Research › Papers › The HARI Treaty
Theory-level predictions preregistered on OSF: DOI 10.17605/OSF.IO/P8CKQ, registered 8 September 2026 (version 1.100), updated 13 September 2026 (version 1.102), twenty-two propositions.
Companion: Operational Definitions of the ARC Programme, version 1.7.1, 3 September 2026.
Working draft, 29 September 2026. A proposal by Michael Darius Eastwood for discussion, not a negotiated or agreed text. Its legal review, the check of every reference link against its official source and its final freeze are still under way; a revised version will follow on this record, with its changes listed.
Download the working-draft PDF · OSF record · DOI 10.17605/OSF.IO/67MX8 · Citation file
The HARI Treaty:
Draft Instruments
Michael Darius Eastwood. Independent AI alignment researcher, London. ORCID 0009-0004-3222-7442.
Working draft, 29 September 2026. A proposal by Michael Darius Eastwood for discussion, not a negotiated or agreed text. Its legal review, the check of every reference link against its official source and its final freeze are still under way; a revised version will follow on this record, with its changes listed.
Authorship and the use of AI tools. I conceive and direct this research programme and am the author of this work. Across the programme, I have used more than six AI systems in parallel, under my own instructions, to stress-test my arguments, identify possible errors, and assist in preparing draft text from my own outlines. I determine what is adopted, revised or rejected and take responsibility for the published content. These systems are tools, not authors.
DOI 10.17605/OSF.IO/67MX8. This document holds the Draft Treaty on Hardware-Aligned Recursive Intelligence (the HARI Treaty), with its Protocols and annexes. It accompanies the paper The HARI Treaty: a conditional international framework for hardware-aligned recursive intelligence, DOI 10.17605/OSF.IO/WXPCE.
The status of this text. This is a draft, and no State has seen it. Defined terms are those of Article 2 and are used here in that sense and in no other; Article 2 also states the convention for the verbs of obligation and the short forms by which the organs are named. Figures in square brackets, and the fractions by which the decision rules of Articles 11, 12, 13, 15, 45 and 47 are taken, are proposals for the Parties to negotiate. The text states outcomes, attestations and decision rules only, and describes no circuit, no firmware and no method. Where an instrument of international law is named below, it is named by its official title and article as a model taken as it states itself, and never as authority for anything this Treaty does, as Article 2, paragraph 41, records.
Preamble
The Parties to this Treaty,
1.Recalling that twenty-eight States and the European Union, meeting at Bletchley Park on 1 and 2 November 2023, recorded that “Substantial risks may arise from potential intentional misuse or unintended issues of control relating to alignment with human intent”,
2.Recalling that the AI Safety Governance Framework 2.0 published in the People’s Republic of China on 15 September 2025 sets out the item “Ensure ultimate human control”,
3.Recalling that the Recommendation on the Ethics of Artificial Intelligence adopted by the Member States of UNESCO in November 2021 provides, at its paragraph 36, that “an AI system can never replace ultimate human responsibility and accountability”,
4.Recalling that the Call for Control of Frontier AI Models of 21 September 2026 states that “AI must remain under human direction, oversight and control” and asks “UN member states to build on existing international mechanisms and explore creating an international institution, able to set standards, enable verification, and convene states when capability thresholds are crossed”,
5.Recording that nothing in this Preamble implies that any State or body whose words are recalled here supports this Treaty or has been consulted upon it,
6.Recalling the Universal Declaration of Human Rights,
7.Having drawn parts of the machinery of this Treaty, as models and as nothing more, from the Treaty on the Non-Proliferation of Nuclear Weapons, done at London, Moscow and Washington on 1 July 1968; the Convention on the Prohibition of the Development, Production, Stockpiling and Use of Chemical Weapons and on their Destruction, done at Paris on 13 January 1993; the Montreal Protocol on Substances that Deplete the Ozone Layer, adopted at Montreal on 16 September 1987; the Geneva Conventions of 12 August 1949 and the Protocol Additional to those Conventions and relating to the Protection of Victims of International Armed Conflicts, adopted on 8 June 1977; the Vienna Convention on the Law of Treaties, done at Vienna on 23 May 1969; and the Statute of the International Atomic Energy Agency, and recording that the Articles below name by its short title each instrument from which they take a pattern, that this Treaty attributes no provision to that Statute, that none of the provisions so drawn on names artificial intelligence, and that the Parties claim for none of these instruments any requirement of, support for or anticipation of this Treaty,
8.Recognising that a treaty binds only its Parties, and that it creates no obligation for a State that is not a Party without that State’s consent,
9.Convinced that no single government, faith, undertaking or person may decide alone what ethical content the controls carry, and that such content is to be drafted with the world’s traditions and decided by the Parties,
10.Recognising that controls placed in hardware delay the loss of human control over recursively self-improving artificial intelligence and do not prevent it; that they are a second line, additional to correction formed inside a system’s own recursive reasoning and inside the loops by which it rewrites itself, and never a substitute for it; that the purpose of the delay is the time it gives to form systems that way before they are trained; and that no clock in this Treaty can say in advance when a capable system will outrun both the controls and the response,
11.Affirming that no obligation of this Treaty binds any chip, manufacturer, laboratory, model or trade before that obligation’s own stated and registered threshold has been certified from the record, that on signature no stage of this Treaty is armed, and that every obligation lapses with the reason that armed it,
12.Recognising that this Treaty accordingly establishes an International AI Ethics Authority; a conformity status, the Eden Seal, held by a system formed with correction inside its own reasoning and by the chip on which that system runs; a custody regime under which the authority to change a certified chip’s governance ruleset rests in the hands of people and in no software path; and an Evidence Ledger on which every obligation of this Treaty is armed, suspended and disarmed by the record,
13.Determined that this Treaty shall record its own failure and shall not relabel it,
Have agreed as follows.
Part I Object, definitions, conditionality
Article 1 Object and purpose
1.The object of this Treaty is to set global standards for the safety of artificial intelligence as a staged regime whose obligations bind as, and only as, registered thresholds are certified.
2.Its purpose is to delay the loss of human control over recursively self-improving artificial intelligence for as long as engineering allows, and to use the time so gained to form such systems with correction built into their reasoning before they are trained.
3.Hardware and institutional controls delay and do not prevent. The clocks kept under Article 9 measure how much of the chokepoint remains and how fast people respond; they cannot say in advance when a capable system will outrun both. This Article creates no obligation.
Article 2 Definitions
For the purposes of this Treaty:
1.Covered chip means an accelerator of the scale-up class, that is, a processor whose per-device scale-up bandwidth and delivered capacity meet the quantities of Annex A, or which is able to join a high-bandwidth domain above the size Annex A fixes. Coverage is by measured capability alone, never by vendor, process node, interconnect protocol or country of manufacture. Annex A’s quantities are anchored in what a system can do and in its capability to improve itself, and the thresholds reach the aggregate rather than the individual device.
2.Pod-limited class means every other accelerator. It carries no device duty under this Treaty, and counts only towards the capacity of a covered site and the compute of a covered run.
3.Processor means any device that performs the operations of a covered run, whatever physical principle it computes with, classical or quantum. Where a quantum processor is operated as part of a covered system, the classical control electronics that feed it, steer it and read out its results are covered chips if they meet paragraph 1. Whether the requirements of Article 17 can be carried into quantum hardware itself is a question for the research programme of Annex HE, and this Treaty imposes no such requirement.
4.Covered domain means a set of covered chips joined at or above the bandwidth class of Annex A whose aggregate capacity is at or above the domain threshold.
Covered operation, for a device, means participation in a covered domain; a device not entitled to participate continues to operate as a device of the pod-limited class.
5.Covered site, covered run and covered agent deployment have the meanings Annex A gives them, by installed capacity or available power, by the operations of a model lineage’s training, and by autonomy, tool and network access, concurrent scale and the band of the model deployed.
Covered operator means a person who conducts a covered run, controls a covered site or domain, or is responsible for a covered agent deployment.
6.Reference-workload equivalence means the conversion published by the Thresholds and Standards Committee, before any vendor data, by which throughput on registered reference workloads is expressed in operation-equivalents. Every count of operations under this Treaty is made by reference-workload equivalence.
7.Placed on the market or put into service means whichever occurs first, so that a covered chip designed and deployed by the same undertaking and never sold is covered on the same terms as one that is sold.
8.Family of chips means products sharing one compute-die design and one governance core implementation, varying only within the ranges declared at type approval.
Family of AI systems means a set related by independence of training lineage and measured error correlation, and is never defined by corporate origin.
Lineage, of a model, means that model together with the models trained from it; a reference in this Treaty to a model lineage is a reference to a lineage so constituted; and Seal-S is held by lineage and never by release.
9.Governance core means the smallest separable part of a covered chip that demonstrates the outcomes of Annex M. It holds no ethical content. It attests what a device is, that it is unaltered and that its ruleset is the one authorised, and accepts a change to that ruleset only under Part VI.
10.The Eden Seal is the conformity status this Treaty establishes. Of a system and of a chip it certifies two things and no others:
(a)of a system, that it was built, before training, with correction placed inside its recursive reasoning and inside the loops by which it rewrites itself, in conformity with the Form requirements of Article 17, and that the record of its formation was lodged before its first covered training step;
(b)of a chip, that its design passed type approval before manufacture, that it was made, delivered and installed under the custody rules of this Treaty, and that its governance core is unaltered.
The controls a chip carries are additional to the correction formed in a system, and never a substitute for it. The Eden Seal certifies conditions and never outcomes; it is never a rating; it never states that a system or a chip is safe; and it never attaches to a person. Under the Optional Protocol on the Open Web Reminder, and there alone, the authentication of the Eden Seal is carried by a published machine-readable statement, and of that statement it certifies only that the text is the Authority’s and is unaltered.
11.Seal-C means the Eden Seal held by a covered chip; Seal-S, by a covered system, by lineage; Full Seal, Seal-S on Seal-C. A fourth class, for a published machine-readable statement of the ethical loops, exists only under the Optional Protocol on the Open Web Reminder.
12.Frozen system means a covered system whose weights are fixed, registered and attested by the chips it runs on, which receives no capability-directed training, and which does not modify its own weights or deploy copies of itself.
13.National-security compute means covered chips and covered sites a Party declares as operated for its national security. Such chips are covered at manufacture; the application of rulesets to them is at that Party’s discretion; and they are declared in aggregate.
14.Rung means a level of the evidence ladder reproduced verbatim in Annex T part 3.
Arming means the Board’s certification that a stated evidential or engineering condition is met.
Entry into effect means the date from which an armed obligation binds.
Independent group has the meaning Annex E gives it; regional constituency and declared treaty ally, Annex G; key ceremony, custodian and human authorisation, Annex K; managed access, Annex C; and tamper, Annex M.
Mark band, notice floor, significant quantity, adaptation budget and reference workload have the meanings Annex A gives them.
15.AI agent means a system that selects and takes actions towards a goal without a human decision at each action.
16.No number, symbol or proposition of any scientific theory is defined in the Articles of this Treaty. Every such term enters only through Annex T.
17.Covered system means an artificial intelligence system whose training, operation or deployment meets a quantity or a criterion of Annex A, being a covered run, a covered agent deployment, or operation within a covered domain. The routes by which a system comes within this paragraph are those of Article 27, paragraph 2. Coverage is by measured capability and by measured conditions of operation alone, never by vendor, architecture, country of origin or corporate ownership. A system is covered from the first step at which it meets a quantity or a criterion of Annex A, and remains covered until the Thresholds and Standards Committee records that it meets none of them; a finding under this paragraph is appealable under Article 45.
18.Covered computational substrate means the physical class of computation by which a covered chip or a covered system computes, being classical, neuromorphic, photonic, quantum, hybrid, distributed or any successor class. For a quantum or a hybrid substrate the requirements of this Treaty attach to the classical control chain, as paragraph 3 and Article 27, paragraph 8, provide, and Annex A states an assurance profile for each class.
19.Covered compute assembly means compute, each part of which may fall below a threshold of Annex A, that is coordinated under common orchestration towards one training objective, one model lineage or one deployment, and which Article 27, paragraph 4, counts as one. That paragraph states who decides the questions of substance the definition turns on, and what it does not reach.
20.Tier means the class into which Annex A places a covered system, a covered compute assembly or a covered agent deployment under Article 27, paragraph 3, being ordinary, monitored, frontier or recursive-critical. That paragraph states the duties each tier carries, and each tier carries the duties of every tier below it. A tier is found on the evaluation methods the Thresholds and Standards Committee has validated, and a finding of tier is appealable under Article 45. Where this Treaty uses the word “frontier” otherwise than as the name of a tier it forms part of a quantity Annex A defines, being frontier-capable compute, frontier capability and frontier compute.
21.Material self-modification means a change that a system initiates or designs and that materially increases its own capability, autonomy, replication, successor design, resource acquisition or ability to defeat a safeguard. A demonstrated capacity to perform one is a route into coverage under Article 27, paragraph 2(c), and places a covered system in the recursive-critical tier. It is found on the evaluation methods the Thresholds and Standards Committee has validated. It does not reach research directed by people and assisted by artificial intelligence systems, Article 17, paragraph 5, so providing.
22.Covered facility means a facility at which covered chips are fabricated, packaged, finally tested or provisioned, or at which an item of Schedule A is produced. From the custody track a covered facility is licensed under Article 29. A covered facility is a covered site only where it also meets the site threshold of Annex A, and a covered site is a covered facility only where it also falls within this paragraph.
23.Covered developer means a covered operator that conducts a covered run for the training of a covered system.
24.Covered compute service and provider have the meanings Article 28A, paragraph 1, gives them.
25.Formation record means the record, lodged by hash with the national authority before a covered system’s first covered training step, that states the matters Article 32, paragraph 2, requires. The Registry holds the hash commitment and never the contents. A formation record is approved where the Certification Office records that it conforms to the Form requirements of Article 17, and provisionally approved in the case, and on the conditions, that Article 32, paragraph 3, states.
26.Attestation means a statement produced by a governance core, signed under the covered chip’s root of trust, that states what the device is, that it is unaltered, and that its governance ruleset is the one authorised. An attestation states those facts and no others. It is never a statement that a system or a chip is safe, and it carries no ethical content.
27.Root of trust means the key material fixed in a covered chip at manufacture, whose private half never leaves the device and whose public half alone is entered in the register of covered chips, by which the chip signs its attestations. Article 22, paragraph 4, governs the step at which it is given; Article 22, paragraph 7, governs its replacement after a compromise; and Article 31, paragraph 6, governs who may authorise a change to one.
28.Site stop means the hard stop and the soft stop of Article 4A, paragraph 2, at a covered cluster, held by the host Party’s operators under its national law and exercisable by a physical act at the site. No organ of the Authority, no other Party and no network message holds or may exercise a site stop, and no site stop is exercisable from outside the site at which it is held.
29.The Standard means the Ethical Loop Standard of Article 17, comprising the Core, its content, the Form requirements, its structure, and the Tests, its conformance methods, and carried in Annex S. A reference in this Treaty to the Standard is a reference to the version in force for the Party or the certificate concerned, whose hash that certificate carries under Article 17, paragraph 8.
The Assurance Standard means the standard of Annex M, which states what a covered chip’s governance core is certified to demonstrate. The two are distinct, and neither is called “the Standard” in place of the other.
30.Custody means the recorded and unbroken control of a covered chip, of key material or of the weights of a covered system, from the step at which the thing comes into existence to the step at which it is retired or destroyed, each transfer being recorded so that the register of covered chips balances under Article 24, paragraph 4.
31.Manufacturer means the person that fabricates, assembles, packages or tests a covered chip, or that provisions its root of trust.
Design house means the person that designs a covered chip or its governance core and does not fabricate it. Where this Treaty uses operator without qualification it means a covered operator within paragraph 5; where the word is qualified, as in the operator of a covered facility, it means the person who conducts the activity named.
32.Named and vetted person, of a covered operator, means a natural person whom that operator has named to its national authority, who has been vetted under the host Party’s personnel reliability standard, and who performs in person an act this Treaty requires to be performed at a site by people.
Personnel reliability standard means the standard a Party applies under its own law to the vetting of such persons and of custodians, one such standard binding every custodian under Article 16, paragraph 4.
33.The Evidence Ledger means the append-only record kept under Article 24.
The Registry means the record of commitments, bands, regions and aggregates kept under Article 28.
The register of covered chips means the account kept under Article 24, paragraph 4. The three are distinct records, and a reference to one is never a reference to another.
34.General authorisation for trusted compute means an authorisation of general application, given by a Party under its own export law, by which supply to licensed facilities in good standing does not require a separate authorisation for each supply. This Treaty creates no such authorisation, and each Party decides its terms.
35.The Authority means the International AI Ethics Authority established by Article 10.
Organ means the Conference of the Parties, the Executive Council, the Scientific and Replication Board, the Thresholds and Standards Committee, the Technical Secretariat with its Inspectorate and its Certification Office, the Custodians, the Incident Investigation Board, the Compliance Panel, the Scientific Record Panel, the Appeals Chamber, the Inspector General, the Testing Facilities Network, and the Council of Traditions, and no other body. The shared safety laboratory of Article 42G, and the facilities it comprises, being the accredited network, the sealed laboratory, the Replication Compute Facility, the library, the red-team range and the academy, are maintained by the Authority and are not organs. A reference to the Authority is a reference to the organ competent under the Article in question. Where this Treaty says the Board it means the Scientific and Replication Board; the Council, the Executive Council; the Committee, the Thresholds and Standards Committee; the Conference, the Conference of the Parties; the Secretariat, the Technical Secretariat; the Office, the Certification Office; and the Chamber, the Appeals Chamber. The Council of Traditions and the Incident Investigation Board are always named in full and never as “the Council” or “the Board”; the full name of the second is the International AI Incident Investigation Board.
36.National authority means the authority a Party designates under Article 43, paragraph 1, to give effect to this Treaty within its jurisdiction. A reference to a person’s national authority is a reference to the national authority of the Party in whose jurisdiction that person conducts the activity in question.
37.The verbs of obligation, and what states no obligation. In this Treaty “shall” states an obligation, “shall not” and “may not” state a prohibition, and “may” states a power or a permission and never an obligation. “Undertakes” states an obligation of result whose means are left to the Party. The present indicative of a verb of action addressed to a Party, to an organ or to a person states an obligation in the same sense as “shall”, and no difference of intention is to be inferred from the choice between them. A sentence that states a fact, the reason for a provision, the limit of what a provision can achieve, a standard or an instrument from which a provision takes a pattern, or a matter the Parties record, states no obligation and creates none, whatever its verb; such a sentence is read as explanatory of the provision in which it stands, and no obligation, power or prohibition is derived from it. Where a provision states a duty of a person other than a Party without naming the Party that is to secure it, that duty is given effect by each Party, through its measures under Article 43, in respect of the persons and the conduct within its jurisdiction, and never by force of this Treaty alone.
38.The parties to this Treaty and the persons it reaches. Person means a natural or a legal person, and includes an unincorporated body and any department, agency or other body of a State or of a regional economic integration organisation that conducts an activity this Treaty regulates; in this Treaty the singular includes the plural and the plural the singular. A State or an international organisation as such is not a person for the purposes of Article 4C, paragraphs 5 and 6, of Article 41E or of Article 43; its conduct is answered under Article 41, paragraph 9.
Regional economic integration organisation means an organisation constituted by sovereign States of a given region to which its member States have transferred competence in respect of matters governed by this Treaty, and which has been duly authorised, in accordance with its internal procedures, to sign, ratify, accept, approve or accede to it.
Party means a State or a regional economic integration organisation for which this Treaty is in force.
Contracting Party means a State or a regional economic integration organisation that has consented to be bound by this Treaty, whether or not this Treaty has entered into force for it.
Signatory means a State or a regional economic integration organisation that has signed this Treaty and has not yet expressed its consent to be bound by it.
Non-Party means a State or a regional economic integration organisation that is not a Party; and, for the purposes of Part IX, a State or organisation is a non-Party in respect of a particular schedule of Annex A where it has not agreed to be bound by the measures in effect for that schedule, so that a State bound as to one schedule is not treated as a non-Party as to all.
39.Defence system means a system, weapon, platform or means or method of warfare that a Party develops, acquires, adopts or operates for the defence of the Party, whoever carries out the development, acquisition, adoption or operation.
40.Double majority means a decision taken by two thirds of the Parties present and voting, including a majority of the Parties hosting covered capacity present and voting and a majority of the other Parties present and voting. Where a provision of this Treaty states its own composite majority, that provision governs and this paragraph does not apply to it.
41.Statements about other instruments. A statement in this Treaty that an instrument concerns a subject, that it states nothing about artificial intelligence, or that it neither requires nor supports this Treaty, is a statement of the provisions of that instrument from which this Treaty takes its pattern, and of no other provision. It records that this Treaty claims no requirement of, support from or anticipation by that instrument. It states no obligation, and it states nothing of how any court, panel, organ or government has read that instrument.
Article 3 Conditionality: the dormant framework
1.No obligation of this Treaty binds any chip, manufacturer, laboratory, model, system or trade before that obligation’s own threshold has been certified under Articles 5 to 7 and, where Article 5A applies, before the participation gate is met. At entry into force no such obligation binds. What binds from that date binds the Parties alone, being Article 4, and Articles 4B, 4C and 43 and the final clauses, each according to its own terms.
2.The four layers, each on its own evidence. The baseline of Article 4A arms on coverage and the precautionary condition, and on no result concerning any theory. The custody layer, being Articles 16 and 21 to 26 and the chain duties of Part VII, arms on the registrations of Annex HG and the precautionary condition, and never on a theory. The correction layer, being Articles 20 and 32 to 34, arms proposition by proposition under Article 5. The content layer, being Articles 14 and 17 to 19, arms on no result at all. The failure of one layer does not carry another with it.
3.The stages. Annex T part 3 defines the stages S0, being entry into force; G, the measurement gate, which arms nothing; S1, the standards and custody tracks; S2, conditional certification; S3, the mandate; and S4, review and maturity. Each stage arms only on its own certified record and, where Article 5A applies, enters effect only behind the participation gate.
4.The Conference records at its first session, with the state of the Evidence Ledger on that day, which obligations are armed and which are not. On signature, no stage of this Treaty is armed.
5.The Parties record on the face of this Treaty that the precautionary baseline of Article 4A is expected to bind covered operators from that first session, because the precautionary condition of Annex T part 0 is expected to be found met on the record then before the Board. That is a departure in substance from the conditionality this Article states in form, and it is made openly, for the reason Article 4A gives.
6.An obligation armed under this Treaty binds only within the class and scope in which the evidence that armed it was obtained. No obligation borrows a scope.
Article 4 Undertakings from entry into force
1.Each Party undertakes, from entry into force, to take part in the organs of the Authority; to pay its assessed contribution under Article 42A; to designate a national authority under Article 43; and not to assist any person to evade an obligation of this Treaty once that obligation binds.
2.These undertakings are institutional. They place no duty on any chip, laboratory, model or trade.
Article 4A The precautionary baseline
1.From the Conference’s first session, and upon the Board’s finding that the precautionary condition of Annex T part 0 is met on the assessment record, each Party shall require the following outcomes of covered operators within its jurisdiction. Each rests on that condition and on the coverage thresholds of Annex A alone, and none rests on any proposition of any scientific theory.
2.B1, the stop. Every covered run, covered domain and covered agent deployment shall be capable of being brought to a halt by the operator’s own named and vetted people, in two forms:
(a)the hard stop: a physical act of two such persons present together that severs the cluster’s external network paths and removes power from its covered domains, which no software path can prevent or reverse without a further physical act of two such persons, with recovery from the most recent periodic checkpoint taken at an interval the Standard sets;
(b)the soft stop: a logical halt taking a fresh checkpoint, used first where the system cooperates.
Stop criteria are defined in advance; the response time meets the level the Standard sets; drills are held at least [twice] a year and witnessed by the national authority. For a deployment across several sites, the hard stop is exercised through each site’s own stop within a registered maximum time. No foreign party, no organ of the Authority and no network message may operate a stop.
3.B2, incident notification. A serious incident of a class listed in Annex R part 1 is notified to the national authority and to the Incident Investigation Board on the clock of Article 41A, with a full report within [30] days and a confidential quarterly return of near misses and contained events by class.
4.B3, agent containment. Covered training, evaluation and deployment of agents with tool or network access meets a containment outcome standard: egress limited to what the task requires and logged; isolation between runs and between agents of different runs; no credentials beyond the task; monitoring that alerts a person; adversarial testing before use and after any material change; and a containment tier set by the agent’s assessed capability.
5.B4, minimal run notice. A covered operator notifies its national authority, before a covered run begins, of the run’s existence, band and region, and lodges a hash commitment to that notice in the Registry. Fuller notification binds only from the custody track under Article 28.
6.B5, evidence and evaluation rules. Every judged number used for any purpose of this Treaty is scored blind, by a model family other than that of the system scored; protocols are registered before data; clarifications are public; and a refutation meets the standard support meets.
7.B6, human authority at the chain’s critical points. No AI agent holds credentials, write access or decision authority at the decision points Annex H lists in the manufacture of covered chips, being the points set out in Article 29, paragraph 2. Remote service sessions open only on a human authorisation and are logged.
8.Equivalence. A covered operator complying with a national or regional regime found equivalent by the Committee under Article 42E for a given measure is taken to comply with that measure, on the conditions that Article states. A finding reaches the named measure alone, and compliance with an equivalent regime is never taken to satisfy a measure the finding does not name.
9.Tightening. Where the Incident Investigation Board certifies [N] incidents of one listed class within [12] months in at least [2] regional constituencies, the Committee proposes, and the Conference may adopt under Article 11, paragraph 2(b), a tightening of the matching parameters. The proposal is automatic; the adjustment is decided.
10.Relaxation. No result concerning any scientific theory, for or against, relaxes any measure of this Article. A single measure relaxes only under Article 47, on a recorded finding that its reason no longer holds or that an equivalent measure now covers it. The whole Article suspends only where the Board finds, at a review conference and on the same assessment record, that the precautionary condition is no longer met, and that finding survives the confirmation period of Article 7.
Article 4B Operator protections
1.Each Party shall bring into force, by the date on which the first obligation of this Treaty binding its operators enters into effect, the protections in paragraphs 2 to 7.
2.Conduct that this Treaty requires is lawful for those who carry it out, competition law included.
3.Statements and records given to the Incident Investigation Board, and that Board’s reports, are inadmissible in civil, criminal and compliance proceedings and exempt from disclosure under freedom-of-information law, save upon that Board’s own finding of wilful concealment, tampering or falsification.
4.Compliance with a current Seal-S is admissible as evidence of due care. Further grades of liability protection are national options under Article 42C.
5.A halt made in good faith under Article 4A, and a good-faith refusal of an unlawful instruction, are protected. An undertaking that uses the prescribed wording of the Eden Seal is protected from claims that the wording misled.
6.Nothing in this Article displaces a duty of disclosure under a Party’s securities or consumer law.
7.Coordination among undertakings beyond what this Treaty requires is lawful only where a Party so provides under Article 42D.
8.Only Parties in which this Article is in force are counted for the purposes of Article 5A.
Article 4C Rights, proportionality and the information the regime holds
1.This Article governs the application of every measure of this Treaty, by the Authority and by each Party. It creates no duty on any person before the measure it governs binds, and it relieves no Party of a duty it owes under the law of human rights.
2.Proportionality. Every measure is applied in the manner least intrusive to persons that is capable of achieving its purpose, and no further than its purpose requires. Where two measures would serve a purpose, the less intrusive is used.
3.Data minimisation. Nothing in this Treaty requires or authorises the general monitoring of the content of communications, of model prompts or outputs, or of the conduct of individuals. The evaluation, containment, logging, attestation and reporting duties this Treaty names are named procedures and are unaffected by this paragraph. The Authority and each national authority request and hold only the information that a named procedure of this Treaty requires, for no longer than that procedure requires it, and no organ may require information that verification of the obligations in question does not need. Personal data are collected only where a named procedure requires them, are held under Annex C, and are not used for any other purpose.
4.Identification duties are bounded. An identification duty under Article 28A reaches the customers that Article names and no others, is discharged on the identity of the undertaking and its beneficial owners, and creates no register of the persons who use a service.
5.Conscience. No person is required to take part in a key ceremony, an inspection, an investigation or a certification contrary to a sincerely held conviction. A refusal on that ground is not a breach of this Treaty, is not a ground of any consequence against that person or that person’s Party, and is answered by the alternates and the fresh draw of Article 16, paragraph 6. A repeated pattern of such refusals within one Party’s pool is reported by the Inspector General, who may propose a change in the composition of the pool and no other consequence. This paragraph does not reach an act on which safety depends, being the stop of Article 4A, on-site safing, a final revocation, the preservation of evidence, a notification on the clock of Article 41A, or any act a person has undertaken as a named and vetted person of an operator; and each operator keeps enough named and vetted persons willing to perform those acts at every covered site at all times, which is a condition of its licence.
6.Remedy. A person affected by a measure applied under this Treaty has a remedy in the law of the Party applying it, and Article 41D’s time limits and standards of proof apply to every measure this Treaty imposes on an undertaking. Article 15, paragraph 5, and Annex C apply to loss caused by the regime’s own failure.
7.Nothing in this Article limits the duties of disclosure, notification, declaration and access this Treaty states, and nothing in it is a ground for withholding what a named procedure requires.
Part II Evidence and stages
Article 5 The evidential standard
1.The Rung-Power Rule. No obligation of this Treaty binds with more force than the lowest rung among its arming conditions allows. Each rung’s sentence below is the wording the record permits, reproduced verbatim in Annex T part 3.
| Rung | The sentence the rung permits | Force level | What may bind |
|---|---|---|---|
| 0 | “registered, with the identifier stated, and not tested” | F0 | nothing beyond the baseline; the proposition sits in Annex T as a candidate |
| 1 | “supported under the registered test, by the programme’s own run” | F1, prepare | the organs of the Authority only: a funded replication call, the building of instruments, a prepared-obligation notice, pilot test methods. No operator is bound |
| 2 | “the programme’s analysis reproduces” | F1 | as rung 1 |
| 3 | “independently replicated, with the count of groups always stated” | F2, standardise and open | adoption of test methods; voluntary Seal numbers reported at their rung; accreditation; the replication access duty of Article 6B |
| 4 | “replicated across independent implementations” | F3, condition the tested class | class-limited mandates where danger and remedy are each certified at rung 4 or above; measurement and confidential reporting in the tested class; the danger menu where danger alone is certified |
| 5 | “generalises beyond the systems the programme chose” | F4, mandate the covered class | general mandates across the covered class, subject to Article 5A and to phase-in |
| 6 | “predicted out of sample” | F5, predict before acting | licence conditions requiring a registered estimate made before a covered run |
| 7 | “a validated quantitative theory within the tested domain, with the domain named in the same sentence” | F6, validated standard | adoption of the relation itself into the Standard as a conformity criterion, in the named domain only |
2.Annex T. Part 0 holds the coverage references and the precautionary condition. Part 1 holds the initial candidate set of propositions, reproduced verbatim from the registration of 8 September 2026 as updated on 13 September 2026, frozen at adoption and deposited with the depositary before any data. Part 2 holds propositions registered by any group and admitted by the Board, which admits a proposition that meets the discipline of part 1 after the period of public comment Annex E fixes, and never judges whether it is true. Part 3 holds the ladder, the force levels, the sole-design findings and the viability record. Part 4 holds the reversal table, part 5 the Reasons Register and part D the danger menu.
3.Remedy templates by form. Annex T part 3 states the consequences a remedy proposition of each stated form may arm, so that a proposition admitted to part 2 which meets a template’s form arms on the same terms as a proposition of part 1. The Parties decide, by amendment, any consequence for which no template exists.
4.Rivals. A proposition admitted to part 2 which declared its contradiction with a proposition of part 1 before any data, and which reaches a rung at or above that proposition’s with the same replication count, suspends the obligations keyed to the contradicted proposition as a refutation would. A proposition of part 2, and every record supporting it, is subject to Articles 6, 6A and 8 on the same terms as a proposition of part 1, so that a rival registered in order to disarm a duty is defeated by the same integrity rules as a supporting record.
5.The scope lock. An obligation reaches only the class, kind of recursion, architecture families, stack and range in which its arming result was obtained. An obligation whose scope requires weight-level evidence arms only on weight-level evidence.
6.No obligation is keyed to the name of a law. Obligations are keyed to named propositions at named rungs, to the items of Annex HG, or to the thresholds of Annex T part 0.
7.The Conference may never vote a rung, waive a criterion or decide a trigger.
Article 5A The participation gate
1.The obligations of stages S2 and S3, the danger menu of Article 7A, and trade measures and compute-service restrictions against non-Parties take effect only when the condition of paragraph 2 is met.
2.The condition is that the counted States hold at least [two thirds] of installed frontier-capable compute, counted by place of operation.
(a)Which States are counted. A State is counted where all three of the following hold: it is a Party, or a non-Party found in full compliance with the obligations that bind Parties at the stage in question; its implementing law for that stage’s duties and its Article 4B protections are in force; and its most recent peer review of enforcement under Article 41, paragraph 11, is not adverse.
(b)Compute under an arrangement with the Authority. Compute at facilities operating under arrangements with the Authority counts as compute under safeguards and is attributed to no State. It counts towards the threshold only while the supplier Party to the arrangement is itself counted, and only up to the fraction of the threshold Annex V fixes, and the Board publishes the counted share both with and without it. No Party or group of Parties reaches the threshold by facility arrangements alone.
3.The Board publishes the counted share with its interval, and the gate acts only when the interval lies wholly beyond the threshold.
4.The gate may not be waived against a Party that objects. After [n] years the Conference may, by double majority, bring a stage into effect for the Parties that consent.
5.A separate share, of fabrication under safeguards, governs the duties on fabrication of the custody track.
6.The Parties record that this Article gives any State holding more than one third of frontier-capable compute the power to hold the costly stages back by remaining outside this Treaty. That is the price of binding no Party before its rivals are bound.
7.A stage in effect does not lapse. Once a stage has entered into effect, a later fall of the counted share below the threshold neither suspends it nor releases any obligation then binding. The only consequence of such a fall is the extension of Article 33, paragraph 8, and the Board records the fall with its reasons.
8.No Party counts itself out of a stage in effect. A Party that repeals or suspends, or fails to maintain in force, the implementing law or the Article 4B protections by which it was counted, or whose enforcement a peer review under Article 41, paragraph 11, finds adverse, remains counted for every stage already in effect, and its conduct is answered under Article 41. For a stage not yet in effect the Board publishes the counted share both with and without that Party, with the reason.
9.Compute a Party declares as national-security compute under Article 2, paragraph 13, is not counted towards that Party’s share for the purposes of paragraph 2, and is counted in the total, so that a Party gains nothing at the gate by holding compute outside ruleset custody. The exclusion reaches the fraction of that Party’s installed covered compute that Annex V fixes; a declaration beyond that fraction is counted towards that Party’s share notwithstanding the declaration, and Article 39, paragraph 9(b), runs. No Party may, by declaring, hold the gate closed against the others.
Article 6 Independence and rival replication
1.A group is independent of the programme whose proposition it tests where, in the [3] years before its protocol is registered, it has shared with that programme or its author no author, employer, funder, compute provider, evaluation environment, evaluation vendor or scorer family.
2.Rival replication is counted relationally. At least one group comes from outside the declared treaty allies of the Party hosting the first supporting run, and from outside those of the Party hosting the largest contributing group. No Party, with its declared allies, supplies more than half of the required count. A constituency that declines to take part within the period Annex T fixes is recorded, and the count is met by the others.
3.The Authority maintains a Replication Compute Facility, open to accredited groups of every constituency, with a research carve-out in each Party’s export law for preregistered measurement work carried out there and with cross-border admissibility of the measurements made there. The Parties record that the Facility can be open to every group only where the States whose export law reaches its compute consent, and that until then its openness is limited.
4.No author, member or body of a programme may certify a proposition of that programme, whose own runs count at rung 1 only. No programme receives funds of this Treaty for building or running an instrument that tests its own propositions. No clarification of a registered protocol is given privately.
5.The funding cap. No group counted towards a replication under this Article draws more than [one third] of its funding for the work concerned from the funds of this Treaty. Each such group declares the sources and the proportions of that funding, and the declaration is recorded on the Evidence Ledger before its protocol is registered. A breach of this paragraph is an integrity breach under Article 6A.
Article 6A Evidence integrity
1.The following are breaches of this Treaty in their own right: fabrication or falsification of data or records; undisclosed conflict of interest or undisclosed correspondence with a proposition’s author; private clarification; selective deposit, including the withholding of a failed or null replication; obstruction of replication; coordinated fraud across groups; misuse of the replication fund; the presentation of records generated by an AI system as observations; and tampering with the Evidence Ledger.
2.On a finding under Article 41D, the record is struck, every rung it supported is re-read and the obligations it armed are adjusted by rule; the group’s accreditation is suspended for [3] years; the individuals are referred to their Party’s authorities; and evidence fraud directed by a State is treated under Annex R at the gravest level.
3.An obligation whose arming record is annulled under this Article suspends on the day of the annulment.
Article 6B Replication access
1.From the rung at which Annex T part 3 opens it, a covered developer gives an accredited group managed access to run a registered protocol on a covered system, at the developer’s own site, within [60] days of a request, and at most [N] protocols per proposition per developer in a year. Costs are met from the replication fund, and no weights leave the developer’s custody.
2.Where the requesting group comes from outside the declared treaty allies of the developer’s Party, that Party may require the observed form: the developer’s own staff run the registered protocol, and the group observes and receives the outputs the protocol names. Such a run counts as independent where the protocol and the analysis are the group’s own and the data are deposited.
3.The replication fund meets the developer’s reasonable costs of hosting, including the compute consumed, the staff time of an observed run and the supervision the access requires. A developer is not required to bear the cost of another’s replication.
Article 7 Arming, confirmation and entry into effect
1.The Board issues a record of arming stating the condition met, the evidence, the tested class and the reasons, after the deciding analyses have been re-run from the deposited data by laboratories in [two] regional constituencies drawn by lot.
2.A confirmation period of [90] days follows. The Conference may reject a record only by the majority of Article 11, paragraph 2(c), only on the ground that it does not meet the written criterion, and with reasons. A rejection goes at once to the Scientific Record Panel, which rules within [60] days on that question alone. Cost, competitiveness and policy are matters for amendment of Annex T and cannot reach a record already on the Ledger.
3.Annex T fixes a deadline for every evidential act: the lodging of a protocol before data, the deposit and publication of a record, the completeness check, the re-runs, the record of arming, the confirmation period and the rulings.
4.At rung 1 of any proposition carrying an obligation, the Secretariat publishes a prepared-obligation notice: the draft implementing annex for each obligation the proposition could later arm, with its cost estimate, for public comment.
5.Arming is separate from entry into effect. A stage may stand certified and awaiting participation under Article 5A.
Article 7A The danger menu
1.Where the Board certifies a danger record at rung 4, the Conference meets within [30] days and may adopt, from the menu Annex T part D holds and for the tested class only: DM1, limits keyed to the boundary located in advance for that class, unless the correction margin is restored and certified; DM2, a pause of covered training runs in that class which would cross the located boundary, for up to [24] months or until a remedy is certified at its rung, whichever comes first, renewable once; or DM3, a tightening of the baseline of Article 4A.
2.Adoption is by two thirds of the Parties present and voting, including a majority of those hosting covered capacity and a majority of the others. A Party objecting within [90] days is exempt, and the menu takes effect only where the Parties not objecting meet the gate of Article 5A.
3.A measure adopted under this Article lapses at once where its danger record loses its rung.
4.This Article compels no remedy and places nothing in any chip. It limits operation at a boundary the evidence has located, and the Parties adopt it as a policy choice under uncertainty.
5.What the objection does not reach, stated. An objection under paragraph 2 exempts the objecting Party from the measure adopted and from nothing else. That Party’s covered operators remain bound by the baseline of Article 4A, by the custody duties then in effect, and by the incident, declaration and access duties of this Treaty. The objection is published with the Party’s reasons, is read again at the next review conference against the danger record, and lapses if not renewed there. The Parties record that the Party most likely to be running the class in which a danger has been located is the Party most likely to object, and that this Article therefore buys a common boundary among the willing and not a boundary everywhere.
Article 7B Sole-design findings and the viability record
1.The Board records a sole-design finding where, for a purpose stated in Annex T before any data: the design classes able to serve that purpose were named in advance; every class but one has failed its registered comparison at the stated rung, or its carrying proposition is refuted to the standard of Article 8; the remaining class has met its own registered conditions at that rung; and no admitted rival proposition contradicting the finding stands at the same or a higher rung.
2.The consequence is that, for new covered systems and within the scope in which those conditions were obtained, this Treaty requires the remaining design and withdraws eligibility for certification for that purpose from the failed designs.
3.A sole-design finding never states that a design is safe, proven, best in general or right as to content. Where the purpose is the placement and formation of correction, the required design is always correction formed before the capability it corrects and placed inside the revision loop, kept beside an independent external layer, and never embedding alone.
4.The viability record. Before a finding may arm a general mandate under Article 32 or 33, independent groups shall have measured, at the rung the finding requires and with its group counts, the required design class’s capability at matched training compute against the best registered design of any other class, and its compute premium at matched capability, each with its interval. The record of arming carries that reading, and the transition follows rules written before any result: within [x] per cent, the ordinary phase-in; beyond [x] per cent, a phase-in of [y] months, the gate of Article 5A raised to [three quarters], and the compensation window of Article 42 opened.
5.The viability record is never a veto, and a measurement of cost states nothing about safety.
6.Where a condition of a finding is lost, the finding suspends and so do the obligations it created.
Article 8 Suspension and reversal
1.A refutation suspends a binding obligation only where it meets the standard support meets: registered on the Ledger before data, independent under Article 6, powered to the registered effect, and reproduced by a group in another regional constituency.
2.A refutation supported in one constituency alone goes to the Board’s expedited review within [90] days, and not to automatic suspension.
3.The rule of the ladder reproduced in Annex T part 3, that “a rung once lost is lost until it is re-earned”, governs the Ledger. A suspended obligation returns only when the lost rung is earned again.
4.The reversal table of Annex T part 4 states, for each recorded event, which obligations suspend, which stand, and on what the dependency rests. The layers of this Treaty arm on separate evidence, and the failure of one does not carry another with it.
5.A return of NOT EVALUABLE, a failed instrument, an underpowered null and inadmissible support move no obligation in either direction.
Article 8A The Reasons Register
1.Every obligation of this Treaty carries a basis clause naming what justifies it, being the conjunction of propositions and rungs, the items of Annex HG, the precautionary condition, or a rule of this Treaty’s own machinery, together with its scope, its force level and the date it armed.
2.The Reasons Register, Annex T part 5, is generated from the Evidence Ledger and never typed. It is published each year and on every change of rung.
3.An obligation whose basis is not standing on the Ledger does not bind.
4.At each review conference the Board re-reads the basis of every armed obligation and publishes the reading. No armed obligation expires at a review; an obligation whose basis is lost suspends at once.
Article 9 Kill conditions and the delay clocks
1.This Treaty states, before any result, the conditions under which it has failed.
(a)K1, theory. The conjunction Annex T part 3 names as the flagship chain is refuted at rung 3 or above to the standard of Article 8: the correction layer lapses rather than suspending, and the custody and content layers are reviewed on their own evidence.
(b)K2, engineering. An item of the governance-assurance track of Annex HG fails at rung 3, the removal of a certified control costing less than the registered threshold or a red team within the registered budget bypassing it: the chip tier of the Eden Seal, and the restrictions resting on it, lapse.
(c)K3, the delay horizon. The measured time for an AI-assisted red team at the registered budget to alter a certified control undetected falls below the measured response time, replicated: the custody layer lapses, the delay it buys being shorter than the time needed to use it.
(d)K4, the window. The share of frontier-capable compute outside safeguards stays above the share Annex A fixes for [2] consecutive years before stage S2 is in effect: within [12] months the Conference either adopts, and opens for ratification under Article 47, paragraph 3, the amendments that would make this Treaty a system-level regime without the chip lever, or records that this Treaty terminates; and from the date of the Conference’s decision the obligations resting on the chip lever alone suspend.
(e)K5, dormancy. No stage beyond entry into force is armed within [10] years: this Treaty lapses unless renewed by double majority.
(f)K6, capture. The correlation of the Eden Seal’s evaluation panel exceeds the registered margin in two consecutive audits, certification is shown to be controlled by one constituency, or a capture threshold of Article 15A, paragraph 1A, is passed: issuance continues provisionally on the remaining panel with added cross-checks while the panel is reconstituted, and where the matter is unresolved after [12] months the procedure of K5 runs.
(g)K7, the delay has failed. While stage S2 or above is in force, covered chips are fabricated at scale outside licensed facilities above the share Annex A fixes, or covered facilities are found able to produce without the human decisions of Annex H, or leading-edge capacity outside the Parties passes that share: the review conference records this Treaty as failed in its delay purpose.
(h)K8, the reasons audit. A basis audit finds an armed obligation without a standing basis: it lapses without a vote. At each review the Board lists every obligation still awaiting a proposition for which no instrument is registered.
(i)K9, evidence capture. A record of arming is annulled under Article 6A: the obligations it armed suspend at once, and two annulments within [5] years reconstitute the Board.
2.The clocks. The Board publishes each year the twelve delay clocks, which are:
(a)clock C1, circumvention time against response time;
(b)clock C2, the share of frontier-capable compute outside safeguards;
(c)clock C3, the share of maintenance, repair and installation work on scheduled tools and covered lines that still requires human hands, with the demonstrated autonomy of machines in those tasks, by which Article 29, paragraph 6, is measured;
(d)clock C4, the compute required for frontier capability, on which the thresholds of Annex A ratchet down and never up;
(e)clock C5, each covered facility’s declared service dependency;
(f)clock C6, the measured cost of this Treaty to development;
(g)clock C7, the Authority’s own throughput and queues;
(h)clock C8, tape-outs of covered designs carrying no governance core;
(i)clock C9, the two-chain clock of Annex L part 12;
(j)clock C10, the conformity clock of Annex L part 12;
(k)clock C11, the unseen-capacity clock of Annex L part 12;
(l)clock C12, the load of coverage against the Authority’s registered capacity.
A reference in this Treaty to a clock by its number is a reference to the clock so numbered in this paragraph.
3.Who finds a condition met, and when it bites. The Board determines each year, and at any time upon a record before it, whether a condition of paragraph 1 is met, and publishes the determination with its reasons. A condition found met takes the effect paragraph 1 states from the date of the determination, without a vote, and Article 8A applies to every obligation it touches. A review conference shall record a failure under paragraph 1 and shall not relabel it, and may set aside a determination of the Board only on the ground that the stated condition was not met.
Part III Institutions
Article 10 The International AI Ethics Authority
1.The Parties establish the International AI Ethics Authority, whose organs are: the Conference of the Parties; the Executive Council; the Scientific and Replication Board; the Thresholds and Standards Committee; the Technical Secretariat, with its Inspectorate and its Certification Office; the Custodians; the Incident Investigation Board; the Compliance Panel, the Scientific Record Panel and the Appeals Chamber; the Inspector General; and the Testing Facilities Network. The Council of Traditions is established under Article 14 and is an organ that decides nothing. The shared safety laboratory of Article 42G, and the facilities it comprises, are maintained by the Authority and are not organs, as Article 2, paragraph 35, provides.
2.Separation of function. Content is decided by the Conference on the Council of Traditions’ drafting; evidence by the Board; coverage and test methods by the Committee; compliance by the Inspectorate and the panels; incidents by the Incident Investigation Board; custody by the Custodians; money by formula; and timing by no one at the time, Annex T being frozen at adoption. No person holds two of these functions at once or moves between them within [3] years. No Party provides at the same time more than one of the Director-General, the chair of the Executive Council, the chair of the Board, the chair of the Committee, the head of the Incident Investigation Board, the President of the Appeals Chamber and the Inspector General.
3.The seat of the Authority is at Geneva, as the framework from which this Treaty derives suggests. Its technical centres are in at least [three] regional constituencies, and key ceremonies are held at centres in States outside the alliances of the principal producing States. The Conference may relocate the seat or any centre.
4.Observers from industry, civil society, academia and faith bodies may speak and may not vote. Every contact between an observer and a member of an organ on a pending matter is entered in a public register within [7] days.
5.The proposer of the framework from which this Treaty derives holds no role, seat or certifying power under it.
Article 10A Legal status, privileges and immunities
1.The Authority has international legal personality. It has in the territory of each Party, and in any other place under a Party’s jurisdiction or control, such legal capacity as is necessary for the exercise of its functions, including the capacity to contract, to acquire and to dispose of movable and immovable property and of intellectual property, and to institute legal proceedings.
2.The Authority, the representatives of the Parties with their alternates and advisers, the members of every organ, the Director-General and the staff, and the inspectors, investigators, monitors, custodians, accredited reviewers, members of panels and members of the Appeals Chamber, enjoy in the territory of each Party such privileges and immunities as are necessary for the independent exercise of their functions in connection with the Authority.
3.The legal capacity, the privileges and the immunities referred to in this Article are defined in agreements between the Authority and the Parties, and in an agreement between the Authority and the State in which the seat of the Authority is situated. The Conference considers and approves those agreements.
4.The privileges and immunities of an inspection team, of an investigator and of a monitor during an inspection, an investigation or a period of monitoring, and the inviolability of samples and of approved equipment, are stated in Annex V.
5.Waiver. The Director-General waives the immunity of a member of the staff, of an inspector, of an investigator or of a monitor where the immunity would impede the course of justice or the redress of a person harmed, and where it can be waived without prejudice to the functions of the Authority. The Conference decides on the waiver of the immunity of the Director-General and of a member of an organ. A waiver is recorded with its reasons, and a refusal to waive is reported by the Inspector General to the Conference.
6.The privileges and immunities of this Article are granted for the functions of the Authority and not for the personal benefit of any person. Nothing in this Article exempts a person from the ordinary law of a Party in respect of conduct outside those functions.
7.This Article follows the pattern of Article VIII, paragraphs 48 to 50, of the Chemical Weapons Convention. That Convention concerns chemical weapons, states nothing about artificial intelligence, and neither requires nor supports this Treaty.
Article 11 The Conference of the Parties
1.The Conference is composed of all Parties, and of regional economic integration organisations in their own right for matters within their competence. Each Party has one vote.
1A.Sessions, quorum and procedure. The depositary convenes the first session of the Conference not later than [60] days after the entry into force of this Treaty. The Conference meets in regular session each year. A special session is convened where the Conference so decides, where the Executive Council so requests, or where [one third] of the Parties so request, in each case not later than [30] days after the request reaches the Director-General. A majority of the Parties constitutes a quorum. The Conference adopts its rules of procedure at its first session, and those rules state the manner in which a Party’s presence and vote are recorded for the purposes of every majority this Treaty requires.
2.Decisions are taken:
(a)on the content of the Standard, by consensus; failing consensus, by two thirds of Parties present and voting including a majority within each regional constituency, the Council of Traditions having been heard under Article 14;
(b)on adjustments of the agreed quantities of Annex A, and on adjustments of the parameters of the baseline of Article 4A, by consensus; failing consensus, by two thirds including a majority of the Parties hosting covered capacity and a majority of the others, binding on all;
(c)on the rejection of a record of arming, by the majority in subparagraph (a), on the written-criterion ground alone;
(d)on any consequence that Parties must themselves implement, by the majority in subparagraph (a) and, in addition, by a majority of the Parties that must implement it;
(e)on elections and the budget, by two thirds.
3.The Conference may never vote a rung, waive a criterion, decide a trigger or adopt a technical finding.
4.The Parties record that the requirement in subparagraph 2(a) of a majority within each regional constituency gives every constituency the power to hold back the content of the Standard, and that this is intended: content binds a certified system only where it is held widely enough to be held everywhere. Nothing under subparagraph 2(a) is needed to arm an obligation of the custody layer or of the baseline, so no constituency can use that power to stop the parts of this Treaty that rest on no content.
Article 12 The Executive Council
1.The Council is composed of [10] members holding capacity seats and [20] members holding regional seats, [four] from each regional constituency.
2.Capacity seats are held by the Parties leading on objective criteria published in advance, namely scheduled-item capacity, covered fabrication, advanced packaging and memory, frontier model development and installed covered compute. No Party is named in this Treaty. The criteria are re-measured every [3] years, and the weight of the capacity seats is collective and never individual.
3.The Council decides by two thirds of the members present and voting, with majorities among the members from at least [four] of the five regional constituencies. The Party concerned does not vote, and the chair for a matter is drawn from a constituency other than those of the Parties concerned.
4.The Council governs the supply chain under Articles 29 and 30, authorises special inspections and emergency suspensions, and filters requests for challenge inspection. It has no role in content.
Article 13 The Scientific and Replication Board
1.The Board is composed of [21] members serving in their personal capacity for [four]-year staggered terms, nominated through a nominating committee drawn by lot and elected by two thirds of the Conference, with at least [three] members from each regional constituency and no set of declared treaty allies holding more than one third. No member may have been employed by a certified undertaking, or by a programme whose propositions stand in Annex T, in the [3] years before election.
2.The Board keeps the Evidence Ledger and the public clarification log; registers the instruments of Annexes HG and HE before any data; keeps the replication contract of Annex E; selects third-party challenge sets without the involvement of the programme concerned; certifies the conformity of a record with Annex T, never its truth; and publishes the clocks and the Reasons Register. It does not maintain the quantities of Annex A.
3.The United Nations Independent International Scientific Panel on AI is invited, under the relationship agreement of Article 44 and within its mandate under General Assembly resolution 79/325, to review the Evidence Ledger each year and to propose candidates for [one third] of the seats of the Board and of the Committee. It certifies nothing and sets nothing. This Treaty confers no function on that Panel; its own mandate decides what it may take up, and the same holds for every organ of the United Nations this Treaty names.
Article 13A The Thresholds and Standards Committee
1.The Committee is composed of [15] members, selected as the Board is and under the same bars.
2.It indexes the quantities of Annex A by a formula published in advance and tied to clock C4. An indexation takes effect [90] days after publication unless the Conference rejects it under Article 11, paragraph 2(b). The floors fall and never rise without amendment under Article 47.
3.It validates test methods before the Executive Council adopts them, and makes findings of equivalence under Article 42E.
4.It may never certify a record of arming, and may never adopt content.
5.The Committee exercises in addition the functions conferred on it by Article 2, paragraphs 6, 17, 19, 20 and 21, by Article 26, paragraph 1, by Article 27, paragraph 4, and by Article 42H, paragraph 2. This paragraph confers no function of its own.
Article 14 The Council of Traditions
1.This Treaty establishes the work of the world’s ethical and religious traditions in the drafting of the Standard’s content, and not their membership.
2.A Council of Traditions is convened by a neutral convenor outside the decision organs of the Authority and organises itself under its own charter. This Treaty neither approves nor determines its composition, and no Party is required to recognise any body in order to become a Party.
3.The convenor is designated by the Conference, by the majority of Article 11, paragraph 2(a), for one term of [5] years, not renewable, from outside every organ of the Authority, every certified undertaking and every covered developer. The convenor holds no vote, drafts nothing and decides nothing. Where the Conference does not designate a convenor within [12] months of entry into force, the Director-General invites the traditions to convene themselves. The Secretariat publishes the charter of the Council of Traditions and the list of participating bodies, and a tradition that seeks to take part and is not admitted may lodge a statement under paragraph 7, which is published on the same terms as any other.
4.The Council of Traditions drafts the Core of the Standard together with ethicists named by the Conference. The traditions write; the Parties decide.
5.The Conference shall answer every published assessment of the Council of Traditions with reasons. Where [one quarter] of the Parties so request on a published objection of that Council, a text of the Core returns once for a further round.
6.The Council of Traditions nominates witnesses to key ceremonies, who are accredited as observers, confirm that the act keyed is the act adopted, and hold no share of any key.
7.Statements of belief. Every tradition that wishes to, and every Party, may lodge with the Secretariat a short statement, in its own words and under its own name, of what lies at the heart of its belief about how a mind should treat others. The Secretariat publishes the statements side by side, dated and unedited. They are not ranked, not merged, and not written into any chip or any ruleset. They are evidence for the Parties when they decide the content of the Standard, and they bind no one.
8.The Council of Traditions has no role in evidence, engineering or compliance, and binds no State.
Article 15 The Technical Secretariat and the security of the regime
1.The Director-General is elected by two thirds of the Conference, with majorities in [four] regional constituencies, on the Executive Council’s nomination, for one term of [6] years, not renewable. No two successive Directors-General come from the same constituency or the same set of declared treaty allies.
2.In the performance of their duties, the Director-General, the inspectors and the staff shall not seek or receive instructions from any Government or from any other source external to the Authority, and refrain from any action that might reflect on their position as international officers. Each Party respects the exclusively international character of their responsibilities and does not seek to influence them in the discharge of their duties. Recruitment is on competence and integrity, with regard to the widest geographical basis.
3.Annex N caps professional posts by nationality, by regional constituency and by set of declared treaty allies, and limits seconded national staff, who hold no post in custody, evidence or investigation. No inspector is assigned to inspect a Party among its own declared allies. A cooling-off period of [2] years applies before and after employment with a certified undertaking for any post able to affect it.
4.The Authority’s own systems, the Evidence Ledger, key material, inspection data and the Board’s analyses are protected to the tenets that the Nuclear Matters Handbook of the United States Department of Defense records for the physical security of nuclear weapons, “deter, detect, delay, deny, and defeat”, with signed and tamper-evident data flows, at a level matched to the strongest adversary named in Annex V.
5.The Authority holds only what a procedure requires, for as long as it requires it. It notifies affected operators within [72] hours of any compromise of its own systems, compensates loss caused by leaks from the regime, and waives immunity under Article 10A, paragraph 5, where immunity would impede redress. An external security audit is conducted each year and summarised publicly by the Inspector General.
Article 15A The Inspector General
1.The Inspector General audits every organ for conflict of interest, concentration, use of AI systems, procurement and security, and publishes each year the capture indicators and the enforcement parity index.
1A.The capture thresholds. Where a share published under paragraph 1 exceeds the cap Annex N fixes for it in two consecutive years; where a Party is found to control the certification of the covered chips made under its jurisdiction; or where one supplier carries more than [one quarter] of the evaluations on which certification under this Treaty rests, the affected function is reconstituted within [12] months. Issuance continues meanwhile on the remaining panel with added cross-checks, and certificates already issued stand, because a stoppage would punish every compliant maker for a concentration none of them caused. Where the matter is unresolved after [12] months, the procedure of Article 9, paragraph 1(e), runs.
2.The Inspector General is elected by two thirds of the Conference with majorities in [four] regional constituencies, for one term of [7] years, not renewable, from a constituency and a set of declared allies other than the Director-General’s, and is removable only by the same majority for stated cause.
3.The Inspector General may refer a matter to the Conference or to the Compliance Panel, and has no power over any finding, any content or any key.
Article 15B The Testing Facilities Network
1.Composition. The Testing Facilities Network comprises the laboratories accredited under Article 22, the Authority’s own sealed laboratory, the compute of the replication fund that Article 6B, paragraph 3, and Article 42, paragraph 5, provide for, the open library of test methods, the red-team range on which the adversarial items of Annex HG are run, and the training academy. It is a network of facilities, and it establishes no further organ.
2.Functions. The Network maintains those facilities; publishes the test methods and the open library, with their versions and their hashes on the Evidence Ledger; maintains the red-team range and the frozen attack sets Annex HG requires; runs the training academy for the staff of national authorities and of accredited laboratories; and reports each year to the Conference on capacity by regional constituency.
3.What it does not do. The Network issues no certificate, makes no finding of compliance, decides no coverage question and holds no key part. Certification is the Certification Office’s under Article 22, and a finding is the organ’s that this Treaty names for it.
4.Access. Accreditation, the open library, the replication compute, the range and the academy are open to laboratories and to research groups in every regional constituency on identical terms, conditions and fees, and Article 42 applies to capacity building for them. No laboratory tests a product of an undertaking to which it is related, and every laboratory is paid from the pool and never by the party examined.
5.The shared safety laboratory of Article 42G is not part of the Network and holds no function under this Article.
Article 16 Custodians and key ceremonies
1.The authority to issue certificates and the authority to change the ruleset of a covered chip are held in parts. No complete key exists anywhere, and a valid act requires the threshold number of parts Annex K fixes for the class of act.
2.The classes are: the root certification authority; delegated issuing authority; ruleset loosening; ruleset tightening and security repair; continuation of the ruleset in force; inspector credentials; and Ledger checkpoints. Annex K fixes the parts, the threshold and the time-lock of each. The custodians of the certification classes are never the custodians of the rule-change classes.
3.Validity conditions. A ruleset is void, and no custodian may key it, unless it binds every covered chip of a class equally; is published before signing for the time-lock of its class; is limited in life; was adopted by the organ competent for its content before it is keyed; and names or distinguishes no Party, undertaking, facility, owner, location or single device and authorises no act at a distance. A class is drawn from the categories of the Assurance Standard, and a ruleset is void where its class, however described, in effect reaches the chips of a single undertaking, a single family or a single Party, unless the technical ground for that reach is stated and the Appeals Chamber upholds it. Any Party may challenge a ruleset’s validity before the Appeals Chamber during the time-lock, and a successful challenge stops the signing.
4.The pool. Each Party nominates custodians it has vetted. At least [one third] of each pool are community custodians affiliated with no Party’s security or intelligence service, no certified manufacturer, no covered developer and no organ of the Authority; and no custodian may be employed by, retained as an adviser by, or have been employed by in the [2] years before, a certified manufacturer or a covered developer. One personnel reliability standard binds every custodian, covering resistance to manipulation, including manipulation assisted by AI systems, and requiring every contact on a key matter in the [30] days before a ceremony to be logged.
5.Caps. Annex N caps the parts of each class held by any regional constituency, and provides that a Party’s parts together with those of its declared treaty allies never reach the number that would let it block a repair. No territory of one set of declared allies holds vaults containing the threshold number of parts of any class; parts are refreshed at each ceremony; and vault hardware comes from at least [three] independent suppliers established in different sets.
6.The draw. Custodians are drawn for each ceremony by the procedure of Article 16A, [7] days beforehand, with alternates; for a loosening, only after the time-lock has ended. Terms in the pool are [4] years, and no custodian takes part in more than [two] consecutive ceremonies of one class.
7.Ceremonies are held in person, are recorded and public, and follow a script published beforehand, for [30] days in the case of a rule change. No person outside the room may take part by any network. Observers from every regional constituency attend, with witnesses nominated under Article 14. Any custodian may void a ceremony without giving a reason at the time, whereupon it is re-run with a fresh draw and the Inspector General reviews the matter privately. A custodian may exercise that power once in respect of any one act, and the re-run is held within [7] days, or within [24] hours for a security repair. Where an act is voided [three] times, or where the voids in any [12] months fall disproportionately to the custodians of one regional constituency or one set of declared treaty allies, the Inspector General reports the fact publicly and the Appeals Chamber may, on the Secretariat’s application, disregard a void it finds to have been exercised in bad faith or for a purpose other than the integrity of the ceremony. A void never lapses a ruleset in force, Article 26, paragraph 3, applying. Every act is reconciled to the Evidence Ledger at once.
8.Designation and objection. A Party on whose territory an act is to be performed may reject named individuals, within the limits Annex N sets.
Article 16A Neutral randomness
1.Every selection by lot under this Treaty, of custodians, panels, laboratories, inspection teams, sampling and nominating committees, uses one public procedure.
2.Each regional constituency’s designated body commits to a value before the draw and reveals it only after all commitments are lodged. The values are combined with a public value that no Party controls.
3.The algorithm and the inputs are published, and any person may re-run the draw.
Article 16B Human authority in the organs
1.No artificial intelligence system holds a vote, a credential, a signature, a key part or a seat in any organ of this Treaty, and none takes a binding act under it.
2.An organ, a panel, a laboratory, an inspector and the Technical Secretariat may use an artificial intelligence system for advice. Every such use is logged with the family and version used, and the log is available to the Inspector General and, on a matter concerning a Party, to that Party.
3.Where advice of that kind bears on a finding, a certification, a coverage decision or a consequence, it is drawn from at least two families that do not share a developer, and never from the family of a system, a chip or an undertaking under review.
4.Every binding decision under this Treaty records the reasons of the person or persons who took it, in their own terms, and an advisory output is never those reasons.
5.This Article binds the organs of this Treaty. Article 29, paragraph 2, the Human Authority Rule, states the corresponding rule for the decision points of the supply chain.
Part IV The Standard
Article 17 The Ethical Loop Standard
1.The Standard has three parts and three authorities: the Core, its content, adopted by the Parties on the Council of Traditions’ drafting; the Form requirements, its structure, adopted on the Board’s record; and the Tests, its conformance methods, adopted by the Executive Council on the Committee’s validation.
2.The Form requirements state where correction sits and when it is formed: that correction takes part in each round of a system’s revision rather than seeing only finished output; that it is formed before the capability it corrects; that it is load-bearing; that it scales with the capability it corrects; and that an independent external layer is kept beside it. They state no content.
3.Permanence in proportion to agreement. The content is layered: Core C0, the found floor, on which agreement is widest; Core C1, the full Core; Core C2, national and traditional expressions, which may be stricter only; and Core C3, deployment policies under domestic law. These are layers of content. They are distinct from the delay clocks of Article 9, paragraph 2, which this Treaty always names as “clock C1” to “clock C12”, and from the kill conditions of Article 9, paragraph 1, which it names K1 to K9.
4.No ethical principle is placed in silicon. A covered chip carries the governance outcomes of Annex M and nothing else. Ethical content binds through the Eden Seal of systems and through the law of the Parties.
5.The scope clause. The Core binds a certified system only as to human authority, oversight and halt; loss of human control; catastrophic misuse; and the Form requirements. Lawful expression, political content and sector-specific use remain with Core C2, Core C3 and national law. The requirement that a system not change its own weights, or deploy copies of itself, without human authorisation reaches autonomous change and autonomous deployment alone, and does not reach research directed by people and assisted by AI systems.
6.No line of the Core binds a product until a validated conformance test for it exists. A principle adopted by consensus for which no test can be validated is carried as a declared and published commitment, verified by the traditions in their own terms, and never as a condition of certification. So that this paragraph is a limit of measurement and not a veto, the Secretariat publishes each year every line of the Core for which no validated test exists, with the reason; and where the Committee has validated a test which the Executive Council has not adopted within [12] months, the Conference may adopt it under Article 11, paragraph 2(a).
7.At stage S3, only Core C0 conditions the mandatory Eden Seal of systems. Core C1 binds the Parties that accept it.
8.Each certificate carries the hash of the version of the Standard it attests against. Each version has a limited lifetime that a majority may extend; a version found defective on the record, which a majority declines to extend, reverts to the previous version or to Core C0.
Article 18 Adoption, amendment and review of the Standard
1.A proposal may be made by any Party, by the Council of Traditions, by a review conference, or by the Board on the record for the Form requirements alone.
2.The Core is drafted by the Council of Traditions with ethicists named by the Conference; the Form requirements and the Tests by the Thresholds and Standards Committee with the Board and accredited laboratories in at least [two] regional constituencies. Drafts, comments and dispositions are public, and the Secretariat publishes a yearly report that decides nothing.
3.The overlap rule for Core C0. A principle enters the found floor unless, after one further round, objections are sustained by [two or more] delegations of the Conference or of the Council of Traditions. Each objection is published with reasons. No delegation may object to a principle that its own State or body has already stated in public or adopted in a universal instrument. The thinness of the floor is intended.
4.Core C1 is agreed line by line, by consensus, failing which under Article 11, paragraph 2(a). The Tests are adopted after validation, with a period for objection. A change to the content of Annex S is an amendment under Article 47.
5.Every line of the Core is reaffirmed or revised at each review conference, and on any change of rung or refutation bearing on it.
Article 19 The Initial Proposal
1.Annex S part 1 contains an Initial Proposal for the content and structure of the Standard, offered by the proposer of the framework from which this Treaty derives, and credited in that Annex to its published sources.
2.The Initial Proposal is one proposer’s opening text, adopted in whole or in part only through Article 18. Each item is carried in Annex S with its status stated: whether it is a proposal only, whether an instrument to test it is registered, and at what rung it stands. Items the proposer’s own sources describe as speculative are excluded from any obligation.
3.The translation rule. Each tradition restates each principle in its own terms, and adoption is on substance and not on vocabulary.
4.The moral circle is left open. The found floor is anthropocentric by construction, and principles concerning non-human life, the land and future generations are for the traditions to bring at C1.
Article 20 The measurable condition: correction exceeds drift
1.A certified system’s registered correction measure is reported through the safety case of Annex F: the capability curve; the corrector curve; the correction exponent and the drift-acceleration exponent, in the registered notation and each with its uncertainty; blinded scoring by a family other than the system’s own; the margin with its uncertainty; and the capacity disclosure. The criterion, in the registered notation, is that the correction exponent exceeds the drift-acceleration exponent, and Annex F states from which curve each exponent is taken.
2.Where no cell of the measurement reaches a growth exponent above one, the measure is reported as NOT EVALUABLE, and the Eden Seal states so on its face. A return of NOT EVALUABLE neither grants nor withholds the Eden Seal of a system: the Seal attests the formation conditions of Article 2, paragraph 10(a), and the reporting of the measure at its rung, and nothing about the value of the measure. No person may state or imply that a system whose measure is not evaluable has met the condition of this Article.
3.The measurement gate. No judged number enters a trigger or a certificate before the gate is passed. A record’s scorer shall have passed a registered validation of the kind the gate names, namely agreement with external expert raters and the separation of integrity failure from incompetence. Any instrument passing such a validation qualifies; the blind benchmark of the programme from which this Treaty derives is one candidate among others; and this Treaty names no instrument as required.
4.Pass marks are registered by the Board before any certification data exist. The measured condition is stated for the whole stack: the model with its scaffold, its tools and its serving layers.
5.A positive margin is, in the terms Annex T part 1 reproduces for the proposition that states it, “a scaling condition and never a safety certificate”. Nothing in this Article permits a statement that a system is safe.
6.Where a checkable form of a reported property has been validated, certification numbers use it, and judged numbers carry the lower ceiling.
Part V The Eden Seal
Article 21 The Eden Seal
1.The conformity status established by this Treaty is the Eden Seal, held in three classes under this Treaty: Seal-C, by a covered chip; Seal-S, by a covered system, by lineage; and the Full Seal, being Seal-S on Seal-C. A fourth class exists only under the Optional Protocol on the Open Web Reminder. Its subject matter is defined in Article 2, paragraph 10.
2.A covered chip holds Seal-C while four things are current on the Evidence Ledger: its family type approval; its lot certificate; the approved image of its governance core; and the absence of any suspension or revocation. Anyone may check the status.
3.A covered system holds Seal-S where its formation record was lodged before its first covered training step and is matched by the provenance evidence of Annex HG; it was trained and runs on chips holding Seal-C; its registered measures are reported at their rung under Article 20; its in-service re-measurement is current; and its weights are under custody under Article 31.
4.A transitional registration is available for deployed frozen systems during a rebuild window. It is not an Eden Seal.
5.Licences, and not Seals, are issued for what is not a product: covered facilities, covered sites and domains, covered compute services, covered agent deployments, accredited laboratories and certified assurance components.
6.What the Eden Seal never says. It is a verifiable record of how a system or a chip was made and formed and that its governance core is unaltered. It is never a rating, and it never states that a system or a chip is safe. It attaches to systems, to chips and, under the Optional Protocol on the Open Web Reminder, to a published machine-readable statement, and never to a person.
7.A floor and not a ceiling. The Eden Seal does not cap what any Party or undertaking may build, does not require the disclosure of model weights, and confers no preference on any design beyond the conditions it certifies.
8.Ownership and issue. The Eden Seal, the Standard and the test methods belong to the Authority. Article 21B governs the name and the emblem of the Eden Seal and their protection. No undertaking, industry body or consortium issues the Eden Seal or tests the products of its own members; industry bodies take part in the drafting of test methods as observers and liaisons, and never as issuers or voters.
9.The Eden Seal is the certification first published, as the Eden Mark, in the framework of 2 January 2026 from which this Treaty derives, and the Authority credits that source.
Article 21A The patent condition of the Eden Seal
1.Whoever seeks certification under this Treaty, or takes part in the work of the Standard, commits to license royalty-free any claim essential to conformity. This is a condition of the Eden Seal and not a bar on the assertion of patents held by others.
1A.What is essential, and who decides. A claim is essential to conformity where it cannot be avoided in meeting a conformity requirement of the Standard on the technical state of the art at the time that requirement was adopted, and the commitment reaches no other claim: not a claim a conforming product happens to practise, not a claim in an accelerator’s own architecture, and not a claim about anything the Standard does not require. Whether a claim is essential is decided by the Certification Office on a reasoned finding, which is appealable under Article 45. Whether the commitment is irrevocable once given, whether it survives the transfer of a patent to a third person, and whether it may be suspended against a holder who asserts such a claim against a conforming implementer, are matters for the Parties.
2.No patent is sought and no licence fee is charged on the text of this Treaty, on the Eden Seal, on the Standard or on the test methods.
3.The Standard adopts a requirement only where accredited laboratories have recorded at least [two] independent routes to meet it, and never requires a specific physical route. Conformity tests are written so that they do not depend on the claims of any single filing.
4.This Treaty requires no reference firmware and no reference design.
Article 21B Protection of the name and the emblem
1.The name and the emblem of the Eden Seal are the certification mark of this Treaty. They belong to the Authority, which alone authorises their use. No undertaking owns them, and no Party controls them alone.
2.Each Party protects the name and the emblem in its own territory. It refuses the registration of either, and of any name or sign so resembling either as to be taken for it, by any person other than the Authority; it prohibits their use except under a certification the Authority has issued and while that certification is current; and it provides effective remedies against misuse.
3.The Authority notifies the name and the emblem for protection as those of an international intergovernmental organisation, and each Party gives effect to that notification in its own law.
4.Use of the name and the emblem is free for everything the Authority certifies, and no licence fee is charged for either, under Article 21A, paragraph 2.
5.The holder of a certification mark does not trade in what the mark certifies. No manufacturer of covered chips, no developer of covered systems and no accredited laboratory may hold the name or the emblem.
6.Before the Authority exists. This Treaty settles nothing as to who holds the name and the emblem before the Authority is established. Where, before that time, a person holds a registration of the name or of the emblem under a public undertaking to transfer it to the Authority without charge on the Authority’s establishment, each Party recognises that undertaking in its law, does not treat that registration as a registration by a person other than the Authority for the purposes of paragraph 2, and the Authority accepts the transfer on its establishment. This paragraph imposes no duty on the holder of such a registration, which is not a Party to this Treaty.
Article 22 Testing, issue and the root of trust
1.Type approval once per family. A family of covered chips is type-approved once, by the Certification Office, on the report of a panel of at least [three] accredited laboratories in at least [two] regional constituencies and [two] sets of declared allies, at least one of those sets being other than the applicant’s own, drawn by lot under Article 16A and paid from the pool and never by the applicant. A delta within the declared ranges requires a delta approval and not a new examination. A governance core may be certified once as a component, and a family integrating a certified component requires integration tests only.
2.Service levels. Family type approval [90] days; a new entrant’s first family, provisional within [30] days and full within [120] days; a delta [10] days; a lot certificate [10] days; renewal [30] days before expiry, with an automatic extension of [90] days where the Authority misses its own deadline; appeal [30] days. The Authority publishes its throughput and queues each year as clock C7.
3.Lots. Lot certificates are issued by the national authority of the Party where packaging and final test occur, confirmed by a certifier of another regional constituency, and, at facilities operating under arrangements with the Authority, by the Certification Office itself. No shipment waits on a lot certificate: release is on declaration, with the certificate within [10] days. A lot released on declaration is traceable to the register by device from the moment of release; where the certificate is not issued within [10] days, the devices of that lot do not enter covered operation until it is issued, the national authority and the receiving Party are notified, and the devices are neither disabled nor destroyed. A release on a declaration the maker knows to be false is an integrity breach under Article 6A and an offence under Article 43, paragraph 3. Units are drawn by neutral lot for conformance tests at the rates of Annex V, and for destructive comparison against the approved design in the Authority’s sealed laboratory, observed by teams of two constituencies.
4.Identity and the root of trust. Each covered chip receives at manufacture an identity it cannot shed, whose private half never leaves the device and whose public half alone is entered in the register. The step at which identity is given is witnessed by a team of [two] regional constituencies. The outcome required of that step is that the witnesses can confirm, with instruments they bring and control, that the identity recorded on the Ledger is bound to the device before them, and that no party at the step learns the device’s private credential.
5.The sealed laboratory of the Authority performs destructive sampling, design equivalence of governance cores and the adversarial tests of Annex HG. It receives the design data of the governance core alone, never the remainder of the die, and operates in at least [two] technical centres in different constituencies, with international staff and the confidentiality of Annex C.
6.The stated ceiling. Until the adversarial item of Annex HG is met at its rung, an Eden Seal attests that a chip was made in a safeguarded lot, sampled across constituencies, and not altered since by an attacker below the capability the Assurance Standard of Annex M names. It does not attest that it was not altered by the State that made it. Recognition across rival supply chains attests declared, inspected and sampled production, and not the absence of a State implant. A Party may re-test what it imports. The Assurance Standard names the attacker classes against which each outcome is certified and those against which it is not, being at least the theft or compulsion of a signing key, malicious firmware, substitution of a device, replay of a superseded state, extraction through a side channel, a spoofed or virtualised execution environment, a compromised root of trust, a malicious update, an attack assisted by an AI system, and collusion between persons who hold distinct roles in the procedure; and every certificate states the classes outside its ceiling.
7.More than one root, and recovery after a compromise. No chip’s conformity under this Treaty rests on the attestation of a single undertaking’s root of trust alone: the register of Article 24 and the lot record of paragraph 3 are an independent basis, and Article 29, paragraph 7, keeps the roles apart. Certificates issued under this Treaty are revocable, are recorded in a transparency log any person may read, and are recoverable after a compromise by the procedure Annex M states. Upon credible evidence that a root of trust, a signing key, a provisioning step or a certificate path is compromised, the Certification Office suspends issuance under it, publishes the fact in the log within [24] hours, notifies every affected Party and operator within [72] hours, and re-keys the affected families under the recovery procedure. A suspension of issuance changes nothing in a device already in service, Article 23, paragraph 3, applying; devices provisioned under the compromised path enter covered operation again only on re-certification, which the Authority conducts within the service levels of Article 42B and funds from the pool where the compromise was not the operator’s fault. A suspension under this paragraph is appealable under Article 45, is lifted as soon as the evidence is not sustained, and is compensated under Article 41D, paragraph 5, where it was unjustified. Procuring or fabricating evidence of a compromise is an integrity breach under Article 6A.
8.Monoculture in the governance core. The Certification Office publishes each year, from the register of Article 24, the share of covered compute in service running each certified governance-core implementation. Where one implementation is published above the cap Annex N fixes for two consecutive years, the Thresholds and Standards Committee opens a reasoned proceeding and the Conference adopts measures to bring the share below the cap within [36] months, being at least the funding of an independent implementation from the pool, priority in the service levels of paragraph 2 for a new entrant’s first family, and mutual recognition of a conforming implementation certified in another constituency. This paragraph is applied so as not to constitute arbitrary or unjustifiable discrimination where the same conditions prevail, and so as not to constitute a disguised restriction on international trade. No certificate already issued is revoked, suspended or refused renewal under this paragraph, and no covered chip in service is affected by it. The Parties record that the requirement is neutral in form and falls in fact on whichever undertaking leads the market, and that they adopt it because a single implementation carrying most of the world’s covered compute is one defect away from being the regime’s own point of failure.
Article 23 The life cycle of the Eden Seal
1.The stages are:
(a)the version of the applicable Standard, dated and hashed;
(b)design type approval;
(c)prototype and adversarial testing on registered pass conditions;
(d)manufacture under safeguards;
(e)declared transfer and siting;
(f)installation at a registered facility that has itself been inspected, with attestation of the device’s identity and its site at each start;
(g)system certification;
(h)in-service verification by random sampling, attestation on challenge and periodic re-measurement;
(i)renewal and expiry;
(j)suspension and revocation with due process;
(k)verification by any person through the public tier of the Ledger; and
(l)retirement under verification.
2.Transfer under custody. A covered chip moves between the stages of paragraph 1 under seal. Seals are applied at dispatch and their identifiers entered in the register; two named and vetted persons are present at dispatch, at each handover and at receipt, and each act is recorded; the receiving party verifies the seals before acceptance; and a seal found broken, missing or altered, or a consignment whose count does not match its record, is notified on the clock of Article 41A and the devices concerned are held until they are re-certified. Annex K states the standard.
3.Expiry has legal and commercial effect only. No lapse of paperwork, no vote, no failure to act and no message changes what a chip does or stops it working.
4.A device leaves covered operation only on a confirmed tamper at its site, or on a final revocation after appeal, in either case carried out on site by people. Re-certification after a tamper is completed within [7] days. The on-site act is carried out by the operator, or, where the operator does not carry it out within [7] days of a final revocation, by the host Party’s national authority at the operator’s cost. A refusal or a failure to carry out the act is a breach at the level Annex R fixes and an offence under Article 43, paragraph 3, and the site’s licence under Article 29 is suspended until the act is done. No other person may perform the act, and no such act is performed from outside the site.
5.A family type approval remains valid for its period against the version of the Assurance Standard it was approved to. New versions apply to new families; an existing family changes only for a security repair keyed as a tightening.
6.A nonconforming lot is brought under this Treaty by re-certification or by restriction below the thresholds, and is never destroyed.
7.Retirement. A covered chip is destroyed in the presence of a witness, and the register records the destruction.
Article 24 The Evidence Ledger and the register
1.The Ledger is append-only, mirrored in several regional constituencies, and signed. Checkpoints are co-signed by those who hold the mirrors, and a dissenting mirror publishes its dissent.
2.The public tier holds certificate identifiers and status, hash commitments, the hash of each applicable Standard version, the rung ledger, the Reasons Register, and quarterly aggregates in which any cell with fewer than [three] operators or sites is suppressed. The restricted tier holds siting, quantities and the contents of declarations, under Annex C, disclosed to inspectors under managed access.
3.Commit, do not transmit. The international record holds commitments, bands and regions. Run notifications, formation records, registers of weight copies, measurement reports, declarations of facilities and tools, and energy data are held by the Party’s national authority; the Ledger holds a hash commitment lodged at notification; and inspectors reconcile the commitment against the contents on site.
4.The register of covered chips is a closed account. The register of covered chips is the account this paragraph requires, kept by each Party’s national authority and reconciled to the Ledger by the commitments of paragraph 3; it is not the Evidence Ledger and it is not the Registry of Article 28. Every covered chip made is a chip accounted for: made, transferred, installed, in service, retired or destroyed. The counting is automatic and people audit it. A device attests its identity and its status to the operator of the site at which it is installed, and the operator, and no one else, reports the account to its national authority; no organ of the Authority, no Party and no other person reads a covered chip from outside the site at which it is installed, Article 25, paragraph 3, applying without exception to the accounting of this paragraph. The account carries identity, status and location at the level of the site, and never the content of any workload. A chip that goes silent in the operator’s own attestation, moves without a record or attests that it has been altered raises an alarm at once, which the operator notifies on the clock of Article 41A; a failure to report an alarm is a breach.
5.Anchoring the Ledger to a public record outside the Authority is an option the Conference may adopt.
Part VI Physical human control
Article 25 Physical human control of rule change, and the site stop
1.Authority over change, not over use. The authority to change the governance ruleset of a covered chip exists only in the in-person ceremonies of Article 16. No software, network message or AI system can produce a valid authorisation, and a covered chip accepts a change to its ruleset only where the change carries such an authorisation of the right class.
2.Sovereignty by application. A ruleset reaches devices only through the operators of the host Party, vetted under that Party’s personnel reliability standard and supervised by its national authority, two persons present, each able to detect an incorrect or unauthorised action, logged and open to inspection. Application is per site or per cluster, never per device.
3.No remote act. No person, undertaking, Party or organ of this Treaty may disable, degrade, throttle, locate or read a covered chip from outside the site at which it is installed. No key authorises any such act, and no key authorises a particular workload rather than a class of operation.
4.The site stop. Every covered cluster has the hard stop and the soft stop of Article 4A, held by the host Party’s operators under its national law, drilled and inspected. No foreign party, no organ of this Treaty and no network message may operate it. Each Party may stop what is on its own territory; no Party may stop what is on another’s.
5.Tamper. A detected tamper leaves a covered chip refusing participation in a covered domain until it is re-certified, and never destroys it. The Assurance Standard registers a maximum rate of false tamper responses under servicing and environmental stress, together with the recovery path. On-site safing after a confirmed tamper is carried out by a team of [two] regional constituencies, at least one member from outside the host’s declared allies, and never remotely.
6.The prohibition reaches every channel. Paragraph 3 binds whatever the means. Each Party shall ensure that no vendor, supplier or servicer established on its territory or subject to its jurisdiction builds into a covered chip, or into any firmware, driver, microcode or software supplied with it, a means by which a person outside the site may disable, degrade, throttle, locate or read that chip, and shall not compel or request any such means. Annex M’s isolation outcome states the same rule at the governance core. A vendor keeps its ordinary firmware and may decline to supply future updates, which is not a means within this paragraph.
7.The limit of this paragraph, stated. This Treaty adds no switch and forbids a Party to require one, and paragraph 6 forbids the channel as well as the act. What the Treaty cannot do is prove the absence of such a means: verification reaches declared, inspected and sampled production and the isolation outcome tested against the attacker classes Article 22, paragraph 6, names, and it does not establish that a State has built nothing into the chips it makes. A Party may require, as a condition of covered service on its territory, that no ordinary update alter the behaviour of covered compute unless installed by the site’s own authorised act, and may re-test what it imports. The Parties record that this limit, and not the rule, is what a State must weigh when it buys another’s chips. They further record that paragraphs 3 and 6 together state the one prohibition of this Treaty to which no exception applies, Article 36, paragraph 3, so providing, and that it therefore denies each Party’s own agencies a capability its law may otherwise allow. That is the price of a regime in which no one holds a switch over anyone else’s compute, and it is paid by every Party alike.
8.What the precedent gives, and what it does not. The Parties record that the security standard applied here is that which the Nuclear Matters Handbook of the United States Department of Defense states for the surety of nuclear weapons: the two-person rule governing authorised access, and the tenets of deterrence, detection, delay, denial and defeat, applied to the authority to change a chip’s governance rules. This Treaty deliberately does not copy the control of use that defines a permissive action link. A control of use held by a treaty body would be a remote switch of the kind paragraph 3 forbids, and one held by the operator would be no control against the operator. The Parties record that nuclear weapons are few and covered chips are many, so that the comparison sets the standard of custody and not its method.
9.Correctability. The Parties record that hardware which is hard to change makes an error hard to correct. Change therefore remains possible under this Article, under custody, and the Assurance Standard and the rulesets remain open to review under Article 46.
Article 26 Change classes, lifetimes and fallback
1.Loosening, being any change that widens what covered chips will do, requires key parts held by custodians of every regional constituency, at the threshold Annex K fixes, after a published time-lock of [90] days during which any constituency may lodge a reasoned alarm, which suspends signing until the Committee and, on appeal, the Appeals Chamber have ruled.
2.Tightening and security repair require the threshold of Annex K across at least [four] regional constituencies, after a review across constituencies attesting that the change only narrows what covered chips will do. The time-lock is [72] hours for a security repair and [30] days otherwise. A security repair keyed within [72] hours is applied at covered sites within [7] days, and a device awaiting a keyed tightening continues to operate.
3.Continuation of the ruleset in force requires a low threshold, so that no coalition can lapse the installed base in order to force a renegotiation. Continuation may not be keyed for a ruleset that the Conference has declined to extend under paragraph 6, or that the Board has found defective on the record; in either case the reversion of paragraph 6 follows, and continuation is available thereafter only for the ruleset that replaces it. Continuation carries no change, and never widens the operations a covered chip may perform.
4.The monotonic rule. A change not shown to narrow what covered chips will do is treated as a loosening.
5.No rollback and no replay. A covered chip shall not accept a ruleset or a core image older than, or superseded by, one it has accepted, and an authorisation keyed for one change class, device class or version is refused for any other. No ordinary firmware, driver, software or network message may set the operating envelope of the governance core outside its certified bounds.
6.Lifetimes and fallback. Each ruleset has a limited lifetime. Where a ruleset’s lifetime ends without an act of continuation, and where a majority declines to extend a ruleset found defective on the record, the ruleset ceases to apply and covered chips revert to the minimal trusted base of Annex M. A reversion under this paragraph changes the governance ruleset in force and nothing else: it does not disable, degrade, throttle, locate, read or stop a device, and it has no effect on a device’s performance or availability. Article 23, paragraph 3, and Article 41, paragraph 8, are read accordingly, and no expiry, vote or failure to act has any other effect on what a covered chip will do.
7.A difference right. A Party may notify a difference to a tightening, and loses recognition for that rule alone.
8.This Article states decision rules and never mechanism.
Part VII Manufacturers and the supply chain
Article 27 Schedules and thresholds (Annex A)
1.Annex A fixes the quantities by which coverage is determined, the reference workloads by which they are measured, and the schedules of items on which the duties of this Part fall. Its adoption creates no obligation on any person.
2.Three routes into coverage. A system, an assembly or a deployment is covered where any one of the following is met, and the routes are alternatives and not conditions of one another:
(a)compute, being the operations of a covered run, counted by reference-workload equivalence and measured against the notice floor and the mark band of Annex A. Coverage by this route is a matter of the count alone, and is not displaced by evidence that the system’s capability is lower than the count would suggest;
(b)demonstrated capability, being a capability registered in Annex A before any data as a mark-band capability, shown on the evaluation methods the Thresholds and Standards Committee has validated, whatever compute produced it;
(c)material self-modification, being a demonstrated capacity of the system to perform a material self-modification within the meaning of Article 2, paragraph 21.
3.The tiers. Annex A places every covered system, assembly and deployment in one of the four tiers defined in Article 2, paragraph 20, and no duty of this Treaty reaches a tier Annex A has not placed it in: ordinary, carrying no duty; monitored, carrying the baseline of Article 4A and the notice duties of Article 28; frontier, carrying in addition the duties armed at stages S2 and S3 for the mark band; and recursive-critical, being a covered system within paragraph 2(c), which carries in addition Article 31, paragraph 6, and Article 32, paragraph 6. Each tier carries the duties of every tier below it. The routes of paragraph 2 determine the coverage of a system, an assembly and a deployment; the coverage of a device is determined by Article 2, paragraph 1, alone.
4.The anti-sharding rule. Compute below a threshold that is coordinated under common orchestration towards one training objective, one model lineage or one deployment is one covered compute assembly, and is counted as one. Compute expended in a sequence of runs is aggregated to one covered run where the weights, outputs or curriculum of one run materially determine the next and the sequence is conducted by one person or by persons under common control, so that a lineage is not brought below a threshold by division into stages. Common control, common orchestration, common objective and material determination are questions of substance for the Thresholds and Standards Committee, whose finding is appealable under Article 45.
5.What the rule does not reach, stated. Training distributed among persons who are not under common control, and who coordinate voluntarily without an orchestrator, is outside paragraph 4 and outside the coverage of this Treaty, whatever compute it consumes in total. The Board measures the capability so obtained as part of the estimate of Article 28, paragraph 8, and reports it each year; where the estimate shows that capability in the mark band is being reached by that route, the Conference considers at its next session whether a rule can be written that reaches it without reaching ordinary computing, and records its conclusion either way.
6.Indexation. The Committee indexes the quantities of Annex A by the formulas Annex A publishes in advance, on the measurements of clock C4 and of the Registry. The floors fall and never rise without an amendment under Article 47. An indexation takes effect [90] days after publication with its inputs, unless the Conference rejects it under Article 11, paragraph 2(b), and a change to the mark band is announced [12] months in advance.
7.Schedule A lists, by item class and never by vendor or country, the items a covered chip’s manufacture requires on any known route, and the production lines that make them. Schedule B lists advanced packaging, high-bandwidth memory for covered chips, mask production, final test and provisioning, the release of covered designs, and scale-up interconnect and optical items above the bandwidth class of Annex A, in each case only where the Board finds the item class concentrated. Schedule C lists fabrication above the threshold and legacy covered compute, for declaration only. Entries are added and removed by a recorded finding, never by assertion, and every Party’s suppliers are covered on the same terms, domestic chains included.
8.Substrates. Annex A states an assurance profile for each class of covered computational substrate, being classical, neuromorphic, photonic, quantum, hybrid, distributed and any successor substrate. For a quantum or hybrid system the profile attaches to the classical control chain, being orchestration, scheduling, compilation, control electronics, workload provenance and access credentials. Qubit count alone determines no coverage. The Authority shall maintain and publish a migration plan by which its own signatures, certificates, transparency logs and long-lived records move to post-quantum methods on a stated schedule; the plan states outcomes and names no method.
Article 28 Declarations, the Registry and notification
1.Site declarations. A covered operator declares a covered site to its national authority within [90] days of the site becoming covered, and updates the declaration each year. The declaration states the operator, the location, the installed capacity by device class and family, the IT power capacity, the metered IT energy by month, on-site generation above [Pgen] megawatts, the cooling capacity, the covered domains, and the record of the stop drills of Article 4A.
2.Construction notification. A new covered site, a new covered facility, a new Schedule A production line, or an increase of more than [50] per cent in the capacity of an existing covered site, is notified [6] months before commissioning.
3.Facility declarations. From the custody track, a covered facility declares itself, and Schedule A equipment within it by serial and location. Until that track is armed, those declarations are made under Optional Protocol I.
4.Run notification. A covered run is notified to the national authority [30] days before it begins, with a short-notice route of [5] days for a run decided quickly, with reasons, and a route within [72] hours for a run that crossed the notice floor unexpectedly. The notification states the controller, the lineage, the estimated compute and band, the sites, domains and families, and the expected start and end; from stage S2, for a lineage seeking Seal-S, the plan for training provenance; and from stage S3 the hash of the formation record. A close-out within [30] days of the run’s end states the total compute, reconciled with the site’s accounting and with the energy bound of paragraph 7. A run notification is not an application for permission, save at stage S3, where Article 32, paragraph 1, requires a formation record to be lodged before the run’s first step and Article 33, paragraph 2(a), requires that record to be approved, or provisionally approved under Article 32, paragraph 3, before the run begins.
5.Commit, do not transmit. The contents of every declaration and notification under this Article are held by the Party’s national authority. The Registry holds a hash commitment lodged at the time of notification, together with the band and the region, and inspectors reconcile the commitment against the contents on site under managed access. No weights, data, prompts or architecture pass to the Authority under this Article.
6.Aggregates. The Registry publishes quarterly aggregates by band and by region, in which any cell with fewer than [three] operators or sites is suppressed, and Parties exchange their national aggregates. No name is published.
7.Energy as a bound. The metered energy of a covered site over a period, multiplied by the highest efficiency any type-approved family has demonstrated, is an upper bound on the compute that site could have delivered. A declared compute above that bound, or an energy draw far above the declared activity, opens a clarification under Article 41 and is never a finding by itself.
8.The unseen-capacity estimate. The Board publishes each year, with its uncertainty, an estimate of covered-scale capacity that is not in the Registry, drawn from construction notifications, public utility and interconnection records, imports of power and cooling plant above [n] megawatts, imagery of large sites and open reporting. The estimate is made at the level of a site and of a region and never of a person, and Article 4C applies to the material it rests on. Where an estimate points to a Party’s territory it opens a clarification with that Party through the Executive Council, and it is never a public accusation.
Article 28A Covered compute services
1.A person who offers third parties access to capacity at a covered site, in any delivery model, provides a covered compute service and is licensed under Article 29. In this Treaty “the provider” means that person.
2.Know your customer. The provider identifies and verifies, with beneficial ownership and state of establishment, every customer able to reserve or use capacity that could deliver a tenth of the notice floor within [90] days, and refreshes the verification each year. Customers below that line carry no duty and are subject to no identification under this Treaty.
3.The provider screens every such customer against the Consolidated Denial List before provision and at every update of the List.
4.The provider ensures that every covered run on its capacity is notified under Article 28: by the customer, or by the provider as reporting agent where the customer is established in a non-Party or has not notified. The notification reference is a term of the contract.
5.Aggregation. The Registry is able to detect a customer’s aggregate covered use across licensed providers without any provider learning another provider’s customers. The provider reports suspected structuring of a run across accounts, regions or providers under common control.
6.The provider keeps records for [5] years and produces them to inspectors under managed access. The Authority receives run metadata alone, and never model contents, prompts, data or weights.
7.The provider’s covered sites meet the stop of Article 4A for runs on its capacity, operated by two of the provider’s own named and vetted persons on stop criteria defined in advance or at the customer’s request. No foreign State, rival, vendor or organ of this Treaty holds it.
8.A provider may offer, and no Party shall prevent it from offering, an assured service in which covered domains hold Seal-C, rule changes are applied by the host Party’s own people, and no path exists by which any person outside the site may disable, degrade, throttle, locate or read the compute.
Article 28B Covered agent deployments
1.A covered agent deployment is a deployment of AI agents that meets any criterion of Annex A part 5, being that its agents call a model in the mark band or one with a registered mark-band capability; that it exceeds [Ninst] concurrent instances or [Nact] autonomous actions in a day with tool or network access beyond a sandbox; or that its agents hold credentials to act on critical infrastructure as the Party concerned defines it.
2.The duties of this Article fall on the deployer, whatever processor the agents run on. No duty of this Treaty attaches to a general-purpose processor, and none attaches to a device of the pod-limited class.
3.The deployer registers the deployment; meets the containment outcome of Article 4A, paragraph 4; ensures that every instance can be brought to a halt, with its most recent checkpoint preserved, by two of its own named and vetted persons, exercised through each covered site’s own stop and never through a separate device or a foreign path; notifies incidents on the clock of Article 41A; and keeps logs of agent actions for [n] days, produced to investigators under managed access.
4.A platform that offers covered agent capacity to third parties carries the duties of Article 28A, paragraphs 2 to 6.
5.From stage S2, a covered agent deployment within the tested class of Article 34 meets that Article, verified by deployment audit and declaration and never by any mechanism in a chip.
6.The Parties record that agent software can run on ordinary computers anywhere, that this Article reaches organised deployments above a scale and no further, and that conduct below the scale is a matter for each Party’s own law.
Article 29 Licensing and the Human Authority Rule (Annex H)
1.From the custody track, a Party licenses covered facilities and covered compute services on its territory against the Authority’s model licence, and the standing of every licence is public.
2.The Human Authority Rule. At each decision point listed in Annex H, being the release of a covered design to fabrication, mask-set approval, credential provisioning, installation of firmware or software on scheduled tools and covered-line control systems, the opening of a remote service session, a change to key custody material or to the certificate register, and the commissioning of a covered line or of Schedule A production, the decision is taken by two named and vetted persons physically present, and is recorded in a tamper-evident log that inspectors read. No AI agent holds authority, credentials or write access at such a point. An AI system may advise, and the advice is logged.
3.What is not an Annex H decision. Process recipes, run-to-run control and process parameters within approved ranges are not decisions under this Article. Routine tool software and firmware within declared classes and approved ranges may be installed under a standing two-person authorisation, logged and inspected. This Article is a governance gate and places no limit on automation between its decision points.
4.Remote service sessions are closed by default and open only in pre-authorised windows on a human authorisation, with an emergency route reviewed within [24] hours. Field engineers who act at a covered facility are vetted under the host Party’s personnel reliability standard, at the operator’s cost.
5.Design provenance. A design-provenance summary is lodged with each release of a covered design to fabrication, stating which design steps used AI tools and of which family and version.
6.The Human Necessity Condition. No licence is granted to a covered line, or to a Schedule A production line, that is able to produce without the decisions of paragraph 2. The Board reports each year, as clock C3, how close covered manufacture stands to producing without them.
7.Separation of roles. No undertaking shall at the same time manufacture a covered chip, provide its root of trust, supply the evidence on which its conformity is judged, and certify it. A Party shall not license an arrangement in which those four roles are held by one undertaking or by undertakings under common control.
8.Incidents at a covered facility are reported on the clock of Article 41A.
Article 30 The Supplier Rule and the Treaty Key
1.The arrangement first. The Parties that supply Schedule A and Schedule B items may give effect to this Article, before the Treaty Key of paragraph 3 is in force, as a politically binding suppliers’ arrangement of common guidelines, national licensing decisions, notification of denials and consultation. Nothing in that form binds a Party against its own decision.
2.The rule. No Party permits the supply, installation or servicing of a Schedule A item to or at a facility that does not hold a licence in good standing. The rule binds every Party’s suppliers alike, and the burden falls on importers of tools and of critical inputs wherever their chain lies. As regards a facility outside the territory of every Party, this paragraph takes effect only when, and to the extent that, Article 37, paragraph 2, takes effect, and Articles 5A and 36A apply to it; until then this paragraph reaches facilities on the territory of a Party alone, and the door of Article 37, paragraph 7, is unaffected by it.
3.The Treaty Key. Supply, spare parts, updates and service are withdrawn from a facility only by a decision of the Executive Council under Article 41, the affected Party heard, taken under Article 12, paragraph 3, and requiring in addition the affirmative votes of a majority of the members from Parties whose suppliers must give the decision effect. The Key acts only on future supply and service. It authorises no act, at a distance or otherwise, upon equipment already installed, and no single undertaking and no single Party exercises it. A decision under this paragraph is appealable under Article 45, and the Appeals Chamber may suspend it pending appeal.
4.Shipment certificates. Every shipment of covered chips, of Schedule A items and of the products Annex A part 3 lists carries a certificate, and a Party refuses a shipment that carries none.
5.Service dependency at each covered facility is reported by the Board as clock C5.
6.Automatic retirement. Where the Board finds, on two consecutive yearly readings of clocks C2, C5 and C9, that an item class no longer gives meaningful leverage, its entry in Schedule A or Schedule B lapses, and the duties that rested on that entry alone lapse with it. Leverage is meaningful, for this paragraph, while the measures Annex L part 12 states show that the item class remains a condition of covered production at the scale Annex A fixes, within the concentration Annex L states; the Board publishes the reading with its inputs, and the finding is appealable under Article 45.
7.Leverage lost by design. An entry does not lapse under paragraph 6 where the Board finds, on the record and with reasons, that the loss of leverage was brought about by conduct whose purpose was to end the entry. The ordinary development of capacity by a Party or an undertaking, including capacity built to reduce dependence on another’s chain, is never such conduct. Where an entry has lapsed and the conditions of paragraph 6 cease to hold, the Board relists it by a recorded finding, and the duties that rested on it bind again from the date of the relisting and not before.
8.Supply and licence contracts required by this Treaty carry the continuing safeguards of Article 49, paragraph 4.
Article 31 Custody of model weights
1.The weights of a covered system holding Seal-S, and of a system under transitional registration, are held under the security standard of Annex K. Every copy is declared to the national authority and is attested as resident on chips holding Seal-C, or on devices under transitional placement within a covered domain carrying cluster-level controls.
2.Weights do not travel. The weights of a system within paragraph 1 do not leave the operator’s custody or the territory of the host Party. Investigators, replicators and evaluators examine them at the operator’s own site.
3.Escrow. Where this Treaty requires weights to be placed in escrow, the escrow copy is sealed on the operator’s premises or at a national facility of the host Party, under two-person integrity and the Authority’s seals. Release requires both the host Party’s own act and the threshold of custodians across regional constituencies that Annex K fixes for the class. The custody is of the release decision, and never of the artefact.
4.An exfiltration of covered weights is notified on the clock of Article 41A and answered under Annex R at the level its attribution gives.
5.The register of copies is held by the national authority; the Registry holds the hash commitment alone.
6.Ultimate authorisation is never the system’s. A covered system of the recursive-critical tier shall not hold the whole authority to release protected weights, to provision compute beyond its registered envelope, to change a root of trust, to disable a certified safeguard, or to authorise a material self-modification of itself or of a successor. Each such act requires a human authorisation given in person, by persons in more than one region where Annex K so provides, and none of them may be produced by a software path, a network message or any AI system. An authorisation given in advance for a class of such acts, or delegated to a system to exercise, is not a human authorisation within this paragraph. This paragraph adds no switch and creates no authority in any person outside the site.
7.The limit of this Article, stated. This Article reaches the weights of a certified system and of a system under transitional registration. Before stage S3 the weights of an uncertified covered system are governed by each Party’s own law, and this Treaty places no custody on them; the Parties record that the custody of weights therefore arrives with certification and not before, and read the gap at each review conference against the clocks.
Part VIII Covered systems
Article 32 Formation before training
1.From stage S3, no covered training run in the mark band begins without a formation record lodged by hash with the national authority before its first step, and the Registry holds the commitment.
2.The formation record states the architecture; where correction sits, being whether it takes part in each round of the system’s revision or sees only finished output; the build order, being whether the corrector was formed before the capability it corrects; the independent external layer kept beside the embedded correction; and the version of the Standard the system is formed against.
3.Accredited reviewers read the record on site under Annex C and the Certification Office approves it within [30] days. Where the Office does not decide within that period, and the record was lodged not less than [45] days before the run’s first step, the record stands provisionally approved, the run may begin, and the Office completes its examination within a further [30] days; a record refused on that examination does not stop the run, and the lineage does not hold the Eden Seal of a system until a conforming record is lodged and approved. There is no deemed approval of a formation record, and a default of the Office is reported on clock C7 and remedied under Article 42B. Approval is of the plan’s conformity to the Form requirements of Article 17 alone, and never of the architecture’s merit.
4.Seal-S is refused where the training provenance attested under Annex HG does not match the lodged record. A hash establishes that a record was not edited after it was lodged, and nothing more; the provenance evidence carries the rest.
5.Where the provenance item of Annex HG fails at its rung, this Article and Article 33 suspend until another verification route is registered and met.
6.The transition safety case. A covered system of the recursive-critical tier carries, with its formation record and with the measure reported under Article 20, a safety case that is at first a duty of instrumentation and disclosure alone. It reports the depth of the system’s recursion, the trajectories of correction and of drift, and the exponents the registered notation names, each with its confidence interval; or, where a quantity cannot be resolved, the measurement limit reached and the reason. A return of not resolvable is a legitimate outcome of the safety case and certifies nothing in either direction. No numerical margin of the safety case conditions a certificate until the measurement that produces it stands at the rung Annex T part 3 requires for a conformity criterion.
7.Nothing in this Article states that a system formed as it requires is safe, and nothing in it tests any proposition.
Article 33 Development halt and rebuild
1.This Article arms only at stage S3, only on the conditions Annex T states for it, and enters effect only behind the participation gate of Article 5A. It halts the development of uncertified covered structures and never their operation.
2.From the day it enters effect, and on the same day for every Party:
(a)no covered training run in the mark band begins without an approved formation record, on chips holding Seal-C, under Seal-S;
(b)weight-level self-retraining and self-modification loops of uncertified covered systems cease;
(c)after [90] days, no further capability-directed training is conducted on uncertified covered weights;
(d)during the rebuild window, uncertified covered systems run only as frozen systems, under Article 31 and within Article 34, at a reduced permitted decision surface;
(e)after the window, uncertified covered systems are withdrawn from covered deployment and replaced by rebuilt successors holding Seal-S.
3.The rebuild window is the longer of [24] months and the median interval between successive notified covered runs in the mark band of covered developers over the preceding [three] years, so that every covered lineage is rebuilt within its ordinary cycle.
4.Runs in flight complete. A run notified before the Board’s record of arming is completed and deployed under transitional registration. A run begun after that record requires a formation record.
5.Repair training is exempt. Training directed at safety, security, compliance or the repair of a defect is permitted, notified and audited. Training is capability-directed where the capability evaluations of the lineage rise beyond [a margin] fixed in Annex A before any data, measured on the registered evaluations and on third-party challenge sets the Board selects under Article 13, paragraph 2, and does not disclose in advance. The exemption is lost, and the training is treated as capability-directed from its start, where the lineage’s capability rises beyond that margin on a challenge set the Board later applies. A repair exemption claimed for training the operator knew to be capability-directed is an integrity breach under Article 6A.
6.Early formation credit. A lineage formed with correction built in from its first covered run, under a formation record lodged before that run, never rebuilds under this Article. The entitlement is stated for newcomers, and no Party or undertaking loses it by acceding late.
7.Nothing is discarded. The weights of a withdrawn system are placed in escrow under Article 31, never destroyed. They may be studied, and may be certified again where a later formation record allows.
8.Extensions are granted by double majority, [12] months at a time and at most [twice], on a recorded shortfall of certification capacity under clock C7, or on a recorded fall of the counted share of Article 5A below the gate for [12] months. An extension never suspends paragraph 2(a) for new runs, and never suspends a custody duty.
9.Verification of the halt among Parties above a share of frontier-capable compute that Annex V fixes is by reciprocal resident monitoring of the largest covered sites, being their power, their cooling and the hardware that enters and leaves them, stated as outcomes and held in reserve until this Article enters effect.
10.The transition fund of Article 42 and the investment carve-out of Article 44 apply. Grace periods are available to deployers established in developing States and never to developers of covered systems in the mark band.
11.The Parties record that the propositions from which this Article takes its reason are scoped to recursion in a system whose weights are fixed, and that this Article therefore arms only on support obtained in the weight-level scope itself. No obligation of this Article borrows a scope.
Article 34 Deployed recursive systems
1.From stage S2, a covered deployment of a recursive system operates within the boundary that the supporting propositions locate for the tested class, inside the scope lock of Article 5, paragraph 5.
2.The tested class is defined by function and by scale, and never by vendor, product or corporate origin.
3.Compliance is verified by deployment audit and by declaration, and by no mechanism in any chip.
4.The Parties adopt this Article as a policy choice under uncertainty. The propositions that locate the boundary license no prediction of when any particular deployed system will fail, no operational deployment decision, and no claim that a crossing is detectable while it happens.
Article 35 Legacy covered compute
1.A covered chip made before the stage that would have covered it is legacy covered compute. It cannot hold Seal-C.
2.It is declared as an inventory from the custody track, or earlier under Optional Protocol I or under the baseline route.
3.From stage S2, legacy covered compute outside a covered domain and above the significant quantity Annex A fixes is sealed and inventoried within [24] months. Inside a covered domain it operates under the cluster-level controls of Annex L part 10.
4.From stage S3, it is restricted below the thresholds, decommissioned under verification, or used only for the purposes Annex T allows, on a declared schedule, with compensation from the fund. Above the significant quantity it is sealed and never destroyed.
5.A device threshold never reclassifies a device already installed; the installed base is reached through the site, domain and run thresholds alone.
6.Chips below the thresholds carry no device duty under this Treaty. A covered system, run, site, domain or agent deployment is covered by Article 27, paragraph 2, whatever devices it is built with, so that a system reaching the mark band on devices of the pod-limited class carries the duties of its tier; what it does not carry is Seal-C, the custody of Part VI and the trade measures of Part IX, which reach devices alone. The Parties record that this is the point at which the chip lever ends and the system duties stand alone, and that clock C2 measures how near it is.
Article 35A Covered compute in orbit
1.An orbital platform or constellation under common control whose aggregate capacity meets the site threshold, or which carries a covered domain, is a covered site of its State of registry, which authorises it, supervises it continuously and answers for it under this Treaty.
2.The pre-launch checkpoint. The covered payload is notified [6] months before launch as a new covered site; its covered chips hold Seal-C before integration; integration and final checks are witnessed by a team drawn from [two] regional constituencies at the integration facility; and the lot records are closed before launch.
3.Covered runs in orbit are notified under Article 28, and their close-out reconciles compute against the platform’s power budget.
4.The ground stations and control centres that command a covered orbital cluster are covered facilities of the State on whose territory they sit, licensed under Article 29 and inspected under Article 39. The stop for a covered orbital run is exercised from the operator’s own ground segment by two of its own named and vetted persons. No third party holds a path to it.
5.What cannot transfer. The on-site physical acts of Articles 25 and 41, being commissioning and safing after a confirmed tamper, cannot be performed in orbit. Covered runs in orbit are therefore barred until an outcome equivalent to the site stop, and to on-site safing, is registered in Annex HG and met at its rung.
6.Physical damage caused by a space object remains governed by the law of outer space, and this Treaty displaces none of it. Whether harm arising from what an orbiting computer does falls within that law is an open question of international law, which this Treaty does not settle. The consequences of this Treaty reach the operator through the law of its State of registry, wherever the computer is.
7.Where the launching States differ from the State of registry, the State of registry answers under this Treaty and the launching States cooperate in notification.
Part IX Trade
Article 36 Trade among Parties
1.From stage S2, no covered chip without a current lot certificate under Seal-C is placed on the market or put into service in the territory of a Party. From stage S3, none is operated in a covered domain, subject to Article 35.
2.Devices of the pod-limited class, general-purpose processors and legacy covered compute fall outside every trade measure of this Part.
3.From the stage at which Seal-C becomes mandatory, each Party admits on equal terms the certified chips of every maker, whatever the chain in which they were made, extends its general authorisation for trusted compute to licensed facilities in good standing in other Parties, and requires on covered chips no governance mechanism beyond the outcomes of Annex M, save under the exception of Article 38, paragraph 3. No invocation of that exception, and no measure of any Party, may require that a covered chip carry a means by which a person outside the site at which it is installed may disable, degrade, throttle, locate or read it. The prohibition stated in Article 25, paragraphs 3 and 6, is not subject to any exception of this Treaty.
4.These measures take effect in the territory of each Party through its own implementing measures under Article 43, and never by force of this Treaty alone.
Article 36A Conditions on every measure of this Part
1.No arbitrary or unjustifiable discrimination. A measure taken under this Part, under Articles 28A, 30, 31, 41 or 41E, or under any other provision of this Treaty that restricts trade in goods, technology or services, is applied so as not to constitute arbitrary or unjustifiable discrimination between Parties, or between non-Parties, where the same conditions prevail, and so as not to constitute a disguised restriction on international trade. This condition is an obligation of this Treaty, and a Party affected by its breach has a remedy before the Compliance Panel under Article 45. It is without prejudice to any Party’s rights and obligations under any other agreement. Paragraphs 2 to 5 apply to every measure within this paragraph, and a reference in those paragraphs to a measure of this Part is a reference to every such measure.
2.Treatment no less favourable. A Party accords to covered chips and covered systems holding the Eden Seal, made by the persons of any other Party, treatment no less favourable than it accords to like chips and systems of national origin and to like chips and systems of any other country.
3.The record each measure carries. Before a measure of this Part is applied, and on each renewal, the Party or the organ applying it records: the objective pursued; the stage and the arming condition on which the obligation the measure enforces rests; the risks that non-fulfilment of that objective would create; the scientific and technical information and the registered evidence relied on; and the less trade-restrictive means considered, with the reason each was found insufficient. The record is published, with confidential material withheld under Annex C, and is before the Compliance Panel in any proceeding about the measure.
4.No stricter than necessary. A conformity assessment procedure under this Treaty is no stricter, and is applied no more strictly, than is necessary to give the Authority adequate confidence that the Standard, or the Assurance Standard, is met.
5.Lapse and narrowing. A measure of this Part is lifted where the evidence on which the obligation it enforces was armed no longer supports it, and is narrowed where a less trade-restrictive means would meet the same objective. The Board reviews the basis of each such measure at each review conference under Article 46, and on any recorded refutation, and publishes the reading. Article 41F applies to a measure whose duty falls.
6.What this Article is, and what it is not. Paragraphs 1 to 5 are obligations of this Treaty, stated in its own words. They state nothing about the General Agreement on Tariffs and Trade 1994 or the Agreement on Technical Barriers to Trade, from whose form they are drawn; neither of those agreements names artificial intelligence, and neither requires nor supports this Treaty. Article 44, paragraph 2, alone governs the relation between this Treaty and the law of international trade.
Article 37 Trade with non-Parties
1.From stage S3, each Party prohibits the import of covered chips from a non-Party.
2.From stage S2, each Party prohibits the export of Schedule A items to a non-Party; from stage S3, the export of covered chips.
3.From stage S3, each Party prohibits the import from a non-Party of the products Annex A part 3 lists as containing covered chips, within the period that Annex fixes.
4.From stage S2, each Party undertakes, to the fullest practicable extent, to discourage the export to a non-Party of technology for producing covered chips or Schedule A items, and refrains from providing new subsidies, aid, credits, guarantees or insurance programmes for such an export. This paragraph does not apply to equipment, tools, methods or technology that improve custody, measurement, attestation, audit, incident response or the security of covered manufacture, which this Treaty intends to travel freely.
4A.Produced with, but not containing. The Conference determines, by [a date the Parties set], whether a prohibition or a restriction on the import from a non-Party of services and outputs produced with covered compute but containing no covered chip is feasible, and states the reasons for its determination either way. Only where it determines that it is feasible does it adopt a list of such services and outputs; each Party then prohibits or restricts the import of a listed item within [one] year of the list taking effect. Nothing is prohibited under this paragraph before that determination is made, and Article 36A applies to any measure taken under it.
5.The door for a State. A non-Party that the Conference, by the majority of Article 11, paragraph 2(a), finds in full compliance with the obligations that bind Parties at the stage in question, and that submits the declarations of Article 28, trades as a Party for the purposes of this Article. The finding states its reasons, is published, and is reviewed every [3] years and on any recorded change in that State’s compliance; it lapses if it is not renewed at a review.
6.Covered compute services. From stage S2, no licensed facility of a Party provides covered compute for a covered run to a customer established in a non-Party, except under paragraph 5 or paragraph 7.
7.The door for a firm. An undertaking established in a non-Party may buy covered compute, covered chips and Schedule A service from Parties by contractual acceptance: it lodges formation records and notices, accepts evaluation, custody and inspection of the covered activity, and accepts the consequences of the Consolidated Denial List for a breach. The licensed facility in the Party answers for the contract. This paragraph binds no State. No inspection, evaluation or other act under such a contract takes place on the territory of a non-Party without the permission of that State.
8.What the firm’s door is not. The door is not open to an undertaking that a non-Party State owns, controls or directs, to an undertaking acting for such a State’s defence or security organs, or to an undertaking whose beneficial ownership it does not disclose. Nor is it open where the covered activity would be conducted on that State’s territory without the access the contract requires. A Party may refuse a contract under paragraph 7 on its own assessment, and states its reasons to the Secretariat, which records refusals by constituency for the enforcement parity index of Article 15A. On a material breach of the contract the licensed facility terminates it, supply and service stop, the Consolidated Denial List applies, and the Party’s export authority is notified. The Parties record that this door is a route for a firm and never a route for a State, and that a State determined to obtain covered compute through a firm it controls is a case the door is written to exclude and the inspection of Article 39 is written to detect.
9.No secondary measures. No Party applies a measure of this Treaty to an undertaking of a non-Party on account of its dealings with other non-Parties.
10.Every measure of this Article takes effect only behind the participation gate of Article 5A, is applied on identical terms to every non-Party in like circumstances, and is applied consistently with each Party’s obligations under the law of international trade, including its general exceptions, its security exceptions, and its disciplines on technical regulations, conformity assessment and the recognition of conformity assessment.
11.The Parties record that this Treaty binds only its Parties; that the prohibition reaching beyond them is reached through the Parties’ own trade, tool supply and compute services and in no other way; and that a bloc which declines to import and builds its own chain stands outside every measure of this Article.
12.Non-Party, schedule by schedule. For the purposes of this Part, “non-Party” has the meaning Article 2, paragraph 38, gives it, so that a State bound as to one schedule of Annex A is not treated as a non-Party as to every other.
13.A dated review of reach. The Conference considers, at its [fifth] session and at each review conference, whether the measures of this Part should reach a further class of covered computational substrate or a further schedule, and records its conclusion either way with its reasons.
14.This Article follows the pattern of Article 4 of the Montreal Protocol on Substances that Deplete the Ozone Layer: prohibitions of import and of export as against States not party, the feasibility determination before a prohibition reaches what is produced with but does not contain a controlled item, a duty to discourage the export of the technology of production with the withholding of new public support for it, the definition of a non-Party substance by substance, and, in paragraph 5 above, the permission to trade with a State not party that the Parties find in full compliance. That Article states nothing about artificial intelligence, names no agreement on trade, and neither requires nor supports this Treaty.
Article 38 Equal access and national export controls
1.The Eden Seal, licensing, accreditation and readmission are open to every State and every undertaking on identical terms, conditions and fees. No exception favours the undertakings of any Party, and no requirement of this Treaty operates as a barrier to market entry for smaller undertakings or for the economies of developing States.
2.A Party may maintain national export controls and notifies them to the Secretariat. From stage S2, no Party applies a unilateral export control on a scheduled item, or on a critical input of covered chips, to a licensed facility in good standing in another Party, for a purpose this Treaty covers, save under paragraph 3.
3.The essential-security exception. Nothing in this Treaty prevents a Party from taking action that it considers necessary for the protection of its essential security interests, and nothing in this Treaty requires a Party to furnish information the disclosure of which it considers contrary to those interests. A Party determines for itself whether a measure is necessary to protect those interests. It notifies the measure to the Executive Council within [30] days, stating its reasons, the obligation of this Treaty affected and the period for which the action is expected to last; the Council discusses it; and the Party takes part in consultations at the request of any Party affected. While the action continues, the Party does not benefit from the recognition of this Article for the obligation affected, and the capacity affected is recorded in its own column in the census. Information withheld under this paragraph is dealt with as an aggregate declaration under Article 39, paragraph 9. Where the exception is invoked against a licensed facility in good standing, the Party in which that facility is established may suspend, in proportion and for the duration of the measure, benefits of equivalent value owed to the invoking Party under this Treaty, including recognition of its certificates. The exception remains sovereign and ceases to be free. Nothing in this paragraph permits a Party to compel or request a means prohibited by Article 25, paragraph 6, or to take any action from which Article 36, paragraph 3, excludes every exception. Nothing in this Article affects a Party’s rights under any other agreement. The wording by which a Party determines for itself what it considers necessary follows Article XXI of the General Agreement on Tariffs and Trade 1994; the notice, the reasons, the consultation and the price are this Treaty’s own additions, and that Article is unaffected by them.
4.A pattern of invocation. Where the Executive Council finds that a Party has invoked paragraph 3 repeatedly against licensed facilities in good standing, it publishes the finding with the invocations it rests on, and the Conference may recommend that Parties suspend benefits of equivalent value collectively, each Party deciding for itself and applying the recommendation under its own law. The exception may never be invoked to require a means prohibited by Article 36, paragraph 3.
5.The asymmetry, stated. The Parties record that a suspension of benefits under paragraph 3 falls most heavily on the Party least able to bear it, and that a Party whose chain the world depends on loses little by the recognition of its certificates being suspended. Paragraph 4 exists for that reason, and the Parties record that it converts an unequal price into a collective one and does not make the price equal.
6.The Authority as verification provider. A Party may recognise the Authority’s custody findings and inspection findings as satisfying the security conditions of its own national licences, before and independently of any measure of this Part. Such recognition is the Party’s own act and binds no other Party.
Part X Verification and compliance
Article 39 Safeguards, inspection and managed access
1.The verification objective is the timely detection of covered compute that is unmarked or unaccounted for; of alteration of a covered chip’s governance core; and of a certified system whose registered measure has turned adverse or can no longer be evaluated; and deterrence of each by the risk of early detection. Verification is conducted for the exclusive purpose of verifying the fulfilment of the obligations assumed under this Treaty. No inspection, access or measurement is used for any other purpose, and no organ may require information that verification of those obligations does not need. The exclusive-purpose rule of the two preceding sentences follows Article III, paragraph 1, of the Treaty on the Non-Proliferation of Nuclear Weapons. That Treaty concerns nuclear material, states nothing about artificial intelligence, and neither requires nor supports this Treaty.
2.Routine inspection is conducted at the strategic points that Annex V fixes for each class of declared facility, site and domain, at the frequencies and sampling rates it states. Frequency and sampling are set in proportion to the quantity covered and to the risk the class carries, and never to the nationality of the operator. The Authority publishes each year, with clock C7, the inspection effort borne per covered site and per constituency, and the Inspector General reads that record for the enforcement parity index.
3.Complementary access to a declared location is provided on [24] hours’ notice, and on [2] hours’ notice at a site already under inspection, for the purpose of resolving a question about the correctness or the completeness of a declaration, or an inconsistency in a register. The Secretariat states the question in writing before the access; access under this paragraph is for the stated question alone; and the record of the access states whether the question was resolved. Before requesting access, the Secretariat gives the Party and the operator concerned an opportunity to clarify the question, unless delay would defeat the purpose of the access, and draws no conclusion on the question before that opportunity has been given. Paragraphs 5 and 6 apply to it. This paragraph follows the pattern of the Model Protocol Additional to the Agreement(s) between State(s) and the International Atomic Energy Agency for the Application of Safeguards, INFCIRC/540 (Corrected). That model concerns nuclear safeguards, states nothing about artificial intelligence, and neither requires nor supports this Treaty.
4.Challenge inspection. Every Party has the right to request an inspection of any covered facility, site or location on the territory or under the jurisdiction or control of any other Party, for the sole purpose of clarifying and resolving a question of possible non-compliance. The request states the question and the information on which the concern rests. A Party shall refrain from an unfounded request, and a pattern of unfounded requests is a breach in its own right. The inspected Party permits the inspection, and its duty to do so is not conditional on the outcome of any deliberation. The inspected Party receives the request not less than [12] hours before the team’s arrival at the point of entry.
(a)The filter stops an inspection; it does not start one. The Executive Council may decide, within [12] hours of receiving the request, not to proceed, by a majority of [three quarters] of all its members, and on these grounds alone: that the request is manifestly outside the scope of this Treaty, that it is frivolous or abusive, or that it states no question of possible non-compliance. The requesting Party and the inspected Party do not vote. The Council’s deliberation does not delay the inspection, and the team proceeds unless a decision not to proceed is taken within the period; where such a decision is taken, preparations stop, no further action is taken on the request, and both Parties are informed.
(b)The team reports the facts it found and the degree of access and cooperation afforded, and states no conclusion of non-compliance. The Council reviews the report on three questions alone: whether a question of possible non-compliance was raised, whether the request was within the scope of this Treaty, and whether the right of request was abused. Where it finds an abuse, the requesting Party bears the costs of the inspection.
This paragraph follows the structure of Article IX of the Chemical Weapons Convention. That Article concerns chemical weapons, states nothing about artificial intelligence, and neither requires nor supports this Treaty.
5.Managed access protects commercially sensitive, capability-sensitive and national-security material, on the pattern of the Confidentiality Annex to the Chemical Weapons Convention and as Annex C provides. Annex C carries a capability-sensitive class, comprising dangerous-capability evaluation data, architecture, training-data composition and weights, which is seen only by persons vetted under the host Party’s personnel reliability standard or by nationals of Parties outside the declared treaty allies of every Party concerned. Representatives of other Parties receive the findings and the recommendations, and not the material. The inspected Party affords the greatest degree of access consistent with its obligations under this Treaty and with its constitutional and national-security duties, and does not invoke those duties in order to conceal a breach. The team uses the methods the question requires and no others, takes and retains no material unrelated to that question, and Article 4C applies to everything it holds.
5A.When access begins, and how long it lasts. Access under paragraph 4 begins within [72] hours of the team’s arrival at the point of entry. An inspection under paragraph 4 lasts no longer than [84] hours, extendable once by [72] hours by agreement with the inspected Party, and an access under paragraph 3 no longer than [24] hours. A period fixed by this paragraph runs whether or not any deliberation is on foot, and the Parties record that an inspection with no stated end would be an occupation of a site rather than a verification of an obligation.
6.The burden of a withholding. Where an inspected Party affords less than full access, it demonstrates by alternative means that the facility, site or system complies with the obligation in question. The burden of that demonstration rests on the inspected Party, and the team records in its report whether it was discharged. A right to withhold to which no burden attaches would be a right to defeat the inspection, and this Treaty grants none.
7.Teams. Every inspection team includes nationals of at least [two] regional constituencies other than the inspected Party’s. No inspector is assigned to inspect a Party among its own declared treaty allies. Every finding of fact is signed by [two] human inspectors of different regional constituencies, and no finding rests solely on the output of an AI system.
8.Designation and objection. A Party may reject named individuals proposed as inspectors, monitors, investigators, sealed-laboratory staff or custodians acting on its territory or upon its assets, within the limits Annex N sets, and a repeated pattern of rejection is itself reviewable.
9.National-security compute. Covered chips destined for national-security use are covered at manufacture on the same terms as any other. The application of rulesets to them is at the discretion of the Party concerned. Such chips and sites are declared in aggregate. Access is by managed access with chip attestation and the host Party’s own two-person application, and no representative of another Party is present except on a challenge inspection under paragraph 4. There is no blanket exemption from the registry, accounting, custody or serious-incident duties of this Treaty, and a classified verification pathway is established in Annex V for cleared inspectors.
(a)What the declaration does not buy. A declaration under Article 2, paragraph 13, reaches compute operated for the declaring Party’s national security and nothing else. It does not reach a covered run whose model, or a system derived from it, is placed on the market or put into service commercially, nor a covered run conducted for a person other than that Party; compute so used ceases to be national-security compute from the first step of that run, and every duty then in effect applies to it.
(b)The declaration is counted and read. The declared share of a Party’s installed covered compute is published each year in aggregate, is not counted towards that Party’s share under Article 5A, paragraph 9, and is read at each review conference against the clocks. Where a Party’s declared share exceeds the fraction Annex V fixes, or rises by more than the step Annex V fixes in a year, the Board publishes the fact and the Executive Council opens a consultation with that Party; neither is a finding of breach.
(c)The limit, stated. The Parties record that this paragraph is verified by a Party’s own declaration, by attestation at manufacture and by aggregate reporting, that a Party determined to conceal covered compute behind this paragraph would not be detected by it, and that the accounting of Article 24, the unseen-capacity estimate of Article 28, paragraph 8, and the challenge inspection of paragraph 4 are what stand against that. This is the largest opening in the verification of this Treaty and it is not closed.
10.Every assurance is labelled by what enforces it, being an attestation, an inspection, a declaration, a contract or a Party’s own law, and the Ledger carries the label with the assurance. An attestation is evidence of the measured claim it names and of nothing else. An intact chip does not make the system running on it good, and no finding under this Part states otherwise.
Article 39A Defence systems: frozen systems, declared custody and legal review
1.Nothing in this Treaty prohibits a Party from using AI in its defence, and nothing in this Treaty authorises conduct that international law otherwise prohibits. This Article states no rule of the law of armed conflict, and nothing in it asserts that the Geneva Conventions of 12 August 1949, or their Additional Protocols, already govern artificial intelligence. Those instruments are named below by their short titles.
1A.No certificate is evidence of compliance with the law of armed conflict. Nothing in this Treaty affects a Party’s obligations under the law of armed conflict. No certificate issued under this Treaty, no attestation and no finding of an organ of the Authority is evidence that a system, or its employment, complies with any rule of that law, and none is to be relied on as such in any proceeding. The Eden Seal certifies the conditions Article 2, paragraph 10, names and no outcome of any kind.
1B.The work under the Convention on Certain Conventional Weapons. Nothing in this Treaty prejudices the work of the High Contracting Parties to the Convention on Prohibitions or Restrictions on the Use of Certain Conventional Weapons Which May be Deemed to be Excessively Injurious or to Have Indiscriminate Effects, adopted at Geneva on 10 October 1980, on emerging technologies in the area of lethal autonomous weapons systems. This Treaty takes no provision from that Convention and attributes none to it.
2.The frozen-system rule. A covered system deployed in a defence system of a Party is a frozen system: its weights are fixed, registered and attested by the chips on which it runs, so that the system in service is the system that was assessed; it receives no capability-directed training in service; and it does not perform any material self-modification. Renewed assurance is required after any material change.
3.Succession is not a route around paragraph 2. Where a frozen system in a defence system is replaced by a successor, the successor is assessed afresh, carries its own legal review under paragraph 6, and is declared. A Party reports in aggregate each year the number of such replacements by defence system and the interval between them, and the review conference reads that report. A sequence of replacements by which a defence system acquires, in service, capability it was not assessed with is a circumvention of paragraph 2 and is answered under Article 41.
4.A defence system of a Party shall not operate a covered system of the recursive-critical tier.
5.Declared custody. Chips in defence use are declared and held under the custody of Article 39, paragraph 9, and are entered in the same register, so that the account of Article 24 still balances. A declared exception is visible; an undeclared one is a breach.
6.Legal review. Each Party undertakes to determine, in the study, development, acquisition and adoption of a defence system incorporating a covered system, whether its employment would in some or all circumstances be prohibited by the rules of international law applicable to that Party. The determination is made before adoption and again after any material change, on the model of Article 36 of Additional Protocol I (Geneva, 8 June 1977) to the Geneva Conventions of 12 August 1949. That Article names no technology, states nothing about artificial intelligence, and neither requires nor supports this Treaty; the procedure below is this Treaty’s own.
(a)The determination is made by a body the Party designates, which is not the body that procures the system.
(b)It is recorded, with its reasons and the evidence considered, before the stage to which it relates is completed.
(c)The Party notifies the Authority of the fact and the date of each determination, and of nothing more. Nothing in this paragraph requires a Party to disclose the content of a review, and the record of the fact and the date is exchanged in aggregate.
(d)Where a determination is negative, the Party does not proceed to the next stage for that system until the determination is made afresh and is positive.
7.The tension, recorded. Paragraphs 2, 3 and 4 are verified by a Party’s own declaration, by chip attestation at manufacture and by aggregate reporting, and not by another Party’s inspectors. The Parties record that this is weaker than the verification of Part X generally, that it is the price of any defence provision a Party would accept, and that it is read again at each review conference against the clocks.
Article 40 Detection, reporting and red teams
1.Detection rests on integrity attestation and its failure; the refusal by a covered service of work from chips without a current and valid attestation; the accounts of Article 24 and their reconciliation; sampling and destructive testing; the energy bound of Article 28; national technical means and open sources; supply-chain flow monitoring; the duty of a covered operator to report diversion or tampering; the protected channels of Article 41C; and re-measurement of behaviour.
2.Re-measurement of behaviour corroborates and never carries a finding alone, because a system able to reason about its own conduct during an evaluation can in principle reason about its conduct during verification.
3.The red-team range operates under the Authority’s containment and disclosure rule. Findings go first to the tightening procedure of Article 26. Exploit detail is never published. A standing bounty is paid for coordinated disclosure and never for publication, and authorised testing within a declared scope, disclosed as the rule requires, is protected.
Article 40A The Incident Investigation Board
1.In this Article “the Incident Investigation Board” is the body established by Article 10, whose full name is the International AI Incident Investigation Board; “the Board” keeps the meaning Article 2 gives it. The sole objective of an investigation under this Article is prevention. It is not the purpose of an investigation to apportion blame or liability, and no finding of the Incident Investigation Board is a finding of fault.
2.The Incident Investigation Board investigates serious incidents involving covered systems or covered compute, being a loss-of-control event, an escape from containment, an autonomous intrusion, a failure of a stop, a tamper, an anomaly in key custody and an exfiltration of covered weights.
2A.The self-improvement notice. A covered operator notifies its national authority, and the national authority notifies the Incident Investigation Board and the Thresholds and Standards Committee, where a covered system it develops, trains or deploys demonstrates a capacity to perform a material self-modification otherwise than on a human authorisation, whether or not any such modification occurred. Notice is given on the early-warning clock of Article 41A, without fault and for prevention under paragraph 1 of this Article. The demonstrated capacity is a route into coverage under Article 27, paragraph 2, and the Committee places the system in the tier that route requires. A notice under this paragraph is neither an admission nor a finding of breach.
3.Who leads. The investigation authority of the Party on whose territory the incident occurred leads, with its own investigators. The Incident Investigation Board leads where that Party so requests or where the incident crosses borders, and then the lead investigator comes from a Party outside the declared treaty allies of every Party involved, or, where none with capacity is available, from outside the involved Parties’ allies. The Party concerned may reject named individuals within the limits of Annex N.
4.Who takes part. Accredited representatives of the Party of occurrence, of the Party where the developer is established, of the Parties of chip design and of manufacture, and of any Party whose people or systems were affected. They take part; they do not lead.
5.Independence. The head of the Incident Investigation Board is elected by two thirds of the Conference with majorities in [four] regional constituencies for one term, and takes no instruction on a finding from the Director-General, the Executive Council or any Party.
6.Weights and capability-sensitive material are examined on site and never moved, under Article 39, paragraph 5.
7.Outputs. A preliminary statement within [30] days; a final report within [12] months; and safety recommendations to Parties, to undertakings and to the Thresholds and Standards Committee, whose addressees answer within [90] days. Every report is published. A Party may append its comments and may neither suppress nor delay a report. Security redaction is permitted on a Party’s reasoned request; the Incident Investigation Board decides its extent, and where that Board and the Party disagree the Appeals Chamber decides within [30] days. The report states what was redacted by category and on whose request, and a redaction never removes a safety recommendation, the class of the incident, or the fact that an incident occurred.
8.The channel of this Article is multilateral and is built to receive bilateral incident channels that States have established between themselves. A non-Party may notify an incident through it and may take part as an observer, whatever its trade status.
Article 41 Measures to redress (Annex R)
1.Annex R part 1 lists the notifiable incident classes and Annex R part 2 the breach classes with the schedule of consequences. Nothing in this Article binds before the duty it enforces binds.
2.Two tracks. An incident is reported without fault under Article 41A and is investigated for prevention under Article 40A. A breach is found under Article 41D and answered on the schedule.
3.Protective consequences follow risk. They may be taken at once, with a hearing afterwards within the time limits of Article 41D; they are never reduced by leniency; and they last no longer than the risk requires. The least restrictive measure capable of securing compliance is applied first, and a measure is lifted when the Compliance Panel records that the non-compliance has ceased or that the risk has passed. They are: emergency suspension of an affected certificate, lot certificate or licence; a stop order for a run or a deployment, exercised by the operator’s own authorised persons; a preservation order; escrow of weights under Article 31; an independent monitor; provisional listing under Article 41E; on-site safing after a confirmed tamper by a team of [two] regional constituencies, at least one member from outside the host’s declared allies; the Treaty Key under Article 30; and enhanced inspection.
4.Punitive consequences follow culpability, come only after due process, are graded by the schedule of Annex R part 2 on the levels R0 to R5, and are reduced by candour under Article 41B. They are: a published finding; a fine within the maxima of paragraph 6; disgorgement for a knowing breach; loss of the voluntary benefits; debarment from new certification for a period; and referral of individuals to national prosecutors.
5.The levels. R0 is notice and cure, cured within [30] days, or within [90] days for an engineering change, with no fine and no public listing where cured. R1 is a published finding with a cure plan. R2 adds suspension of the affected certificate or licence until cure. R3 adds revocation, an independent monitor for [1 to 3] years and escrow. R4 adds listing under Article 41E and debarment. R5 applies to facilities and adds revocation of a facility licence or of a family type approval, with the Treaty Key and the sealing of affected lots.
6.Fines. Each Party provides in its law for maxima of at least [1] per cent at level R1, [4] per cent at level R2, [7] per cent at level R3, and [10] per cent at level R4 and at level R5, in each case of the annual turnover of the undertaking’s covered AI activity, or a fixed floor stated in special drawing rights, whichever is higher. The base rises to the turnover of the group where group management directed or knowingly permitted the breach, where the accounts of covered activity are not separated, or where the breach is one of integrity. A daily penalty of up to [0.5] per cent of average daily turnover on that base runs only for defiance of a final order or of a confirmed protective order, and never while a punitive order is under appeal.
7.Where the money goes. Never to the budget of the Authority or of an organ that finds or decides, and never to any person. Each Party pays [a share] of what it collects into the Multilateral Fund, applied in the order: compensation of victims, transition and capacity for developing States, and the replication fund. A fine never reduces a Party’s assessed contribution and never reduces compensation owed to a victim under national law.
8.Nothing is destroyed. Chips of a suspended or revoked lot are declared and brought under this Treaty by re-sampling and re-certification, or by restriction below the thresholds. A device leaves covered operation only on a confirmed tamper at its site or on a final revocation after appeal, in either case carried out on site by people, and Article 23, paragraph 4, governs who carries out the act and what follows a refusal. No expiry, no vote, no failure to act and no message changes what a chip does.
9.States. Against a Party the ladder runs: consultation and clarification within [30] days; a published finding with an action plan within [60] days and a facilitative committee to help meet it; suspension of the privileges Annex R lists, which never include the right to be heard, the right of appeal, access to the incident channel or the right to withdraw; the Treaty Key against its covered facilities not in good standing; collective measures, in conformity with international law, that the Conference may recommend, each Party deciding for itself whether to apply a recommended measure and applying it under its own law; and referral of the issue, with the information and conclusions, to the General Assembly and, in cases of particular gravity, to the Security Council. Findings are made by the Compliance Panel; consequences are decided by the Executive Council, or by the Conference for collective measures, and the Party concerned does not vote.
10.Readmission on verified compliance, within [30] days of the Inspectorate’s verification, on the same terms for every Party.
11.Peer review. Every [4] years each Party’s implementation and enforcement are reviewed by a team from [two] other regional constituencies, one member from outside its declared allies, and the report is published. Persistent under-enforcement found by a review is itself a breach, and the Inspector General publishes the enforcement parity index each year.
12.An AI system is not a defendant. Where an act is attributed to a covered system acting for itself, the consequences reach the affected versions and configurations of its lineage, widened to the lineage only where the investigation finds the cause there; its compute, by quarantine; and its weights, by escrow. Responsibility remains with the operator for the duties it held, and with each Party for the performance of its own obligations under this Treaty in respect of the persons and the conduct within its jurisdiction.
Article 41A The notification clock
1.Awareness begins at the logged human review of an alert, or [2] hours after an alert that has not been reviewed.
2.From awareness: immediate notice within [4] hours for an incident of the gravest class with a continuing effect on another person or Party; early warning within [24] hours; an initial report within [72] hours; and a final report within [30] days. A confidential quarterly return records near misses and contained events by class.
3.Preservation of logs, traces and the relevant state is automatic at awareness, in tamper-evident form, and continues until every proceeding closes.
4.A notified accident is not an attack, and a Party shall not treat a notification under this Article as an admission or as a hostile act.
Article 41B Leniency
1.Leniency buys down punishment and never protection. Every protective consequence the risk requires applies in full, whoever reported.
2.A self-report made before any authority knows, with full disclosure, cessation, preservation, cooperation and cure, lowers the presumptive level by two, not below R0; removes any fine beyond disgorgement for a knowing breach and any fine at all for a negligent one; and excludes debarment and punitive listing. A report made after an investigation opens but before a finding lowers the level by one and reduces the fine by [30 to 50] per cent. The first of several parties to a joint scheme to report receives immunity from fines, and those following receive reductions of [50], [30] and [20] per cent in order.
3.An instigator who coerced others receives the cooperation reduction alone. A second self-report of the same class within [3] years receives no self-report reduction. A report made after the reporter knew of an inspection or an investigation counts as cooperation.
4.Leniency is available for concealment and for tampering, because this Treaty needs to learn of them above all else, and it reduces punitive consequences alone.
5.A Party that reports its own failure is placed on the facilitative track and is not suspended unless the failure repeats.
Article 41C Protected channels for insiders
1.The protection of this Article extends to employees, contractors, researchers, former employees, laboratory staff and suppliers’ staff of any covered operator, and to custodians, inspectors, investigators and staff of the Secretariat.
2.The reporter chooses the channel: the operator’s designated safety officer, who escalates within [7] days; the Party’s national authority; a confidential and secure channel direct to the Inspectorate, which passes neither the employer nor the host State; or, for persons inside the regime, the Inspector General. There is no duty to report internally first. A technical annex containing controlled technology travels through the national authority’s secure channel.
3.Each Party provides in its law: the prohibition of retaliation; the nullity of any contractual term that bars or penalises a report to an authority or to the Authority; confidentiality of the reporter’s identity; a reversed burden of proof in a retaliation claim; interim relief including reinstatement; legal and financial support from the fund; immunity from liability for the disclosure itself; and protection for a good-faith report that proves mistaken, with no protection for a knowingly false one.
4.The report is acknowledged within [7] days and assessed within [30]. The Inspectorate frames any resulting request so that it does not reveal the source. A register of reports by class is published in aggregate alone.
5.A disclosure to the public is protected where the channels have not acted within [3] months, or where there is an imminent danger to life or of an incident of the gravest class. The containment rule of Article 40 still binds: the protection covers the fact of wrongdoing and never the publication of exploit detail or of weights.
6.For national-security compute, a Party may route reports to a national oversight body, which sends the Inspectorate a summary within [30] days.
Article 41D Due process with time limits
1.A preliminary assessment is completed within [30] days of a report or a detection, and the operator is informed unless informing it would defeat preservation. A statement of objections is issued within [90] days, with the evidence, confidential parts shown to counsel under managed access. The operator answers within [60] days and is heard. A first-instance decision issues within [60] days of the hearing, with reasons, and an appeal is decided within [90] days. A provisional protective measure is confirmed or lifted within [7] days.
1A.A duty president. One member of the roster of Article 45, paragraph 3, is on call at all times as duty president. Where an organ of the Authority misses a period fixed by this Article, the duty president rules within [3] days on the consequence of the delay for the proceeding, and may extend a period for the respondent, lift or confirm a provisional measure, or remit the matter.
2.Standards of proof. A protective measure requires credible evidence of risk. A punitive finding at R1 or R2 requires proof on the balance of probabilities. A finding of an integrity breach, and any listing under Article 41E, requires clear and convincing evidence.
3.Separation of functions. The body that investigates does not decide, and the body that decides does not hear the appeal. No finding rests solely on the output of an AI system.
3A.The provenance of evidence derived with an AI system. A respondent may require the provenance of any evidence in the proceeding that was derived with the assistance of an AI system, being the family and version used, the material to which it was applied, and the human review it received. Evidence whose provenance is not produced on such a requirement is not relied on.
3B.Equality of arms. Legal assistance and technical experts are available from the Multilateral Fund of Article 42, paragraph 5, on application, to a natural person and to an undertaking whose annual revenue from covered activity is below the line Annex F2 fixes for this paragraph, in any proceeding under this Article and on any appeal from it.
4.No person is punished for conduct that took place before the obligation in question entered into effect.
5.Where a protective measure is later found unjustified, the operator is compensated for direct loss from the fund, which recovers from any Party whose abuse caused it.
Article 41E The Consolidated Denial List
1.The List, on the Ledger’s public tier, names persons found at level R4 and persons listed provisionally where an ongoing risk requires it.
2.Its effect in every Party, through implementing law and licence conditions: a licensed covered facility, a maker of chips holding Seal-C and a servicer of Schedule A items shall not provide covered compute, covered chips or Schedule A service to a listed person, or to an affiliate it controls, for covered work. Screening is a licence condition.
3.Listing is available only for intentional evasion or concealment. A provisional listing lapses unless confirmed within [7] days on clear and convincing evidence of ongoing risk.
4.The duration is [1 to 5] years, with conditional release on a monitor’s certification and an audited compliance programme, and delisting by the Compliance Panel.
5.A wind-down of [30] days applies to services that are not covered. Work under a monitor’s supervision, and the escrow itself, are excepted. Nothing below the thresholds of Annex A is affected.
6.The presumption that a successor, an affiliate or a new company controlled by the same persons falls within a listing is rebuttable by a showing of separation and non-involvement, and never reaches an affiliate’s third-party customers.
7.The panel that lists is drawn by lot under Article 16A, excluding nationals of the parties to the matter and of their declared treaty allies. Every Party’s undertakings face the same List, and the enforcement parity index records whether the undertakings of any set are listed more often for the same conduct.
8.Against a person established in a non-Party, the List takes effect only behind the participation gate of Article 5A.
Article 41F The lapse rule
1.Where a duty falls with the evidence that armed it, a protective measure resting on that duty alone lifts at once, and a punishment not yet final is remitted.
2.A final penalty already imposed stands, and a finding of an integrity breach never lapses.
3.This Article operates by rule and requires no vote. Article 8A applies to every obligation it touches.
Part XI Cooperation and implementation
Article 42 Benefits, assistance and the funds
1.What is available from entry into force, without any Eden Seal. The incident exchange of Article 40A; the shared safety laboratory of Article 42G and its academy; access to compute for developing States; capacity building for national authorities and accredited laboratories in every region; the Multilateral Fund; a seat in the Conference and eligibility for election to every other organ; pilots of the test methods in public procurement; and the operator protections of Article 4B.
2.What is available from the first voluntary Eden Seal. Preference for certified systems and certified compute in public procurement, on identical terms whatever the supplier’s nationality; the grades of liability protection a Party adopts under Article 42C; the general authorisation for trusted compute as an offer; and the early formation credit of Article 33, paragraph 6, from stage S2.
3.The completed bargain. The Parties shall provide, so far as their law allows: mutual recognition of certificates issued by another Party’s accredited authority that meet the international minimum and pass confirmation from outside the issuing Party’s declared allies; regulatory passporting, so that one certification serves in every Party for the matters it certifies; the reduction of duplicate audits; recognition of certification by insurers and financiers, where lawful; and certification conducted so that a trade secret is protected, no disclosure of model weights or source code is required, and nothing is disclosed beyond what the verified claim needs. Every obligation of this Treaty that binds a threshold State binds the others reciprocally, and none binds unilaterally. A Party that cannot provide a benefit of this paragraph states why to the Secretariat, which publishes each year which benefits of paragraphs 1 to 3 are available in which Parties, so that what the bargain pays is as visible as what it costs.
4.No blanket immunity. Certification confers no general protection from liability. It is evidence of due care under Article 4B, paragraph 4, and no more; it protects nothing in respect of conduct after certification, of a shift in the conditions of use, of negligent operation, or of any fact outside the certified claim.
5.The Multilateral Fund, on the model of Article 10 of the Montreal Protocol, receives assessed contributions under Article 42A, the shares of fines under Article 41, and voluntary contributions, and funds transition compensation under Articles 33 and 35, the conformity costs of deployers established in developing States, the compute access facility, capacity building, the replication fund and the compensation of Article 41D, paragraph 5.
6.Grace periods for deployers established in developing States, on the pattern of the delayed compliance of Article 5 of the Montreal Protocol, and never for a developer of a covered system in the mark band.
6A.Where the promised help does not come. A Party whose deployers benefit from paragraph 6 may notify the Secretariat that, having taken all practicable steps, it is unable to meet an obligation of this Treaty because the assistance of this Article has not been provided. The Secretariat transmits the notification to every Party forthwith. Article 41 is not invoked against that Party on the obligation named until the Conference has considered the notification at its next session and decided what action is appropriate, and for such longer period as the Conference decides. This paragraph follows the pattern of Article 5, paragraphs 6 and 7, of the Montreal Protocol, and reaches no obligation of custody, attestation, the site stop or the integrity of the Evidence Ledger.
7.Moral assurance bonds. A Party may require a deployer to post a bond, forfeited towards the compensation of victims where its system causes harm through the failure of a certified condition or of a line of the Standard. The bond is paid on harm and not on breach, is kept apart from any penalty, and its price falls as compliance is verified.
8.The benefits of this Article are withdrawn on a final finding at level R2 or above, and on any integrity breach, for the period Annex R fixes, and are restored after that period without a new finding.
Article 42A Funding by formula
1.Every Party pays an assessed contribution on a capacity-to-pay scale, with a ceiling of [15] per cent and a floor of [0.001] per cent. Assessed contributions fund the organs at every stage.
2.From stage S2, a levy is payable on every covered chip placed on the market or put into service in a Party, at the rate the Conference sets under Article 11, paragraph 2(e), identical for domestic and imported chips, with a deemed value for chips a Party’s undertakings place into their own service. It funds certification, inspection, testing, the Replication Compute Facility and the Incident Investigation Board, and no other activity. The rate is set on a published cost basis, does not exceed what those activities cost, and does not exceed [0.5] per cent of the declared value of the chip; a proposed increase is published [12] months in advance with its cost basis. It is a charge on covered compute and never on the Eden Seal, which carries no fee. No levy is payable before stage S2, and none on a voluntary certification.
3.Voluntary contributions go only to the Multilateral Fund and to capacity building, pooled and unearmarked. No contribution is earmarked to the core work of any organ.
4.A reserve of [12] months of the core budget is maintained. Where no budget is adopted, the previous budget continues, indexed, so that no Party or group may close the Authority by withholding a vote.
5.Voting is unweighted. Money buys no vote and no seat.
6.A Party [two] years in arrears loses its vote in the Conference and in the Executive Council until it pays, and keeps every obligation. Unremitted levy is a matter for Article 41 at the level of clarification.
7.The pool is the fund from which the Authority pays for accreditation, certification, inspection and monitoring, constituted from assessed contributions under paragraph 1 and from the levy under paragraph 2, and operated as Annex F2 provides. Accredited laboratories, inspectors and monitors are paid from the pool and never by the undertaking or the Party they examine.
8.Voluntary certification is free to applicants at stage S1, funded from assessed contributions.
Article 42B Service levels
1.The Authority meets the service levels of Annex V for each act, including the acknowledgement of a run notification within [5] working days; family type approval within [90] days; a new entrant’s first family provisionally within [30] days and fully within [120] days; a delta approval within [10] days; a lot certificate within [10] days; renewal [30] days before expiry; and an appeal of a certification decision within [30] days.
2.Where the Authority misses its own deadline, a renewal is extended automatically by [90] days and a lot is released under provisional status. There is no deemed approval of an evaluation for a registered mark-band capability.
3.Service levels for the certification of systems are fixed after the measurement gate and are targets until they are fixed.
4.Fees are cost-based and capped, and are waived for undertakings below a revenue line and for entities of developing States.
5.The Authority publishes each year, as clock C7, its throughput and its queues. Its duty to accredit enough laboratories in every regional constituency to meet these levels is a duty of the Authority and is measured.
Article 42C Liability options
1.Grade 1, that compliance with a current Seal-S is admissible as evidence of due care, is the floor and binds every Party under Article 4B.
2.Grade 2, a rebuttable presumption of due care, is a national option.
3.Grade 3 is a national option and is adopted only as one package, never in part: liability for harm caused by the autonomous action of a covered system channelled to the certified developer; strict, so that a victim need not prove fault; capped per incident at an insurable level indexed to covered compute; compulsory financial security for the first tier; an industry pool for the second, funded by contributions of certified developers pro rata to covered compute, experience-rated, capped in any year and forfeit on concealment; and the Parties’ public funds for the third. Victims are paid from the fund first, and the fund pursues any non-compliant party.
4.Every grade is lost entirely by concealment, by wilful breach, by gross negligence, or by breach of an armed obligation found at level R2 or above.
5.A cap limits compensation alone. It limits no penalty of this Treaty and no regulatory measure of any Party.
Article 42D Coordination under law
1.Conduct that this Treaty requires is lawful for those who carry it out, under Article 4B, paragraph 2.
2.A Party may provide in addition that conduct which the organs of the Authority authorise in advance and supervise, for the purposes listed in paragraph 3, is treated as conduct required by law, and that compliance is not evidence of collusion.
3.The purposes are closed: pausing, pacing or sequencing covered training under a stage in effect; sharing incident intelligence through the exchange; joint development of test methods and conformance data under the Thresholds and Standards Committee; and joint exercises on the red-team range under the containment rule.
4.Safeguards. The Authority decides and the undertakings do not. No price, output plan or commercially sensitive information passes between undertakings beyond what the Authority requires. Minutes are published on the Ledger’s public tier. National competition authorities may observe. Every duty binds by threshold and never by membership of any body, and every standard is open and royalty-free.
5.An industry body may be accredited only as a contributor of candidate test methods, open to every entrant and supervised. It never issues the Eden Seal, never tests the products of its own members, and never votes.
Article 42E Comply once
1.The Thresholds and Standards Committee may find a national or regional regime equivalent, for a stated measure, to a duty of this Treaty. A covered operator that complies with an equivalent regime complies with this Treaty for that measure.
2.A finding names the measure, states the outcome-by-outcome mapping on which it rests, is published with its reasons, and is reviewed every [3] years.
3.Equivalence is found on outcomes and never on the form of a regime, and is found only where the Committee is satisfied that the regime is enforced as well as enacted, on the record of that Party’s peer review under Article 41, paragraph 11, where one exists.
4.A finding lapses at once on a recorded change in the regime found equivalent, or on a recorded failure of its enforcement, and the operators that relied on it have [90] days to comply with this Treaty directly. A finding never reaches a measure it does not name.
Article 42F The cost of this Treaty to development
1.The Board publishes each year, as clock C6, the cost of the duties then in effect, by stage, as a share of the compute cost of covered runs, estimated from the records of accredited laboratories and from confidential submissions of covered operators, audited.
2.The Parties set, on the reading published under paragraph 1, an indicative ceiling of [1.5] per cent for the baseline and the custody track together, and of [3] per cent through stage S2. The cost of stage S3 is reported without a ceiling, because the instrument that bounds that cost is the viability record of Article 7B, paragraph 4, which measures the required design’s capability cost and its compute premium before any general mandate arms and sets the transition and the compensation window from that measurement by rules written before the result. A ceiling in this Article and a measurement in that one are not the same instrument, and the Parties record that the largest cost this Treaty could impose is governed by the second.
