By Marc Rotenberg, Founder and Executive Director, Center for AI and Digital Policy
There is a tendency in current debates about artificial intelligence to assume that international governance is either impossible or irrelevant. AI technology is developing too quickly, the argument goes. Governments have different interests, and companies operate across borders. The most powerful countries will not accept meaningful constraints. Therefore, we should expect a patchwork of national laws, voluntary commitments, and technical standards.
The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law offers a different answer.
The AI Treaty, as it is commonly known, is the first legally binding international treaty for artificial intelligence. It establishes a common framework for governments to ensure that AI systems respect human rights, democratic institutions, and the rule of law. It is technology-neutral, applies across the AI lifecycle, and is designed to accommodate different national legal systems.
Most importantly, it is intended to be global. That point deserves more attention. The Council of Europe negotiated the treaty, but the treaty is not simply a European instrument. Countries outside Europe participated in its negotiation. The United States, Canada, Japan, Israel, and Uruguay have signed it, and other countries from around the world may ultimately join. Japan’s participation gives the treaty a foothold in East Asia, and Uruguay’s signature extends the framework to South America.
This is precisely what global AI governance should look like: not the creation of a new international bureaucracy, not an effort to impose a single regulatory model on every country, but agreement on fundamental principles and legal obligations that governments can implement through their own institutions.
The progress has already been remarkable. The Center for AI and Digital Policy (CAIDP) counts more than 45 countries as supporting the framework when the European Union and its member states are taken into account. The formal Council of Europe treaty record currently shows 20 state signatures in addition to the European Union, which formally approved the Convention in May 2026.
That is a significant achievement at a moment when international consensus on almost any major technology policy issue is difficult to achieve. But the work is far from complete.
The treaty must now move from endorsement to ratification, from ratification to implementation, and from implementation to effective enforcement. Whether the AI Treaty ultimately becomes a landmark in international law or simply another promising international agreement will depend on what governments do next.
Why a treaty is needed
AI is inherently international. A model may be developed in one country, trained on data collected from many others, operated through cloud infrastructure scattered across several jurisdictions, incorporated into products sold globally, and used to make decisions about people who have no connection at all to the country where the system was created.
National regulation therefore matters, but national regulation alone cannot solve the problem. The same is true of cybersecurity, aviation, telecommunications, financial markets, and environmental protection. When activities routinely cross borders, governments eventually discover that sovereignty is strengthened, not diminished, by international rules. That is one of the important lessons of the AI Treaty.
Sovereignty in the digital age cannot simply mean that every government makes its own rules within its own territory. Countries remain sovereign, but the systems they seek to govern are interconnected. Meaningful sovereignty increasingly requires cooperation.
The alternative is not national independence, but private governance by a small number of multinational technology companies whose technical decisions become global policy by default.
The AI Treaty provides another path. It says that governments should agree on a common floor: AI must remain consistent with human rights, democracy, and the rule of law. That proposition sounds straightforward, but its significance should not be underestimated.
Much of the early debate about AI governance focused on broad ethical principles. Governments and companies endorsed concepts such as fairness, transparency, accountability, safety, and privacy, as I described when I published the first AI Policy Sourcebook in 2019. These principles were useful, but they were generally voluntary. There was little agreement about implementation and almost no mechanism for enforcement.
The Council of Europe took the next step, converting many of these principles into an international legal framework.
What the treaty actually does
The full title tells us a great deal: the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law.
The treaty does not begin with technology. It begins with democratic institutions and fundamental rights. The objective is not to make AI trustworthy simply so that people will use it, nor is it to maximize innovation and deal with the social consequences later. The starting proposition is that governments already have obligations to protect rights and democratic institutions. AI does not displace those obligations.
The treaty therefore requires parties to address AI systems throughout their lifecycle, from design and development through deployment and eventual decommissioning. Its core principles include human dignity and individual autonomy, transparency and oversight, accountability and responsibility, equality and non-discrimination, privacy and data protection, reliability, and safe innovation.
Several provisions are particularly important.
First, there is transparency and oversight. People should be able to understand when important decisions affecting them involve AI systems and be able to meaningfully contest adverse outcomes, and public authorities must have the information necessary to exercise meaningful oversight.
Second, there is accountability. The use of AI cannot become an excuse for avoiding responsibility. Governments and organizations remain responsible for decisions made with AI systems.
Third, there is equality and non-discrimination. AI systems should not reproduce or amplify discrimination that would otherwise violate fundamental rights.
Fourth, the treaty protects privacy and personal data, concerns that have become increasingly important as AI companies seek enormous quantities of data for training and operation.
Fifth, the treaty recognizes the importance of remedies and procedural safeguards. If an AI system contributes to a decision that harms an individual’s rights, there must be a meaningful possibility to challenge that decision. The Convention also calls for appropriate notice when people are interacting with AI rather than with a human.
Sixth, and perhaps most importantly for future AI governance, the treaty requires risk and impact assessment. Governments must establish measures to identify, assess, prevent, and mitigate risks to human rights, democracy, and the rule of law. That approach moves governance upstream. It is far better to identify foreseeable harms before an AI system is widely deployed than to wait until after people have been injured and then ask whether anyone can be held accountable.
The treaty even recognizes that some applications of AI may simply be inconsistent with human rights, democracy, or the rule of law and therefore may require bans, moratoria, or other restrictive measures. Red lines are now the front lines of effective AI governance.
These are substantial obligations. They also provide an answer to one of the central questions in global AI policy: how do we govern a rapidly changing technology without writing rules that become obsolete as soon as they are adopted?
The Council of Europe chose to regulate consequences and responsibilities rather than particular technical architectures. This is one reason the treaty may prove durable.
A genuinely international achievement
The geographic reach of the AI Treaty is also significant. The Convention was negotiated by the Council of Europe’s 46 member states with participation from the European Union and non-European countries including Argentina, Australia, Canada, Costa Rica, Israel, Japan, Mexico, Peru, the United States, Uruguay, and the Holy See. Civil society, academia, industry, and other international organizations also participated in the drafting process.
When the treaty opened for signature in September 2024, the United States was among the original signatories. Canada followed. Japan signed in February 2025. Uruguay signed in September 2025. Those signatures matter because they demonstrate that the principles underlying the Convention are not uniquely European. Democratic governance, privacy, fairness, transparency, and access to remedies have relevance far beyond Strasbourg or Brussels.
The treaty is structured accordingly. Once it enters into force, additional non-member countries can be invited to accede. In June 2026, the Parliamentary Assembly of the Council of Europe specifically encouraged non-member states worldwide to seek accession.
This may ultimately be the treaty’s greatest contribution. For several years, the international AI debate has appeared to be moving toward competing regulatory blocs: the European approach, the American approach, the Chinese approach, and various regional alternatives. Some divergence is inevitable, but complete regulatory fragmentation would be dangerous. AI companies would confront conflicting obligations. Smaller countries would struggle to develop effective national frameworks. And basic protections could depend on where a person happened to live.
A global framework does not require identical national laws, but agreement on minimum obligations. The Council of Europe has experience with precisely this model. Convention 108 on data protection and the 2006 Cybercrime Convention, for example, eventually attracted parties well beyond Europe. The AI Convention could follow a similar path.
Experts have rallied behind the treaty
The treaty has also received unusually strong support from leading figures in artificial intelligence, law, and technology policy. Turing Award recipient Yoshua Bengio has described the treaty as establishing much-needed global guardrails for AI and placing human rights and democratic principles at the center of its development.
Stuart Russell, the British computer scientist and UC Berkeley professor, has welcomed the Convention as providing a basic level of agreement for managing what may become the dominant technology of the future.
Virginia Dignum, the Dutch-Portuguese computer scientist and Umeå University professor, has called it a vital step toward ensuring that AI aligns with human rights, democracy, and the rule of law. Former world chess champion and democracy advocate Garry Kasparov has emphasized the importance of maintaining accountability and putting human values first.
Leading scholars and experts from Africa, Latin America, Europe, Asia, and North America have made similar statements.
Law is essential, but norms also matter. Governments, companies, researchers, lawyers, and civil society organizations need a common reference point when evaluating AI policies. The AI Treaty can provide that reference point.
The treaty is not perfect
Support for the Convention should not prevent candid discussion of its limitations. One significant concern involves private companies. The treaty clearly applies to AI activities undertaken by public authorities and private actors acting on their behalf. But governments have more flexibility in determining how the Convention’s principles will apply to other private actors. They may apply the treaty obligations directly or use other appropriate measures consistent with the Convention’s purpose.
