Artificial Intelligence (AI)

Artificial Intelligence (AI) refers to computer systems designed to perform tasks that typically require human intelligence, including perception, reasoning, learning, decision-making, and language understanding.

What AI Actually Covers

The term AI covers a wide range of technologies with very different capabilities and risk profiles. Traditional machine learning models trained for narrow tasks (fraud detection, image classification) are AI. Large language models capable of generating text and reasoning across topics are AI. Autonomous agents that plan, decide, and act are AI. So are the rule-based expert systems that predate the current wave.

Governance and risk work has to distinguish between these categories, because the controls appropriate for a narrow classifier are not the controls appropriate for a general-purpose LLM or an agentic system.

Why the Legal Definition Matters

Regulatory frameworks now define AI in legally binding terms. The EU AI Act, in Article 3(1), defines an AI system in specific terms that determine which systems fall under regulatory scope. The NIST AI RMF uses a similar but distinct definition. Organizations subject to these regulations need to determine which of their systems meet the legal definition, not just which are colloquially called "AI."

AI as an Enterprise Category

For enterprise risk purposes, AI is best thought of as a category of systems that share three characteristics: they produce outputs or decisions based on learned patterns rather than deterministic rules, their behavior can change with new inputs or updated models, and their outputs can materially affect people, decisions, or business processes.

Those three characteristics are what make AI a distinct governance category, requiring the range of controls captured across this glossary.

Related Terms

Full AI Visibility. Full Control. One Connected Platform.

Enterprise AI is expanding faster than most governance programs can track. Kovrr connects every AI signal across browser, endpoint, network, identity, and vendor systems into a single platform so security, governance, and risk teams work from the same evidence.