Skip to main content
v2026.11,858 entries · CC-BY 4.0

The Council of Europe HUDERIA Methodology and Model: What It Asks For, and What It Explicitly Is Not

HUDERIA’s four elements, COBRA’s four steps and three contexts, the avoid-mitigate-restore-compensate hierarchy, and the Council of Europe’s own statement that it is not a means for implementing CETS 225.

Written and maintained by CASRAI Editorial Board

Last updated

HUDERIA is the Council of Europe’s methodology for assessing the risks and impacts of AI systems on human rights, democracy and the rule of law — and the one thing its own text is most insistent about is what it is not. It is not mandatory, it is not an interpretative aid for the Council of Europe’s AI treaty, and, in the wording added when the second half of it was approved in 2026, it “is not a means for implementing the Framework Convention”. This page walks the instrument itself: the four elements, the four COBRA steps, the four risk variables, the four-level mitigation hierarchy — and the scoring method it pointedly declines to specify. Because HUDERIA footnotes that its own “probability” is called “likelihood” elsewhere and its “reversibility” is called “remediability” elsewhere, it lands directly on the terminology problem CASRAI’s own NIKOLAI dictionary tracks in its Likelihood Term element.

  • Full name: HUDERIA — Methodology and Model (HUDERIA = Human Rights, Democracy and the Rule of Law Impact Assessment)
  • Issued by: the Council of Europe’s Committee on Artificial Intelligence (CAI), approved by the Committee of Ministers
  • Methodology: adopted by the CAI 28 November 2024; approved by the Committee of Ministers 26 February 2025
  • Model (COBRA Resources): adopted by the CAI 5 November 2025; approved by the Committee of Ministers 25 February 2026
  • Consolidated volume: HUDERIA — Methodology and Model, Council of Europe Publishing, 2026 (ISBN 978-92-871-9692-7)
  • Legal status: stand-alone, non-legally binding, no legal effect, not mandatory
  • Relationship to CETS 225: facilitative only — explicitly not an interpretative aid and not an implementation mechanism
  • Four elements: COBRA, Stakeholder Engagement Process, Risk and Impact Assessment, Mitigation Plan, plus a standing Iterative Review
  • Scoring method prescribed: none

Where HUDERIA came from, and the chronology that most coverage stops short of

HUDERIA’s lineage runs back before the treaty it is usually discussed alongside. The consolidated volume records that it originated in the work of the Ad Hoc Committee on Artificial Intelligence (CAHAI, 2019-2021) and specifically its Policy Development Group, which mandated the Alan Turing Institute — the UK’s national institute for data science and AI — to prepare “an original proposal operationalising the outline for a model for a human rights, democracy and the rule of law impact assessment”.

The instrument then arrived in two halves, several years apart:

  • 28 November 2024 — the Committee on Artificial Intelligence (CAI) adopts the HUDERIA Methodology, the high-level, technology-neutral half.
  • 26 February 2025 — the Committee of Ministers approves the Methodology.
  • 5 November 2025 — the CAI adopts the HUDERIA Model: Context-Based Risk Analysis (COBRA) Resources, the implementable half.
  • 25 February 2026 — the Committee of Ministers approves the Model.
  • 2026 — Council of Europe Publishing issues the two halves as a single volume, HUDERIA — Methodology and Model.

That second pair of dates is the part worth checking any summary against. A great deal of third-party writing about HUDERIA was produced in the window between the November 2024 adoption and the November 2025 one, and describes the Model as still forthcoming. It is not forthcoming; it exists, it has a defined scope, and its scope is narrower than the placeholder descriptions suggested — see the section on COBRA Resource D below.

The dates also matter because “adopted” and “approved” are different acts by different bodies here. The CAI adopts; the Committee of Ministers approves. Neither act makes HUDERIA binding on anyone, which the text says in terms.

The four elements, and the review that never closes

The HUDERIA Methodology sets out four elements. In the volume’s own framing:

  1. Context-based risk analysis (COBRA) — “a structured approach to collecting and mapping the information needed to identify and understand the risks the AI system could pose”, and an initial determination of whether an AI system is even an appropriate solution to the problem in hand.
  2. Stakeholder engagement process (SEP) — an approach to engaging relevant stakeholders “in order to gain information regarding potentially affected persons and contextualise and corroborate potential harm and mitigation measures”. Note that the Methodology’s SEP footnotes point to supporting resources that have not yet been developed; CASRAI’s companion page on the parts of the HUDERIA Model that are not yet adopted tracks which pieces exist and which are still on a deadline.
  3. Risk and impact assessment (RIA) — possible steps for assessing the risks and impacts identified.
  4. Mitigation plan (MP) — possible steps for defining mitigation and remedial measures, including access to remedies.

Sitting across all four is the iterative review: a standing obligation to keep reassessing rather than a fifth stage bolted on the end. The Methodology deliberately does not fix “the exact modalities, thresholds, triggers, and monitoring and governance mechanisms” for it. What it offers instead is a set of principles: that continual review is pivotal to the process’s efficacy; that a plan is established for monitoring impacts and reassessing “during each phase of the project’s life cycle up to system retirement or decommissioning”; that review should stay responsive to how the system actually interacts with its operating environment, including “the emergence of new forms of system misuse”; and that rapidly changing contexts may warrant more frequent reassessment.

One structural point that is easy to miss: the four elements are not a fixed pipeline. The text says that while “it is logical to carry out the COBRA element first”, an organisation may change the sequence, or apply only parts of the methodology, depending on its existing AI governance approaches and its own context, needs and capabilities. HUDERIA is written to be raided, not just followed.

COBRA: four steps, three contexts, five resources

COBRA is the element the 2025-26 Model actually fleshes out, and it is the most concrete part of the instrument. It runs in four steps:

  1. Preliminary scoping — carried out, as appropriate, by a multidisciplinary team of experts with complementary specialisations and both technical and non-technical backgrounds.
  2. Analysis of risk factors — collecting information about risk factors across three distinct contexts (below).
  3. Mapping of potential impacts on human rights, democracy and the rule of law — identifying potentially affected persons or groups and making the initial assessment of the key risk variables.
  4. Triage — deciding how much of the rest of HUDERIA is warranted, and whether the system should be built or deployed at all.

The risk factors themselves are sorted into three contexts, which is HUDERIA’s main analytical move and the reason it calls itself socio-technical rather than technical:

  • The application context — the system’s sector and domain, and the legal and regulatory environment it will operate in.
  • The design and development context — how the system was actually built.
  • The deployment context — “factors that govern how potential risks may manifest and be managed in practice”, such as privacy and data protection steps, bias mitigation, training, guarding against unintended uses, and accountability and legal compliance.

Each context has a corresponding COBRA Resource in the Model: Resource A for application-context risk factors, Resource B for design and development, Resource C for deployment. Two further resources are illustrative rather than procedural: Resource E lists areas of potential concern from the point of view of human rights, democracy and the rule of law, mapped against provisions of the ECHR, the ICCPR, the EU Charter, Convention 108+, the UNCRC and the Pact of San Jose; Resource F lists sectors and domains with their potential areas of concern.

There is no Resource D. That is not a numbering accident: the volume footnotes that the CAI “considered the possible inclusion of a COBRA Resource D” and left it out, “without prejudice to any future decision on its inclusion”. It is also worth being clear about what the Model therefore covers. Its full heading in the book is “Resource model for context-based risk analysis (COBRA)”, and its contents go exactly that far — it is a resource set for the first of the Methodology’s four elements, not for all four. CASRAI’s companion page on the four-fifths of the HUDERIA Model not yet adopted sets out the full deliverable register, including the numbered Components still in drafting.

Triage, and the “zero questions”

Triage has two stated purposes. The first is proportionality — “to facilitate the task of identifying and triaging systems that pose significant risk, so that the HUDERIA Methodology is not onerous for minimal or low-risk AI systems”. The second is more consequential: an initial determination of whether the system should be developed or deployed at all, based on whether its benefits outweigh its risks, “as well as whether the use of the AI system is incompatible with respect for human rights, democracy and the rule of law”.

That determination is supported by what the text calls the zero questions — a prompt set asking whether the benefits of building or deploying the system, including social benefits beyond its primary purpose, outweigh the risks identified, and whether use of the system is appropriate given the nature of the problem it is aimed at. The Mitigation Plan stage explicitly offers “an opportunity to revisit the zero questions”, which is the mechanism by which a HUDERIA process can conclude, late, that the answer is no.

Triage is also where COBRA can legitimately terminate the whole exercise early. If the information gathered shows the system is unlikely to have any impact on human rights, democracy or the rule of law — or that the identified impacts are insignificant or unlikely — the subsequent elements are, in the text’s own word, “unnecessary”.

The four risk variables, and what “severity” is defined to mean

HUDERIA indexes risk on four variables: scale, scope, reversibility and probability. The definition that matters is how the first three combine. A footnote in the Methodology states that, “following the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, the United Nations Office of the High Commissioner for Human Rights and the United Nations Guiding Principles on Business and Human Rights, for the purposes of HUDERIA the term ‘severity’ is understood to be composed of a combination of the variables of scale, scope, and reversibility.”

So severity is a composite, not a primitive, and probability sits outside it. That is a deliberate inheritance from business-and-human-rights practice rather than from engineering risk management, and it is one of the clearest points of divergence from the risk vocabularies used in the NIST AI RMF and ISO/IEC 42001, where severity and likelihood are more typically treated as two independent axes of a matrix. Anyone maintaining an AI risk register that already carries severity and likelihood columns should expect HUDERIA’s severity to mean something structurally different from theirs.

The volume also adds two terminology footnotes that are unusually candid for a standards-adjacent document: the term “reversibility” “may sometimes be referred to as ‘remediability’ in risk-assessment contexts”, and the term “probability” “may sometimes be referred to as ‘likelihood’ in risk-assessment contexts”. The Council of Europe is telling readers, in the text itself, that its words have synonyms in neighbouring frameworks and that the mapping is theirs to do.

The scoring method HUDERIA declines to specify

This is the part most likely to surprise anyone expecting a risk matrix. HUDERIA sets out four variables and then does not tell you how to combine them. The text says only that “consideration may be given to establishing a method for combining these variables to enable the calibration of risk”, that this “may involve the formulation of quantitative or semi-quantitative methods of risk calculation, risk matrices or more qualitative or rules-based procedures”, and that “the final determination of whether to use a qualitative, quantitative, mixed or any other method is left to the discretion of the authorities or, where applicable, the AI project teams responsible for the system”.

It offers two calibration considerations rather than a formula: in human-rights terms, weigh both low-scope/high-gravity and high-scope/low-gravity effects on each affected person; in democracy and rule-of-law terms, weigh high-scope and long-lasting effects on persons, institutions and society in general. And it is explicit that “HUDERIA does not prescribe detailed guidance for adjusting risk-management efforts, but simply sets out proposed elements that may be applied as appropriate”.

The practical consequence is that two organisations can both run HUDERIA faithfully and produce non-comparable risk ratings. That is a design choice consistent with the instrument’s non-binding character — but it means HUDERIA is not, and does not claim to be, a source of cross-organisational comparability.

The mitigation hierarchy: avoid, mitigate, restore, compensate

The Mitigation Plan offers a four-level structured approach it calls the mitigation hierarchy: avoid, mitigate, restore, compensate.

  • Avoid — changes to the design, development or deployment processes, or to the system itself, made at the outset to avoid adverse impact. The text adds a pointed caveat: “avoid does not equate to ignoring potential negative impacts”.
  • Mitigate — actions in those same processes, or changes to the system, to minimise adverse impact.
  • Restore — restoration where impact has already occurred.
  • Compensate — compensation or remuneration for harm suffered.

The hierarchy is time-indexed to the life cycle. Early on, when impacts have not yet occurred, avoid and mitigate are the relevant options; in later iterations, during deployment, restore and compensate become relevant alongside them, and more than one option may apply at once — the example given is an affected individual needing rehabilitation while immediate actions are also taken to minimise further harm. The ordering is normative, not merely descriptive: “choices made to avoid and mitigate adverse impacts should be preferred to choices to compensate or remunerate potentially impacted persons for any harm suffered”.

One limit the text is careful about: it notes that “the availability and effectiveness of legal remedies, including restoration or compensation as legal remedies, are determined by applicable international and domestic law”. HUDERIA can tell you restoration is preferable to compensation; it cannot create a remedy that domestic law does not provide.

What HUDERIA is explicitly not — and the sentence added in 2026

The single most commonly mis-stated thing about HUDERIA is its relationship to the Council of Europe Framework Convention on AI (CETS 225). It is frequently described as the treaty’s implementation mechanism or its risk-assessment annex. The instrument’s own text denies both.

Part I of the consolidated volume, carrying the Methodology as adopted in 2024, states: “HUDERIA is a stand-alone, non-legally binding guidance that, as such, does not have legal effect. It is not mandatory, nor is it intended as an interpretative aid for the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law.”

Part II — the preface to the COBRA Resources, the newer half — repeats that paragraph and then adds a sentence the Methodology’s version does not contain: “In addition, while HUDERIA has a facilitative role, it is not a means for implementing the Framework Convention.”

The two paragraphs sit roughly fifty-five thousand characters apart in the same published volume, and the difference between them is the newer, sharper disclaimer. Read together, they suggest the drafters saw the “HUDERIA implements the treaty” framing take hold between 2024 and 2026 and wrote a rebuttal into the Model’s preface.

What the treaty actually requires is separate. Both versions of the paragraph say Parties have the flexibility to use or adapt HUDERIA in whole or in part, or to use existing approaches, “provided that parties fully meet their obligations under the Framework Convention, including in particular the baseline for risk and impact management set out in its Chapter V”. Chapter V is the obligation. HUDERIA is one optional route to satisfying it, sitting alongside, in the text’s own list, “many existing or future frameworks, policies, guidance, standards or tools”.

The volume does state a compatibility ambition: HUDERIA aims “to promote compatibility and interoperability with existing and future guidance, standards and frameworks developed by relevant technical, professional and other organisations”, naming ISO, IEC, ITU, CEN, CENELEC and IEEE. That is an aspiration toward interoperability, not a claim of equivalence with any of them.

Why this matters for university and public-sector research offices

HUDERIA is written for “both public and private actors”, but its centre of gravity is public administration — the triage language repeatedly refers decisions to “the authorities”, and the Chapter V framing addresses Parties to the treaty. For research administrators in Council of Europe member states, that makes it relevant in a narrow but real way: a public university or a state research funder deploying AI in admissions screening, student welfare flagging, research-integrity triage or first-pass grant sifting is a public actor making consequential decisions about identifiable individuals, which is exactly the profile COBRA’s application context is built to interrogate. HUDERIA imposes nothing on such an institution — it is not mandatory for anyone — but where a national regulator or ministry chooses HUDERIA as its reference method for Chapter V purposes, the institutions it supervises inherit the vocabulary. The four-context question set in Resources A, B and C is also usable on its own, independently of any treaty question, as a structured intake for an institutional AI review committee that currently has none.

Where NIKOLAI fits

NIKOLAI is CASRAI’s own independent frontier-AI-safety dictionary. It is unendorsed: no lab, evaluator, regulator or treaty body has reviewed it or been consulted on it, and its crosswalk rows are shadow mappings — CASRAI’s own reading of published text — unless the organisation concerned has filed a Mapping Declaration. The Council of Europe has filed none, so everything in this section is a shadow mapping and nothing here is endorsed by the CAI.

With that said, HUDERIA lands squarely on two elements NIKOLAI already defines.

The first is Likelihood Term (Track N4, Claims and argument), which NIKOLAI proposes as “a controlled ladder of ordinal terms (or, where a source permits it, a numeric band) expressing the probability that a harm or claim holds”, with a mandatory scheme reference identifying which scale applies. The element exists precisely because sources use probability words without anchoring them to defined ranges — which is why it carries an explicit unanchored value for exactly that case. HUDERIA is a textbook instance on two counts: it footnotes that its “probability” is called “likelihood” elsewhere, and it then declines to define any bands at all, leaving quantitative versus qualitative to the discretion of the authorities. A HUDERIA probability rating would map to Likelihood Term as unanchored, not because the drafters were careless but because they chose not to anchor it. CASRAI’s guide on three frameworks with no shared probability scale covers the same failure mode in frontier-lab safety frameworks.

