AI Act vs CoE Convention: what they share and how they differ

AI Act and CoE Convention share 7 of 24 control themes and 5 checks. 60% of CoE Convention requirements can be proven with checks AI Act already uses, 12% the other way round.

EURegulationPhasing in

AI Act

How to make an AI system compliant with the EU AI Act

33 requirementsNext Aug 2, 2027
CoETreatyAdopted, not yet applicable

CoE Convention

What the Council of Europe AI Convention requires

5 requirementsNext 2027
7/24shared control themes
5shared checks
60%of CoE Convention requirements covered by AI Act evidence
12%of AI Act requirements covered by CoE Convention evidence

At a glance

AI Act CoE Convention
JurisdictionEuropean UnionCouncil of Europe
KindRegulationTreaty
StatusPhasing inAdopted, not yet applicable
BindingYes sameYes same
Object analysedAI system sameAI system same
ScopeProviders, deployers, importers and distributors of AI systems; providers of GPAI models.Public authorities; private sector at each state's choice.
Territorial reachExtraterritorial: applies when the system is placed on the EU market or its output is used in the EU.State parties.
PenaltiesUp to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information).Depends on national implementation.
Qualification axesAI Act risk level, Organisation role, General-purpose modelSector
RolesProvider, Deployer, GPAI providerPublic authority, Private actor
Requirements335
Next milestoneAug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 20252027, Entry into force after 5 ratifications incl. 3 member states

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

5

CodeCheckRequirements AI ActRequirements CoE Convention
VER-003-01Documented and up-to-date risk register
VER-018-D-01Persons informed of the interaction with an AI system
VER-018-D-03AI-generated content marked as such
VER-020-D-01FRIA carried out in accordance with Art. 27
VER-033-D-01Decision explanation procedure documented

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

AI Act

29

EX-001
EX-005
Technical documentation Art. 11 + Annexe IV
EX-008
EX-010
QMS Art. 17
EX-011
EX-013
EX-014
Cooperation with authorities Art. 21 + Art. 26§12
EX-016
CE marking Art. 48
EX-019
DPIA Art. 26§9
EX-023
Accessibility Art. 16(l)
EX-024
EX-026
Value chain Art. 25
EX-027
Compliant use Art. 26§1
EX-028
Input data Art. 26§4
EX-031

CoE Convention

2

Timelines

PastSet in the textPotentialTo verify
Apr 21, 2021AI Act · Commission proposal
May 17, 2024CoE Convention · Adopted by the Committee of Ministers
Jul 12, 2024AI Act · Published in the Official Journal
Aug 1, 2024AI Act · Entry into force
Sep 5, 2024CoE Convention · Opened for signature (Vilnius)
Nov 28, 2024CoE Convention · HUDERIA methodology adopted
Feb 2, 2025AI Act · Prohibited practices (Art. 5) and AI literacy (Art. 4)
Jul 10, 2025AI Act · GPAI Code of Practice published
Aug 2, 2025AI Act · GPAI obligations, governance, penalties, notified bodies
Nov 19, 2025AI Act · Digital Omnibus proposal: high-risk delay tied to standards
Aug 2, 2026AI Act · General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay)
2027CoE Convention · Entry into force after 5 ratifications incl. 3 member states
Aug 2, 2027AI Act · Annex I high risk (regulated products); GPAI placed on the market before Aug 2025
Dec 2, 2027AI Act · Omnibus backstop for Annex III high risk
Aug 2, 2028AI Act · Omnibus backstop for Annex I high risk
Aug 2, 2030AI Act · High-risk systems of public authorities already in service (Art. 111)

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo