Definition: AI System (EU AI Act)
An AI system, under Article 3(1) of the EU AI Act, is a machine-based system that operates with varying levels of autonomy, may adapt after deployment, and infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that influence physical or virtual environments.
Core characteristics of AI system
The definition names an effect, not a technique, so machine learning models, rule-based expert systems, and hybrid architectures can all qualify.
- Infers from input rather than executing fixed, human-written instructions
- Machine-based, covering software on conventional or specialized hardware
- Operates with some autonomy from step-by-step human control
- May adapt after deployment, though adaptiveness is not required
AI system vs. traditional software
A traditional script follows rules written in advance and produces the same output every time. An AI system instead derives how to produce an output rather than being told exactly how. A spreadsheet formula summing invoice totals is traditional software; a tool that reads an invoice image, infers the vendor and due date, and flags anomalies is an AI system. The Commission’s February 2025 guidelines confirm this line, excluding basic data processing, classical heuristics, and simple statistical benchmarking.
Importance of AI system in enterprise AI
Every other obligation in the Act, provider duties, deployer duties, risk classification, only attaches once a tool clears this gate. Bitkom’s KI-Studie 2026 found 41% of German companies now use AI productively, up from 20% in 2024, but 85% of SMEs still have no documented AI inventory of which tools meet the Article 3(1) test.
Methods and procedures for AI system
Three steps turn the legal definition into a repeatable classification process.
Element-by-element scope test
Each candidate tool is checked against the definition’s components in sequence, rather than judged by vendor marketing.
- Does the system infer an output, or execute a fixed rule set?
- Does it run with some autonomy, or does a human control every step?
- Does its output feed a decision, recommendation, prediction, or content?
Cross-checking against the Commission’s exclusion list
Where a tool sits close to the line, teams compare it against the Commission’s examples: pure optimization, basic data processing, classical heuristics, and simple statistics are excluded, while logic-, knowledge-, or learning-based inference is in scope.
Linking classification to role and risk tier
Once a tool qualifies as an AI system, the next question is who holds duties for it. A company that builds or substantially modifies the system is typically the AI provider; the company using it under its own authority is the AI deployer. The system is then checked against the high-risk AI system criteria, or the general-purpose AI model definition if it is a foundation model.
Important KPIs for AI system
Classification work is tracked with metrics that show progress and gaps.
Inventory completeness metrics
- Screening coverage: percentage of tools assessed against Article 3(1)
- Classification backlog: tools awaiting a scope decision
- Re-screening cadence: tools reassessed after major changes
Strategic readiness metrics
Leadership should track how classification effort scales as tool count grows. Gartner reports AI governance now consumes 8-12% of the average enterprise AI budget in 2026, up from 3-5% in 2024.
Quality and accuracy metrics
A mature process produces consistent results when different staff review the same tool, and flags disagreements for escalation instead of leaving them unresolved.
Risk factors and controls for AI system
Getting the scope question wrong carries consequences in both directions.
Misclassifying scope in either direction
Under-scoping leaves genuine AI systems undocumented; over-scoping burns budget on plain automation that never needed it.
- Shadow AI tools adopted by individual teams without central review
- Vendor tools marketed as “AI-powered” that are really rule-based automation
Inconsistent classification across teams
Without a shared test, one department may treat a forecasting spreadsheet as out of scope while another flags an equivalent tool as an AI system, producing an inventory nobody trusts.
Treating classification as a one-time exercise
Vendors add AI features to existing products continuously, so a tool classified as traditional software last year can cross into AI system territory after an update.
Practical example
A 65-employee specialty chemicals distributor in Bavaria ran its first AI compliance sweep after learning several departments had adopted tools independently, from a demand-forecasting add-on to a supplier-email triage bot. A two-week sprint applied the Article 3(1) test to every shortlisted tool, confirmed which qualified as AI systems, and logged the rest as traditional automation with a documented rationale.
- Central spreadsheet listing every candidate tool with its scope decision
- Named owner per department responsible for flagging new tools
- Quarterly re-screening tied to the software update calendar
Current developments and effects
Regulatory guidance on the AI system definition is still settling into practice.
Commission guidelines closing edge cases
The Commission’s February 2025 guidelines resolved recurring questions, including whether autonomy requires full independence from humans.
- Systems designed for full manual human control fall outside the definition
- Adaptiveness after deployment is confirmed as optional, not required
Digital Omnibus and the broader compliance timeline
The Digital Omnibus package under discussion through 2026 has focused mainly on high-risk deadlines, leaving the core scope test unchanged.
Growing demand for automated classification tooling
As AI inventories grow past dozens of tools, more Mittelstand companies look for lightweight classification support instead of running the test manually each time.
Conclusion
The AI system definition looks abstract, but it is the practical starting point for every other EU AI Act obligation a company will face. A tool that clears the Article 3(1) test can carry provider, deployer, high-risk, or GPAI duties; a tool that does not clear it stays outside the regulation entirely. Companies that build a disciplined, repeatable classification process now avoid discovering gaps during an audit or a customer’s due-diligence questionnaire. As vendors keep adding inference-based features to ordinary software, that process will only matter more.
Frequently Asked Questions
What exactly counts as an AI system under the EU AI Act?
A machine-based system that infers from its input how to generate outputs such as predictions, recommendations, content, or decisions, per Article 3(1). It covers machine learning models and inference-based rule systems, but not simple automation.
Does an Excel macro or a basic RPA bot count as an AI system?
Usually not. The Commission’s February 2025 guidelines exclude basic data processing and classical heuristics that follow pre-defined rules without inference, though an RPA bot that adds an inference step can cross the line.
Does this classification question matter for a company with only 60 or 80 employees?
Yes. Article 3(1) applies regardless of size, and smaller firms often carry more undocumented shadow AI tools per employee because adoption happens team by team.
How does the AI system definition connect to the EU AI Act’s risk categories?
Classification as an AI system is the entry gate. Once a tool qualifies, it is checked against the high-risk criteria and, for foundation models, the general-purpose AI model rules.
Do we need outside help to classify our tools, or can our own IT team do it?
Many Mittelstand IT teams can run the test themselves with a clear checklist, though borderline cases involving vendor-embedded AI features often benefit from a second opinion from legal counsel or a compliance partner.
How does this connect to how Superkind builds AI agents for customers?
Superkind builds and documents its AI agents centrally, so customers deploying them do not each run their own Article 3(1) classification from scratch.