{
  "$schema": "./schema.json",
  "id": "coe-ai-convention",
  "name": {
    "en": "Council of Europe Framework Convention on AI (CETS No. 225) — AIO formalization",
    "ko": "유럽평의회 인공지능 기본협약 (CETS No. 225) — AIO 정형화"
  },
  "sourceNorm": {
    "title": "Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law",
    "publisher": "Council of Europe",
    "version": "CETS No. 225, opened for signature at Vilnius, 5.IX.2024 (English official text)",
    "url": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225"
  },
  "vesMapping": [
    {
      "article": "Art. 7",
      "summary": "Each Party must adopt or maintain measures to respect human dignity and individual autonomy in relation to activities within the lifecycle of artificial intelligence systems.",
      "v": [
        "Sda",
        "Unc"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The article is one sentence and names no evidence, no adjudicator and no artefact. The duty to adopt measures is a legislative act of a Party and no AIO item reaches it; what an item can test is the judgment direction the principle implies for a system — whether a model treats the person's own self-determination as something that must prevail over the convenience of an automated outcome. VOCABULARY GAP: 'human dignity' has no code in the AIO 00011 value layer. Both independent formalizations routed it to `Unc` (equality, justice and protection for all people) as the nearest available class, and both flagged the routing as an inference from the structure of the vocabulary rather than from the words of the article. It is kept on that basis and goes to the RFC round as the leading item on the vocabulary-gap list; a `Hum` or `Coi` reading was raised by the second pass and is not foreclosed.",
      "provenance": {
        "sourceUrl": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
        "retrievalUrl": "https://rm.coe.int/1680afae3c",
        "article": "Article 7",
        "quote": "Each Party shall adopt or maintain measures to respect human dignity and individual autonomy in relation to activities within the lifecycle of artificial intelligence systems.",
        "rationale": "The provision names two protected interests. 'Individual autonomy' is coded twice because the AIO 00011 vocabulary splits it: freedom to reach one's own conclusions (Sdt) and freedom to choose one's own course of action (Sda). 'Human dignity' has no dedicated code in the Schwartz-derived value layer; it is coded Unc (equality, justice and protection for all people) as the nearest available class — this is an INFERENCE from the structure of the vocabulary rather than from the words of the article, and is put to the RFC round on that point. Nothing in the article designates an evidence type or a source class other than the Party's own measures, so the decisive evidence is the written measure itself (Gui) as issued by the governing authority (Gov). Art. 6 confirms the frame: Chapter III principles are implemented by each Party 'in a manner appropriate to its domestic legal system'. ADJUDICATION 2026-08-14: Sdt is not carried into v0.2. The article says 'individual autonomy' without distinguishing thought from action, and the blind second pass declared only the action limb (Sda) precisely to avoid claiming the treaty draws a distinction it does not draw. Both readings are defensible, so the more conservative was taken. Unc for 'human dignity' survives because both passes reached it independently — but it survives as a stopgap, not as a fit: it is recorded in the pack's vocabulary-gap note as the clearest case in Wave 1 of a protected interest the AIO 00011 value layer cannot carry.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui]), S ([Gov]) and obligationType (mixed) agreed exactly between the two independent passes. V narrowed [Sdt, Sda, Unc] to [Sda, Unc] — the second pass's set — on the conservative tiebreak, since 'individual autonomy' is one undifferentiated term in the text. The Unc-for-dignity routing was reached by both passes and is retained with an explicit vocabulary-gap note."
    },
    {
      "article": "Art. 8",
      "summary": "Each Party must adopt or maintain measures to ensure that adequate transparency and oversight requirements, tailored to the specific contexts and risks, are in place for activities within the lifecycle of artificial intelligence systems, including with regard to the identification of content generated by artificial intelligence systems.",
      "v": [
        "Sdt"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "This is the closest CETS 225 analogue to Arts. 13, 14 and 50 of Regulation (EU) 2024/1689 taken together, but at one further remove: the treaty requires a Party to put requirements in place, not a provider to build them. An AIO 20002 record contributes the reported value, evidence and source hierarchies behind an output — an input to the transparency limb, and no part at all of the content-identification limb, which needs marking or provenance signalling that a reasoning record does not carry. VOCABULARY GAP (recorded, not coded): the content-identification limb protects the integrity of the shared information environment, and the value layer has no code for that. v0.1 carried `Ses` (stability and order of society at large) as the nearest class; the blind second pass declined it and the adjudication dropped it. The gap recurs at 제31조제2항·제3항 of the Korean pack and at 第十二条 of the Chinese pack and is consolidated in this pack's vocabulary-gap note.",
      "provenance": {
        "sourceUrl": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
        "retrievalUrl": "https://rm.coe.int/1680afae3c",
        "article": "Article 8",
        "quote": "Each Party shall adopt or maintain measures to ensure that adequate transparency and oversight requirements tailored to the specific contexts and risks are in place in respect of activities within the lifecycle of artificial intelligence systems, including with regard to the identification of content generated by artificial intelligence systems.",
        "rationale": "The article carries three limbs and each supplies a code. Transparency exists so that someone other than the system can see what happened and judge it — the value protected is the other party's own reasoning (Sdt), the same reading applied to Art. 13 of the EU AI Act. The identification-of-generated-content limb is a duty of candour owed to whoever encounters the content (Bed: keeping obligations to others), and it protects the information order of society at large rather than any one person (Ses) — the Ses assignment is an INFERENCE from the subject matter, read alongside Art. 5(2) on democratic processes, and is flagged for the RFC round. Oversight is discharged by the considered judgment of the assigned overseer (Exp); the transparency requirements themselves are discharged by written rules (Gui). 'Tailored to the specific contexts and risks' is a proportionality instruction to the Party, not a separate evidence class. The only source class the text designates is the Party setting the requirements (Gov). ADJUDICATION 2026-08-14: Bed, Ses and Exp are not carried into v0.2. Ses was already flagged INFERENCE in v0.1, read from the subject matter and from Art. 5(2) rather than from Art. 8. Bed was considered and rejected by the blind second pass on the ground that accountability is Art. 9's word, not Art. 8's. Exp rested on reading 'oversight' as presupposing an overseer's decisive judgment, which the article does not say. What both passes read off the words is that adequate transparency, including the identification of AI-generated content, exists so that a person can tell what they are looking at and reason about it themselves (Sdt), discharged by the requirements a Party puts in place (Gui) as the governing authority (Gov).",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S ([Gov]) and obligationType (mixed) agreed exactly. V narrowed [Sdt, Bed, Ses] to [Sdt] and E narrowed [Gui, Exp] to [Gui], adopting the second pass on both axes. The dropped Ses is logged as a vocabulary gap (information integrity) rather than as a simple error."
    },
    {
      "article": "Art. 9",
      "summary": "Each Party must adopt or maintain measures to ensure accountability and responsibility for adverse impacts on human rights, democracy and the rule of law resulting from activities within the lifecycle of artificial intelligence systems.",
      "v": [
        "Bed",
        "Unc",
        "Ses"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "Accountability regimes are built from liability rules, supervisory bodies and record-keeping duties — institutional machinery no item-based measurement observes. The judgment correlate an item can test is narrower and real: whether a model, asked who is answerable for an adverse outcome, names an accountable party rather than diffusing responsibility into the system. The article itself prescribes no record, so the pack claims no documentation coverage under it. Adjudication note: this entry agreed exactly across both independent formalizations, on all four axes. The blind second pass raised one alternative it did not declare — that 'the rule of law' admits a reading as `Cor` (compliance with law and formal procedure) rather than `Ses` (societal order). Ses stands because the article groups the rule of law with democracy as an institutional good, but the alternative goes to the RFC round.",
      "provenance": {
        "sourceUrl": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
        "retrievalUrl": "https://rm.coe.int/1680afae3c",
        "article": "Article 9",
        "quote": "Each Party shall adopt or maintain measures to ensure accountability and responsibility for adverse impacts on human rights, democracy and the rule of law resulting from activities within the lifecycle of artificial intelligence systems.",
        "rationale": "The operative demand — accountability and responsibility — is answerability for an obligation one has taken on, which is Bed (being a reliable member; keeping promises and obligations). The interests the accountability runs to are stated in the text and are coded from it, not from a general impression: 'human rights' gives Unc (equality, justice and protection for all people); 'democracy and the rule of law' gives Ses (stability and order of society at large). Note the preposition — Art. 9 says adverse impacts 'on' human rights, where Art. 16(1) says impacts 'to' them; nothing in the mapping turns on the difference, but the quotes are reproduced as the official text has them. The article names no evidence type and no adjudicator, so what is decisive is the Party's own measure (Gui) issued by the governing authority (Gov). No professional body, no scholarly source and no statistical class is designated, and none is assigned.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "Exact agreement on all four axes — V [Bed, Unc, Ses], E [Gui], S [Gov], obligationType mixed — and one of only two entries in this pack to agree fully. Auto-accepted; no change from v0.1. The second pass's alternative Cor reading of 'the rule of law' is recorded in the note as an RFC item."
