Summary: OECD/LEGAL/0449 — the 2019 Recommendation of the Council on Artificial Intelligence, amended May 2024. Five values-based principles plus five national-policy recommendations. The upstream source for most later frameworks’ definitions.
Sources: raw/Laws/OECD_Legal_Instruments_OECD.md
Last updated: 2026-07-28
Adopted 22 May 2019, amended 3 May 2024, in force (source: OECD_Legal_Instruments_OECD.md).
Its influence is disproportionate to its length: NIST’s AI system definition is “Adapted from: OECD Recommendation on AI:2019,” and NIST’s “AI actors” concept is taken directly from OECD (source: raw/Laws/NIST.AI.100-1.md).
Section 1 — Five principles for responsible stewardship
The Recommendation “UNDERLINES that the following principles are complementary and should be considered as a whole.”
1.1 Inclusive growth, sustainable development and well-being.
1.2 Respect for the rule of law, human rights and democratic values, including fairness and privacy. Covers “non-discrimination and equality, freedom, dignity, autonomy of individuals, privacy and data protection, diversity, fairness, social justice, and internationally recognised labour rights,” and — added in the 2024 amendment — “addressing misinformation and disinformation amplified by AI, while respecting freedom of expression.”
1.2(b) requires “mechanisms and safeguards, such as capacity for human agency and oversight, including to address risks arising from uses outside of intended purpose, intentional misuse, or unintentional misuse.”
That clause is a security requirement in a human-rights principle: misuse is named as something the design must anticipate.
1.3 Transparency and explainability. Four sub-obligations: foster general understanding of capabilities and limitations; make stakeholders aware they are interacting with AI systems “including in the workplace”; where feasible provide plain information on data sources, factors and logic; and “provide information that enable those adversely affected by an AI system to challenge its output.”
The AI-interaction disclosure prefigures AI Act Art 50(1) by five years.
1.4 Robustness, security and safety — the security principle, quoted in full:
a) AI systems should be robust, secure and safe throughout their entire lifecycle so that, in conditions of normal use, foreseeable use or misuse, or other adverse conditions, they function appropriately and do not pose unreasonable safety and/or security risks.
b) Mechanisms should be in place, as appropriate, to ensure that if AI systems risk causing undue harm or exhibit undesired behaviour, they can be overridden, repaired, and/or decommissioned safely as needed.
c) Mechanisms should also, where technically feasible, be in place to bolster information integrity while ensuring respect for freedom of expression.
(source: OECD_Legal_Instruments_OECD.md)
1.4(b) is the kill-switch principle. It is the governance-level statement of what the loss of control specified systemic risk is about, and what NIST means by “the ability to shut down, modify, or have human intervention into systems that deviate from intended or expected functionality.”
1.4(c) on information integrity is a 2024 addition, tracking the deepfake and disinformation concerns that Art 50 addresses through marking.
1.5 Accountability. Requires “traceability, including in relation to datasets, processes and decisions made during the AI system lifecycle, to enable analysis of the AI system’s outputs and responses to inquiry.”
1.5(c) requires “a systematic risk management approach to each phase of the AI system lifecycle on an ongoing basis,” with risks including “harmful bias, human rights including safety, security, and privacy, as well as labour and intellectual property rights,” addressed “as appropriate, via co-operation between different AI actors, suppliers of AI knowledge and AI resources, AI system users, and other stakeholders.”
The traceability requirement is the conceptual ancestor of AI Act Art 12 record-keeping, and the multi-actor cooperation clause anticipates the value-chain problem the Act handles through deployer roles.
Section 2 — Five national policy recommendations
2.1 Investing in AI R&D — including “open-source tools and open datasets that are representative and respect privacy.”
2.2 Fostering an inclusive AI-enabling ecosystem — including “mechanisms, such as data trusts, to support the safe, fair, legal and ethical sharing of data.”
2.3 Shaping an enabling interoperable governance and policy environment — governments “should consider using experimentation to provide a controlled environment in which AI systems can be tested, and scaled-up.” This is the sandbox concept that AI Act Arts 57–59 makes law.
2.4 Building human capacity and preparing for labour market transformation.
2.5 International co-operation — including promoting “multi-stakeholder, consensus-driven global technical standards for interoperable and trustworthy AI.”
Follow-through
The Digital Policy Committee, through its Working Party on AI Governance, must “develop and iterate further practical guidance,” provide a forum for policy exchange, and report to Council “no later than five years following its revision and at least every ten years thereafter.”
Why it matters for security work
It is the shared vocabulary layer. When NIST, the AI Act, Singapore’s framework and the Code of Practice agree on what an “AI system” or “AI actor” is, it is because they all inherit from here. That makes cross-framework mapping tractable — see the comparison table in trustworthy-ai-characteristics.