Bletchley Park · 1 November 2023 · 11:30 GMT
Twenty-eight countries and the European Union signed the same page. It has not happened since.
The Bletchley Declaration was about 1,300 words long, created no institution, bound nobody to anything, and remains the most significant thing that has ever been agreed internationally about artificial intelligence. This is what it said, who put their name to it, and why the moment closed.
Who signed
Twenty-eight countries and the European Union, listed exactly as the Declaration lists them: alphabetically. No hierarchy, no billing order, no host country first. The European Union sits between China and France because that is where the alphabet put it.
New Zealand joined the commitment on 23 October 2024, almost a year later, bringing the total to twenty-nine countries and the European Union. The Declaration notes that references to “governments” and “countries” include international organisations acting within their competences — which is the drafting that let the EU sign alongside its own member states.
What it says
It is short enough to read over a coffee and most people never have. Underneath the diplomatic register, it does six specific things — and two of them still shape AI policy today. Select any one.
The lasting contribution
If the Declaration has an heir, this is it. Before Bletchley, “frontier AI” was a phrase used loosely by a handful of labs. After Bletchley, it was a term twenty-nine governments had agreed the meaning of — and it went on to shape the EU AI Act's treatment of general-purpose models, the AI Safety Institutes, and every frontier safety framework published since.
The definition turns on what a model can do — match or exceed the capabilities of today's most advanced systems — not on how it was built. That choice has aged extremely well, because it does not expire when the architecture changes.
Almost everyone misquotes this. The definition expressly extends to relevant specific narrow AI that could exhibit capabilities that cause harm. Frontier was never only about the big general-purpose models, and the drafters knew it.
Intentional misuse, and unintended issues of control relating to alignment with human intent. That pairing — misuse and misalignment — has structured the entire safety debate since, and it was agreed by China and the United States in the same paragraph.
The Declaration was also specific about where it was most worried: cybersecurity and biotechnology, and the amplification of disinformation. It used the words “serious, even catastrophic”. For a consensus document signed by twenty-nine parties, that is remarkably unhedged language, and it is the sentence that made the front pages.
Honestly
A historical resource that only reports the press release is not much of a resource. The Declaration was significant despite being, in strictly legal terms, almost nothing at all.
A declaration is a statement of shared intent, not a treaty. No obligation in it is enforceable against any signatory, there is no dispute mechanism, no penalty and no compliance test. Nobody has ever breached the Bletchley Declaration, because it is not possible to.
The pre-summit briefing floated an IPCC-style global body for AI. The Declaration did not create one. It resolved to support an internationally inclusive network of scientific research — carefully chosen words that commit nobody to building anything.
No rules for developers, no thresholds, no testing requirements. It acknowledges that approaches will differ by national circumstance and legal framework — which is diplomatic drafting for “we are not agreeing on rules”.
Who decides what counts as frontier? The Declaration defines the term and declines to say who applies it. That question is still open, and it is the reason the AI Safety Institutes exist.
None of which makes it unimportant — it makes it interesting. Its power was never legal. It was that twenty-nine parties who agree on very little agreed on this, in public, with their names attached, at a moment when nobody had to. That is a diplomatic achievement, and diplomatic achievements are perishable.
What happened next
The Declaration closed with a single sentence of intent: the signatories looked forward to meeting again in 2024. They did. And then the thing that made Bletchley extraordinary quietly stopped being true.
That is why this page exists as a historical resource rather than a policy tracker. Bletchley was not the beginning of a process that is still running. It was the high-water mark, and the tide has been out ever since. Whether it comes back in is one of the more consequential open questions in technology policy.
The document
The authoritative text is published by the Prime Minister's Office, the Foreign, Commonwealth and Development Office and the Department for Science, Innovation and Technology on GOV.UK, where it first appeared at 11:30 on 1 November 2023.
It is © Crown copyright and licensed under the Open Government Licence v3.0, which means — unusually for a document of this significance — anyone may copy, publish and adapt it, provided they acknowledge the source. It is one of the few genuinely important AI documents that is free to read, free to quote and free to republish.
If you read nothing else, read the paragraph beginning “Particular safety risks arise at the frontier”. It is the definition, the risk taxonomy and the reason for the whole exercise, in about 150 words.
“We affirm.” “We recognise.” “We resolve.” “We encourage.” Not one “shall”, not one “must”. Diplomatic texts tell you their legal weight through their verbs, and this one is telling you it has none.
“We look forward to meeting again in 2024.” That is the whole enforcement mechanism: the expectation of another meeting. For fifteen months, it was enough.
About this resource
This page is maintained by Matthew Blakemore, a member of the BSI and ISO artificial intelligence committees and sub-editor of ISO/IEC 8183. Bletchley resolved to support an inclusive network of scientific research and to build risk-based policy; the standards committees are one of the places that work actually happens, slowly and unglamorously, long after the summit photographs.
The Declaration set the vocabulary. Turning “human-centric, trustworthy and responsible” into something an organisation can be assessed against is what the standards do — and that is the day job.
