What the declaration says
The declaration was led by Finland and Norway. Its core proposition is that AI must remain under human direction, oversight and control — a formulation that sounds anodyne until you notice that it is the proposition frontier developers have spent two years explaining is technically difficult to guarantee.
Around that core it asks for common standards, sharing of safety incident reports, pre-deployment testing and independent evaluations. It calls on UN member states to build on existing mechanisms and to explore creating a new international institution able to set standards, enable verification and convene states.
Named signatories include Germany, Canada, Australia, South Africa, Kenya, Singapore, the United Arab Emirates, Kazakhstan and Türkiye alongside the two sponsors. Reporting varied on the count, with some outlets giving twenty and others twenty-two, apparently depending on whether the European Union is counted separately. The statement remains open for further endorsement.
Why the absences are the story
An instrument of this kind is measured by who is bound, and on that measure the declaration is thin.
Frontier model development is concentrated in the United States and China, with meaningful capability in the United Kingdom, France, Japan, Korea and Canada. Of that list only Canada and Germany signed. The declaration's substantive asks — pre-deployment testing, independent evaluation, incident sharing, verification — are obligations that would have to bite on developers, and almost none of the states with jurisdiction over those developers are party to it.
This is not a drafting failure. It reflects positions that were already clear. The United States has moved decisively toward a promotion-first posture, with a federal framework oriented to preemption of state AI rules, and a competition enforcer that declined in the same month to bless AI safety coordination. China has built a substantial domestic regime — labelling rules, generative AI measures, recurring enforcement campaigns — and has consistently declined to accept external verification of it. The United Kingdom has been signalling tougher domestic rules while keeping distance from multilateral commitments. Each has a coherent reason to stay out, and none of the reasons is likely to change soon.
What the declaration therefore maps is not a coalition capable of governing AI. It is the set of states willing to accept international oversight — which turns out to be, with a few exceptions, the states that do not host the developers.
Türkiye's position
Türkiye's signature is worth more attention than it has received, because it is consistent with everything else the country did that week.
On 22 September, in the general debate, President Erdoğan linked AI risk to disinformation, said the technology is becoming harder to control, and stated that the time had long since come for a common international legal framework — calling for work on a UN international AI convention to be accelerated.
That is a more forward position than most signatories took. A declaration asks states to explore an institution. A head of state calling from the General Assembly rostrum for acceleration of a convention is asking for a binding instrument.
It is also consistent with the domestic record. The parliamentary AI research commission recommended in March 2026 that Türkiye ratify the Council of Europe Framework Convention on artificial intelligence. The AI Action Plan for 2026–2030, brought into force by presidential circular in August 2026, contains a governance pillar promising a proportionate risk-based regulatory framework and regulatory sandboxes across priority sectors. On 23 September the Minister for Industry and Technology announced that at least two per cent of the public investment programme budget would be allocated to AI projects.
The picture is of a state positioning itself as a rule-taker in the constructive sense: not a developer of frontier models, but a jurisdiction that wants the rules to exist and to be international, because a country in that position benefits from a framework it did not have to build. That is a rational posture and a sincere one. It carries a cost that is worth naming: a state that advocates a convention while its own domestic framework is still a draft has an argument that is easier to make abroad than at home.
The Security Council briefing
Two days later, on 23 September, France used its Council presidency to convene a high-level briefing on AI and international security, chaired by its foreign minister. The briefers were Yoshua Bengio, co-chair of the UN scientific panel, and the heads of OpenAI, Anthropic and Hugging Face.
The stated focus was systemic risk from misalignment and loss of control, including autonomous systems and recursive self-improvement — which places it directly downstream of the scientific panel's thematic brief published on 21 September, the same day as the declaration.
No resolution or presidential statement was expected, and the Council's own analysts framed the meeting as a discussion forum: members agreeing on the need for safeguards while differing on who sets the rules, how restrictive they should be, and how they would be enforced.
The significance is jurisdictional rather than operational. Taking AI up under the maintenance of international peace and security agenda item moves it, conceptually, from a development and economic file into the Council's domain — where mandated monitoring and, in principle, Chapter VII machinery exist. Nothing binding was on the table and none of that machinery is remotely in prospect. But the categorisation is a precedent, and categorisation is how Council practice develops.
There is also something notable about the format. Private companies briefing the Security Council on a risk they themselves create and are best placed to describe is an unusual arrangement, and one with an obvious tension. It is hard to think of another security file where the Council takes its technical briefing principally from the industry under discussion.
Three instruments, one week, no enforcement
Set the week's outputs side by side and the structural problem is visible.
