Does Framework Convention on AI, Human Rights, Democracy and Rule of Law (CETS 225) require Risk Assessment?

Council of Europe • enacted

Yes — 1 provision

Requirements at a glance

This regulation imposes 5 specific requirements for Risk Assessment across 1 provision:

Risk and Impact Management (Article 16)

Copy link to this provision

Obligation:
Risk Assessment
pending
Effective:
Pending entry into force
Risk tier:
all
Scope:
Treaty Parties adopting or maintaining Article 16 risk measures for covered AI lifecycle activities; private actor duties depend on domestic implementation
high-impactcross-domainupcoming
Article 16 directs Parties to adopt graduated, context-sensitive risk measures and assess whether uses they consider incompatible with human rights, democracy or the rule of law warrant a moratorium, ban or other measure. Its operation depends on treaty entry into force and Party implementation.

Requirements

RequirementDetails
Lifecycle risk measuresEach Party must adopt or maintain measures to identify, assess, prevent and mitigate AI-system risks to human rights, democracy and the rule of law (Art. 16(1))
Graduated approachParty measures account for context, intended use, severity and probability; they apply iteratively and include monitoring of risks and adverse impacts (Art. 16(2)(a)-(e))
Risk documentationParty measures include documentation of risks, actual and potential impacts, and the management approach (Art. 16(2)(f))
Pre-use testingParty measures require testing before first use and when significantly modified, where appropriate (Art. 16(2)(g))
Moratoria assessmentEach Party assesses the need for a moratorium, ban or other measure for uses it considers incompatible with human rights, democracy or the rule of law (Art. 16(4))

Penalties

ViolationFine
Non-complianceNo direct supranational fine; Party implementation and oversight mechanisms determine applicable domestic consequences after entry into force
View full regulation View obligation Obligation matrix