Questions
A statement on artificial intelligence safety agreed by 28 countries and the European Union at Bletchley Park in the United Kingdom on 1 November 2023, during the AI Safety Summit. It runs to roughly 1,300 words and sets out a shared understanding of AI's opportunities and risks, a definition of “frontier AI”, and a two-part agenda for international cooperation.
It is the first time a large group of governments — including both the United States and China — agreed a common text on AI risk. It remains the high-water mark of international AI consensus.
Twenty-eight countries and the European Union, listed alphabetically in the Declaration itself: Australia, Brazil, Canada, Chile, China, the European Union, France, Germany, India, Indonesia, Ireland, Israel, Italy, Japan, Kenya, the Kingdom of Saudi Arabia, the Netherlands, Nigeria, the Philippines, the Republic of Korea, Rwanda, Singapore, Spain, Switzerland, Türkiye, Ukraine, the United Arab Emirates, the United Kingdom, and the United States of America.
New Zealand joined the commitment on 23 October 2024, almost a year later, taking the total to 29 countries and the EU.
Yes — and that is the single most consequential fact about it. China signed alongside the United States and the European Union, and every country represented at the summit endorsed the text. The list is alphabetical, so China appears immediately before the European Union, which appears immediately before France.
It has not been repeated. At the Paris AI Action Summit in February 2025 the United States and the United Kingdom declined to sign the final statement — the two countries that convened and championed the Bletchley process.
No. It is a declaration — a statement of shared intent — not a treaty. It creates no obligations enforceable against any signatory, establishes no dispute mechanism, imposes no penalties and contains no compliance test. Its verbs give it away: affirm, recognise, resolve, encourage. There is not a single “shall” in it.
Nobody has ever breached the Bletchley Declaration, because it is not possible to. Its significance was diplomatic rather than legal.
Six things. A definition of frontier AI. A shared statement of the risks its signatories were most concerned by — misuse and loss of control, especially in cybersecurity and biotechnology, and the amplification of disinformation. A particular responsibility on the actors developing the most capable systems. A two-part agenda: identifying risks of shared concern through shared scientific understanding, and building respective risk-based national policies. Support for an internationally inclusive network of scientific research on frontier AI safety. And a commitment to meet again in 2024.
As highly capable general-purpose AI models, including foundation models, that could perform a wide variety of tasks — and, importantly, also relevant specific narrow AI that could exhibit capabilities that cause harm — which match or exceed the capabilities present in the most advanced models of the day.
Two things make that definition durable. It is capability-based rather than technology-based, so it does not expire when the architecture changes. And it expressly reaches narrow AI, which almost every summary of it omits.
At Bletchley Park in Buckinghamshire, England, on 1 November 2023, during the AI Safety Summit held on 1–2 November. The venue was the point: Bletchley Park was the home of British codebreaking during the Second World War and the birthplace of modern computing, and the choice was a deliberate piece of symbolism about international cooperation on a transformative technology.
The signatories kept their promise to meet again. The Republic of Korea co-hosted a second summit in Seoul in May 2024, producing the Seoul Declaration and the Frontier AI Safety Commitments, under which major AI developers published frontier safety frameworks. A network of AI Safety Institutes began to form.
France hosted the third in February 2025 — renamed the AI Action Summit, with “safety” dropped from the title. The United States and the United Kingdom declined to sign its final statement. The Bletchley consensus lasted roughly fifteen months.
Yes. It is © Crown copyright and published under the Open Government Licence v3.0, which permits anyone to copy, publish, distribute and adapt it, including commercially, provided the source is acknowledged and the licence identified. That is unusually permissive for a document of this importance, and it is why the Declaration is quoted so widely and so accurately.
The authoritative version is on GOV.UK, published by the Prime Minister's Office, the Foreign, Commonwealth and Development Office and the Department for Science, Innovation and Technology.
None, directly. It imposes nothing on companies. What it did was set the vocabulary and the direction that the binding instruments then followed — the EU AI Act's treatment of general-purpose models, the AI Safety Institutes and their evaluations, and the ISO/IEC standards that turn “trustworthy and responsible” into something auditable.
So the honest answer is that the Declaration will never be enforced against you, and the things it started very much will be. The EU AI Act › · ISO/IEC 42001 ›
Because it is the proof that it was once possible. Twenty-nine parties who agree on almost nothing — the United States and China, Israel and Saudi Arabia, Ukraine and the EU — agreed in public, with their names attached, that frontier AI poses risks serious enough to warrant coordinated attention.
Nothing since has matched it, and the vocabulary it fixed is still the vocabulary everyone uses. Whether the moment returns is one of the more consequential open questions in technology policy, and the Declaration is the benchmark against which any future attempt will be measured.
From declaration to practice
“Human-centric, trustworthy and responsible” is a fine sentence and an unauditable one. Turning it into something an organisation can evidence — to a regulator, an insurer or a customer — is the work the Declaration pointed at and did not do. That is judgement, and it is what these three do.