Most of the time a company says "we're using AI", it's actually referring to very different things, with risk levels and governance needs that have nothing to do with each other. This isn't a technical-vocabulary problem — it's a practical one, because usage policy, the level of oversight required, and AI Act obligations all depend on what type of AI is actually being used. This glossary covers the four pairs of terms that generate the most confusion — and the most poorly made decisions — in practice.

Office AI vs. analytical AI

Office AI helps a person with an individual task, inside tools they already use: drafting an email, summarizing a document, generating a slide deck, or reviewing a piece of text. Its scope is one person's productivity at a specific moment, and the output is normally reviewed by that same person before it's used. A typical example is an assistant built into email or a word processor that suggests a draft or summarizes a long thread.

Analytical AI is different: it's applied to business data to generate an output that feeds a decision, often without a person reviewing every individual case. A credit-scoring model, a demand forecast that drives stock purchasing, or a price-recommendation system are all examples of analytical AI. The confusion between the two matters because the level of risk, governance, and oversight each one needs is very different — a solid policy for office AI use doesn't come close to covering what a scoring model that decides on real customers actually needs.

Agent vs. chatbot

A chatbot responds within a conversation: it receives a question and generates an answer, without taking any action of its own outside that exchange. An AI agent goes further — it executes multi-step actions autonomously, with its own tools and permissions, and can query systems, modify data, or start processes without a person approving every step. That autonomy is exactly what calls for a different kind of governance, with permissions, auditing, and escalation clearly defined — we cover that in full in agentic AI governance.

Generative AI vs. predictive AI

Generative AI creates new content that didn't previously exist: text, images, code, or audio, from a prompt or instruction. Predictive AI does the opposite: it doesn't create anything new — it estimates a value or a classification from historical data, such as a risk score, a demand forecast, or the likelihood a customer will churn. A chatbot that drafts replies is generative; a model that calculates a customer's probability of default is predictive.

What matters from a governance standpoint is that both can be high-risk AI systems under the AI Act, and what determines the risk level isn't the type of model (generative or predictive) but the use it's put to. A predictive model used to decide on hiring or credit access can be high-risk; the same type of model used to forecast a warehouse's electricity consumption isn't.

"AI model" vs. "AI system"

It's common to use "AI model" and "AI system" as synonyms, but the AI Act distinguishes between the two, and that distinction is what determines what actually gets regulated. Article 3(1) of Regulation (EU) 2024/1689 defines an AI system as "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments".

The key idea for a company is this: the AI Act doesn't regulate the model in the abstract (a generic language model, for instance) — it regulates the system as deployed for a specific purpose, meaning the model plus its integration, its use case, and its deployment context. That means the same model can be low-risk in one use (an internal drafting assistant) and high-risk in another (that same model integrated into a hiring-selection system). You can't classify the risk of "a model" without first knowing which system, and for what purpose, it's actually being used in — see how to classify AI systems by risk.

The most common mistake: using "agent" to describe any AI-based automation, including a simple chatbot or a rules-based flow with a model behind it. That creates expectations of autonomy — and of risk — that a tool which only responds within a conversation doesn't have, and it can lead to over-governing what's simple or, worse, under-governing what actually takes action on its own.

Summary: the 4 term pairs

TermsThe difference in one line
Office AI vs. analytical AIHelps a person with a task vs. generates an output that feeds a business decision
Agent vs. chatbotExecutes multi-step actions with its own permissions vs. responds within a conversation
Generative AI vs. predictive AICreates new content vs. estimates a value or classification from historical data
AI model vs. AI systemThe model in the abstract vs. the model deployed for a specific purpose — what the AI Act regulates
Acceptable AI Use Policy If your company uses several of these types of AI without a clear policy of what's allowed and what isn't, this template covers all 4 cases from this glossary in a single document. €9.99 VAT incl.
Buy →

If you're not sure which AI Act risk tier a specific system in your company falls under, the next step is to classify AI systems by risk — that classification is what determines which obligations apply, not what you happen to call the system.