The OECD AI Principles are the most widely endorsed text on artificial intelligence in the world, and one of the least understood inside companies. Adopted in 2019, revised in 2024 and backed by nearly fifty governments, they are not law and they are addressed to states. Yet the definition that decides whether the EU AI Act applies to your software comes straight from this text, and in 2026 the OECD added two instruments aimed at companies rather than ministries. This guide does not restate the five values and stop. It reads each principle the way an auditor would: which binding duty implements it, and which record proves it.

Key takeaways
- The OECD AI Principles are a Council Recommendation (OECD/LEGAL/0449), adopted on 22 May 2019 and revised on 8 November 2023 and 3 May 2024. They are not legally binding.
- They contain five values-based principles for AI actors and five recommendations to governments.
- Their definition of an AI system is the basis of Article 3(1) of the EU AI Act and of the Council of Europe convention on AI.
- Two company-facing instruments arrived in 2026: the Due Diligence Guidance for Responsible AI (19 February) and version 2.0 of the Hiroshima reporting framework (28 May).
- Nobody certifies or enforces the principles. The proof is yours to assemble: one binding duty and one dated record per principle.
What are the OECD AI Principles?
The OECD AI Principles is the common name of the Recommendation of the Council on Artificial Intelligence, reference OECD/LEGAL/0449. Ministers adopted it on 22 May 2019, which made it the first intergovernmental standard on AI. One month later, at the Osaka summit, G20 leaders welcomed a set of G20 AI Principles drawn from it. The text has two halves. The first sets out five values-based principles for “AI actors”, meaning everyone who plays an active role in the lifecycle of an AI system. The second gives five recommendations to policy makers: invest in research and development, foster an inclusive AI-enabling ecosystem, shape an interoperable governance and policy environment, build human capacity and prepare for labour market transition, and co-operate internationally. How many governments stand behind it depends on where you look. The OECD’s own overview page lists 47 adherents: the 38 OECD members, the European Union, and eight non-members (Argentina, Brazil, Egypt, Malta, Peru, Romania, Singapore and Ukraine). The White & Case regulatory tracker, dated 11 May 2026, counts 49 adherents as of April 2026 and adds Saudi Arabia and Uruguay. Quote the number with its source and date.
A Council Recommendation, not a law
An OECD Recommendation carries political commitment, not legal force. There is no sanction for an adherent that ignores it, no certification scheme, no audit standard and no register of compliant organisations. Implementation is followed through the OECD.AI Policy Observatory, launched in February 2020, which tracks national AI policies and hosts a catalogue of tools and metrics. That has a practical consequence for procurement. A supplier that claims to be “compliant with the OECD AI Principles” is making a statement that no scheme can verify. The useful question is not whether a vendor endorses the OECD AI Principles but what it can show for each of them, which is the subject of a proper vendor due diligence file.
The five OECD AI Principles, read as evidence
Each of the OECD AI Principles is short, and each one maps to duties that are binding somewhere. The table pairs the principle with what it asks of AI actors and with a record that an auditor, a customer or a market surveillance authority could ask to see. <table header-row=”true”> <tr> <td>Principle</td> <td>What it asks of AI actors</td> <td>Evidence a company can show</td> </tr> <tr> <td>1.1 Inclusive growth, sustainable development and well-being</td> <td>Pursue outcomes that benefit people and the planet, including, since 2024, environmental sustainability</td> <td>AI system impact assessment naming affected groups; environmental footprint noted for large workloads</td> </tr> <tr> <td>1.2 Rule of law, human rights and democratic values, including fairness and privacy</td> <td>Safeguards such as human oversight; attention to non-discrimination, privacy, labour rights and, since 2024, AI-amplified misinformation</td> <td>Fundamental rights impact assessment; bias test results; a human oversight procedure with named reviewers</td> </tr> <tr> <td>1.3 Transparency and explainability</td> <td>Tell people when they interact with AI; give meaningful information on the factors behind an outcome; allow it to be challenged</td> <td>User-facing notice; instructions for use; an explanation procedure with response times</td> </tr> <tr> <td>1.4 Robustness, security and safety</td> <td>No unreasonable safety or security risk in normal use, foreseeable use or misuse; since 2024, the ability to override, repair or decommission safely</td> <td>Risk register; test and red-team reports; incident log; a tested shutdown and rollback procedure</td> </tr> <tr> <td>1.5 Accountability</td> <td>Traceability of datasets, processes and decisions; systematic risk management at each lifecycle phase; responsible business conduct with suppliers</td> <td>AI inventory with owners; RACI; supplier due diligence file; retained logs; committee minutes</td> </tr> </table> Two details in the wording matter. First, the OECD AI Principles address AI actors, not only developers: an organisation that deploys a purchased system plays an active role in its lifecycle and is inside the scope. Second, principle 1.5 was strengthened in 2024 to say that accountability includes a systematic approach to risk across the lifecycle, which is the same idea that Article 9 of the EU AI Act and clause 6.1 of ISO/IEC 42001 turn into a requirement.
