Council of Europe Framework Convention on AI: implications for UK implementation
The UK signed the Council of Europe Framework Convention on AI in September 2024. Implementation choices will shape British AI governance and the relationship with the EU AI Act. What practitioners and businesses should expect.
- UK
- Council of Europe
- regulation
- international
On 5 September 2024 in Vilnius, the United Kingdom signed the Council of Europe Framework Convention on Artificial Intelligence, the world’s first binding international treaty on AI. The signature was significant: the UK joined the European Union, the United States, Israel, Andorra, Georgia, Iceland, Norway, Moldova, and San Marino among the opening signatories. It was also instructive about the direction of UK AI governance post-Brexit.
This article considers what the Framework Convention means in practice for UK-based AI practitioners and the organisations they work in, and how it relates to the UK’s own regulatory approach.
The UK’s distinctive AI policy posture
The UK has consistently positioned itself differently from the EU on AI regulation. The March 2023 white paper “A pro-innovation approach to AI regulation” set the direction: no new horizontal AI statute, but principles-based guidance applied by existing sectoral regulators: the Information Commissioner’s Office, the Competition and Markets Authority, the Financial Conduct Authority, the Medicines and Healthcare products Regulatory Agency, Ofcom, and others.
This approach was reinforced through 2024 and 2025 with iterative guidance, the establishment of the AI Safety Institute (now AI Security Institute), and the AI Safety Summit process initiated at Bletchley Park in November 2023. The model is principles plus sectoral application rather than EU-style horizontal statute.
Signing the Framework Convention does not change this fundamental posture. What it does is anchor the principles in binding international law for the UK. Ratification will require UK legislation to implement Convention obligations, but the implementing vehicles can be sectoral and guidance-based, consistent with existing UK policy.
What the Convention requires
The Convention sets obligations on signatory states with respect to public-sector AI use and permits, but does not require, extension to the private sector through national law. Its three foundational pillars are familiar: human rights protection, democratic integrity, and the rule of law.
For practitioners, the operational obligations matter more than the principles: risk and impact assessment throughout the AI lifecycle, transparency and oversight, effective remedies for those harmed by AI, and safe innovation pathways including regulatory sandboxes.
These requirements largely already exist in UK law for public-sector AI through the Data Ethics Framework, Algorithmic Transparency Recording Standard, and Equality Act 2010 duties. The Convention formalises and strengthens them, and adds international accountability through the Convention’s monitoring mechanisms.
What changes for private-sector AI practitioners
The Convention permits but does not require parties to extend obligations to private actors. Whether the UK does so, and how, will be a key implementation choice. Three plausible scenarios.
Scenario one: minimal private-sector extension. The UK ratifies the Convention with public-sector obligations only. Private-sector AI remains regulated through sectoral regulators applying existing principles-based guidance. Practitioners see incremental updates to ICO, FCA, MHRA, CMA guidance but no new statute.
Scenario two: targeted private-sector obligations. The UK extends specific Convention obligations to private actors operating in high-risk contexts: biometric identification, critical infrastructure, employment decisions. This would resemble a lighter version of EU AI Act high-risk obligations. New guidance or statutory instruments translate Convention principles into operational requirements.
Scenario three: broader private-sector implementation. The UK enacts something closer to a horizontal AI statute, applying Convention principles broadly to private-sector AI. This scenario is the least likely given the UK’s stated preference for sectoral regulation, but political conditions may change.
The current trajectory points toward scenario one or two. The AI Security Institute focuses on frontier AI risks; sectoral regulators continue to develop AI-specific guidance; major AI deployment areas (financial services, healthcare, employment) receive priority attention.
The EU AI Act overlap
For UK-based organisations with EU exposure, which means most internationally operating UK businesses, the EU AI Act remains the primary regulatory anchor. The Act applies extraterritorially: UK organisations placing AI on the EU market or whose AI output is used in the EU fall within scope. Most large UK financial services, technology, healthcare, and consulting firms are affected.
The Framework Convention and the EU AI Act are complementary for these organisations. EU AI Act compliance work covers most Convention principles in practice. The Convention adds an international-law layer rather than parallel operational requirements.
For UK organisations without EU exposure, such as purely domestic public-sector services and UK-focused SMEs, the Framework Convention is more directly relevant than the EU AI Act. Implementation will determine how much practical change this means.
What UK practitioners should do now
Three actions are sensible for UK-based AI practitioners through the rest of 2026 and into 2027.
First, map current AI activity to Convention principles. Risk and impact assessment; transparency; oversight; remedies. Most mature organisations already have these elements at some level; the question is how complete and how operationally embedded they are.
Second, track UK implementation. The Department for Science, Innovation and Technology leads UK AI policy; sectoral regulators publish guidance updates regularly; the AI Security Institute publishes research and recommendations. A regular cadence of guidance review is worth establishing.
Third, maintain credentials and competencies that travel. The European Digital Credential remains valuable for UK practitioners working with EU clients and counterparties. AIPIA membership offers ongoing access to European-recognised AI training and credentials despite the UK’s post-Brexit status.
AIPIA’s UK orientation
AIPIA membership is open to practitioners regardless of nationality or residence. UK members form a meaningful share of AIPIA’s international membership. The association’s working groups on EU AI Act compliance, the Framework Convention, and international AI standards all include UK-based contributors.
For UK-based organisations interested in supporting their teams’ professional development in this transitional period, shaped by Brexit, Framework Convention ratification, and ongoing EU AI Act enforcement, AIPIA’s training programmes offer European-recognised credentials that retain value across the Channel and beyond.
The Council of Europe Framework Convention is not a sudden change for UK AI governance. It is a formalisation of principles the UK has been articulating through its own policy documents for several years. The substantive direction is consistent with UK practice. The binding force is new, and that matters.