What Is AI? The Definitions Regulators And Standards Bodies Use
AI has a working definition that the OECD, the EU AI Act and NIST broadly share. Here is what it says, what it leaves out and why the wording matters.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
“Artificial intelligence” is used to describe everything from a chatbot to a spreadsheet macro, which makes it hard to discuss risk or compliance with any precision. Fortunately, the bodies that write rules about AI have settled on a fairly consistent definition, and it is more specific than the marketing use of the term.
This article walks through that shared definition, shows where the OECD, the EU AI Act and the US National Institute of Standards and Technology (NIST) agree and differ, and explains the one idea that separates an AI system from ordinary software.
The Shared Definition In Plain Words
In November 2023 the OECD Council revised the definition of an AI system in its Recommendation on Artificial Intelligence, first adopted in May 2019.1 Stripped to its parts, the revised version says an AI system is a machine-based system that works towards objectives, uses the input it receives to work out how to produce outputs, and produces outputs such as predictions, content, recommendations or decisions that can affect a physical or virtual environment. It also says that systems differ in how independently they operate and in whether they keep changing after they are deployed.
The EU AI Act, signed on 13 June 2024 and published in the Official Journal on 12 July 2024, uses almost the same wording in Article 3(1).2 It was amended in July 2026, but that amendment left the definition unchanged.3 Because the Act is binding law in the EU, this definition is the first test of whether a product falls inside its scope. The key phrase is that an AI system “infers, from the input it receives, how to generate outputs”.3
NIST’s AI Risk Management Framework, published in January 2023 as voluntary guidance, uses an earlier version adapted from the 2019 OECD text and from ISO/IEC 22989.4 It describes an engineered or machine-based system that generates outputs for a given set of objectives and operates with varying levels of autonomy.
Where The Definitions Line Up
The three texts share a skeleton. The differences are mostly about timing: NIST published before the OECD revision, so it lacks the newer elements that the EU later adopted.
| Element | OECD (2023 revision) | EU AI Act, Article 3(1) | NIST AI RMF 1.0 (2023) |
|---|---|---|---|
| Status | Intergovernmental recommendation | Binding EU regulation | Voluntary US guidance |
| Objectives | Explicit or implicit | Explicit or implicit | A given set of objectives |
| Infers from input | Yes | Yes | Not stated in these words |
| Outputs listed | Predictions, content, recommendations, decisions | Predictions, content, recommendations, decisions | Predictions, recommendations, decisions |
| Autonomy | Varying levels | Varying levels | Varying levels |
| Adaptiveness after deployment | Mentioned | May exhibit it | Not mentioned |
An explainer from OECD staff set out the reason for each 2023 change.5 “Implicit” objectives were added because a system can learn goals during training rather than having them written down. “Content” was added to the list of outputs so that generative AI, which produces text, images or video, is clearly covered. “Real” environments became “physical” ones, since virtual environments are real too. Adaptiveness was added to reflect systems, such as recommendation engines, that keep changing as they are used.
The Idea That Matters Most: Inference
The word doing the work in the modern definition is “infers”. Ordinary software follows rules a programmer wrote explicitly: if the invoice total is over a limit, send it for approval. An AI system works out how to turn inputs into outputs. Today that usually means applying patterns learned from data, but the EU text also counts logic-based and knowledge-based methods that reason from encoded expert knowledge. What it excludes is software that simply executes rules written entirely by people.6
A concrete comparison helps. A fraud check that blocks any card payment over 5,000 euros in a foreign currency is a fixed rule. A fraud model that scores each payment based on patterns learned from millions of past transactions is inferring, because nobody wrote down the exact conditions it uses. The first is ordinary automation. The second sits inside the definition.
Autonomy And Adaptiveness
Autonomy comes in degrees, and all three texts recognise that systems vary in how independently they act. A spam filter that labels emails for a person to review has little autonomy. A system that sends payments or changes access rights without a person in the loop has much more. AI agents, which plan and take actions on their own, sit at the high end; they are covered in AI Agents And Multi-Agent Systems.
Adaptiveness is handled differently. NIST’s definition does not mention it, while the OECD and EU texts do. The EU recitals describe it as self-learning that lets a system change while it is in use.6 A recommendation engine that updates itself from new user clicks is an example. Many deployed models are frozen and do not change at all, and the EU wording reflects this by saying a system may show adaptiveness, not that it must.
Why The Wording Matters To Your Organisation
Definitions shape scope. If a tool meets the EU definition, the AI Act’s rules for AI systems may apply to it, with obligations that depend on the use case and risk level.2 If it does not, those rules do not apply, although other law such as data protection still might. The definition is only one part of the scope question: the Act also covers general-purpose AI models separately, and it has its own territorial reach and exclusions.3 Getting the classification right is a sensible first step in any AI inventory.
A practical approach is to list each tool your organisation uses or sells and ask three questions: does it infer how to produce its outputs, what kind of output does it produce, and how independently does it act. The answers feed directly into risk assessment and governance, which are covered in AI Governance And Regulation.
Footnotes
-
OECD, “Recommendation of the Council on Artificial Intelligence”, OECD/LEGAL/0449, adopted 22 May 2019, definition revised 8 November 2023. legalinstruments.oecd.org ↩
-
European Union, “Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence … (Artificial Intelligence Act)”, Official Journal, 12 July 2024. eur-lex.europa.eu ↩ ↩2
-
Regulation (EU) 2024/1689, Articles 2 and 3(1), consolidated text of 27 July 2026 (as amended by Regulation (EU) 2026/1744), EUR-Lex. eur-lex.europa.eu ↩ ↩2 ↩3
-
NIST, AI 100-1, “Artificial Intelligence Risk Management Framework (AI RMF 1.0)”, January 2023. nvlpubs.nist.gov ↩
-
S. Russell, K. Perset and M. Grobelnik, “Updates to the OECD’s definition of an AI system explained”, OECD.AI, 29 November 2023. oecd.ai ↩
-
Regulation (EU) 2024/1689, Recital 12, Official Journal, 12 July 2024. eur-lex.europa.eu ↩ ↩2
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.