Government & Policy | 4 min read

Council of Europe Adopts World's First Legally Binding International AI Treaty

The world's first legally binding international AI treaty took effect September 16, creating binding obligations for public and private AI deployments across any country that ratifies it.

Hector Herrera
Hector Herrera
A government building interior related to Council of Europe Adopts World's First Legally Binding Inter from an unusual angle or perspective
Why this matters The world's first legally binding international AI treaty took effect September 16, creating binding obligations for public and private AI deployments across any country that ratifies it.

Council of Europe Adopts World's First Legally Binding International AI Treaty

By Hector Herrera | September 28, 2026 | Government

The world's first legally binding international AI treaty entered force on September 16, when the Council of Europe formally adopted the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law. Unlike the EU AI Act — which is regional legislation enforceable only within the European Union — this treaty creates binding legal obligations for any country that ratifies it, including non-EU nations such as the United States, Canada, Japan, and the United Kingdom.

Why This Is Different From Everything Before It

Most AI governance to date has taken one of two forms: voluntary principles (the OECD AI Principles, the G7 Hiroshima Code of Conduct) or regional legislation (the EU AI Act, the Colorado AI Act). Voluntary frameworks have no enforcement mechanism. Regional laws bind only the jurisdiction that passed them.

According to AI Governance Weekly, the Council of Europe Framework Convention is categorically different. It is an international treaty — meaning once a country ratifies it, the treaty's requirements become legally binding obligations under international law in that country, not aspirational targets. Signatories must align their domestic AI governance with the convention's standards or face legal accountability at the international level.

The convention applies to both public authorities and private actors operating within signatory states, spanning the full AI lifecycle from development through deployment and decommissioning. That private-sector scope is significant: prior international AI instruments largely focused on government use of AI, leaving commercial deployment in a voluntary framework vacuum.

The Council of Europe Is Not the EU

The Council of Europe is frequently confused with the European Union but is a distinct body. It has 46 member states — more than the EU's 27 — and includes non-EU countries such as the United Kingdom, Turkey, Iceland, Switzerland, and Norway. Its most prominent prior work is the European Convention on Human Rights and the creation of the European Court of Human Rights.

Importantly, the US, Canada, Japan, and Israel were among the non-European nations that participated in drafting negotiations. Their participation signals intent to ratify, though ratification processes vary by country and can take years. The US, for instance, would require Senate approval of any treaty before it takes domestic legal effect.

What the Convention Requires

The treaty establishes requirements across the AI lifecycle:

  • Risk identification and mitigation before deployment of AI systems with significant human rights implications
  • Transparency obligations — those affected by AI decisions must be able to obtain meaningful information about how those decisions were made
  • Human oversight requirements — systems that can affect rights must maintain mechanisms for human review and redress
  • Non-discrimination standards — AI systems must not be used in ways that unlawfully discriminate on protected grounds
  • Accountability — member states must designate competent authorities responsible for overseeing compliance

The convention explicitly does not apply to national security and defense applications, which was a red line in negotiations for several major state participants. That carve-out limits the treaty's reach in the AI domains with the most acute human rights risk — surveillance, autonomous weapons, and signals intelligence — but it was the price of broad participation.

The US Position

The United States has not yet ratified the treaty. US participation in the drafting negotiations was conducted primarily through the State Department and the National Institute of Standards and Technology. The Biden-era AI executive order and the NIST AI Risk Management Framework aligned broadly with the convention's principles, but the Trump administration's position on ratification is not yet formally stated.

For US technology companies operating in signatory countries — which will include the UK, EU member states, and potentially Canada — the treaty creates a new compliance layer on top of existing requirements. A company that builds an AI hiring tool, for example, would need to demonstrate compliance with the convention's transparency and non-discrimination requirements in every signatory country where it deploys.

What This Means for the Industry

The framework convention is a floor, not a ceiling. Countries can and will impose stricter requirements through domestic legislation — but the convention creates a minimum baseline that no signatory government can fall below. For technology companies, that means a slowly converging international compliance standard is now in motion.

That convergence is neither fast nor guaranteed. The EU AI Act took years to pass and will take more years to fully enforce. The Council of Europe convention will move through national ratification processes on timelines that vary by country. But the direction is clear: AI governance is becoming a domain of binding international law rather than voluntary self-regulation.

For enterprises building or buying AI systems: the convention's transparency and human oversight requirements are directionally consistent with what the EU AI Act, the UK's AI Safety Institute, and US executive guidance already require. Compliance architectures that satisfy the strictest current requirements — documentation, explainability, human-in-the-loop review for high-risk decisions — will be best positioned as the treaty's standards take hold.

What to Watch

Ratification timelines are the immediate signal to track. If major non-European economies ratify within 18 months, the convention becomes a genuine anchor for global AI compliance. If ratification stalls — particularly in the US — the practical effect may be limited to European jurisdictions that were already bound by the EU AI Act. The first enforcement actions brought under the treaty will clarify how broadly the private-sector provisions are being interpreted, especially for AI systems that operate cross-border by design.

Key Takeaways

  • ✓ By Hector Herrera | September 28, 2026 | Government
  • ✓ both public authorities and private actors
  • ✓ Risk identification and mitigation
  • ✓ does not apply to national security
  • ✓ defense applications

Did this help you understand AI better?

Your feedback helps us write more useful content.

Hector Herrera

Written by

Hector Herrera

Hector Herrera is an AI systems architect and the founder of Hex AI Systems. He designs and runs AI systems in production and writes daily about how AI is reshaping business, government and everyday life. 20+ years building for the web. Houston, TX.

More from Hector →

Get tomorrow's AI briefing

Join readers who start their day with NexChron. Free, daily, no spam.

More from NexChron