Paper deep dive
Defining AI Models and AI Systems: A Framework to Resolve the Boundary Problem
Yuanyuan Sun, Timothy Parker, Lara Gierschmann, Sana Shams, Teo Canmetin, Mathieu Duteil, Rokas GipiĆĄkis, Ze Shen Chin
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 92%
Last extracted: 7/20/2026, 8:18:46 PM
Summary
This paper addresses the lack of clear definitions for 'AI model' and 'AI system' in emerging regulations like the EU AI Act. Through a systematic review of 896 academic papers and 80+ regulatory documents, the authors analyze existing definitions, tracing their lineage to OECD frameworks and Russell & Norvig's textbook. They identify that while 'AI system' definitions are abundant, 'AI model' definitions are sparse and often derivative. The paper proposes conceptual and operational definitions: an AI model consists of trained parameters and architecture, while an AI system comprises the model plus additional components like input/output interfaces. These definitions aim to resolve boundary ambiguities affecting regulatory obligations for providers and deployers.
Entities (9)
Relation Signals (10)
AI System â comprises â AI Model
confidence 98% · systems consist of the model plus additional components
AI Model â consistsof â Architecture
confidence 95% · models consist of trained parameters and architecture
AI Model â consistsof â Trained Parameters
confidence 95% · models consist of trained parameters and architecture
EU AI Act â distinguishesobligationsfor â AI Model
confidence 95% · the EU AI Act distinguishes providers and deployers for both AI models and AI systems
EU AI Act â distinguishesobligationsfor â AI System
confidence 95% · the EU AI Act distinguishes providers and deployers for both AI models and AI systems
AI System â includescomponent â Interface
confidence 95% · systems consist of the model plus additional components including an interface for processing inputs and outputs
Italian Data Protection Authority â banned â ChatGPT
confidence 92% · Italian Data Protection Authority banning ChatGPT from operating in Italy
Clearview AI â developed â AI facial recognition system
confidence 90% · Clearview AI, a US company that developed an AI facial recognition system
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Emerging AI regulations assign distinct obligations to different actors along the AI value chain (e.g., the EU AI Act distinguishes providers and deployers for both AI models and AI systems), yet the foundational terms "AI model" and "AI system" lack clear, consistent definitions. Through a systematic review of 896 academic papers and a manual review of over 80 regulatory, standards, and technical or policy documents, we analyze existing definitions from multiple conceptual perspectives. We then trace definitional lineages and paradigm shifts over time, finding that most standards and regulatory definitions derive from the OECD's frameworks, which evolved in ways that compounded rather than resolved conceptual ambiguities. The ambiguity of the boundary between an AI model and an AI system creates practical difficulties in determining obligations for different actors, and raises questions on whether certain modifications performed are specific to the model as opposed to the non-model system components. We propose conceptual definitions grounded in the nature of models and systems and the relationship between them, then develop operational definitions for contemporary neural network-based machine-learning AI: models consist of trained parameters and architecture, while systems consist of the model plus additional components including an interface for processing inputs and outputs. Finally, we discuss implications for regulatory implementation and examine how our definitions contribute to resolving ambiguities in allocating responsibilities across the AI value chain, in both theoretical scenarios and case studies involving real-world incidents.
Tags
Links
- Source: https://arxiv.org/abs/2603.10023v2
- Canonical: https://arxiv.org/abs/2603.10023v2
Trouble viewing inline? Open PDF directly â
Full Text
248,182 characters extracted from source content.
Expand or collapse full text
DEFINING AI MODELS AND AI SYSTEMS: A FRAMEWORK TO RESOLVE THE BOUNDARY PROBLEM Yuanyuan Sun 1 Timothy Parker 7 Lara Gierschmann 7 Sana Shams 2 Teo Canmetin 3 Mathieu Duteil 7 Rokas GipiĆĄkis 4,5 Ze Shen Chin 4,6â 1 AI Governance Exchange 2 University of British Columbia 3 Oxford Internet Institute, University of Oxford 4 AI Standards Lab 5 Vilnius University 6 Oxford Martin AI Governance Initiative 7 Independent March 18, 2026 ABSTRACT Emerging AI regulations assign distinct obligations to different actors along the AI value chain (e.g., the EU AI Act distinguishes providers and deployers for both AI models and AI systems), yet the foundational terms AI model and AI system lack clear, consistent definitions. Through a systematic review of 896 academic papers and a manual review of over 80 regulatory, standards, and technical or policy documents, we analyze existing definitions from multiple conceptual perspectives. We then trace definitional lineages and paradigm shifts over time, finding that most standards and regulatory definitions derive from the OECDâs frameworks, which evolved in ways that compounded rather than resolved conceptual ambiguities. The ambiguity of the boundary between an AI model and an AI system creates practical difficulties in determining obligations for different actors, and raises questions on whether certain modifications performed are specific to the model as opposed to the non-model system components. We propose conceptual definitions grounded in the nature of models and systems and the relationship between them, then develop operational definitions for contemporary neural network-based machine-learning AI: models consist of trained parameters and architecture, while systems consist of the model plus additional components including an interface for processing inputs and outputs. Finally, we discuss implications for regulatory implementation and examine how our definitions contribute to resolving ambiguities in allocating responsibilities across the AI value chain, in both theoretical scenarios and case studies involving real-world incidents. 1 Introduction The effective regulation of AI requires clear definitions for the terms contained within said regulation. This makes it easier to consistently enforce the regulation, while also providing clarity to AI developers regarding their responsibilities. Clarifying definitions allows for more meaningful academic and public discussion on this increasingly important subject. Two particularly fundamental definitions are AI model and AI system. Therefore, it is our intention to provide a thorough survey and categorisation of the existing definitions, along with a discussion of our findings and recommendations for the most important considerations when selecting which definitions to use. â Corresponding author: zeshen@aistandardslab.org arXiv:2603.10023v2 [cs.CY] 16 Mar 2026 A PREPRINT The importance of clear definitions around AI has already been demonstrated multiple times in the real world. One example is the AlienChat dispute in China, where developers of the application were convicted for producing obscene materials (Zhang, 2026). In this case, the court decided that the fault lies with the developer of the system and not the underlying model, as the system-level components were found to have elicited this behavior. Another example is the 2023 case of the Italian Data Protection Authority banning ChatGPT from operating in Italy, citing the failure to follow General Data Protection Regulation (GDPR) in the collection and processing of the personal data used to train the GPT-3.5 model (the model powering ChatGPT at the time) (Italian Data Protection Authority, 2023a). While service was reinstated after OpenAI implemented additional disclosure mechanisms (Italian Data Protection Authority, 2023b), it highlighted a potential regulatory gap whereby restrictions were imposed at the system level (ChatGPT as a service), yet the relevant data may have already embedded within the model itself, beyond the scope of the imposed remedies. A third example is the case of Clearview AI, a US company that developed an AI facial recognition system trained on up to three billion images (Jung and Kwon, 2024). Regulators argued that this system violated privacy rights, while Clearview responded that the facial recognition algorithm and the database of embeddings were separate technical components, making the algorithm a neutral backend model distinct from the data itself. As a result, Clearview was able to continue operating in most of the US, but not in the EU, Canada or Australia. While these jurisdictional outcomes were driven primarily by differences in privacy law frameworks, they also illustrate the kind of definitional ambiguity surrounding systems and models that this paper addresses. These case studies are discussed in more detail in Section 5.6 where we illustrate how our proposals may contribute towards resolving these cases. Our review reveals that the definitional landscape for AI model and AI system is characterised by a concentrated chain of influence. The majority of regulatory and standards definitions trace back to a small number of foundational sources, most notably Russell and Norvigâs textbook, Artificial Intelligence: A Modern Approach 3rd Edition (Russell and Norvig, 2009), and Scoping the OECD AI Principles (OECD, 2019a). While this convergence has facilitated a degree of international harmonisation, it has also propagated ambiguities. Furthermore, it appears definitions of AI system are relatively well-developed and numerous, appearing across regulatory instruments ranging from the EU AI Act to ISO standards and NIST frameworks. In contrast, definitions of AI model remain sparse, fragmented, and often purely derivative, defined only in relation to systems or through specific subtypes such as general-purpose AI models without a clear base definition. This imbalance reflects the historical focus of governance discourse on system-level considerations, yet it creates practical difficulties as regulatory frameworks (such as the EU AI Act) seek to assign distinct obligations to model providers and system providers. The rapid pace of AI development has further complicated definitional efforts. Terms that were developed to describe classical agent architectures or early machine learning systems strain under application to modern foundation models and large language models (LLMs). The very word model carries semantic baggage from its origins in representing external phenomena. This framing fits poorly with current frontier LLMs, which are not obviously models of anything in the traditional sense (particularly post-fine-tuning). This paper addresses these challenges through a systematic examination of existing definitions and using what we have learned to propose our own improved definitions. We aim to serve multiple audiences: policymakers seeking to draft or interpret AI legislation, standards bodies working toward international harmonisation, technical and legal teams of AI developers seeking clarity on their compliance obligations, and researchers engaged in discourse on AI governance including those involved in the interpretation of case law. We recognise that effective definitions must be administrable by and comprehensible to non-specialists, while remaining coherent with how the technical community understands and uses these terms. The remainder of this paper is organised as follows. In Section 2 (Related Work), we review prior scholarship on AI terminology and definitions, situating our contribution within the existing literature. Section 3 (Methods) describes our dual approach combining a systematic literature review of academic sources with a manual review of regulatory and standards documents across major jurisdictions. In Section 4 (Findings and Analysis), we gather the results of these reviews, including a survey of existing definitions from intergovernmental organisations, standards bodies, governmental actors, and NGOs, and provide an analysis of conceptual perspectives that organise definitions according to their underlying characterisations of models and systems. Subsequently, we describe shifting paradigms and examine how definitions have evolved over time, analyze the observed chain of influence across definitions, and identify key inconsistencies in foundational frameworks. Section 5 (Developing definitions for AI models and AI systems) presents our proposed conceptual and operational definitions, along with criteria for evaluating definitional quality and the challenges inherent in drawing boundaries between models and systems, as well as consider the implications of our proposals for regulatory implementation and examine case studies illustrating model-system boundary disputes. Section 6 (Limitations) acknowledges constraints on our analysis and remaining areas of ambiguity. Finally, Section 7 (Conclusion) summarises our contributions and identifies directions for future work. 2 A PREPRINT 2 Related Work To the best of our knowledge, there is no previous work that systematically surveys the different definitions of AI models and systems. However, there are a number of works that are related to our paper through providing reviews of related terms, or discussing the importance of clear terminology around AI. Note that works that simply present definitions of AI models or AI systems without substantial analysis will be surveyed in Section 4 (Findings and Analysis). Maas (2023) provides a comprehensive overview of many important terms and concepts related to the governance of advanced AI, alongside a taxonomy and preliminary analysis. He discusses three different purposes for seeking definitions of AI (technological, sociotechnical, and regulatory), the importance of such terminology in shaping AI policy and law, and then reviews a total of 101 definitions across 69 terms relevant to advanced AI. Finally, he reviews various concepts within AI governance. However, he does not provide definitions of AI model or AI system, though he does define more specific terms such as general-purpose AI system and foundation model. These terms were also missing in other taxonomies and overviews of definitions that we surveyed (Bandi et al., 2025; Mukhamediev et al., 2022; MĂŒller et al., 2021; Sposato, 2025; Triguero et al., 2024). Murdick et al. (2020) discuss the importance of clear definitions around AI, and propose key principles for writing such definitions, and present a definition of AI research that leverages judgments from AI experts using machine learning. They also discuss the implications of their definition for our understanding of the state of international AI competition. FernĂĄndez-Llorca et al. (2025) provide an interdisciplinary analysis of the terms and definitions used in official documentation around the EU AI Act (whereas our work surveys a broader set of literature), particularly the terms AI system, general-purpose AI system, foundation model and generative AI. They also address the distinction between AI system and AI model briefly, but do not discuss in detail the boundaries between the two. They also highlight the importance of making definitions accessible to both AI experts and lawyers in order for legislation to be effective. In a similar vein, Trincado CastĂĄn (2024) charts the history of the EU definition of AI system, including the debate over whether the definition should be âbroadâ (any techniques considered to be AI plus other software) or ânarrowâ (only specific techniques) and how the definition evolved during the legislative process of the AI Act. He also surveys definitions from other sources, including the US, China and the OECD. Tomi Ì c and Ć timac (2025) argue that the definition of AI system used in the EU AI Act is primarily a conceptual definition, and is thus insufficient for effective AI regulation in practice. As a complement to the current conceptual definition, they present an operational definition of AI systems, focusing on the immutable features that any AI system would be expected to possess: decision models, data, and an interface. They also discuss a number of areas where current EU AI regulation could be amended in light of their work. Similarly, Burden et al. (2025) provide a framework for identifying whether models qualify as general-purpose AI (GPAI) models based on their capabilities and generality. The framework is based on four core components of general- purpose models: attention and search, comprehension and compositional expression, conceptualisation, learning and abstraction; and quantitative and logical reasoning. They give examples of their framework with empirical cases from existing models, and make policy recommendations for thresholds and metrics when categorising GPAI models. Krafft et al. (2019) also highlight the dangers of ambiguous definitions around AI, and compare the definitions favoured by AI researchers and policymakers. They find that the definitions of AI researchers emphasise technical functionality, while those of policymakers use comparisons to human thinking and behavior. Finally, both Algorithm Audit (2025) and the European Commission (2025a,b) have provided guidelines for the implementation of the EU AI Act focusing on the definition of an AI system, demonstrating demand for clarity on this topic. 3 Methods First, the literature review was conducted in two ways: a manual review and a systematic literature review (SLR). Completing a manual review of the literature ensured that important papers in the legislative context were included, while the SLR allowed for the inclusion of academic findings and discussions on existing definitions, capturing both well-established definitions as well as variations across more domain-specific research. Next, we analysed the conceptual perspectives of these definitions, and traced how past sources have influenced later definitions. Finally, we outline the approach taken to propose our own definitions. 3 A PREPRINT 3.1 Manual Review of Global Regulatory and Standards Documents Alongside the SLR, we conducted a manual review of how âAI systemâ and âAI modelâ are defined across government documents, regulations and policy documents. These include key documents related to the jurisdictions of the EU, United States, and China â published up to October 2025. Chinese-language documents were assessed and translated by a native Mandarin speaker with expertise in policy terminology, reducing ambiguities associated with machine translation. Because relevant materials are decentralised and fragmented across various internet archives, websites, repositories, and legal publishers, we opted for manual search rather than automation when reviewing texts. Keywords such as âdefinitionâ, âglossaryâ, âsystemâ, âmodelâ were used to identify relevant sections across documents. These sections were then screened against our inclusion and exclusion criteria, similar to that being used for the systematic literature review as described in Section 3.2 (Systematic Literature Review). For example, the use of the word âmodelâ outside of contexts related to AI were excluded. We grouped institutions into four categories: (1) national/state-level government bodies, (2) intergovernmental organisations, (3) standards bodies, and (4) NGOs. Verbatim definitions were extracted and tabulated with source, date, and organisational category. 3.2 Systematic Literature Review To identify how AI model and AI system are defined in academic literature, we conducted a systematic literature review following Carrera-Rivera et al. (2022). We searched Scopus, Web of Science, and IEEE Xplore for papers from 2012 onwards, marking the beginning of the modern deep learning era with AlexNet (Krizhevsky et al., 2012). To ensure papers actually discussed definitions rather than merely using these terms, we employed proximity operators (NEAR/4 or W/4) requiring definitional terms (âdefinitionâ, âontologyâ, âtaxonomyâ, etc.) to appear within four words of âAI modelâ, âAI systemâ, or their synonyms. After excluding papers focused on domain-specific applications (e.g., medical diagnosis, educational contexts) to maintain focus on general conceptual definitions, 896 papers remained after deduplication. Papers were then assessed for definition clarity and completeness, with particular attention to whether definitions were original or cited from other sources. Full details including search strings, PICOC criteria, and complete inclusion/exclusion criteria are provided in Appendix A Overview of the Systematic Literature Review. 3.3 Analysis of the Definitions Using the definitions compiled from the systematic literature review and the manual review, we analysed the different conceptual perspectives of these definitions. We identified three key dimensions along which definitions vary: (i) parent categories (subordinate concept class), (i) features (production, function, and for systems, mechanism), and (i) relationships between models and systems. We also traced citation patterns to identify influential sources and analysed how past definitions have influenced recent regulatory frameworks, particularly the EU AI Act. 3.4 Development of Proposed Definitions We developed evaluation criteria for proposed definitions by drawing on principles from ISO 704:2022 (technical concept definition) (ISO, 2022), legal drafting scholarship, and AI governance literature. These sources informed criteria related to structural clarity, technical coherence, and legal operability. Using these criteria, we developed both conceptual definitions (clarifying fundamental nature and relationships) and operational definitions (enabling practical regulatory application). For operational definitions, we specifically addressed contemporary neural network-based machine learning AI, where we systematically analysed aspects of a transformer-based LLM (e.g. weights, prompts, activations, RAG, fine-tuning adapters, filters, etc.) to establish if these aspects are part of a model or a system. 4 Findings and Analysis This section presents the results of both manual and systematic literature reviews examining how AI models and AI systems are defined across academic and regulatory sources. These findings provide the empirical foundation for understanding the definitional landscape and the relationships between different formulations of AI model and AI system definitions. Then, we discuss paradigm shifts that lead to an evolution of the meanings of these terms. Finally, we explore definitional lineages in major academic references and regulatory frameworks, and investigate how changes in definitions in the OECD frameworks have affected later definitions. 4 A PREPRINT 4.1 Conceptual Perspectives on Existing Definitions As described in Section 3.1 (Manual Review of Global Regulatory and Standards Documents), we manually gathered over 80 definitions from four categories of institutions: (i) intergovernmental organisations, (i) standards bodies, (i) national or state-level governmental organisations, and (iv) NGOs. Across documents produced by governments, regulatory agencies, inter-governmental and non-governmental organisations, we observed that AI definitions often remain ambiguous and inconsistent, particularly at the boundary between an AI model and an AI system. We provide a compilation of these definitions in Appendix B (Compilation of Definitions from the Manual Review). Additionally, based on the methods described in Section 3.2 (Systematic Literature Review), we conducted an SLR which screened 896 records from the literature resulting in 37 studies included. The process and findings of this SLR is further described in Appendix A (Overview of the Systematic Literature Review), and a compilation of these definitions are included in Appendix B (Compilation of Definitions from the Systematic Literature Review). Collectively, the definitions gathered through both the manual and systematic literature review can be interpreted from several perspectives. While many definitions appear similar, they can nonetheless be considered from different angles that highlight different conceptual emphases. Overall, when including both the papers found through the SLR and the manual review, more definitions were found for AI system and related terms (83 instances), than for AI model and related terms (43 instances), without excluding double-counting for instances that appear in both the manual review and the SLR. Included in the following conceptual perspectives were the terms AI model, machine learning model, AI system, and machine learning system, as well as sources providing clarifications on autonomous systems and intelligent systems. Figure 1: Overview of conceptual perspectives for definitions of AI model and AI system. We organise these conceptual perspectives along three dimensions (Figure 1). The first captures what kind of âthingâ an AI model or system is understood to be; for example, a representation, a component, or a system. This is about identifying the subordinate concept of a term, which ISO 704:2022 (ISO, 2022) notes as an important component of a definition. We refer to this dimension as âparent categoriesâ, as it reflects the broader conceptual class to which the definition assigns the term. The second dimension addresses the features of the model or system referenced in the definitions. For both models and systems, this addresses their production and function, analysing how models and systems are made, and what they do respectively. Additionally, for AI systems, this dimension also addresses its mechanism in order to define how the system operates. Third, we also consider the relational dimension, looking at the relationship between AI models and AI systems and how they are distinguished. Having a closer look at this difference provides further clarity on both terms. We refer to this dimension as ârelationship between AI model and AI systemâ. As an example of these dimensions, one source might define an AI model as the result of machine learning algorithms (parent category), used to make predictions (features), and referred to as the reasoning component of an AI system (relationship). Any of these perspectives can overlap within a single definition. For example, several definitions 5 A PREPRINT define an AI model as both the core reasoning or knowledge component of an AI system (relationship), and also as a representation of some external structure (parent category). The following sections elaborates on these different perspectives with several examples. A more comprehensive list of references behind these perspectives can be found in Appendix D (References on Conceptual Perspectives of Definitions). 4.1.1 AI Model We first consider how the term AI model is conceptualised across definitions. The definitions can be roughly divided into two parent categories: model artifact and model as representation. Definitions under model artifact describe models as the result of building or training, specifying the required elements a model possesses after building (e.g. weights, parameters, or the specific architecture). Definitions describing models as representations emphasise not the way a model has been built, but its purpose of providing a representation of some external structure (e.g. representing laws of the external world or the data it has been trained on). Parent Categories: 1. Model artifact (result of building/training): Focusing on weights, parameters, or architecture. (a)âA model can be based on data and/or expert knowledge, by humans and/or by automated tools like machine learning algorithms.â (OECD, 2019a, p. 7) 2.Model as representation: A model represents some external structure (e.g. the laws of the external world or the distribution of token sequences in a dataset). (a)âAI models are mathematical representations that capture, in a set of parameters, the patterns underlying their training personal dataâ (European Data Protection Supervisor, 2025, p. 9) (b) âphysical, mathematical or otherwise logical representation of a system, entity, phenomenon, process or dataâ (ISO/IEC, 2022a, ISO/IEC 22989:2022 3.1.23) (c)âA Model is an actionable representation of all or part of the external environment of an AI system that describes the environmentâs structure and/or dynamicsâ (OECD, 2019a, p. 7) Next, the features of an AI model are split into two perspectives: production and function. In accordance with the model life cycle, we first consider how models are built, and next what they are used for after being built. Accordingly, the production perspective contains all definitions referring to how a model is built or trained, including specific techniques or approaches. For example, a model can be described as being built using machine learning. The function perspective addresses definitions describing what a model is used for after building. This can be its intended use, specifications on its purpose, and describing the capabilities and characteristics it possesses to fulfil its function. Features: 1.Production (how it is built/trained): Considering the techniques or approach used to develop or create the model (e.g. use machine learning with data or hard-coded expert knowledge). (a)âuses computational, statistical, or machine-learning techniques to produce outputs from a given set of inputsâ (Executive Office of the President, 2023, Sec. 3(c)) 2. Function (what it is used for after building): (a) Emphasising what the model is intended to do (e.g. inference, prediction, pattern recognition). i. âused to make inferences from inputs to produce outputsâ (OECD, 2024, p. 8) i. âcan make predictions/decisions over dataâ (EstĂ©vez Almenzar et al., 2022, p. 43) (b) Wide purpose or narrow purpose: Describing its characteristics and capabilities (adaptable across a wide range of tasks or specific to one). i.âevery AI Model possesses the potential to adapt to other tasks, some (for example, neural networks) even being universal approximatorâ (Li and Zhan, 2022, p. 1) These perspectives are non-exclusive and orthogonal, meaning that definitions are not separated into different categories, but can fall into several different perspectives. Furthermore, perspectives on the features of a model only suggest different focal points of a definition. Therefore, different definitions grouped into these features may have other differences, as long as they share the same focal point of either production or function. For example, one definition 6 A PREPRINT might say a model is built using machine learning, while another might say it is built using hard-coded expert knowledge; but they both are defined with similar functions. It is also important to note that while two definitions may occupy different points along the first dimension (different parent categories of AI model), they can agree on the same definition along the second dimension (the same features are referenced in the definition). For example, one definition might describe a model as the result of machine learning, while the other describes it as a representation of the external world, resulting in different parental categories. However, they might both describe the function of an AI model as making inferences. 4.1.2 AI System In contrast to AI models, AI systems are defined more frequently and comprehensively. As with models, definitions can be viewed from two different dimensions: the parent categories and the features. Definitions of AI system can be divided into two different parent categories: AI systems as a type of system or as a type of technology. Many definitions describe AI systems as a type of system, specifying for example an AI system as a kind of machine-based system or an engineered system. Definitions falling into the technology category are focused on a broader category, either describing AI systems as technologies, or defining AI as a system, suggesting that the terms AI and AI system are often used interchangeably. Parent Categories: 1. AI system as a specific system: AI systems as a specific type of system. (a) âAn AI system is a machine-based systemâ (OECD, 2024, p. 4) (b) âan engineered systemâ (ISO/IEC, 2022b, ISO/IEC 22989:2022 3.1.4) (c) âArtificial intelligence (AI) systems are software (and possibly also hardware) systemsâ (High-Level Expert Group on Artificial Intelligence, 2019a, p. 36) 2. AI/AI system as a technology: AI systems as a technology and AI as AI-based systems in general. (a) âAI systems are information-processing technologiesâ (UNESCO, 2022, p. 10) (b)âArtificial Intelligence (AI) refers to systemsâ (High-Level Expert Group on Artificial Intelligence, 2019b, p. 7) The features of an AI system are grouped into similar perspectives as for an AI model. The first angle, considering the production, addresses what a system is made of and which techniques were used to build it. For example, a system can be described as requiring different components, such as an AI model, data pipelines, and an architecture. The second perspective describes the function of an AI system, entailing definitions that describe what an AI system does (e.g. giving predictions) and what kind of action it is conducting (e.g. acting autonomously or affecting the physical world). In addition to the perspectives of production and function, definitions of AI system have also been found to describe its mechanism. This perspective answers how the system does what it is created to do. For example, if a system is built to provide recommendations (function), this perspective may describe it as generating recommendations by inferring an output from the input it receives, or by perceiving, planning and reflecting. Features: 1. Production (how it is built): What a system is made of and the techniques used to build it. (a)âcan either use symbolic rules or learn a numeric modelâ (High-Level Expert Group on Artificial Intelligence, 2019a, p. 36) (b)âmore âgrownâ or âtrainedâ than they are programmed [...] produced by rewarding an AI for âgood behaviorâ and punishing it for âbad behaviorââ (Center for Humane Technology, 2024) (c)âBringing one or more AI models to a real-world application is not immediate, as it implies the effort of integrating them in a functional system (i.e., an AI system), including the necessary infrastructure, user interfaces, data pipelines, and other components required for the application to operate effectively in a production environmentâ (Hupont et al., 2024, p. 3) 2. Function (what it does): What is the system intended to do and what kind of actions it performs (intelligent action, impactful action). (a) âgenerate outputs such as predictions, content, recommendations, or decisionsâ (European Parliament and Council of the European Union, 2024, Article 3(1)) (b) âvary in their levels of autonomyâ (OECD, 2024, p. 4) 7 A PREPRINT (c)âinfluence physical or virtual environmentsâ (European Parliament and Council of the European Union, 2024, Article 3(1)) 3. Mechanism (how it does it): How does the system fulfil its function. (a) âIt does so by utilising machine and/or human-based inputs/dataâ (OECD, 2019a, p. 7) (b)â[AI systems act] by perceiving their environment through data acquisition, interpreting the collected structured or unstructured data, reasoning on the knowledge, or processing the information, derived from this data and deciding the best action(s) to take to achieve the given goal.â (High-Level Expert Group on Artificial Intelligence, 2019a, p. 36) 4.1.3 Relationship between AI Models and AI Systems Another dimension to be considered is the relationship between AI models and AI systems. This relationship has been split into two perspectives. âModel as a core component of a systemâ encompasses definitions that describe models as the core of an AI system, often performing a systemâs main function. âModel as a tool for a systemâ takes a broader view on the relationship of an AI model and an AI system, where an AI model is defined according to its function as a tool for an AI system. Relationship between AI models and AI systems: 1.Model as a core component of a system: A model defined as the core of an AI system, performing functions such as reasoning and knowledge recall (e.g. frontier language models in modern chatbots). (a)âA model characterizes an input-output transformation intended to perform a core computational task of the AI systemâ (Dunietz et al., 2024, p. 12) 2. Model as a tool for a system: Focusing on the function of a model as a tool within an AI system. (a)âAl systems contain a model which they use to produce predictions [...]â (ISO/IEC, 2022c, ISO/IEC 22989:2022 7.1) (b)âAI systems are information-processing technologies that integrate models and algorithms that produce a capacity to learn and to perform cognitive tasksâ (UNESCO, 2022, p. 10) 4.2 Paradigm Shifts in the Meaning of AI Models and AI Systems Having laid out the different conceptual perspectives of AI models and AI systems, we now describe the observed trends and evolutions of definitions of these terms over time. This section is not intended as a comprehensive history. Its purpose is to show that shifts in the meaning of AI model and AI system track changes in technical paradigms rather than deliberate definitional refinement, which become inadequate when applied to modern general-purpose models. 4.2.1 AI Models 4.2.1.1 Conceptual Senses of AI models The Oxford English Dictionary (n.d.) entry distinguishes four senses of model as a noun: a representation of structure, an object of imitation, a type or design, and other uses (obsolete historical senses). This corresponds to the sense of âmodel as representationâ that we identified in our literature review. It is also compatible with âmodel artifact (result of building/training)â as its parent category and âmodel as a tool for a systemâ as its relationship with the system. However, this definition of model is not clearly compatible with âmodel as a core component of a systemâ, since reasoning and knowledge recall are not capabilities typically associated with representations. The notions of âmodel as representationâ and âmodel as a particular toolâ are closely tied to the concept of a âworld modelâ which is a key component of some (typically older) archetypes of AI systems or agents. The idea is that since most AI agents will only have partial observability of the world around them, they need some way to deduce or predict changes in the world that they cannot directly observe, such as food decaying in a closed fridge, or the outcomes of actions that the agent has yet to perform. Thus, an AI agent will require some component that âmodelsâ the exterior world and allows them to make better-informed decisions. For example, Artificial Intelligence: A Modern Approach (Russell and Norvig, 2009) says that âknowledge about âhow the world worksâ [...] is called a model of the worldâ and âan agent that uses such a model is called a model-based agent.â Crucially, under this paradigm the âmodelâ is not expected to decide what action the agent should take, merely to predict what the likely effects of different actions would be. 8 A PREPRINT In the field of modern AI, LLMs are typically referred to as models despite not seeming to be a model of anything, and are relied upon to perform tasks and make decisions by themselves, rather than being used to inform a decision-making process. Therefore the use of the term model to describe these entities appears to be due to the ancestry of current frontier models, since nearly all such models are (primarily) neural networks using transformer architecture (Zhao et al., 2025). Neural networks were originally proposed as a model of networks of neurons in the human brain (McCulloch and Pitts, 1943), and are known to be capable of approximating (or âmodellingâ) a wide range of mathematical functions (Cybenko, 1989; Hornik et al., 1989). Furthermore, transformers were originally proposed in the field of computational language modelling (Vaswani et al., 2017). For these reasons, it is commonplace to refer to any neural network with transformer architecture as a model, even if it is not clear what, if anything, it is modelling (as is the case in the neural networks that form the core of modern frontier LLMs). As transformer-based neural networks have become an increasingly dominant force in AI, particularly in the most capable and general systems, and as more classical agent architectures have become correspondingly less popular, we argue that the usage of the term AI system has shifted. This can be observed in the OECD definitions. The 2022 definition states âAI models are actionable representations of all or part of the external context or environment of an AI system (encompassing, for example, processes, objects, ideas, people and/or interactions taking place in context)â (OECD, 2022), which corresponds to the first (representation) sense of AI model. The 2024 definition states âAn AI model is a core component of an AI system used to make inferences from inputs to produce outputs [. . . ] while the parameters of an AI model change during the build phase, they usually remain fixed after deployment once the build phase has concludedâ (OECD, 2024), corresponding to a different second sense of a model, which views the model primarily as a component instead of a representation. While frontier models are not typically used for modelling purposes, they are still built from an architecture (transform- ers) that was intended to model something (natural language). What, if anything therefore, can frontier models be said to be models of? The pre-training of GPT-3 attempts to maximise its accuracy at modelling its training dataset (Brown et al., 2020), meaning that pre-trained GPT-3 can meaningfully be said to be a model of whatever corpus of text it was trained on. The fine-tuning will, strictly speaking, make it less representative of its training data (for example, it will produce less offensive language than contained in its dataset). However, it will move the model closer to being a useful AI assistant. Therefore, if a fine-tuned GPT-3 can be meaningfully said to be a model of anything, it is an (imprecise) model of the perfect AI assistant. 4.2.1.2 Historical Shift towards Generality Beyond a shift in the different senses of an AI model, there was also a notable shift from AI models that have specific purposes to being general-purpose during the machine-learning era. 2016-2020: Statistical Methods, Specific Tasks When specifically searching for definitions of AI model in the systematic review, some early definitions characterised AI models predominantly through the lens of machine learning and statistical models, emphasizing their task-specific nature. One 2016 definition described machine learning models as ânon-deterministic statistical approximationsâ bound to function correctly only âa certain portion of the time,â emphasizing their probabilistic nature and limited scope (Ramanathan et al., 2016). Following the conventions of this era, ISO/IEC (2022c, ISO/IEC 22989:2022) used the term âAI modelâ with reference to two separate definitions for âAIâ and âmodelâ, where model is defined in part as a âmathematical or otherwise logical representation of a systemâ. This pattern in the retrieved literature suggests that the AI model terminology was closely associated with traditional machine learning paradigms during this period. 2021-2022: Foundation Models By 2021, definitions had started to include structured components such as algorithms, training datasets, and performance metrics while remaining fundamentally task-oriented. The concept of a foundation model was introduced in 2021, marking a shift in moving away from machine learning for specific applications to focus on versatility. These definitions focus on models being âpretrained on massive amounts of dataâ and capable of adaptation âto perform a wide variety of tasks through fine-tuningâ (Bommasani et al., 2022). This period marked the transition from AI as specialised tools to AI as general-purpose capabilities. The characteristics of foundation models would later be recognised under the term âgeneral-purposeâ after its use in the EU AI Act in 2023. 2023-2024: Formalisation of General-purpose By 2023, the shift in capability influenced the definition of general-purpose AI models within formal regulatory recognition. Article 3(63) of the EU AI Act defined these as models âcapable of competently performing a wide range 9 A PREPRINT of distinct tasks regardless of the way the model is placed on the marketâ (European Parliament and Council of the European Union, 2024). This trend reflects a fundamental reconceptualisation of AI from being application-specific to general-purpose, which played a significant role in expanding the scope of how systems were to be defined. 4.2.2 AI Systems From the systematic literature review and manual extraction, several observations emerge regarding the evolution of the definition of AI systems. Unlike the evolution observed in the definitions of AI models, the trends in the definitions of AI systems emerged in parallel, hence a lack of distinct timelines. 4.2.2.1 The Emergence of Autonomy and Adaptiveness as Core Attributes Initial definitions of autonomy in AI systems and/or autonomous systems focused on independence from human supervision. The 2016 characterisation emphasised systems âcapable of performing certain tasks in an unstructured environment without human supervision,â with self-awareness defined as the ability to âanalyze the situation and do the decision-making on its ownâ (Helle et al., 2016). The OECDâs 2019 definition introduced the idea that AI systems are âdesigned to operate with varying levels of autonomy,â acknowledging autonomy as a spectrum rather than a binary state (OECD, 2019a). The period from 2019 to 2024 saw increasing sophistication in how autonomy was conceptualised within the definitions of systems. The 2024 EU AI Act definition represented this evolution, noting that the autonomy offers the possibility of continual adaptation, acknowledging systems âdesigned to operate with varying levels of autonomy [. . . ] that may exhibit adaptiveness after deploymentâ (European Parliament and Council of the European Union, 2024, Article 3(1)). The concept of adaptiveness introduced an additional temporal dimension: systems could change their behavior after deployment through âself-learning capabilities, allowing the system to change while in useâ (European Parliament and Council of the European Union, 2024, Recital 12). This post-deployment evolution distinguished modern AI systems from earlier conceptions of AI as a program for symbolic logic, and traditional software which operates according to fixed programming. 4.2.2.2 Recognition of Unintended Capabilities Early definitions implicitly assumed that AI systems would perform tasks for which they were explicitly designed and trained. Capabilities were understood as direct results of intentional design choices, training data selection, and optimisation objectives. Later definitions explicitly recognised that modern AI systems exhibit capabilities beyond those explicitly programmed or trained for. The 2022 definitions of general-purpose AI systems could have âmultiple intended and unintended purposesâ (Future of Life Institute, 2022). By 2023, definitions acknowledged systems that could âaccomplish a range of distinct tasks, including some for which it was not intentionally and specifically trainedâ (Gutierrez et al., 2022). Overall, the recognition of emergent capabilities signals an acknowledgement that traditional approaches based on comprehensive specification and validation become vulnerable to rapid technological change. 4.2.2.3 Legal Frameworks and Regulatory Motivations Pre-2021 definitions originated primarily from academic and technical communities, focusing on capabilities, methods, and performance characteristics. These definitions were adequate for descriptive purposes in technical research, but were not written with regulatory needs in mind. The OECD AI Principles (OECD, 2019a), adopted in May 2019, played a foundational role in shaping subsequent regulatory standards. Along with their supplementary documentation that define their scope, they established a common reference point for the EU, ISO, and NIST. The EU AI Act (European Parliament and Council of the European Union, 2024), developed between 2021 and 2024, uses a risk-based classification framework (unacceptable, high, limited, and minimal risk) rather than attempting comprehensive definitional precision. The 2023 American Executive Order on âSafe, Secure, and Trustworthy Development and Use of Artificial Intelligenceâ (later rescinded in 2024) provided an alternative regulatory approach, defining AI systems broadly as âany data system, software, hardware, application, tools, or utility that operates in whole or in part using AI,â demonstrating generalised and all-encompassing approach (Executive Office of the President, 2023). 10 A PREPRINT Overall, the emergence of legally operative definitions represents the maturation of the field and its growing significance. These definitions establish frameworks for governance and compliance. However, as the analysis above demonstrates, approaches to definitional precision vary considerably, reflecting competing priorities between regulatory clarity and future-proofing. 4.2.3 Overall Trends In general, the trends observed in the definition of AI systems may also apply to definitions of AI models. However, trends identified for AI models were derived primarily from changes in explicit definitional language across the sources retrieved from our search. In contrast, several trends associated with AI systems were observed in their definition and accompanying explanatory context and regulatory framing. Definitions of AI models were typically accompanied by far less contextual elaboration, reflecting the larger volume of system-level definitions retrieved in the review. Moreover, governance discourse mostly focused on the concept of systems over models. As such, these system-level trends should not be interpreted as uniformly applying to AI models, though both systems and models may share broader conceptual paradigms. 4.3 Definitional Lineages and Influence In this section we consider more broadly how the various definitions from our surveys have influenced each other. Our analysis reveals that many secondary definitions (summarisations, syntheses, and adaptations), and most definitions proposed by major organisations, can be traced back to a particularly concentrated set of foundational sources, including OECD frameworks. We also find that these OECD frameworks have evolved in ways that integrate previously distinct concepts, blurring the boundary between models as representations and models as components of AI systems. We examine these issues in depth, tracing the chain of influence through various sources, analysing how ambiguities have compounded through successive iterations. 4.3.1 Overall Chain of Influence As described, much of the definitions used in major regulatory frameworks have their lineages traced back to the OECD definitions, which in turn are heavily based on the work of Stuart Russell and Peter Norvig, as illustrated by (Figure 2). The lineage begins with Russell and Norvigâs Artificial Intelligence: A Modern Approach (Russell and Norvig, 2009, 3rd edition), which articulates the agent-based architecture of perception, representation, reasoning, and action. This framework is adopted directly into OECDâs Scoping the OECD AI Principles: Deliberations of the Expert Group on Artificial Intelligence at the OECD (AIGO) (OECD, 2019a), which identifies Russell and Norvig as the conceptual basis for understanding AI systems as composite systems of interacting models. AIGO deliberations informed the OECD Recommendation on Artificial Intelligence (OECD, 2019b, AI Principles). OECD (2019a) established key definitional elements including âmachine-based system,â âvarying levels of autonomy,â and the capacity to âinfluence the environment,â which would propagate through subsequent regulatory instruments. Notably, while the 2019 OECD documents (OECD, 2019a,b) incorporated the concept of model as a component of AI systems, they did not provide a formal standalone definition of AI model at this stage. In 2022, the OECD published the Framework for the Classification of AI Systems (OECD, 2022), which built upon OECD (2019a) by embedding the same conceptual architecture into a more granular classification taxonomy. This document formally introduced and defined the term AI model as a distinct concept, establishing a clearer conceptual boundary between models and systems. Parallel to this, ISO/IEC 22989:2022 Artificial IntelligenceâConcepts and Terminology (ISO/IEC, 2022c) adopted and detailed AI terminology for international technical standardisation. While ISO drew on its own pre-existing general definition of model from other standards, the document explicitly references OECD (2019a) in Annex A when mapping the AI system lifecycle. By 2023, the U.S. National Institute of Standards and Technology (NIST) published its AI Risk Management Framework (AI RMF 1.0) (National Institute of Standards and Technology, 2023). NIST explicitly notes that its definition of an AI system is âadapted from: OECD Recommendation on AI: 2019; ISO/IEC 22989:2022,â and it uses the OECD (2022) to structure its lifecycle and dimensional analysis. Also in 2024, the OECD published the Explanatory Memorandum on the Updated OECD Definition of an AI Sys- tem(OECD, 2024), revising the 2019 definition. The memorandum states that the updated definition was shaped to âsupport broad alignment of the definitions of AI systems in several ongoing processes in the European Unionâ as well as other emerging regulatory frameworks. 11 A PREPRINT Figure 2: Definitional lineage of terms related to AI models and AI systems Subsequently, the European Commission (2021) adapted and expanded upon the OECD (2019a). Although the OECD is not explicitly cited in the legislative text itself, the influence is acknowledged in recitals and supplementary documentation. The final EU AI Act (European Parliament and Council of the European Union, 2024, Article 3(1)) demonstrates convergence with the updated 2024 OECD definition, incorporating OECDâs new additions: âmachine- based system,â âexplicit or implicit objectives,â âvarying levels of autonomy,â âinfers from input,â and âinfluence physical or virtual environments.â This represents a bidirectional feedback loop: OECD (2024) notes that its revised definition was developed with awareness of the evolving EU AI Act, while the EU AI Actâs final text converged toward the OECD formulation. 4.3.2 Analysis of OECD Frameworks The OECDâs AI taxonomy has become one of the most influential frameworks for AI governance globally. Its definitions have been adopted or adapted by numerous jurisdictions, In particular, definitions originating in the OECD framework have influenced ISO standards, the NIST AI Risk Management Framework, and most significantly the EU AI Act. 12 A PREPRINT This section assesses whether successive OECD revisions preserve a stable conceptual boundary between AI model and AI system. We observe that across the 2019, 2022, and 2024 iterations, the framework progressively expands the meaning of AI model without sufficient conceptual clarification. As a result, the distinction between model and system becomes increasingly flexible, which may create challenges when used for regulatory allocation of obligations. 4.3.2.1 OECD (2019a): The Original Conceptual Framework OECD (2019a) noted its adaptation of Russell and Norvig (2009) for its definitions, a connection made clear by comparing the two conceptual diagrams, as shown in Figure 3. Figure 3: OECD (2019a) (top) versus Russell and Norvig (2009) (bottom) The OECDâs 2019 report Recommendation of the Council on Artificial Intelligence (OECD, 2019b) established a comprehensive taxonomy with three core concepts. These definitions appear to draw heavily from Russell and Norvigâs agent-based framework, while introducing several additional terms and conceptual reinterpretations (Russell and Norvig, 2009). The main relevant definitions are AI system (or intelligent agent), AI operational logic, and model, as summarised in Table 1. 13 A PREPRINT Table 1: Key definitions related to AI models and AI systems from OECD (2019a) AI system / Intelli- gent Agent âAn AI system is a machine-based system that is capable of influencing the Environment by making recommendations, predictions or decisions for a given set of Objectives. It does so by utilising machine and/or human-based inputs/data to: i) perceive real and/or virtual environments; i) abstract such perceptions into models manually or automatically; and i) use Model Interpretations to formulate options for outcomes.â (OECD, 2019a, p. 7) AIOperational Logic (p. 6) âThe key power of an AI system resides in its Operational Logic, which, for a given set of objectives and based on input data from Sensors, provides output for the Actuators â as recommendations, predictions or decisions â that are capable of influencing the state of the Environment.â (OECD, 2019a, p. 6) Model (p. 6-7)âA Model is an actionable representation of all or part of the external envi- ronment of an AI system that describes the environmentâs structure and/or dynamics. The model represents the core of an AI system. A model can be based on data and/or expert knowledge, by humans and/or by automated tools like machine learning algorithms. Model Interpretation is the process of deriving an outcome from a model.â (OECD, 2019a, p. 7) âModel (a data object constructed by the Model Building process)â (OECD, 2019a, p. 6) OECD (2019a) defines an AI system as comprising two parts: its function and its mechanisms (including both building and using). The latter two terms are defined by their relationship to the AI system itself: the AI operational logic maps the âinput from sensorâ to the âoutput for actuator,â while the model represents the âexternal environmentâ of the AI system. This taxonomy presents three conceptual challenges that may affect its application in regulatory contexts: 1. Ambiguous Inclusion or Exclusion of Human Involvement The report states: âAn AI system consists of three main elements: Sensors, Operational Logic and Actuatorsâ (OECD, 2019a, p. 8). Under this strict interpretation, a software program that generates a credit score would not, by itself, constitute an AI system, as it lacks a physical actuator (e.g., the bank staff who ultimately approve or deny the loan). However, the OECD (2019a)âs conceptual diagram introduces flexibility by noting that sensors and actuators can be human. Consequently, a credit scoring system would be considered a hybrid of human and machine, which is an interpretation that may differ from common public understanding. This ambiguity marks the beginning of a broader, recurring issue in subsequent years, where human involvement is often reconciled by classifying such systems as AI with a âlow level of autonomy.â 2. The Conflation of Real, Digital, and Abstract Objects This framework illustrates a conflation of object types. It describes an AI system as being made of Sensors, Actuators, and Operational Logic. While sensors and actuators are tangible, physical components, the operational logic is presented as a pure, abstract object described as a âlogical mappingâ with no reference to the physical computational substrate (e.g., hardware like GPUs) required to implement it. Take an autonomous vehicle as an example. Under this description, the self-driving car is said to be âmade ofâ the radar (sensor), the engine (actuator), and the logical mapping between them. The computing hardware that physically instantiates this logic is not explicitly referenced in the definition, which leaves the relationship between abstract function and real-world implementation less clearly specified. Russell and Norvig (2009, p. 35) maintain strict separation: âThe agent function is an abstract mathematical description; the agent program is a concrete implementation, running within some physical system.â They formalise this as: 14 A PREPRINT Agent = Architecture + P rogram Architecture = Sensor + Actuator + Computing Device Therefore: Agent = (Sensor + Actuator + Computing Device) + P rogram The OECD framework does not explicitly articulate this distinction, instead presenting the system as encompassing both tangible components and abstract functional elements. 3. The Ambiguity of âActionable Representationâ The term âactionable representationâ is not formally defined within OECD (2019a)âs taxonomy. Nevertheless, there are academic sources which define it. For example, Ghosh et al. (2018, p. 1) defines it as the following: 1. Is âaware of the dynamics of the environment.â 2.Captures âonly the elements of the observation that are necessary for decision making rather than all factors of variation, eliminating the need for explicit reconstruction.â 3.Is typically âobtained from a goal-conditioned policyâa policy that knows how to reach arbitrary goal states from a given state.