Glossary Terms

AI System

A machine-based system that produces outputs such as predictions, recommendations, content or decisions from supplied inputs.
On this page

What is an AI system?

An AI system is a machine-based system that uses supplied inputs to infer how to generate outputs such as predictions, recommendations, classifications, content or decisions. The level of autonomy can vary significantly. Some systems provide a score or suggestion for a human to consider, while others automatically trigger actions in digital or physical environments.

The term covers much more than generative AI. Examples include fraud-detection models, recommendation engines, facial-recognition tools, automated hiring systems, demand forecasts, dynamic pricing, content moderation and predictive maintenance. Whether a particular technology is treated as an AI system may depend on its technical characteristics and the definition used by the applicable law or governance framework.

What are the main components of an AI system?

An AI system normally includes a model, the data used to develop or configure it, the inputs received during operation, the infrastructure that runs it and the business process in which its outputs are used. It may also rely on external APIs, human reviewers, user interfaces, rules and post-processing steps. Risk cannot be understood by examining the model alone because the surrounding context determines how outputs affect people or operations.

A complete system record should therefore describe intended purpose, owner, provider, users, affected people, data sources, model or service version, outputs, decision authority, limitations, monitoring and dependencies. The same model can create very different risks when used in different contexts.

Why is it important to identify AI systems?

An organisation cannot govern what it has not identified. AI features are increasingly embedded in ordinary software and may be enabled through product updates without a separate procurement event. Employees can also introduce tools through free accounts or local experimentation. A central inventory helps organisations understand where AI is used and determine which privacy, security, contractual and regulatory requirements apply.

Identification also supports proportionate review. A system used to summarise internal notes may have a different risk profile from a system used to decide whether a person receives employment, insurance or healthcare. Clear classification prevents both under-governance of significant systems and unnecessary bureaucracy for low-risk tools.

How should an AI system be documented?

Documentation should include the business purpose, system boundaries, technical approach, provider, lifecycle stage, training or configuration data, operational inputs, outputs, users and affected groups. It should explain how a human uses the output, what level of automation exists and what happens when confidence is low or the system fails.

Organisations should also record performance measures, known limitations, testing results, security controls, privacy considerations, incident routes and review dates. For third-party services, documentation may rely partly on provider evidence, but the deploying organisation still needs to understand its own use and responsibilities.

Frequently asked questions

Is every algorithm an AI system?

No. Traditional rules-based software and simple calculations may not meet a legal or organisational definition of AI. The technical method, level of inference and applicable framework should be considered.

Is a spreadsheet with automated formulas an AI system?

Usually not, although a spreadsheet may connect to an AI service or contain a predictive model. The actual functionality and decision process matter more than the interface in which it appears.

Can a third-party software feature be an AI system?

Yes. AI embedded in a vendor platform should be inventoried and assessed even when the organisation did not develop the underlying model.

Who is responsible for an AI system?

The business owner is responsible for the use case and outcomes, while technical, legal, privacy, security and risk teams provide specialised controls. Responsibility should be documented rather than assigned informally.

When does an AI system leave the lifecycle?

Retirement occurs when the system is no longer used, but governance should also address deletion or retention of data, preservation of required records, removal of integrations and communication to affected users.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.