New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Sector trends10 min read

The First Binding AI Treaty Governs Your Public University, Not Just Your Vendor

You have spent two years asking whether your AI course-evaluation tool is "high-risk" under the EU AI Act. For a public university, that is the wrong sentence. The AI Act regulates the product and its provider. The Council of Europe's Framework Convention on AI regulates you — the public authority that deploys it — in the language of human rights, not product safety.

Koji Education Team

Product ·

For two years the compliance question about AI in course evaluation has been the same: is the tool "high-risk" under the EU AI Act? For a state-funded university, that is the wrong sentence to be worried about. The AI Act is product-safety law: it regulates the system and, above all, its provider. But on 5 September 2024 a second regime opened for signature that regulates something the Act largely does not — you, the public authority that deploys the system — and it does so in the vocabulary of human rights, democracy and the rule of law rather than CE-marks and conformity assessments. It is the Council of Europe Framework Convention on Artificial Intelligence, and it is the first-ever international legally binding treaty on AI (Council of Europe).

If your university is a public authority — as most European public universities are, or as bodies exercising public functions — then deploying AI to read student comments, moderate evaluation interviews, or flag a lecturer as a "course of concern" now engages a duty that no vendor datasheet can discharge for you.

Two regimes, two defendants

The single most important thing to understand is that the AI Act and the Framework Convention point at different defendants.

The EU AI Act is product law. Its heaviest obligations — risk management, data governance, technical documentation, conformity assessment — fall on the provider who places the system on the market. A university that buys an evaluation tool is typically a deployer, with a lighter set of Act duties.

The Framework Convention flips the frame. Adopted on 17 May 2024 and opened for signature on 5 September 2024, when the EU and a group of states signed it, it obliges each Party to ensure that "activities within the lifecycle of artificial intelligence systems" undertaken by public authorities, or by private actors acting on their behalf, are consistent with human rights, democracy and the rule of law (Future of Privacy Forum analysis; European Commission). The defendant here is the state and its public bodies. When a public university deploys AI, the state's treaty duty lands on the deployment — not on the vendor.

What the Convention requires that the Act is quieter about

The Convention's obligations are principle-based but pointed, and several speak directly to the deployer rather than the manufacturer. It requires respect for human dignity and individual autonomy (Article 7); adequate transparency and oversight tailored to context and risk (Article 8); accountability for adverse human-rights impacts (Article 9); equality and non-discrimination, framed as a positive obligation to work toward fair and equitable outcomes (Article 10); and privacy protection (Article 11). Article 16 requires a risk and impact management framework across the lifecycle — identifying, assessing, preventing and mitigating risks, incorporating the perspectives of affected stakeholders, monitoring iteratively, documenting, and testing before deployment — and contemplates moratoria or bans where risks are incompatible with human rights.

Crucially, the Convention also requires effective remedies for people adversely affected by AI activity, together with procedural safeguards — including that a person be notified when they are interacting with an AI system rather than a human. That is a deployer-facing, individual-facing duty. It is not satisfied by a supplier's conformity paperwork; it is satisfied by how you run the system and what recourse you give the people it touches.

Why course evaluation is squarely in scope

It is tempting to file a treaty about "human rights and the rule of law" under things that happen to other people's AI. It is not. Course evaluation is a small system that touches two rights-bearing groups at once. Students have data-protection and expression interests in how their comments are read, summarised and retained. Staff — this is the part universities routinely miss — have interests in fair treatment and, potentially, private-life and employment protections when an AI-derived judgement feeds a decision about their teaching, promotion or contract. An AI tool that ingests free-text feedback, produces themes, scores quality, or surfaces an instructor for scrutiny is performing an "activity within the lifecycle of an AI system" by a public authority that bears on individuals' rights. That is exactly the situation the Convention was written for.

But hasn't the AI Act already covered all this?

This is the strongest objection, and it has real force — so answer it precisely. Three points.

First, different claimant, different defendant. The Act's teeth are aimed at providers; its deployer duties are comparatively thin, and it is enforced by market-surveillance authorities. The Convention makes the public body answerable and gives the affected individual — including a lecturer contesting an AI-derived flag — a rights-based route that product law does not centre.

Second, it reaches where the Act carves out. If a particular evaluation use is not classified as high-risk under the Act, the Act's heavy obligations simply do not apply. The Convention's rights-based duties still do, because they attach to the public authority's deployment, not to a risk tier. It is a backstop with a wider net.