â This narrower technical interpretation requires a âgoal-conditioned policyâ which may not align with all AI systems encompassed by the OECD framework, potentially creating ambiguity between terminology and intended scope. The OECD appears to use âactionableâ colloquially to mean âcan inform actions,â but this divergence from technical usage creates ambiguity about what exactly a âmodelâ is supposed to be. Terminological Relationships OECD (2019a)âs taxonomy introduces the non-standard concept of AI operational logic, which is rarely found in other literature. Its definition, describing the mapping of outputs for actuators from inputs received from sensors, is conceptually almost identical to Russell and Norvigâs agent function, which is defined as a description that âmaps any given percept sequence to an actionâ (Russell and Norvig, 2009, p.35). The relationship and differences between the core concepts in the two frameworks are summarised in Table 2: Table 2: Relationship and differences between Russell and Norvig (2009) term and OECD (2019a) Russell & Norvigâs Term OECD (2019a) Equivalent Key Difference in Taxonomy Primary Object Type Agent / Rational Agent / Intelligent Agent AI System / Intelligent Agent The definitions are almost identical. OECD: A mixture of real, digital, and abstract objects. Agent FunctionAI Operational Logic Near-identical definitions (mapping inputs to outputs) Abstract Agent Program(Most analogous to) Model Agent program is concrete software; OECD model is âdata objectâ Digital World Model (of a model-based agent) A specific type of Model Russell and Norvig (2009): specific to subset of agents (model-based); OECD: implied for all systems Digital or Abstract 15 A PREPRINT 4.3.2.2 OECD (2022): Compounding the Conceptual Confusion As an update to the previous version, OECD (2022) did not fully resolve the conceptual questions identified in 2019; instead, it consolidated previously distinct elements into a unified framework. The framework merged the already problematic AI operational logic and model into a single, ill-defined term: âAI modelâ. This move effectively formalises the earlier conflation, redefining the model as the component that dictates the systemâs operational logic while simultaneously treating it as a representation of the environment. The new conceptual diagrams are shown in Figure 4. Figure 4: OECD (2022)âs conceptualisation of the term AI model The original rationale provided was a desire for simplification (OECD, 2022, p. 23): âIt should be noted that in the present classification framework, the âPerceivingâ (data collection) and âdata/inputâ elements â that were separate elements in the original OECD work presented in Figure 5 â have been combined in an effort to simplify the framework (see dotted lines in Figure 4). The âOutcomesâ and âActingâ elements have also been combined.â This simplification creates significant ambiguity. Combining âPerceivingâ with âData/Inputâ blurs the boundary between the AI model and the AI system. Inputs now flow directly from the environment into the AI model, bypassing the conceptual layer of the system and its sensors that would typically collect and pre-process data. The AI Model is not only expanded to encompass what was previously called the AIâs operational logic, but the operational logic itself is broadened relative to the system, where its input becomes the systemâs input. This, in turn, narrows the definition of the AI System itself, potentially excluding essential components like data pre-processing modules. For this taxonomy to remain coherent, there is a logical pressure to treat the AI model as an abstraction of the entire AI system â a tendency that becomes explicit in the 2024 documents, which we discuss further in Section 4.3.2.3 (OECD (2024): Expansion and Functional Broadening). If both the AI model and the AI system are conceived as concrete entities, the conceptual boundary between them becomes less clearly defined. This interpretation may not fully capture the structure of certain real-world deployments. For example, a recommendation model abstracts user preferences for items, not the entire recommendation system, which requires additional components to collect live user data and integrate business rules (e.g., paid promotions) that ultimately determine how the modelâs outputs are applied. Internal Inconsistencies: Diagram versus Definition The conceptual diagram places the label âAI modelâ precisely where âAI Operational Logicâ was previously located. Yet, the textual definitions of an âAI modelâ remain closer to the OECD (2019a) notion of a âmodelâ (a representation of the environment) rather than to operational logic. A key inconsistency is that the diagram depicts system inputs and outputs flowing directly to and from the AI model, while the definition states a model may represent âall or partâ of the external environment. This implies the modelâs inputs/outputs need not align with the systemâs. 16 A PREPRINT Table 3: Differences and similarities between terminologies in OECD (2019a) and OECD (2022) AspectOECD (2019a)OECD (2022)Consequences Core DefinitionAn actionable repre- sentation of all or part of the external envi- ronment of an AI sys- tem. An actionable representation of all or part of the external context or environment of an AI system. Slight expansion from âenvi- ronmentâ to âcontext.â Relationshipwith Environment Themodel[...] describes the envi- ronmentâs structure and/or dynamics. The model represents, de- scribes, and interacts with real or virtual environments. Introduces the incorrect idea that a model can âinteract.â Relation to SystemClearly a component within the system, representing its envi- ronment. Blurred; diagrammatically equated with the systemâs core logic, definitionally re- mains a representation. Fundamental tension be- tween the visual framework and its textual definitions. The OECD (2022) claim that a model can âinteract withâ environments is conceptually flawed and contradicts common usage of the term âactionable representation,â where âactionableâ should mean the representationâs outputs can inform actions taken by another component (e.g. an actuator), not that the model itself acts. This misinterpretation is evident in the reportâs own examples. It states that actions are taken âbased on the outcomes of an AI system, e.g. by autonomous vehicles,â confirming the system provides an output that is actualised by the vehicle. Similarly, an AI gamerâs policy model generates action probabilities; the system architecture executes the actions. The capacity to act resides in the system, not in the model. 4.3.2.3 OECD (2024): Expansion and Functional Broadening Figure 5: OECD (2024)âs conceptual diagram Subsequently, OECD (2024) illustrates the extent to which the taxonomy has evolved in scope and application. In its latest conceptual diagram as seen in Figure 5, the term âinfluenceâ replaces âacting,â a change that further abstracts the systemâs relationship with its environment without resolving core ambiguities. Critically, OECD (2024) appears to have recognised a foundational flaw, where many modern AI systems, such as those using model-free reinforcement learning, operate without an explicit âmodelâ as previously defined. Instead of revising the earlier conceptual structure, the organisation expanded the definition of model to retroactively include these systems, thereby altering the termâs meaning and its relationship to the AI system. This has resulted in a set of scattered, often conflicting definitions for AI model within the same document: 1. A system component: â[. . . ] an AI model is a core component of an AI system used to make inferences from inputs to produce outputs.â (OECD, 2024, p. 8) 17 A PREPRINT 2.A representation (per ISO): âA model is defined as a âphysical, mathematical or otherwise logical representa- tion of a system, entity, phenomenon, process or dataâ [. . . ]â (OECD, 2024, p. 8) 3. An input-output mapping: âAI models include, among others, various kinds of input-output functions (such as decision trees and neural networks).â (OECD, 2024, p. 8) 4.A world model: âAn AI model can represent the transition dynamics of the environment, allowing an AI system to select actions by examining their possible consequences using the model.â (OECD, 2024, p. 8) 5. A policy or Q-function: âIn such cases [âmodel-free reinforcement learningâ], the policy or Q-function would be an AI model in the more general sense of an input-output function.â (OECD, 2024, p. 11) These definitions create a high degree of contextual and internal conflict. For instance, in a model-based agent, the AI system uses the world model to determine actions. In a model-free agent, the AI model (the policy/Q-function) is now said to determine the action itself. This contradiction highlights an underlying shift: the model is inconsistently framed as a component within the system, a functional abstraction of the system, and the systemâs driving logic. This new, expansive definition finally aligns the term AI model with what was originally termed AI operational logic or Russell and Norvig (2009)âs agent function. The taxonomy now reflects a substantially broadened conception of AI model across contexts, as summarised in Table 4, which tracks the termâs shifting applicability across frameworks. Table 4: Conceptions of AI model across different frameworks ConceptRussell and Norvig (2009) OECD (2019a) OECD (2022) (Text) OECD (2022) (Image) OECD (2024) World model of a model- based agent YesYesYesSometimesSometimes Representation of (part of) the external environment YesYesYesSometimesSometimes Core component of an AI system Sometimes (model-based only) YesYesYesYes Abstract mapping between system input and output No (Agent Function) No (AI Operational Logic) SometimesYesYes Policy/Q-functionofa model-free agent NoNoNoYesYes Regulatory Implications The OECD itself acknowledges the indeterminacy surrounding core concepts, noting that âdifferent interpretations of the word âmodelâ exist.â While such open-textured definitions are appropriate within a non-binding, standards-setting context, they acquire regulatory significance when subsequently referenced in binding legal instruments. In the same document, the OECD explicitly disclaims any engagement with liability allocation, stating that its definition of an AI system âintentionally does not address the issue of liability and responsibility for AI systems,â which it leaves to human actors and jurisdiction-specific regulatory choices. This creates a structural challenge when OECD-derived taxonomies are repurposed within the EU AI Act, which must operationalise distinctions between AI models and AI systems in order to assign legal obligations. The result is a potential misalignment when a deliberately non-normative technical taxonomy is referenced within a normative legal framework. Overall, the progression from 2019 to 2024 demonstrates how well-intentioned simplification can increase conceptual ambiguity. OECDâs acknowledgment of âdifferent interpretationsâ may sit in tension with the precise boundaries that legal instruments required to allocate liability, determine compliance, and enable enforcement. 18 A PREPRINT This analysis motivates our proposed framework in Section 5 (Developing Definitions for AI Models and AI Systems), which provides technically accurate and legally robust definitions capable of withstanding regulatory scrutiny while reflecting the architectural realities of modern AI systems. 5 Developing Definitions for AI Models and AI Systems We now turn to the constructive task of developing improved definitions for AI model and AI system. Section 4 (Findings and Analysis), particularly Section 4.3.2 (Analysis of OECD Frameworks) identified several deficiencies in existing definitions: the conflation of distinct conceptual categories (representation versus operational component), internal inconsistencies between textual definitions and accompanying diagrams, the progressive expansion of terms to accommodate technological developments without corresponding conceptual clarification, and the absence of clear criteria for distinguishing where a model ends and a system begins. In the case of both AI model and AI system we argue that these problems cannot be solved with a single, all-encompassing definition, and instead propose two separate but complementary definitions. First, we provide conceptual definitions that capture what AI models and systems fundamentally are, providing clarity about the nature of these entities and their relationship to one another. Second, we provide operational definitions that enable consistent, practical application in the real world, allowing non-specialists to determine whether a given artifact falls within the scope of a particular definition. This two-level approach draws inspiration from Tomi Ì c and Ć timac (2025), who distinguish between conceptual and operational definitions in the context of AI regulation. However, their analysis is primarily concerned with operationalizing the concept of an AI system itself by identifying its invariant features, whereas our focus is to clarify the boundary between AI models and AI systems. The following sections develop both types of definition, beginning with an examination of the criteria that good definitions should satisfy, proceeding to our proposed conceptual definitions, followed by our operational definitions specifically tailored to the dominant paradigm of neural network-based machine learning systems, and concluding by discussing regulatory implications and case studies. 5.1 Criteria for Technically and Legally Robust Definitions Definitions exist for a variety of purposes. They can be meant for coordinating usage and ensuring that interlocutors are referring to the same phenomenon (DeLancey, 2017; Copi et al., 2014). They can be used to stipulate a termâs meaning for the purposes of a specific inquiry or to refine an imprecise expression into a form suitable for analytical or regulatory reasoning, as discussed in analytic philosophy and legislative drafting scholarship (Gupta and Mackereth, 2023). Definitions can also be used to create or stabilise a concept by naming it, turning a diffuse or loosely recognised phenomenon into an object of inquiry (Burgess et al., 2020). They can clarify a conceptâs content by identifying the features that constitute it and distinguishing it from related concepts (Margolis and Laurence, 2023). Finally, in law and regulation, definitions serve a normative and operational function: they simplify language, secure consistent interpretation across a text, and determine the boundaries of obligations, rights, and responsibilities (Jopek-Bosiacka, 2011; Bailey and Norbury, 2025). Because AI-related terms sit at the intersection of these different functions (descriptive, conceptual, and normative) this section focuses on the latter purposes and on how they can best contribute to clearer regulation. ISO 704:2022 (ISO, 2022) outlines principles for defining technical concepts in a precise, systematically structured way. It requires definitions to identify indispensable features that distinguish a concept from related ones, while excluding variable non-essential attributes. Therefore, according to ISO 704:2002, extensional definitions that attempt to specify a concept by listing its instances are inadequate for technical and conceptual clarity. The norm requires that the distinguishing characters of similar or adjacent terms are explicitly listed, clarifying the boundaries within the broader conceptual structural ontology of the domain (what ISO 704:2002 calls a âconcept systemâ). Specifically, definitions should follow a specific pattern where the broader category to which the concept belongs is first identified, then differentiating characteristics from neighboring concepts is further specified. Definitions can be written for various purposes, such as clarifying research scope or explaining technical concepts. A technical definition primarily captures meaning and facilitates communication within a domain, and might not fit the criteria we can expect from a legal definition, which must establish clear, enforceable boundaries that support consistent application in practice. Below, we describe properties of a definition suitable for this regulatory function, particularly when distinguishing between AI models and AI systems. Structural Clarity and Definitional Boundaries 19 A PREPRINT A legal definition should express necessary and sufficient conditions in plain, unambiguous language, avoiding circularity and unstated background assumptions (Dickerson, 1977; House Legislative Services, 2015). It must enable a non-specialist decision-maker to determine inclusion or exclusion from scope using the text alone. At the same time, a definition should establish the outer boundary of application while leaving detailed classifications or risk tiers to secondary instruments. This layered and calibrated structure allows precision to evolve without reopening primary legislation and prevents the definition from becoming overly rigid or granular (Ebers, 2024; Renda and Engler, 2023). Technical Coherence and Adaptability Legal definitions in fast-changing domains must both reflect and withstand technological evolution. They should be technology-neutral, describing functions rather than methods. For example, they should focus on what a system does rather than how it operates (Reed, 2007; Greenberg, 2016; Birnhack, 2012). Because underlying technologies develop rapidly, definitions should also include mechanisms for future-proofing: delegated standards, guidance documents, or periodic reviews. These mechanisms should enable reinterpretation without statutory amendment (Ebers, 2024), and remain coherent with the technical object it describes, even as that object changes over time. Legal Operability and Policy Alignment The point of a good legal definition is not only to describe phenomena accurately, but also to work as a legal instrument. It should be administrable and enforceable, enabling authorities and courts to apply it consistently without deep technical expertise. Each definitional element should correspond to observable or documentable features (for instance, the presence of a learning process or adaptive behavior), allowing compliance to be verified objectively. Schuett (2021) observes that many AI definitions fail such tests because they rely on vague or colloquial descriptors. It should also be interoperable with existing technical and international vocabularies to minimise conflict between legal and engineering interpretations. The EU AI Actâs definition of an AI system, for instance, was intentionally aligned with the OECD wording (FernĂĄndez-Llorca et al., 2025; Nahra et al., 2024). Finally, the definition should exhibit policy fit and proportionality, including only the systems the law intends to govern and excluding those that would make enforcement disproportionate (Ebers, 2024; Renda and Engler, 2023). In practice, this means drawing the boundary of AI systems where risk-based obligations attach, not where the term is used informally. Additionally, where appropriate, providing examples and explicit carve-outs clarifies intent and prevents disputes at the margins. Legislative drafting manuals recommend this practice to ensure shared understanding among implementers (Dickerson, 1977; House Legislative Services, 2015). These criteria show that the purpose of a legal definition for a technical concept such as AI model or AI system go beyond describing, as they must also establish enforceable boundaries. A good definition has to draw stable, policy-aligned lines that regulators can administer consistently and that remain intelligible and applicable as technology develops. 5.2 Conceptual Definitions As described in the Section 4 (Findings and Analysis), we can see that the conceptual frameworks behind AI models and systems have changed over time. In this section, we attempt to flesh out useful conceptual definitions of AI models and AI systems. Note that these proposed definitions are not operational definitions which we will discuss further in Section 5.3 (Operational Definitions for Contemporary AI). Our conceptual definitions are not recommended for technical use, but help to explain the motivation behind our operational definitions, and outline the principles according to which the operational definitions could be further extended if needed. We propose the following conceptual definitions, largely adopted from OECD (2024): AI model: A computational construct that makes inferences from inputs to produce outputs and forms (or is intended to form) the reasoning or knowledge core of an AI system. AI system: A machine-based system that makes inferences from inputs from physical or virtual environments to produce outputs that influence physical or virtual environments. Our definition of AI model represents what we see as the conceptual shift in the usage of the term from âmodel as representationâ to âmodel as core reasoning/knowledge componentâ as discussed in more detail in Section 4.2.1.1 (Conceptual Senses of AI model). In particular, we feel that the current usage of the term in industry (particularly as it relates to frontier models, the kind of models where effective legislation is by far the most important) has shifted almost entirely to the âmodel as core reasoning/knowledge componentâ perspective. This is primarily because most of the post-training âfine-tuningâ that is done to these entities makes them less accurate representations of the datasets on which they were originally trained (for example, they produce far less offensive text than randomly sampling from the 20 A PREPRINT dataset). The fact that this does not appear to be considered as making the entity âless of a modelâ strongly indicates that the sense of âmodelâ being used in frontier AI development now has very little to do with the notion of ârepresentationâ. In principle we allow that a strict subset of an AI model may be an AI model, and a strict subset of an AI system may itself be an AI system. Whether real-world techniques such as mixture-of-experts (MoE) architectures should be considered as nested models or not will be discussed in the Section 5.3 (Operational Definitions for Contemporary AI). In addition, we allow for the possibility that an AI system may contain multiple AI models. In principle, we consider it possible that an AI system may not clearly contain a distinct component that can be called the AI model, however for all important contemporary systems, such a component clearly exists. We now explain the reasoning behind each element of these definitions and their implications for the model-system boundary. In practice, given the current paradigm of large neural networks based on transformer architecture, most AI models will start out as representations of some dataset. However, in order for our definition to function as intended, it is important that an entity continues to be an AI model even if it is not used for the purpose of representation, and even if it is modified in ways that make it a less accurate representation. According to our definition, AI models are core components of AI systems. However, the key difference is that AI systems receive input from and influence external (real or virtual) environments, which AI models cannot do. Therefore, according to our definition, an AI model can never be a system by itself, since it lacks the necessary properties. This puts us in line with the EUâs view on models and systems (European Parliament and Council of the European Union, 2024, Recital 97). Our definition of AI system is a simplified version of the definition found in OECD (2024). We used OECD as a basis because their definition of AI system already effectively captured the core concept behind the term, and that it is sensible to re-use existing definitions where possible, to aid compatibility with existing work. We simplified the definition slightly (mostly by removing examples) to make it easier to read. We are not concerned by the loss of technical precision or applicability, since this is the role of the operational definition, which will be presented later We recognise that the boundary between AI systems and systems that are not considered AI can be fuzzy. Since the Dartmouth Workshop in 1956, which is said to be the inception of AI (Russell and Norvig, 2009), there have been several paradigms and trends of AI development, some of which we have described in Section 4.2 (Paradigm Shifts in the Meaning of AI model and AI system). Notably, an earlier paradigm known as Good Old-Fashioned AI (GOFAI) mainly uses symbol manipulation explicitly defined by rules, and AIs developed in this manner are referred to as symbolic AI ISO/IEC (2022d, ISO/IEC 22989:2022 3.1.33). After the 21st century, especially after the creation of AlexNet in 2012, the dominant paradigm has been machine learning, where model parameters are optimised through computational techniques (ISO/IEC, 2022e, ISO/IEC 22989:2022 3.3.5). We elaborate on these paradigms below. These two main paradigms of AI do not have a clean boundary between them, as they have evolved slowly over decades. In addition, modern hybrid systems (e.g., neurosymbolic AI) increasingly combine learned statistical models with symbolic reasoning mechanisms, further blurring the boundaries between these approaches. Our intention is that our conceptual definition of AI system covers both approaches, making it as widely applicable and future-proof as possible. Our operational definition (given in the next section) focuses more heavily on the current paradigm of AI. Given the historical context of the term AI, which is to create intelligence artificially (i.e. non-human intelligence), and with the different paradigms that the field of AI went through, we find it challenging to come up with a clean conceptual definition of AI systems and AI models. Nevertheless, for AI systems, we believe it is important that, in line with cybernetic principles which preceded the field of AI, AI systems should carry the concept of producing outputs from inputs, where it would interact with its environment. 5.3 Operational Definitions for Contemporary AI Having a conceptual definition helps us understand what AI systems and AI models are, but it does not necessarily draw clean boundaries in a way that makes it clear what counts as AI systems or AI models. In this section, we attempt to develop an operational definition such that the boundary between an AI model and an AI system is clear. According to the American Psychological Association (2018), an operational definition is âa description of something in terms of the operations (procedures, actions, or processes) by which it could be observed and measuredâ. For example, Alan Turingâs proposed âimitation gameâ (Turing, 1950), now widely known as the Turing test, is considered to be an operational definition of machine intelligence (French, 2012). In other words, while a conceptual definition helps us understand the ideas behind a concept, an operational definition allows us to reliably identify instances of that concept in the real world. 21 A PREPRINT As discussed previously, there are many types of AIs, including symbolic AI, machine learning, and neurosymbolic systems. The question of where the boundary between the model and the system lies is thus applicable across the different types of AI. However, because the dominant paradigm in current high-impact and general-purpose AI deployments is neural network-based machine learning AI such as LLMs, the operational definitions developed here are explicitly scoped to this class of systems, since at present these are the systems most in need of effective regulation. We therefore focus on contemporary general-purpose AI systems such as transformer-based LLMs. These operational definitions are not intended to exhaustively characterise model-system boundaries for other types of AIs. This means that our operational definition is much narrower and less future-proof than our conceptual definition, while being much easier and clearer to apply in practice. This is why we provide both a conceptual and operational definition, as the conceptual definition can be used to guide future updates to the operational definition. We propose our operational definition in this section, summarised as follows: AI model (for contemporary AI): Trained parameters and their architecture, understood as the computational specification necessary to use them for inference. AI system (for contemporary AI): One or more AI models, an interface for receiving inputs from and delivering outputs to an environment, and the configuration connecting these and any additional components. In the rest of this section, we explain the rationale behind establishing these operational definitions. Based on both the systematic literature review and the manual review as well as the observed definitional developments in Section 4 (Findings and Analysis), we have found the OECD reports to have been the most informative and influential in developing such definitions. Hence, here we attempt to use definitions from the OECD reports as a starting point, and further operationalise it to clarify the boundary between AI systems and AI models. OECD (2024) defines AI system as follows: âAn AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.â (p. 4) Although the report does not explicitly provide a definition of an AI model, they describe it in several paragraphs, including the following: âAn AI model is a core component of an AI system used to make inferences from inputs to produce outputs. It is important to note that while the parameters of an AI model change during the build phase, they usually remain fixed after deployment once the build phase has concludedâ (p. 8) Several points follow from the OECD description. First, an AI system is described as inferring âfrom the input it receives,â implying that inputs originate outside the system and are not constitutive parts of it. Second, an AI model is characterised as âa core component of an AI systemâ which means it is considered a subset of the system rather than a representation of it. This means all parts of the model are necessarily parts of the system, but not vice-versa. Third, the model is the component responsible for performing inference. While the OECDâs phrasing is somewhat ambiguous (it is unclear if the AI model or the AI system is the one making inference), we take this to mean that the model is the component responsible for performing inference, and that the system possesses this capability by virtue of containing the model. Nevertheless, we can draw relationships between an AI system, AI model, and the inputs and outputs, as shown in Figure 6. This would be similar to the diagrams that OECD uses. In most cases, however, the AI system would contain other components that are not part of the AI model, which we elaborate further below. This can be illustrated in Figure 7. The description of an AI model being âa core component of an AI systemâ alone does not disambiguate what parts of a system are a part of the model. We must then rely on the additional elaboration, where the OECD notes that âwhile the parameters of an AI model change during the build phase, they usually remain fixed after deployment once the build phase has concludedâ. This suggests two additional properties that can be operationalised as criteria for AI models: its parameters change during the build phase, and that these parameters usually remain fixed after deployment. 22 A PREPRINT Figure 6: AI system containing an AI model Figure 7: AI system containing an AI model with other non-model components OECD does not specify an operational test for âcore component.