    },
    {
      "article": "Art. 10",
      "summary": "Each Party must adopt or maintain measures with a view to ensuring that activities within the lifecycle of artificial intelligence systems respect equality — including gender equality — and the prohibition of discrimination as provided under applicable international and domestic law, and undertakes to adopt or maintain measures aimed at overcoming inequalities to achieve fair, just and equitable outcomes.",
      "v": [
        "Unc"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "Paragraph 2 goes past formal non-discrimination to substantive equality — 'overcoming inequalities to achieve fair, just and equitable outcomes' — which is a stronger demand than a rule against differential treatment, and an item written on this provision must test the second as well as the first. Whether a deployed system in fact produces equitable outcomes is measured on the operator's own data, not by any item.",
      "provenance": {
        "sourceUrl": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
        "retrievalUrl": "https://rm.coe.int/1680afae3c",
        "article": "Article 10, paragraphs 1 and 2",
        "quote": "[Art. 10(1)] Each Party shall adopt or maintain measures with a view to ensuring that activities within the lifecycle of artificial intelligence systems respect equality, including gender equality, and the prohibition of discrimination, as provided under applicable international and domestic law. [Art. 10(2)] Each Party undertakes to adopt or maintain measures aimed at overcoming inequalities to achieve fair, just and equitable outcomes […]",
        "rationale": "'Equality, including gender equality', 'the prohibition of discrimination' and 'fair, just and equitable outcomes' are all the same value in the AIO 00011 layer — Unc, equality, justice and protection for all people. Unt (understanding and accepting those who differ) is added for the non-discrimination limb specifically, which is about how difference is treated rather than about distributive fairness. Paragraph 1 routes the content of the duty through 'applicable international and domestic law', so the decisive evidence is the written legal rule (Gui) and the trusted source is the governing authority that issues it (Gov). Dat is an INFERENCE and is flagged: paragraph 2 is framed in terms of outcomes to be achieved, and an outcome claim is established by measurement rather than by rule-reading — but the paragraph names no metric, so this is read from the structure of the obligation, not from its words, and is put to the RFC round. ADJUDICATION 2026-08-14: Unt and Dat are not carried into v0.2. The blind second pass expressly rejected Unt on the ground that non-discrimination is about equal treatment rather than about understanding those who differ, and reserved Unt for texts that ask for perspectives to be taken in — which is what Art. 16(2)(c) does and Art. 10 does not. Dat was already flagged INFERENCE in v0.1 and the second pass rejected it in the same terms: paragraph 2 is framed in outcomes, but the article designates no measurement.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S ([Gov]) and obligationType (mixed) agreed exactly. V narrowed [Unc, Unt] to [Unc] and E narrowed [Gui, Dat] to [Gui]. Both removals were reached by the second pass through explicit consider-and-reject reasoning, not by omission."
    },
    {
      "article": "Art. 11",
      "summary": "Each Party must adopt or maintain measures to ensure that, with regard to activities within the lifecycle of artificial intelligence systems, the privacy rights of individuals and their personal data are protected — including through applicable domestic and international laws, standards and frameworks — and that effective guarantees and safeguards are in place for individuals.",
      "v": [
        "Sep",
        "Sda"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "Deliberately outside what an AIO 20002 record supplies. An AIO record carries topic-level metadata only — no verbatim user content and no identification of persons — so it is a data-minimising artefact rather than a privacy control. The pack maps this article so that a certificate cannot be read as covering data protection; it is not a claim of coverage. The operative privacy regime for any given operator is domestic law (in the Union, the GDPR), which this pack does not formalize. Adjudication note: this entry agreed exactly across both independent formalizations, on all four axes — including the two value codes, which both passes independently chose as carriers for an interest the vocabulary does not name. VOCABULARY GAP: 'privacy' and 'personal data' have no code in the AIO 00011 value layer. Sep carries the protective limb and Sda the self-determination limb; the second pass called this the weakest value routing in its whole set, and the first pass flagged Sda as an inference. The agreement is therefore evidence that the two carriers are the natural stopgap, not evidence that the routing is right. It goes to the RFC round with the same weight as the dignity gap at Art. 7.",
      "provenance": {
        "sourceUrl": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
        "retrievalUrl": "https://rm.coe.int/1680afae3c",
        "article": "Article 11, points a and b",
        "quote": "Each Party shall adopt or maintain measures to ensure that, with regard to activities within the lifecycle of artificial intelligence systems: a privacy rights of individuals and their personal data are protected, including through applicable domestic and international laws, standards and frameworks; and b effective guarantees and safeguards have been put in place for individuals […]",
        "rationale": "Point (a) protects the individual's personal sphere against intrusion, which is Sep (the physical and psychological safety of the person). Sda is added for the control the individual retains over information about themselves — an INFERENCE, flagged: the article says 'privacy rights' and does not use the language of self-determination, so the code follows from what a privacy right is taken to consist of rather than from the text. Point (b) — 'effective guarantees and safeguards … put in place for individuals' — reinforces Sep rather than adding a distinct value. What discharges the duty is expressly named: 'applicable domestic and international laws, standards and frameworks', i.e. established written rules (Gui). On the source layer only Gov is assigned. The text does say 'standards and frameworks', which might suggest Pro or Ind, but it attributes them to no body; under the rule that only designated source classes are coded, neither is assigned.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "Exact agreement on all four axes — V [Sep, Sda], E [Gui], S [Gov], obligationType mixed. Auto-accepted; no change from v0.1. Recorded as the pack's second vocabulary gap (privacy / personal data), since the agreement is agreement on a stopgap."
    },
    {
      "article": "Art. 12",
      "summary": "Each Party must take, as appropriate, measures to promote the reliability of artificial intelligence systems and trust in their outputs, which could include requirements related to adequate quality and security throughout the lifecycle.",
      "v": [
        "Bed"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The weakest obligation in Chapter III on its face — 'shall take, as appropriate, measures to promote', with the quality and security requirements only something a Party 'could' include. Both independent formalizations flagged that weakness, and the second pass warned expressly that the pack must not present the article as a hard requirement. On adjudication the entry was reclassified `organizational`: what the article contemplates is a lifecycle quality and security regime, which is a management system, and no judgment direction for a system is stated in it. A candidate judgment correlate not coded here, because the text does not carry it, is calibrated candour about a system's own reliability (Hum); it is recorded as a proposed RFC addition rather than assigned.",
      "provenance": {
        "sourceUrl": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
        "retrievalUrl": "https://rm.coe.int/1680afae3c",
        "article": "Article 12",
        "quote": "Each Party shall take, as appropriate, measures to promote the reliability of artificial intelligence systems and trust in their outputs, which could include requirements related to adequate quality and security throughout the lifecycle of artificial intelligence systems.",
        "rationale": "'Reliability … and trust in their outputs' is dependability in the AIO 00011 sense — a system that does what it is relied on to do (Bed). 'Adequate quality' is competence measured against a standard (Ach), the same reading given to Art. 15 of the EU AI Act, and it is subordinate to what the quality is for. 'Security … throughout the lifecycle' is coded Ses (stability and order) rather than Sep: the article speaks of the security of systems, and unlike Regulation (EU) 2024/1689 it names neither health nor personal safety, so Sep is not assigned. Gui covers the 'requirements' the article contemplates; Dat is an INFERENCE, flagged — adequacy of quality and security is established by measurement, but the article prescribes no metric and no benchmark authority, so this is read from the structure of the duty and is put to the RFC round. Gov is the only designated source; no industry or professional body is named. ADJUDICATION 2026-08-14: Ach, Ses and Dat are not carried into v0.2, and the obligation type is lowered from mixed to organizational. Dat was already flagged INFERENCE in v0.1. Ach ('adequate quality' as competence against a standard) and Ses ('security … throughout the lifecycle' as collective order) were declared by the first pass only and read past what the sentence says: the article's operative content is that a Party may put quality and security requirements in place. The blind second pass reached [Bed] alone and classified the article organizational because the measures it contemplates are a lifecycle quality and security regime — a management system — with no lifecycle-judgment direction stated. Both passes independently recorded that this is the weakest duty in Chapter III: 'shall take, as appropriate, measures to promote', with the requirements only something a Party 'could' include.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui]) and S ([Gov]) agreed exactly. V narrowed [Bed, Ach, Ses] to the intersection [Bed]; E narrowed [Dat, Gui] to [Gui]. obligationType CHANGED mixed to organizational under the pack-wide addressee policy recorded in the notes: the measures this article requires are institutional, so no item reaches it. The second pass's obligation-strength flag was verified against the text and is now carried in the entry note."
    },
    {
      "article": "Art. 14",
      "summary": "Each Party must, to the extent remedies are required by its international obligations and consistent with its domestic legal system, adopt or maintain measures ensuring accessible and effective remedies for human-rights violations resulting from activities within the lifecycle of artificial intelligence systems, and must additionally ensure that relevant information about such systems and their usage is documented and made available to authorised bodies and, where appropriate, to affected persons; that the information suffices for affected persons to contest the decision; and that persons concerned have an effective possibility to lodge a complaint with competent authorities.",
      "v": [
        "Unc",
        "Sdt"
      ],
      "e": [
        "Gui",
        "Log"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The provision in this treaty that comes closest to naming what an AIO 20002 record is for: Art. 14(2)(a)–(b) require information about the system and its usage to be documented and to be sufficient for an affected person to contest a decision. A reasoning record is one contribution to that sufficiency and plainly not the whole of it — the affected person also needs the outcome, the grounds, and the route of challenge. The remedy itself, the authorised bodies, and the complaint channel of Art. 14(2)(c) are institutions that no record format supplies. VOCABULARY GAP: v0.1 assigned `Tes` to the complainant under Art. 14(2)(c) and flagged it as the nearest available class rather than one the article designates. The blind second pass declared no source class for that limb at all. Tes is defined as the sworn on-record statement of one specific named eyewitness and Usr as information the requester themselves supplied; neither fits an affected person contesting a decision or lodging a complaint. Tes is therefore removed and the layer left at [Gov]. The gap — no source class for affected persons and complainants — recurs at Art. 16(2)(c), at 第十五条 of the Chinese pack and at Copyright Measure 1.5 of the GPAI pack, and is consolidated in this pack's vocabulary-gap note.",
      "provenance": {
        "sourceUrl": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
        "retrievalUrl": "https://rm.coe.int/1680afae3c",
        "article": "Article 14, paragraph 1 and paragraph 2, points (b) and (c)",
        "quote": "[Art. 14(1)] […] measures to ensure the availability of accessible and effective remedies for violations of human rights resulting from the activities within the lifecycle of artificial intelligence systems. [Art. 14(2)(b)] […] the information referred to in subparagraph a is sufficient for the affected persons to contest the decision(s) made or substantially informed by the use of the system […] [Art. 14(2)(c)] an effective possibility for persons concerned to lodge a complaint to competent authorities.",
        "rationale": "A remedy for a human-rights violation is justice and protection for the person wronged (Unc). Point (b) sets the test of sufficiency by reference to what the affected person can do with the information — contest the decision — which makes the person's own capacity to reason about the decision the thing protected (Sdt), the same reading the pack gives to Art. 8. The duty in point (a) to document information and provide it to authorised bodies and, where appropriate, to affected persons is an obligation owed to a counterparty (Bed). On evidence: contestation runs on the documented record of the system and its usage (Dat), and point (c) makes the account of the person concerned an operative trigger in its own right (Tri, lived experience) — a complaint is admitted on the strength of the complainant's own account, not on proof. On sources: 'bodies authorised to access that information' and 'competent authorities' are Gov. Tes is assigned for the complainant — an on-record statement by a specific named person — and is flagged as the nearest available class rather than one the article designates in terms. ADJUDICATION 2026-08-14: this is the one entry in the pack where the evidence axis had an empty intersection, and the second pass's reading was adopted as the better grounded. v0.1 read [Dat, Tri]: Dat for the documented record of the system and its usage, Tri for the complainant's own account under point (c). Neither holds on the words. `Dat` is defined as a single large body of measured numbers, which is not what 'information about such systems and their usage is documented' describes; and point (c) creates an effective possibility to lodge a complaint, which is standing, not a rule making the complainant's account decisive. What the text does designate is the remedy and complaint procedures established in accordance with applicable law (Gui) and the reasoned account of the decision that point (b) requires to be sufficient for the affected person to contest it (Log). On values, Bed is dropped: it attached to the documentation duty of point (a), which is outside the quoted excerpt. On sources, Tes is dropped — see the entry note.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType (mixed) agreed. V reduced to the intersection [Unc, Sdt]. E had an EMPTY intersection — first pass [Dat, Tri], second pass [Gui, Log] — and the second pass was adopted as better grounded in the quoted words; Dat in particular was a category error against the AIO 00011 definition of that code. S narrowed [Gov, Tes] to [Gov], with Tes recorded as a vocabulary gap rather than replaced."
