Every substantive obligation in an AI statute is preceded by a definition, and almost every genuine dispute about whether an organisation is in scope turns on that definition rather than on the obligations themselves.
The formulation that spread
The OECD's definition — a machine-based system that infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments — has been adopted with modification into subsequent binding regimes, including the EU AI Act.
It was written to be technology-neutral, so that a statute would not be obsoleted by an architecture nobody had thought of. That was the right choice and it has a direct consequence: the definition is broad, and it does not distinguish between a frontier model and a logistic regression that has been in production since 2009.
Where the boundary actually gets argued
Two elements carry the weight. The first is inference: does the system derive how to produce its output from data, or does it apply rules a person specified? The second is autonomy: does it operate with some independence from human involvement, and how much is some?
A rules engine written by hand is generally outside. A model fitted to data is generally inside. The interesting cases are hybrids, which is most enterprise software of any age — a scoring system with learned weights and hand-tuned overrides sits precisely on the line.
The statistical software problem
On a literal reading, a great deal of conventional statistical and optimisation software falls inside these definitions. Regulatory practice has generally not treated it that way, and recitals and guidance have been used to narrow the reading. That gap between text and practice is uncomfortable: it means scope depends on interpretive material rather than on the operative provision, and interpretive material carries less weight in a dispute.
Why drift between jurisdictions matters more than differing rules
An organisation can manage different obligations across jurisdictions. Managing different scope is harder, because it means the same system is a regulated AI system in one place and ordinary software in another, and the inventory that underpins every compliance programme has to record which.
Organisations operating across several regimes generally end up adopting the broadest definition they face and applying it everywhere, for the same reason they adopt the strictest substantive requirement — maintaining jurisdiction-specific classification of the same system is more expensive than over-including.