Artificial intelligence is often described in broad, sometimes vague terms. For organisations trying to govern AI or work toward ISO 42001, that is a problem: if you cannot say clearly what “AI” is in your context, it is very hard to govern it.
In this insight, we use a practical definition of artificial intelligence that you can apply inside your organisation, then show how that definition connects to governance, risk, and management-system work.
A practical definition of artificial intelligence
There are many formal definitions of artificial intelligence, but most share a common core. At a high level, artificial intelligence refers to computer systems that perform tasks that normally require human intelligence, such as learning, reasoning, problem-solving, perception, or decision-making.
The UK Information Commissioner’s Office (ICO) describes AI as an umbrella term for a range of algorithm-based technologies that solve complex tasks by carrying out functions that previously required human thinking. ISO similarly notes that AI systems analyse large datasets, recognise patterns, and make decisions or predictions in ways that go beyond simple automation.
For governance purposes, that gives us a working definition:
Artificial intelligence refers to systems that use algorithms and data to perform complex tasks or make decisions that would normally require human judgement, learning, or pattern recognition.
This definition is deliberately broad enough to include current AI technologies, but focused enough that it is clear we are talking about more than basic rules and scripts.
How AI differs from simple automation
Not every piece of software is “AI.” Distinguishing AI from simpler automation is useful when you are deciding what should fall under AI governance and what should remain under normal IT or process controls.
Simple automation typically:
- follows fixed, pre-defined rules;
- does not adapt based on data;
- does not change behaviour unless humans change the rules.
By contrast, AI systems typically:
- learn from data and experience, or adapt their behaviour based on inputs;
- handle complex or ambiguous tasks, such as recognising patterns or interpreting language;
- can make recommendations or decisions without a human specifying every step in advance.
That does not mean simple automation is risk-free or outside governance. But it does mean that AI often introduces different kinds of risk and uncertainty, which is why standards such as ISO 42001 focus on AI-specific governance rather than treating all software as the same.
Types of artificial intelligence
Definitions of AI usually distinguish between different types or levels of capability. Although the terminology varies, three categories appear frequently in authoritative sources.
-
Artificial Narrow Intelligence (ANI)
AI systems designed for a specific task or narrow set of tasks, such as image classification, fraud detection, or language translation. These are the systems in widespread use today. -
Artificial General Intelligence (AGI)
Hypothetical systems capable of understanding and performing any intellectual task that a human can, across many domains. This level of AI remains theoretical and does not exist in practice today. -
Generative AI
AI models that generate new content (text, images, code, audio, video) based on patterns learned from training data. They are a form of narrow AI with distinctive capabilities and risks, particularly around outputs, explainability, and misuse.
For most organisations, current governance questions centre on narrow and generative AI systems, not AGI. However, being clear about the type of AI you are dealing with is important when you define scope and risk.
Why a clear definition matters for governance
Whether you are working under ISO 42001, internal AI policies, or regulatory expectations, you need to be able to answer basic questions such as “which of our systems count as AI?” and “where does our AI Management System apply?”.
A clear, agreed definition of AI helps you:
- identify which systems and use cases fall under AI governance;
- avoid blind spots where AI is used informally or embedded in third-party tools;
- communicate consistently with stakeholders, regulators, and certification bodies;
- make sure your AI risk assessments and controls focus on the right things.
Without that clarity, there is a risk of either over-scoping (treating all automation as AI) or under-scoping (ignoring important AI use cases), both of which create governance problems.
How this connects to ISO 42001
ISO/IEC 42001:2023 is the international standard for Artificial Intelligence Management Systems. It assumes that organisations can identify which systems and activities are “AI” in their context, because that is the starting point for defining scope, roles, risks, and controls.
In practice, that means:
- documenting how your organisation defines AI;
- agreeing which systems, services, and use cases meet that definition;
- using that understanding to define the scope of your AI Management System (AIMS);
- aligning risk assessment, controls, monitoring, and review to those in-scope AI systems.
A good definition does not need to be perfect or universal. It needs to be clear, defensible, and useful for the decisions your organisation has to make.
Questions to ask inside your organisation
If you are at the stage of trying to define AI internally, useful questions include:
- Where do we have systems that learn from data or adapt their behaviour over time?
- Where are we using models, algorithms, or tools to support or automate decisions?
- Where do those systems materially affect customers, employees, regulated activity, or strategy?
- Which of those systems would external stakeholders reasonably expect us to treat as “AI”?
Working through those questions with stakeholders across technology, risk, legal, and the business can help turn abstract AI debates into a practical scope for governance and assurance.
Where Viritux fits
At Viritux, we help organisations move from abstract definitions of AI to a scoped, practical view of where AI is used and how it should be governed. That is often the first step in designing an AI Management System or running an ISO 42001 gap analysis.
If you are beginning to define what “AI” means in your organisation, or want to understand how that definition feeds into ISO 42001 and broader governance, our ISO 42001 consultancy page sets out how we support AI governance design and readiness.