The principles every other AI regime borrows from.
The OECD AI Principles were the first intergovernmental standard on AI, and they are the quiet common denominator underneath the EU AI Act, the NIST AI Risk Management Framework and the G20 principles. They bind no one directly — and they shape almost everything that does. Here is what they say, what changed in the 2024 revision, and how to evidence alignment.
At a glance
- Adopted 22 May 2019; revised May 2024 (OECD/LEGAL/0449)
- 47 adherents, including the European Union
- First intergovernmental AI standard; basis of the G20 AI Principles
- Non-binding — a Recommendation, not a treaty or a statute
- 2024 revision added safety, privacy, IP and information integrity
The standard, accurately
The OECD AI Principles are a Recommendation of the Council — an instrument that adherent governments commit to politically but that creates no direct obligation on companies. Reading that as "so it does not matter" is the common mistake. Because it arrived first and achieved broad agreement, it became the vocabulary later instruments were drafted in: the structure of the EU AI Act's risk logic, the trustworthiness characteristics in the NIST AI Risk Management Framework, and the G20 AI Principles all trace back to it.
The Recommendation has two halves. The first sets out five value-based principles for responsible stewardship of trustworthy AI, addressed to everyone involved in AI systems. The second sets out five recommendations for policy makers — investing in AI research and development, fostering an inclusive AI-enabling ecosystem, shaping an interoperable governance and policy environment, building human capacity and preparing for labour-market transition, and international co-operation for trustworthy AI. Only the first half is a practical checklist for an organisation deploying AI.
One of the Recommendation's most consequential exports is its definition of an AI system. The updated OECD definition was adopted, near-verbatim, into the EU AI Act — which means the question of whether a given piece of software is "AI" for European legal purposes is answered, in substance, by an OECD text. If you are scoping systems for EU AI Act purposes, you are already applying this instrument whether or not you have read it.
The May 2024 revision responded to general-purpose and generative AI. It sharpened the treatment of safety, added explicit attention to intellectual property and privacy, and introduced information integrity — the risks of synthetically generated content, misinformation and disinformation — which the 2019 text did not anticipate. Principle 1.2 was also broadened from "human-centred values and fairness" to human rights and democratic values, including fairness and privacy.
What adherence actually asks of you
-
01
Inclusive growth, sustainable development and well-being
AI should be directed at beneficial outcomes for people and the planet — augmenting human capability, reducing inequality, and supporting sustainability. In practice this is the principle that asks whether the purpose of a system was ever examined, not just its accuracy.
-
02
Human rights and democratic values, including fairness and privacy
Respect the rule of law, human rights, democratic values and diversity throughout the AI lifecycle — with safeguards such as human intervention where appropriate. The 2024 revision made fairness and privacy explicit here rather than implied.
-
03
Transparency and explainability
Meaningful disclosure: that people know when they are interacting with AI, that those affected by an AI-informed outcome can understand the basis of it, and that stakeholders can grasp a system's capabilities and limits. Note the standard is meaningful to the audience, not maximal technical detail.
-
04
Robustness, security and safety
Systems should function appropriately across their lifecycle and not pose unreasonable safety risk under normal use, foreseeable misuse or adverse conditions — with traceability of datasets, processes and decisions, and mechanisms to override, repair or decommission. The 2024 revision strengthened this materially.
-
05
Accountability
Named organisations and individuals are answerable for AI systems working as intended, on the basis of a risk-management approach applied across the lifecycle. This is the principle that turns the other four from aspiration into something auditable — because it requires an owner.
Why this lands on your desk
Align once, map many. The strongest practical argument for using the OECD principles as your organising frame is leverage: because the EU AI Act, NIST AI RMF and ISO/IEC 42001 were all built in dialogue with them, controls that satisfy an OECD principle usually satisfy something concrete in each of the others. Organisations that start from a specific regulation and work outward tend to rebuild their programme every time a new jurisdiction appears. Starting here, that is a mapping exercise instead.
Expect to meet them in procurement, not in an enforcement letter. No regulator will fine you under the OECD principles. But they surface constantly in enterprise vendor questionnaires, investor and board diligence, public-sector tenders, and the responsible-AI commitments companies publish. The gap that hurts is not non-adherence — it is a public commitment to the principles with nothing behind it, which is a statement about your AI that a buyer, a journalist or the FTC can test.
Nobody can certify you against them, and claiming otherwise is the risk. A Recommendation to governments has no conformity-assessment regime and no accredited certifier. What can be produced is evidence: a documented assessment, principle by principle, of what was examined, what held, and what did not — dated, and performed by someone who did not build the systems. That is a defensible claim. "OECD-compliant" is not.
Readiness you can evidence
An audit can't issue legal certification — but it can verify concrete, checkable artifacts that map to the standard.
Principle-by-principle assessment
We assess your AI against all five value-based principles and report what is evidenced, what is asserted without support, and what is absent — rather than returning a single pass or a score.
Mapping to the regimes that bind you
Each finding is mapped onward to the EU AI Act, NIST AI RMF and ISO/IEC 42001, so one assessment feeds several compliance conversations instead of one.
Transparency and explainability in practice
We test whether disclosure is meaningful to the people who receive it — AI-interaction notice, the basis of adverse outcomes, and documented limits — not whether a model card exists.
Robustness and information integrity
Behaviour under foreseeable misuse and adverse conditions, traceability of data and decisions, override and decommission paths, and the synthetic-content exposure the 2024 revision added.
Accountability that names someone
We check that each system has an identifiable owner, a risk-management approach applied across its lifecycle, and escalation that functions — the principle most often documented and least often true.
Evidence for the claim you publish
If your site, RFP responses or investor materials cite the OECD principles, we give you a dated independent assessment standing behind that statement.
Common questions
Are the OECD AI Principles legally binding?
No. They are a Recommendation of the OECD Council: adherent governments make a political commitment to them, but they impose no direct legal obligation on companies and carry no penalties. Their force is indirect — they shaped the instruments that are binding, and they appear routinely in procurement and diligence.
How many countries have adhered?
Forty-seven adherents, including the European Union — OECD members plus a number of non-member countries. The G20 also endorsed a set of AI principles drawn from them in 2019, which extends their reach well past the formal adherent list.
What changed in the 2024 update?
The revision responded to general-purpose and generative AI. It strengthened safety, added explicit treatment of intellectual property and privacy, and introduced information integrity — covering synthetic content, misinformation and disinformation. The human-centred values principle was also broadened to reference human rights and democratic values directly.
How do they relate to the EU AI Act and NIST AI RMF?
They are the shared ancestor. The EU AI Act adopted the OECD definition of an AI system almost verbatim, and the NIST AI RMF's trustworthiness characteristics map closely onto the five principles. Aligning to the OECD principles gives you a frame that translates into both, which is why they are a sensible starting point for a multi-jurisdiction programme.
Can we say we are "OECD AI Principles compliant"?
We would advise against that phrasing. There is no conformity-assessment regime or accredited certifier for a Recommendation, so the claim cannot be substantiated and invites challenge. "Independently assessed against the OECD AI Principles", with a dated report behind it, says more and is defensible.
Can an iDharma audit certify OECD alignment?
No — nobody can certify against a non-binding Recommendation. We provide an independent, documented assessment of your AI against the five principles, mapped to the binding regimes, so you can evidence the work rather than assert the conclusion.
Informational only, reflecting the OECD Recommendation on Artificial Intelligence (OECD/LEGAL/0449) as adopted in 2019 and revised in May 2024; not legal advice. The Recommendation is non-binding and confers no certification — confirm how it is being applied in your jurisdiction and sector with qualified counsel.
Turn a moving target into a documented posture
An independent audit gives you evidence you were ready — useful as rules shift and as buyers ask.
Request an AI audit