Inferential Learning vs. Hardcoded Rules: How International Frameworks Legally Distinguish AI Systems From Deterministic Software
Global legal frameworks have established a precise boundary between artificial intelligence and traditional software. By focusing on a system's ability to infer outputs and adapt autonomously, regulators ensure that deterministic, rule-based code remains exempt from heavy AI compliance burdens.
By Mateo Ramos
In short
- International frameworks legally distinguish artificial intelligence from traditional software based on a system's ability to infer outputs and adapt autonomously.
- The OECD, EU AI Act, and Council of Europe treaty explicitly exclude deterministic, hardcoded software from heavy AI compliance burdens.
- A three-factor legal test—evaluating data-driven development, goal-oriented optimization, and formal indeterminacy—determines whether a system triggers regulatory oversight.
Industry groups and software developers frequently argue that sweeping new artificial intelligence regulations will accidentally capture traditional software. They claim that basic spreadsheets, rule-based scripts, and standard automation tools will be subjected to crippling compliance costs, stifling digital innovation across the board.[1]
The legal text of the world's major frameworks contradicts this fear directly. The European Union, the Organisation for Economic Co-operation and Development (OECD), and the Council of Europe have all adopted precise statutory language that legally separates inferential learning models from deterministic, hardcoded software.[2][3][4]
The dividing line rests on three specific mechanical capabilities: autonomy, adaptiveness, and the ability to infer outputs from data. If a program merely follows explicit human-written rules to execute a task, it falls outside the legal definition of artificial intelligence entirely.[5]
The Global Baseline Definition
The foundation for this legal boundary was established by the OECD. In May 2024, the organization updated its foundational definition to explicitly require that a system "infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions."[2]
This single verb—infers—is the load-bearing legal distinction across international law. It means the system derives its own logic and statistical weights from training data, rather than executing a predetermined pathway written line-by-line by a human programmer.[2][5]
The European Union adopted this exact phrasing almost word-for-word in Article 3(1) of the AI Act. The EU legislation defines an AI system as a machine-based system designed to operate with varying levels of autonomy that can influence physical or virtual environments.[3]
Furthermore, the European Commission's February 2025 guidelines clarified the exact boundaries of this definition. The guidelines explicitly state that systems based on rules defined solely by natural persons to execute operations automatically are strictly excluded from the regulation's heavy compliance burdens.[6]
This lifecycle-based perspective examines both the pre-deployment building phase and the post-deployment use phase. To be regulated as AI, the system must be computationally driven by machine operations that go beyond simple manual controls, demonstrating a capacity to formulate its own options.[6][7]
Autonomy and Adaptiveness
To trigger regulatory oversight, a system must exhibit some degree of independence from human involvement. A traditional optical character recognition program based solely on predefined pattern rules does not qualify as AI under these frameworks, because its execution path is entirely fixed.[5]
Conversely, an image recognition system that learns to identify handwriting styles by training on millions of examples operates autonomously. Because the system's logic was not explicitly programmed by a human, it falls squarely under the AI definition and its associated legal obligations.[5]
Adaptiveness after deployment is another critical statutory marker. While not strictly mandatory for a system to be classified as AI, self-learning capabilities that allow a model's behavior to change in production strongly indicate an AI system that requires ongoing regulatory monitoring.[7]
Traditional software is fundamentally deterministic: given the same input, it will always produce the exact same output through a fixed execution path. AI models are probabilistic, generating outputs based on statistical approximations that can vary significantly between identical queries.[5]
The Council of Europe Treaty
This technical distinction is now enshrined in international human rights law. On September 5, 2024, the Council of Europe opened the Framework Convention on Artificial Intelligence for signature, creating the first legally binding international AI treaty designed to protect democratic institutions.[4]
The treaty, drafted by 46 member states alongside the US, Canada, and Japan, mirrors the OECD definition perfectly. It explicitly limits its scope to systems that infer how to generate outputs that influence physical or virtual environments, excluding traditional IT infrastructure.[4][8]
By aligning with the EU and OECD, the treaty ensures a harmonized global standard. Signatories must implement risk management frameworks to protect human rights, but they are protected from applying these heavy governance structures to conventional, deterministic software systems.[8]
The Convention gives signatories the discretion to adopt graduated measures based on the severity and probability of adverse impacts. This risk-based approach relies entirely on the foundational distinction between inferential AI and deterministic code to determine which systems require strict oversight.[8]
The US Regulatory Approach
The United States has historically relied on a patchwork of state laws and agency guidelines rather than a single comprehensive federal AI act. However, the underlying technical definitions used by American regulators remain highly consistent with these established international norms.[9]
Under 15 U.S. Code § 9401, artificial intelligence is described as a machine-based system that operates toward human-defined objectives by generating predictions, recommendations, or decisions. This statutory language aligns closely with the OECD's focus on inferred outputs and autonomous operation.[10]
The Fiscal Year 2019 National Defense Authorization Act further refined this legal boundary. It defined AI as artificial systems that learn and improve performance when exposed to data, or that act under unpredictable conditions without close human oversight.[10]
Recent federal actions continue to build on this framework. On September 29, 2026, President Trump issued Executive Order 14434, directing federal agencies to use the term "Super Intelligence" for frontier models, while maintaining the statutory definition of AI for existing compliance programs.[11]
The Three-Factor Compliance Test
For corporate compliance officers, legal experts have distilled these international frameworks into a practical three-factor test. The first factor examines whether the system was developed using data-driven machine learning techniques or if it relies entirely on explicit, hardcoded rules.[5]
The second factor assesses goal-oriented optimization. An AI system pursues explicit or implicit goals by formulating its own options for action, rather than simply executing a user's direct, step-by-step command in a linear, predictable sequence.[2][5]
The third factor is formal indeterminacy. If a software program's output can be perfectly predicted simply by reading its source code, it is deterministic software. If the output depends on learned weights and probabilistic inference, it is legally classified as AI.[5]
Practical Implications for Businesses
This precise legal boundary protects businesses from unnecessary regulatory burdens. A company deploying a standard rules-based chatbot with pre-written responses does not need to register it in the EU's high-risk AI database, saving significant compliance costs and administrative overhead.[5][9]
This precise legal boundary protects businesses from unnecessary regulatory burdens.