Third, "framework" is not "optional". The Convention is implemented through national law, which means its duties will harden into concrete domestic obligations and already shape how national regulators and courts interpret public-sector AI. Treating it as mere principles is the same mistake institutions made early with the GDPR.

The Convention does not duplicate the AI Act. It sits behind it, aimed at a different party, triggered by a different question: not "is this product compliant?" but "is our use of it consistent with the rights of the people it affects?"

What a compliant deployment looks like

For a public university, meeting the Convention means treating an AI evaluation deployment as a rights exercise, not only a procurement one. In practice: run a rights-and-impact assessment that goes beyond a GDPR DPIA and the vendor's AI Act conformity file, and that explicitly considers staff as affected stakeholders; document genuine human oversight so a person, not a model, owns any consequential judgement; be transparent to both students and staff that AI is involved in moderating or analysing feedback; and build a concrete route for a lecturer to see the evidence behind, and contest, an AI-derived characterisation of their teaching. Building AI literacy among the staff who run the system is part of the same duty.

How the right tooling helps you discharge the duty

A treaty obligation on the deployer is easier to meet with a system designed to produce the artefacts the obligation demands. Koji for Education is built around transparency and contestability: it discloses when an AI is moderating an evaluation, and its automatic thematic analysis is quote-traceable — every theme points back to the students' own words, so a flagged concern can be inspected and challenged rather than taken on faith, which directly supports the remedy and procedural-safeguard duties. Its reporting keeps a human in the loop for consequential decisions rather than letting automation bias turn a summary into a verdict, and its moderation is standardised and bias-aware, supporting the equality obligation. Data is handled in a GDPR/AVG-compliant, EU-appropriate way. The point is not that a tool makes you compliant — the duty is yours — but that a deployer meeting a rights-based standard needs evidence of oversight, transparency and recourse, and the instrument should generate it by design. Universities running wider research under the same duties will find the same interview engine in the general-purpose koji.so platform.

The bottom line

Stop asking only whether your evaluation vendor's product is high-risk. As a public university you are now a named actor under the first binding international AI treaty, answerable for whether your use of AI respects the rights of the students and staff it touches. That is a deployer's duty, not a supplier's — and it is the right question for a public body to have been asking all along.

Deploy AI course evaluation you can stand behind — transparent, contestable and human-overseen. Explore Koji for Education.

Frequently asked questions

What is the Council of Europe Framework Convention on Artificial Intelligence?

It is the first international legally binding treaty on AI, adopted on 17 May 2024 and opened for signature on 5 September 2024. It requires each Party to ensure that activities across the AI lifecycle are consistent with human rights, democracy and the rule of law. Unlike the EU AI Act, which is product-safety law aimed at providers, the Convention places duties on states and their public authorities.

How is the Convention different from the EU AI Act?

The AI Act regulates the AI system and its provider through risk tiers, conformity assessment and market surveillance. The Framework Convention regulates the public authority that deploys AI, in human-rights terms, and gives affected individuals rights-based protections and remedies. They target different defendants: the Act the provider, the Convention the deploying public body.

Does the Convention apply to a public university's course evaluation?

In most cases, yes. Public universities are typically public authorities or bodies exercising public functions, and an AI tool that analyses student feedback, moderates evaluation interviews or flags instructors is an AI-lifecycle activity affecting the rights of students and staff. That places it within the Convention's scope for deployments by public authorities and private actors acting on their behalf.

What does the Convention require a deployer to do?

Key duties include transparency and oversight, accountability for adverse impacts, equality and non-discrimination, privacy protection, a lifecycle risk-and-impact management process that includes affected stakeholders, and effective remedies and procedural safeguards — including notifying people when they are interacting with an AI system. For universities this means rights-based impact assessment, documented human oversight, transparency to students and staff, and a route to contest AI-derived judgements.

If our evaluation tool is not high-risk under the AI Act, are we in the clear?

No. The AI Act's heavy obligations attach to risk classifications; if a use is not high-risk, those obligations do not apply. But the Convention's rights-based duties attach to the public authority's deployment regardless of risk tier, so they can still apply where the Act is silent. The Convention functions as a backstop with a wider net.

How does Koji help a university meet these obligations?

Koji supports the deployer-side duties by disclosing AI involvement, keeping thematic findings quote-traceable so they can be inspected and contested, keeping a human in the loop for consequential decisions, applying standardised bias-aware moderation, and handling data in a GDPR/AVG-compliant, EU-appropriate way. The compliance duty remains the institution's, but the tooling generates the evidence of oversight, transparency and recourse the Convention expects.