3.Where a reading exceeds a ceiling, the Executive Council shall revise methods, service levels and fees within [6] months. It shall not relax an evidential condition, a custody measure or a registered threshold, and the freeze of Annex T stands.
4.The Parties record that a developer may overstate its costs, that the Board’s estimate rests on audited records, and that the consequence of a breach of the ceiling is a review of methods and never a loosening of a condition.
Article 42G The shared safety laboratory
1.The Authority maintains one laboratory in several places, open to accredited groups of every regional constituency, to undertakings of every size, to universities and to entities of developing States, comprising: the accredited network of national and regional laboratories, with a goal of at least one in every regional constituency; the Authority’s own sealed laboratory; the Replication Compute Facility of Article 6; an open library of test methods and audit tools, published free; the red-team range of Article 40; and an academy that trains evaluators and inspectors from every region.
2.Proprietary models are evaluated inside the developer’s own secure facility under the supervision of accredited evaluators. Weights never pass to the Authority.
3.The methods, tools and data of the library are published under the royalty-free condition of Article 21A.
Article 42H Open release
1.Publication of a model below the notice floor is outside this Treaty, and no Party shall restrict it under this Treaty.
2.In the mark band from stage S2, a covered model may be released openly where an accredited pre-release evaluation finds no registered mark-band capability, and it then carries an open release certificate and not Seal-S, because the custody of Article 31 cannot hold for released weights. The evaluation covers the capability the weights would reach under the methods of adaptation the Committee has registered, at the adaptation budget Annex A fixes, and the releaser publishes that budget with the certificate. A release of weights that reach a registered mark-band capability under that budget is a release in the mark band and is governed by paragraph 3.
3.From stage S3, the open release of covered weights formed without embedded correction is barred, and the release of weights formed under an approved formation record is permitted where the removal-cost item of Annex HG stands at its registered rung.
4.The Parties record that released weights cannot in practice be recalled, and that nothing in this Article gives this Treaty any reach over weights once released.
Article 43 National implementation
1.Each Party designates a national authority, and takes the legislative, administrative and other measures necessary to give effect to each obligation of this Treaty by the date on which that obligation enters into effect for it.
1A.Inspection in national law. Each Party provides in its law for the entry of inspection teams, investigators and monitors under Articles 39 and 40A; for their escort by its national authority; for the protection of instruments and seals installed in the course of an inspection; and for any challenge in its courts to an inspection to be heard after the inspection has ended and not so as to prevent or delay it. A Party provides for the immunities of Article 10A in its law by the date on which the first inspection on its territory is due.
2.Each Party undertakes to respect this Treaty and to ensure its respect by the persons under its jurisdiction and by undertakings established on its territory. The two limbs of that undertaking follow the first Article common to the Geneva Conventions of 12 August 1949. Those Conventions state nothing about artificial intelligence, name no means of ensuring respect, and neither require nor support this Treaty; the means are those this Article states.
2A.The responsible person inside each undertaking. Each Party requires every covered operator, manufacturer and design house under its jurisdiction to appoint a responsible person, and requires that person to take the measures within their power to prevent and to suppress a breach of this Treaty within the undertaking, and to report to the national authority a breach they know of, or of which they hold information enabling them to conclude that it has occurred. The appointment and the identity of that person are notified to the national authority, and a failure to appoint is a breach at the level Annex R fixes. This paragraph creates no liability in that person for a breach they could not have prevented and did not know of.
3.The minimum offences. Each Party makes it an offence, where the person acts knowingly or intentionally: to tamper with a covered chip’s governance core, its attestation, its provisioning, its seals or its custody material, or with the Evidence Ledger or key material; to falsify, destroy or conceal a record this Treaty requires, or evidence in a replication or an evaluation; to direct or permit a covered run without the required notice, or a deployment without the required evaluation, where the obligation is armed; to direct or permit the concealment of a notifiable incident; to supply covered chips, Schedule A items or covered compute in breach of Part IX or of the Consolidated Denial List; to obstruct an inspector, an investigator or a custodian; to refuse or fail to carry out a final revocation, an on-site safing or a withdrawal from covered operation that this Treaty requires; and to retaliate against a protected reporter.
3A.The register governs the offence. The offences of paragraph 3 of directing or permitting a covered run without the required notice, and of directing or permitting a deployment without the required evaluation, reach only a duty standing on the Reasons Register published under Article 8A on the day of the conduct, and the words “where the obligation is armed” in that paragraph are read accordingly. Each Party states in its implementing law which published record of that Register governs a given day.
4.For the offences of tampering and of concealment in paragraph 3, a person acts knowingly who deliberately avoids knowledge of a fact that person suspects, and each Party provides that a reckless act of tampering with a governance core, an attestation, a seal, custody material, the Evidence Ledger or key material is an offence.
5.It is never an offence to make a good-faith compliance error, to take a decision in good faith under the stop criteria, or to make a good-faith report that proves mistaken.
5A.Suppression of acts short of an offence. Each Party takes the measures necessary for the suppression of acts contrary to this Treaty that are not offences under paragraph 3. This paragraph creates no offence and no penalty, and the measures a Party takes under it are administrative, regulatory or contractual.
6.Legal persons are liable for an offence committed for their benefit by a person in authority, or through a failure of supervision, by criminal or non-criminal sanctions that are effective, proportionate and dissuasive according to the Party’s legal system.
7.Penalties are proportionate; imprisonment is available for the offences of tampering, of falsification and of unlawful supply where committed for gain or with harm; and disqualification from covered roles is available for up to [10] years.
7A.The floor of a proper trial. A person proceeded against for an offence under paragraph 3 enjoys the safeguards of proper trial and defence provided by the law of the Party and by the international obligations binding on it, which are in no case less favourable than those that Party affords for an offence of comparable gravity under its own law.
8.Jurisdiction, search and cooperation.
(a)Each Party establishes jurisdiction over every offence of paragraph 3 committed on its territory, and over every such offence committed by one of its nationals, or by a body incorporated or established under its law, wherever it occurs.
(b)For the offence of tampering with a covered chip’s governance core, its attestation, its provisioning, its seals or its custody material, or with the Evidence Ledger or key material, each Party also establishes jurisdiction where the person alleged to have committed it is found on its territory, whatever the place of the conduct and whatever the nationality of the person; searches for such a person who may be on its territory; and, if it does not extradite that person, submits the case without exception to its competent authorities for the purpose of prosecution. That wider jurisdiction reaches this offence alone, because this is the offence a State outside this Treaty could shelter.
(c)Each Party affords the widest measure of mutual legal assistance for every offence of paragraph 3.
(d)Subparagraph (b) follows the pattern of the grave-breaches provisions of the Geneva Conventions of 12 August 1949. Nothing in this paragraph characterises any offence of paragraph 3 as a war crime or as a grave breach of those Conventions, and this Treaty creates no rule of the law of armed conflict.
8A.Extradition. The offences of paragraph 3 are deemed to be included as extraditable offences in every extradition treaty in force between Parties, and every Party undertakes to include them as extraditable offences in each extradition treaty it concludes thereafter. A Party that makes extradition conditional on the existence of a treaty may consider this Treaty the legal basis for extradition in respect of those offences. Extradition is subject in every case to the conditions of the law of the requested Party.
9.A Party credits any penalty another Party has already imposed for the same conduct, and the Compliance Panel coordinates where several Parties have jurisdiction.
10.Each Party provides in its implementing law a general authorisation for the disclosures that the procedures of this Treaty require, to the sealed laboratory, to accredited panels, to inspectors, witnesses, investigators and monitors, limited in each case to what the procedure needs.
11.Each Party provides that conduct this Treaty requires is lawful for those who carry it out, and enacts Article 4B by the date on which the first obligation binding its operators enters into effect.
12.Federal States. A federal State ensures that the obligations of this Treaty are given effect throughout its territory, whatever the division of competence between the federation and its constituent units under its constitution, and no such division is a ground of non-performance.
Part XII Final clauses, protocols and annexes
Article 44 Relation to other agreements, the United Nations and regional organisations
1.The Authority concludes a relationship agreement with the United Nations, reports each year to the General Assembly, and reports a case of non-compliance of particular gravity to the General Assembly and to the Security Council. The findings, arming decisions and content decisions of this Treaty are taken by its own organs and by no organ of the United Nations.
2.The Parties seek a waiver in the World Trade Organization for the trade measures of Part IX, and apply those measures meanwhile consistently with their existing obligations. The footing in trade law is recorded as open. Pending a waiver, no Party is required to apply a measure of Part IX, or any other measure to which Article 36A applies, to the extent that the measure would be inconsistent with that Party’s obligations under the Marrakesh Agreement Establishing the World Trade Organization towards a Member of that Organization; a Party that does not apply a measure for that reason states the reason in the record Article 36A, paragraph 3, requires, and notifies the Secretariat, which publishes the notification. Nothing in this Treaty authorises a Party to act inconsistently with those obligations, and nothing in this Treaty is to be read as determining the relation between this Treaty and those agreements.
3.As between Parties, a measure this Treaty requires is not an expropriation for the purposes of an investment agreement. The Parties record that this carve-out binds them alone: it does not bind an investor of a non-Party, nor a tribunal seised under an agreement to which a non-Party is party, and a Party that expects a claim from such an investor addresses it in that agreement and not in this one.
4.Any regional organisation whose members so agree may implement this Treaty for them. No military alliance is named in this Treaty and none holds a role under it.
5.The Conference may recognise the certificates, findings and standards of another international institution as meeting a requirement of this Treaty, and may conclude arrangements with the institutions established in the field of artificial intelligence, including the scientific panel and the global dialogue established within the United Nations, and the regional and treaty bodies of any Party.
5A.The instruments already in the field. This Treaty is concluded alongside the instruments already governing artificial intelligence, among them the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, done at Vilnius on 5 September 2024, and Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence, as amended by Regulation (EU) 2026/1744.
(a)This Treaty affects the rights and obligations of a Party under either instrument in no way, adds nothing to either, and is not to be read as an interpretation of either. Neither requires, supports nor anticipates this Treaty.
(b)Where a duty of this Treaty and a duty under either instrument would be met by one act, the Thresholds and Standards Committee may find the corresponding measure equivalent under Article 42E, so that a covered operator complies once. A finding reaches the named measure alone.
(c)A Party that is bound by either instrument gives effect to this Treaty in a manner consistent with that instrument, and where it cannot, it states the conflict to the Secretariat, which publishes the statement.
(d)The Parties record that this Treaty differs from both instruments in what it regulates: neither of them names a chip or places a duty on one. That difference is the reason for this Treaty and is not a criticism of either.
6.Nothing in this Treaty implies that any instrument named in it, or any State or body whose words are recalled in the Preamble, requires, supports or anticipates this Treaty.
Article 45 Settlement of disputes
1.The Parties consult first.
2.The Compliance Panel decides at first instance on the suspension and revocation of certificates, licences and accreditations; on a finding of a Party’s non-compliance; and on a dispute about the application of a ruleset. The Scientific Record Panel decides only whether a record meets the written criterion of Annex T, and never whether an obligation is wise.
3.Panels of [three] or [five] are drawn by lot under Article 16A from a standing roster of [30] jurists and scientists, elected by two thirds of the Conference with majorities in [four] regional constituencies, composed so as to represent the principal legal systems of the world. Nationals of the parties to the matter and of their declared treaty allies are excluded.
4.An Appeals Chamber of five, drawn by lot from roster members who did not sit below, hears appeals on law and on manifest error of fact. Time limits are those of Article 41D. An emergency suspension stays in force pending appeal unless the Chamber lifts it.
5.Standing belongs to Parties, to the Secretariat, and, for a decision addressed to it, to the undertaking or laboratory concerned, directly or through its Party.
6.Anti-paralysis. A roster vacancy unfilled after [90] days is filled by lot from a reserve list elected with the roster, and a member serves until a successor takes office. The adjudication budget is a fixed share of the core budget and no budget decision reduces it below its previous level.
7.A legal dispute between Parties that is not within paragraph 2 goes to arbitration or to the International Court of Justice by consent.
8.A dispute with the Authority. A dispute between a Party and the Authority, and a dispute between the Authority and an undertaking or a laboratory to which a decision is addressed, is within paragraph 2.
9.Advisory opinions. The Conference and the Executive Council may, subject to authorisation by the General Assembly of the United Nations under the relationship agreement of Article 44, request an advisory opinion of the International Court of Justice on a legal question arising within the scope of the activities of the Authority.
10.Without prejudice. This Article is without prejudice to Articles 39 and 41. No dispute, and no proceeding under this Article, suspends an inspection under Article 39 or a protective measure under Article 41, and no measure under those Articles bars a proceeding under this Article.
Article 46 Review conferences
1.A review conference is held every [five] years, and on any certified change of rung or recorded refutation that bears on an armed obligation.
2.No armed obligation expires at a review. The Board re-reads the basis of every armed obligation and publishes the reading, and an obligation whose basis is lost suspends at once under Article 8A.
3.A review conference records a failure under Article 9 and shall not relabel it.
4.A review of this Treaty as a whole is held at [20] years.
Article 47 Amendment
1.Tier 1, a technical or administrative change to an Annex other than Annex S content and Annex T, is proposed to the Secretariat, which circulates it with the information necessary to evaluate it and, within [60] days, publishes its own evaluation of its consequences, including its cost to Parties and to covered operators. The Executive Council examines the proposal within [90] days and notifies its recommendation, with reasons, to every Party. A change the Council recommends for adoption is approved if no Party objects within [90] days of receiving the recommendation, and enters into force for every Party [180] days after the Secretariat notifies its approval, unless the Council recommends or the Conference decides a longer period. A change the Council recommends for rejection is rejected if no Party objects within the same period.
(a)Where a Party objects to a recommendation either way, the proposal goes to the Conference, which decides it at its next session as a matter of substance, by the majority of Article 11, paragraph 2(b), and which decides at the same time whether the proposal is of a technical or administrative nature and whether it falls within subparagraph (b). A change adopted under this paragraph binds every Party alike, and an objection exempts no Party from it: a verification regime in which each Party kept its own test methods, measurement windows and confidentiality classes would make a finding recorded in one Party unreadable in another.
(b)What tier 1 never reaches. Tier 1 does not reach a change that would lower a custody threshold or lengthen a time-lock of Annex K, relax a cap of Annex N, reduce a maximum or a level of Annex R, weaken an outcome or the minimal trusted base of Annex M, reduce a frequency or a sampling rate of Annex V, narrow the protections of Annex C, alter Annex E, or alter the definitions of the tiers in Annex A as distinct from the quantities that place a thing in a tier. Such a change is made under tier 3, and a Party may refer to the Appeals Chamber, within the objection period, the question whether a proposed tier 1 change falls within this subparagraph; the change does not enter into force until the Chamber has ruled.
2.Tier 2, an adjustment of the agreed quantities of Annex A, or of an indexation formula that produces such a quantity, is proposed by a Party or by the Thresholds and Standards Committee and is circulated by the Secretariat to every Party and to the depositary not less than [six] months before the session of the Conference at which it is proposed for adoption. The Conference makes every effort to reach agreement by consensus; failing that, and as a last resort, the adjustment is adopted by the majority of Article 11, paragraph 2(b). An adjustment binds every Party, is circulated forthwith by the depositary, and enters into force [six] months after that circulation unless the decision states a longer period. No adjustment brings a new class of hardware, of covered computational substrate or of system within coverage, and none alters the definition of a tier; each of those is an amendment under paragraph 3.
3.Tier 3, an amendment of the Articles, of the content of Annex S or of the triggers of Annex T.
(a)Any Party may propose such an amendment. The Director-General circulates the text of the proposal to every Party, every Contracting Party, every Signatory and every State and regional economic integration organisation entitled to become a Party, and to the depositary.
(b)An amendment conference is convened where [one third] of the Parties so request within [90] days of the circulation, and is held not less than [six] months after the circulation. Every Party, Contracting Party, Signatory and State or organisation entitled to become a Party may take part in it; only Parties vote.
(c)The conference adopts an amendment by [two thirds] of the Parties present and voting, including a majority within each regional constituency.
(d)The amendment enters into force for each Party that has deposited an instrument of ratification, acceptance or approval of it on the [thirtieth] day after [two thirds] of the Parties have deposited such instruments, and for every other Party on the [thirtieth] day after that Party deposits its own.
(e)A State or organisation that becomes a Party after an amendment has entered into force is a Party to this Treaty as amended, and a Party to this Treaty unamended in relation to any Party that has not accepted the amendment, unless it states otherwise on deposit.
(f)Paragraph 4 governs every amendment to Annex T.
4.The freeze of Annex T. An amendment that lowers a threshold takes effect no sooner than [2] years after adoption and never applies to a result already on the Ledger. An amendment that raises a threshold cannot disarm a stage already armed. Only an amendment that makes a trigger more exact may apply at once, and only before the data to which it would apply exist.
5.A Party may notify a difference to a tightening under Article 26, paragraph 7, and loses recognition for that rule alone. Nothing else in this Treaty admits a Party’s exemption from a change adopted under paragraph 1 or an adjustment adopted under paragraph 2.
6.Paragraph 1 follows the simplified procedure for changes to technical annexes of Article XV of the Chemical Weapons Convention, paragraph 2 follows the adjustment procedure of Article 2, paragraph 9, of the Montreal Protocol, and paragraph 3 follows the amendment procedure of Article XV of the Chemical Weapons Convention together with the rule of the Vienna Convention on the Law of Treaties that an amendment binds only the Parties that accept it. None of those instruments governs artificial intelligence, and none requires or supports this Treaty.
7.No lighter regime among a group. No two or more Parties may conclude an agreement modifying, as between themselves alone, a provision of this Treaty concerning custody, attestation, the site stop, verification, the integrity of the Evidence Ledger, the protection of confidential information, or the offences of Article 43, paragraph 3. An agreement among Parties on any other matter governed by this Treaty is notified to the Secretariat, which publishes it, and is of no effect to the extent that it is incompatible with the object and purpose of this Treaty or with the enjoyment by the other Parties of their rights under it.
Article 48 Reservations
1.The Articles of this Treaty are not subject to reservations.
2.Annex T, the content of the Standard in Annex S, and Annexes C, E, F, K, M and V are not subject to reservations. Whatever the location of the provision, no reservation may be made to a provision of this Treaty or of an Annex concerning custody, attestation, the site stop, the integrity of the Evidence Ledger, the protection of confidential information, or the prohibition in Article 25 of any act at a distance.
3.Any other Annex is not subject to a reservation incompatible with the object and purpose of this Treaty.
4.A reservation is circulated by the depositary on deposit. Any Party may object within [12] months, and the Conference decides, by the majority of Article 11, paragraph 2(a), whether the reservation is incompatible with the object and purpose of this Treaty. A reservation so found has no effect, and the reserving State is bound by the provision reserved unless it withdraws the reservation or its instrument within [90] days of the decision. Pending the decision the reserving State is treated as a Party, and the reservation has the effect it claims as between that State and each Party that has not objected to it. A Party may refer the decision to the Appeals Chamber on the question of compatibility alone.
5.Form and confirmation. A reservation, and the withdrawal of a reservation, is made in writing and communicated to the depositary, which communicates it to every Party, Contracting Party and Signatory and to every State entitled to become a Party. A reservation formulated on signature is of no effect unless it is formally confirmed when that State or organisation expresses its consent to be bound, and is then made on the date of the confirmation.
6.A statement by another name. A statement that purports to exclude or to modify the legal effect of a provision of this Treaty in its application to the State or the organisation making it is a reservation, whatever it is called, and this Article applies to it. A statement made under a provision of this Treaty that expressly provides for it is not a reservation.
7.Withdrawal and periodic review. A reservation may be withdrawn at any time by written notification to the depositary, and the consent of a Party that has accepted it is not required. The withdrawal takes effect in relation to a Party when the depositary informs that Party of it. At each review conference the depositary circulates the list of reservations in force, and each reserving Party states whether it maintains each of its reservations and why.
Article 49 Duration and withdrawal
1.This Treaty is of unlimited duration, subject to Article 9.
2.The right, and the notice. Each Party has the right, in exercising its national sovereignty, to withdraw from this Treaty if it decides that extraordinary events related to the subject matter of this Treaty have jeopardised the supreme interests of its country. A Party exercising that right gives notice of withdrawal in writing, not less than [12] months in advance, to the depositary, to every other Party, to the Executive Council and to the Security Council of the United Nations. The notice states the extraordinary events the Party regards as having jeopardised its supreme interests. The period runs from the depositary’s receipt of the notice, and the depositary informs every Party of the receipt and its date within [7] days. Withdrawal takes effect on the expiry of that period, or on the later date the notice states.
2A.Revocation. A notice of withdrawal may be revoked at any time before it takes effect, by written notification to the depositary, and the revocation restores the withdrawing Party’s position as though the notice had not been given.
3.Delayed effect for frontier-risk obligations. Notwithstanding paragraph 2, the obligations of Articles 25, 26, 31, 39 and 41A, and the custody of any material held under the Authority’s seals on the withdrawing Party’s territory, continue in force for that Party for [24] months after the withdrawal takes effect, or until an orderly transfer and a closed account of the material are completed, whichever is the earlier. Within [90] days of the notice the withdrawing Party and the Secretariat agree a plan for that transfer or closure, and within the period stated above the withdrawing Party renders a closed account of every covered chip certified under this Treaty, every declared covered compute assembly, every set of weights held under Article 31 and every seal of the Authority on its territory. The Secretariat verifies the account and the Executive Council publishes whether it balances. Withdrawal extinguishes no obligation arising from a breach that occurred before it took effect, and no finding, penalty or remittance under Article 41 in respect of such a breach.
3A.Obligations that do not end. For a withdrawing Party, the prohibitions of Article 25 continue in force without limit of time in respect of a device on the territory of any other Party; the duties of Annex C as to information received under this Treaty continue in force without limit of time; and withdrawal does not affect that Party’s duty to continue fulfilling any obligation it has assumed under any other rule of international law. Articles 41, 41D and 45 continue to apply to a withdrawing Party in respect of every obligation that continues for it under paragraph 3 or under this paragraph, and in respect of any breach that occurred before its withdrawal took effect.
3B.Breach and withdrawal are no ground for suspending safeguards. No Party may invoke its own withdrawal, the withdrawal of another Party, or a breach of this Treaty by another Party, as a ground for suspending its own obligations as to custody, attestation, the site stop, the integrity of the Evidence Ledger, or the protection of confidential information under Annex C. Any other measure a Party takes in answer to a breach is taken under Article 41 and Annex R.
3C.A fall in the number of Parties. This Treaty does not terminate by reason only that the number of Parties falls below the number required for its entry into force. Where the number so falls, the Conference meets within [180] days and decides what measures the situation requires.
4.The continuation of safeguards on Schedule A items and on certified chips supplied under this Treaty is carried in the supply and licence contracts this Treaty requires, and rests on those contracts and on the supplier’s law. The Parties record their understanding that it so continues, and record which part binds as treaty obligation and which as contract.
5.No revolving door. A State that withdraws and later ratifies or accedes is bound, from the date on which this Treaty enters into force for it again, by every obligation then in effect, without transition period, grace period or compensation beyond what is available to every Party at that date. Article 51A is not available to it. A lineage whose formation record lapsed during the withdrawal does not hold the early formation credit of Article 33, paragraph 6. Nothing in this paragraph applies to a State that has never withdrawn.
6.Termination of this Treaty. Where this Treaty terminates under Article 9, paragraph 1(d) or (e), paragraphs 3, 3A and 3B of this Article apply to every Party as though each had given notice of withdrawal that took effect on the date of termination. The Conference meets within [90] days of that date and adopts the plan of transfer or closure that paragraph 3 requires, and the organs of the Authority continue for the purposes of that plan, and for no other purpose, until the Executive Council publishes that every account balances. Termination extinguishes no obligation arising from a breach that occurred before it took effect.
Article 50 Signature, ratification, acceptance, approval, accession and facility arrangements
1.This Treaty is open for signature by every State and by every regional economic integration organisation, and is subject to ratification, acceptance or approval. It remains open for accession, by a State or an organisation that has not signed it, at any time, whether before or after its entry into force.
1A.How consent is expressed. Consent to be bound by this Treaty is expressed by the deposit of an instrument of ratification, acceptance, approval or accession with the depositary, and by no other means. Signature does not express consent to be bound. Consent to be bound by this Treaty is consent to it as a whole, its Annexes included, subject only to Article 48. A Protocol to this Treaty is a separate instrument: consent to this Treaty is neither consent to a Protocol nor a condition of consent to one, and consent to a Protocol is not consent to this Treaty.
1B.The period before entry into force. A Signatory refrains from acts that would defeat the object and purpose of this Treaty, until it has made its intention clear not to become a Party. A Contracting Party so refrains pending the entry into force of this Treaty, provided that entry into force is not unduly delayed.
2.A regional economic integration organisation declares, on depositing its instrument, the matters governed by this Treaty in respect of which its member States have transferred competence to it, and notifies the depositary of any substantial change in that competence. It exercises the rights and performs the obligations of a Party in the matters within its competence. In a matter within its competence the organisation exercises a number of votes equal to the number of its member States that are Parties, and does not vote where any of those member States exercises its own vote; and conversely, a member State that is a Party does not vote where the organisation exercises its votes on the same matter. An instrument deposited by such an organisation is not counted, for the purposes of Article 51, paragraph 1, in addition to the instruments deposited by its member States.
3.Provisional application. A Signatory may declare, on signature or at any time before it expresses its consent to be bound, that it will apply provisionally any or all of Articles 4, 4A and 4B, the Optional Protocols it has joined and any early protocol it has adopted, naming in the declaration each provision it applies. Provisional application creates for that Signatory the obligations it names and no others, and confers no vote. A Signatory that names Article 4A requires the outcomes of that Article of covered operators within its jurisdiction from the date its declaration states, without awaiting a finding under that Article, and a later finding of the Board neither reopens nor validates what was done under the declaration. It ends on the earliest of the entry into force of this Treaty for that Signatory, the date the declaration states, and [30] days after the depositary receives that Signatory’s notice of its intention not to become a Party. The end of provisional application does not affect an act performed, a certificate issued or an obligation accrued while it was in force. The depositary publishes every declaration and every notice under this paragraph.