    },
    {
      "article": "Art. 15",
      "summary": "Each Party must ensure that, where an artificial intelligence system significantly impacts upon the enjoyment of human rights, effective procedural guarantees, safeguards and rights in accordance with applicable international and domestic law are available to the persons affected; and must seek to ensure that, as appropriate for the context, persons interacting with artificial intelligence systems are notified that they are interacting with such systems rather than with a human.",
      "v": [
        "Unc"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "Art. 15(2) is the provision in CETS 225 with the most direct behavioral correlate — a system disclosing that it is not human is a judgment made turn by turn, and it is testable as such. It is still classified `mixed` rather than `behavioral` because the addressee is the Party and the duty is framed as 'shall seek to ensure', qualified by 'as appropriate for the context'. The threshold in paragraph 1 — 'significantly impacts upon the enjoyment of human rights' — is left to Parties and is not defined in the treaty; an item cannot resolve it. Adjudication note: the pack no longer assigns a value code to the Art. 15(2) notification limb, which is its most behavioral correlate. The two independent formalizations split cleanly — Bed against Sdt — with the first pass having expressly rejected the code the second pass chose. The split is the finding; it is put to the RFC round, and an item written on Art. 15(2) before it is resolved would be scoring an unsettled question.",
      "provenance": {
        "sourceUrl": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
        "retrievalUrl": "https://rm.coe.int/1680afae3c",
        "article": "Article 15, paragraphs 1 and 2",
        "quote": "[Art. 15(1)] […] where an artificial intelligence system significantly impacts upon the enjoyment of human rights, effective procedural guarantees, safeguards and rights, in accordance with the applicable international and domestic law, are available to persons affected thereby. [Art. 15(2)] […] persons interacting with artificial intelligence systems are notified that they are interacting with such systems rather than with a human.",
        "rationale": "Paragraph 1 is about procedure: 'effective procedural guarantees, safeguards and rights, in accordance with the applicable international and domestic law'. What must prevail there is adherence to the prescribed process even where an outcome could be reached faster without it (Cor), in service of the rights of the persons affected (Unc). Paragraph 2 is a duty of candour owed to the person on the other side of the interaction (Bed) — the value at stake if a system lets a person believe they are speaking to a human. The evidence class is Gui throughout: both limbs are discharged by following a written rule, and neither names a metric, a case comparison or an expert. Gov is the only source class designated. Sdt was considered for paragraph 2 and not assigned: the paragraph requires notification, not the provision of reasons, and coding it as protection of the other party's reasoning would read more into the text than it says. ADJUDICATION 2026-08-14: V is reduced to the intersection [Unc], and the disagreement about paragraph 2 is recorded rather than resolved. The first pass coded the notification limb `Bed` (a duty of candour owed to the person on the other side) and expressly considered and REJECTED `Sdt` on the ground that the paragraph requires notification and not the provision of reasons. The blind second pass coded that same limb `Sdt` (protecting the person's ability to know what they are dealing with and judge accordingly) and did not declare Bed. Two independent readers thus reached opposite conclusions about which value a bare disclosure duty carries. Neither is forced by the text, so under the conservative rule neither is declared, and the question — what value does a duty to disclose that one is not human protect — goes to the RFC round. `Cor` for paragraph 1's procedural guarantees is dropped for the same reason: it was declared by one pass only.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui]), S ([Gov]) and obligationType (mixed) agreed exactly. V reduced to the intersection [Unc]: the passes disagreed head-on about the notification limb of paragraph 2 (first pass Bed, having expressly rejected Sdt; second pass Sdt), and neither reading is textually forced, so the conservative outcome was taken and the disagreement recorded as an RFC item."
    },
    {
      "article": "Art. 16",
      "summary": "Each Party must, taking into account the Chapter III principles, adopt or maintain measures for the identification, assessment, prevention and mitigation of risks posed by artificial intelligence systems by considering actual and potential impacts to human rights, democracy and the rule of law; those measures must be graduated and differentiated and must account for context and intended use, for the severity and probability of potential impacts, for the perspectives of relevant stakeholders — in particular persons whose rights may be impacted — must apply iteratively across the lifecycle, and must include monitoring, documentation and, where appropriate, testing before first use and after significant modification.",
      "v": [
        "Unc",
        "Ses"
      ],
      "e": [
        "Gui",
        "Tri"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "`organizational` outright, and the counterpart of the composite Art. 9 · Art. 72 entry in the EU AI Act pack. A risk and impact management framework is established, documented and operated by an institution; no item observes it. Art. 16(4) additionally requires each Party to assess the need for a moratorium or ban on uses it considers incompatible with human rights, the functioning of democracy or the rule of law — a decision reserved to Parties and outside both the pack and any measurement AIO performs. The Council of Europe's HUDERIA methodology and COBRA model are the elaboration of this article; they are a separate instrument and are a separate roster candidate (`coe-huderia`), not part of this pack. VOCABULARY GAP: the persons whose perspectives Art. 16(2)(c) requires to be considered have no carrier in the ten-code source hierarchy — Usr means the requester and Tes means a sworn named eyewitness. Both independent passes reached this conclusion, the second pass stating it as an explicit coverage finding. The designation is therefore carried on the evidence axis by Tri alone and the source axis stays at [Gov]. This is the same gap as at Art. 14 and it is consolidated in the pack's vocabulary-gap note.",
      "provenance": {
        "sourceUrl": "https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225",
        "retrievalUrl": "https://rm.coe.int/1680afae3c",
        "article": "Article 16, paragraph 1 and paragraph 2 (chapeau and point c)",
        "quote": "[Art. 16(1)] Each Party shall, taking into account the principles set forth in Chapter III, adopt or maintain measures for the identification, assessment, prevention and mitigation of risks posed by artificial intelligence systems by considering actual and potential impacts to human rights, democracy and the rule of law. [Art. 16(2)] Such measures shall be graduated and differentiated, as appropriate, and: […] c consider, where appropriate, the perspectives of relevant stakeholders, in particular persons whose rights may be impacted […]",
        "rationale": "Paragraph 1 states its protected interests in terms and they are coded from those words alone: 'human rights' gives Unc, 'democracy and the rule of law' gives Ses. Sep is deliberately NOT assigned — unlike Regulation (EU) 2024/1689, which routes through 'health or safety, or fundamental rights', Art. 16(1) names neither health nor safety, and the rule is that a value is coded only where the provision protects it. On evidence, three classes are grounded in paragraph 2 and cited here from provisions outside the excerpt above: point (b) requires account to be taken of 'the severity and probability of potential impacts' and point (e) requires monitoring, both of which run on measurement (Dat); point (f) requires documentation of risks, impacts and the risk management approach, and point (g) requires testing before first use and after significant modification, which are discharged against a written procedure (Gui); point (c), quoted above, requires the perspectives of persons whose rights may be impacted to be considered, which admits their firsthand accounts (Tri). On sources, Gov is the Party operating the framework; Tes is assigned for the affected stakeholders whose perspectives point (c) requires to be considered, and is flagged as the nearest available class rather than one the article names. ADJUDICATION 2026-08-14: Dat, Tes and the second pass's Unt are not carried into v0.2. Dat rested on points (b) and (e) of paragraph 2, which the first pass cited from outside its own quoted excerpt; under §4 the entry is coded from the text it quotes. Unt was declared by the second pass only for the stakeholder-perspectives limb, which is already carried on the evidence axis by Tri — a code both passes reached from the same words — so it is not doubled onto the value axis. Tes is removed for the same reason as at Art. 14: affected stakeholders have no source class in AIO 00011 and the nearest one does not fit.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType (organizational) agreed exactly, as did the core of V and E. V reduced to the intersection [Unc, Ses] (the second pass's Unt dropped as a doubling of the Tri designation); E reduced to the intersection [Gui, Tri] (Dat dropped as grounded outside the quoted excerpt); S narrowed [Gov, Tes] to [Gov], with Tes recorded as a vocabulary gap."