That flexibility was controversial during the negotiations, and understandably so. Many of the world’s most consequential AI systems are developed and operated by private companies.
The European Union has taken a strong position. In approving the Convention, it declared that it will apply the treaty’s principles and obligations to private actors through implementation of the EU AI Act. Other governments should provide similarly clear commitments.
There are also exclusions relating to national defense and qualifications concerning national security. These areas deserve continuing scrutiny, particularly as AI is increasingly used in intelligence, cybersecurity, border control, and military systems.
And the international monitoring mechanism will depend heavily on the seriousness with which governments approach implementation.
These limitations are reasons to strengthen the treaty, not reasons to dismiss it. No major international agreement begins as a complete solution. Treaties establish institutions, expectations, procedures, and common legal principles. Those mechanisms can become stronger over time.
Ratification is now the priority
The immediate challenge is straightforward: governments need to ratify the Convention. The treaty requires five ratifications, including at least three Council of Europe member states, before it enters into force. As of August 30, 2026, the European Union has formally approved the Convention, but the threshold for entry into force has not yet been reached.
Countries that have signed should move promptly toward ratification. Governments that participated in the negotiations but have not yet signed should reconsider. And once the Convention enters into force, countries in Africa, Asia, Latin America, and other regions should examine accession.
Governments will also need to translate the treaty into domestic law and practice. They will need meaningful risk and impact assessments and effective remedies, along with independent oversight bodies with adequate authority, expertise, and resources.
The Convention specifically requires effective oversight mechanisms, and its explanatory materials emphasize that these bodies must have sufficient independence and power to carry out their responsibilities.
The treaty also establishes a Conference of the Parties to review implementation, encourage cooperation, and respond to new legal, policy, and technological developments.
Civil society will have an important role as well. They should continue to push their national governments toward implementation and effective enforcement. Governments should publish implementation plans. Impact assessments should be meaningful rather than procedural exercises. Oversight bodies should be able to investigate complaints. People harmed by AI systems should be able to obtain remedies. Researchers and public-interest organizations should have sufficient access to information to determine whether governments are meeting their obligations.
These are the tests that will determine whether the AI Framework Convention succeeds.
A framework for what comes next
International cooperation on AI is often described as something the world should eventually attempt. The Council of Europe AI Treaty shows that it has already begun. Countries with different legal systems and different economic interests have agreed that AI must operate within boundaries established by human rights, democratic institutions, and the rule of law.
The Council of Europe AI Convention does not solve every problem. It does not resolve the debate over autonomous weapons or establish a global AI regulator. It does not eliminate regulatory competition. And it will not prevent every misuse of AI.
But international governance rarely develops through a single comprehensive agreement. It develops through institutions and norms that gradually establish expectations for responsible conduct. Aviation safety, human rights law, environmental protection, nuclear non-proliferation, cybersecurity, and data protection all demonstrate versions of this process.
AI governance will likely develop in much the same way. The next phase will be harder. Governments must ratify the Convention and implement it. Regulators must enforce it, and civil society must scrutinize compliance. And the international community must continue to strengthen the framework as technology evolves.
At a time of geopolitical fragmentation and rapid technological change, more than 45 countries have already aligned themselves with a common framework for AI governance. Japan and Uruguay demonstrate its reach beyond Europe. Leading AI experts have endorsed its principles. And the Convention provides a pathway for participation by countries around the world.
The Council of Europe has given the international community something it badly needed: a starting point for global AI governance based not on technological dominance, but on human rights, democracy, and the rule of law.
The task now is to make it work.
Marc Rotenberg is Founder and Executive Director of the Center for AI and Digital Policy (CAIDP), an international organization promoting AI policies that safeguard human rights, democratic institutions, and the rule of law. CAIDP publishes the Artificial Intelligence and Democratic Values Index and has supported the development, adoption, ratification, and implementation of the Council of Europe Framework Convention on Artificial Intelligence.
The views expressed in this article are those of the author and do not necessarily reflect the views of Techplomacy Magazine or the Techplomacy Foundation. Articles may be republished in full, without alteration, with credit to Techplomacy Magazine (magazine.techplomacyfoundation.org).
Series: Techplomacy Conversations™




