There is a statutory definition of an AI system, and it has applied across the European Union since 2 February 2025.
By that definition, almost anything shipping with a language model inside qualifies, which is a scoping result rather than a compliment.
What makes the definition useful is the set of things it throws out.
Those exclusions are far more specific than anything the hype argument has produced in a decade.
Article 3(1) of the EU AI Act defines an AI system as a machine-based system that operates with varying levels of autonomy, may adapt after deployment, and infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
The European Commission’s guidelines split that sentence into seven elements and identify the one carrying the weight.
The capacity to infer is described there as a key and indispensable condition, the thing that separates an AI system from other software.
Adaptiveness is optional.
A frozen model that never learns anything after deployment still qualifies because the statutory word is "may."
The Commission’s guidelines name categories of software that sit outside the definition, and the list is unkind to a fair amount of what currently ships with an AI label.
Systems using machine learning to accelerate mathematical optimization, including linear and logistic regression, are out.
So is basic data processing: database sort-and-filter, ordinary spreadsheets, computing an average from survey responses.
So are descriptive dashboards that summarise and visualize without recommending anything, classical heuristics such as a chess engine running minimax, and simple prediction systems whose performance a basic statistical rule could match.
Then the inversion.
The same guidelines name expert systems, knowledge bases, and symbolic reasoning as inference-enabling techniques, so a rule engine designed in 1985 satisfies the definition, while a 2026 analytics dashboard does not.
The line is drawn at derivation.
A system that determines how to produce its output falls inside; a system that executes a procedure a person wrote down falls outside.
Retrieval plus a foundation model plus an orchestration scaffold is inference under the definition, and the number of components between the query and the answer changes nothing.
The statute is indifferent to architecture and interested only in if the output was derived.
That reading dismantles both of the industry’s favorite moves.
Calling something a wrapper no longer excludes it from the category, and calling something real AI no longer distinguishes it from anything else in the category.
The engineering question that survives classification is the one worth asking regardless: when the output is wrong, which component produced the error, and more importantly, can anyone outside the system tell?
My read is that most teams can answer the first, and very few can answer the second.
American regulators approached the same subject from the opposite direction, declining to define artificial intelligence at all and instead testing if firms could substantiate their claims about it.
On 18 March 2024, the Securities and Exchange Commission settled its first two AI-washing cases against the investment advisers Delphia and Global Predictions for a combined $400,000 in civil penalties.
Neither order rules on whether the technology involved would have counted as AI had it existed.
The finding is narrower and much harder to argue with: the advisers described capabilities they did not have.
The Federal Trade Commission landed on the same standard for consumer protection.
Announcing Operation AI Comply in September 2024, then-chair Lina Khan said the enforcement actions made clear there is “no AI exemption from the laws on the books.”
Europe scopes by classification; the United States scopes by evidence.
Between the two, there is no version of the question that a product team gets to leave open.
The expensive obligations moved, and the definition did not.
Under the Digital Omnibus on AI, agreed politically on 7 May 2026 and confirmed by the Council at the end of June, high-risk obligations for stand-alone Annex III systems now apply from 2 December 2027, and for AI embedded in regulated products from 2 August 2028.
The definition has been live since February 2025, and the AI Act’s transparency rules take effect on 2 August 2026.
Classification is therefore due well before the requirements that make classification consequential.
The Commission is unusually direct about what most of that classification yields.
The vast majority of systems meeting the definition will carry no regulatory requirement under the Act whatsoever, and the guidelines add that no automatic determination is possible and no exhaustive list exists.
So the reasoning has to be done by a person, written down, and kept; a determination that was never recorded is indistinguishable, a year later, from one that was never made.
The hype was never really located in the word.
It sat in the sentences attached to the word, on the product page and the earnings call and the pitch deck, and those are the sentences now being read against evidence.
If a system infers that a question is about architecture with a checkable answer, and if the claim on the page can be substantiated, then it is a question of record-keeping, and I suspect that is where most of the concern over the next few years will come from. Thanks for taking the time to read my article!
I hope my posts offer you a new perspective on technology that you can apply in a positive way to your daily workflow and life.
Follow and subscribe to me here on Medium, and connect with me on LinkedIn if you want to add me to your network.
Best Regards,
The Definition of AI Is Now a Compliance Question With a Written Answer was originally published in Stackademic on Medium, where people are continuing the conversation by highlighting and responding to this story.