Why the definition of an AI system matters
Every obligation in the EU AI Act hangs on a question most companies skip past: is the software actually an AI system? If it is not, the Regulation does not reach it at all. There is no risk classification, no technical documentation, no transparency duty and no market surveillance exposure. If it is, the company is inside a regime with real consequences.
The error runs in both directions. Some companies assume that anything marketed as “AI-powered” must be regulated, and spend money on compliance work the law never asked for. Others assume that because their system is “just statistics” or “just business rules” the Regulation cannot touch them, then are caught out when a customer’s procurement team asks for a declaration of conformity. Getting the threshold question right, and writing down the reasoning, is cheaper than either mistake.
What Article 3(1) actually says
The definition runs to a single sentence. An AI system means “a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments”.
Two things about that sentence deserve emphasis. First, it is deliberately technology-neutral: it does not mention machine learning, neural networks or large language models. A system built with methods that predate the current wave of AI can satisfy it, and a system built with the newest methods can fall outside it. Second, it survived the Digital Omnibus untouched. Regulation (EU) 2026/1744, which entered into force on 27 July 2026 and rewrote a good deal of the AI Act, left Article 3(1) exactly as adopted in 2024. Anyone hoping the simplification package narrowed the entry point to the Regulation will be disappointed.
The Commission has published guidelines on how to apply the definition, as Article 96(1)(f) of the AI Act required it to. The adopted text is a Communication, Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act), C(2025) 5053 final, dated 29 July 2025. They are expressly not binding, and note that only the Court of Justice of the European Union can give an authoritative interpretation.
The elements the Commission works through
The guidelines break the definition into seven elements, running from “a machine-based system” through autonomy, adaptiveness, objectives and inference to outputs that influence physical or virtual environments. Three of them carry most of the weight in a borderline case.
Autonomy means some independence, not full independence
The threshold is low, and companies routinely set it too high. The guidelines state that the reference to some degree of independence of action “excludes systems that are designed to operate solely with full manual human involvement and intervention”. They then give the example that decides most cases: a system requiring manually provided inputs to generate an output by itself still has some degree of independence of action, “because the system is designed with the capability to generate an output without this output being manually controlled, or explicitly and exactly specified by a human”. A human pressing the button and reviewing the result does not take a system outside the definition.
Adaptiveness is optional
The word in Article 3(1) is “may”. Recital 12 of the AI Act explains that adaptiveness “refers to self-learning capabilities, allowing the system to change while in use”. A system trained once, frozen, and never updated in the field is still an AI system if it meets the other elements. This is the most common misunderstanding we encounter.
The capacity to infer is the real dividing line
Recital 12 calls the capability to infer “a key characteristic of AI systems”, describes it as “a capability of AI systems to derive models or algorithms, or both, from inputs or data”, and draws the boundary in one sentence: “The capacity of an AI system to infer transcends basic data processing by enabling learning, reasoning or modelling.” It also states that the definition “should not cover systems that are based on the rules defined solely by natural persons to automatically execute operations”. If every rule was written by a person and the system merely executes them, it is not inferring.
What the Commission says falls outside
The most useful part of the guidelines is a catalogue of system types that have some capacity to infer but sit outside the definition because of their limited capacity to analyse patterns and adjust their output autonomously. Systems used to accelerate or approximate traditional, well-established optimisation methods such as linear or logistic regression are one such category: they have the capacity to infer, but do not transcend basic data processing. The guidelines add that an indication a system does not transcend basic data processing “could be that it has been used in consolidated manner for many years”.
Basic data processing is the category covering most ordinary business software. Such a system “follows predefined, explicit instructions or operations” and executes tasks based on manual inputs or rules “without any ‘learning, reasoning or modelling’ at any stage of the system lifecycle”. The examples named are database management systems used to sort or filter data on specific criteria and standard spreadsheet applications without AI-enabled functionalities. Systems intended solely for descriptive analysis, hypothesis testing and visualisation are also outside. The sales-dashboard example is worth remembering: a dashboard showing total sales, average sales per region and trends over time is not an AI system, but the guidelines note carefully that it “does not recommend how to improve sales or which products to promote”. Add the recommendation and the analysis changes.
Classical heuristics are a further category, relying on rule-based approaches, pattern recognition or trial-and-error rather than data-driven learning. So are simple prediction systems: machine-based systems whose performance can be achieved via a basic statistical learning rule fall outside because of that performance, even though they may technically rely on machine learning. Predicting tomorrow’s temperature from last week’s average is the example given. A trivial baseline predictor does not become regulated merely because it was implemented with a machine learning library.
Two closing statements should govern how any company uses this catalogue. The first: “No automatic determination or exhaustive lists of systems that either fall within or outside the definition of an AI system are possible.” The second, and the one to put in front of an anxious board: “The vast majority of systems, even if they qualify as AI systems within the meaning of Article 3(1) AI Act, will not be subject to any regulatory requirements under the AI Act.”
The one definition the Omnibus did change
While Article 3(1) was left alone, the Digital Omnibus did replace the definition of “safety component” in Article 3, and for manufacturers that matters more than the AI system definition itself. The amended definition adds that “for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property”.
That ties the concept to intended purpose, and the narrowing matters because being a safety component of a regulated product is one of the routes into the high-risk regime under Article 6(1). Software sitting inside a machine, a medical device or a lift has to be read against this definition too.
Practical example
A Gothenburg logistics company sells a route planning product to Nordic hauliers. It has three components. The first solves a vehicle routing problem with a well-established optimisation solver, using a machine learning model to produce good starting solutions faster. The second is a dashboard showing fuel consumption by depot and a rolling twelve-week trend. The third scores each driver on a risk index built from telematics data and suggests who should be prioritised for retraining.
Applying the guidelines, the first component looks like an accelerated optimisation method and probably falls outside, because the machine learning element improves computational performance rather than making the decision. The second is descriptive analysis and visualisation, also outside. The third infers a risk score from data, produces a recommendation about identifiable individuals, and is plainly an AI system. So the company is a provider of an AI system, but only of one of its three components. Whether that component is also high-risk depends on Article 6 and Annex III, and driver risk scoring in an employment context is exactly the kind of use case requiring a careful look. Being able to show that reasoning is what keeps the work proportionate.
Common mistakes companies make
The first is treating marketing language as a legal classification. A product page saying “powered by AI” is not a determination under Article 3(1), and neither is a product page that carefully avoids the word. Supervisory authorities and customers will look at what the system does.
The second is assessing the product rather than the system. Most commercial software is a bundle of components with different characteristics, and the guidelines say the determination “should be based on the specific architecture and functionality of a given system”.
The third is the frozen-model argument, concluding that because a model does not learn in production it is not an AI system; adaptiveness is optional. The fourth is stopping at the definition: concluding that something is an AI system tells you almost nothing about your obligations, because most AI systems carry none. A final mistake is writing nothing down. There is no filing requirement for a negative determination, but when a customer or an authority asks, a dated one-page assessment is a very different conversation from a recollection.
Recommended actions
Start with an inventory at component level rather than product level. For each component, record what the input is, what the output is, whether a person specified every rule that produces the output, and whether the system derives its model or algorithm from data. That record answers the Article 3(1) question in most cases, and where it does not, it isolates the difficult ones so advice can be targeted. Keep the assessments dated and revisit them when a component changes materially, because a rules engine that acquires a learned scoring model has changed its classification.
For the components that are AI systems, move straight to the risk question rather than assuming the worst. Check Article 5 first, then Article 6 and Annex III, then the Article 50 transparency rules, which have applied since 2 August 2026 and were not deferred. For components embedded in products covered by EU product legislation, read the amended safety component definition carefully, because the intended-purpose clause may take a component out of Article 6(1) that would previously have been caught.
Frequently asked questions
Did the Digital Omnibus change what counts as an AI system?
No. Article 3(1) was not amended by Regulation (EU) 2026/1744 and remains as adopted in 2024. The Omnibus did replace the definition of “safety component” in the same article, but the definition of an AI system itself is unchanged.
Are the Commission’s guidelines on the definition binding?
No. The guidelines state expressly that they are not binding and that any authoritative interpretation of the AI Act may ultimately only be given by the Court of Justice of the European Union. In practice they remain the reference point that authorities, customers and advisers will use, so a company departing from them should be able to explain why.
If our system is an AI system, does that mean we have compliance obligations?
Usually not, or not many. The guidelines state that the vast majority of systems qualifying as AI systems will not be subject to any regulatory requirements under the AI Act. Obligations attach to prohibited practices under Article 5, to high-risk systems under Article 6, to certain systems under Article 50, and to general-purpose AI models.
Conclusion
The definition in Article 3(1) is short, technology-neutral and unchanged by the Digital Omnibus, and it is the gate through which every other obligation in the AI Act has to pass. The Commission’s guidelines make that gate navigable: they name the categories of software that sit outside and say plainly that most AI systems carry no requirements at all. What they cannot do is make the assessment for you. That has to be done component by component, and it has to be recorded.
Lawgent helps businesses assess whether their software falls within the EU AI Act’s definition of an AI system and document the classification decision.