â In applying the definition, we interpret âcoreâ as being necessary for the AI system to perform inference, and âcomponentâ as that it is part of the systemâs configuration rather than a transient computational state. Also referenced above are the âparametersâ and the âbuild phase.â While the âbuild phaseâ is not defined in the same OECD (2024) framework, it is described in OECD (2022) which references OECD (2019a), which states âthe model-building process is often called âtrainingâ or âoptimisationâ (OECD, 2022, p. 46). In the context of machine learning, the process of training updates the model parameters to achieve the training objectives. Parameters can also be defined as the mathematical objects that can be changed by the gradient descent process during training (LeCun et al., 2015). Interpreting the OECD description operationally yields three candidate criteria for identifying what counts as part of an AI model: 1. Core component of AI system to make inferences 2. Parameters change during the build phase, i.e. training phase 3. Usually remain fixed after deployment The concepts of âbuild phase,â âparameters,â and âafter deploymentâ are compatible with machine-learning-based AI. We therefore use the three criteria above as operational criteria for determining whether a given element belongs to the AI model or not. We apply these rules below to elements of a transformer-based LLM system, including weights, input prompts, activations, system prompts, retrieval-augmented generation (RAG), temperature settings, input or output filters, and fine-tuning. 1.Weights (and biases, where available): In the transformer architecture, these include embeddings and unembeddings weights, attention weights, feed-forward network weights, and layer normalisation weights. 23 A PREPRINT They are certainly a core component of AI systems, where these parameters change during the build phase, and usually remain fixed after deployment (unless the model undergoes continuous learning post-deployment). As such, weights are certainly part of the AI model, and they are often referred to as âmodel weightsâ. 2.Input prompt: Inputs are processed by the system but are not part of the systemâs configuration. They are runtime data rather than system components and are not made of parameters. Thus, they are not part of the AI model. 3. Activations: These are intermediate computational states produced during forward passes as a function of inputs and parameters. Although they are necessary for performing inference, they are not themselves trained parameters and do not persist as part of the system after computation. While they are usually referred to as âmodel activationsâ, they are not part of the systemâs configuration, as they are results of intermediate calculations performed during model inference. 4.System prompt: As inputs to the AI model (and correspondingly, the AI system), system prompts can be important components of an AI system as it greatly influences how it makes inferences. A system prompt stored as part of deployment configuration can be a core component of the system, but it is not made of parameters and thus not part of the AI model. 5.Retrieval-augmented generation (RAG): As a technique that takes in additional sources beyond the input or system prompts to perform model inference, it does not consist of parameters and therefore is not part of the AI model. The associated knowledge base or retrieval database may constitute a component of the AI system if it is integrated into deployment, but it contains data rather than trained parameters. Hence, RAG databases are treated as system components but not as parts of the AI model. 6. Temperature: As a setting that determines which tokens is being selected as output, this is not a component but a model setting. They do not contain parameters, and can be changed after deployment. 7.Input or output filters: These can be said to be components that modify inputs before it is being processed by the model, or modify model results before it is being output by the system. These filters can be rule-based or produced using a training process. In the latter case, they would then contain parameters that are updated during training. 8.Fine-tuning: As a training process that modifies model parameters, it is not itself a component. However, certain parameter-efficient fine-tuning (PEFT) methods such as low-rank adaptation (LoRA), produce trained parameters in an adapter that is then âattachedâ to a frozen base model. These adapters can be argued as a core component of an AI system, which contains parameters that are trained and usually do not change after deployment. These are summarised in Table 5. Table 5: Assessment of whether an element is part of an AI model according to the three candidate criteria from OECD (2024) Core component of AI system to make inferences Parameters change during the build phase Usually remain fixed after deployment Part of AI model? Model weightsYesYesYesYes Input promptYesNot parametersNot parametersNo ActivationsNot a component - they are dynamic intermediate computation results Not parametersNot parametersNo System promptNot a component - itâs an input of the model Not parametersNot parametersNo 24 A PREPRINT RAGNot a component - itâs a technique; but the associated knowledge base used by RAG can be a core component of the system Not parametersNot parametersNo Temperature settingNot a component - itâs a setting Not parametersNot parametersNo Input / output filtersComponent, but ambiguous if core It depends on whether it has parameters Yes if they are parameters Maybe, depending on whether it has parameters Parameter-efficient fine-tuning (PEFT), e.g. LoRA YesYes, even though it may not be built together with the rest of the model YesYes We can now see a fairly principled way of determining if something is part of an AI model or not. Nevertheless, we believe these conditions can be simplified. With regards to the point on âparameters change during the build phaseâ, where the âbuild phaseâ refers to model training, we can simplify the criteria of being considered part of the AI model as being âtrained parametersâ. In short, the definition of an AI model would contain two criteria: being a component of the AI system, and being trained parameters. Table 6: Assessment of whether an element is part of an AI model according to our candidate criteria Component of AI system Trained parametersPart of AI model? Model weightsYesYesYes Input promptNoNoNo ActivationsNot reallyNoNo System promptNoNoNo RAGNo for the technique itself; yes for the associated knowledge base, if implemented as part of the system NoNo Temperature settingNoNoNo Input / output filtersYesYes in some casesYes in some cases Dumb classifierYesNoNo Parameter-efficient fine-tuning (PEFT), e.g. LoRA Yes, if it is a component e.g. adapter Yes, if it is a component e.g. adapter Yes, if it is a component e.g. adapter A notable omission from the list above is model architecture. Architecture is not itself a set of trained parameters, and in its broad sense (e.g., âtransformerâ or âconvolutional neural networkâ) it denotes only a general design family 25 A PREPRINT rather than a specific model. However, in a narrower technical sense, architecture refers to the full computational graph specification, including the precise topology, connections, and operations that determine how trained parameters transform inputs into outputs. It is this narrower sense that is relevant here. Under our conceptual definition, an AI model is something capable of performing inference. Trained parameters alone cannot perform inference without a computational specification that determines how they are applied. Accordingly, model architecture in this technical sense must be treated as part of the AI model, as it provides the necessary computational structure through which trained parameters are used to generate outputs. This definition provides a principled way of determining whether something is part of an AI model. It also helps clarify when multiple trained parts belong to the same model. When several trained parts work together to produce a single inference and are not usable on their own to perform that inference, they are treated as parts of one AI model rather than as separate models. Under this approach, PEFT adapters such as LoRA are considered to be part of the AI model, since they adjust the modelâs parameters and are not used on their own. Likewise, instances of mixture-of-experts (MoE) architectures (including weights of all the experts) can be treated as a single AI model, because the experts and routing mechanisms work together to produce one inference and are not designed to operate separately. A further implication of treating trained parameters as constitutive of the model is that the underlying data used to produce those parameters (i.e., the training data) should be considered as falling within the scope of the model, since it directly shapes the modelâs trained parameters. By contrast, data that is merely connected to or retrieved by the model at runtime as part of the wider system (e.g., via RAG) should be considered as falling within the scope of the wider system rather than the model itself. Stepping back to the system level, the distinction between models and systems becomes clearer. An AI model consists of trained parameters and their architecture and is capable of performing inference. An AI system, by contrast, includes not only one or more such models but also the surrounding components that receive inputs and produce outputs in relation to an environment. This includes interfaces, configuration choices, and any additional components that are part of the systemâs overall functioning. This distinction becomes especially clear in the case of AI agents, which are typically designed to interact with an environment, maintain state or memory across steps, and select actions in pursuit of goals. Such systems generally include one or more AI models alongside additional components such as memory stores, planning modules, or tool-use mechanisms. Under the definitions proposed here, these assemblies clearly qualify as AI systems, as they combine models with interfaces and other components that enable interaction with an environment. 5.4 Comparison Against Existing Definitions As per the previous sections, our proposed definitions and clarifications on the terminologies are relevant to some of the conceptual perspectives and not others. We summarise our proposed definitions in Table 7. Table 7: Our proposed conceptual and summarised operational definitions of AI model and AI system Conceptual definitionSummarised operational definition for contem- porary AI AI modelA computational construct that makes infer- ences from inputs to produce outputs and forms (or is intended to form) the reasoning or knowledge core of an AI system. Trained parameters and their architecture, under- stood as the computational specification necessary to use them for inference. AI systemA machine-based system that makes infer- ences from inputs from physical or virtual environments to produce outputs that influ- ence physical or virtual environments. One or more AI models, an interface for receiving inputs from and delivering outputs to an environ- ment, and the configuration connecting these and any additional components. In defining an AI model, we use the conceptual perspective of treating the model as an artifact resulting from training (i.e. trained parameters) instead of treating the model as a representation of some external structure. As we are mainly concerned with contemporary general-purpose AI which are predominantly ML models, we operationally define a 26 A PREPRINT model as the result of the training process, which may be a definition that may not be appropriate for AI models that are not built through a training process. Additionally, we do not define an AI model in terms of its task-level function (e.g., prediction, recommendation, classification), since these functions are often properties of the system as a whole. While specifying particular functions may be suitable for defining specific AI systems, such as how Article 3(1) of the EU AI Act defines an AI system as being able to generate outputs âsuch as predictions, content, recommendations, or decisionsâ, this specificity may not be helpful for defining AI models. This is because task-level functions of a system may arise from the interaction between the model and other system components and may not arise solely from the model itself. Hence, we define a model only by the general function of being able to perform inference. For the relationship between the AI model and the AI system, we use one as a subset of the other, where the model is the subset of the system, and the system is the one that deals with the environment by taking in inputs and spitting out outputs. This is similar to but in contrast with Sharkey et al. (2024) who defines an AI model as a component of the AI system, but states that AI models can also be AI systems that have no other system parameters. We posit a model, considered in isolation, does not constitute a perception-action loop with an environment, as environmental interaction arises only at the system level. This is in line with Recital 97 of the EU AI Act which says âalthough AI models are essential components of AI systems, they do not constitute AI systems on their own. AI models require the addition of further components, such as for example a user interface, to become AI systemsâ (European Parliament and Council of the European Union, 2024). 5.5 Regulatory Implications and Recommendations In this section, we discuss regulatory implications and our recommendations both generally as well as specifically in the EU-context. 5.5.1 General Implications and Recommendations Regulatory frameworks implicitly assume a supply-chain structure. The distinction between AI models and AI systems is valuable insofar as it corresponds to separable stages of design and creation of components, integration into products, and deployment into consumer markets that are often handled by different actors with different capacities to foresee and mitigate risk. Its legal relevance therefore lies not in the terminology itself, but in how it helps map obligations onto real divisions of responsibility in the AI value chain. While some jurisdictions explicitly rely on a distinction between AI models and AI systems, notably the EU, other jurisdictions may frame similar separations albeit using different categories such as components, services, or applications. This issue becomes more salient with the rise of AI agents and agentic AI, which are often implemented by layering tools, memory, and other components onto existing or augmented models or systems (Sapkota et al., 2025), often by different actors in a modular manner. Across these variations in terminology and architecture, the key regulatory question is whether an artefact constitutes a separable or additional unit associated with a distinct actor and a distinct locus of control. Ambiguity in the boundary between AI models and AI systems or similar terminologies thus creates predictable regulatory failure modes, including misallocated obligations, duplicative compliance burdens, and enforcement gaps. As such, definitions should have sufficient clarity to result in regulation that clearly spells out what is regulated, which actor is responsible, and how obligations are triggered when specific modifications are performed. Our proposed operational definition of an AI model is deliberately narrow, identifying only the trained parameters and their architecture. In practice, however, commercial providers often place on the market a product that bundles the bare model with pre-specified components such as safety filters, content moderation layers, and system prompts, and refer to the whole package as a âmodel.â This terminological variation is reflected even in provider documentation which have evolved over time. OpenAI published a âModel Cardâ for GPT-3 (OpenAI, 2020) but shifted to âSystem Cardâ from GPT-4 onward (OpenAI, 2023); Anthropic similarly used âModel Cardâ through Claude 3.5 (Anthropic, 2024) before adopting âSystem Cardâ from Claude 3.7 (Anthropic, 2025). The terminologies for these documentations are updated as their products appear to expand from bare models to include other system components. On the other hand, Google DeepMindâs Gemini 3 Pro âModel Cardâ explicitly describes âproduct-level mitigations such as safety filtering,â acknowledging that what is being documented extends beyond the model while still labelling the document as a Model Card (Google DeepMind, 2025). More broadly, different parties along the value chain can and should draw their own contractual lines to allocate responsibilities. This is acceptable as long as some identifiable entity is designated as bearing each relevant obligation, 27 A PREPRINT and the precise boundary between a model and a system is only instrumental to ensuring no responsibilities or obligations fall between the cracks. Definitions should not be treated as ends in themselves; they serve a regulatory purpose, and if technological practice shifts enough that a given boundary no longer maps onto meaningful differences in control or responsibility, the definition should be revised or abandoned. Finally, we offer three principles for how regulatory definitions should relate to technical terminology. First, regulatory definitions should not deviate from technical consensus. Legal categories ultimately map onto technical artefacts in the real world, and a definition that is internally coherent from a drafting perspective may fail its purpose if it does not correspond to how real-world systems are actually built. We approached our proposed definitions with this consideration as a priority. Second, where a technically grounded definition is too narrow for a regulationâs objectives, the appropriate response is to expand the regulatory scope explicitly through carve-ins, special provisions, or adapted definitions, rather than to distort the underlying technical term. For example, if regulation targets systems based on autonomy or societal impact, some recommendation systems may fall within scope even without a clearly identifiable AI model. This should be handled through explicit provisions, not by stretching what model means. Third, where no existing technical term cleanly captures the intended regulatory object, it may be better to coin a new or more specific term purpose-built for the regulatory context rather than forcing an ill-fitting label into service. 5.5.2 Implications specific to the EU The EU AI Act (European Parliament and Council of the European Union, 2024) imposes obligations for providers of both high-risk AI systems (Article 16) and general-purpose AI models (Article 53). Providers are not limited to entities who first developed an AI system or an AI model. For high-risk AI systems, Article 25(1)(b) states that entities who make substantial modifications to a high-risk AI system shall be considered to be a provider of a high-risk system and become subject to provider obligations. For general-purpose AI models, a similar implication follows from two provisions. Recital 97 states that general-purpose AI models may be further modified or fine-tuned into new models, and Article 3(3) defines a provider to include entities who develop a general-purpose AI model and place it on the market. Together, these provisions support the view that placing a modified model on the market may confer provider status. However, ambiguity remains as to when a modifying entity qualifies as a provider. This stems from two related uncertainties: what counts as an AI model or AI system, and what degree of change counts as a substantial modification or as creating a new GPAI model. As such, the European Commission issued guidelines for providers of GPAI models to clarify the scope of these obligations (European Commission, 2025b, Article 96), alongside criteria for identifying AI models as GPAI models (Section 2.1) and for determining when an entity is considered a GPAI model provider (Section 3). However, because they do not clearly define what constitutes an AI model, uncertainty about modification and provider status persists, creating ambiguities on whether certain modified models are unregulated (Holtman and Chin, 2025). Several authors have attempted to address the ambiguity surrounding when a modification yields a new model. For example, building on work by Burden et al. (2025), Pacchiardi et al. (2025) proposes a framework for treating modified GPAI models as new ones by assessing behavioral changes, either by direct measurement or by using proxy metrics. On the other hand, Hacker and Holweg (2025) proposes categorizing modifications into insubstantial and substantial modifications, where insubstantial modifications include RAG, fine-tuning with minor adjustments, system prompts; while substantial modifications include fine-tuning with substantial adjustments, reinforcement learning with human or AI feedback (RLHF/RLAIF), and jailbreaking and related interventions. Unfortunately, categorizing modifications by substantiveness merely shifts the ambiguity to the question of when certain modifications are considered substantial. In both proposals, whether a change is a modification of a model is evaluated through proxies concerning intervention or behavior, without first specifying what constitutes the model whose modification is at issue. Our definitions address this prior question of what the model is, even though we do not purport to resolve when a modification is substantial enough to create a new model that comes with the relevant provider obligations. Our proposed operational definitions aim to help address these ambiguities and support more consistent allocation of responsibilities across the AI value chain. Current definitional gaps create uncertainty about what constitutes an AI model versus general-purpose software, where system boundaries lie when multiple components are integrated, and which entities bear provider obligations in complex deployment scenarios. For instance, when an entity combines a retrieval system with a generative model to create a retrieval-augmented generation application, our operational definition clarifies that the retrieval component alone (which merely retrieves data) does not constitute an AI model, whereas the generative component (which consists of trained parameters) does, thereby clarifying which aspects of modification ought to trigger relevant provider obligations. Similarly, the definitions help allocate responsibilities when models are accessed remotely via APIs and integrated into downstream applications. In such cases, even though a model in itself may have passed through rigorous safety assessments, the system into which it is integrated could behave in 28 A PREPRINT ways that are inconsistent with the modelâs intended performance once additional components are added to the system. Hence, the obligations of the provider of this system can thus be considered separately from those of the underlying model provider. A related source of ambiguity concerns safety-enhancing components bundled with a model prior to market placement. Article 55(1)(b) of the EU AI Act requires providers of GPAI models with systemic risk to âassess and mitigate possible systemic risksâ, and Measure 5.1 of the GPAI Code of Practice explicitly lists system-level interventions among appropriate safety mitigations, including input/output filtering, staged API access, and tools for downstream actors (European Commission, 2025a). This makes clear that it is acceptable and even expected for model providers to deploy system-level components to mitigate model-level risks. Under our operational definition, such additions (e.g., output filters, guardrails) are system-level components rather than parts of the model itself. However, the provider may package and market the entire bundle as a single âmodel.â This does not, in our view, change the underlying technical composition, any more than packaging changes the nature of the packaged product. For regulatory purposes, this bundling should not affect the providerâs status: if the product being offered clearly contains a model, the provider remains subject to model-provider obligations regardless of what additional components are included. Our recommendation is in-line with that of Chin and Holtman (2025), who propose as a general principle that the provider of a new model should unilaterally and pre-emptively define in their documentation exactly what they consider the boundaries of their model to be. Notably, our conceptual and operational definition of AI model and AI system is built upon the definition of OECD 2024, which also served as the basis of the definition in the EU AI Act (Nessler and Wendehorst, 2024). As a result, these definitions can easily be incorporated into existing regulations simply by providing additional clarification rather than requiring amendments. In the EU context, the most practical mechanism for incorporating these refined definitions would be through updated Commission guidelines issued under Article 96 of the AI Act, such as the guidelines for providers of general-purpose AI models (European Commission, 2025b) issued in July 2025. We believe additional clarity will be helpful for various actors in the value chain, such as providers and deployers for AI systems and GPAI models. 5.6 Case Studies The following case studies illustrate practical consequences of ambiguities in distinguishing between models and systems, and demonstrate how our proposed operational definitions may contribute to resolving these ambiguities. 5.6.1 AlienChat Dispute In September 2025, the Xuhui District Peopleâs Court in Shanghai convicted the two developers of the AlienChat app of âproducing obscene materials for profitâ under Chinese criminal law (Zhang, 2026). AlienChat integrated a third-party large language model to generate conversational responses and monetised access through subscriptions. The court found that the chatbot routinely generated sexually explicit content at scale. At the core of the dispute was not whether the underlying model was capable of producing explicit language, but why such content was regularly produced at scale in deployment. The defendants argued that the ability to generate sexual content was an inherent property of the large language model they had integrated, and that the application merely exposed this pre-existing capability. The prosecution and the court, by contrast, focused on system-level design and deployment choices, including modifications to system prompts, the configuration of safety constraints, and the overall interaction design of the application. These were treated as evidence that the app developers had intentionally shaped the chatbotâs behaviour to elicit and sustain explicit interactions, rather than merely passing through the default neutral model outputs. Our proposed definitions would arrive at the same conclusion, where the addition of non-model components of the system had changed the behavior of the system, even though modifications were not performed on the model. Nevertheless, in this case, the primary contribution of clearer definitions is analytic clarity and evidentiary burden. They help distinguish between harms arising from deployment choices and those arising from latent model capabilities or propensities, which can structure legal and factual analysis with regards to the allocation of liability. 5.6.2 ChatGPT Geofencing in Italy In 2023, the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, Garante) issued a temporary limitation order on ChatGPT, which operated on OpenAIâs GPT-3.5 model, citing concerns about compliance with multiple provisions of the GDPR. Garante found that OpenAI lacked an appropriate legal basis for the collection 29 A PREPRINT and processing of personal data used to train the systemâs underlying algorithms, raising potential infringement issues under the GDPR (Braun, 2023). One issue highlighted in public debate around the case was the difficulty of applying data subject rights, where the relationship between model training data and ongoing service-level processing became conceptually contested. OpenAI was subsequently fined a total ofC15 million in relation to GDPR violations connected to ChatGPTâs data processing (Laher, 2025). Although the service was reinstated after OpenAI implemented additional transparency and user-rights mechanisms, the company did not publicly clarify whether personal data used in prior training had been removed or technically isolated. This uncertainty highlights a structural tension in data protection law: regulatory restrictions were applied to the deployed service, while some of the underlying concerns related to historical training practices that shape model behavior. The order targeted the system level (ChatGPT service in Italy), but the contested data processing was reflected in the model parameters through training. While in this particular case, the provider of both the AI model and the AI system was the same entity i.e. OpenAI, a lack of clarity between the model and system may prove legally challenging had they been provided by different entities. Under our proposed definitions, disputes about personal data used to train the model would concern the model itself, whereas disputes about personal data used as part of the systemâs operation or accessed by the system at runtime (e.g., via RAG databases) would concern the system. This distinction does not by itself resolve how regulators should respond when personal data are already incorporated into model parameters and cannot be selectively removed. However, it clarifies whether a regulatory measure is directed at data used in model training or system-level data use, which in turn affects which actors are in a position to comply. 