Back to Essential Home

Is This Even AI?

A practical classification framework for distinguishing AI systems from traditional software — essential groundwork before any governance work begins.

5 min
Article

Is This Even AI?

The most dangerous AI systems in most organizations are the ones no one has classified as AI. They didn't arrive in a resource purchase request or a board presentation. They came as platform updates, smart features, productivity tools — and they've been shaping consequential decisions ever since.


Why Misclassification Creates Real Risk

Most governance frameworks assume you already know what's in scope. They skip straight to policies, risk tiers, and compliance checklists. If you haven't correctly identified which systems actually qualify as AI, everything built on top of that foundation is wrong.

Misclassification runs in two directions, and both cause harm.

Over-classification means governing rule-based automation as AI. Resources get spread across tools that don't need oversight, while the systems that actually learn from data and affect people get less attention. Teams become desensitized. The word "AI" loses meaning.

Under-classification is more dangerous. A hiring tool quietly reproducing historical bias never gets a fairness review. A generative assistant drafting customer communications never gets a content policy. By the time something goes wrong, there's no audit trail, no clear accountability, and no defense.

Classification isn't a preliminary exercise before governance begins. It is governance — the foundation everything else sits on.


The One Distinction That Changes Everything

The most important question in AI classification isn't about the marketing label. It's about how the system actually works.

A rules-based system does exactly what it was programmed to do. Someone wrote explicit instructions — if condition A, then action B. The logic is fixed. The output is predictable. You can audit the rules and know exactly why the system did what it did.

An AI system works differently. Instead of following explicit rules, it was trained on data and developed its own internal model of how to respond. That model can produce outputs no one explicitly programmed. It can behave differently as conditions change. And it can be wrong in ways that are difficult to predict or explain.

With a rules-based system, you govern the rules. With an AI system, the logic is often opaque, the outputs can surprise you, and the system's behavior can shift over time without anyone changing a line of code. That difference determines the entire nature of your governance obligation.

"AI-powered" on a vendor slide does not answer the question.


The Four-Question Classification Framework

Run any system through these questions in order. Stop when you reach an outcome.

QuestionIf yes...If no...
Does it learn from data?Continue to Q2Rules-based automation. Existing software controls apply.
Does it generate outputs no one explicitly programmed?Continue to Q3Lower-risk AI. Light oversight sufficient.
Does it affect people's money, jobs, rights, or access?Continue to Q4In scope for governance. Standard risk assessment.
Can users see how it works and meaningfully override it?Standard governance program requiredElevated risk tier — prioritize controls and transparency.

Applied: The candidate fit score in your hiring platform — if it's generated by a model trained on historical hiring data — answers yes to all four questions, including the one about affecting people's jobs. That's governed AI requiring a fairness review, documentation, and human oversight controls.

The smart approval workflow in your procurement platform — if an administrator configured the routing logic in a setup screen and it never updates unless someone manually changes it — is rules-based automation. Your existing controls are sufficient, regardless of what the vendor calls it.

On vendor language: "AI-powered," "intelligent," and "adaptive" are marketing terms, not technical classifications. Apply the four questions regardless of what the pitch deck says.

Getting that distinction backwards — in either direction — has real consequences. The classification doesn't complete your governance program. It determines whether your governance program is protecting anything real.


Pro Tip from the Method 9 Team

The systems that most need governance attention are rarely the ones anyone is worried about. The obvious systems — the ones named "AI" in the procurement request, announced in a company-wide rollout — usually get some form of scrutiny. It's the systems that arrived quietly, as a platform update or a productivity feature or a third-party integration, that escape review entirely.

Your four-question framework is most valuable not when applied to tools someone flagged. It's most valuable when applied to tools no one thought to flag at all.

The question isn't just "is this AI?" It's "what in our environment has never been asked that question?"

Continue Learning

This is a free preview module. Method 9 members access the full library of compliance frameworks, assessment tools, and implementation templates.

Explore Membership