⚡ Quick Summary
Published by the United Nations Economic Commission for Europe (UNECE), this document sets out an overarching common regulatory arrangement (CRA) for the regulatory compliance of products and services with embedded artificial intelligence or other digital technologies, together with a declaration that government agencies can sign. It was developed within the UNECE Working Party on Regulatory Cooperation and Standardization Policies (WP.6) and builds on the WP.6 paper prepared for the November 2023 Annual Session and on the United Nations Advisory Board on Artificial Intelligence's Interim Report: Governing AI for Humanity.
The CRA is a voluntary framework intended to promote convergence of national technical regulations. Its stated uses are setting legitimate regulatory objectives, identifying and assessing risks, identifying relevant international standards, establishing mutually recognizable conformity assessment procedures, and establishing market surveillance and enforcement mechanisms. It distinguishes high, limited (or medium) and low risk and links each level to proportionate conformity assessment, including a six-step process for testing and evaluating residual risk. Its deliverable is a signature-ready declaration in the annex, by which agencies pledge to adopt CRA version 2024 (ECE/CTCS/WP.6/2024/11), propose product-specific use cases and share lessons learned.
🧩 What’s Covered
- Introduction and basis: product regulation is described as siloed while embedded technologies are horizontal, with definitions, standards and regulations varying across economies. The arrangement builds on the WP.6 paper for the November 2023 session and the UN Advisory Board on AI interim report, and is to be reviewed periodically with version numbers cited.
- Scope and terms: the arrangement is to serve five purposes, from setting legitimate regulatory objectives and assessing risks to establishing conformity assessment, market surveillance and enforcement. Definitions cover AI systems (drawing on ISO/IEC 22989), generative AI and products or services with embedded AI; terminology follows the WTO TBT Agreement Annex 1 or WP.6 recommendations. Autonomous wheeled vehicles and autonomous weapons are out of scope, while aerial and submarine vehicles and robots are in scope.
- Regulatory objectives and risk: zero risk is not achievable; tolerable risk and risk appetite follow WP.6 Recommendation R. Risk is tiered as intrinsically high, limited (or medium) and low. Where AI error risk is high, human decision-making "shall be included wherever possible" and AI systems "should not be able to override human control". Residual risk must be tolerable and disclosed, with reference to the NIST AI Risk Management Framework.
- Societal and digital considerations: requirements address bias in AI and AI-aided decisions (ISO/IEC TR 24027), loss of individual freedom or autonomy, mental wellbeing and children's rights (UNCRC General Comment No 25), the digital divide (A/78/L.49) and market access for emerging economies. Trustworthiness (ISO/IEC TR 24028), data protection (GDPR, EU AI Act) and protection against cyber-attacks, data drift, concept drift, reward hacking and safe exploration are covered (ISO/IEC TR 5469, NIST AI 100-2e2023, NIST CSF 2.0).
- Reference to international standards: the WTO TBT Agreement Article 2.4 obligation is quoted, followed by instruments such as ISO/IEC 42001, ISO/IEC 23894:2023, ISO/IEC TR 22100-5, IEC 62443, IEEE 7001-2021, OECD/LEGAL/0449, the UNESCO Recommendation on the Ethics of AI and WHO guidance on large multi-modal models.
- Conformity assessment and declarations: sector-specific mandates are contrasted with horizontal AI compliance. A six-step process covers identifying hazards, building scenarios, evaluating severity and frequency, selecting test scenarios and evaluating residual risk. Low risk may need no process or a supplier's declaration, limited risk a supplier's declaration, and high risk independent third-party assessment, which could sit within or beyond existing mutual recognition agreements.
- Market surveillance: remotely updated products create a continuous compliance problem. Authorities are to integrate regular mandatory independent audits, prompt recall of non-compliant products and an international alert in cases of critical non-conformity.
- Declaration annex: a pledge for government agencies, with fields for organization and authorized signatory, covering adoption of CRA version 2024, product-specific use cases and tracking of progress.
💡 Why it matters?
For regulators, conformity assessment bodies and product manufacturers, the document offers a shared vocabulary and sequence for handling AI embedded in products, at a time when individual national agencies might otherwise apply conflicting AI compliance rules within a single economy. It links risk tiers to proportionate conformity routes and addresses continuous compliance after a product reaches the market. It also points readers to the standards and instruments the arrangement expects them to use, including ISO/IEC 42001, IEC 62443, the NIST AI RMF and, where data protection is affected, the GDPR and the EU AI Act.
❓ What’s Missing
The document does not provide the product-specific use cases it proposes, so sectoral requirements and worked examples remain to be developed. It sets out principles rather than binding obligations and leaves the acceptable level of residual risk undefined, to be settled by each government. Practical detail on how market surveillance authorities would audit remotely updated or opaque systems is not given, and no review interval is specified. Two categories, autonomous wheeled vehicles and autonomous weapons, are explicitly excluded.
👥 Best For
Government agencies and regulators drafting or aligning technical regulation for products with embedded AI, especially those working through WTO TBT channels; standards and conformity assessment bodies designing AI-specific verification; and product compliance teams that need to place supplier declarations and third-party assessment within a common framework.
📄 Source Details
Compliance of products with embedded artificial intelligence: Overarching principles and declaration to promote convergence of product regulations. Geneva: United Nations Economic Commission for Europe, 2024. It was developed under the leadership of Markus Krebsz with contributions from twelve named specialists and edited by Lance Thompson. Reference ECE/TRADE/486; ISBN 978-92-1-106783-5; printed at United Nations, Geneva, October 2024. The extraction covers all 19 PDF pages, several of which are blank; numbered body pages run from 1 to 11. Issued in English, French and Russian. No URL for the document itself is printed; the links in the text point to other instruments.