OECD AI Principles Explained: The 2019 Standard and 2024 Update

The OECD AI Principles are the first intergovernmental standard on artificial intelligence, adopted in May 2019 and updated in May 2024. They set out five values-based principles for trustworthy AI and five recommendations to governments. They aren't legally binding, but they're the source code for most of the AI rules that have followed, from the EU AI Act to the US NIST framework. If you sit on a board, write policy, or run AI in a regulated business, this is the document the others trace back to.
What are the OECD AI Principles?
The Organisation for Economic Co-operation and Development adopted the Principles on 22 May 2019 as the first intergovernmental standard on AI. The formal legal text is the Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449).
They do two jobs at once. First, they define what trustworthy AI looks like through five value-based principles. Second, they tell governments what to do about it through five recommendations. That split matters, and most summaries blur it. One half speaks to anyone building or deploying AI. The other half speaks only to policymakers.
The OECD updated the text in May 2024, the first major revision since 2019. The G20 also drew on the original principles for its own 2019 AI guidance, which is part of why this framework reaches well beyond OECD borders.
How many countries have adopted them?
As of 2026, there are 47 adherents, including all OECD member countries, the European Union, and several non-members such as Argentina, Brazil, Peru, Romania, Singapore, and Ukraine (OECD.AI). The principles started with 42 adherents in 2019, so the list has grown steadily.
Adherence is a political commitment, not a binding treaty. Countries agree to promote the principles and reflect them in national policy. That's why you see the same five ideas reappear, reworded, in framework after framework.
What are the five OECD AI Principles?
These are the value-based principles. They apply to any actor in the AI lifecycle: developers, deployers, operators. The 2024 update kept all five but sharpened the wording and the underlying guidance.
| Principle | What it asks for |
|---|---|
| Inclusive growth, sustainable development and well-being | AI should benefit people and the planet, widen access to its gains, and account for environmental cost |
| Human rights and democratic values, including fairness and privacy | AI should respect human rights, democratic values, fairness, and privacy, with safeguards and human oversight |
| Transparency and explainability | People should be told when they're dealing with AI and be able to understand and challenge its outcomes |
| Robustness, security and safety | AI should work reliably and safely across its whole life, with risk managed and mechanisms to override or decommission systems when needed |
| Accountability | Those who build, deploy, or run AI are answerable for it working properly and for traceability |
Note the second principle. In 2019 it read "human-centred values and fairness." The 2024 revision rewrote it as "human rights and democratic values, including fairness and privacy" (OECD.AI). Privacy moved from implied to named. That's not cosmetic. It's the OECD reacting to what generative models do with personal data.
What did the May 2024 update change?
The OECD revised the principles on 3 May 2024 and announced it at that month's Ministerial Council Meeting (OECD press release). The driver was general-purpose and generative AI, which barely existed as a public concern in 2019. The headline changes:
- Information integrity. New, explicit attention to mis- and disinformation, and to synthetic content generated at scale. This is the clearest sign of a post-ChatGPT rewrite. The 2019 text had nothing equivalent.
- Generative and general-purpose AI. The definition of an AI system and the AI lifecycle was updated so the principles cover foundation models and the way they get reused downstream.
- Privacy and intellectual property. Both got stronger billing, reflecting the data-scraping and copyright questions that large models raise.
- Safety mechanisms. Clearer expectations around managing risk, including the ability to override, repair, or safely decommission a system that's misbehaving.
- Environmental sustainability. Sharper framing of AI's resource and energy footprint.
If you read a guide that only describes the 2019 version, it's out of date. The information-integrity language alone changes how the principles apply to anyone deploying generative AI in a regulated setting.
What are the five recommendations to policymakers?
This is the half aimed at governments, not at the businesses running AI. Worth knowing because it tells you where regulation is heading.
| Recommendation | The ask of governments |
|---|---|
| Investing in AI research and development | Fund trustworthy AI research, including open datasets and a fair environment for it |
| Fostering an inclusive AI-enabling ecosystem | Build the digital infrastructure, data, and knowledge-sharing that trustworthy AI needs |
| Shaping an enabling, interoperable governance and policy environment | Create agile policy and governance that supports trustworthy AI and works across borders |
| Building human capacity and preparing for labour market transition | Equip people with skills and support workers through the shift AI brings |
| International co-operation for trustworthy AI | Work across governments and stakeholders on shared standards and responsible stewardship |
Source: OECD.AI. The third recommendation gained the word "interoperable" in the 2024 update. Governments are now being told, in the standard itself, to make their AI rules fit together across jurisdictions. For any business operating in more than one country, that's the most useful sentence in the document.
How do national AI frameworks trace back to the OECD Principles?
This is the part that makes the OECD Principles worth a board's attention. They aren't enforceable themselves, but they're the common ancestor of the rules that are.
- EU AI Act. Its risk-based approach and its human-oversight and fundamental-rights requirements rest on the same human-centred and accountability ideas the OECD set out. For the detail, see our EU AI Act timeline.
- NIST AI Risk Management Framework (US). The voluntary US framework shares the OECD's vocabulary of trustworthy, valid, safe, accountable, and transparent AI. See our NIST AI RMF guide.
- ISO/IEC 42001. The international AI management-system standard gives organisations an auditable way to operationalise the same principles. See our ISO/IEC 42001 guide.
- National AI strategies. Dozens of countries cite the OECD Principles directly in their own AI policy, which is the whole point of an intergovernmental standard.
So when you align with the OECD Principles, you're not chasing one more framework. You're aligning with the layer underneath the others. Get the foundation right and the jurisdiction-specific compliance work gets easier, because most of it is the same five ideas in local clothing.
How can organisations put the principles into practice?
The principles are deliberately high-level. That's their strength as an international standard and their weakness as an operating manual. Turning them into something a regulator or an auditor would accept takes structure. A workable order:
- Governance. Name who's accountable for AI outcomes. Set up a review function with real authority, not a committee that meets twice a year.
- Risk assessment. Run impact assessments before deployment, not after an incident. Match the depth of review to the stakes of the use case.
- Transparency. Tell people when they're interacting with AI. Build explanations suited to the audience, whether that's a clinician, a customer, or a court.
- Robustness and safety. Test against edge cases and adversarial conditions. Keep a way to override or shut down a system that goes wrong.
- Monitoring. Watch deployed systems over time. Models drift. Build feedback channels and an incident process before you need them.
The hardest part isn't any single step. It's keeping ethical intent and technical reality in the same room. That's where most "AI ethics policies" fail: the document is fine, the deployment ignores it. The fix is treating responsible AI as an engineering discipline with checks you can verify, not a values statement you file away.
Frequently asked questions
Are the OECD AI Principles legally binding?
No. They're a Council Recommendation, which is a political commitment rather than enforceable law. The binding force comes downstream, when adhering countries build the principles into national legislation like the EU AI Act.
What's the difference between the principles and the recommendations?
The five principles describe what trustworthy AI looks like and apply to anyone in the AI lifecycle. The five recommendations are instructions to governments on policy, investment, and skills. One set is for builders and deployers; the other is for policymakers.
Do the OECD AI Principles cover generative AI?
Yes, since the May 2024 update. The revision added explicit language on general-purpose and generative AI, information integrity, and the spread of synthetic mis- and disinformation. The original 2019 text predated the public rise of large language models.
Where can I read the official text?
The legal text is OECD Legal Instrument 0449, the Recommendation of the Council on Artificial Intelligence. The OECD.AI Policy Observatory at oecd.ai tracks adoption and national policies.
The bottom line
Don't treat the OECD AI Principles as one more box-ticking framework. Treat them as the source document. The EU AI Act, NIST, ISO/IEC 42001, and most national strategies are downstream of these five ideas, which means alignment here is the cheapest compliance work you'll ever do: it covers the foundation that everything else is built on. The May 2024 update is the part to act on now. If your AI governance still reads like it was written for the 2019 version, with nothing on generative AI or information integrity, it's already behind the standard it claims to follow. Fix that first.
If you want support with this, VerityAI offers board-level AI governance.

Sotiris Spyrou
Sotiris Spyrou is the founder of VerityAI, a Responsible AI advisory for boards and AI-deploying businesses. With 27 years across agencies, global in-house roles, and the C-suite, he advises leaders on AI governance and risk, and on answer-engine visibility engineered without the dark patterns the rest of the industry is getting penalised for. He is the author of TRANSFORM, AI Moats, and Ethical AI.
Founder at VerityAI
Areas of Expertise: