In our last piece we explored why the world has struggled to agree on what artificial intelligence actually is. A reasonable response is: so what? If philosophers, regulators, and standards bodies can’t settle it, why should a business leader spend time on it?
Because whether you write it down or not, your organization is already operating on a definition of AI. It’s embedded in your policies, your procurement questionnaires, your customer contracts, and your board updates. When that definition is implicit, every one of those documents may quietly mean something different — and the gaps between them are where obligations get missed and risk goes unowned.
KEY TAKEAWAYS
01
Your definition of AI decides scope — which systems your policies, contracts, and regulatory obligations actually cover.
02
Regulators, customers, and insurers each work from different definitions — the gaps between them are where risk hides.
03
You don’t need the perfect definition. You need a documented one that your organization applies consistently.
Consider the practical questions an organization has to answer as it adopts AI. Which systems belong in our AI inventory? Which projects need extra review before launch? Which vendor tools trigger our AI clauses? Which disclosures do we owe customers or regulators? Every one of those questions begins the same way: it depends on what counts as AI. NIST’s AI Risk Management Framework and ISO/IEC 42001 both reinforce the importance of defining scope, context, intended use and organizational responsibilities before risk can be managed consistently.⁴,⁵
Draw the boundary too narrowly and systems escape oversight — the recommendation engine nobody labelled “AI,” the vendor tool with a model quietly embedded inside it. Draw it too broadly and every spreadsheet macro lands in your governance process, and the process collapses under its own weight. The definition is not a preamble to the real work. It is one of the controls that determines what the real work applies to.
The bodies that can hold you accountable do not all define AI in the same way — because they are not all trying to answer the same question. The OECD’s definition establishes what counts as an AI system for the purposes of its AI Recommendation.¹ The EU AI Act defines AI for a regulatory regime and then applies requirements according to factors including the use, the organization’s role and the level of risk.² ISO/IEC 22989 provides common AI concepts and terminology intended to support consistent understanding across different stakeholders.³ NIST’s AI Risk Management Framework, meanwhile, takes the discussion into risk management, helping organizations understand and manage AI in the context in which it is actually developed, deployed or used.⁴
Your contracts may add another layer. A customer’s procurement team may define AI more broadly in an AI addendum; a supplier may use a narrower definition in its terms; and an insurer may define it differently again in an exclusion or coverage clause. The same system can therefore fall inside the scope of one obligation and outside another. A forecasting model might not trigger a particular regulatory requirement but still fall within a customer’s contractual AI provisions or your own governance framework. None of those definitions necessarily has to be wrong. They may simply be answering different questions — and if nobody in the organization is looking at them together, the gaps between them can become unmanaged risk.
A QUICK TEST
Could someone in your organization say, with confidence, whether a given system is ‘AI’ under your policy?
Would your customer’s contract — or your regulator’s definition — agree with that answer?
If you were asked for your AI inventory tomorrow, would the boundary you drew be defensible?
If you’re working through these questions in your own organization, Orelia can help. Our AI Governance Framework is developed with reference to the NIST AI Risk Management Framework and leading international standards including ISO/IEC 42001, ISO/IEC 23894 and ISO/IEC 42005. We help leadership teams define the governance perimeter, establish proportionate guardrails, and put in place the decision rights, controls and oversight needed to use AI with greater confidence.