5.6.3 Clearview AI Litigation Clearview AI, a facial recognition company based in the United States, developed a search engine built on an AI system trained using data scraped from publicly available websites, including social media platforms. By 2024, the companyâs database contained over 50 billion facial images, which were converted into biometric identifiers and stored as feature vectors, which are numerical embeddings that allow the system to match uploaded images against the database (Jung and Kwon, 2024). Regulators across Europe determined that this end-to-end pipeline, from mass data collection to the embedding of facial features, violated privacy rights under GDPR. Similar legal scrutiny followed in Canada, Australia, and the United States. Under the terms of the ACLU v. Clearview AI settlement, the restrictions applied to access to the faceprint database, while the facial recognition algorithm itself was not subject to the injunction (ACLU of Illinois, 2022). Although banned from operating in the EU, Australia, and Canada, and barred under the ACLU settlement from providing database access to most private entities nationwide and to any entity in Illinois for five years, Clearview retained the ability to sell its facial recognition algorithm without the accompanying embeddings database to public and private entities elsewhere in the US (ACLU of Illinois, 2022). In the ACLU v. Clearview AI settlement, the company admitted no liability (Clearview AI, 2022). This divergence in regulatory outcomes illustrates that jurisdictions do not consistently regulate both the AI model and the broader system in which it operates. The US settlement left the algorithm untouched, restricting only access to the faceprint database, effectively treating the model and database as separable for remedial purposes. However, authorities in the EU, Canada, and Australia concluded that the embeddings themselves constitute biometric data that remain linked to identifiable individuals, and therefore subject to data protection law. Our proposed operational definitions do not determine whether embeddings qualify as biometric data, which is a separate legal question. They instead clarify what is being referred to when actors and regulators speak of the model versus the system, which can matter in disputes involving modular architectures or multiple responsible parties. In this case, regulators differed in whether they treated the database at the system level or the trained model as the object of regulation. Making these layers explicit helps describe such differences in regulatory practice more precisely. 6 Limitations In this section, we discuss the limitations of the manual and systematic literature review process, as well as limitations of our proposed conceptual and operational definitions. 30 A PREPRINT 6.1 Methodological Limitations Several limitations emerged throughout the literature review process during the different stages of the review that affect the completeness of the collected dataset and the interpretive certainty of the findings. This section discusses the challenges and limitations of both the manual review and the systematic literature review. 6.1.1 Manual Review: Limitations in Screening and Inclusion Incorrect References In some cases, different versions of the same regulatory or standards documents were inadvertently referenced, leading to inconsistencies in citations and uncertainty about which definition was operative at the time of publication. This issue is exacerbated by the frequent revision cycles of regulatory drafts and newly updated standards. Relatedly, definitions were occasionally misattributed, due to publications reusing earlier definitions without direct credit. These incorrect references may have impacted the analysis and comparison of different definitions. Ambiguity in Definitional Boundaries In many cases, there was a lack of explicit definitional sections in the documents. Several sources discuss AI models and systems descriptively but do not formally define them, and descriptions were often dispersed throughout the text. This would require interpretive judgments about whether a passage constituted a definition or was merely contextual commentary. This may have introduced subjectivity into inclusion decisions and may have led to the exclusion of borderline cases. Identifying Original Contributions During the manual extraction of definitions, there was some difficulty in tracing the chain of influence across definitions. Many definitions that appear as standalone entries in different sources are in fact replications or paraphrases of earlier definitions. This limited the ability to assess definitional originality and may have artificially inflated counts of âuniqueâ definitions. 6.1.2 Systematic Literature Review: Limitations in Search and Corpus Construction Language Constraints and Jurisdictional Representation The scope of the corpus was constrained by the inclusion and exclusion criteria, which limited the search to materials written in English. While this ensured terminological consistency given the studyâs focus on the specific phrases AI model and AI system, it necessarily excluded regulations, standards, and academic literature from jurisdictions where English is not the primary language of publication. Consequently, the final corpus exhibits a predominantly Eurocentric representation, reflecting jurisdictions such as the EU and OECD member states, whose materials are both accessible in English and where these terms are most explicitly formalised. It is important to acknowledge, however, that non-English jurisdictions may use alternative terminology or conceptual framings that could contribute meaningfully to future analyses of how these definitions evolve. Source Fragmentation It was observed that relevant regulatory and standards documents were distributed across agency websites, standards repositories, and institutional portals, many of which lacked unified indexing or persistent identifiers. This decen- tralisation made it difficult to retrieve materials through database-driven searches and often required supplementary manual search and retrieval, leading to reduced reproducibility. As a consequence, results may be skewed towards more accessible or well-indexed documents. Access Barriers Certain materials, such as technical standards from ISO were paywalled, preventing full-text access and verification. For these materials, analysis retrieval was usually conducted through limited previews, or references in other sources including excerpts or summaries. This may have resulted in the overrepresentation of open-access publications, whereas closed-access materials yielded fewer definitional artifacts despite being relevant. Imbalance between AI model vs AI system 31 A PREPRINT Definitions of AI systems appeared far more frequently than definitions of AI models. As a result, the corpus is inherently skewed toward system-level descriptions. This limited the comparative analysis across the two terms and their definitional boundary, and nuanced changes in the conceptualisation of AI models may have been overlooked. 6.2 Definitional Limitations and Future Work This work aimed to clarify an important distinction between two concepts that have been used almost interchangeably for the past few years, despite being given different roles in the legislation. The main challenge was to align with common usage in the field, when it is this usage that has been ambiguous. Words do not have an inherent definition, as their meaning comes from usage, and the boundaries we have placed could be deemed arbitrary. Our focus was that these new definitions could disambiguate the concepts of AI models and AI systems, so that regulatory frameworks referencing these concepts could be applied with greater clarity. However, the definitions do not resolve all ambiguities. Years of inconsistent and overlapping usage of the terms AI models and AI systems, be it in technical literature, standards, and industry practice mean that it is not always clear where the boundaries of these concepts should lie. While improved definitions can reduce ambiguity in many cases, they cannot provide definitive answers to all edge cases. Some questions may not have a single âcorrectâ solution at present, as the field would first have to converge on shared understanding of certain fundamental distinctions. Rather than claiming to provide definitive answers to all edge cases, our work aims to propose operational definitions that reduce ambiguity where possible, while highlighting remaining areas where continued interpretation and debate among regulators, implementers, and the technical community will be necessary. Furthermore, despite an attempt to be technology neutral and future-proof, it is impossible to predict whether radical shifts in AI paradigms could give rise to new forms that would not fit neatly within the boundaries drawn by our definitions. Our proposed conceptual and operational definitions are grounded in current understanding of how AI models and systems are structured and deployed. While expect this framework to remain functional for at least 5-10 years considering current AI trajectories and past AI paradigm cycles (Dhar, 2023), future developments may be transformative enough to represent fundamental breaks from current paradigms, and could require reconceptualisation of these fundamental categories. In consequence, mechanisms for periodic review and refinement of regulatory definitions into the governance frameworks that rely on them will be necessary. Several categories of ambiguity remain unresolved. First, questions about compositional architectures persist: In agent-based systems, should the tools available to the agent be considered part of the system? Likewise, should the data used by a RAG system be considered as part of the system, or external to the system? Second, determining when modifications create a new model rather than an updated version of an existing model remains challenging. While the EU AI Act provides specific thresholds, such as the guideline that modifications using one-third of the original training compute may constitute a new model (European Commission, 2025b), it remains unclear whether compute-based metrics adequately capture the relevant distinctions. The relationship between computational resources expended and functional changes is not straightforward: shallow fine-tuning with minimal compute can produce significant behavioral shifts (Volkov, 2024), such as circumventing safety guardrails, while extensive parameter updates might produce relatively smaller functional changes. Moreover, as the scale of AI training continues to grow, fixed compute thresholds may become less meaningful indicators of whether a model has been sufficiently transformed to warrant treatment as a new regulatory object. Third, technical questions about model identity remain open: does changing activation functions without modifying weights constitute a new model? More fundamentally, when regulatory obligations hinge on these distinctions, what criteria should determine whether a modified system triggers new compliance requirements? 7 Conclusions This paper provides a comprehensive survey and analysis of how AI model and AI system are defined across regulatory frameworks, standards bodies, and academic literature. Through both systematic and manual literature reviews, we examined over 80 definitions from sources including the OECD, EU AI Act, ISO standards, NIST, and numerous academic publications, tracing the evolution of these terms from 2012 to the present. Our findings reveal several key insights. First, definitions of AI system are far more numerous and developed than those of AI model, reflecting the historical focus of governance discourse on system-level considerations. Second, we identified a concentrated chain of influence flowing from Russell and Norvigâs foundational textbook into OECD frameworks, and further into ISO, NIST and EU definitions. Third, we documented how the OECDâs own definitions evolved from 2019 to 2024, with the term AI model expanding from a representation-focused definition to one that considers a modelâs role as the reasoning and knowledge core of an AI system. 32 A PREPRINT In our conceptual analysis of the existing literature, we found that definitions of AI models and AI systems can be organised along two main axes: parent categories (what kind of object they are taken to be) and features (how they are produced and what functions they serve). For AI models, we identified two principal parent categories: model as artifact, which emphasises the result of building or training processes such as weights and parameters, and model as representation, which focuses on the modelâs purpose of representing some external structure. The representation is rooted in the history of AI (world models in classical agent architectures, neural networks as models of biological neurons, transformers originating in computational language modelling, etc). However, this perspective has become increasingly strained when applied to contemporary systems. Large language models, for instance, are routinely called models despite not obviously being models of anything (particularly post fine-training). We argue that their designation as models stems from architectural lineage rather than from any representational function they perform. Recognising and accounting for this semantic drift is important to ensure that our definitions resemble the usage of the terms by frontier AI developers, helping those developers to clearly understand their legal responsibilities. Our proposed definitions of the terms AI models and AI systems improve on the current state of the art while remaining compatible with existing regulatory frameworks. Our operational definition takes the form of an extensional definition grounded in technical practice, ensuring that it can be straightforwardly applied in real-world settings. Specifically, for neural network-based machine learning AI, we propose that an AI model consists of trained parameters and their architecture, understood as the computational specification necessary to use them for inference. This resolves questions about whether components such as system prompts, temperature settings, or retrieval databases constitute part of the model. Furthermore, our conceptual definition of AI models, while less suitable for real-world application, helps to explain the conceptual motivation behind our work, and should serve as a useful guide in case future AI paradigms require an adjustment in our operational definition. For AI systems and other definitions such as GPAI models, we find that the existing definitions are generally adequate, so we only recommend light changes to existing standards, if necessary. Our work has several implications for policymakers and standards bodies. By design, our definitions and recom- mendations can be incorporated into existing legal or technical frameworks without requiring substantial amendment. By clarifying the boundary between models and systems, these definitions support more consistent allocation of responsibilities across the AI value chain. This is a matter of increasing practical importance as models are deployed through APIs and integrated into downstream applications by parties other than the original developers. While we believe that our work represents a significant contribution to the field, it is not without limitations, which we have outlined and discussed in the paper. For example, our corpus exhibits a predominantly English-language and Eurocentric representation, potentially missing alternative conceptual framings from other jurisdictions. Additionally, while we have attempted to future-proof our definitions, transformative developments in AI could necessitate recon- ceptualisation of these fundamental categories. Future work should extend this analysis to non-English regulatory frameworks and examine how definitions are operationalised in enforcement actions and compliance assessments. As AI systems become more complex and modular, empirical studies of how boundary disputes are resolved in practice would provide valuable guidance for refining definitional frameworks. The periodic review and refinement of regulatory definitions should be built into governance frameworks as a matter of course. The effective regulation of AI requires shared understanding of fundamental terms. By documenting the landscape of existing definitions, analysing their conceptual underpinnings, and proposing clarifications grounded in both technical practice and regulatory needs, we hope to contribute towards this goal. 8 Acknowledgements This work was carried out through the Supervised Program for Alignment Research (SPAR), whose program structure and infrastructure support made the research possible. We thank Koen Holtman, Antonio Puertas Gallardo, Yi-Yang Chua, Zifeng Wang, and Adrian RegenfuĂ for helpful comments on earlier drafts. All errors remain our own. 9 References Phoebe Zhang. Jailed Chinese AI chatbot developers appeal landmark pornography case. South China Morning Post, jan 2026. URLhttps://w.scmp.com/news/china/politics/article/3339908/jailed-chinese-a i-chatbot-developers-appeal-landmark-pornography-case. Accessed: 2026-02-11. Italian Data Protection Authority. Artificial intelligence: stop to ChatGPT by the Italian SA. Personal data is collected unlawfully, no age verification system is in place for children. Press Release, mar 2023a. URLhttps: 33 A PREPRINT //w.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9870847. Garante per la protezione dei dati personali. Document number: 9870847. Published: 2023-03-31. Accessed: 2025-02-11. Italian Data Protection Authority. ChatGPT: OpenAI reinstates service in Italy with enhanced transparency and rights for European users and non-users. Press Release, apr 2023b. URLhttps://w.garanteprivacy.it/web/gues t/home/docweb/-/docweb-display/docweb/9881490. Garante per la protezione dei dati personali. Document number: 9881490. Published: 2023-04-28. Accessed: 2025-02-11. Won Kyung Jung and Hun Yeong Kwon. Privacy and data protection regulations for AI using publicly available data: Clearview AI case. In Proceedings of the 17th International Conference on Theory and Practice of Elec- tronic Governance, ICEGOV 2024, pages 48â55, Pretoria, South Africa, oct 2024. ACM. ISBN 9798400717802. doi:10.1145/3680127.3680200. URL https://doi.org/10.1145/3680127.3680200. Stuart Russell and Peter Norvig. Artificial Intelligence: A Modern Approach. Pearson, Upper Saddle River, NJ, USA, third edition, dec 2009. ISBN 9780136042594. OECD. Scoping the OECD AI principles: Deliberations of the expert group on artificial intelligence at the OECD (AIGO). Technical Report 291, Organisation for Economic Co-operation and Development, nov 2019a. URL https://w.oecd.org/en/publications/scoping-the-oecd-ai-principles_d62f618a-en.html. Reference code: DSTI/CDEP(2019)1/FINAL. Matthijs Maas. Concepts in Advanced AI Governance: A Literature Review of Key Terms and Definitions, oct 2023. URL https://law-ai.org/advanced-ai-gov-concepts/. Ajay Bandi, Bhavani Kongari, Roshini Naguru, Sahitya Pasnoor, and Sri Vidya Vilipala. The Rise of Agentic AI: A Review of Definitions, Frameworks, Architectures, Applications, Evaluation Metrics, and Challenges. Future Internet, 17(9):404, sep 2025. ISSN 1999-5903. doi:10.3390/fi17090404. URLhttps://w.mdpi.com/1999-5 903/17/9/404. Ravil I. Mukhamediev, Yelena Popova, Yan Kuchin, Elena Zaitseva, Almas Kalimoldayev, Adilkhan Symagulov, Vitaly Levashenko, Farida Abdoldina, Viktors Gopejenko, Kirill Yakunin, Elena Muhamedijeva, and Marina Yelis. Review of Artificial Intelligence and Machine Learning Technologies: Classification, Restrictions, Opportunities and Challenges. Mathematics, 10(15):2552, jul 2022. ISSN 2227-7390. doi:10.3390/math10152552. URL https://w.mdpi.com/2227-7390/10/15/2552. Manuel MĂŒller, Timo MĂŒller, Behrang Ashtari Talkhestani, Philipp Marks, Nasser Jazdi, and Michael Weyrich. Industrial autonomous systems: a survey on definitions, characteristics and abilities. at - Automatisierungstechnik, 69(1):3â13, jan 2021. doi:doi:10.1515/auto-2020-0131. URL https://doi.org/10.1515/auto-2020-0131. Martin Sposato. Artificial intelligence in educational leadership: a comprehensive taxonomy and future directions. International Journal of Educational Technology in Higher Education, 22(1):20, apr 2025. ISSN 2365-9440. doi:10.1186/s41239-025-00517-1. URLhttps://educationaltechnologyjournal.springeropen.com/ar ticles/10.1186/s41239-025-00517-1. Isaac Triguero, Daniel Molina, Javier Poyatos, Javier Del Ser, and Francisco Herrera. General Purpose Artificial Intelligence Systems (GPAIS): Properties, Definition, Taxonomy, Societal Implications and Responsible Governance. Information Fusion, 103:102135, mar 2024. ISSN 15662535. doi:10.1016/j.inffus.2023.102135. URLhttp: //arxiv.org/abs/2307.14283. Dewey Murdick, James Dunham, and Jennifer Melot. AI Definitions Affect Policymaking. Issue brief, Center for Security and Emerging Technology, Washington, DC, jun 2020. URLhttps://cset.georgetown.edu/public ation/ai-definitions-affect-policymaking/. David FernĂĄndez-Llorca, Emilia GĂłmez, Ignacio SĂĄnchez, and Gabriele Mazzini. An interdisciplinary account of the terminological choices by EU policymakers ahead of the final agreement on the AI Act: AI system, general purpose AI system, foundation model, and generative AI. Artificial Intelligence and Law, 33(4):875â888, dec 2025. ISSN 0924-8463, 1572-8382. doi:10.1007/s10506-024-09412-y. URLhttps://link.springer.com/10.1007/s105 06-024-09412-y. Carlos Trincado CastĂĄn. The legal concept of artificial intelligence: The debate surrounding the definition of AI system in the AI act. BioLaw Journal - Rivista di BioDiritto, pages 305â344, 2024. ISSN 2284-4503. doi:10.15168/2284- 4503-3000. URL https://teseo.unitn.it/biolaw/article/view/3000. Slobodan Tomi Ì c and Vid Ć timac. Pinning down an octopus: towards an operational definition of AI systems in the EU AI Act. Journal of European Public Policy, pages 1â36, aug 2025. ISSN 1350-1763, 1466-4429. doi:10.1080/13501763.2025.2534648. URLhttps://w.tandfonline.com/doi/full/10.1080/135 01763.2025.2534648. 34 A PREPRINT John Burden, Lorenzo Pacchiardi, Plumed Fernando MartĂnez, and Orallo Jose HernĂĄndez. A Framework for General- Purpose AI Model Categorisation. Publications Office of the European Union, oct 2025. ISBN 978-92-68-31431-9. doi:10.2760/5330387. URLhttps://publications.jrc.ec.europa.eu/repository/handle/JRC143256. JRC number: JRC143256. P. M. Krafft, Meg Young, Michael Katell, Karen Huang, and Ghislain Bugingo. Defining AI in Policy versus Practice, dec 2019. URL http://arxiv.org/abs/1912.11095. Algorithm Audit. Implementation of the AI act: Definition of an AI system. White paper, Algorithm Audit, Amsterdam, Netherlands, feb 2025. URLhttps://algorithmaudit.eu/knowledge-platform/knowledge-base/guid elines_ai_act_implementation/. European Commission. Guidelines on the scope of obligations of providers of general-purpose AI models under the AI Act. European Commission, jul 2025a. URLhttps://digital-strategy.ec.europa.eu/en/library/gu idelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act. Annex to the communication to the Commission. Accessed: 2026-02-13. European Commission. Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act), jul 2025b. URLhttps://digital-strategy.ec.europa.eu/en/libr ary/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rul es-application. Communication from the Commission. Angela Carrera-Rivera, William Ochoa, Felix Larrinaga, and Ganix Lasa. How-to conduct a systematic litera- ture review: A quick guide for computer science research. MethodsX, 9:101895, jan 2022. ISSN 2215-0161. doi:10.1016/j.mex.2022.101895. URLhttps://w.sciencedirect.com/science/article/pii/S2215016 122002746. Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton. ImageNet Classification with Deep Convolutional Neural Networks. In F. Pereira, C. J. Burges, L. Bottou, and K. Q. Weinberger, editors, Advances in Neural Information Processing Systems, volume 25. Curran Associates, Inc., 2012. URLhttps://proceedings.neurips.c/paper _files/paper/2012/file/c399862d3b9d6b76c8436e924a68c45b-Paper.pdf. ISO. ISO 704:2022. Terminology work â Principles and methods. International Organization for Standardization, Geneva, Switzerland, 4 edition, jul 2022. URL https://w.iso.org/standard/79077.html. European Data Protection Supervisor. Guidance for Risk Management of Artificial Intelligence systems, nov 2025. URLhttps://w.edps.europa.eu/system/files/2025-11/2025-11-11_ai_risks_management_guid ance_en.pdf. ISO/IEC. Information technology â Artificial intelligence â Artificial intelligence concepts and terminology. model. International Organization for Standardization, Geneva, Switzerland, 2022a. URLhttps://w.iso.org/obp/ ui/en/#iso:std:iso-iec:22989:ed-1:v1:en:term:3.1.23. Standard number: ISO/IEC 22989:2022(en). Term: 3.1.23. Executive Office of the President. Safe, secure, and trustworthy development and use of artificial intelligence. Federal Register, Vol. 88, No. 210, 75191â75226, nov 2023. URLhttps://w.federalregister.gov/documents/ 2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-i ntelligence. Executive Order 14110. OECD. Explanatory memorandum on the updated OECD definition of an AI system. Technical Report 8, OECD Publishing, Paris, mar 2024. URLhttps://w.oecd.org/en/publications/explanatory-memor andum-on-the-updated-oecd-definition-of-an-ai-system_623da898-en.html. Reference code: DSTI/CDEP/AIGO(2023)8/FINAL. Marina EstĂ©vez Almenzar, David FernĂĄndez Llorca, Emilia GĂłmez GutiĂ©rrez, and Fernando MartĂnez Plumed. Glossary of human-centric artificial intelligence. JRC Science for Policy Report EUR 31113 EN, Joint Research Centre (European Commission), Luxembourg, 2022. URLhttps://publications.jrc.ec.europa.eu/repository /handle/JRC129614. Yatao Li and Jianfeng Zhan. SAIBench: Benchmarking AI for Science. BenchCouncil Transactions on Benchmarks, Standards and Evaluations, 2(2):100063, apr 2022. ISSN 27724859. doi:10.1016/j.tbench.2022.100063. URL https://linkinghub.elsevier.com/retrieve/pii/S2772485922000503. ISO/IEC. Information technology â Artificial intelligence â Artificial intelligence concepts and terminology. artificial intelligence system. International Organization for Standardization, Geneva, Switzerland, 2022b. URLhttps: //w.iso.org/obp/ui/en/#iso:std:iso-iec:22989:ed-1:v1:en:term:3.1.4 . Standard number: ISO/IEC 22989:2022(en). Term: 3.1.4. 35 A PREPRINT High-Level Expert Group on Artificial Intelligence. Ethics guidelines for trustworthy AI. Technical report, European Commission, apr 2019a. URLhttps://digital-strategy.ec.europa.eu/en/library/ethics-guideli nes-trustworthy-ai. UNESCO. Recommendation on the Ethics of Artificial Intelligence. Technical Report SHS/BIO/PI/2021/1, United Nations Educational, Scientific and Cultural Organization, Paris, France, 2022. URLhttps://unesdoc.unesco .org/ark:/48223/pf0000381137. Adopted: 2021-11-23. High-Level Expert Group on Artificial Intelligence. A Definition of AI: Main Capabilities and Disciplines. Technical report, European Commission, apr 2019b. URLhttps://digital-strategy.ec.europa.eu/en/library/de finition-artificial-intelligence-main-capabilities-and-scientific-disciplines. Center for Humane Technology. Ai in society, 2024. URLhttps://w.humanetech.com/ai-society. Accessed: 2026-02-14. Isabelle Hupont, David FernĂĄndez-Llorca, Sandra Baldassarri, and Emilia GĂłmez. Use case cards: a use case reporting framework inspired by the European AI Act. Ethics and Information Technology, 26(2):19, jun 2024. ISSN 1388- 1957, 1572-8439. doi:10.1007/s10676-024-09757-7. URLhttps://link.springer.com/10.1007/s10676-0 24-09757-7. European Parliament and Council of the European Union. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on Artificial Intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act), jul 2024. URL https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689. Official Journal of the European Union L 2024/1689. Adopted: 2024-06-13. Published: 2024-07-12. Jesse Dunietz, Gry Hasselbalch, Irina Orssich, Andrea Renda, Reva Schwartz, and Elham Tabassi. EU-U.S. Terminology and Taxonomy for Artificial Intelligence. Technical report, European Commission and National Institute of Standards and Technology (NIST), apr 2024. URL https://digital-strategy.ec.europa.eu/en/library/eu-us-t erminology-and-taxonomy-artificial-intelligence-second-edition. EU-U.S. Trade and Technology Council (TTC) Working Group 1: Technology Standards. ISO/IEC. Information technology â Artificial intelligence â Artificial intelligence concepts and terminology. Interna- tional Organization for Standardization, Geneva, Switzerland, 2022c. URLhttps://w.iso.org/obp/ui/en/ #iso:std:iso-iec:22989:ed-1:v1:en. Standard number: ISO/IEC 22989:2022(en). Oxford English Dictionary. model, n. & adj., n.d. URLhttps://w.oed.com/dictionary/model_n. Accessed 14 February 2026. Wayne Xin Zhao, Kun Zhou, Junyi Li, Tianyi Tang, Xiaolei Wang, Yupeng Hou, Yingqian Min, Beichen Zhang, Junjie Zhang, Zican Dong, Yifan Du, Chen Yang, Yushuo Chen, Zhipeng Chen, Jinhao Jiang, Ruiyang Ren, Yifan Li, Xinyu Tang, Zikang Liu, Peiyu Liu, Jian-Yun Nie, and Ji-Rong Wen. A Survey of Large Language Models, mar 2025. URL http://arxiv.org/abs/2303.18223. Warren S. McCulloch and Walter Pitts. A logical calculus of the ideas immanent in nervous activity. The Bulletin of Mathematical Biophysics, 5(4):115â133, dec 1943. ISSN 0007-4985, 1522-9602. doi:10.1007/BF02478259. URL http://link.springer.com/10.1007/BF02478259. George Cybenko. Approximation by superpositions of a sigmoidal function. Mathematics of Control, Signals, and Systems, 2(4):303â314, dec 1989. ISSN 0932-4194, 1435-568X. doi:10.1007/BF02551274. URLhttp: //link.springer.com/10.1007/BF02551274. Kurt Hornik, Maxwell Stinchcombe, and Halbert White. Multilayer feedforward networks are universal approximators. Neural Networks, 2(5):359â366, jan 1989. ISSN 0893-6080. doi:10.1016/0893-6080(89)90020-8. URLhttps: //w.sciencedirect.com/science/article/pii/0893608089900208. Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, Lukasz Kaiser, and Illia Polosukhin. Attention Is All You Need, jun 2017. URL http://arxiv.org/abs/1706.03762. OECD. OECD Framework for the Classification of AI systems. OECD Digital Economy Papers, feb 2022. doi:10.1787/cb6d9eca-en. URLhttps://w.oecd.org/en/publications/oecd-framework-for-t he-classification-of-ai-systems_cb6d9eca-en.html. Tom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared Kaplan, Prafulla Dhariwal, Arvind Neelakantan, Pranav Shyam, Girish Sastry, Amanda Askell, Sandhini Agarwal, Ariel Herbert-Voss, Gretchen Krueger, Tom Henighan, Rewon Child, Aditya Ramesh, Daniel M. Ziegler, Jeffrey Wu, Clemens Winter, Christopher Hesse, Mark Chen, Eric Sigler, Mateusz Litwin, Scott Gray, Benjamin Chess, Jack Clark, Christopher Berner, Sam McCandlish, Alec Radford, Ilya Sutskever, and Dario Amodei. Language models are few-shot learners. In 36 A PREPRINT Proceedings of the 34th International Conference on Neural Information Processing Systems, NIPS â20, pages 1877â1901, Red Hook, NY, USA, dec 2020. Curran Associates Inc. ISBN 978-1-7138-2954-6. URLhttps: //dl.acm.org/doi/10.5555/3495724.3495883. Arvind Ramanathan, Laura L. Pullum, Faraz Hussain, Dwaipayan Chakrabarty, and Sumit Kumar Jha. Integrating symbolic and statistical methods for testing intelligent systems: Applications to machine learning and computer vision. In 2016 Design, Automation & Test in Europe Conference & Exhibition (DATE), pages 786â791, mar 2016. URL https://ieeexplore.ieee.org/document/7459413. ISSN: 1558-1101. Rishi Bommasani, Drew A. Hudson, Ehsan Adeli, Russ Altman, Simran Arora, Sydney von Arx, Michael S. Bernstein, Jeannette Bohg, Antoine Bosselut, Emma Brunskill, Erik Brynjolfsson, Shyamal Buch, Dallas Card, Rodrigo Castellon, Niladri Chatterji, Annie Chen, Kathleen Creel, Jared Quincy Davis, Dora Demszky, Chris Donahue, Moussa Doumbouya, Esin Durmus, Stefano Ermon, John Etchemendy, Kawin Ethayarajh, Li Fei-Fei, Chelsea Finn, Trevor Gale, Lauren Gillespie, Karan Goel, Noah Goodman, Shelby Grossman, Neel Guha, Tatsunori Hashimoto, Peter Henderson, John Hewitt, Daniel E. Ho, Jenny Hong, Kyle Hsu, Jing Huang, Thomas Icard, Saahil Jain, Dan Jurafsky, Pratyusha Kalluri, Siddharth Karamcheti, Geoff Keeling, Fereshte Khani, Omar Khattab, Pang Wei Koh, Mark Krass, Ranjay Krishna, Rohith Kuditipudi, Ananya Kumar, Faisal Ladhak, Mina Lee, Tony Lee, Jure Leskovec, Isabelle Levent, Xiang Lisa Li, Xuechen Li, Tengyu Ma, Ali Malik, Christopher D. Manning, Suvir Mirchandani, Eric Mitchell, Zanele Munyikwa, Suraj Nair, Avanika Narayan, Deepak Narayanan, Ben Newman, Allen Nie, Juan Carlos Niebles, Hamed Nilforoshan, Julian Nyarko, Giray Ogut, Laurel Orr, Isabel Papadimitriou, Joon Sung Park, Chris Piech, Eva Portelance, Christopher Potts, Aditi Raghunathan, Rob Reich, Hongyu Ren, Frieda Rong, Yusuf Roohani, Camilo Ruiz, Jack Ryan, Christopher RĂ©, Dorsa Sadigh, Shiori Sagawa, Keshav Santhanam, Andy Shih, Krishnan Srinivasan, Alex Tamkin, Rohan Taori, Armin W. Thomas, Florian TramĂšr, Rose E. Wang, William Wang, Bohan Wu, Jiajun Wu, Yuhuai Wu, Sang Michael Xie, Michihiro Yasunaga, Jiaxuan You, Matei Zaharia, Michael Zhang, Tianyi Zhang, Xikun Zhang, Yuhui Zhang, Lucia Zheng, Kaitlyn Zhou, and Percy Liang. On the Opportunities and Risks of Foundation Models, jul 2022. URL http://arxiv.org/abs/2108.07258. Philipp Helle, Wladimir Schamai, and Carsten Strobel. Testing of Autonomous Systems â Challenges and Current State-of-the-Art. INCOSE International Symposium, 26(1):571â584, jul 2016. ISSN 2334-5837, 2334-5837. doi:10.1002/j.2334-5837.2016.00179.x. URLhttps://incose.onlinelibrary.wiley.com/doi/10.1002/j .2334-5837.2016.00179.x. Future of Life Institute. General Purpose AI and the AI Act. Technical report, Future of Life Institute, may 2022. URL https://futureoflife.org/document/general-purpose-ai-and-the-ai-act/. Carlos Ignacio Gutierrez, Anthony Aguirre, Risto Uuk, Claire Boine, and Matija Franklin. A Proposal for a Definition of General Purpose Artificial Intelligence Systems, oct 2022. URLhttps://papers.ssrn.com/abstract=423 8951. OECD. Recommendation of the Council on Artificial Intelligence. Technical Report OECD/LEGAL/0449, Organization for Economic Co-operation and Development, 2019b. URLhttps://legalinstruments.oecd.org/en/instr uments/oecd-legal-0449. Adopted on 22 May 2019; amended on 3 May 2024. National Institute of Standards and Technology. Artificial intelligence risk management framework (ai rmf 1.0). Technical Report NIST AI 100-1, National Institute of Standards and Technology, jan 2023. URLhttps://w.ni st.gov/itl/ai-risk-management-framework. European Commission. Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on Artificial Intelligence (AI Act) and amending certain Union legislative acts. COM/2021/206 final, 2021. URLhttps://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52021PC0206. Accessed: 2026-02-13. Dibya Ghosh, Abhishek Gupta, and Sergey Levine. Learning Actionable Representations with Goal-Conditioned Policies, 2018. URL https://arxiv.org/abs/1811.07819. Version Number: 2. Craig DeLancey. A Concise Introduction to Logic. Open SUNY Textbooks, mar 2017. ISBN 978-1-942341-42-0. URL https://milnepublishing.geneseo.edu/concise-introduction-to-logic/. Irving M. Copi, Carl Cohen, and Kenneth MacMahon. Introduction to Logic. Pearson custom library. Pearson Education Limited, Harlow, 14 ed., pearson new international ed edition, 2014. ISBN 978-1-292-02482-0. Anil Gupta and Stephen Mackereth. Definitions. In Edward N. Zalta and Uri Nodelman, editors, The Stanford Encyclopedia of Philosophy. Metaphysics Research Lab, Stanford University, Fall 2023 edition, 2023. URL https://plato.stanford.edu/archives/fall2023/entries/definitions/. Alexis Burgess, Herman Cappelen, and David Plunkett, editors. Conceptual Engineering and Conceptual Ethics. Oxford University Press, Oxford, UK, 2020. ISBN 978-0-19-880185-6. 37 A PREPRINT Eric Margolis and Stephen Laurence. Concepts. In Edward N. Zalta and Uri Nodelman, editors, The Stanford Encyclopedia of Philosophy. Metaphysics Research Lab, Stanford University, Fall 2023 edition, 2023. URL https://plato.stanford.edu/archives/fall2023/entries/concepts/. Anna Jopek-Bosiacka. Defining Law Terms: A Cross-Cultural Perspective. Research in Language, 9(1):9â29, jun 2011. ISSN 1731-7533. doi:10.2478/v10015-011-0008-y. URLhttps://czasopisma.uni.lodz.pl/research/arti cle/view/8122. Diggory Bailey and Luke Norbury. Clarity in legislation. Statute Law Review, 46(3):hmaf035, sep 2025. ISSN 0144-3593, 1464-3863. doi:10.1093/slr/hmaf035. URL https://doi.org/10.1093/slr/hmaf035. F. Reed Dickerson. Legislative drafting. Greenwood Press, Westport, Conn, 1977. ISBN 978-0-8371-9688-6. House Legislative Services. Drafting Style and Usage Manual. Louisiana House of Representatives, Baton Rouge, LA, nov 2015. URLhttps://documents.ncsl.org/wwwncsl/LegislativeStaff/RELACS/2016LAHouseDraf tingManual.pdf. Martin Ebers. No. 101: Truly Risk-Based Regulation of Artificial Intelligence: How to Implement the EUâs AI Act. Working paper, Stanford-Vienna Transatlantic Technology Law Forum, 2024. URLhttps://law.stanford.edu /publications/no-101-truly-risk-based-regulation-of-artificial-intelligence-how-to-imp lement-the-eus-ai-act/. Andrea Renda and Alex Engler. Whatâs in a Name? Getting the definition of Artificial Intelligence right in the EUâs AI Act. Technical Report 2023-02, Centre for European Policy Studies, Brussels, 2023. URLhttps: //w.ceps.eu/ceps-publications/whats-in-a-name/. CEPS Explainer. Chris Reed. Taking Sides on Technology Neutrality. SCRIPT-ed, 4(3):263â284, sep 2007. ISSN 1744-2567. doi:10.2966/scrip.040307.263. URL http://w.law.ed.ac.uk/ahrc/script-ed/vol4-3/reed.asp. Brad A. Greenberg. Rethinking technology neutrality. Minnesota Law Review, 100:1495â1562, 2016. URLhttps: //w.minnesotalawreview.org/wp-content/uploads/2016/04/Greenberg_ONLINEPDF.pdf. Michael D. Birnhack. Reverse Engineering Informational Privacy Law. SSRN Electronic Journal, feb 2012. ISSN 1556-5068. doi:10.2139/ssrn.2002757. URLhttps://papers.ssrn.com/sol3/papers.cfm?abstract_id= 2002757. Jonas Schuett. Defining the scope of AI regulations, aug 2021. URLhttps://papers.ssrn.com/abstract=345 3632. Kirk Nahra, Arianna Evers, Ali Jessani, Martin Braun, Anne Vallery, and Itsiq Benizri. The European Parliament adopts the AI Act. WilmerHale Privacy and Cybersecurity Law Blog, mar 2024. URLhttps://w.wilmerhale.com /en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20240314-the-european-parli ament-adopts-the-ai-act. Accessed: 2026-02-14. ISO/IEC. Information technology â Artificial intelligence â Artificial intelligence concepts and terminology. symbolic AI. International Organization for Standardization, Geneva, Switzerland, 2022d. URLhttps://w.iso.org/ob p/ui/en/#iso:std:iso-iec:22989:ed-1:v1:en:term:3.1.33 . Standard number: ISO/IEC 22989:2022(en). Term: 3.1.33. ISO/IEC. Information technology â Artificial intelligence â Artificial intelligence concepts and terminology. machine learning. International Organization for Standardization, Geneva, Switzerland, 2022e. URLhttps://w.is o.org/obp/ui/en/#iso:std:iso-iec:22989:ed-1:v1:en:term:3.3.5. Standard number: ISO/IEC 22989:2022(en). Term: 3.3.5. American Psychological Association. Operational definition. APA Dictionary of Psychology, 2018. URLhttps: //dictionary.apa.org/operational-definition. Accessed: February 21, 2026. A. M. Turing. Computing Machinery and Intelligence. Mind, 59(236):433â460, oct 1950. ISSN 0026-4423. doi:10.1093/mind/LIX.236.433. URLhttps://academic.oup.com/mind/article-abstract/LIX/23 6/433/986238. Robert M. French. Moving beyond the Turing test. Communications of the ACM, 55(12):74â77, December 2012. ISSN 0001-0782. doi:10.1145/2380656.2380674. URL https://dl.acm.org/doi/10.1145/2380656.2380674. Yann LeCun, Yoshua Bengio, and Geoffrey Hinton. Deep learning. Nature, 521(7553):436â444, may 2015. ISSN 1476-4687. doi:10.1038/nature14539. URL https://doi.org/10.1038/nature14539. Lee Sharkey, ClĂodhna NĂ Ghuidhir, Dan Braun, JĂ©rĂ©my Scheurer, Mikita Balesni, Lucius Bushnaq, Charlotte Stix, and Marius Hobbhahn. A Causal Framework for AI Regulation and Auditing, jan 2024. URLhttps://w.preprint s.org/manuscript/202401.1424/v1. 38 A PREPRINT Ranjan Sapkota, Konstantinos I. Roumeliotis, and Manoj Karkee. AI Agents vs. Agentic AI: A Conceptual Taxonomy, Applications and Challenges, may 2025. URL https://arxiv.org/abs/2505.10468v5. OpenAI. Gpt-3 model card. GitHub Repository, sep 2020. URLhttps://github.com/openai/gpt-3/blob/ma ster/model-card.md. Technical documentation for the GPT-3 language model. OpenAI. GPT-4 system card. Technical report, OpenAI, mar 2023. URLhttps://cdn.openai.com/papers/gp t-4-system-card.pdf. Anthropic. Model card addendum: Claude 3.5 Haiku and upgraded Claude 3.5 Sonnet. Technical report, Anthropic, oct 2024. URL https://w-cdn.anthropic.com/c7822cdc35ad788ec87e14b3a9d45010f1f86c38.pdf. Anthropic. Claude 3.7 sonnet system card. Technical report, Anthropic, feb 2025. URLhttps://w-cdn.anthrop ic.com/9f93dfa8f445c932415d335c88852ef47f1201e.pdf. Google DeepMind. Gemini 3 pro model card. Technical report, Google DeepMind, dec 2025. URLhttps: //storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-Pro-Model-Card.pdf. Koen Holtman and Ze Shen Chin. An analysis of the GPAI model guidelines published by the European Commission. Technical report, AI Standards Lab, jul 2025. URLhttps://aistandardslab.org/gpai_guidelines_analy sis/. Accessed: 2026-02-21. Lorenzo Pacchiardi, John Burden, Fernando MartĂnez-Plumed, and JosĂ© HernĂĄndez-Orallo. A Framework to Categorise Modified General-Purpose AI Models as New Models Based on Behavioural Changes. Publications Office of the European Union, oct 2025. ISBN 978-92-68-31545-3. doi:10.2760/4372557. URLhttps://publications.jrc .ec.europa.eu/repository/handle/JRC143257. JRC number: JRC143257. Philipp Hacker and Matthias Holweg. The Regulation of Fine-Tuning: Federated Compliance for Modified General- Purpose AI Models, jun 2025. URL https://papers.ssrn.com/abstract=5289125. Ze Shen Chin and Koen Holtman. White paper: GPAI model providers and modifiers and their obligations under the AI act. White paper, AI Standards Lab, may 2025. URLhttps://aistandardslab.org/white-paper-gpai-mod el-providers-and-modifiers-and-their-obligations-under-the-ai-act/. Accessed: February 21, 2026. Bernhard Nessler and Christiane Wendehorst. Commission guidelines on the application of the definition of an AI system and the prohibited AI practices established in the AI act: Response of the European Law Institute. Technical Report RC-2024-9, European Law Institute, Vienna, Austria, dec 2024. URLhttps://w.europeanlawinsti tute.eu/news-events/news-contd/news/eli-submits-a-response-to-the-european-commissions -public-consultation-on-the-ai-act/. Martin Braun. Italyâs privacy regulator takes action against ChatGPT. WilmerHale Privacy and Cybersecurity Law Blog, apr 2023. URLhttps://w.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cyb ersecurity-law/20230403-italys-privacy-regulator-takes-action-against-chatgpt. Accessed: 2026-02-14. Zahra Laher. Openai facesC15 million fine as the italian garante strikes again. Lewis Silkin Insights, jan 2025. URL https://w.lewissilkin.com/insights/2025/01/14/openai-faces-15-million-fine-as-the-i talian-garante-strikes-again-102jtqc. Accessed: February 14, 2026. ACLU of Illinois. In Big Win, Settlement Ensures Clearview AI Complies With Groundbreaking Illinois Biometric Privacy Law. ACLU of Illinois Press Release, may 2022. URLhttps://w.aclu-il.org/press-release s/big-win-settlement-ensures-clearview-ai-complies-groundbreaking-illinois-biometric/. Accessed: 2026-02-21. Clearview AI. Clearview ai settles ACLU illinois lawsuit, confirming continuity of business supporting public safety. Clearview AI Press Room, may 2022. URLhttps://w.clearview.ai/press-room/clearview-ai-set tles-aclu-illinois-lawsuit-confirming-continuity-of-business-supporting-public-safety. Accessed: 2026-02-14. Vasant Dhar. The Paradigm Shifts in Artificial Intelligence, aug 2023. URL http://arxiv.org/abs/2308.02558. Dmitrii Volkov. Badllama 3: removing safety finetuning from Llama 3 in minutes, jul 2024. URLhttp://arxiv.or g/abs/2407.01376. OECD. Summary of the CDEP technology foresight forum: Economic and social implications of artificial intelligence. Technical Report DSTI/CDEP(2016)17, OECD Directorate for Science, Technology and Innovation, Paris, France, feb 2017. URLhttps://one.oecd.org/document/DSTI/CDEP%282016%2917/en/pdf. Summary of the Forum held on 17 November 2016 at the OECD Conference Centre. 39 A PREPRINT European Commission. Communication from the Commission to the European Parliament, the European Council, the Council, the European Economic and Social Committee and the Committee of the Regions: Artificial Intelligence for Europe. COM(2018) 237 final, apr 2018. URL https://eur-lex.europa.eu/legal-content/EN/TXT/?uri =celex:52018DC0237. High-Level Expert Group on Artificial Intelligence. The Assessment List for Trustworthy Artificial Intelligence (ALTAI) for Self-assessment. Technical report, European Commission, jul 2020. URLhttps://digital-strategy.ec.e uropa.eu/en/library/assessment-list-trustworthy-artificial-intelligence-altai-self-ass essment. Third deliverable of the AI HLEG. Committee of Ministers. Committee on Artificial Intelligence (CAI) â Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law â Explanatory Report. Technical report, Council of Europe, Strasbourg, France, may 2024. 133rd Session of the Committee of Ministers. Reference code: CM(2024)52-addfinal. Yoshua Bengio, Sören Mindermann, Daniel Privitera, Tamay Besiroglu, Rishi Bommasani, Stephen Casper, Yejin Choi, Philip Fox, Ben Garfinkel, Danielle Goldfarb, Hoda Heidari, Anson Ho, Sayash Kapoor, Leila Khalatbari, Shayne Longpre, Sam Manning, Vasilios Mavroudis, Mantas Mazeika, Julian Michael, Jessica Newman, Kwan Yee Ng, Chinasa T. Okolo, Deborah Raji, Girish Sastry, Elizabeth Seger, Theodora Skeadas, Tobin South, Emma Strubell, Florian TramĂšr, Lucia Velasco, Nicole Wheeler, Daron Acemoglu, Olubayo Adekanmbi, David Dalrymple, Thomas G. Dietterich, Edward W. Felten, Pascale Fung, Pierre-Olivier Gourinchas, Fredrik Heintz, Geoffrey Hinton, Nick Jennings, Andreas Krause, Susan Leavy, Percy Liang, Teresa Ludermir, Vidushi Marda, Helen Margetts, John McDermid, Jane Munga, Arvind Narayanan, Alondra Nelson, Clara Neppel, Alice Oh, Gopal Ramchurn, Stuart Russell, Marietje Schaake, Bernhard Schölkopf, Dawn Song, Alvaro Soto, Lee Tiedrich, GaĂ«l Varoquaux, Andrew Yao, Ya-Qin Zhang, Fahad Albalawi, Marwan Alserkal, Olubunmi Ajala, Guillaume Avrin, Christian Busch, AndrĂ© Carlos Ponce de Leon Ferreira de Carvalho, Bronwyn Fox, Amandeep Singh Gill, Ahmet Halit Hatip, Juha HeikkilĂ€, Gill Jolly, Ziv Katzir, Hiroaki Kitano, Antonio KrĂŒger, Chris Johnson, Saif M. Khan, Kyoung Mu Lee, Dominic Vincent Ligot, Oleksii Molchanovskyi, Andrea Monti, Nusu Mwamanzi, Mona Nemer, Nuria Oliver, JosĂ© RamĂłn LĂłpez Portillo, Balaraman Ravindran, Raquel Pezoa Rivera, Hammam Riza, Crystal Rugege, CiarĂĄn Seoighe, Jerry Sheehan, Haroon Sheikh, Denise Wong, and Yi Zeng. International AI Safety Report. arXiv preprint, jan 2025. doi:10.48550/arXiv.2501.17805. URLhttps://arxiv.org/abs/2501.17805. Available at https://internationalaisafetyreport.org/and produced by UK Department for Science, Innovation and Technology. California State Legislature. Senate bill 53: Artificial intelligence models: large developers, sep 2025. URLhttps: //leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53 . Chapter 138, Statutes of 2025. Colorado General Assembly. Senate Bill 24-205: Concerning Consumer Protections in Interactions with Artificial Intelligence Systems. Legislative act, General Assembly of the State of Colorado, Denver, Colorado, 2024. URL https://leg.colorado.gov/bills/sb24-205. Sponsors: Rodriguez, Cutter, Michaelson Jenet, Priola, Winter F., Fenberg; Approved: 2024-05-17. Cyberspace Administration of China. Interim measures for the management of generative artificial intelligence services. Official Regulation of the Peopleâs Republic of China, jul 2023. URLhttps://w.cac.gov.cn/2023-07/13/c _1690898327029107.htm. Promulgated by CAC, NDRC, MOE, MOST, MIIT, MPS, and NRTA; Effective August 15, 2023. National Assembly of the Republic of Korea. Framework act on the development of artificial intelligence and establishment of trust. Act No. 20676, January 2025. URLhttps://w.law.go.kr/%EB%B2%95%EB%A0%B9/% EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5%20%EB%B0%9C%EC%A0%84%EA%B3%BC%20%EC%8B%A0%EB%A2%B0 %20%EA%B8%B0%EB%B0%98%20%EC%A1%B0%EC%84%B1%20%EB%93%B1%EC%97%90%20%EA%B4%80%ED%95%9C%2 0%EA%B8%B0%EB%B3%B8%EB%B2%95/(20676,20250121) . Promulgated January 21, 2025; effective January 22, 2026. ISO/IEC/IEEE. Software and systems engineering â Software testing â Part 1: General concepts. AI-based system. International Organization for Standardization, Geneva, Switzerland, 2022. URLhttps://w.iso.org/ob p/ui/en/#iso:std:iso-iec-ieee:29119:-1:ed-2:v1:en:term:3.6. Standard number: ISO/IEC/IEEE 29119-1:2022(en). Term: 3.6. ISO/IEC. Artificial intelligence â Testing of AI â Part 2: Overview of testing AI systems. International Organization for Standardization, Geneva, Switzerland, 2025. URLhttps://w.iso.org/obp/ui/en/#iso:std:iso-iec: ts:42119:-2:ed-1:v1:en:term:3.2. Standard number: ISO/IEC TS 42119-2:2025(en). Term: 3.2. State Administration for Market Regulation (PRC). Information Technology â Artificial Intelligence â Terminology. State Administration for Market Regulation and Standardization Administration of the Peopleâs Republic of China, 40 A PREPRINT Beijing, China, oct 2022. URLhttps://w.codeofchina.com/standard/GBT41867-2022.html. Chinese National Standard. Maximilian Poretschkin, Anna Schmitz, Maram Akila, Linara Adilova, Daniel Becker, Armin B. Cremers, Dirk Hecker, Sebastian Houben, Michael Mock, Julia Rosenzweig, Joachim Sicking, Elena Schulz, Angelika Voss, and Stefan Wrobel. Guideline for Designing Trustworthy Artificial Intelligence: AI Assessment Catalog. Guideline, Fraunhofer Institute for Intelligent Analysis and Information Systems IAIS, Sankt Augustin, Germany, feb 2023. URL https://doi.org/10.48550/arXiv.2307.03681. Mind Foundry. Model, 2026. URLhttps://w.mindfoundry.ai/ai-glossary/model. AI Glossary. Accessed: 2026-02-14. Nicolas MoĂ«s. Defining general-purpose AI systems in the AI act. Technical report, The Future Society, apr 2022. URL https://thefuturesociety.org/wp-content/uploads/2022/09/3-Defining-General-purpose-AI-s ystems-in-the-AI-Act.pdf. Prepared for Yordanka Ivanova, European Commission. Rainer MĂŒhlhoff and Hannah Ruschemeier. Updating purpose limitation for AI: a normative approach from law and philosophy. International Journal of Law and Information Technology, 33:eaaf003, jan 2025. ISSN 0967-0769, 1464-3693. doi:10.1093/ijlit/eaaf003. URL https://doi.org/10.1093/ijlit/eaaf003. R. MĂŒhlhoff and H. Ruschemeier. Regulating AI with Purpose Limitation for Models. Journal of AI Law and Regulation, 1(1):24â39, 2024. ISSN 29424380, 29424372. doi:10.21552/aire/2024/1/5. URLhttp://aire.lexxion.eu/ar ticle/AIRE/2024/1/5. Lara Kallab, Elio Mansour, and Richard Chbeir. Towards ML Modelsâ Recommendations. Data Science and Engineering, 9(4):409â430, dec 2024. ISSN 2364-1185, 2364-1541. doi:10.1007/s41019-024-00262-x. URL https://link.springer.com/10.1007/s41019-024-00262-x. Christian Janiesch, Patrick Zschech, and Kai Heinrich. Machine learning and deep learning. Electronic Markets, 31(3): 685â695, sep 2021. ISSN 1019-6781, 1422-8890. doi:10.1007/s12525-021-00475-2. URLhttps://link.sprin ger.com/10.1007/s12525-021-00475-2. Qinghua Lu, Liming Zhu, Xiwei Xu, Yue Liu, Zhenchang Xing, and Jon Whittle. A Taxonomy of Foundation Model based Systems through the Lens of Software Architecture. In Proceedings of the IEEE/ACM 3rd International Conference on AI Engineering - Software Engineering for AI, CAIN 2024, pages 1â6, New York, NY, USA, apr 2024. Association for Computing Machinery. ISBN 9798400705915. doi:10.1145/3644815.3644956. URL https://doi.org/10.1145/3644815.3644956. Seungkyu Park, Joong Yoon Lee, and Jooyeoun Lee. AI system architecture design methodology based on IMO (Input-AI Model-Output) structure for successful AI adoption in organizations. Data & Knowledge Engineering, 150:102264, mar 2024. ISSN 0169023X. doi:10.1016/j.datak.2023.102264. URLhttps://linkinghub.elsevie r.com/retrieve/pii/S0169023X23001246. Lara Kallab, Elio Mansour, and Richard Chbeir. SML: Semantic Machine Learning Model Ontology. In Feng Zhang, Hua Wang, Mahmoud Barhamgi, Lu Chen, and Rui Zhou, editors, Web Information Systems Engineering â WISE 2023, volume 14306, pages 896â911. Springer Nature Singapore, Singapore, 2023. ISBN 978-981-99-7253-1 978-981-99-7254-8. doi:10.1007/978-981-99-7254-8_70. URLhttps://link.springer.com/10.1007/978-9 81-99-7254-8_70. Series Title: Lecture Notes in Computer Science. Lalli Myllyaho, Mikko Raatikainen, Tomi MĂ€nnistö, Jukka K. Nurminen, and Tommi Mikkonen. On misbe- haviour and fault tolerance in machine learning systems. The Journal of Systems & Software, 183:111096, 2022. doi:10.1016/j.jss.2021.111096. URL https://doi.org/10.1016/j.jss.2021.111096. Arun Rai, Panos Constantinides, and Saonee Sarker. Next-generation digital platforms: Toward human-AI hybrids. MIS Quarterly, 43(1):iâix, mar 2019. ISSN 0276-7783. URL https://wrap.warwick.ac.uk/1136533. Anatoly M. Korikov. Once more on mechatronics as a science. Mechatronics, Automation, Control, (5):2â8, 2011. ISSN 1684-6427. URL https://w.elibrary.ru/item.asp?id=16358207. In Russian. Tom M. Mitchell. The discipline of machine learning. Technical Report CMU-ML-06-108, Machine Learning Department, School of Computer Science, Carnegie Mellon University, Pittsburgh, PA, jul 2006. URLhttp: //w.cs.cmu.edu/afs/cs/usr/mitchell/ftp/pubs/MachineLearningTR.pdf. Igor M. Makarov and Vladimir M. Lokhin. Intelligent Automatic Control Systems. Fizmatlit, Moscow, 2001. ISBN 5-9221-0162-5. Originally published in Russian as âIntellektualnye sistemy avtomaticheskogo upravleniyaâ. Alexander Backlund.The definition of system.Kybernetes, 29(4):444â451, jun 2000.ISSN 0368-492X. doi:10.1108/03684920010322055. URL https://doi.org/10.1108/03684920010322055. Atte Ojanen. Technology neutrality as a way to future-proof regulation: the case of the Artificial Intelligence Act, February 2025. URL https://papers.ssrn.com/abstract=5181085. 41 A PREPRINT Oliver MĂŒller, Veronika Lazar, and Matthias Heck. Transparency of AI Systems (Practitioner Track). OASIcs, Volume 126, SAIA 2024, 126:11:1â11:7, 2025. ISSN 2190-6807. doi:10.4230/OASICS.SAIA.2024.11. URL https://drops.dagstuhl.de/entities/document/10.4230/OASIcs.SAIA.2024.11. European Parliament. Amendments adopted by the european parliament on 14 june 2023 on the proposal for a regulation of the european parliament and of the council on laying down harmonised rules on artificial intelligence (artifi- cial intelligence act) and amending certain union legislative acts (com(2021)0206-c9-0146/2021-2021/0106(cod)). P9_TA(2023)0236, jun 2023. URLhttps://w.europarl.europa.eu/doceo/document/TA-9-2023-023 6_EN.pdf. Provisional Edition. Miriam C. Buiten. Product liability for defective AI. European Journal of Law and Economics, 57(1-2):239â273, apr 2024. ISSN 0929-1261, 1572-9990. doi:10.1007/s10657-024-09794-z. URLhttps://link.springer.com/10 .1007/s10657-024-09794-z. Miriam Buiten, Alexandre De Streel, and Martin Peitz. The law and economics of AI liability. Computer Law & Security Review, 48:105794, apr 2023. ISSN 2212473X. doi:10.1016/j.clsr.2023.105794. URLhttps://linkingh ub.elsevier.com/retrieve/pii/S0267364923000055. Theodore S. Boone. The challenge of defining artificial intelligence in the EU AI Act. Journal of Data Protection & Privacy, 6(2):180â195, dec 2023. ISSN 2398-1687. doi:10.69554/QHAY8067. URLhttps://hstalks.com/do i/10.69554/QHAY8067/. Council of the European Union. Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) and amending certain Union legislative acts - General approach. Technical Report 14954/22, Council of the European Union, nov 2022. URLhttps: //data.consilium.europa.eu/doc/document/ST-14954-2022-INIT/en/pdf . Interinstitutional File: 2021/0106(COD). Vincent J. Straub, Deborah Morgan, Jonathan Bright, and Helen Margetts. Artificial intelligence in government: Concepts, standards, and a unified framework. Government Information Quarterly, 40(4):101881, oct 2023. ISSN 0740-624X. doi:10.1016/j.giq.2023.101881. URLhttps://w.sciencedirect.com/science/article/pi i/S0740624X23000813. Yolanda Gil and Bart Selman. A 20-Year Community Roadmap for Artificial Intelligence Research in the US, aug 2019. URL http://arxiv.org/abs/1908.02624. Oleksandr V. Spivakovsky, Serhii A. Omelchuk, Vitaliy V. Kobets, Nataliia V. Valko, and Daria S. Malchykova. INSTITUTIONAL POLICIES ON ARTIFICIAL INTELLIGENCE IN UNIVERSITY LEARNING, TEACHING AND RESEARCH. Information Technologies and Learning Tools, 97(5):181â202, oct 2023. ISSN 2076-8184. doi:10.33407/itlt.v97i5.5395. URLhttps://journal.iitta.gov.ua/index.php/itlt/article/view/539 5. Cabinet of Ministers of Ukraine. Resolution of the Cabinet of Ministers of Ukraine of December 2, 2020, No. 1556-r: On the Approval of the Concept for the Development of Artificial Intelligence in Ukraine. Official Website of the Verkhovna Rada of Ukraine, dec 2020. URLhttps://zakon.rada.gov.ua/laws/show/1556-2020-%D1%80# Text. Accessed: 2026-02-14. Lorenzo Diaferia, Ivo Blohm, Leonardo Maria De Rossi, and Gianluca Salviotti. When Standard Is Not Enough: a Conceptualization of AI Systemsâ Customization and its Antecedents. In Proceedings of the 43rd International Conference on Information Systems (ICIS), Copenhagen, Denmark, 2022. Association for Information Systems. URL https://aisel.aisnet.org/icis2022/is_implement/is_implement/8. Article 8. Andreas Kaplan and Michael Haenlein. Siri, Siri, in my hand: Whoâs the fairest in the land? On the interpretations, illustrations, and implications of artificial intelligence. Business Horizons, 62(1):15â25, jan 2019. ISSN 00076813. doi:10.1016/j.bushor.2018.08.004. URLhttps://linkinghub.elsevier.com/retrieve/pii/S0007681318 301393. P. M. Krafft, Meg Young, Michael Katell, Jennifer E. Lee, Shankar Narayan, Micah Epstein, Dharma Dailey, Bernease Herman, Aaron Tam, Vivian Guetler, Corinne Bintz, Daniella Raz, Pa Ousman Jobe, Franziska Putz, Brian Robick, and Bissan Barghouti. An Action-Oriented AI Policy Toolkit for Technology Audits by Community Advocates and Activists. In Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency, pages 772â781, Virtual Event Canada, mar 2021. ACM. ISBN 978-1-4503-8309-7. doi:10.1145/3442188.3445938. URL https://dl.acm.org/doi/10.1145/3442188.3445938. Andreia Martinho, Maarten Kroesen, and Caspar Chorus. Computer Says I Donât Know: An Empirical Approach to Capture Moral Uncertainty in Artificial Intelligence. Minds and Machines, 31(2):215â237, jun 2021. ISSN 0924-6495, 1572-8641. doi:10.1007/s11023-021-09556-9. URLhttps://link.springer.com/10.1007/s110 23-021-09556-9. 42 A PREPRINT Elizabeth H. Manser Payne, Andrew J. Dahl, and James Peltier. Digital servitization value co-creation framework for AI services: a research agenda for digital transformation in financial service ecosystems. Journal of Research in Interactive Marketing, 15(2):200â222, feb 2021. ISSN 2040-7122. doi:10.1108/JRIM-12-2020-0252. URL https://doi.org/10.1108/JRIM-12-2020-0252. Nagadivya Balasubramaniam, Marjo Kauppinen, Sari Kujala, and Kari Hiekkanen. Ethical Guidelines for Solving Ethical Issues and Developing AI Systems. In Maurizio Morisio, Marco Torchiano, and Andreas Jedlitschka, editors, Product-Focused Software Process Improvement, volume 12562, pages 331â346. Springer International Publishing, Cham, 2020. ISBN 978-3-030-64147-4 978-3-030-64148-1. doi:10.1007/978-3-030-64148-1_21. URL https://link.springer.com/10.1007/978-3-030-64148-1_21. Series Title: Lecture Notes in Computer Science. James P. H. Coleman. AI and Our Understanding of Intelligence. In Kohei Arai, Supriya Kapoor, and Rahul Bhatia, editors, Intelligent Systems and Applications, volume 1250, pages 183â190. Springer International Publishing, Cham, 2021. ISBN 978-3-030-55179-7 978-3-030-55180-3. doi:10.1007/978-3-030-55180-3_15. URLhttp: //link.springer.com/10.1007/978-3-030-55180-3_15. Series Title: Advances in Intelligent Systems and Computing. A Korikov. Artificial intelligence in robot control systems. IOP Conference Series: Materials Science and Engineering, 363:012013, may 2018. ISSN 1757-8981, 1757-899X. doi:10.1088/1757-899X/363/1/012013. URLhttps: //iopscience.iop.org/article/10.1088/1757-899X/363/1/012013. Caleb Sponheim. Artificial intelligence glossary, jul 2024. URLhttps://w.nngroup.com/articles/artific ial-intelligence-glossary/. Accessed: 2026-02-16. Illugi Torfason Hjaltalin and Hallur Thor Sigurdarson. The strategic use of AI in the public sector: A public values analysis of national AI strategies. Government Information Quarterly, 41(1):101914, mar 2024. ISSN 0740-624X. doi:10.1016/j.giq.2024.101914. URLhttps://w.sciencedirect.com/science/article/pii/S0740624 X24000066. Ministry of Economic Affairs and Employment of Finland. Leading the way into the age of artificial intelligence: Final report of Finlandâs Artificial Intelligence Programme 2019. Technical Report 2019:41, Ministry of Economic Affairs and Employment of Finland, Helsinki, June 2019. URL http://urn.fi/URN:ISBN:978-952-327-437-2. Michael Haenlein and Andreas Kaplan. A Brief History of Artificial Intelligence: On the Past, Present, and Future of Artificial Intelligence. California Management Review, 61(4):5â14, aug 2019. ISSN 0008-1256, 2162-8564. doi:10.1177/0008125619864925. URL https://journals.sagepub.com/doi/10.1177/0008125619864925. Qunying Song, Emelie Engstrom, and Per Runeson. Concepts in Testing of Autonomous Systems: Academic Literature and Industry Practice. In 2021 IEEE/ACM 1st Workshop on AI Engineering - Software Engineering for AI (WAIN), pages 74â81, Madrid, Spain, may 2021. IEEE. ISBN 978-1-6654-4470-5. doi:10.1109/WAIN52551.2021.00018. URL https://ieeexplore.ieee.org/document/9474374/. Francesco Flammini. Digital twins as run-time predictive models for the resilience of cyber-physical systems: a conceptual framework. Philosophical Transactions of the Royal Society A: Mathematical, Physical and Engineering Sciences, 379(2207):20200369, oct 2021. ISSN 1364-503X, 1471-2962. doi:10.1098/rsta.2020.0369. URL https://royalsocietypublishing.org/doi/10.1098/rsta.2020.0369. Joseph Sifakis. Autonomous Systems â An Architectural Characterization. In Michele Boreale, Flavio Corradini, Michele Loreti, and Rosario Pugliese, editors, Models, Languages, and Tools for Concurrent and Distributed Programming, volume 11665, pages 388â410. Springer International Publishing, Cham, 2019. ISBN 978-3-030- 21484-5 978-3-030-21485-2. doi:10.1007/978-3-030-21485-2_21. URLhttp://link.springer.com/10.1007/ 978-3-030-21485-2_21. Series Title: Lecture Notes in Computer Science. Mohammadreza Torkjazi and Ali K. Raz. A Taxonomy for System of Autonomous Systems. In 2022 17th Annual System of Systems Engineering Conference (SOSE), pages 198â203, jun 2022. doi:10.1109/SOSE55472.2022.9812673. URL https://ieeexplore.ieee.org/abstract/document/9812673. Panos J. Antsaklis and Arash Rahnama. Control and Machine Intelligence for System Autonomy. Journal of Intelligent & Robotic Systems, 91(1):23â34, jul 2018. ISSN 0921-0296, 1573-0409. doi:10.1007/s10846-018-0832-6. URL http://link.springer.com/10.1007/s10846-018-0832-6. Hui-Min Huang. Autonomy Levels for Unmanned Systems (ALFUS) FrameworkVolume I: Framework Models Initial Version. NIST Special Publication 1011-I-1.0, jan 2007. doi:10.6028/NIST.SP.1011-I-1.0. URLhttps: //w.academia.edu/41829482/Autonomy_Levels_for_Unmanned_Systems_ALFUS_FrameworkVolume _I_Framework_Models_Initial_Version. 