GovCompass

The OECD AI Principles: the reference point the other layers cite

By Michel Venniker· Last updated August 2026

The OECD AI Principles are the first intergovernmental standard on AI, adopted in May 2019 and updated in May 2024, with 47 adhering jurisdictions including the European Union. They consist of five values-based principles for AI actors and five recommendations for policymakers. They are not law, not certifiable, and not a management system: they are the shared reference point that the EU AI Act, national AI strategies, and international frameworks build on. The OECD classification framework for AI systems, published in 2022, is the practical instrument that operationalizes them.

Status of time-bound facts in this article: 1 August 2026.

What the principles are

The OECD Council adopted the Recommendation on Artificial Intelligence in May 2019, making it the first AI standard endorsed at intergovernmental level. The G20 AI PrinciplesprincipleOne of the seven responsible-AI values a governed system should live up to (fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, human oversight). A principle is abstract: it states an outcome, not a lever you can pull. It becomes governable by naming the harm that would breach it, assessing the risk that harm carries, and placing controls against that risk. Held this way, a principle becomes a pillar. See pillar, harm, risk.Open full entry → that followed drew directly on it. In May 2024 the adherents updated the text to address general-purpose and generative AIgenerative AIAI systems that produce new content (text, images, audio, code) rather than only classifying or predicting. Large language models are the prominent example.Open full entry →, with sharper attention to safety, privacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry →, intellectual property, and information integrity. As of the 2024 update, 47 countries and jurisdictions adhere, including every OECD member and the European Union.

The recommendation has two halves. Five values-based principles address anyone who develops, deploys, or operates AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry →: inclusive growth, sustainable development and well-being; respect for human rights and democratic values, including fairnessfairnessThe responsible-AI principle that systems should not create or reinforce unjust discrimination; operationalized through bias testing, representative data and per-group thresholds. It has multiple, mutually incompatible mathematical definitions. Under the EU AI Act, providers of high-risk AI systems must examine their data sets for possible biases (Article 10), and several discriminatory uses are prohibited outright (Article 5). See bias, proxy discrimination, high-risk AI system, responsible AI.Open full entry → and privacy; transparency and explainabilitytransparency and explainabilityThe principle that people can know an AI system is involved and can be told why it produced a given outcome. The failure is concrete rather than abstract: it arrives on the day a customer, a supervisor, or a court asks for the reasoning, and "the model decided" turns out to be the absence of an explanation rather than one. The EU AI Act separates the two directions: Article 13 requires high-risk systems to be transparent enough for the deployer to interpret and use their output, and Article 50 requires people to be informed when they interact with AI or receive AI-generated content. See model card, responsible AI.Open full entry →; robustnessrobustnessA system's ability to perform reliably under realistic conditions including noise, edge cases and adversarial pressure, the engineering core of the safety-and-reliability principle.Open full entry →, security and safety; and accountabilityaccountabilityThe principle that a named human or organization answers for an AI system's outcomes, through ownership, documentation, audit trails and redress; never the system itself. The EU AI Act attaches obligations to the role rather than the technology, with provider duties in Article 16 and deployer duties in Article 26, supported by technical documentation (Article 11) and record-keeping (Article 12). See provider, deployer, record-keeping, responsible AI.Open full entry →. Five recommendations address governments: invest in AI research and development, foster an inclusive AI ecosystem, shape an enabling and interoperable policy environment, build human capacity and prepare for labor market transition, and pursue international cooperation.

The principles are deliberately non-binding. Adherence is a political commitment, not a legal obligation, and each jurisdiction translates the principles into its own framework at its own pace. That flexibility is the design, not a weakness: it is what allowed 47 different legal systems to commit to one text.

Why they matter more than their legal weight suggests

For a non-binding text, the principles have unusual downstream force, and it arrives through three channels.

The definition channel is the most concrete. The OECD updated its definition of an AI system in December 2023, and the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → aligned the definition in Article 3(1) with it. When a European organization determines whether something is an AI system at all, the words it applies trace back to the OECD. The same definition anchors interoperability between jurisdictions: a system classified as AI in one adhering country is, by design, classified the same way elsewhere.

The vocabulary channel runs through every framework in this section. The trustworthiness language of the NIST AI RMFNIST AI RMFThe AI Risk Management Framework of the US National Institute of Standards and Technology, published as version 1.0 in 2023. It is a voluntary framework built around four functions: govern, map, measure, and manage. In a layered setup, it serves as the risk method inside a management system such as ISO/IEC 42001. See ISO/IEC 42001, ISO/IEC 23894.Open full entry →, the responsible AIresponsible AIThe set of principles an AI system should live up to: fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, and human oversight. Widely shared and sitting under the EU AI Act and the major frameworks. On their own the principles are statements of intent; the law turns them into duties that cannot be met unless they are carried inside the organization's governance, which is how responsible AI lands in governance rather than beside it. The seven principles are organized into seven pillars, one pillar per principle. See principle, pillar, governance. The seventh principle carries two names in practice: human oversight in the seven-pillar model, and human-centricity in the IAPP AIGP body of knowledge; the substance overlaps.Open full entry → principles that ISO/IEC 42001ISO/IEC 42001The international requirements standard for AI management systems, published in 2023 and certifiable. It defines how an organization establishes, implements, maintains, and continually improves a management system for AI. Certification against ISO/IEC 42001 does not create a legal presumption of conformity with the EU AI Act. See AI management system, harmonized standard.Open full entry → asks an organization to adopt, and the seven pillarspillarA responsible-AI principle as something an organization actively holds rather than merely endorses: one of the seven pillars of responsible AI, one per principle. A pillar is held, not implemented, by naming the harms that would breach the principle, assessing their risk, and placing controls that reduce it. Distinct from agentic AI, which is not one of the seven but a condition that changes how all of them are governed. See principle, harm, risk, agentic AI.Open full entry → this site uses all speak recognizable dialects of the same five principles. The OECD text is where that vocabulary was first agreed at government level.

The policy channel is the OECD.AI Policy Observatory, which tracks how adherents implement the principles. By early 2024 it recorded over 850 AI policy initiatives, and mapping national AI strategies against the five recommendations shows most jurisdictions building along the same lines. For an organization operating across borders, the principles are the closest thing to a common denominator of what regulators everywhere will expect.

The classification framework: the instrument behind the principles

Principles need an instrument, and the OECD published one in February 2022: the Framework for the Classification of AI Systems. It assesses any AI system along five dimensions: people and planet, economic context, data and input, AI model, and task and output.

Each dimension asks questions an assessor can answer. Who is affected and how (people and planet). In which sector, for which business function, with which criticality (economic context). What data, collected how, with which provenanceprovenanceThe documented origin and history of data or content, used to establish where it came from and whether it can be trusted or lawfully used.Open full entry → (data and input). What kind of model, learned or programmed, with which degree of autonomy (AI model). What the system does with its output, and how much human involvement remains (task and output).

The framework does two jobs. For policymakers, it makes riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry →-based regulation possible: you cannot regulate by risk without a shared way to describe systems, and the EU AI Act's high-risk logic is a legislated cousin of this classification thinking. For organizations, it is a ready-made intake structure: an AI inventoryAI inventoryA register of all AI systems an organization builds, buys or embeds, with owners and risk tiers. It is the prerequisite for governing any of them.Open full entry → that records the five dimensions per system answers most of the context questions that a risk assessment under any framework starts with. Classification is the step before risk management, and skipping it is why many AI risk registersrisk registerThe living record of an AI system's identified risks, ratings, responses, owners and review dates, kept current from design through retirement.Open full entry → describe risks no one can trace to a system.

What the principles do not do

No certification exists against the OECD AI PrinciplesOECD AI PrinciplesThe intergovernmental principles for trustworthy AI adopted by the OECD in 2019 and updated in 2024. They set value-based expectations such as transparency, accountability, and human-centered values, and have shaped later frameworks and legislation. See responsible AI.Open full entry →, and no organization can be OECD-compliant: the recommendation addresses governments and AI actors as a policy standard, not as an auditable requirement set. Training providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → may issue course certificates about the principles, which record learning, not conformity.

The principles also set no obligations, no deadlines, and no penalties. An organization looking for what it must do looks to the EU AI Act; an organization looking for an auditable structure looks to ISO/IEC 42001; an organization looking for a risk method looks to the NIST AI RMF. The principles sit above all three as the reference point they share, and their practical use inside a company is exactly that: the common language for board-level AI commitments that the operational layers then have to make demonstrable.

Continue reading

Frequently asked questions

Are the OECD AI Principles legally binding?
No. They are an intergovernmental recommendation. Adherence is a political commitment that jurisdictions implement through their own laws and policies.
Can an organization be certified against the OECD AI Principles?
No. No certification scheme exists. Course certificates about the principles record training, not conformity.
What changed in the 2024 update?
The adherents revised the principles to address general-purpose and generative AI, with more direct attention to safety, privacy, intellectual property rights, and information integrity. The update followed the December 2023 revision of the OECD definition of an AI system.
How do the principles relate to the EU AI Act?
The Act's definition of an AI system in Article 3(1) aligns with the OECD definition, and the Act's risk-based approach builds on the classification thinking the OECD developed. The principles inform the law; they are not part of it.
What is the OECD classification framework?
A 2022 instrument that describes any AI system along five dimensions: people and planet, economic context, data and input, AI model, and task and output. It operationalizes the principles and gives organizations a ready structure for AI inventories and intake assessments.
Legal referencesArt. 3
Continue withAccountability
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.