The first binding AI treaty: the Council of Europe Framework Convention
Lesson 3 of 4 in The United Nations and the Treaty Track: Global Digital Compact and the CoE Convention.
Everything in this domain so far has been voluntary. The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225) is the exception: the world’s first binding international treaty on AI. Do not confuse the Council of Europe with the EU — it is the older, larger Strasbourg organization (46 member states, including the UK and Türkiye) that gave the world the European Convention on Human Rights.
The treaty was negotiated by the CoE’s Committee on Artificial Intelligence (CAI) between 2022 and 2024 — with a twist that defines the instrument: non-member observer states, including the United States, Canada, Japan, and Israel, sat at the negotiating table. The Committee of Ministers adopted the text on 17 May 2024, and it opened for signature in Vilnius on 5 September 2024 — hence the nickname the Vilnius Convention. Signatories now include the EU, the UK, the US, Canada, Japan, Israel, Switzerland, Ukraine, Uruguay, and a string of European states from Norway and Iceland to Georgia, Moldova, Montenegro, Andorra, San Marino, and Liechtenstein. A human-rights treaty on AI that Washington signed — that sentence alone makes the Convention historic, and the price paid for it appears below.
Read Article 1 twice, because the phrase adopt or maintain appropriate measures explains what kind of treaty this is. A framework convention does not hand individuals rights they can sue on, and it does not contain an EU-style product-regulation rulebook. It obliges states to ensure certain outcomes through their own law — each party chooses the means. What outcomes? The Convention’s principles track a familiar canon: human dignity and individual autonomy; transparency and oversight; accountability and responsibility; equality and non-discrimination; privacy and personal-data protection; reliability; and safe innovation — the last one operationalized through a nod to regulatory sandboxes. Parties must also provide remedies for people harmed by AI systems, procedural safeguards including notice that one is interacting with an AI, and — the operational heart — a framework for risk and impact assessment across the AI lifecycle, graduated to severity, with the option to ban uses incompatible with human rights.
To make that assessment duty usable, the CAI developed HUDERIA — the Human Rights, Democracy and Rule of Law Impact Assessment methodology, adopted in late 2024. It is non-binding guidance, structured around context-based risk analysis, stakeholder engagement, impact assessment, and a mitigation plan. You have seen this move before: UNESCO ships the EIA with its Recommendation; the CoE ships HUDERIA with its treaty. Instruments that arrive with tooling get implemented; instruments that arrive alone get framed.
Carve-out 1: national security
Activities related to the protection of national security interests are exempt (subject to a requirement that they still respect international law and democratic institutions). Critics note that many of the most rights-threatening AI deployments — mass surveillance, intelligence profiling — live exactly there. The exemption was the price of keeping security-focused states at the table.
Carve-out 2: the private-sector flexibility clause
The Convention applies squarely to public authorities and private actors acting on their behalf. For everyone else — the private sector at large — Article 3 lets each party choose: apply the Convention’s principles directly, or address private-sector AI through "other appropriate measures". This declaration mechanism was insisted on by the United States, whose federal posture could not promise binding private-sector regulation. Civil-society groups called it the treaty’s biggest hole: the states most reluctant to regulate companies may simply declare their existing law sufficient.
Carve-out 3: research, development, and defence
AI activities in research and development (before systems are made available) sit largely outside scope, as do national defence matters — the CoE’s statute has never covered defence. Combined with the security exemption, the treaty’s reach concentrates on civilian, deployed, mostly public-sector AI.
The deeper criticism: does it add anything?
The Convention creates no new court, no fines, no individual complaint mechanism — oversight runs through a Conference of the Parties and periodic reporting. Sceptics argue it restates obligations states already have under existing human-rights law, with softer edges. Defenders answer: it is the first binding instrument that names AI, it pulls non-European democracies into a common legal frame, it hardens the risk-assessment habit into treaty law — and framework conventions are floors that protocols later build on, exactly how European human-rights and data-protection law grew.
Key terms: framework convention, council of europe, HUDERIA, national security exemption
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.