43 A PREPRINT Benjamin S. Bloom, Max D. Engelhart, Edward J. Furst, Walker H. Hill, and David R. Krathwohl. Taxonomy of educational objectives: the classification of educational goals. Handbook 1, Cognitive domain. Longmans, London, UK, 1956. ISBN 978-0-582-32386-5. Machine Intelligence Research Institute. Research guide, 2026. URLhttps://intelligence.org/research-gui de/. Live document, no explicit publication date; accessed 2026-02-13. A Overview of the Systematic Literature Review A systematic literature review was conducted to obtain definitions of the terms AI model and AI system. The proposed structure by Carrera-Rivera et al. (2022) regarding the planning and conducting of a systematic literature review was followed. Specifically, we adopted the planning-phase steps outlined in their framework, adapted to the present topic, including defining the research objective using the Population, Intervention, Comparison, Outcome, and Context (PICOC) structure (Carrera-Rivera et al., 2022), selecting databases, establishing inclusion and exclusion criteria, conducting quality assessment, and performing data extraction. Research Objective Carrera-Rivera et al. (2022) suggest the PICOC structure to define the research objective and formulate search terms. Table 8 provides an overview of the keywords found using the PICOC criteria. Based on this breakdown, the following research question was formulated: How are the terms AI model and AI system defined? Table 8: SLR Keywords from PICOC Criteria CriterionKeywords PopulationAI model and AI system Synonyms: Machine learning system, autonomous system, automated system, algorithmic system Machine learning model, foundation model, algorithmic model, predictive model AI application, machine learning application, AI solution, machine learning solution, AI services InterventionDefinition Synonyms: Ontology, conceptual framework, taxonomy, terminology, scope ComparisonNot applicable OutcomeFind different definitions, clarity on differences ContextComputer science, engineering, social sciences, decision sciences, business, manage- ment and accounting, arts and humanities, multidisciplinary, psychology Databases In order to sufficiently cover the area under investigation, different databases were selected. The following databases were used to obtain an overview of the literature: Scopus, Web of Science, IEEE Xplore. Google Scholar was used as a secondary source. Inclusion and Exclusion Criteria The following inclusion and exclusion criteria were chosen for the literature review. In particular, literature from 2012 onwards were included, as 2012 was the beginning of the modern AI era, with the influential AlexNet architecture (Krizhevsky et al., 2012) being released, marking the beginning of machine learning and deep neural networks as the dominant paradigm in AI. Moreover, only literature written in English was chosen, and their relevance to the research question was ensured by only including articles that provide a definition of the terms AI model, AI system or a 44 A PREPRINT concept synonymous to them in the final review. Lastly, only articles, reviews and conference papers were included. An overview of the criteria is provided in Table 9. Table 9: SLR Inclusion and Exclusion Criteria CategorySelection Criteria PeriodFrom 2012 to present LanguageEnglish Relevance to research questionThe article provides a definition of AI model, AI system, or a concept synonymous with these terms Type of sourceArticles, reviews and conference papers Quality Assessment and Data Extraction The quality of the articles is mainly assessed by manually evaluating for how clear and complete their definitions are. The relevance of each articleâs definition to the research question is also evaluated. Extracted data include the definitions of the relevant terms, as well as their sources. In some cases, the definitions in a source were attributed to another cited source. This was also noted during the manual review of the SLR results. Search String Figure 8 shows the final search string. Synonyms of the terms AI system, AI model and âdefinitionâ were chosen as defined by the PICOC criteria. In order to ensure articles were discussing definitions, the proximity operator W/4, or NEAR/4, was used to only include articles where the definitional term is within a distance of four words of the AI term. To further narrow the search, articles with terms such as âdefined viaâ and âdefined throughâ in the abstract were excluded, as this would typically result in definitions of other terms in the context of AI models or systems, instead of the definition of AI models or systems themselves. Furthermore, only articles in the subject areas specified in the context criterion of the PICOC method were included. Lastly, as a first literature search showed high occurrence of article keywords that were not relevant for this search, the following keywords were excluded: diagnosis, female, adult, male, students, diseases, explainable ai, major clinical study, covid-19, fairness, energy. This search was performed on October 15, 2025, and resulted in 864 papers on Scopus, 113 on Web of Science, 16 on IEEE Xplore. After removing duplicates, a total of 896 papers were screened. Details can be found in Figure 9. B Compilation of Definitions from the Manual Review As discussed in Section 3.1 (Manual Review of Global Regulatory and Standards Documents), we conducted a manual review of definitions from institutions that may not be found through the systematic literature review. Here, we group these institutions into four categories: (1) national/state-level government bodies, (2) intergovernmental organisations, (3) standards bodies, and (4) NGOs. Verbatim definitions were extracted and tabulated with source, date, and organisational category. This review illustrates how a small number of root formulations, most notably the OECDâs 2019 definition of an AI system, have been repeatedly adapted and embedded into legislation, standards and guidance (for example in the EU AI Act, the Council of Europe Framework Convention, ISO standards and NISTâs AI RMF). At the same time, the review highlights an asymmetry: while definitions of an AI system are largely based around a machine-based, goal-directed inference process conceptualisation of the term, definitions of an AI model remain sparse, fragmented, or purely derivative (e.g. âessential componentsâ or âgeneral-purpose AI modelsâ defined without a prior base notion of âmodelâ). AI models are alternately framed as mathematical objects, core components within systems, or bundles of capabilities, which in turn reinforces the conceptual ambiguity at the boundary between system and model that later sections of this paper analyse in more detail. A compilation of these definitions, which are to be understood as samples of their respective categories, are in the following sections. 45 A PREPRINT (âAI systemâ OR âartificial intelligence systemâ OR âmachine learning systemâ OR âML systemâ OR âAutonomous systemâ OR âAutomated systemâ OR âalgorithmic systemâ OR âAI modelâ OR âartificial intelligence modelâ OR âmachine learning modelâ OR âML modelâ OR âfoundation modelâ OR âalgorithmic modelâ OR âpredictive modelâ OR âAI applicationâ OR âartificial intelligence applicationâ OR âmachine learning applicationâ OR âML applicationâ OR âAI solutionâ OR âartificial intelligence solutionâ OR âmachine learning solutionâ OR âML solutionâ OR âAI servicesâ OR âartificial intelligence servicesâ) W/4 (âontologyâ OR âdefin*â OR âconceptual frameworkâ OR âtaxonomyâ OR âterminolog*â OR âconceptualis*â OR âconceptualiz*â OR âscopeâ) AND NOT (âdefined viaâ OR âdefined throughâ OR âwell definedâ OR âuser definedâ) Figure 8: SLR Search String B.1 Intergovernmental Organisations The OECD (Organisation for Economic Co-operation and Development) has standardised a definition of an AI system since 2019, in line with that used in the popular textbook, Artificial Intelligence: A Modern Approach (Russell and Norvig, 2009). This root definition has, for the past few years, been a core influential definition of the term, factored into emerging AI legislation across the globe. Russel and Norvigâs definition has been interwoven into OECD documents since 2019. In 2023, the OECD expanded upon this choice in its Explanatory Memorandum On The Updated OECD Definition of an AI System. Specifically, the objective can be âimplicitâ, outputs can be âinferredâ, and the system may exhibit varying levels of âadaptivenessâ after deployment. This same report also provides a definition of an AI model. In a separate report produced in 2022, the OECD situated its definition of an AI model as a process within the context of the AI system lifecycle. OECD definitions OECD (2017, p. 2 & 7) â[...] because AI is an artifact, AI systems are constructed using architectures that limit AI to the knowledge and potential actions that make sense for a given application.â â[Dr. Joanna Bryson] characterised Artificial General Intelligence as a myth in that, like natural intelligence, AI is constrained by both the mathematics of combinatorics, and by the people who construct architectures limiting AI to actions that make sense. Stressing the difficulty of search if all possible options must be investigated (combinatorics), she attributed human intelligence to humansâ skill at communicating solutions once found, and â more recently â at mining these solutions from our culture as input to machines. Machine learning therefore exploits existing search to find the right thing to do at the right time.â OECD (2019a, p. 7) âAn AI system is a machine-based system that is capable of influencing the Environment by making recommendations, predictions or decisions for a given set of Objectives. It does so by utilising machine and/or human-based inputs/data to: i) perceive real and/or virtual environments; i) abstract such perceptions into models manually or automatically; and i) use Model Interpretations to formulate options for outcomes.â âA Model is an actionable representation of all or part of the external environment of an AI system that describes the environmentâs structure and/or dynamics. The model represents the core of an AI 46 A PREPRINT Figure 9: PRISMA Flow Diagram of the SLR system. A model can be based on data and/or expert knowledge, by humans and/or by automated tools like machine learning algorithms. Model Interpretation is the process of deriving an outcome from a model.â OECD (2022, p. 23 & 42) âAn AI system is a machine based system that is capable of influencing the environment by producing recommendations, predictions or other outcomes for a given set of objectives. It uses machine and/or human-based inputs/data to: 1. perceive environments; 2. abstract these perceptions into models; and 3. use the models to formulate options for outcomes. AI systems are designed to operate with varying levels of autonomy.â âAI models are actionable representations of all or part of the external context or environment of an AI system (encompassing, for example, processes, objects, ideas, people and/or interactions taking place in context). AI models use data and/or expert knowledge provided by humans and/or automated tools to represent, describe and interact with real or virtual environments.â OECD (2024, p. 4, 6, 8) âAn AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions 47 A PREPRINT that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.â âAn AI model is a core component of an AI system used to make inferences from inputs to produce outputs [. . . ] while the parameters of an AI model change during the build phase, they usually remain fixed after deployment once the build phase has concluded.â âAI models include, among others, statistical models and various kinds of input-output functions (such as decision trees and neural networks).â Intergovernmental organisations (Europe) definitions European Parliament and Council of the European Union (2024, Article 3(1); Recital 97; Article 3(63); Article 51(1)) âAI system means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.â âAlthough AI models are essential components of AI systems, they do not constitute AI systems on their own. AI models require the addition of further components, such as for example a user interface, to become AI systems. AI models are typically integrated into and form part of AI systems.â âA âgeneral-purpose AI modelâ is an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market.â â1. A general-purpose textbfAI model shall be classified as a general-purpose AI model with systemic risk if it meets any of the following conditions: (a) it has high impact capabilities evaluated on the basis of appropriate technical tools and methodolo- gies, including indicators and benchmarks; (b) based on a decision of the Commission, ex officio or following a qualified alert from the scientific panel, it has capabilities or an impact equivalent to those set out in point (a) having regard to the criteria set out in Annex XIII. 2. A general-purpose textbfAI model shall be presumed to have high impact capabilities pursuant to paragraph 1, point (a), when the cumulative amount of computation used for its training measured in floating point operations is greater than 10 25 .â European Commission (2025b, 2.1(17)) âA general-purpose AI model is defined as any model trained using more than10 23 FLOPS (floating point operations per second) and capable of generating language (text/audio), text-to-image, or text-to-video outputs.â European Commission (2018, p. 1) âArtificial intelligence (AI) refers to systems that display intelligent behaviour by analysing their environment and taking actions â with some degree of autonomy â to achieve specific goals. AI-based systems can be purely software-based, acting in the virtual world (e.g. voice assistants, image analysis software, search engines, speech and face recognition systems) or AI can be em- bedded in hardware devices (e.g. advanced robots, autonomous cars, drones or Internet of Things applications).â High-Level Expert Group on Artificial Intelligence (2019b, p. 7) âArtificial intelligence (AI) refers to systems designed by humans that, given a complex goal, act in the physical or digital world by perceiving their environment, interpreting the collected structured or 48 A PREPRINT unstructured data, reasoning on the knowledge derived from this data and deciding the best action(s) to take (according to pre-defined parameters) to achieve the given goal. AI systems can also be designed to learn to adapt their behaviour by analysing how the environment is affected by their previous actions. As a scientific discipline, AI includes several approaches and techniques, such as machine learning (of which deep learning and reinforcement learning are specific examples), machine reasoning (which includes planning, scheduling, knowledge representation and reasoning, search, and optimization), and robotics (which includes control, perception, sensors and actuators, as well as the integration of all other techniques into cyber-physical systems)â High-Level Expert Group on Artificial Intelligence (2019a, p. 36; 2020, p. 24) âArtificial intelligence (AI) systems are software (and possibly also hardware) systems designed by humans that, given a complex goal, act in the physical or digital dimension by perceiving their environment through data acquisition, interpreting the collected structured or unstructured data, reasoning on the knowledge, or processing the information, derived from this data and deciding the best action(s) to take to achieve the given goal. AI systems can either use symbolic rules or learn a numeric model, and they can also adapt their behaviour by analysing how the environment is affected by their previous actions.â EstĂ©vez Almenzar et al. (2022, p. 13; p. 43) âAI system: A system based on artificial intelligence.â âAI model: In AI, this keyword mostly refers to a machine learning model or statistical model, which can make predictions/decisions over data. So only a subset of algorithms are models.â Committee of Ministers (2024, Article 2) â23. The definition of an artificial intelligence system prescribed in this Article is drawn from the latest revised definition adopted by the OECD on 8 November 2023. The choice of the Drafters to use this particular text is significant not only because of the high quality of the work carried out by the OECD and its experts, but also in view of the need to enhance international co-operation on the topic of artificial intelligence and facilitate efforts aimed at harmonising governance of artificial intelligence at a global level, including by harmonising the relevant terminology, which also allows for the coherent implementation of different instruments relating to artificial intelligence within the domestic legal systems of the Parties. 24. The definition reflects a broad understanding of what artificial intelligence systems are, specifically as opposed to other types of simpler traditional software systems based on the rules defined solely by natural persons to automatically execute operations. It is meant to ensure legal precision and certainty, while also remaining sufficiently abstract and flexible to stay valid despite future technological developments. The definition was drafted for the purposes of the Framework Convention and is not meant to give universal meaning to the relevant term. The Drafters took note of the Explanatory Memorandum accompanying the updated definition of an artificial intelligence system in the OECD Recommendation on Artificial Intelligence (OECD/LEGAL/0449, 2019, amended 2023) for a more detailed explanation of the various elements in the definition. While this definition provides a common understanding between the Parties as to what artificial intelligence systems are, Parties can further specify it in their domestic legal systems for further legal certainty and precision, without limiting its scope.â Dunietz et al. (2024, p. 12) âModel: A core component of an AI system used to make inferences from inputs in order to produce outputs. A model characterizes an input-to-output transformation intended to perform a core computational task of the AI system (e.g., classifying an image, predicting the next word for a sequence, or selecting a robotâs next action given its state and goals)â European Data Protection Supervisor (2025, p. 9) âFor the purposes of this Guidance, an AI system is understood within the meaning of Article 3(1) of Regulation 2024/1689 (AI Act) as âa machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environmentsâ. The AI Act, 49 A PREPRINT however, does not contain a definition of an âAI modelâ. The terms AI model and AI system are often used as if they were synonyms, when they are not.â AI models are mathematical representations that capture, in a set of parameters, the patterns underly- ing their training personal data. 16 Although AI models are essential components of AI systems, they do not constitute AI systems on their own, as they will always require other software components to be able to function and interact with users and the virtual or physical environment. In fact, an AI system can be composed of more than one AI model. For example, a voice translator AI system could be composed of a first model transcribing voice data into text, a second model translating the text from one language to another and a third model producing as output voice data from the translated text.â Intergovernmental organisations (global) definitions Bengio et al. (2025, p. 35) âChatGPT is a general-purpose AI system that combines the GPT-4o model with a chat interface, content processing, web access, and application integration to create a functional product. The additional components in an AI system also aim to enhance capability, usefulness, and safety. For example, a system might come with a filter that detects and blocks model inputs or outputs that contain harmful content. Developers are also increasingly designing so-called âscaffoldingâ around general-purpose AI models that allows them to plan ahead, pursue goals, and interact with the world (see 1.2. Current capabilities).â UNESCO (2022, p. 10) âAI systems are information-processing technologies that integrate models and algorithms that produce a capacity to learn and to perform cognitive tasks leading to outcomes such as prediction and decision-making in material and virtual environments. AI systems are designed to operate with varying degrees of autonomy by means of knowledge modelling and representation and by exploiting data and calculating correlations. AI systems may include several methods, such as but not limited to: (i) machine learning, including deep learning and reinforcement learning; (i) machine reasoning, including planning, scheduling, knowledge representation and reasoning, search, and optimization. AI systems can be used in cyber-physical systems, including the Internet of things, robotic systems, social robotics, and human-computer interfaces, which involve control, perception, the processing of data collected by sensors, and the operation of actuators in the environment in which AI systems workâ B.2 Governmental Organisations US state definitions California State Legislature (2025, 22757.11(b)) ââArtificial intelligence modelâ means an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.â Colorado General Assembly (2024, 6-1-1701(2)) âA machine-based system that, for explicit or implicit goals, uses the inputs it receives to infer how to generate outputs (like content, decisions, predictions, or recommendations) that can influence physical or virtual environments.â Chinese governmental definitions Cyberspace Administration of China (2023, Article 22(1-2), translated from Mandarin Chinese) âGenerative Artificial Intelligence Technology Refers to models and related technologies with the capability to generate content such as text, images, audio, or video.â 50 A PREPRINT âGenerative Artificial Intelligence Service Provider Refers to organisations or individuals that provide generative AI services using generative AI technol- ogy (including through programmable interfaces).â Korean governmental definitions National Assembly of the Republic of Korea (2025, Article 2(1-3)) ââArtificial intelligenceâ refers to the electronic implementation of human intellectual abilities such as learning, reasoning, perception, judgment, and language comprehension.â ââArtificial intelligence technologyâ refers to hardware, software technology, or its utilization technology required to implement artificial intelligence.â ââArtificial intelligence systemâ refers to an artificial intelligence-based system that infers results such as predictions, recommendations, and decisions that affect real and virtual environments for a given goal with various levels of autonomy and adaptability.â B.3 Standards Agencies ISO definitions ISO/IEC (2022c, ISO/IEC 22989:2022) â3.1.1 AI agent automated (3.1.7) entity that senses and responds to its environment and takes actions to achieve its goalsâ â3.1.4 AI system engineered system that generates outputs such as content, forecasts, recommendations or decisions for a given set of human-defined objectives Note 1 to entry: The engineered system can use various techniques and approaches related to artificial intelligence (3.1.3) to develop a model (3.1.23) to represent data, knowledge (3.1.21), processes, etc. which can be used to conduct tasks (3.1.35). Note 2 to entry: AI systems are designed to operate with varying levels of automation (3.1.7).â â3.1.23 model physical, mathematical or otherwise logical representation of a system, entity, phenomenon, process or data [SOURCE:ISO/IEC 18023-1:2006, 3.1.11, modified â Remove comma after âmathematicalâ in the definition. âor dataâ is added at the end.]â â3.3.7 machine learning model mathematical construct that generates an inference (3.1.17) or prediction (3.1.27) based on input data or informationâ â7.1 [...] Al systems contain a model which they use to produce predictions and these predictions are in turn used to successively make recommendations, decisions and actions, in whole or in part by the system itself or by human beings.â ISO/IEC/IEEE (2022, ISO/IEC/IEEE 29119-1:2022) â3.6 AI-based system system including one or more components implementing AI (3.7)â ISO/IEC (2025, ISO/IEC TS 42119-2:2025) â3.2 AI model machine-readable representation of knowledge (3.15) 51 A PREPRINT Note 1 to entry: An ML model (3.19) and the knowledge captured from experts as rules in an expert system are both forms of AI model.â â3.15 knowledge <artificial intelligence> abstracted information about objects, events, concepts or rules, their relation- ships and properties, organized for goal-oriented systematic use Note 1 to entry: Knowledge in the AI (3.1) domain does not imply a cognitive capability, contrary to usage of the term in some other domains. In particular, knowledge does not imply the cognitive act of understanding. Note 2 to entry: Information can exist in numeric or symbolic form. Note 3 to entry: Information is data that has been contextualized, so that it is interpretable. Data is created through abstraction or measurement from the world. [SOURCE:ISO/IEC 22989:2022, 3.1.21]â Chinese standards agencies definitions State Administration for Market Regulation (PRC) (2022, GB/T 41867-2022) â3.1.2 artificial intelligence; AI <subject> research and development of related mechanisms and applications of artificial intelligence system (3.1.8)â â3.1.8 artificial intelligence system a class of engineering systems that produce outputs such as content, prediction, recommendation, or decision for a given human-defined target Note 1: This engineering system uses various technologies and methods related to AI (3.1.2) to develop models such as representing data, knowledge, processes, etc. for performing tasks. Note 2: AI systems have different levels of automation.â US standards agencies definitions National Institute of Standards and Technology (2023, NIST AI 100-1) âThe AI RMF refers to an AI system as an engineered or machine-based system that can, for a given set of objectives, generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments. AI systems are designed to operate with varying levels of autonomy (Adapted from: OECD Recommendation on AI:2019; ISO/IEC 22989:2022).â B.4 Other Non-Governmental Organisations Non-governmental organisations (NGOs) were identified through a structured manual review of publicly available online sources. Starting from curated indexes and directories of AI-focused organisations, such as the AI Ethicist AI Organisations list, we iteratively followed outbound links to NGO websites and publications, and then applied inclusion criteria aimed at locating definitional or quasi-definitional language about AI models or AI systems/applications (e.g., glossaries, policy briefs, technical explainers, and governance reports). The resulting NGO list is therefore a sample, and does not represent all civil society actors. NGO definitions Poretschkin et al. (2023, p. 17-19) âAn ML model is a mathematical, abstract object that was created by a Machine Learning technique and serves to solve a task in the sense of creating an input-output relation. For example, regarding a neural network, the model consists of a list of hyperparameters, learned parameters and a description of how they interact when operating (architecture), among others. The ML model provides the functional basis of the AI application. For instance, a model can serve as the basis for performing a classification task, where the input is the object to be classified and the model output characterizes its 52 A PREPRINT class. In some cases, such as in generative models, the input (usually random numbers) may be of secondary importance to the actual task to be solved.â âAn AI application is the input-output mapping in a given application context based on the imple- mented AI component. Importantly, the AI assessment catalog does not take an isolated view of the ML model or the AI component. In fact, the catalog examines whether the individual processing steps performed up to the results being generated by the AI component through interaction with other components of the embedding are meaningful and appropriate for the given application context. For example, it assesses whether they are sufficiently free of errors and discrimination or secure against attacks and manipulation. Thus, the assessment object of the catalog is not predominantly the mathematical concepts underlying the AI component, but the functionality i.e., the input-output mapping, that is performed based on the AI component (as a functional basis) in a given application context. An AI application can be a standalone system that, for example, communicates directly with users, or it can be integrated into a larger (IT) system or product.â âIf an AI application is part of a larger system that is not entirely based on AI technologies, its boundaries within this surrounding system must be clearly defined. For example, ML-based object recognition (AI application) can be integrated into an autonomous vehicle, into a drone or into a site surveillance system (as larger system). Defining an AI application within a surrounding system is largely based on its functionality. For example, regarding an AI-based pedestrian detection system (AI application) in an autonomous car (larger system), the software modules that perform consistency checks on the outputs of the AI component should be seen as part of the AI application; however, other components that perform the overall planning of a driving route, for instance, would not be.â Mind Foundry (2026) âA model in AI and machine learning is a mathematical representation that captures patterns in data to make predictions or perform specific tasks. It is created through training, where the model learns from examples to recognise relationships between inputs and outputs. Models can vary in complexity, from simple linear regression to advanced neural networks, depending on the type of problem they are designed to solve.â Center for Humane Technology (2024, p. 25) âAI systems are more âgrownâ or âtrainedâ than they are programmed. AI systems are produced by rewarding an AI for âgood behaviorâ and punishing it for âbad behaviorâ, but the final capabilities, intentions, and goals of an AI model are hard to characterize. (informal definition)â MoĂ«s (2022, p. 2) âBenchmark-based definition is the most accurate and liked, but harder to roll out: âGeneral purpose AI systems are AI systems that score abovex%on the EU standardized testing suite for generality administered by the European Benchmarking Institute.ââ âSelf-reported task-based definition is easier to roll out, but has many loopholes: âGeneral purpose AI systems are AI systems that can be reasonably foreseen to carry out a broad range of tasks (e.g. â„ 10) from the EU official list of tasks with minimal recalibration.ââ Sharkey et al. (2024, p. 25) âThe objects of our framework, AI systems, are a slight generalization of AI models. AI systems include not only the weights and architecture of the model, but also include a broader set of system parameters (Figure 1). These consist of retrieval databases and particular kinds of prompts.â âAI models are still AI systems. They are simply a special case of AI systems that have only model parameters and no other AI system parameters.â CCompilation of Definitions from the Systematic Literature Review In total, 25 definitions for the term âAI modelâ and related terms were retrieved through the systematic literature review (across 13 different papers). The total number of definitions for the term âAI systemâ and related terms is higher, 53 A PREPRINT with 57 (across 25 different papers). Terms related to âAI modelâ found in the literature were: foundation model (8 definitions), AI model (7 definitions), machine learning model (7 definitions), semantic machine learning model (2 definitions), general purpose AI model (1 definition). Terms related to âAI systemâ were: AI system (32 definitions), general purpose AI system (7 definitions), autonomous system (5 definitions), a systemâs autonomous capabilities (3 definitions), automated decision system (2 definitions), machine learning system (1 definition), foundation model-based system (1 definition), Artificial General Intelligence system (1 definition), industrial autonomous system (1 definition), AI-based system (1 definition), intelligent system (1 definition), human-aware AI system (1 definition), cybernetic system (1 definition). C.1 AI Model Included in Table 10 are the authors and sources of definitions for the terms AI model and âmachine learning modelâ. 10 authors provide a total of 13 unique definitions of these terms (the definition from ISO/IEC 22989:2022 (ISO/IEC, 2022c) is used by two separate authors). Despite the broad search from 2012 to 2025, the publication years of the papers that were found range between 2022 and 2025, with 6 of 9 papers published in 2024. When looking at the publication dates of the sources referenced, a similar pattern can be found, with all sources apart from one Ramanathan et al. (2016) being published between 2021 and 2024. Table 10: SLR Findings for AI model and machine learning model AuthorsTerm definedSource of definition MĂŒhlhoff and Ruschemeier (2025)Machine learning model Machine learning model Authors themselves MĂŒhlhoff and Ruschemeier (2024) Kallab et al. (2024)Machine learning model Machine learning model Authors themselves Janiesch et al. (2021) FernĂĄndez-Llorca et al. (2025)AI model Machine learning model ISO/IEC (2022c) ISO/IEC (2022c) Lu et al. (2024)AI modelAuthors themselves Hupont et al. (2024)AI model AI model ISO/IEC (2022c) OECD (2024) Park et al. (2024)AI modelAuthors themselves Trincado CastĂĄn (2024)AI modelExecutive Office of the President (2023) Kallab et al. (2023)Machine learning modelAuthors themselves Li and Zhan (2022)AI modelAuthors themselves Myllyaho et al. (2022)AI modelAuthors themselves C.2 AI System Table 11 lists the authors and sources for the definitions of the terms AI system, âmachine learning systemâ, and âAI-based systemâ. 18 authors provided definitions for these terms, with many giving multiple definitions, leading to a total of 36 definitions. Some sources are referenced across different papers, with 9 references of the EU AI Act or other sources authored by EU institutions and 6 references of various OECD documents. This gives a total of 22 unique definitions, twice the number of definitions for AI model. Publications are again skewed towards recent years, and 54 A PREPRINT 2024 is once again the publication year with the highest number of publications (5). However, some papers with earlier publication years than for the term AI model exist, with the earliest published in 2018. Some of the sources referenced by the authors show even earlier publication years, including: Rai et al. (2019), Korikov (2011), Russell and Norvig (2009), Mitchell (2006), Makarov and Lokhin (2001), and Backlund (2000). Table 11: SLR Findings for AI system and âmachine learning systemâ AuthorsTerm definedSource of definition Ojanen (2025)AI systemEuropean Parliament and Council of the European Union (2024) MĂŒller et al. (2025)AI systemAuthors themselves FernĂĄndez-Llorca et al. (2025)AI system AI system AI system AI system OECD (2019b) European Commission (2021) European Parliament (2023) European Parliament and Council of the European Union (2024, Article 3(1)) Lu et al. (2024)AI modelAuthors themselves Hupont et al. (2024)AI system AI system Authors themselves OECD (2019b) Buiten (2024)AI system AI system AI system Authors themselves Buiten et al. (2023) European Parliament and Council of the European Union (2024) Trincado CastĂĄn (2024)AI system AI system AI system Executive Office of the President (2023) OECD (2019b) European Parliament and Council of the European Union (2024) Boone (2023)AI system AI system AI system AI system AI system AI system European Commission (2021) Council of the European Union (2022) European Parliament (2023) OECD (2019b) National Institute of Standards and Technology (2023, Adapted from OECD (2019b), ISO/IEC (2022c)) OECD (2024) 55 A PREPRINT Straub et al. (2023)AI system AI system Authors themselves Gil and Selman (2019) Spivakovsky et al. (2023)AI systemCabinet of Ministers of Ukraine (2020) Diaferia et al. (2022)AI system AI system Kaplan and Haenlein (2019) Rai et al. (2019) Myllyaho et al. (2022)Machine learning systemMitchell (2006) Krafft et al. (2021)AI/AISystem/Automated Decision System AI/AISystem/Automated Decision System OECD (2019b) Authors themselves Martinho et al. (2021)AI systemAuthors themselves Backlund (2000) Manser Payne et al. (2021)AI systemAuthors themselves Balasubramaniam et al. (2020)AI systemAuthors themselves Coleman (2021)AI systemRussell and Norvig (2009) Korikov (2018)AI System AI System Authors themselves Makarov and Lokhin (2001) and Ko- rikov (2011) D References on Conceptual Perspectives of Definitions As described in Section 4.1 (Conceptual Perspectives on Existing Definitions), we offer several conceptual perspectives on the existing definitions of AI models and AI systems, according to their parent categories and their features for both AI models and AI systems, and the relationship between the two. Below, we detail the references behind these conceptual perspectives. D.1 AI Model D.1.0.1 Parent Categories of AI Model Model Artifact (Result of Building/Training) Several sources specify that an AI model is the result of building/training. The OECD (2019a) states that a model can be âbased on data and/or expert knowledgeâ, specifying that it is created either by humans or by automated tools like machine learning algorithms. Similarly, Hupont et al. (2024), citing Explanatory Memorandum on the Updated OECD Definition of an AI System (OECD, 2024), portrays an AI model as the outcome of training via machine learning algorithms or other AI methods. Trincado CastĂĄn (2024), referring to Executive Order 14110 (Executive Office of the President, 2023), further supports this notion, suggesting that a model uses âcomputational, statistical, or machine-learning techniques.â Moreover, EstĂ©vez Almenzar et al. (2022) specifies that the term AI model often refers to either statistical models or machine learning models. A few definitions for machine learning models also fall under the perspective of model artifact. Myllyaho et al. (2022) cited Ramanathan et al. (2016) for a description of machine learning models as non-deterministic statistical approximations. Kallab et al. (2024) define a machine learning model as consisting of an algorithm, a training dataset, an application domain, model performance metrics, and metadata. Lastly, MĂŒhlhoff and Ruschemeier (2024) (as cited 56 A PREPRINT by MĂŒhlhoff and Ruschemeier (2025)) refer to weights and parameters as âmodel dataâ, emphasising the informational essence of machine learning models. Model as Representation AI models have been described as different types of representations. Some definitions foreground the mathematical nature of models. The European Data Protection Supervisor (2025) defines an AI model as a mathematical representation, capturing patterns found in their training data. This is further confirmed by Mind Foundry (2026) that defines a model as a mathematical representation. The EstĂ©vez Almenzar et al. (2022)âs view of AI models as either statistical or machine learning models suggests a similar view, as statistical models are mathematical representations. While Hupont et al. (2024) have a similar stance, defining an AI model as a mathematical construct, reviewing the source they are citing reveals an error in their citation. The researchers refer to EstĂ©vez Almenzar et al. (2022) who provide a definition of a machine learning model as a mathematical construct, rather than an AI model, and refer to ISO/IEC 22989:2022 (ISO/IEC, 2022c). We have reviewed ISO/IEC 22989:2022 (ISO/IEC, 2022c) in our manual review, and found that while ISO/IEC 22989:2022 (ISO/IEC, 2022c) does describe an AI model as possibly a mathematical representation, it can also be a physical or otherwise logical representation of a system, entity, phenomenon, process or data (also quoted like this by FernĂĄndez-Llorca et al. (2025)). The definition of a machine learning model is provided as referenced by EstĂ©vez Almenzar et al. (2022). Other definitions focus on the AI model as a representation of an external environment. The OECD, both in 2019 and 2022 (OECD, 2019a, 2022) refers to an AI model as an âactionable representation of all or part of the external environment of an AI systemâ. More broadly, ISO/IEC TS 42119-2:2025 (ISO/IEC, 2025) defines it as a machine- readable representation of knowledge, and ISO/IEC 22989:2022 (ISO/IEC, 2022c) suggests it can be a number of different representations (as discussed above). This is also found by Sponheim (2024), who refer to models as approximate representations of natural phenomena or concepts. Particularly for machine learning models, as already mentioned, ISO/IEC 22989:2022 ISO/IEC (2022c) defines them as mathematical constructs (also cited by FernĂĄndez-Llorca et al. (2025)). This view is also held by Poretschkin et al. (2023). Myllyaho et al. (2022) citing Ramanathan et al. (2016) to define machine learning models as non-deterministic statistical approximations suggests a similar viewpoint. D.1.0.2 Features of AI Model Production (How It Is Built/Trained) Some definitions specify how a model is built. In particular, several definitions by the OECD discuss the creation of an AI model. Its definition from both 2019 and 2022 specifies a model based on data and/or expert knowledge, provided by humans and/or automated tools (OECD, 2019a, 2022). This definition changes in 2023, describing more broadly that a modelâs parameters change during its build phase, and specifying the inclusion of statistical models and other input-output functions (OECD, 2024). Hupont et al. (2024) also cited the Explanatory Memorandum on the Updated OECD Definition of an AI System (OECD, 2024), portraying an AI model as the outcome of training via machine learning algorithms or other AI methods. Other sources apart from the OECD provide similar definitions. Trincado CastĂĄn (2024) cites Executive Order 14110 (Executive Office of the President, 2023) to define an AI model as using âcomputational, statistical, or machine-learning techniques.â The EstĂ©vez Almenzar et al. (2022) specifies that the term AI model often refers to either statistical models or machine learning models, which provides information on how it is built. More explicitly, Mind Foundry (2026) suggests that an AI model is built through training, learning to recognise relationships between inputs and outputs through examples, which indicates a focus on machine learning methods as well. Lu et al. (2024) follow this focus on machine learning, defining a model as trained from scratch on a dataset for a specific task. Function (What It Is Used for After Building) A recurring focus in several definitions is on the function or purpose of the model. ISO/IEC 22989:2022 (ISO/IEC, 2022c) (according to Hupont et al. (2024) and FernĂĄndez-Llorca et al. (2025)), Executive Order 14110 (according to Trincado CastĂĄn (2024)), Glossary of human-centric artificial intelligence (EstĂ©vez Almenzar et al., 2022), and California Senate Bill 53 (California State Legislature, 2025) describe a model as generating inferences or predictions from input data. Moreover, the OECD (2022) describes AI models as representing, describing and interacting with real or virtual environments, and Mind Foundry (2026) describes the function of an AI model as pattern recognition in order to make predictions or perform specific tasks. Some sources phrase the function of a model slightly differently, suggesting that a model is used for inference (Dunietz et al., 2024; OECD, 2024; ISO/IEC, 2022c). One source specifies 57 A PREPRINT that a model has the capacity to adapt to other tasks, calling an AI model a âuniversal approximatorâ, which might indicate a focus on machine learning (Li and Zhan, 2022). Regarding machine learning models, three definitions address their functions. Similar to the broader definitions of AI model functions, ISO/IEC 22989:2022 (ISO/IEC, 2022c) defines a machine learning model as generating inferences or predictions based on input data or information. Kallab et al. (2023) and MĂŒhlhoff and Ruschemeier (2025) identify pattern recognition as the primary function of a machine learning model, resembling the AI model definition by Mind Foundry (2026). D.2 AI System D.2.0.1 Parent Categories of AI System AI System as a System AI systems have been defined as several kinds of systems. Particularly prominent in definitions by the OECD and the EU is the definition of AI systems as a type of machine-based system (OECD, 2019a, 2022, 2024; European Parliament and Council of the European Union, 2024; Committee of Ministers, 2024; European Data Protection Supervisor, 2025). Several studies also reference various definitions by OECD and the EU when defining an AI system as a machine-based system (Hupont et al., 2024; Trincado CastĂĄn, 2024; Boone, 2023; FernĂĄndez-Llorca et al., 2025; Krafft et al., 2021). Apart from OECD and the EU, other sources also use machine-based systems as a parent category (National Institute of Standards and Technology, 2023 also referenced by Boone, 2023); Colorado General Assembly, 2024; Straub et al., 2023). Several other terms have been used to describe which type of system is the parent category of AI system. NIST defines AI systems as âengineered systemsâ (National Institute of Standards and Technology, 2023 also referenced by Boone, 2023). This term is also used by ISO/IEC 22989:2022 (ISO/IEC, 2022c) and GB/T 41867-2022 (State Administration for Market Regulation (PRC), 2022). Several EU documents define AI systems as software or hardware systems (High-Level Expert Group on Artificial Intelligence, 2019a, 2020; European Commission, 2021 also referenced by Boone, 2023 and Buiten, 2024)). Broader terms found in the literature are âartificial intelligence-based systemâ (European Commission, 2018; ISO/IEC/IEEE, 2022; National Assembly of the Republic of Korea, 2025; Coleman, 2021 referring to Russell and Norvig, 2009), âcomputer systemâ (Straub et al., 2023 referring to Gil and Selman, 2019), and most broadly âsystemâ (EstĂ©vez Almenzar et al., 2022; Council of the European Union, 2022, Article 3(1) as cited by FernĂĄndez-Llorca et al., 2025; Executive Office of the President, 2023 as cited by Trincado CastĂĄn, 2024; European Commission, 2021 as cited by Boone, 2023 and Korikov, 2018). AI/AI system as a Technology While most definitions describe AI systems as systems, a few either broadly define them as technologies, or define AI as AI systems. UNESCO (2022) uses the term âinformation-processing technologiesâ to describe AI systems. The European Commission refers to AI as systems in two of their communications (European Commission, 2018; High-Level Expert Group on Artificial Intelligence, 2019b). The SLR also found two national government documents defining AI as a system. Hjaltalin and Sigurdarson (2024) refer to Leading the way into the age of artificial intelligence: Final report of Finlandâs Artificial Intelligence Programme 2019 (Ministry of Economic Affairs and Employment of Finland, 2019), defining AI as âdevices, software and systems that are able to learn and make decisions in almost the same manner as people.â Similarly, Spivakovsky et al. (2023) cite the Resolution of the Cabinet of Ministers of Ukraine of December 2, 2020, No. 1556-r: On the Approval of the Concept for the Development of Artificial Intelligence in Ukraine (Cabinet of Ministers of Ukraine, 2020, in Ukrainian), calling AI an âorganized set of information technologiesâ, using a âsystem of scientific research methods and algorithms for processing information. D.2.0.2 Features of AI System Production (How It Is Built) Different definitions specify how an AI system is built and what it is made of. The EU AI Act and related documents, as referenced by Buiten (2024) and Boone (2023) identify three main categories of techniques and approaches underpinning AI systems: (i) machine-learning approaches, (i) logic-and knowledge-based approaches, and (i) statistical, Bayesian estimation, search, and optimisation methods. These categories encapsulate the methodological diversity of AI systems and reflect the broad regulatory scope intended to encompass current and emerging techniques. Similarly, the High-Level Expert Group on Artificial Intelligence (2019a, 2020) specify that an AI system can either use symbolic rules or learn a numeric model. UNESCO (2022) provides some explanation on the methods of developing an AI system as well, 58 A PREPRINT grouping them into (i) machine learning, which entails deep learning and reinforcement learning, and (i) machine reasoning, which is specified as planning, scheduling, knowledge representation and reasoning, search and optimisation. Other definitions are less specific about how a system is built. The Center for Humane Technology (2024) describes AI systems as being âmore âgrownâ or âtrainedâ than they are programmed, produced by rewarding an AI for âgood behaviorâ and punishing it for âbad behaviorââ, suggesting a focus on machine learning. GB/T 41867 (2022) keeps the definition similarly broad, stating that AI systems use âAI-related technologies and methods.â The EstĂ©vez Almenzar et al. (2022) communicates this even more broadly, describing AI systems as containing artificial intelligence. Some studies provide further descriptions of what a system consists of. Hupont et al. (2024) and Lu et al. (2024) both describe an AI system as consisting of one or more AI models, infrastructure, data pipelines, user interfaces, and other modules. Furthermore, an AI system has been described as an interacting ensemble of interdependent components operating within an integrated structure (Martinho et al., 2021 referring to Backlund, 2000). Lastly, Buiten et al. (2023) describes AI systems as incorporating algorithms that require training data, model architecture, and decision-making rules. Function (What It Does) According to the literature, the defining function of an AI system, especially in regulatory and policy contexts, is to generate inferences or outputs from inputs and to influence its environment (physical or virtual). This is reflected in numerous sources (OECD, 2019b as cited by Hupont et al., 2024); European Parliament and Council of the European Union, 2024, Article 3(1); Council of the European Union, 2022, Article 3(1) and European Parliament, 2023, Article 3(1) as cited by FernĂĄndez-Llorca et al., 2025); Committee of Ministers, 2024; European Data Protection Supervisor, 2025; National Institute of Standards and Technology, 2023, NIST AI 100-1; ISO/IEC, 2022c, ISO/IEC 22989:2022; National Assembly of the Republic of Korea, 2025, Article 2; Colorado General Assembly, 2024, Senate Bill 24-205; State Administration for Market Regulation (PRC), 2022, GB/T 41867-2022; Poretschkin et al., 2023; Krafft et al., 2021). The OECD (2019a, 2022, 2024) has a very similar formulation, suggesting an AI system makes recommendations, predictions or decisions for a given set of objectives. Moreover, ISO/IEC 22989:2022 (ISO/IEC, 2022c) describes an AI systemâs function as generating outputs such as content, forecasts, recommendations or decisions for a given set of human-defined objectives (similarly found in GB/T 41867-2022 (State Administration for Market Regulation (PRC), 2022)). Several other specifications are made regarding the function of an AI system. The EU AI Act (as referenced by Buiten (2024)) stipulates that systems operate toward human-defined objectives. Other sources specifying this requirement are ISO/IEC 22989:2022 (ISO/IEC, 2022c) and GB/T 41867-2022 (State Administration for Market Regulation (PRC), 2022). UNESCO (2022) describes a systemâs function as prediction and decision-making. Other interpretations describe AI systems as mechanisms for interpreting external data (Diaferia et al., 2022 referring to Kaplan and Haenlein, 2019; Manser Payne et al., 2021 referring to Haenlein and Kaplan, 2019), or performing pattern recognition (Krafft et al., 2021). Further, systems are described as completing cognitive tasks (Straub et al., 2023; Diaferia et al., 2022 referring to Kaplan and Haenlein, 2019; UNESCO, 2022), problem-solving (Coleman, 2021 referring to Russell and Norvig, 2009), perceiving, reasoning, learning, and interacting (both with their environment and internally) (Diaferia et al., 2022 referring to Rai et al., 2019; Martinho et al., 2021 referring to Backlund, 2000). AI systems are often described as exhibiting varying degrees of autonomy (OECD, 2019b as referenced by Hupont et al., 2024; European Parliament and Council of the European Union, 2024, EU AI Act as referenced by Trincado CastĂĄn, 2024 and Ojanen, 2025; National Institute of Standards and Technology, 2023 as cited by Boone, 2023; Straub et al., 2023; OECD, 2022, 2024; UNESCO, 2022; European Parliament and Council of the European Union, 2024, Article 3(1); Committee of Ministers, 2024, Article 2; European Data Protection Supervisor, 2025; National Institute of Standards and Technology, 2023, NIST AI 100-1; ISO/IEC, 2022c, ISO/IEC 22989:2022; National Assembly of the Republic of Korea, 2025, Article 2; State Administration for Market Regulation (PRC), 2022, GB/T 41867-2022). Definitions of autonomous systems expand on this by describing entities capable of acting on their own rules, with self-contained decision-making capacity (Buiten et al., 2023 as referred to by Buiten, 2024; Song et al., 2021 referring to Helle et al., 2016; Flammini, 2021). Further attributes of autonomous systems found in the literature include self- awareness (Song et al., 2021 referring to Helle et al., 2016), adaptivity (Song et al., 2021 referring to Helle et al., 2016 and Sifakis, 2019; Torkjazi and Raz, 2022 referring to Antsaklis and Rahnama, 2018), and the ability to learn, diagnose failures, reconfigure, and plan (Torkjazi and Raz, 2022 referring to Antsaklis and Rahnama, 2018). Song et al. (2021) quote Sifakis (2019) to identify five core modules of autonomy: perception, reflection, planning, goal management, and self-adaptation. Similarly, Torkjazi and Raz (2022) refer to Huang (2007) to outline âRoot Autonomous Capabilities (RACs)â: sensing, perceiving, analysing, communicating, planning, deciding, and acting toward goals. They also refer to Woudenberg et al. (2020) to highlight three dimensions of autonomy: intelligence, operational independence, and collaboration with other systems. 59 A PREPRINT Multiple other attributes are ascribed to AI systems. Some definitions describe AI systems as showing various degrees of adaptivity (Hupont et al., 2024 referring to OECD, 2019b; Trincado CastĂĄn, 2024 and Ojanen, 2025 referring to the European Parliament and Council of the European Union, 2024, EU AI Act; Manser Payne et al., 2021 referring to Haenlein and Kaplan, 2019; OECD, 2024; High-Level Expert Group on Artificial Intelligence, 2019b,a, 2020; Committee of Ministers, 2024, Article 2; European Data Protection Supervisor, 2025; National Assembly of the Republic of Korea, 2025, Article 2). Another prominent feature is learning ability (Straub et al., 2023; Diaferia et al., 2022 referring to Kaplan and Haenlein, 2019; Manser Payne et al., 2021 referring to Haenlein and Kaplan, 2019; Coleman, 2021 referring to Russell and Norvig, 2009; UNESCO, 2022). Lastly, intelligence is mentioned by some sources as well (Straub et al., 2023 referring to Gil and Selman, 2019; Korikov, 2018 referring to Makarov and Lokhin, 2001 and Korikov, 2011; European Commission, 2018). Further definition on the aspect of intelligence is provided by (Coleman, 2021), who defines an intelligent system as one that manipulates facts and concepts and displays behaviours across different levels of Bloomâs taxonomy (Bloom et al., 1956). One definition describes the function of a machine learning system: producing correct outputs without explicit programming (Myllyaho et al., 2022 referring to Mitchell, 2006). Mechanism (How It Does It) Apart from analysing what a system does, it is important to consider how it does this. The OECD has a clear definition for this, explaining that AI systems use machine and/or human-based inputs for various activities, such as perceiving its environment, abstracting these perceptions into models, and using model interpretations to produce an outcome (OECD, 2019a, 2022). In a similar manner, the High-Level Expert Group on Artificial Intelligence (2019b,a, 2020) describes AI systems as acting in the physical or digital world and achieving their function by perceiving their environment, interpreting the collected structured or unstructured data, reasoning on the knowledge derived from this data and deciding the best action(s) to take (according to pre-defined parameters) to achieve the given goal. This is also found by European Commission (2018), describing AI systems as analysing the environment and taking actions to achieve their goals. UNESCO (2022) explains that knowledge modelling, representation, data and calculations are the means by which AI systems reach their goals. Broadly, AI systems have also been described as typically operating in whole or in part using AI (Trincado CastĂĄn, 2024 referring to Executive Office of the President, 2023, Executive Order 14110). Machine Intelligence Research Institute (2026) focuses on the safety aspect of an AI system, explaining that some AI systems may possess the capability to resist intervention by programmers, while others may be âcorrigibleâ. Lastly, machine learning systems have also been described in terms of its mechanism. They are defined as improving their behaviour through experience and having the ability to adapt and predict situations (Myllyaho et al., 2022 referring to Mitchell, 2006). D.3 Relationship between AI Model and AI System D.3.0.1 Model as a Core Component of a System Several sources describe the AI model as an integral part of a broader system. ISO/IEC 22989:2022 (ISO/IEC, 2022c) describe AI models as part of AI systems, used to make predictions. The (OECD, 2019a) and (OECD, 2024), and (Dunietz et al., 2024) share this perspective, describing an AI model as the core component of an AI system. Recital 97 of the EU AI Act (European Parliament and Council of the European Union, 2024) and the Guidance for Risk Management of Artificial Intelligence Systems (European Data Protection Supervisor, 2025) confirm this view, by identifying AI models as essential components of AI systems, while also emphasizing that they require other software components to be able to function and interact with users and the virtual or physical environment. In addition, Trincado CastĂĄn (2024) refers to Executive Order 14110 (Executive Office of the President, 2023) when defining an AI model as a component of an information system, and both Hupont et al. (2024) and Lu et al. (2024) describe AI systems as containing one or more models. Regarding definitions of machine learning models, only Myllyaho et al. (2022) consider the machine learning model as a core component, broadly referring to them as elements within a machine learning system. D.3.0.2 Model as a Tool for a System Some definitions describe the relationship between AI model and AI system in terms of how an AI system uses an AI model as a tool. The definition of ISO/IEC 22989:2022 (ISO/IEC, 2022c) fits not just the perspective of the model as a core component of a system, but also this one, as it specifies AI systems use AI models to make predictions and conduct tasks. Two other sources apart from ISO/IEC 22989:2022 (ISO/IEC, 2022c) refer to AI models as tools for inference in 60 A PREPRINT an AI system, both also suggesting AI models are core components of systems (Dunietz et al., 2024; OECD, 2024). The OECDâs definition provided in 2019 (OECD, 2019a) differs slightly, specifying that an AI system uses models to âformulate options for outcomes.â Another source that describes AI models not just as core components but also as tools is Trincado CastĂĄn (2024), citing Executive Order 14110 (Executive Office of the President, 2023), and suggesting that AI models implement AI technology within an AI system, providing outputs from a set of inputs. Not defining AI models as core components of AI systems, UNESCO (2022) defines AI systems as integrating models that give them the capacity to learn and perform cognitive tasks. Moreover, Park et al. (2024) describe AI models as implementing AI functions within systems. Lastly, and referring to AI systems but only machine learning models, Poretschkin et al. (2023) defines machine learning models as the âfunctional basisâ of an AI application. 61