legislation, such as the EU AI Act or the GDPR, for private sector activity. Which pattern a given Party has chosen is a question for that Party's own instrument of ratification and implementing law, not something an operator can infer from the treaty text.
The European Union and its member states are expected to cover private sector activity through the EU AI Act for in-scope AI systems. The gap worth noticing is that the EU AI Act's high-risk category is narrower than the range of AI activity that can affect the rights the Convention protects. An AI system outside Annex III and Annex I carries few EU AI Act obligations but can still bear on privacy, non-discrimination or access to justice. Whether the EU AI Act alone is sufficient for those systems is an open question rather than a settled one.
For operators in non-EU signatory states, the implementation picture is more varied. The United States signed as a non-member observer state but has not ratified CETS 225. The US federal regulatory framework for AI does not yet have a comprehensive statute equivalent to the EU AI Act. Executive Order 14110 of October 2023 was revoked on 20 January 2025 by Executive Order 14148, so it is not the current federal baseline; an earlier version of this guide presented it and OMB Memorandum M-24-10 as live. State-level legislation addresses some of the Convention's themes: Colorado's SB 24-205, codified at C.R.S. section 6-1-1701 et seq., was extended to 30 June 2026 by SB25B-004 and then rewritten by SB26-189, signed 14 May 2026, into a disclosure model with developer and deployer duties from 1 January 2027, verified at leg.colorado.gov on 17 August 2026. None of this constitutes implementation of the Convention across US territory.
The relationship between CETS 225 and other international frameworks
CETS 225 sits within a broader landscape of international AI governance initiatives. The OECD AI Principles, adopted in 2019 and revised in 2024, provide a non-binding framework covering trustworthy AI characteristics, transparency, accountability, and human-centred values. The G7 Hiroshima AI Process, concluded in 2023 with an International Code of Conduct for Advanced AI Systems, added governance commitments for advanced AI development. The United Nations has adopted a resolution on AI and the General Assembly has established an advisory body on AI governance. ISO/IEC 42001:2023 provides a voluntary management system standard applicable globally.
CETS 225 is the only instrument in this landscape that is legally binding as a matter of international treaty law once it enters into force for a Party. The OECD Principles, G7 Code of Conduct, and UN resolutions are all non-binding. ISO/IEC 42001 is a voluntary standard. CETS 225 creates binding obligations at the state level in a way none of these other instruments does.
The extraterritorial reach of the EU AI Act already means that many operators outside the EU face EU-derived compliance obligations through the Act's market access provisions. CETS 225 adds a second international dimension: operators in non-EU signatory states must also monitor domestic implementation of the Convention in those states as ratification processes advance and implementing legislation is adopted.
Transparency, appeal mechanisms, and the individual rights dimension
Sourcing note, 17 August 2026. An earlier version of this section attributed specific content to Articles 14, 15 and 16 of the Convention: an explanation right at Article 14, a remedies and review right at Article 15, and AI in judicial and administrative proceedings at Article 16. Those attributions could not be checked against the Convention text, because coe.int could not be read from this session on that date, and internal review raised doubt about at least two of the three. They have been withdrawn rather than restated. The article numbers should be taken from the Convention text at coe.int and not from this page.
What survives, and does not depend on the numbering, is the shape of the obligation. The Convention requires Parties to ensure that a person affected by an AI-influenced decision can find out that AI was involved, can obtain enough information to understand its role, and has a route to complain and to have the decision looked at. Those are duties on the state, discharged through domestic law. They reach an operator only through whatever that domestic law says.
These procedural safeguards are operational requirements for any organisation deploying AI in contexts where it affects individual rights. Compliance teams should confirm that their AI deployment policies include documentation of which systems affect individuals significantly, how those individuals are informed, and what appeal pathway is available. The Article 26 analysis on agentliability.eu covers the EU AI Act dimension of the same requirements in detail.
What global operators should do now
The practical steps for global operators are grounded in monitoring and documentation rather than immediate statutory compliance. The Convention's obligations apply to Parties at the state level, and private sector obligations flow through national implementing legislation. Until a given state has ratified and implemented CETS 225 in its domestic law, the Convention does not directly create enforceable private sector obligations in that state.
However, four preparatory steps are well-founded. First, identify which of your AI deployments fall in jurisdictions that have ratified CETS 225 and have adopted implementing legislation. For EU member states, this means reviewing whether the combination of the EU AI Act, GDPR, and any national AI legislation satisfies the Convention's requirements in the specific sectors you operate in. For UK and US deployments, monitor domestic implementation as ratification processes advance.
Second, conduct an AI impact register that maps each significant AI deployment against the categories of fundamental rights the Convention is designed to protect: privacy, non-discrimination, freedom of expression, access to justice, and democratic participation. This exercise will identify deployments that may be in scope for CETS 225-derived obligations even if they fall outside the EU AI Act's Annex III categories.
Third, review your transparency practices for AI decisions affecting individuals. The Convention's procedural safeguards reach broadly across AI activity, not only high-risk systems. Any deployment that makes or materially influences a significant decision about an individual should come with a user-facing explanation of the AI's role and an appeal or review pathway.
Fourth, engage with the certification and documentation infrastructure that makes compliance demonstrable. A structured AI governance framework, such as ISO/IEC 42001 or the Agent Certified assessment available at agentcertified.eu, produces documentation that is directly usable as evidence of CETS 225-aligned governance in any jurisdiction where the Convention's implementing measures require such evidence.
Frequently asked questions
What is the Council of Europe Framework Convention on AI?
CETS 225 is the first legally binding multilateral treaty on AI governance. Adopted in May 2024 and opened for signature in September 2024, it requires signatory states to implement measures ensuring that AI systems in their jurisdictions respect human rights, democracy, and the rule of law. Private sector obligations flow through national implementing legislation in each signatory state.
How does CETS 225 interact with the EU AI Act?
EU member states that have signed CETS 225 are expected to satisfy the Convention's private sector equivalent safeguard requirement through the EU AI Act for in-scope systems. However, the EU AI Act covers a narrower scope than the Convention. AI systems that are not high-risk under the EU AI Act may still fall within CETS 225-derived national implementing measures in specific jurisdictions. Operators should review national implementation laws in each state where they operate.
Does CETS 225 apply to US and UK operators?
The Convention creates binding obligations only upon ratification. Whether a given state has signed or ratified could not be read at the Council of Europe treaty office on 17 August 2026 and the specific statements previously made here have been withdrawn; check the treaty office list directly. However, both signatories indicated an intent to align domestic regulatory development with the Convention's principles. US operators should monitor federal and state legislative developments; UK operators should monitor the UK's AI regulatory White Paper implementation track as it evolves.
References
- Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS 225), adopted 17 May 2024, opened for signature 5 September 2024, Vilnius. The treaty text, chapter structure, article numbering, and the signature and ratification list could not be read at coe.int from this session on 17 August 2026. Every article-level attribution previously made on this page has been withdrawn. Take them from coe.int.
- Regulation (EU) 2024/1689 on Artificial Intelligence (EU AI Act), OJ L 1689, 12 July 2024.
- OECD Recommendation on Artificial Intelligence (OECD/LEGAL/0449), revised 2024.
- Executive Order 14110 on Safe, Secure, and Trustworthy Artificial Intelligence, 30 October 2023. Revoked on 20 January 2025 by Executive Order 14148; it is not the current US federal baseline.
- OMB Memorandum M-24-10, Advancing Governance, Innovation, and Risk Management for Federal AI, March 2024. Its current status should be confirmed at whitehouse.gov before it is relied on.
- Colorado Artificial Intelligence Act, SB 24-205, codified at C.R.S. section 6-1-1701 et seq. Extended to 30 June 2026 by SB25B-004 (signed 28 August 2025), then rewritten by SB26-189 (signed 14 May 2026) into a disclosure model with developer and deployer duties from 1 January 2027. Verified at leg.colorado.gov, 17 August 2026.
- ISO/IEC 42001:2023, Information Technology: Artificial Intelligence: Management System.