Written and maintained by CASRAI Editorial Board
Last updated
The “OECD AI Principles” are a non-binding OECD Council Recommendation — formally the Recommendation of the Council on Artificial Intelligence, catalogued as OECD/LEGAL/0449. It was adopted at Ministerial level on 22 May 2019, revised on 8 November 2023 to update its definition of an “AI system”, and revised again at Ministerial level on 3 May 2024. It contains five values-based principles and five recommendations for national policy. Exactly one of those principles — 1.4, Robustness, security and safety — carries the instrument’s entire safety content, and it contains no capability threshold, no compute trigger, no concept of a frontier model, and no reporting duty. Because a Recommendation binds nobody, the gap between what an adherent commits to here and what a frontier statute such as California’s SB 53 commands is the whole story of this page. It also maps cleanly onto one element in NIKOLAI, CASRAI’s independent frontier-AI-safety dictionary: Capability threshold, which OECD/LEGAL/0449 has no equivalent of.
- Formal name: Recommendation of the Council on Artificial Intelligence
- Legal instrument number: OECD/LEGAL/0449
- Adopted: 22 May 2019, by the OECD Council meeting at Ministerial level, on the proposal of the Digital Policy Committee (then the Committee on Digital Economy Policy)
- Revised: 8 November 2023 (definition of “AI system” only) and 3 May 2024 (substantive revision at Ministerial level)
- Legal force: none — a Recommendation, in the OECD’s own classification, is “not legally binding”
- Adherents: 47, per OECD.AI — the 38 OECD member countries, the European Union, and eight non-members
- Structure: Section 1 (principles 1.1-1.5) and Section 2 (recommendations 2.1-2.5)
- Frontier-safety content: principle 1.4, three sub-paragraphs, roughly 100 words
What kind of instrument this actually is
The OECD publishes five categories of substantive legal instrument, and the category matters more than anything in the text. The Compendium’s own definitions, reproduced in the back matter of OECD/LEGAL/0449 itself, distinguish Decisions from Recommendations in one sentence each. Decisions “are adopted by Council and are legally binding on all Members except those which abstain at the time of adoption. They set out specific rights and obligations and may contain monitoring mechanisms.” Recommendations, by contrast, “are adopted by Council and are not legally binding. They represent a political commitment to the principles they contain and entail an expectation that Adherents will do their best to implement them.”
OECD/LEGAL/0449 is a Recommendation. “Do their best to implement them” is the operative commitment — not a duty, not an obligation, and with no monitoring mechanism of the kind a Decision may carry. The instrument’s only accountability machinery is a reporting instruction to a committee: the Council instructs the Digital Policy Committee, through its Working Party on AI Governance, to “report to Council, in consultation with other relevant committees, on the implementation, dissemination and continued relevance of this Recommendation no later than five years following its revision and at least every ten years thereafter.” That is a five-yearly self-assessment by the body that proposed the instrument, reporting to the body that adopted it. No adherent is evaluated individually, and nothing follows from a poor showing.
This is not a criticism of the drafters. The OECD’s own background note describes the Recommendation as “the first intergovernmental standard on AI” and says it “strives to set a standard that is implementable and flexible enough to stand the test of time in a rapidly evolving field.” Flexibility was the design goal. But it means that when a later, harder text reuses the OECD’s vocabulary, the vocabulary arrives without the enforcement — and readers who know the phrase from the OECD often assume the commitment travelled with it.
Who the 47 adherents are
OECD.AI states: “Today, there are 47 adherents to the Principles.” The instrument’s own back matter lists the 38 OECD member countries: Australia, Austria, Belgium, Canada, Chile, Colombia, Costa Rica, the Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Israel, Italy, Japan, Korea, Latvia, Lithuania, Luxembourg, Mexico, the Netherlands, New Zealand, Norway, Poland, Portugal, the Slovak Republic, Slovenia, Spain, Sweden, Switzerland, Türkiye, the United Kingdom and the United States. OECD.AI adds that the European Union adheres, and names eight non-member adherents: Argentina, Brazil, Egypt, Malta, Peru, Romania, Singapore and Ukraine. Those three groups — 38, 1 and 8 — reconcile to the stated 47; that arithmetic is CASRAI’s reconciliation of two OECD sources, not a figure either source states in that form.
Separately, the OECD records that “In June 2019, at the Osaka Summit, G20 Leaders welcomed the G20 AI Principles, drawn from the Recommendation.” That is the OECD’s own account of its text being carried into a second intergovernmental forum, and it is the clearest documented instance of the Recommendation’s language travelling. CASRAI has deliberately not asserted on this page that the EU AI Act, the NIST AI Risk Management Framework or the G7 Hiroshima code each derive their definitions from this text, because verifying that claim requires quoting each of those instruments side by side and this page quotes only OECD/LEGAL/0449. What can be said from the source in hand: the OECD calls its own instrument the first intergovernmental standard on AI, and records one specific case of downstream adoption.
The five principles, as the instrument words them
Section 1 is titled “Principles for responsible stewardship of trustworthy AI”. The Council “RECOMMENDS that Members and non-Members adhering to this Recommendation (hereafter the ‘Adherents’) promote and implement the following principles”, separately “CALLS ON all AI actors to promote and implement” them, and “UNDERLINES that the following principles are complementary and should be considered as a whole.”
- 1.1 Inclusive growth, sustainable development and well-being — stakeholders should pursue “beneficial outcomes for people and the planet”, including “protecting natural environments, thus invigorating inclusive growth, well-being, sustainable development and environmental sustainability.”
- 1.2 Respect for the rule of law, human rights and democratic values, including fairness and privacy — two sub-paragraphs. (a) covers non-discrimination, dignity, privacy and data protection, labour rights, and “addressing misinformation and disinformation amplified by AI, while respecting freedom of expression”. (b) requires “mechanisms and safeguards, such as capacity for human agency and oversight, including to address risks arising from uses outside of intended purpose, intentional misuse, or unintentional misuse”.
- 1.3 Transparency and explainability — four numbered items covering general understanding of capabilities and limitations, awareness of interactions with AI systems “including in the workplace”, plain-language information on “the sources of data/input, factors, processes and/or logic that led to the prediction, content, recommendation or decision”, and information enabling those adversely affected “to challenge its output”.
- 1.4 Robustness, security and safety — three sub-paragraphs, quoted in full below.
- 1.5 Accountability — three sub-paragraphs covering accountability for proper functioning, traceability “in relation to datasets, processes and decisions made during the AI system lifecycle”, and a “systematic risk management approach to each phase of the AI system lifecycle on an ongoing basis”.
Section 2, “National policies and international co-operation for trustworthy AI”, addresses governments: 2.1 Investing in AI research and development; 2.2 Fostering an inclusive AI-enabling ecosystem; 2.3 Shaping an enabling interoperable governance and policy environment for AI; 2.4 Building human capacity and preparing for labour market transformation; 2.5 International co-operation for trustworthy AI.
Principle 1.4 in full — the entire safety text
This is the whole of the Recommendation’s safety content, quoted verbatim from OECD/LEGAL/0449:
1.4. Robustness, security and safety
a) AI systems should be robust, secure and safe throughout their entire lifecycle so that, in conditions of normal use, foreseeable use or misuse, or other adverse conditions, they function appropriately and do not pose unreasonable safety and/or security risks.
b) Mechanisms should be in place, as appropriate, to ensure that if AI systems risk causing undue harm or exhibit undesired behaviour, they can be overridden, repaired, and/or decommissioned safely as needed.
c) Mechanisms should also, where technically feasible, be in place to bolster information integrity while ensuring respect for freedom of expression.