The scientific panel published a finding that the preconditions for loss of control converged in a production system. Twenty-two states declared that AI must remain under human control and floated an institution to verify it. The Secretary-General used his final General Assembly address to demand a multilateral risk-management framework with independent oversight. The Security Council discussed the matter with the developers present.
What none of them produced was an obligation binding on anyone.
The gap is not rhetorical. Every proposal on the table requires verification — pre-deployment testing, independent evaluation, monitoring against capability thresholds. Verification requires access: to models, to training infrastructure, to evaluation results. No state currently has a legal right of access to a frontier developer's internal systems, and the states that could create such a right are the ones that have declined to join the instrument asking for it.
This is the same problem that arms control faced, and arms control solved it slowly, bilaterally, and only where both sides concluded that verified restraint beat unverified competition. That calculation has not yet been made about AI by either of the two states that would have to make it.
What a verification institution would actually have to do
The declaration asks states to explore an institution that can set standards, enable verification and convene. The first and third are straightforward. The second is where every such proposal has failed, and it is worth setting out why, because the difficulty is technical rather than political.
Verification of a nuclear facility works because the object being verified is physical, located, and has properties that persist. Inspectors can count centrifuges, take environmental samples and seal containers. The thing being measured does not change while nobody is looking.
A model has none of those properties. Weights can be copied without trace. A training run leaves no residue an inspector could sample. Capability is not a property you can read off the artefact — it is discovered by evaluation, evaluations are expensive, and their results depend heavily on how the evaluation was constructed. A developer that wished to conceal a capability would not need to hide anything physical; it would need only to not look for it, or to look in a way unlikely to find it.
Which makes verification, in practice, a question of access to process rather than inspection of objects: the right to observe how evaluations were designed and run, to re-run them independently, and to see the results that were not published. That is a far deeper intrusion into a commercial organisation than arms control ever asked of a state facility, and it lands on companies rather than governments, which raises questions about trade secrets, jurisdiction and compelled disclosure that no existing framework answers.
There is one partial precedent worth noting: financial audit. Auditors do not inspect an object either. They obtain a right of access to process and records, backed by statute, with the auditor's own independence regulated and with liability attaching to a negligent opinion. It is an imperfect analogy, and audit's failures are well documented. But it is the only established model in which a private organisation is compelled to open its internal processes to an external verifier whose opinion carries legal weight — and it is, notably, a model built domestically by each jurisdiction rather than internationally by treaty.
That last point is the practical one. If verification arrives, it is more likely to arrive as a domestic audit obligation in several jurisdictions that later converge than as an international inspectorate created by convention. The declaration's own signatories are the obvious place for that to start.
The energy flank
One Turkish item from the same week belongs in this picture, and it has been discussed separately from it.
On 22 September the Minister for Environment, Urbanisation and Climate Change, who holds the presidency of COP31 in Antalya in November, said that governments should set rules on AI energy consumption, that technology companies should be transparent about their consumption, and that data centres should run on clean energy. A political commitment document on AI and climate, prepared with the United Nations, is to be published before the summit.
This is a different regulatory flank on the same industry, and in some respects a more tractable one. Energy consumption is measurable, meters exist, and disclosure obligations on large consumers are an established regulatory form. A state that cannot verify a model's capability can verify its electricity bill.
It also puts Türkiye in an interesting position. The same government that is committing at least two per cent of the public investment budget to AI and targeting a quadrupling of data-centre capacity by 2030 is chairing a summit that will ask for transparency and clean-energy commitments from data-centre operators. Those are not contradictory — a state can build capacity and regulate its energy profile — but the sequencing will be watched, and the credibility of the COP31 ask will depend partly on what Türkiye requires of its own build-out.
What follows in practice
For businesses, the immediate significance of the week is low and the medium-term significance is not.
Nothing in the declaration creates an obligation. No company needs to do anything differently because twenty-two states signed a statement. But the declaration's content is a reliable forecast of what the signatories will legislate domestically, because states that sign such instruments generally intend to implement them, and the asks are specific: incident reporting, pre-deployment testing, independent evaluation.
An organisation operating across several of the signatory jurisdictions can reasonably expect those three to appear in national law over the next two to three years, in forms that will differ in detail and converge in substance. Building the capability to report incidents, to evidence pre-deployment testing and to accommodate third-party evaluation is therefore not premature compliance. It is the durable part.
The second practical point concerns contracts rather than statutes. Where regulation lags, procurement leads. Enterprise buyers in signatory jurisdictions will begin asking suppliers for exactly what the declaration asks states for, because it is the available language, and contractual obligations arrive years before legislative ones. Turkish suppliers to German or Canadian customers should expect the questions before they expect the law.
