AI Definition 2026: What UK Businesses Need to Know

Is your chatbot AI in the eyes of the law? Three 2026 regulations hinge on that answer—and most UK companies aren't ready.

by Cleverson Gouvêa

AI Definition 2026: What UK Businesses Need to Know

The definition of artificial intelligence has moved from the classroom to the courtroom. In August 2026, three different regulations will rely on it to decide whether your system is in or out of scope: the UK's new AI Bill, the ICO's updated guidance on AI and data protection, and the EU AI Act (which still affects UK businesses operating in Europe). If you run a chatbot, this reaches you.

TL;DR

  • A definition of AI exists to separate deterministic automation from systems that infer—and the verb infer is the dividing line.
  • The OECD rewrote the concept in 2023/2024; the EU AI Act and the UK's AI Bill inherited the same skeleton.
  • The UK's AI Bill doesn't just define the system: it defines provider, deployer, and AI agent. Those who merely use also bear responsibility.
  • The ICO's guidance on AI and data protection is already in effect, and the EU AI Act's high-risk obligations apply to UK businesses serving EU customers.
  • Only 17% of Brazilian companies used some form of AI in 2025 (Cetic.br). The bar is arriving before adoption.

A definition of AI needs to serve two audiences with opposing needs, and that's where the confusion begins.

In everyday use, "AI" has become an umbrella term for anything that seems smart: email autocomplete, spam filters, video recommendations, shop chatbots. This elasticity is harmless in a corridor conversation but costly inside a contract.

The technical definition describes a field of research: systems that perform tasks normally associated with human cognition—recognising patterns, learning from examples, deciding under uncertainty. It's useful for engineers and terrible for lawyers, because it doesn't delimit anything.

The legal definition does the opposite. It needs to be narrow enough not to capture an Excel spreadsheet and broad enough not to let a language model escape on a technicality. That's why legal texts have converged on a specific verb: infer.

If the system merely executes the rule you wrote ("if the message contains the word invoice, reply with link X"), it doesn't infer—it obeys. If the system derives on its own how to achieve the goal from the input data, it infers. That's the dividing line that underpins virtually all AI regulation written in the last five years.

Holding on to this difference is what separates a useful answer from unnecessary panic. Much of the customer service automation running today in the UK is not AI in the legal sense. Some of it is—and doesn't know it.

The OECD's definition of AI has become the global standard

In 2023 and 2024, the OECD revised the concept it had published in 2019. The current version describes it as follows:

"An AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptability after deployment."

Three words carry the weight of the sentence: infers, autonomy, and adaptability.

The most relevant change from the 2019 text is subtle but important: the system's objectives no longer need to have been set by a human. An agent that generates sub-objectives on its own still falls within the concept. It was a course correction in light of what models began doing between 2020 and 2024.

This formulation was adopted by the EU AI Act, the Council of Europe, the United Nations, and US regulations. When you read an international contract that mentions AI system, this is almost always the standard being applied—including in the annexes of cloud providers that many UK companies sign without reading. The full text is in the OECD AI Principles.

Why lawmakers prefer "infer" over "learn"

"Learn" would exclude symbolic systems and also already-trained models that just run in production. "Infer" covers both cases: the model that continues training and the frozen model that only produces outputs. Every definition of AI written after 2019 inherited this verb for that reason.

For a business, the consequence is direct: running a ready-made model—a GPT or a Gemini via API, for example—is enough to fall within the concept. You don't need to train anything or hire a data scientist.

How the UK's AI Bill writes the definition of AI

The UK government introduced the AI Bill in 2025, and it is currently progressing through Parliament. The Bill takes a pro-innovation, outcomes-focused approach, but it still relies on a definition of AI. The Bill's definition is similar to the OECD's, focusing on systems that infer from inputs to generate outputs. The Bill also introduces obligations for providers and deployers, with the Information Commissioner's Office (ICO) as one of the key regulators.

"AI system" means a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.

Compare this with the OECD and you'll see the same skeleton: variable autonomy, inference, outputs that influence the world. The UK's difference lies in what comes next. The Bill doesn't stop at the definition—it distributes responsibilities.