What changed in 2024, and why the 2023 definition matters more
The revision of the OECD AI Principles on 3 May 2024 responded to general-purpose and generative AI. According to the OECD’s announcement, the updated text:
- addresses information integrity, including misinformation and disinformation;
- covers uses outside a system’s intended purpose, and intentional or unintentional misuse;
- asks for mechanisms to override, repair or decommission a system safely;
- makes environmental sustainability explicit;
- stresses responsible business conduct across the AI lifecycle and co-operation between AI actors;
- calls for governance that is interoperable between jurisdictions.
The quieter change came six months earlier. On 8 November 2023 the OECD revised only one thing: the definition of an AI system. It now reads: “a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments”, and adds that AI systems vary in their levels of autonomy and adaptiveness after deployment. The reasoning is set out in an explanatory memorandum published in March 2024. That sentence is now law in Europe. Article 3(1) of Regulation (EU) 2024/1689 keeps the same inference-based core and writes autonomy and possible adaptiveness into the definition itself. Recital 12 says the notion should be closely aligned with the work of international organisations, and the Commission’s guidelines on the definition, published on 6 February 2025, interpret it element by element. The drafters of the Council of Europe Framework Convention, opened for signature on 5 September 2024, chose the OECD wording on purpose, to avoid a proliferation of definitions. The consequence is concrete. When your AI inventory asks “is this an AI system?”, the answer is given in OECD vocabulary, whatever the law that applies to you.
How the OECD AI Principles reach companies: four channels
A text written for governments reaches a company by four routes. Two of them are new in 2026.
1. The definition in binding law
This is the channel described above. The scoping decision under the EU AI Act, and under every law that borrowed the same wording, rests on the OECD definition. A company that documents its scoping reasoning per system is already applying the OECD AI Principles, whether it knows it or not.
2. The Due Diligence Guidance for Responsible AI
On 19 February 2026, at the India AI Impact Summit, the OECD published its Due Diligence Guidance for Responsible AI. It is voluntary, and it is the first OECD instrument on AI written for enterprises. It applies the six-step framework of the OECD Guidelines for Multinational Enterprises on Responsible Business Conduct to the AI value chain, as summarised by Hunton and Burges Salmon:
- Embed responsible business conduct into policies and management systems.
- Identify and assess actual and potential adverse impacts.
- Cease, prevent and mitigate adverse impacts.
- Track implementation and results.
- Communicate how impacts are addressed.
- Provide for or co-operate in remediation when appropriate.
It covers three groups: enterprises that supply inputs for AI development, those that take part in the AI system lifecycle, and those that use AI systems in their products and operations. It is designed to be coherent with the EU AI Act, the ASEAN Guide on AI Governance and Ethics and the Korean AI Basic Act. One feature gives it more weight than a typical voluntary text: the Guidelines it implements are backed by National Contact Points, a non-judicial grievance mechanism in each adhering country that can receive complaints about a company’s conduct.
3. The Hiroshima AI Process Reporting Framework
The OECD hosts the reporting framework of the G7 Hiroshima process, launched on 7 February 2025. It is a standard questionnaire through which organisations report how they apply the Hiroshima Process International Code of Conduct for Organisations Developing Advanced AI Systems. Twenty-five organisations reported in the first round, analysed in the OECD’s 2025 report “How are AI developers managing risks?”. Version 2.0 was launched in Paris on 28 May 2026, on the margins of the G7 Digital and Tech Ministerial Meeting. It opens the exercise to organisations of all sizes, distinguishes model developers, application developers and deployers, connects to the OECD.AI catalogue of tools and metrics, and covers agentic AI. More than 50 organisations pledged to report, among them Amazon, Google, Microsoft, OpenAI, Salesforce and Mistral AI. Reports received by 30 September 2026 feed the next analytical review. A mid-size company outside the G7 might conclude this is not its concern. The questionnaire is public, though, and customer security and procurement questionnaires tend to copy whatever structure the largest suppliers already answer.
4. National strategies, procurement and incident vocabulary
Adherents committed to promote the OECD AI Principles, and they do so through national AI strategies, public procurement criteria and regulator guidance. The OECD also supplies shared vocabulary that regulators reuse: its Framework for the Classification of AI Systems (February 2022) describes a system along five dimensions, and its work on AI incidents defined “AI incident” and “AI hazard” in May 2024 before proposing a common reporting framework on 28 February 2025. If you operate an AI incident reporting process, those definitions are a sensible baseline for the incidents no law yet obliges you to report.
OECD AI Principles vs EU AI Act, ISO/IEC 42001 and NIST AI RMF
The four texts are often presented as alternatives. They are layers. <table header-row=”true”> <tr> <td>Framework</td> <td>Nature</td> <td>Addressed to</td> <td>Binding?</td> <td>What it produces</td> </tr> <tr> <td>OECD AI Principles</td> <td>Intergovernmental Recommendation</td> <td>Governments, and AI actors in general</td> <td>No</td> <td>Shared values, definitions and vocabulary</td> </tr> <tr> <td>EU AI Act</td> <td>Regulation</td> <td>Providers, deployers, importers, distributors</td> <td>Yes</td> <td>Obligations by role and risk class, with penalties</td> </tr> <tr> <td>ISO/IEC 42001</td> <td>Management system standard</td> <td>Any organisation</td> <td>No, but certifiable</td> <td>An audited AI management system</td> </tr> <tr> <td>NIST AI RMF</td> <td>Voluntary risk framework</td> <td>Any organisation</td> <td>No</td> <td>A risk method in four functions: Govern, Map, Measure, Manage</td> </tr> </table> The OECD AI Principles say what trustworthy AI means. The EU AI Act says who must do what, and by when: prohibited practices and AI literacy since 2 February 2025, general-purpose AI model obligations since 2 August 2025, Article 50 transparency duties since 2 August 2026, and, after the Digital Omnibus (Regulation (EU) 2026/1744), high-risk obligations for Annex III systems from 2 December 2027 and for Annex I products from 2 August 2028. ISO/IEC 42001 gives the organisation a management system that an accredited body can certify (ISO). The NIST AI RMF supplies a risk method (NIST). A mature programme uses all four, and the OECD AI Principles are the layer that lets a group operating in several jurisdictions keep one vocabulary.
From the OECD AI Principles to evidence: a five-step method
- Scope with the OECD definition. For every system in the inventory, record whether it infers how to generate outputs from the input it receives, and why. Keep the reasoning, not only the answer.
- Map each principle to the binding duties that apply to you. Principle 1.2 leads to Articles 10, 14 and 27 of the EU AI Act and to the GDPR; 1.3 to Articles 13, 50 and 86; 1.4 to Articles 9 and 15; 1.5 to Articles 12, 16, 17, 25 and 26 and to clause 5.3 of ISO/IEC 42001. Name one owner per duty.
- Attach one dated record per principle. Use the evidence column above. A record that has no date and no owner is an intention.
- Run the six due diligence steps on your AI value chain. Include suppliers of models and data. This is where AI risk management stops being an internal exercise.
- Decide whether to report publicly. A Hiroshima framework report or your own transparency report both work. Whichever you choose, set a review date.
An AI governance platform such as AI Sigil keeps the mapping, the owners and the records in one place, so the pack stays current when a system or a law changes.
FAQ
What are the OECD AI Principles in simple terms? They are a 2019 agreement between governments, updated in 2024, on what trustworthy AI should look like. Five principles describe the values AI should respect: benefit to people and the planet, human rights and fairness, transparency, safety and security, and accountability. Five recommendations tell governments how to support those values through investment, skills and international co-operation. Are the OECD AI Principles legally binding? No. They are an OECD Council Recommendation, which carries political commitment but no legal force, no penalties and no enforcement body. Their influence is indirect: the EU AI Act and the Council of Europe convention use the OECD definition of an AI system, and national strategies and procurement rules cite the OECD AI Principles. How many countries have adopted them? The OECD’s overview page lists 47 adherents: the 38 OECD members, the European Union and eight non-member countries. White & Case’s tracker of May 2026 counts 49 as of April 2026, adding Saudi Arabia and Uruguay. The G20 also welcomed principles drawn from the OECD text in June 2019. What is the OECD definition of an AI system? Since 8 November 2023, an AI system is a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. Systems vary in autonomy and in adaptiveness after deployment. How do the principles relate to the EU AI Act? The Act borrows the OECD definition in Article 3(1) and turns several principles into obligations: human oversight in Article 14, transparency in Articles 13 and 50, risk management in Article 9 and record-keeping in Article 12. The OECD AI Principles state values; the Act assigns duties by role and attaches penalties. Can a company be certified against the OECD AI Principles? No certification exists. The closest options are a certificate against ISO/IEC 42001, which audits your AI management system, and a public report under the Hiroshima AI Process Reporting Framework, which the OECD hosts. Neither certifies the OECD AI Principles themselves, but both produce evidence that maps to them.
Conclusion
The OECD AI Principles are the shared vocabulary of AI regulation. Their definition of an AI system sits inside the EU AI Act, their five values reappear as obligations in law after law, and in 2026 the OECD began addressing companies directly through due diligence guidance and a broader reporting framework. Their weakness is equally clear: nobody enforces them and nobody certifies them. That is why the evidence has to come from you. Scope your systems with the definition, map each principle to the duties that bind you, give every duty an owner and a dated record, and decide what you are prepared to report. Done once and kept current, that file answers the regulator, the customer and the board with the same documents.