Read it for what is absent. There is no threshold of any kind — no capability level, no training-compute figure, no user count, no deployment scale that switches an obligation on. There is no concept of a frontier model, a foundation model, or a general-purpose AI model; the instrument’s scope term is “AI system”, applied uniformly. There is no duty to test before deployment, no duty to let an outsider test, no duty to publish anything, and no duty to tell anyone when something goes wrong. The word “should” governs every clause, twice qualified further by “as appropriate” and “where technically feasible”.
The nearest thing to a risk-management duty sits in a different principle. Paragraph 1.5(c) asks AI actors to “apply a systematic risk management approach to each phase of the AI system lifecycle on an ongoing basis and adopt responsible business conduct to address risks related to AI systems”, listing risks “related to harmful bias, human rights including safety, security, and privacy, as well as labour and intellectual property rights.” The OECD’s own background note confirms this placement was deliberate: in the 2024 revision “the text on traceability and risk management was further elaborated and moved to the ‘Accountability’ principle as the most appropriate principle for these concepts.” Anyone searching principle 1.4 for a risk-management obligation and finding none is not misreading it — it was moved.
What the May 2024 revision actually changed
OECD.AI’s summary page says only that “Adherents updated them to consider new technological and policy developments, ensuring they remain robust and fit for purpose.” That sentence carries no substance, and it is the sentence most secondary coverage repeats. The specific changes are set out in the background section of the legal instrument itself, which is the only place CASRAI found them stated. The instrument records that the 3 May 2024 revision was made “In line with the conclusions of the 2024 Report to Council”, and lists updates aimed at:
- “reflecting the growing importance of addressing misinformation and disinformation, and safeguarding information integrity in the context of generative AI”
- “addressing uses outside of intended purpose, intentional misuse, or unintentional misuse”
- “clarifying the information AI actors should provide regarding AI systems to ensure transparency and responsible disclosure”
- “addressing safety concerns, so that if AI systems risk causing undue harm or exhibit undesired behaviour, they can be overridden, repaired, and/or decommissioned safely by human interaction”
- “emphasising responsible business conduct throughout the AI system lifecycle, involving co-operation with suppliers of AI knowledge and AI resources, AI system users, and other stakeholders”
- “underscoring the need for jurisdictions to work together to promote interoperable governance and policy environments for AI, against the increase in AI policy initiatives worldwide”
- “introducing an explicit reference to environmental sustainability, of which the importance has grown considerably since the adoption of the Recommendation in 2019”
The instrument adds that “some of the headings of the principles and recommendations were expanded for clarity” — which is why principle 1.2 now reads “Respect for the rule of law, human rights and democratic values, including fairness and privacy” rather than the shorter 2019 heading — and that traceability and risk management were elaborated and relocated to 1.5, as noted above.
The fourth bullet is the safety-relevant one: 1.4(b), the override-repair-decommission clause, is a 2024 addition. So is 1.4(c) on information integrity. In other words, the 2019 text’s safety principle was closer to 1.4(a) alone. That is worth knowing before quoting “the OECD AI Principles” at a 2019 date for a proposition the 2024 text supports.
The separate 8 November 2023 revision touched only the definition of “AI system”, which now reads: “An AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.” The instrument lists the five edits behind that wording, including “clarifying that the Recommendation applies to generative AI systems, which produce ‘content'” and “substituting the word ‘real’ with ‘physical’ for clarity and alignment with other international processes.”
Adherent commitment vs. frontier statute: the same subject, two different documents
Set the Recommendation beside a frontier-specific statute and the difference is not one of stringency but of kind. Under OECD/LEGAL/0449, an adherent government has made a political commitment to promote five principles and to implement five policy recommendations, with a five-yearly committee report as the only follow-up. Under California’s SB 53, the Transparency in Frontier Artificial Intelligence Act, a developer that meets the statute’s scope test must publish a frontier AI framework, must report critical safety incidents to a state agency, and faces civil penalties for failure — obligations on a named private party, enforceable, with a defined scope trigger. CASRAI’s SB 53 foundational explainer and SB 53 critical safety incident reporting guide cover those duties and their deadlines in detail.
Three structural differences are worth naming precisely. First, the addressee: the Recommendation’s Section 2 addresses governments and its Section 1 addresses “all AI actors” as a call, not a command; SB 53 addresses a specific class of developer. Second, the trigger: the Recommendation applies uniformly to every “AI system” with no threshold, whereas a frontier statute exists precisely to define a threshold above which extra duties attach — which is why the eleven scope tests CASRAI has compared all come from statutes and lab policies, and none from the OECD. Third, the consequence: “do their best to implement” against a civil penalty.
For how those harder instruments line up against one another, CASRAI’s comparison of frontier AI law across ten jurisdictions sets out which have a binding scope test and which do not, and the jurisdiction map of AI regulation worldwide places the OECD’s adherent list next to the national statutes actually in force. On the voluntary-standards side, the same non-binding-but-influential dynamic plays out in the management-system literature: CASRAI’s NIST AI RMF vs ISO/IEC 42001 comparison contrasts a voluntary US framework with a certifiable international standard, which is a useful calibration for where an OECD Recommendation sits — further toward the voluntary end than either.
Why a research administrator should care about Section 2.1
Most of the Recommendation’s frontier-safety relevance is thin, but Section 2 contains one recommendation aimed squarely at research policy, and research administrators are its downstream implementers. Paragraph 2.1(a) says governments “should consider long-term public investment, and encourage private investment, in research and development and open science, including interdisciplinary efforts, to spur innovation in trustworthy AI that focus on challenging technical issues and on AI-related social, legal and ethical implications and policy issues.” Paragraph 2.1(b) extends that to “open-source tools and open datasets that are representative and respect privacy and data protection”.
That is a commitment by 47 adherents to fund AI research, open science and open data — which is to say, a commitment discharged through national funding agencies and, in turn, through the sponsored-programs and research-computing offices that administer their awards. Where a funder’s AI-related programme description invokes “trustworthy AI”, this instrument is a plausible upstream reference for that phrase. Paragraph 2.3 is the other one to watch: it asks governments to “consider using experimentation to provide a controlled environment in which AI systems can be tested” — the regulatory-sandbox concept, which universities hosting AI testbeds encounter directly.
The definitional angle matters too. The revised “AI system” definition is a scope boundary that institutions increasingly have to apply to their own research portfolios, because a definition written for an intergovernmental Recommendation is the definition later regulations tend to inherit. Research offices working out which of their projects fall inside an AI regulation’s scope — see CASRAI’s guide to EU AI Act obligations and exemptions for research organizations — are applying definitional tests of this shape. One caution: the Recommendation itself contains no research exemption, no human-subjects provision, and nothing addressed to institutional review boards or export control. Its research relevance is the funding and definitional layer, not the compliance layer.
Where NIKOLAI fits
NIKOLAI is CASRAI’s own frontier-AI-safety dictionary. It is independent and unendorsed: no lab, evaluator, regulator or intergovernmental body has endorsed it, reviewed a mapping, or been consulted on it. Every crosswalk row in it is a shadow mapping — CASRAI’s own reading of published text — unless the organization concerned has filed a Mapping Declaration confirming its own terminology. Nothing here is “the standard” or an official record of the OECD’s vocabulary.
The element that makes the OECD instrument legible is Capability threshold, in Track N3, Thresholds and checkpoints. NIKOLAI defines it as “a level of model capability (or capability plus usage) at which specified additional safeguards or decisions become required, together with its disclosure status (quantified, qualitative, referenced-but-undefined, or classified).” CASRAI checked that element page directly before writing this: its crosswalk carries rows for twelve organizations and frameworks, including Anthropic, OpenAI, Google DeepMind, xAI, the EU, California SB 53, the US government, METR, the Frontier Model Forum, Amazon and Magic.