The second is Reassessment Trigger (element B10, Track N3, Thresholds and checkpoints), which covers the events that should force renewed evaluation of an already-assessed system — capability changes, incidents, changed deployment conditions, altered evaluation methods, substantial modification — and who decides when one has occurred. HUDERIA’s iterative review is the same concept arriving from the human-rights side rather than the frontier-safety side, and its stated principles (retirement-to-decommissioning coverage, responsiveness to new forms of misuse, more frequent reassessment in rapidly changing contexts) are recognisably trigger conditions. The difference worth recording is that HUDERIA explicitly leaves “thresholds” and “triggers” unfixed, where Reassessment Trigger asks a source to name them. That is a gap in the source, not a mismatch in the mapping.

HUDERIA’s “severity = scale + scope + reversibility” definition is the more interesting open question. NIKOLAI’s crosswalks draw on lab and regulator frameworks where severity is generally a primitive; a composite definition inherited from the UNGPs does not slot cleanly into that. CASRAI is flagging it here as a candidate for future crosswalk work rather than asserting a row that does not yet exist.

Frequently asked questions

What does HUDERIA stand for?

Human Rights, Democracy and the Rule of Law Impact Assessment. The published volume’s own title is simply HUDERIA — Methodology and Model.

Is HUDERIA legally binding?

No. The text states it is “a stand-alone, non-legally binding guidance that does not have legal effect” and that it “is not mandatory”. Approval by the Committee of Ministers does not change that.

Is HUDERIA how a country implements the Council of Europe AI treaty?

No, and the 2026 text says so directly: “while HUDERIA has a facilitative role, it is not a means for implementing the Framework Convention.” Parties must meet their obligations under the treaty, including the risk and impact management baseline in its Chapter V, by whatever route they choose. HUDERIA is one optional reference among many.

What is the difference between the HUDERIA Methodology and the HUDERIA Model?

The Methodology is the high-level, technology-neutral guidance — the four elements and the concepts behind them. The Model is the implementable support material: the COBRA Resources, a library of structured questions, explanations and examples. The Methodology was approved in February 2025, the Model in February 2026.

What are the COBRA Resources?

Resource A lists risk factors arising in the system’s application context, Resource B in its design and development context, and Resource C in its deployment context. Resource E lists illustrative areas of concern for human rights, democracy and the rule of law with the legal provisions that may be relevant to each. Resource F lists sectors and domains with their potential areas of concern.

Why is there no COBRA Resource D?

Because the CAI considered including one and did not, for now. The volume footnotes that the CAI “considered the possible inclusion of a COBRA Resource D” and that the Model adopted on 5 November 2025 “comprises COBRA Resources A, B, C, E and F”, adding that this is “without prejudice to any future decision on its inclusion”. See the register of HUDERIA pieces not yet adopted for what else is outstanding.

Does HUDERIA give you a risk score?

No. It names four variables — scale, scope, reversibility and probability — and says a risk calibration mechanism may be formulated, leaving the choice of qualitative, quantitative, mixed or other methods “to the discretion of the authorities or, where applicable, the AI project teams responsible for the system”. No scoring method is prescribed anywhere in the document.

How does HUDERIA define severity?

As a composite of three of its four risk variables: scale, scope and reversibility. Probability is a separate fourth variable and is not part of severity. The definition follows CETS 225, the UN Office of the High Commissioner for Human Rights and the UN Guiding Principles on Business and Human Rights.

Do private companies have to use HUDERIA?

No one has to use HUDERIA. The text says it “can be used by both public and private actors”, but it is voluntary guidance with no legal effect, and nothing in it creates an obligation on any organisation.

Sources

A note on sourcing: the Council of Europe’s own web pages at coe.int refuse automated retrieval, so the primary text above was obtained from the Council of Europe document server (rm.coe.int) and read directly. Where this page attributes a phrase to “the text”, it is quoting that document.

Related reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about The Council of Europe HUDERIA Methodology and Model: What It Asks For, and What It Explicitly Is Not

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

Research-admin question? Get an answer that links its sources.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.