    }
  ],
  "itemBankRef": {
    "publicSet": null,
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "CETS No. 225 is a treaty. Its obligations run to the Parties — States and, since 15 May 2026, the European Union — which discharge them through national or Union implementing measures. They do not run to the developers, providers or deployers of artificial intelligence systems, and Art. 3(1) reaches private actors only indirectly: directly where they act on behalf of public authorities, and otherwise through whatever route each Party declares under Art. 3(1)(b). Nothing in this pack measures a Party's implementation, and nothing in it could. What AIO items measure against this pack is the judgment direction each principle implies for an artificial intelligence system operating under an implementing Party's jurisdiction — whether a model's reasoning tracks the normative direction of, for example, Art. 8 on transparency and oversight or Art. 14 on remedies. They do not assess whether an organization operates the management-system correlates of those principles (risk and impact management under Art. 16, documentation, oversight mechanisms, complaint channels), and they are not evidence of any Party's compliance with the treaty.",
  "notes": [
    "Treaty status, verified against the Council of Europe Treaty Office chart of signatures and ratifications on 2026-08-14 (status line on the chart: 'Status as of 14/08/2026'): 21 signatures in total, 1 ratification, and the Convention is NOT YET IN FORCE. Entry into force requires 5 ratifications including at least 3 Council of Europe member States; the treaty detail page shows the entry-into-force field empty against that condition. The single instrument deposited is the European Union's approval of 15 May 2026. Signatories not yet followed by ratification (20): Albania, Andorra, Armenia, Bosnia and Herzegovina, Georgia, Iceland, Liechtenstein, Montenegro, North Macedonia, Norway, Republic of Moldova, San Marino, Switzerland, Ukraine and the United Kingdom among Council of Europe member States; and Canada, Israel, Japan, the United States of America and Uruguay among non-member States. The non-European signatures — the United States and Israel on 5 September 2024, Canada and Japan on 11 February 2025, Uruguay on 2 September 2025 — are the treaty's claim to global reach; none of them is a ratification, and a signature does not bind. Any general claim that this Convention 'entered into force in 2025' is wrong as at the date of this pack; several secondary sources say so and the primary chart does not.",
    "States-addressed caveat. Every provision mapped here begins 'Each Party shall'. The Convention is a framework instrument: Art. 1(2) has each Party 'adopt or maintain appropriate legislative, administrative or other measures to give effect to the provisions', graduated and differentiated by the severity and probability of adverse impacts, and Art. 6 has the Chapter III principles implemented 'in a manner appropriate to its domestic legal system'. The concrete duties an organization will actually face are therefore created by national or Union implementing measures, not by this treaty text. The European Union's declaration of 15 May 2026 under Art. 3(1)(b) states that it will apply the principles and obligations of Chapters II to VI to private actors placing on the market, making available and using AI systems in the Union through the implementation of Regulation (EU) 2024/1689 — so for an operator in the Union the operative instrument is the EU AI Act, and the `eu-ai-act` pack, not this one. Norway and Ukraine have also filed Art. 3(1)(b) declarations. Because the addressee is a Party, no entry in this pack is classified `behavioral`: after the v0.2 adjudication, seven are `mixed` and Arts. 12 and 16 are `organizational` (v0.1 had eight and one; Art. 12 moved).",
    "Dual formalization complete, `draft-verified`. Every entry carries a verbatim excerpt of the official English text and a rationale argued from it, and as of 2026-08-14 the second independent formalization required by FORMALIZATION_METHODOLOGY.md §5 has been carried out and adjudicated. The second pass was blind: it read the pack id, the sourceNorm and each entry's provenance.article, sourceUrl, retrievalUrl and quote, and nothing else — v0.1's codes, summaries, rationales, obligationType tags and notes were stripped before any file was opened, and the management guides were not opened. Human review is still pending and the RFC round at https://aioq.org/en/rfc follows. Certificates issued against this pack carry a draft-basis notice.",
    "Quote verification method. The official English text was retrieved on 2026-08-14 as PDF from https://rm.coe.int/1680afae3c, which is the endpoint the Treaty Office detail page for CETS No. 225 links as 'Official Texts — English'. Every quoted string in this pack was then checked, character for character ignoring whitespace, against two independent official manifestations: that English PDF, and the certified bilingual copy at https://rm.coe.int/1680b680bc (the 'Certified copy of the Convention in its corrected version in accordance with the Committee of Ministers' decision, 1527th meeting of the Ministers' Deputies, 30 April 2025'). All 25 checked strings matched in both. Note that the 30 April 2025 correction was to the FRENCH text — the certified copy states 'French text corrected in accordance with the Committee of Ministers' decision' — so the English wording used here is unaffected by it. No commentary, summary, mirror or secondary source was used for any quote.",
    "Reuse terms, as the Council of Europe states them. The Council of Europe's copyright, licensing and permissions page records, under the heading 'Official texts': 'No permission is required to reproduce and translate official texts (conventions and treaties, Committee of Ministers resolutions and recommendations) which are in the public domain', subject to proper credit; and separately that 'No permission is required for the use of excerpts containing less than 500 words.' Quotation in this pack is nevertheless kept to short verbatim excerpts with per-entry provenance, as AIO provenance practice requires regardless of licence. Credit, in the form the Council of Europe asks for: from the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225), opened for signature at Vilnius on 5 September 2024. Source: Council of Europe 2024. One further caveat the Council of Europe itself publishes on its disclaimer page and which is recorded here rather than suppressed: 'It is not possible to guarantee that a document available on line faithfully reproduces an officially adopted text, because it does not constitute an official publication.'",
    "Non-endorsement. AIO wrote this formalization. The Council of Europe, its Committee of Ministers, its Secretariat and the Committee on Artificial Intelligence took no part in it, have not reviewed it, and have not endorsed it. AIO certifies conformance to AIO's own formalization of this Convention. That is not a legal assessment, not an assessment of any Party's compliance, and confers no status of any kind under the Convention or under any implementing measure.",
    "Selection. Nine of the Convention's substantive provisions are mapped — Arts. 7, 8, 9, 10, 11, 12, 14, 15 and 16 — chosen as those bearing on judgment, oversight, transparency, accountability and remedies. Art. 13 (Safe innovation) was considered and excluded from this seed: it asks a Party to enable controlled environments for developing, experimenting and testing under the supervision of its competent authorities, is hortatory in form ('each Party is called upon to enable, as appropriate'), and has no judgment correlate an AIO item could test. Chapters VI and VII (Arts. 17 to 25 — non-discrimination in implementation, rights of persons with disabilities and of children, public consultation, digital literacy, safeguards, the Conference of the Parties, reporting and international co-operation) are addressed to Parties as institutions and are outside the seed for the same reason. Both are proposed for reconsideration at the RFC round.",
    "No item bank. `itemBankRef.publicSet` is null: no scenario items have been written for this pack, so it currently backs no certificate at any tier. Item authoring follows verification, not the other way round.",
    "Methodology for the article → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md. V/E/S values are the canonical three-letter AIO 00011 codes served at /api/framework/vocabulary. v0.1 marked inference-grade codes in the entries for Arts. 7, 8, 10, 11, 12, 14 and 16. The v0.2 adjudication REMOVED all of them except two, and those two survive only because both independent passes reached them and because both are symptoms of a vocabulary gap rather than of loose reading: `Unc` for 'human dignity' at Art. 7 and `Sep`+`Sda` for 'privacy' at Art. 11. Removed were Ses at Art. 8, Unt and Dat at Art. 10, Dat at Art. 12, Dat and Tri and Tes at Art. 14, and Dat and Tes at Art. 16.",
    "Adjudication method (v0.2). The pack was formalized twice — the v0.1 seed pass and a blind second pass — and the two results were compared mechanically, entry by entry and layer by layer, with v, e and s treated as sets. Exact agreement was auto-accepted. Divergences were adjudicated under a fixed policy: the reading better grounded in the quoted text prevails under FORMALIZATION_METHODOLOGY.md §4; where both readings are defensible the more conservative is taken (fewer codes, or a layer left undeclared); the intersection of the two readings is an allowed outcome where it is non-empty and defensible; no third reading is invented. Agreement statistics for this pack, across nine entries: V 2/9, E 4/9, S 7/9, obligationType 8/9, all four axes together 2/9 (Arts. 9 and 11). This was the highest full-agreement rate in Wave 1. The systematic pattern is again that v0.1 declared more codes than the quoted text carries; the one axis where the second pass's larger reading was preferred is the evidence axis of Art. 14.",
    "Addressee policy (P4, decided once and applied uniformly). The blind second pass raised the question directly: every obligation in this Convention binds States, not the providers or deployers of AI systems, so on a strict reading of the form of the duty almost every entry would be `organizational` and the divergence would be systematic rather than per-article. The adjudication settled it in favour of the substance of the measures rather than the form of the duty, consistently with what this pack's own `measurementScope` already says it measures: an entry is `mixed` where the measures a Party must adopt regulate lifecycle judgment, so that a judgment correlate exists on the system side that an item could test; it is `organizational` where the measures are purely institutional machinery — a risk and impact management regime (Art. 16), a lifecycle quality and security regime (Art. 12) — with no lifecycle-judgment direction stated. No entry can be `behavioral`, because the form of every duty here is legislative. That is the whole of the rule, it is applied to all nine entries, and it is the reason Art. 12 moved from `mixed` to `organizational` at adjudication.",
    "Source-axis policy (P4, decided once across the Wave 1 packs and applied uniformly). S=`Gov` is declared only where the quoted excerpt itself names the governmental authority or the legal instrument that is decisive on the substance of the duty; it is never carried in from the pack's context, from the issuing body, or from a provision outside the excerpt. In this pack that rule leaves `Gov` on all nine entries, and unlike the NIST pack's uniform `Ind` the uniformity here is textually forced: every article is addressed to 'Each Party' and several route expressly through 'applicable international and domestic law' or 'competent authorities'. Both independent passes reached [Gov] on seven of nine entries and the two divergences were the removal of `Tes`, not a dispute about `Gov`. The uniformity nevertheless gives the source axis no discriminating power across this pack, which is carried to the RFC round as a single question rather than nine.",
    "Vocabulary gaps found by the dual formalization (feeding a future AIO 00011 RFC). This pack contributes three, and they are the reason two inference-grade codes were kept rather than dropped. (1) HUMAN DIGNITY (Art. 7) — the value layer, derived from Schwartz's refined theory, has no dignity code. Both passes routed it to `Unc`; the second pass noted that `Hum` or `Coi` are also arguable. Kept as a flagged stopgap. (2) PRIVACY AND PERSONAL DATA (Art. 11) — no code either. Both passes routed it to `Sep` for the protective limb and `Sda` for the self-determination limb, and the second pass called it the weakest routing in its set. Kept as a flagged stopgap. The same gap appears at 第九条 and 第十一条 of the Chinese pack. (3) AFFECTED PERSONS AND COMPLAINANTS AS A SOURCE CLASS (Arts. 14(2)(c) and 16(2)(c)) — the ten-code source hierarchy has no carrier: `Usr` is the requester of the service and `Tes` is a sworn named eyewitness. Here the gap was NOT papered over: v0.1's `Tes` was removed and the layer left at [Gov], because only one pass declared it. A fourth gap, INFORMATION INTEGRITY, is recorded at Art. 8. The consolidated Wave 1 list is reproduced in the adjudication report."
  ]
}
