AI vs Automation
Automation follows rules people wrote; AI follows patterns a system learned from data. Neither is the better technology. They fail in different ways, need different checks and increasingly fall under different law, so the most useful systems combine both, with people owning the exceptions, starting from the simplest design that works.
After this chapter you can
- Distinguish automation, which executes rules people wrote, from AI, which applies patterns learned from data.
- Explain how a written rule and a learned model each fail, and why consistent output is not the same as correct output.
- Recognize where written rules are the better engineering choice and where AI earns its place, using evidence.
- Describe how the AI label changes which law applies, and why rules-only systems are still regulated as automated decisions.
- Design a workflow in which AI interprets, automation executes and people own the exceptions, starting from the simplest option.
Between 2015 and 2019, the Australian government sent debt notices to hundreds of thousands of people who had received welfare payments. The calculation behind them was simple. A computer took a person’s annual income, as reported to the tax office, spread it evenly across the year’s 26 fortnights, and compared the result with the income the person had reported to the welfare agency fortnight by fortnight. Where the two differed, the system assumed an overpayment and raised a debt. People with irregular work, which describes many people who move on and off welfare, were treated as if they had earned money in weeks when they had earned nothing.
In 2021 the Federal Court of Australia approved the settlement of the class action that followed. The government had admitted that it had no proper legal basis for debts calculated this way: at least 1.76 billion Australian dollars, asserted against about 433,000 people. The settlement was worth at least 1.8 billion, and the judge called the episode “a shameful chapter” in the administration of the social security system1. Two years later a Royal Commission described the scheme as “a crude and cruel mechanism, neither fair nor legal”2.
The scheme became known as Robodebt, and it is often remembered as an algorithm gone wrong. Yet nothing in it learned anything. It was a rule, written by people and applied by computer without a person checking each case. The first lesson is that “it is only automation” is not a statement about safety. The second is the one leaders need in order to choose well: a written rule and a learned model go wrong in different ways, so they need different designs, different checks and, increasingly, different law.
Written rules, learned patterns
What Exactly Is Artificial Intelligence? put inference at the heart of AI. That gives a clean way to separate the two ideas.
Automation is technology that runs a defined process with little or no manual work. Traditional automation follows instructions people wrote in advance: if this, do that. The system did not discover the rule. Someone defined it, and anyone with access can read it.
AI follows patterns it learned from data, and uses them to infer, predict, classify or generate. Nobody wrote its behavior line by line. The OECD’s definition turns on exactly this: an AI system infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions3. Modern machine learning gets there by fitting a model to large numbers of examples rather than by encoding knowledge by hand4.
So “which is better?” has no general answer. These are different tools for different jobs, and most useful enterprise systems combine both. What is worth managing is the origin of the behavior, because it determines how a system fails, how you check it and which rules apply to it.
Automation is often the better engineering choice
Automation deserves its due first, because the fashion for AI tends to undersell it.
Consider an approval rule in accounts payable. If an invoice is over 10,000 and the supplier is not on the approved list, it goes to the finance manager; everything else is paid on schedule. The same invoice gets the same treatment every time. Anyone can read the rule, predict its result and audit what it did last March.
Rules like this run much of the enterprise, from overdue reminders to leave balances. Economists describe such work as routine, not because it is unimportant but because it can be specified as explicit rules a computer follows5. When a process is stable, well understood and easy to write down, rules are cheaper to run, faster, easier to audit and easier to fix than a model. Replacing them with AI adds cost, delay and a new kind of risk for no gain.
Rules have one characteristic weakness. A rule knows only what its author foresaw. Cases nobody anticipated fall through it or, worse, are handled confidently and wrongly. And because a rule is applied identically every time, a wrong rule is wrong at scale. Robodebt’s averaging rule was not occasionally mistaken; it was mistaken in the same direction for everyone whose income varied. The remedy is the approach’s own strength. When a rule is wrong, you can find the line and change it, which is why the Royal Commission recommended that government business rules and algorithms be open to independent expert scrutiny2.
Where AI earns its place
AI becomes useful where the work involves patterns people recognize but cannot write down completely. The economist David Autor called this Polanyi’s paradox, after the philosopher Michael Polanyi’s observation that “we can know more than we can tell”6. For decades it marked the limit of computerization: if nobody could state the rule, no computer could follow it.
Try writing the complete rule for “this clause in a supplier contract is unusual”. You can start with payment terms beyond 90 days, uncapped liability and automatic renewal. Within an hour you have fifty conditions, and the next contract still surprises you. Experienced lawyers spot unusual clauses because they have read thousands. A model can learn something similar from many clauses that experts flagged and many they did not. That is a capability, not a result: whether a model beats your lawyers’ checklist has to be shown on your own contracts. The same property marks the tasks where AI earns its place: reading varied documents, classifying free-text requests, forecasting demand with many interacting drivers, spotting unusual patterns, summarizing and drafting.
Capability is not a result, though, and the burden of proof sits with the model. Public evidence from retail shows both sides. In the 2020 M5 forecasting competition, where teams predicted Walmart unit sales, the winning machine-learning method was 22.4 percent more accurate than the best statistical benchmark, yet only 7.5 percent of teams beat that benchmark at all7. Learned models can win where patterns are rich and data is good; most attempts, even by motivated specialists, do not. So treat the model as a challenger: the current method is the baseline, and the challenger has to beat it on your own data.
Written versus learned, not predictable versus random
The difference between automation and AI is often described as deterministic versus probabilistic, as if AI were a roll of the dice. That description is half right, and the wrong half leads to bad decisions.
A trained model given the same input often returns exactly the same output. A demand forecast or a credit score computed twice from the same data is usually identical. Generative assistants are usually set to vary their wording on purpose. Even with that variation switched off, language models served at scale can still drift, and researchers have shown that changing the serving software can remove the drift8. Variation is an engineering property that can be tuned, not the essence of AI.
The real difference is where the behavior came from, and therefore how it goes wrong. When a rule is wrong, there is a line to find and fix. When a model is wrong, there is no line. Its behavior is spread across what it learned, and it fails on cases unlike its examples, some of which look perfectly ordinary to a person. It can be just as consistent, and look just as certain, when it is wrong as when it is right. In the spring of 2020, pandemic buying broke models trained on a world that no longer existed9. They were not random. They were consistently, confidently wrong.
That is why AI needs what rules rarely need: testing on many real cases before launch, monitoring after it, a fallback for when the model is unsure or the world shifts, and, where errors are costly, a person who reviews the output. A rule is checked by reading it. A model is checked by testing it.
Where the law draws the line
The distinction is not only an engineering one. It increasingly decides which law applies.
The EU AI Act applies only to systems that meet its definition of an AI system, which centers on inference. Its recitals exclude systems based solely on rules defined by people to execute operations automatically10. The European Commission’s February 2025 guidelines name four kinds of system that fall outside the definition: basic data processing that follows explicit instructions, classical heuristics, simple prediction systems such as forecasting tomorrow’s temperature from last week’s average, and certain systems for mathematical optimization11. A well-written rules engine is, in principle, outside the Act.
Outside the Act is not outside the law. The GDPR’s right not to be subject to solely automated decisions applies whatever technology makes the decision12, and California’s new rules are framed around automated decision-making technology, not AI13. Robodebt, which contained no AI at all, ended with the government admitting it had no proper legal basis for the debts. The label changes which rulebook applies, not whether one does.
AI interprets, automation executes, people handle exceptions
Put the two together and a pattern appears that runs through a great many enterprise systems.
Rules work well on structured fields such as an amount or a status. They struggle with emails, PDFs, scanned forms, contracts and call recordings. Take supplier invoices. If every supplier used one format, automation alone would do. They do not.
AI reads each invoice, works out its layout, extracts the line items and hands over structured data. Automation validates, posts and routes for payment, using the same rules as before, including the approval rule above. When the AI flags something unusual, such as a price far from the contract or a likely duplicate, or when it is not confident in what it read, the case goes to a person who owns the decision.
Three practical points follow. The model’s output should feed the automation, not replace it; the rules that already work keep working. The hand-offs between the parts are where such systems most often break, so each needs an owner. And the human role has to be designed, not assumed: people asked to approve everything soon stop examining anything, a risk Operational and Workforce Risk takes up in Module 06. The same pattern holds for agents, which still act through tools, interfaces and deterministic systems; From AI Assistants to AI Agents covers them later in this module.