Provider, deployer, agent: the labels that decide who answers

Term (AI Bill) Who it is Practical example
Provider Who develops the system, directly or by commission, and places it on the market under their name or brand The company that builds and sells the AI customer service platform
Deployer Who uses or employs the system on their own behalf or benefit, outside of personal activity The clinic, school, or shop that switches on the chatbot on WhatsApp
AI agents Providers and deployers, collectively Both are responsible, to different extents
Competent authority The body responsible for enforcing the law In the UK, this is likely to be the ICO for data protection aspects, with sectoral regulators like Ofcom or the FCA for specific areas

The point that often goes unnoticed: you don't need to develop AI to have obligations. Merely using it is enough. The deployer figure exists precisely to reach the pizzeria that contracted a bot, not just the lab that trained the model. It's the same logic as controller and processor that the UK GDPR has already established since 2018.

Why the definition of AI became urgent this August

Three facts have pushed the topic to the top of search results in recent weeks.

1. The EU AI Act's high-risk obligations are now in force. Although the UK has its own approach, many UK businesses that operate in the EU or serve EU customers are now subject to the EU AI Act. The Act's high-risk requirements, including conformity assessments and transparency obligations, apply from August 2026. This is a major driver for UK companies to understand the definition of AI.

2. The ICO has updated its guidance on AI and data protection. The Information Commissioner's Office (ICO) has been active in regulating AI, particularly around data protection. In 2026, the ICO published new guidance on the lawful basis for using personal data in AI systems, and it has been actively enforcing against companies that fail to comply with the UK GDPR when using AI. This guidance relies on a clear definition of AI to determine when the rules apply.

3. The UK government's AI Bill is progressing through Parliament. The Bill, which was introduced in 2025, is expected to receive Royal Assent later this year. It will establish a new regulatory framework for AI, including a definition of AI and obligations for providers and deployers. This has raised awareness among UK businesses that they need to understand whether their systems are AI.

None of these three movements works without an operative concept. Classifying risk requires knowing what the object being classified is. Labelling synthetic content requires knowing what counts as synthetic. That's why the search for the definition of AI has risen in the UK this month: it has become a compliance prerequisite, not a blog curiosity.

The practical test: does your chatbot fit the definition of AI that the law uses?

Before applying the definition of AI to your case, run through five questions. I use this sequence with clients before any conversation about risk:

  1. Does the system produce outputs that no one wrote in advance? If every possible response is in a flow designed by a human, it's deterministic automation.
  2. Does it decide the path on its own from the input? Classifying intent, choosing a service route, summarising history—all of that is inference.
  3. Does it use a language model, computer vision, or machine learning, even from third parties? Calling an API already counts. Provider and deployer are distinct roles, but both are agents.
  4. Does the output influence a decision about a person? Triage, prioritisation, credit scoring, product recommendation, denial of service.
  5. Can you explain why it responded that way? If you can't, you have a transparency problem before you have a legal problem.

When your bot probably isn't AI

Numbered menu, exact keyword response, fixed link trigger, opening hours notice, handover to a human by rule. That's flow, not model. It's still subject to the UK GDPR and the Consumer Rights Act 2015, but it falls outside the definition of AI adopted by the regulatory texts—which changes the size of your homework considerably.

When it is, without question

Response generated by a language model, automatic intent classification, conversation summarisation, audio transcription, personalised recommendation, automatic lead qualification. If you use any of these components—and most modern WhatsApp operations use at least two—you are a deployer of an AI system. It's worth reading about what AI agents change for businesses before deciding on the design.

AI in the 2026 elections: the rules that already reach chatbots and avatars

While the UK doesn't have a specific AI election rule like Brazil's TSE resolution, the principles are similar. The UK's Online Safety Act and Electoral Commission guidance require transparency for political advertising, and the ICO has issued guidance on the use of AI in political campaigning. The key takeaway for UK businesses is that if your chatbot engages with the public during an election period, you must ensure it doesn't spread misinformation or impersonate candidates.

What the regulations require and prohibit:

  • Mandatory labelling. Any political content created or significantly altered by AI—text, audio, video, or image—must clearly state that AI was used, with specific placement rules per format.
  • Deepfakes prohibited. Synthetic content that creates, replaces, or alters a person's image or voice (living, deceased, or fictional) to harm or favour a candidacy is banned. Labelling doesn't legalise it.
  • AI cannot recommend candidates. Systems cannot rank, recommend, suggest, or prioritise candidates, campaigns, parties, federations, or coalitions—even when the user asks.
  • 72-hour blackout. In the 72 hours before an election and the 24 hours after voting, it is prohibited to publish AI content that uses the voice or image of candidates and public figures.
  • Fine. From £5,000 to £30,000 per piece, based on the Representation of the People Act 1983, plus removal of content and more serious electoral consequences.

