AI Regulation Tracker / International frameworks and standards
Council of Europe Approves the HUDERIA Model and COBRA AI Risk-Analysis Resources
On February 25, 2026, in Strasbourg, the Council of Europe's Committee of Ministers approved the HUDERIA Model and its Context-Based Risk Analysis (COBRA) resources, a voluntary method for assessing how an AI system affects human rights, democracy, and the rule of law. Read the name carefully: this is guidance, not a binding rule. It requires nothing, bans nothing, and carries no penalty. The binding instrument in this area is the separate Framework Convention on AI, which HUDERIA supports.
What did the Council of Europe actually approve?
On February 25, 2026, at the 1551st meeting of the Ministers' Deputies in Strasbourg, the Committee of Ministers approved the HUDERIA Model and its Context-Based Risk Analysis (COBRA) resources. The official announcement is plain about what this is. In the Council's words, HUDERIA "provides structured guidance for assessing the risks and impacts of AI systems on human rights, democracy and the rule of law." It was developed by the Committee on Artificial Intelligence, the same body that produced the Framework Convention on AI. The COBRA resources are the practical layer that sits on top of the 2024 HUDERIA Methodology.
Is this a binding rule? No.
This matters, so I want to be exact about it. The HUDERIA Model is not law. It does not require anyone to do anything, it bans nothing, and it creates no penalty for ignoring it. The Committee of Ministers approved a set of resources, not a regulation. The binding instrument in this area is the Council of Europe's Framework Convention on AI, a separate treaty that states sign and ratify. HUDERIA is a voluntary human-rights impact-assessment tool that supports that treaty. Think of it as the recommended method, published by a serious international body, for doing the risk work the Convention points toward. You can adopt it, adapt it, or leave it. Nobody will fine you either way.
What does the COBRA element add?
The name spells out the idea. Context-Based Risk Analysis. According to the Council, COBRA "helps users systematically collect and map information about an AI system's context, design and deployment to identify potential risks and determine the appropriate governance and mitigation measures." In plainer terms, it walks you through three questions. What is this system, where and how is it being used, and what could go wrong for the people it touches. From there it points you toward governance and mitigation steps that fit the risk you found. It is a structured worksheet, not a black box. That is deliberate, because the point of a human-rights impact assessment is that a person can follow the reasoning and defend it.
Why does this reach a US professional?
Two reasons, and neither is that HUDERIA binds you. It does not. First, it is a free, credible template. If you are a lawyer, a compliance lead, or a consultant who has to produce an AI risk assessment and you would rather not invent the format from scratch, this is a published method from the body that also wrote the Framework Convention on AI. Borrowing a recognized structure is easier to defend than a homemade one. Second, if your firm or your client operates in or sells into Council of Europe member states, the direction of travel matters. The Convention is the binding piece, and tools like HUDERIA show how European regulators expect the risk analysis to be done. Reading it now tells you what good looks like before anyone asks you to prove it.
What to do now
Download the HUDERIA Model and COBRA resources from the Council of Europe site and read them once, end to end, before you need them. Map your current AI risk process against the COBRA steps and note where you have gaps, particularly around context and deployment, which is where most internal reviews are thin. If you advise clients, keep a copy on hand as a reference method you can point to. And keep the categories straight. HUDERIA is guidance. The Framework Convention on AI is the binding instrument. Treating the guidance as if it were law overstates your obligations, and treating the treaty as if it were optional understates them.
Questions professionals are asking
Is the HUDERIA Model legally binding?
No. The HUDERIA Model and its COBRA resources are voluntary guidance approved by the Council of Europe's Committee of Ministers on February 25, 2026. They require nothing, ban nothing, and carry no penalty. The binding instrument in this area is the separate Framework Convention on AI, which HUDERIA supports.
What is the COBRA element?
COBRA stands for Context-Based Risk Analysis. Per the Council of Europe, it helps users systematically collect and map information about an AI system's context, design, and deployment to identify potential risks and determine the appropriate governance and mitigation measures. It is the practical layer built on the 2024 HUDERIA Methodology.
How is HUDERIA different from the Framework Convention on AI?
The Framework Convention on AI is a binding treaty that states sign and ratify. HUDERIA is a voluntary method, not a rule. It gives organizations a structured way to assess AI risks to human rights, democracy, and the rule of law, which is the kind of analysis the Convention points toward. Both came from the Council's Committee on Artificial Intelligence.
Does HUDERIA apply to US organizations?
Not as a legal obligation. It is a Council of Europe tool, and it binds no one, including US organizations. Its practical value for US professionals is as a free, credible template for AI risk assessments and as a signal of how European regulators expect that work to be documented, which matters if you operate in or sell into Council of Europe member states.
RELATED BRIEFINGS
Informational analysis for working professionals, not legal advice. Confirm how any framework, standard, or requirement applies to your situation with qualified professionals in the relevant jurisdiction.