OECD/LEGAL/0449 has no row there, and should not have one. The element requires a stated level at which something additional becomes required; the Recommendation states no level, for any purpose, anywhere in its text. That is not a gap in NIKOLAI’s coverage and not a defect in the Recommendation — it is the accurate result of applying a frontier-safety vocabulary to an instrument that predates the frontier-safety vocabulary by four years and was never scoped to it. CASRAI’s guide to how fourteen labs and regulators use the term differently shows what an actual threshold claim looks like, and by contrast makes clear why the OECD text produces none.
Frequently asked questions
Are the OECD AI Principles legally binding?
No. OECD/LEGAL/0449 is a Recommendation, and the OECD’s own classification states that Recommendations “are adopted by Council and are not legally binding. They represent a political commitment to the principles they contain and entail an expectation that Adherents will do their best to implement them.”
How many countries have adhered?
OECD.AI states there are 47 adherents. That comprises the 38 OECD member countries, the European Union, and eight non-member adherents named by OECD.AI: Argentina, Brazil, Egypt, Malta, Peru, Romania, Singapore and Ukraine.
When were the Principles updated?
Twice. The Council revised the definition of “AI system” on 8 November 2023, and made a broader substantive revision at Ministerial level on 3 May 2024. The original adoption was 22 May 2019.
What exactly changed in May 2024?
The legal instrument’s own background section lists the changes: information integrity and misinformation, uses outside intended purpose and misuse, clarified transparency disclosure, the override/repair/decommission safety clause, responsible business conduct across the lifecycle including suppliers, interoperable governance across jurisdictions, and an explicit reference to environmental sustainability. Headings were expanded, and traceability and risk management were elaborated and moved into the Accountability principle. OECD.AI’s summary page does not itemise these; the instrument does.
Do the OECD AI Principles apply to frontier models?
Not as a distinct category. The Recommendation’s only scope term is “AI system”, applied uniformly. It contains no capability threshold, no training-compute figure, no definition of a frontier or general-purpose model, and no tiering of obligations by model scale.
Do they require incident reporting?
No. There is no incident definition, no reporting recipient, and no deadline anywhere in the instrument. Principle 1.4(b) asks that mechanisms be in place so systems “can be overridden, repaired, and/or decommissioned safely as needed” — an internal capability, not a notification duty.
Is this the same as the G20 AI Principles?
Not the same instrument, but directly related. The OECD records that “In June 2019, at the Osaka Summit, G20 Leaders welcomed the G20 AI Principles, drawn from the Recommendation.”
Who implements the Recommendation inside the OECD?
The Digital Policy Committee, through its Working Party on AI Governance (AIGO), created in 2022. The OECD also launched the AI Policy Observatory (OECD.AI) and the informal OECD Network of Experts on AI (ONE AI) in February 2020 to support implementation.
Sources
- OECD, Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449 — the instrument itself, read in full from the OECD’s published PDF. Source for every quoted principle and recommendation, the definitions in Section I, the adoption and revision dates, the 2023 and 2024 revision itemisations, the OECD member-country list, the reporting instruction to the Digital Policy Committee, and the Decision/Recommendation classification.
- OECD.AI, “AI Principles” — source for the 47-adherent figure, the eight named non-member adherents, and the EU’s adherence.
- OECD.AI, principle page for Robustness, security and safety — cross-check on the text of principle 1.4.
CASRAI read the legal instrument directly rather than relying on OECD.AI’s summary, because the summary page states only that the Principles were updated “to consider new technological and policy developments” without saying what changed. Every claim on this page about the substance of the May 2024 amendment is quoted from the instrument.
Related reading
- OMB M-26-04 and EO 14319: The Unbiased AI Principles Clause Federal LLM Contracts Must Carry
- NIST AI RMF vs ISO/IEC 42001
- AI Regulations Around the World: A Jurisdiction Map
- Frontier AI Law: 10 Jurisdictions Compared
- The Council of Europe AI Treaty (CETS 225): What’s Confirmed So Far
- Who Counts as ‘Frontier AI’? Eleven Scope Tests Compared
- NIKOLAI element: Capability threshold