Here the definition of AI matters twice: to know whether the content is synthetic and to know whether the system that distributes it is AI. For those running automated customer service, the message is direct—if your bot operates during an election year and someone asks who to vote for, it cannot answer. And if it talks to the voter, the voter needs to know they are talking to a machine. Reviewing the system prompt before September costs an hour and avoids a notification.

Transparency, logging, and UK GDPR: what changes for those already using AI

The three central obligations arise from the same definition of AI that the texts share, even if they appear with different words in each regulation.

Tell them it's AI. The patient needs to know (EU AI Act). The voter needs to know (Electoral Commission). The affected person has a right to explanation (UK GDPR). In practice, a line in the bot's first message resolves much of this: "Hello! I'm the virtual assistant of company X." It costs nothing and is worth a lot in a dispute.

Keep a trail. If you don't store what the model responded, you can't prove anything. Conversation log, model version, system prompt, and date. This isn't bureaucracy: it's the only defence available when someone claims the bot promised a discount that didn't exist.

Process data with a legal basis. A WhatsApp conversation with a customer is personal data. If it feeds a model, that's processing. The UK GDPR already applied before any AI framework and remains the floor, not the ceiling.

There's a fourth item, less cited and more expensive: human escalation channel. Every recent regulation keeps the relevant decision with a person. The doctor decides (EU AI Act). The voter cannot be induced (Electoral Commission). The affected person can contest (UK GDPR). A bot without a "talk to an agent" button is legal risk disguised as savings.

Those using the Official WhatsApp API already solve part of this through the channel itself, which logs messages and requires opt-in. If your operation still runs on the regular app, it's worth understanding the difference between the WhatsApp Business App and the Official API, because it's also a difference in auditability. And if automated volume has grown in recent months, the practices that prevent number blocking go hand in hand with transparency rules.

AI adoption in Brazil: 17% and what that number hides

The regulatory bar is arriving faster than adoption. The 16th edition of the TIC Empresas survey, by Cetic.br/NIC.br, released in June 2026 with data collected between February 2025 and January 2026, interviewed 4,174 Brazilian companies with 10 or more employees.

Segment 2024 2025
Companies using some AI 13% 17%
Large companies (250+ employees) 38% 50%
Small companies (10 to 49 employees) 10% 15%
Text mining / written language analysis 33% 38%
Natural language generation 20% 30%

Two sectoral segments stand out: accommodation and food jumped from 13% to 51% in text mining, and arts, culture, sport, and recreation went from 14% to 40%. These are intensive service sectors—exactly where chatbots enter first.

What the aggregate number hides is the distance between sizes. Half of large companies already operate AI; among small companies, which represent 87% of the surveyed population, it's 15%. In other words, most of the Brazilian market will encounter the definition of AI for the first time inside a contract, a tender, or a notification—not in a calmly planned project.

How we handle this in Agathas Web projects

Since 2008 I've built systems for clients in Brazil and abroad, and the most annoying part of any AI project is never the model—it's the perimeter. In the last two years, I've started treating four questions as mandatory before switching on any automation with a language model:

  1. Which decision does the system make on its own and which does it merely suggest?
  2. Does the end user know they are talking to a machine?
  3. Where is the log, in what format, and for how long?
  4. Who is the human on duty when the bot makes a mistake?

It's not conservatism. It's that the answers to these four questions are exactly the material the client will need to present if they are ever questioned—by the ICO, by a sectoral regulator, or by an angry consumer at the ombudsman.

In WhatsApp customer service projects, the standard architecture we use separates the deterministic flow (menu, protocol, hours, handover) from the inference layer (intent classification, summarisation, response drafting). This isn't technical pedantry: it's what allows us to answer precisely which parts of the system fall within the definition of AI and which don't. When the question comes from a lawyer, this separation is worth more than any model benchmark.

Conclusion: concept first, tool later

The definition of AI is not a decorative preamble to legal text—it's the switch that turns on or off an entire set of obligations on your operation.

Next practical step, and it takes less than an hour: list the automations running in your company today, mark which produce output that no one wrote before, and note where the log for each one is. That simple spreadsheet is the beginning of your AI inventory.

With the EU AI Act's high-risk obligations now in force, the ICO's guidance active, and the UK's AI Bill progressing through Parliament, those who already have the inventory ready will spend weeks less than those who start after the first notification. If you want to discuss the technical design of that separation in your customer service, it's the kind of conversation we have here every month.