However, if that same company upgrades to a large language model that infers responses dynamically, the system crosses the legal threshold. It immediately becomes subject to transparency requirements, bias testing, and potential liability under laws like the 2026 Colorado AI Act.[9]
The global legal consensus has successfully isolated the specific mechanical traits that make artificial intelligence uniquely powerful and uniquely risky. By focusing strictly on the machine's ability to infer and adapt, the law regulates the actual mechanism of harm rather than the mere presence of automated code.[12]
Definitions
- Deterministic Software
- Programs that produce the exact same output every time they receive the same input, following a fixed, human-written execution path.
- Inferential Learning
- The process by which a system derives its own logic and statistical weights from training data, rather than executing explicit rules.
- Formal Indeterminacy
- A legal and technical threshold where a software program's output cannot be perfectly predicted simply by reading its source code.
- Frontier Models
- Highly capable foundation models that can perform a wide variety of tasks and pose potential systemic risks.
Questions & answers
Are open-source software libraries automatically classified as AI?
Not unless they contain pre-trained weights capable of inferential learning. A standard open-source library that provides deterministic mathematical functions falls outside the regulatory definitions.
How do regulators classify hybrid systems that use both rules and machine learning?
Under the EU framework, if the machine learning component dictates the final output or significantly influences the system's behavior, the entire integrated product is typically classified and regulated as an AI system.
Does the US Executive Order 14434 change existing corporate compliance laws?
No. The order directs federal agencies to use the term 'Super Intelligence' for frontier models in official communications, but it explicitly leaves existing statutory definitions and corporate compliance obligations unchanged.
Analysis by camp
Software Industry Advocates
Concerned that broad definitions will subject traditional code to unnecessary compliance costs.
Industry groups argue that without precise technical boundaries, standard automation tools and rule-based scripts could be swept into AI regulatory frameworks. They emphasize that subjecting deterministic software to the transparency and testing requirements designed for frontier models would cripple digital innovation and impose unsustainable administrative overhead on small developers.
Regulatory Authorities
Focused on capturing systems that operate autonomously and pose probabilistic risks.
Regulators maintain that the legal definition must remain technology-neutral to future-proof the law, focusing on the system's capabilities rather than its specific architecture. By isolating the ability to 'infer' and 'adapt,' authorities aim to regulate the unique risks of probabilistic models—such as bias and hallucination—without stifling the broader software economy.
Compliance Professionals
Prioritizing clear, testable criteria to classify corporate software inventories.
Legal and compliance teams rely on the three-factor test of data experience, goal optimization, and formal indeterminacy to audit their systems. They argue that clear statutory language is essential for conducting accurate risk assessments, allowing companies to confidently deploy traditional software while applying strict governance frameworks only to genuine inferential models.
- Regulatory Authorities
- Focused on capturing systems that operate autonomously and pose probabilistic risks.
- Software Industry Advocates
- Concerned that broad definitions will subject traditional code to unnecessary compliance costs.
- Compliance Professionals
- Prioritizing clear, testable criteria to classify corporate software inventories.
Perspectives this story doesn't cover
- Open-source developers building hybrid systems
- Judicial courts interpreting the statutory definitions
Sources
[1]Morgan LewisSoftware Industry AdvocatesThe EU AI Act: Implications for M&A
Read on Morgan Lewis →
[2]OECDRegulatory AuthoritiesArtificial Intelligence in Society
Read on OECD →
[3]DLA PiperThe EU AI Act: Definition of an AI System
Read on DLA Piper →
[4]Council of EuropeRegulatory AuthoritiesFramework Convention on Artificial Intelligence and Human Rights
Read on Council of Europe →
[5]SimpliantCompliance ProfessionalsThe Definition of an AI System under the EU AI Act
Read on Simpliant →
[6]Law Society of IrelandCompliance ProfessionalsEU expands on 'AI' definition under act
Read on Law Society of Ireland →
[7]OrrickCompliance ProfessionalsHow does the AI Act define AI Systems?
Read on Orrick →
[8]Inside PrivacyCouncil of Europe Adopts International Treaty on Artificial Intelligence
Read on Inside Privacy →
[9]DrataCompliance ProfessionalsArtificial Intelligence Regulations: State and Federal AI Laws 2026
Read on Drata →
[10]Cornell Law SchoolArtificial intelligence (AI)
Read on Cornell Law School →
[11]Wiley LawTrump AI Executive Order: Promoting Advanced AI Innovation and Security
Read on Wiley Law →
[12]Factlen Editorial TeamSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
More in Artificial Intelligence
See all →AI Compliance
The Five Steps of an Algorithmic Impact Assessment Regulators Use to Mandate AI Risk Mitigation
3 sources
AI Explainability
The Inverse Relationship Between AI Model Complexity and Decision Explainability
11 sources
Frontier AI
The 10^26 FLOP Threshold: How the US Government Monitors Frontier AI
4 sources
AI Regulation
Trump and Tech CEOs Sign Voluntary White House Accord on 'Super Intelligence' Safety Standards
5 sources
Comments
Every angle. Every day.
Get Artificial Intelligence stories with full source coverage and perspective breakdowns, free every day.