Two questions point to the simplest design
None of this means AI should replace every rule. Choosing AI for fashion adds cost, complexity, delay, risk and maintenance. A better habit is to start from the simplest design that solves the problem and ask two questions of each step. Can the complete rule be written? And what does an error cost, especially if the output triggers an action without a check?
Together the questions give four answers. Where the rule can be written and errors are cheap, use rules alone: overdue reminders, leave balances, nightly reports. Where the rule can be written but errors are costly, keep the rule and add a sign-off, as with large payments. Where no complete rule exists and errors are cheap, let AI act and monitor the results, as with routing routine requests. Where there is no rule and errors are costly, AI drafts and a person decides, as with an unusual clause in a major contract. Even where AI earns its place, the answer is usually AI plus automation, not AI alone.
Story: two proposals to fix empty shelves
The case below is a composite, built from patterns documented in forecasting research rather than from one named company. The decision in it is one that many consumer-goods makers face. Read the setup and decide before you read on.
A consumer-goods maker sells household and personal-care products through thousands of stores. Its replenishment runs on rules written years ago: when a store’s stock falls below two weeks of average sales, order more. The rules are cheap, fast and understood by everyone. But they break around promotions, launches and seasonal peaks. Shelves run empty in the first week of a big promotion, and launch quantities are educated guesses.
Two proposals reach the operations director in the same week. The data-science team wants an AI forecast for every product, placing orders directly, with the old rules retired. The planning team wants to keep the rules and add new ones for promotions, such as doubling the usual order whenever a product is on promotion. Which would you fund?
Both are reasonable, and both are wrong in an instructive way. Proposal A puts a model where a one-line rule already works and removes every check on its orders. Proposal B tries to write a rule that cannot be written: promotional demand depends on price, display, season and what competitors are doing, all at once. That is exactly the kind of setting in which learned models have beaten simple methods.
The director funded neither. She asked the two teams to map one workflow together, product by product. For everyday products with steady demand, the old rule was already good enough and every store manager could explain it, so it stayed. For promotions, launches and seasonal items, a model learned demand from years of sales and promotion history. Its forecasts did not place orders on their own. They fed the same ordering automation as before, within limits. Inside the limits, orders went out automatically. Outside them, a planner approved.
The planners’ role was designed too. Research on tens of thousands of supply-chain forecasts found that small manual adjustments often made accuracy worse14. So planners were asked to override only when they knew something the model could not, such as a competitor’s promotion, and to record why.
The redesign avoided two common mistakes: treating everything as an AI problem, as proposal A did, and running AI and automation as separate projects, one team per technology, which is how two incompatible proposals arrived on one desk in the same week.
What this means for leaders
The habit to build is to decide, step by step, what should follow a written rule, what should follow a learned pattern and what should stay with a person. Three disciplines keep it honest. Label honestly: calling a rules engine AI inflates business cases, and, as What Exactly Is Artificial Intelligence? showed, regulators treat false AI claims as misrepresentation, while calling a model “just automation” skips the testing it needs. Keep the burden of proof on the model: working rules are the baseline, and a model earns its place by beating them on your own data. And design the seams: the hand-offs between model, automation and people are where these systems succeed or fail, and each belongs to a named owner.
Check yourself
- Automation is older technology that AI will replace.
- A trained model can give the same answer every time and still be wrong.
- A system that contains no AI cannot do serious harm at scale.
- A model that beats a simple baseline in one competition will beat your current rules too.
- A purely rules-based system can still fall under laws on automated decisions.
- If a workflow contains one AI step, the whole workflow is AI.
Reflection: sort one workflow
What comes next
Automation follows written rules, and AI follows learned patterns. But AI is not one thing either. It contains several major approaches, and the one behind most of today’s systems has a name of its own. The next chapter, AI vs Machine Learning, explains how machine learning differs from AI and where it fits inside the larger picture.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
General Data Protection Regulation · EU
Regulation (EU) 2016/679
Personal data is any information relating to an identified or identifiable person, directly or indirectly, including by an identifier such as an online ID (Art. 4(1)). Lawful basis and purpose limitation (Arts. 5-6); processing special-category data, including biometric data used to identify a person, health data and data revealing ethnicity, is prohibited unless a specific exception applies (Art. 9); data protection by design and by default (Art. 25); processors such as AI vendors may act only under a written contract with required terms and sufficient guarantees (Art. 28); transparency to data subjects (Arts. 13-14); right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (Art. 22); breach notification to the supervisory authority within 72 hours (Art. 33) and to individuals without undue delay when the risk is high (Art. 34); data protection impact assessment for high-risk processing (Art. 35). Fines up to EUR 20 million or 4% of global turnover.
- 2018-05-25 — Applies
Last verified 2026-10-08 · official text
California privacy rules on automated decisions (CCPA regulations) · US - California
California Consumer Privacy Act; CPPA regulations on ADMT, risk assessments and cybersecurity audits (approved by OAL Sept 2025)
The most concrete US privacy rule on AI. Businesses that use automated decision-making technology to make a significant decision about a California resident (finance or lending, housing, education, employment or pay, healthcare) must give notice before use, offer an opt-out unless an exception applies, and answer access requests. Processing that poses significant privacy risk needs a documented risk assessment. There is no comprehensive federal privacy statute; about 20 states have their own laws, and California's is the reference point.
- 2026-01-01 — Updated CCPA regulations take effect; risk-assessment duty applies to new high-risk processing
- 2027-01-01 — ADMT duties for significant decisions: pre-use notice, opt-out (with exceptions) and access (some firm alerts cite enforcement from 1 Apr 2027)
- 2028-04-01 — Attestation of 2026-2027 risk assessments due to the CPPA; cybersecurity audits phase in 2028-2030 by revenue
Last verified 2026-10-06
References
- Federal Court of Australia. Prygodicz v Commonwealth of Australia (No 2) [2021] FCA 634. Federal Court of Australia (Justice Bernard Murphy). 2021.
- Royal Commission into the Robodebt Scheme. Report of the Royal Commission into the Robodebt Scheme. Commonwealth of Australia. 2023.
- OECD. Recommendation of the Council on Artificial Intelligence (OECD AI Principles), updated 2024. OECD. 2024.
- Ian Goodfellow, Yoshua Bengio and Aaron Courville. Deep Learning. MIT Press. 2016.
- David H. Autor, Frank Levy and Richard J. Murnane. The Skill Content of Recent Technological Change: An Empirical Exploration. The Quarterly Journal of Economics 118(4). 2003.
- David H. Autor. Polanyi's Paradox and the Shape of Employment Growth (NBER Working Paper 20485). National Bureau of Economic Research. 2014.
- Spyros Makridakis, Evangelos Spiliotis and Vassilios Assimakopoulos. M5 accuracy competition: Results, findings, and conclusions. International Journal of Forecasting 38(4), 1346-1364. 2022.
- Horace He and Thinking Machines Lab. Defeating Nondeterminism in LLM Inference. Thinking Machines Lab: Connectionism. 2025.
- Will Douglas Heaven. Our weird behavior during the pandemic is messing with AI models. MIT Technology Review. 2020.
- European Parliament and Council of the European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 3(1) and Recital 12. Official Journal of the European Union. 2024.
- European Commission. Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689. European Commission. 2025.
- European Parliament and Council of the European Union. Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union. 2016.
- White & Case. CPPA finalizes rules on ADMT, risk assessments, and cybersecurity audits requirements under the CCPA. White & Case LLP. 2025.
- Robert Fildes, Paul Goodwin, Michael Lawrence and Konstantinos Nikolopoulos. Effective forecasting and judgmental adjustments: an empirical evaluation and strategies for improvement in supply-chain planning. International Journal of Forecasting 25(1), 3-23. 2009.
Further reading
- David H. Autor. Polanyi's Paradox and the Shape of Employment Growth (NBER Working Paper 20485). National Bureau of Economic Research. 2014.
- Spyros Makridakis, Evangelos Spiliotis and Vassilios Assimakopoulos. M5 accuracy competition: Results, findings, and conclusions. International Journal of Forecasting 38(4), 1346-1364. 2022.
- Royal Commission into the Robodebt Scheme. Report of the Royal Commission into the Robodebt Scheme. Commonwealth of Australia. 2023.
Sources last verified 2026-10-08.