The world's first legally binding international AI treaty took effect September 16, creating binding obligations for public and private AI deployments across any country that ratifies it.
By Hector Herrera | September 28, 2026 | Government
The world's first legally binding international AI treaty entered force on September 16, when the Council of Europe formally adopted the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law. Unlike the EU AI Act — which is regional legislation enforceable only within the European Union — this treaty creates binding legal obligations for any country that ratifies it, including non-EU nations such as the United States, Canada, Japan, and the United Kingdom.
Why This Is Different From Everything Before It
Most AI governance to date has taken one of two forms: voluntary principles (the OECD AI Principles, the G7 Hiroshima Code of Conduct) or regional legislation (the EU AI Act, the Colorado AI Act). Voluntary frameworks have no enforcement mechanism. Regional laws bind only the jurisdiction that passed them.
According to AI Governance Weekly, the Council of Europe Framework Convention is categorically different. It is an international treaty — meaning once a country ratifies it, the treaty's requirements become legally binding obligations under international law in that country, not aspirational targets. Signatories must align their domestic AI governance with the convention's standards or face legal accountability at the international level.
The convention applies to both public authorities and private actors operating within signatory states, spanning the full AI lifecycle from development through deployment and decommissioning. That private-sector scope is significant: prior international AI instruments largely focused on government use of AI, leaving commercial deployment in a voluntary framework vacuum.
The Council of Europe Is Not the EU
The Council of Europe is frequently confused with the European Union but is a distinct body. It has 46 member states — more than the EU's 27 — and includes non-EU countries such as the United Kingdom, Turkey, Iceland, Switzerland, and Norway. Its most prominent prior work is the European Convention on Human Rights and the creation of the European Court of Human Rights.
Get this in your inbox.
Daily AI intelligence. Free. No spam.
Importantly, the US, Canada, Japan, and Israel were among the non-European nations that participated in drafting negotiations. Their participation signals intent to ratify, though ratification processes vary by country and can take years. The US, for instance, would require Senate approval of any treaty before it takes domestic legal effect.
What the Convention Requires
The treaty establishes requirements across the AI lifecycle:
- Risk identification and mitigation before deployment of AI systems with significant human rights implications
- Transparency obligations — those affected by AI decisions must be able to obtain meaningful information about how those decisions were made
- Human oversight requirements — systems that can affect rights must maintain mechanisms for human review and redress
- Non-discrimination standards — AI systems must not be used in ways that unlawfully discriminate on protected grounds
- Accountability — member states must designate competent authorities responsible for overseeing compliance
The convention explicitly does not apply to national security and defense applications, which was a red line in negotiations for several major state participants. That carve-out limits the treaty's reach in the AI domains with the most acute human rights risk — surveillance, autonomous weapons, and signals intelligence — but it was the price of broad participation.
The US Position
The United States has not yet ratified the treaty. US participation in the drafting negotiations was conducted primarily through the State Department and the National Institute of Standards and Technology. The Biden-era AI executive order and the NIST AI Risk Management Framework aligned broadly with the convention's principles, but the Trump administration's position on ratification is not yet formally stated.
For US technology companies operating in signatory countries — which will include the UK, EU member states, and potentially Canada — the treaty creates a new compliance layer on top of existing requirements. A company that builds an AI hiring tool, for example, would need to demonstrate compliance with the convention's transparency and non-discrimination requirements in every signatory country where it deploys.
What This Means for the Industry
The framework convention is a floor, not a ceiling. Countries can and will impose stricter requirements through domestic legislation — but the convention creates a minimum baseline that no signatory government can fall below. For technology companies, that means a slowly converging international compliance standard is now in motion.
That convergence is neither fast nor guaranteed. The EU AI Act took years to pass and will take more years to fully enforce. The Council of Europe convention will move through national ratification processes on timelines that vary by country. But the direction is clear: AI governance is becoming a domain of binding international law rather than voluntary self-regulation.
For enterprises building or buying AI systems: the convention's transparency and human oversight requirements are directionally consistent with what the EU AI Act, the UK's AI Safety Institute, and US executive guidance already require. Compliance architectures that satisfy the strictest current requirements — documentation, explainability, human-in-the-loop review for high-risk decisions — will be best positioned as the treaty's standards take hold.
What to Watch
Ratification timelines are the immediate signal to track. If major non-European economies ratify within 18 months, the convention becomes a genuine anchor for global AI compliance. If ratification stalls — particularly in the US — the practical effect may be limited to European jurisdictions that were already bound by the EU AI Act. The first enforcement actions brought under the treaty will clarify how broadly the private-sector provisions are being interpreted, especially for AI systems that operate cross-border by design.
Did this help you understand AI better?
Your feedback helps us write more useful content.
Get tomorrow's AI briefing
Join readers who start their day with NexChron. Free, daily, no spam.