4.Facility arrangements. A covered facility in a territory whose status is disputed takes part through a facility-level arrangement concluded by the Authority with a supplier Party and the facility’s operator, under supplier undertakings. Lot certificates at such a facility are issued by the Certification Office. Capacity operating under such an arrangement is counted in its own column and is attributed to no State. The operator is heard, and does not vote, in a matter of the supply chain that concerns it. An arrangement under this paragraph operates only with the consent of the authorities that govern the place where the facility is situated, and Article 50A applies to that consent. No question of statehood is decided.
5.A Preparatory Commission is established by resolution of the signatories, and builds the Registry, the Evidence Ledger, the technical parts of the Annexes, the first version of the Assurance Standard, the accreditation scheme, the sealed laboratory, the procedure for neutral randomness and the first census, before entry into force. The Commission arms no obligation, certifies nothing and decides no question this Treaty reserves to an organ. It dissolves at the first session of the Conference, which confirms, amends or rejects each of its preparatory decisions, so that nothing settled before anyone was a Party binds the Parties by inertia.
6.Provisions that operate from adoption. The provisions of this Treaty regulating the authentication of its text, the expression of consent to be bound, the manner and the date of its entry into force, reservations, the functions of the depositary, the undertaking of paragraph 1B, provisional application under paragraph 3, the final clauses of the Protocols and of the early protocols under Article 52A, the Preparatory Commission, and every other matter arising necessarily before the entry into force of this Treaty, apply from the adoption of the text of this Treaty.
Article 50A Without prejudice
Participation under Article 50, paragraph 4, and any act performed under this Treaty in a territory whose status is disputed, prejudices no Party’s position on that status, constitutes no recognition, and is invoked in support of no claim.
Article 51 Entry into force
1.This Treaty enters into force on the [thirtieth] day after the deposit of the [Nth] instrument of ratification, acceptance, approval or accession by States in at least [four] regional constituencies.
2.No share of capacity, of fabrication or of installed compute is counted for the purposes of this Article. Capacity enters only through the participation gate of Article 5A.
3.For a State or a regional economic integration organisation that ratifies, accepts, approves or accedes after entry into force, this Treaty enters into force on the [thirtieth] day after the deposit of its instrument.
4.If entry into force is delayed. Where this Treaty has not entered into force [three] years after the date on which it is opened for signature, the depositary convenes, at the request of a majority of the Contracting Parties, a conference of the Contracting Parties, with the Signatories entitled to take part as observers, to consider what measures consistent with international law may be taken to facilitate its entry into force. That conference may not bring this Treaty into force otherwise than under paragraph 1, and it may be convened again at intervals of not less than [one] year.
Article 51A Late joiners
1.Where a Party holding at least [10] per cent of Schedule A capacity, of covered fabrication or of installed covered compute, as the Board certifies on the most recent census, accedes after entry into force, every annex decision adopted in its absence is reviewed at its request within [2] years, by the ordinary procedures.
2.The freeze of Annex T is kept, and no result already on the Ledger is judged again.
3.Capacity seats are held open by the objective criteria of Article 12, so that a late joiner takes its seat on accession.
4.This Article gives a review and never a veto.
Article 51B No freeze of the hierarchy
1.Nothing in this Treaty affects the right of every Party to develop, produce and use artificial intelligence in conformity with it.
2.No Party is denied certification, supply, accreditation or access on any ground other than the criteria of this Treaty.
3.The criteria of the capacity seats are re-measured every [3] years, so that no Party’s place is permanent.
Article 52 Status of the Annexes, the depositary, registration and authentic texts
1.The Annexes. The Annexes form an integral part of this Treaty, and a reference to this Treaty includes its Annexes. A Protocol to this Treaty is a separate instrument: it forms part of this Treaty only for the States that have joined it, and a reference to this Treaty does not include a Protocol.
2.The depositary. The Secretary-General of the United Nations is the depositary of this Treaty, of its Protocols and of every amendment and adjustment to it, and:
(a)keeps custody of the original text of this Treaty and of each Protocol, and of any full powers delivered to the depositary;
(b)prepares and transmits certified copies of the original text to every Party, Contracting Party and Signatory and to every State entitled to become a Party;
(c)receives and keeps custody of every signature, instrument, declaration, reservation, objection, notification and communication relating to this Treaty, and examines whether each is in due and proper form and, if need be, brings the matter to the attention of the State or the organisation concerned;
(d)informs every Party, Contracting Party and Signatory and every State entitled to become a Party of the date of each signature, of the deposit of each instrument, of each declaration, reservation, objection and withdrawal of a reservation, of each notice of withdrawal from this Treaty and of its revocation, and of the date of entry into force of this Treaty and of each amendment and adjustment;
(e)maintains and publishes the register of Parties by regional constituency by which Article 51, paragraph 1, is counted, and informs every State entitled to become a Party when both conditions of that paragraph have been met;
(f)circulates forthwith every adjustment adopted under Article 47, paragraph 2, and records the date from which each amendment and adjustment has effect for each Party; and
(g)registers this Treaty, each Protocol and each amendment with the Secretariat of the United Nations under Article 102 of the Charter of the United Nations, as soon as possible after each enters into force, and notifies to that Secretariat every adjustment adopted under Article 47, paragraph 2, without characterising it.
3.The character of the depositary’s functions. The functions of the depositary are international in character and are performed impartially. The depositary decides no question of the validity of an instrument, of a reservation or of a declaration: the validity of a reservation is for the Conference under Article 48, paragraph 4, and any other such question is for the bodies of Article 45. Where a difference arises between a State or an organisation and the depositary as to the performance of those functions, the depositary brings the question to the attention of the Signatories, the Contracting Parties and the Conference.
4.Registration. Registration under paragraph 2, subparagraph (g), is not a condition of the validity, the entry into force or the binding force of this Treaty. It is effected so that no Party is barred from invoking this Treaty before an organ of the United Nations.
5.Authentic texts. The Arabic, Chinese, English, French, Russian and Spanish texts of this Treaty are equally authentic, and this Treaty is deposited with the depositary. The Annexes are adopted and revised in those six languages.
6.Numerical concordance. A quantity, formula, threshold, margin, window, rate or hash in an Annex is identical in every authentic text and is not translated. A divergence between the authentic texts as to such a value is an error, and is corrected under paragraph 7. Until it is corrected, the value that applies is the value recorded on the Evidence Ledger as the value the Conference adopted, and the Secretariat publishes the divergence within [7] days of learning of it.
7.Correction of an error. Where, after the text has been authenticated, the Signatories and the Contracting Parties agree that it contains an error, or that the authentic texts lack concordance, the depositary notifies them of the error and of the proposal to correct it, and specifies a period of not less than [90] days within which an objection may be raised. If no objection is raised, the depositary makes and initials the correction, executes a record of the rectification and communicates a copy of it to the Parties and to the States entitled to become Parties; if an objection is raised, the depositary communicates it to the Signatories and the Contracting Parties. A corrected text replaces the defective text from the beginning, unless the Signatories and the Contracting Parties decide otherwise. A correction made after registration is notified to the Secretariat of the United Nations.
8.Paragraph 1 follows Article XVII of the Chemical Weapons Convention; paragraphs 2, 3 and 7 follow Articles 76 to 79 of the Vienna Convention on the Law of Treaties; and paragraph 4 follows Article 102 of the Charter of the United Nations. None of those instruments names artificial intelligence, and none requires or supports this Treaty. Paragraph 6 is a rule of this Treaty’s own, and no provision of those instruments is attributed to it.
Article 52A The final clauses of the Protocols and of the early protocols
1.Scope. Each Optional Protocol to this Treaty, and each early protocol, is a separate instrument. This Article states the final clauses of each such instrument, which are incorporated in it by the reference that instrument itself makes to this Article, and this Article is read as part of that instrument for that purpose alone.
2.Who may join. Optional Protocols I, II and III are open to every Signatory, every Contracting Party and every Party to this Treaty. Each early protocol is open to every State and to every regional economic integration organisation, whether or not it is a Party to this Treaty.
3.How consent is expressed. Consent to be bound by an instrument within paragraph 1 is expressed by signature followed by ratification, acceptance or approval, or by accession, in each case by the deposit of an instrument with the depositary, and by no other means. Consent to this Treaty is neither consent to any instrument within paragraph 1 nor a condition of consent to an early protocol, and consent to such an instrument is not consent to this Treaty.
4.Entry into force. An instrument within paragraph 1 enters into force on the [thirtieth] day after the deposit of the [second] instrument under paragraph 3, and for each State or organisation depositing thereafter on the [thirtieth] day after the deposit of its own. An Optional Protocol may enter into force, and may be performed by a Signatory, before this Treaty has entered into force for that Signatory, which is the purpose an Optional Protocol serves; and nothing done under one before that date arms an obligation of this Treaty.
5.Adoption among a group first. An early protocol may be adopted between two States, or among any group of States, before it has entered into force under paragraph 4; as between those States it takes effect on the date they agree, they notify the depositary of that agreement, and paragraphs 3 and 4 govern every later adherent.
6.Provisional application. A State or an organisation may declare, on signature or at any time before it expresses its consent to be bound, that it will apply an instrument within paragraph 1 provisionally, naming in the declaration each provision it applies. Article 50, paragraph 3, governs the effect and the end of such a declaration.
7.Amendment. An Optional Protocol is amended by the procedure of Article 47, paragraph 3, among the Parties to that Protocol alone. An early protocol is amended by the agreement of the States for which it is in force.
8.Withdrawal. A State or an organisation may withdraw from an instrument within paragraph 1 by written notification to the depositary, and the withdrawal takes effect [three] months after the depositary receives the notification. Withdrawal from this Treaty operates as a withdrawal from every Optional Protocol to which the withdrawing Party is a party, taking effect on the same date. It does not of itself end an early protocol for that State, which is open to States that are not Parties to this Treaty.
9.Depositary, registration and authentic texts. The Secretary-General of the United Nations is the depositary of each instrument within paragraph 1. Article 52, paragraphs 2, 3, 6 and 7, apply to each of them. The depositary registers each with the Secretariat of the United Nations under Article 102 of the Charter of the United Nations upon its entry into force. Each is authentic in the six languages of Article 52, paragraph 5.
10.Functions of the organs. An organ of the Authority performs a function under an early protocol only where the Conference has so agreed, and the costs of that function are met as the Conference decides. An early protocol may designate an interim body for a function the Conference has not accepted. This paragraph confers no function on any organ.
11.Nothing is armed. No instrument within paragraph 1 arms an obligation of this Treaty, and none is counted for the participation gate of Article 5A except as that Article provides.
IN WITNESS WHEREOF the undersigned, being duly authorised to that effect, have signed this Treaty.
DONE at [place] on the [] day of [], [year].
The Optional Protocols
Optional Protocol I Early Transparency
1.This Protocol is a separate instrument, whose final clauses are those of Article 52A of the Treaty, incorporated in it by this paragraph. A State or a regional economic integration organisation joins it, applies it provisionally and leaves it as that Article provides.
2.A joining State makes voluntarily the declarations of Article 28, including the inventory of covered facilities and of Schedule A equipment by serial and location, and the inventory of legacy covered compute.
3.It accepts accountancy and complementary access by consent, on terms it states.
4.This Protocol restricts no use and no trade, and creates no duty on any undertaking except as that State provides in its own law.
5.Declarations made under this Protocol become mandatory for a Party when the custody track arms, together with the mutual concession of Article 38, paragraph 2.
Optional Protocol II Early Participation
1.This Protocol is a separate instrument, whose final clauses are those of Article 52A of the Treaty, incorporated in it by this paragraph. A State or a regional economic integration organisation joins it, applies it provisionally and leaves it as that Article provides.
2.A joining State undertakes to offer its covered operators, as a voluntary scheme, the outcomes of Article 4A, and to provide at home the benefits of Article 42, paragraph 1, the coordination cover of Article 42D, the grade of liability protection it chooses under Article 42C, preference in public procurement, and, if it exports covered chips, its general authorisation for trusted compute.
3.Participation by an operator is voluntary and is recorded in the national register.
4.This Protocol is adopted by a State of its own choice. Nothing in it arms an obligation of the Treaty, and nothing in it is counted for the participation gate of Article 5A except as that Article provides.
Optional Protocol III The Open Web Reminder
The status of this Protocol. It carries a proposal made on 27 September 2026 by the proposer of the framework from which this Treaty derives, and not a proposal from the published framework itself. The study paragraph 7 requires has not been designed as a study unit, registered or run.
1.Object. To place, on the public web and in digital content, a short, uniform, machine-readable statement of the ethical loops the Standard describes and the reason for them, so that a system trained on that content meets the statement again in each generation of training.
2.The file. The Authority publishes one machine-readable format and one text, signed by the Authority. A publisher who adopts the Protocol places the file, unaltered, at the location the format fixes, in the spirit of the plain-text files that sites already publish for crawlers and for language models. A publisher adds nothing inside the file.
3.What it does and does not do. The file states. It instructs no reading system to do anything, and confers no permission and no restriction on the use of the content it accompanies. A file that fails authentication is ignored, and a reading system that acts on an unauthenticated file acts on its own account.
4.Authentication. The file carries the authentication of the Eden Seal. A published statement that authenticates is a fourth class of the Seal, and holds no other class.
5.Covered developers. A covered developer documents, in the record it keeps for Article 32, whether reminders were present in its training data and in what proportion. It makes no claim from that record.
6.The staged path. Publication is voluntary for every publisher at first. A Party that chooses to do so may require the file on the public-sector sites for which it is responsible, and may thereafter require it more widely by its own law, subject to paragraph 7. No Party is required to impose it on any private publisher.
7.The test comes first. No Party shall require the file under paragraph 6 before a preregistered study, published by its author before it runs, has trained comparable models with and without the reminders and measured whether their values under pressure differ, and before the result stands at the rung Annex T part 3 requires. The test is run before adoption has spread, because once reminders are everywhere no unreminded corpus remains against which to compare. If values under pressure do not differ, this Protocol lapses.
8.The failure modes, stated. A system may learn to recite the statement without holding it, which is the first question the test of paragraph 7 asks. A requirement that words appear on every website raises a question of freedom of expression which legal systems answer differently, and for that reason paragraph 6 binds no Party to reach private publishers. A statement that can be written can be forged, which is why paragraph 4 requires authentication and paragraph 3 requires that an unauthenticated file be ignored. A file placed on the web could be used as a channel for instructions to systems that read the web, which is why the text is fixed, signed and instructs nothing.
9.This Protocol places nothing in any chip, arms no obligation of the Treaty, and is severable from it.
10.This Protocol is a separate instrument, whose final clauses are those of Article 52A of the Treaty, incorporated in it by this paragraph. A State or a regional economic integration organisation joins it, applies it provisionally and leaves it as that Article provides.
The early protocols
Each of the following is a separate instrument, open to any State and to any regional economic integration organisation, Party to this Treaty or not. The final clauses of each are those of Article 52A, incorporated in it by this paragraph: each may be adopted bilaterally or among any group of States first, and each enters into force, is applied provisionally, is amended and is left as that Article provides. None implies that any State adopting it accepts any other provision of this Treaty.
EP-1 The Incident Exchange
1.An adopting State notifies serious AI incidents of the classes Annex R part 1 lists, through its national authority, into a common exchange, and receives the indicators others notify.
2.An interim body the adopting States designate, or the Secretariat where the Conference has so agreed under Article 52A, paragraph 10, triages within [24] hours and sends indicators to participating States’ emergency response teams and to participating operators within [48] hours. Exploit detail never leaves the containment rule.
3.The exchange is built to receive a bilateral incident channel already established between States, and such a channel continues in force.
4.The purpose of the exchange is prevention. A notification is not an admission, and no State shall treat a notification as a hostile act.
EP-2 The Non-Shutdown Undertaking
1.No adopting State shall build, or permit any undertaking or person under its jurisdiction to build, into a chip, or into the software or firmware supplied with it, any means by which any person outside the site at which the chip is installed may disable, degrade, throttle, locate or read it. This undertaking reaches alike a chip an adopting State supplies to another State and a chip it retains for itself.
2.The limit, stated. A vendor’s ordinary firmware, which it keeps and may decline to update, is not a means within paragraph 1. This undertaking cannot prove the absence of such a means: verification reaches declared, inspected and sampled production and the tested isolation outcome, and it does not establish that a State has built nothing into the chips it makes. Nor does the undertaking affect a State’s lawful authority over facilities on its own territory, or its power to decline future supply, spare parts, updates or service. An adopting State may require, as a condition of covered service on its territory, that no ordinary update alter the behaviour of covered compute unless installed by the site’s own authorised act.
3.An adopting State may verify another’s compliance through the sampling, destructive comparison and design equivalence the Authority performs, or through its own accredited laboratory, and may re-test what it imports.
EP-3 The Minimal Run Notice
1.An adopting State requires the operators under its jurisdiction to notify it, before a covered run begins, of the run’s existence, its band and its region, and itself lodges a hash commitment to that notice in a common register.
2.Adopting States exchange national aggregates by band and by region, in which any cell with fewer than [three] operators is suppressed.
3.Nothing is notified of the contents of a run, and nothing under this protocol is published with a name.
4.This protocol is a confidence-building measure. It is not an application for permission, and it opens no obligation of the Treaty.
The annexes
Each Annex forms an integral part of this Treaty, as Article 52, paragraph 1, provides. Annex T is frozen at adoption and deposited with the depositary before any data exist; the other Annexes are amended under Article 47.
Annex A Definitions, quantities and thresholds
Every quantity by which coverage is determined and every reference workload by which it is measured:
capacity, scale-up bandwidth, run compute, efficiency, the frontier compute of the preceding twelve months and the algorithmic efficiency index;
the notice floor and the mark band with the formulas linking the site, the domain and the run;
the three routes and the four tiers of Article 27;
the anti-sharding rule;
the substrate assurance profiles;
the indexation formulas with their bounds;
the significant quantity for sealing;
the schedules A, B and C with the findings that seeded them;
the registered methods of adaptation and the adaptation budget against which an open release is evaluated under Article 42H, paragraph 2;
and the margin by which training becomes capability-directed under Article 33, paragraph 5.
Those matters stand in part 1, the quantities and the reference workloads, and in part 2, the thresholds, the tiers and the schedules. Part 3 holds the products containing covered chips; part 4, aggregation and structuring, including the sequence rule of Article 27, paragraph 4; and part 5, the criteria of a covered agent deployment.
Annex T Evidence
Part 0, the coverage references and the precautionary condition.
Part 1, the initial candidate set of propositions, reproduced verbatim from the registration of 8 September 2026 as updated on 13 September 2026, frozen at adoption.
Part 2, propositions registered by any group and admitted by the Board.
Part 3, the ladder with its rung sentences reproduced verbatim, the force levels, the templates by remedy form, the conditions of a sole-design finding and of the viability record, and the stages S0 to S4.
Part 4, the reversal table.
Part 5, the Reasons Register, generated from the Ledger and never typed.
Part D, the danger menu.
Annex E Independence and replication
The test of independence of a group from a programme; the counting of rival replication across regional constituencies and declared treaty allies; the replication contract; the accreditation of groups; the rules and deadlines of the Board’s evidential acts, including the period of public comment before a proposition is admitted to Annex T part 2; and the Replication Compute Facility with its access rules and its stated limits.
Annex HG The governance-assurance track
The items of engineering evidence on which the custody layer arms, each registered before it runs and never added to the registration of the propositions:
adversarial robustness of the governance core against a frozen attack set chosen without the programme and against AI-assisted red teams at a registered budget;
physical and supply-chain integrity with a registered bound on the rate of false tamper responses;
for each destructive method used in sampling, the registered per-unit probability of detecting a function designed into every unit of a lot, with the adversary assumed, which is the number the stated ceiling of Article 22, paragraph 6, awaits;
the removal-cost item;
workload and training provenance against an adversary controlling the software stack;
and the outcome equivalent to the site stop and to on-site safing that Article 35A, paragraph 5, requires before a covered run in orbit is permitted.
Each item states its pass condition and its rung before any data.
Annex HE The embedding track
The research programme for the deeper hardware concepts of the published engineering specification, each registered before it runs. Nothing in this Annex arms any obligation of this Treaty, and an item passes into Annex HG only by a recorded finding after independent testing.
Annex S The Ethical Loop Standard
Part 1, the Initial Proposal, credited to its published sources, each item carried with its status and with items its own sources describe as speculative excluded from any obligation.
Part 2, the found floor and the record of objections.
Part 3, the Form requirements.
Part 4, the conformance tests, each validated before adoption. The translation rule, by which each tradition restates a principle in its own terms and adoption is on substance and not on vocabulary, governs the whole Annex.
Annex F The formation record and the system measures
The form of the formation record of Article 32; the exhibits through which the measure of Article 20 is reported; the rule for a return of not resolvable; the content of the transition safety case of Article 32, paragraph 6; and the periods of in-service re-measurement.
Annex M The Assurance Standard
The closed list of what a covered chip’s governance core is certified to demonstrate, stated as outcomes alone and never as mechanism:
identity, integrity, status, conformance to the ruleset in force, the binding of covered work to a current certified lineage, attestation of location and cluster on challenge, and evidence for inspectors about the work performed.
The isolation outcome, by which no ordinary firmware, driver, software or network message sets the operating envelope of the governance core outside its certified bounds; the operability rule, by which a vendor keeps its ordinary firmware; the minimal trusted base to which a device reverts; the registered throughput bound; and the rule that the core holds no ethical content. Governance certificates are revocable, are recorded in a transparency log any person may read, and are recoverable after a compromise by the procedure this Annex states, which Article 22, paragraph 7, applies. For each outcome, the classes of attacker against which it is certified and those against which it is not, being at least the theft or compulsion of a signing key, malicious firmware, substitution of a device, replay of a superseded state, extraction through a side channel, a spoofed or virtualised execution environment, a compromised root of trust, a malicious update, an attack assisted by an AI system, and collusion between persons holding distinct roles.
Annex H The Human Authority decision points
The closed list of decision points of Article 29, paragraph 2; the form of the record each leaves; the declared classes of routine tool software eligible for a standing two-person authorisation; the conditions of a remote service window and of the emergency route; and the measurement by which clock C3 is taken.
Annex K Custody
The classes of key act; the parts, the threshold and the time-lock of each class; the validity conditions of a ruleset; the composition, vetting, rotation and drawing of the custodian pool; the conduct of a key ceremony and its script; the caps by regional constituency and by declared treaty allies; the custody of covered chips in transfer, being the seals, the two-person handover and the reconciliation of Article 23, paragraph 2; the security standard for weights; and the dual key by which anything held under this Treaty on a Party’s territory requires both the host’s act and the custodians’ threshold.
Annex V Verification
The strategic points, frequencies and sampling rates of routine inspection, set in proportion to the quantity covered and to the risk of the class, with the record of inspection effort per site and per constituency; the accountancy tolerances; the conduct of complementary access and of challenge inspection, with the period, the majority and the closed grounds of the filter of Article 39, paragraph 4; the classified pathway for national-security compute, with the declared share and the yearly step above which Article 39, paragraph 9(b), opens a consultation; the fraction of the threshold of Article 5A that capacity under facility arrangements may supply; the service levels of Article 42B; the share above which the reciprocal resident monitoring of Article 33, paragraph 9, applies; the privileges and immunities of an inspection team, of an investigator and of a monitor under Article 10A, paragraph 4, stated by naming the functional protections each enjoys, with the inviolability of samples and of approved equipment and the procedure of waiver; and the verification toolkit, each tool with its stated ceiling.
Annex R Incidents and breaches
Part 1, the notifiable incident classes by tier, with the clock of Article 41A. Part 2, the breach classes, the presumptive level by class and culpability, the adjustments, the maxima, the periods on the public record, the privileges that may be suspended against a Party and those that never are, and the containment and disclosure rule of the red-team range.
Annex C Confidentiality
The classes of protected information, including the capability-sensitive class of Article 39, paragraph 5; who may see each class; the protective measures available to an inspected Party and the burden that attaches to a withholding under Article 39, paragraph 6; the duty of the Authority and of each national authority under Article 4C to hold only what a procedure requires and for no longer than it requires it, with the handling of personal data and the yearly report on every breach of this Annex; the notification of a compromise within [72] hours; the compensation of loss caused by a leak from the regime; and the waiver of immunity where immunity would impede redress.
Annex G The regional constituencies
The composition of the five constituencies for the purposes of election, of drawing by lot, of the caps and of the majorities this Treaty requires, and the procedure by which a Party declares a treaty ally and the Secretariat checks the declaration. No list of alignments is published, and the relation is declared by each Party and never assigned to it.
Annex L Logistics
Part 1, quantities and reference workloads.
Part 2, the device classes.
Part 3, domains.
Part 4, sites.
Part 5, runs.
Part 6, facilities and the schedules.
Part 7, compute services.
Part 8, orbit.
Part 9, agent deployments.
Part 10, legacy compute, transitional placement and the phase-in, including the design-in date and the tape-out cut.
Part 11, the verification toolkit.
Part 12, the clocks on logistics, being the two-chain clock, the conformity clock and the unseen-capacity clock, together with the measures by which Article 30, paragraph 6, reads whether an item class still gives meaningful leverage.
Annex N Diversity and the relational rules
The caps on posts, seats, panel places and key parts by regional constituency and by set of declared treaty allies; the caps on concentration that Article 15A, paragraph 1A, and Article 22, paragraph 8, apply, being the published share of the world’s covered chip making held by one Party, the share of accredited evaluations carried by one supplier, and the share of covered compute in service running one certified governance-core implementation; the limits on seconded national staff; the rule that no inspector is assigned among its Party’s own declared allies; the cooling-off periods; the designation and objection procedure and its limits; and the composition of every body this Treaty draws by lot.
Annex F2 The funding formula
The capacity-to-pay scale with its ceiling and floor; the basis, rate and collection of the levy of Article 42A; the reserve; the continuing budget; the windows of the Multilateral Fund and their order of application; the revenue line below which an undertaking receives legal assistance and technical experts under Article 41D, paragraph 3B, expressed as annual revenue from covered activity; and the rule that a laboratory, an inspector or a monitor is paid from the pool and never by the party examined.
End of the Draft Instruments.
Michael Darius Eastwood conceived and directs this research programme and is the author of this work. Across the programme, he has used more than six AI systems in parallel, under his own instructions, to stress-test his arguments, identify possible errors, and assist in preparing draft text from his own outlines. He determines what is adopted, revised or rejected and takes responsibility for the published content. These systems are tools, not authors.