What to watch next
Whether the signatory count grows, and specifically whether any jurisdiction with frontier development joins — the United Kingdom is the most plausible addition and would change the instrument's weight considerably. Whether the proposed institution acquires a concrete design rather than remaining an invitation to explore, and whether it is pitched as an inspectorate or as a coordinating body for domestic audit regimes. Whether the Council of Europe framework convention on AI reaches the ratifications it needs to enter into force, which would give the field its first binding international instrument and a great deal of momentum. Whether Türkiye follows its signature and its General Assembly call with ratification of that convention, as the parliamentary commission recommended in March. And whether the Global Dialogue on AI Governance, due at UN headquarters in 2027, is given anything operative to discuss, or inherits only declarations.
Frequently asked questions
Is the declaration binding?
No. It is a political declaration with no legal force, open to further endorsement. Its function is to establish a coalition position and to create momentum for an institution that does not yet exist.
Why does it matter that the US and China did not sign?
Because the substantive asks — testing, evaluation, verification — must operate on developers, and the great majority of frontier development sits in those two jurisdictions. An oversight framework without them can describe a standard but cannot verify compliance with it.
What did Türkiye commit to?
Nothing legally. Signature places Türkiye on the record supporting human oversight of AI, common standards, incident sharing and the exploration of an international institution. President Erdoğan's call the following day for acceleration of a UN AI convention goes further rhetorically than the declaration itself.
Does the Security Council briefing change anything?
Not operationally. No resolution or presidential statement was expected or produced. Its significance is that AI was taken up under the international peace and security agenda item, which is a categorisation precedent rather than an action.
Is a UN AI convention realistic?
Not on a short timescale. The Council of Europe's framework convention on AI, opened in 2024, is still not in force. A UN instrument would face the same ratification problem with a much larger and more divided membership.
What should a company actually take from this week?
That incident reporting, pre-deployment testing and third-party evaluation are the three requirements most likely to become law across multiple jurisdictions, and that they will arrive through customer contracts first. Building the capability now is cheaper than retrofitting it under a deadline.
Burhan Doğuş Ayparlar's View
This section sets out my personal assessment as the founder of this site and an AI ethics & compliance counsel.
The instinct when reading a declaration like this is to be cynical about it, and I think the cynicism is only half earned.
The half that is earned concerns capability. A verification institution that does not reach American or Chinese developers cannot verify anything that matters. This is not a defect that more signatures will cure — adding another twenty states without jurisdiction over frontier development adds nothing to the enforcement picture. Anyone presenting the declaration as a step toward global AI oversight is describing an aspiration, not a mechanism.
The half that is not earned concerns what such instruments are actually for. Declarations of this kind rarely bind; they coordinate. Their function is to tell twenty-two legislatures what to draft, and to give officials in each of those countries a document to point at when domestic industry argues that nobody else is doing this. That is a real function, and it is how a good deal of international standard-setting has historically worked — not through enforcement from above, but through convergence among the willing, which later becomes the baseline that the unwilling are measured against. The Council of Europe's data protection convention influenced a great many jurisdictions that never ratified it.
On Türkiye's position I am genuinely supportive, with one reservation. Supporting an international framework is the right call for a country in Türkiye's position: we are a significant deployer and a modest developer, and a jurisdiction in that posture benefits enormously from rules that arrive ready-made rather than having to be invented domestically at great cost. The call for acceleration of a convention is also strategically sensible — the states that engage early in drafting get to shape the text, and the ones that ratify late inherit it.
The reservation is about sequencing. We are asking for an international convention while our own framework remains a draft proposal, our AI act has not been introduced, and our action plan's promised risk-based regulatory framework and sectoral sandboxes have not yet been built. There is nothing dishonourable in that — most signatories are in a similar position — but it does weaken the argument. A state that has implemented human-oversight requirements domestically makes a much stronger case abroad than one that has declared in favour of them. Ratifying the Council of Europe framework convention, which the parliamentary commission already recommended in March, would be the cheapest available way to convert a declaratory position into a legal one, and it would be a better use of the next parliamentary session than another round of drafting.
The thing I would most want a Turkish executive to take from this week, though, is not about diplomacy at all. Three of the four outputs — the panel's brief, the declaration, the Secretary-General's address — converge on the same three asks: report incidents, test before deployment, permit independent evaluation. That convergence is the signal. Whatever happens to the convention, those three requirements are now the international consensus position, they will appear in the signatory states' domestic law, and they will appear in your customers' contracts considerably sooner than that. The organisations that treat this as diplomacy will be retrofitting in 2028. The ones that treat it as a specification will not.
This article is for information only and does not constitute legal advice. It is based on the declaration issued on 21 September 2026 and press reporting of the same week; outlets differ on the number of signatories, and the statement remains open for further endorsement. No readout of the Security Council briefing was available at the time of writing. The analysis and assessments are the author's own.