The Council of Europe Framework Convention on AI, Human Rights, Democracy and the Rule of Law
The one-paragraph answer
CETS 225, the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, is the first legally binding international AI treaty. It was adopted by the Committee of Ministers on May 17, 2024, opened for signature in Vilnius on September 5, 2024, and entered into force on November 1, 2025 after ratification by the United Kingdom, France, Norway, and the required threshold of Council of Europe member states. The European Union ratified on May 15, 2026, and will implement the Convention through the EU AI Act. The United States signed on September 5, 2024, but the Senate has not ratified, so the treaty is not binding in US law. The Convention is not self-executing: each party has to enact or adapt national legislation to meet its standards, and "how much of it reaches the private sector" depends on each signatory's implementation. That produces a specific trap this page is written around: an organisation that operates across signatories will find its obligations look like the EU AI Act in the EU, a lighter co-regulation regime in the UK, and essentially nothing enforceable in the US, all under the same treaty banner. The Convention is genuinely important as a floor-setting instrument, and it is genuinely uneven in practice.
A multinational deploys an AI hiring platform. Its EU obligations are set by the EU AI Act. Its UK obligations turn on how the UK's forthcoming AI legislation implements CETS 225, which is not yet clear. Its US obligations under the Convention are zero, because the Senate has not ratified. Its Canadian obligations depend on how Canada, which signed on February 11, 2025, chooses to implement. The same treaty produces four different compliance postures. That is not a defect in the Convention; it is a feature of framework conventions, which set floors and leave implementation to signatories. But it is a real operational challenge for organisations that have been told CETS 225 is "the global AI treaty" and expected it to homogenise their obligations.
The Convention establishes obligations across the lifecycle of AI systems: transparency, accountability, non-discrimination, human oversight, data protection, and remedies for people harmed by AI systems. Its 26 articles across eight chapters cover general provisions, general obligations, principles related to activities within the lifecycle of AI systems, remedies, procedural safeguards and rights, assessment and mitigation of risks and adverse impacts, implementation, follow-up and cooperation, and final clauses.
The mechanics that matter operationally are:
Adopted: May 17, 2024, by the Council of Europe Committee of Ministers.
Opened for signature: September 5, 2024, in Vilnius.
Entered into force: November 1, 2025, three months after the fifth ratification.
Ratified (as of mid-2026): United Kingdom, France, Norway, the European Union (May 15, 2026), and other Council of Europe member states meeting the entry-into-force threshold.
Signed (not yet ratified) includes: Andorra, Georgia, Iceland, Republic of Moldova, San Marino, Israel, United States, Canada (signed February 11, 2025), Liechtenstein, Switzerland.
Negotiating observers who may sign later: Argentina, Australia, Costa Rica, Holy See, Japan, Mexico, Peru, Uruguay.
The Convention is open to non-member states, which is the source of its potential to become a global instrument. It is the first-ever legally binding international AI treaty, and the ratification threshold has now been crossed.
The United States signed the Convention on September 5, 2024, in Vilnius. Under US constitutional practice, a signed treaty is not binding until the Senate ratifies with a two-thirds vote. The Senate has not done so, and there is no clear timeline. The Center for AI and Digital Policy and other civil-society organisations continue to urge ratification, but the treaty's status inside the US legal system today is: signed, not in force. US companies operating domestically are not subject to CETS 225 obligations as a matter of US law. They are subject to CETS 225 obligations to the extent they operate in signatory countries that have ratified and implemented the Convention through domestic legislation.
The Convention itself does not directly bind private companies. It binds signatory states to enact or adapt national legislation that reaches AI activities in their jurisdiction. How far that legislation reaches into the private sector is a design choice each signatory makes. The European Union's answer is the EU AI Act, which reaches deep into private-sector deployment and imposes high-risk obligations directly on companies. The United Kingdom's approach has been a sectoral "principles-based" model with sector regulators enforcing, which reaches the private sector more lightly. Canada's proposed AIDA (part of Bill C-27) died on the Order Paper when Parliament was prorogued in January 2025 and has not been reintroduced; Canada signed the Convention in February 2025 but currently has no dedicated AI statute to implement it, leaving PIPEDA, Quebec's Law 25, and sector guidance as the operative layer.
The explanatory report to the Convention says the implementation may include "co-regulation" and "self-regulation" mechanisms backed by state oversight, and the goal is a "culture of compliance" with human-rights-by-design as the operating principle. That is a real objective, and it is deliberately less prescriptive than the EU AI Act. It also means that saying "we comply with CETS 225" without saying which signatory's implementation is not saying much.
The Framework Convention on Artificial Intelligence is designed as a technology-neutral instrument that establishes fundamental principles for AI governance, including transparency, accountability, non-discrimination, and human rights protection through eight chapters and 26 articles, and is intended to complement rather than replace regional frameworks such as the EU AI Act.
That complementarity is the piece that determines what the Convention actually means in operational terms: the EU AI Act supplies the enforceable rules for EU operations; the Convention supplies the human-rights floor that constrains how those rules can be interpreted.
Regulation of automated decision-making varies significantly across jurisdictions: consent to solely automated profiling entailing legal or significant consequences is required in the European Union, while the United States and China generally allow only subsequent refusal to apply decisions, and the resulting fragmentation creates real compliance complexity for multinational operators.
No. The US signed on September 5, 2024, but the Senate has not ratified. The treaty is not binding in US law until ratification. US companies operating in the US are not subject to CETS 225 obligations as a matter of US law. They are subject to obligations in ratifying signatory countries where they operate.
No. The Convention and the AI Act are complementary. The EU ratified on May 15, 2026, and will implement the Convention primarily through the AI Act. The Act provides the enforceable rules; the Convention provides the human-rights framework the Act is expected to be consistent with.
No. It binds signatory states to enact legislation that reaches AI activities in their jurisdiction. Private-sector reach depends on how each signatory implements the Convention through national law.
The Convention is a useful floor for multinational operators building a single AI governance program across jurisdictions with heterogeneous rules. Its Chapter III principles align cleanly with the AI Business Enablement Audit's operating assumptions. See Volume I.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including CETS 225, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →