The three terms get used as if they were interchangeable. They are not siblings — they nest inside one another, and knowing where a tool actually sits in that nesting tells you what it can and cannot do.
Key takeaways
“AI” covers any system built to do something that would otherwise require a person’s judgment — and that includes systems that never learn anything from data at all. A set of hand-written if/then rules, coded by a person and never updated by example, is still AI in the sense the term is used in risk-management guidance. The NIST framework’s own categorization step lists several distinct methods under one heading: it asks an organization to define the specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders) — treating classifiers, generative models and recommenders as different techniques living inside the same broad category, not as competing definitions of it.
This is the layer that trips people up most often precisely because it is the broadest: calling something “AI” says almost nothing about how it works internally. Two products can both be marketed as AI while one is a fixed decision tree a person wrote by hand five years ago and the other is a large language model retrained monthly — the label is true of both and useful for neither, on its own, as a way of judging what either one will actually do with a new kind of input.
Machine learning narrows that category to systems that learn a pattern from examples rather than having the pattern written into their code by a person. That distinction — trained versus programmed — is also why these systems carry a specific kind of risk that a hand-coded rules engine does not: the NIST framework warns that deployment of AI systems which are inaccurate, unreliable, or poorly generalized to data and settings beyond their training creates and increases negative AI risks and reduces trustworthiness. A rules engine cannot be poorly generalized to data beyond its training because it was never trained on data in the first place; a machine-learning system can be, precisely because its behaviour comes from what it was shown, not from what a person specified.
Deep learning narrows the category again, to machine-learning systems built from neural networks with many stacked layers, each layer transforming the output of the one before it into a more abstract representation. Stacking layers is what lets a system learn hierarchical features on its own — edges then shapes then objects in an image, for instance — instead of a person hand-engineering which features to look for. That capacity for depth is what made the current generation of large-scale generative systems practical; a shallow network, with only one or two layers, could not learn representations rich enough to produce fluent text or coherent images.
An older style of machine learning — a decision tree that sorts loan applications by a handful of numeric features, for instance — can be trained on data without any of this layering, and can still be genuinely useful and considerably easier to explain to a regulator or a customer than a deep network's internal representations, which is one reason not every machine-learning problem is best solved by reaching for the deepest available model.
Canada’s Cyber Centre draws the next line directly: generative AI is a type of AI that generates new content by modelling features from large datasets that were fed into the model. While traditional AI systems can recognize patterns or classify existing content, generative AI can create unique content in many forms, and it adds that a subset of generative AI that has seen significant improvement in recent years is large language models (LLMs). That single passage gives the full nesting in practice: artificial intelligence, narrowed to machine learning, narrowed to deep learning, narrowed to generative AI, narrowed again to large language models as one application of it — each a subset of the one before, not a different name for the same thing.
When a vendor says a product is “powered by AI,” the honest follow-up question is which layer is actually doing the work. A hand-coded rules engine is predictable but rigid and cannot handle a case its author did not anticipate. A trained classifier can handle new cases but can also drift as the world it was trained on changes. A large language model can produce fluent answers to questions it was never explicitly trained to answer — which is also exactly how it produces fluent wrong answers. The risks differ at each layer, so the label alone tells you almost nothing; predictive AI vs generative AI and generative AI vs agentic AI cover the next layers of distinction once you know which one you are actually being sold.
There is a practical shortcut for asking the question politely: ask what the system does when it encounters an input unlike anything in its training or its rule set. A rules engine will simply fail to match a rule and do nothing, predictably. A classifier will force the case into its nearest known category, sometimes wrongly, without necessarily flagging the low confidence. A large language model will very likely produce a fluent-sounding answer regardless, because producing fluent text is what it always does. That one answer tells you more about which layer you are dealing with than the marketing material usually will.
What businesses are actually planning to deploy bears this out. Among larger businesses planning to adopt AI, the most common intended application is not a large language model at all: nearly half (48.0%) plan to use it for data analytics, ahead of text analytics (32.0%) and virtual agents or chatbots (20.7%); among the smallest businesses planning to adopt AI, data analytics again leads, at 31.8% (Statistics Canada, Canadian Survey on Business Conditions, third quarter of 2025). The most common real-world purchase, in other words, sits at the narrower, older machine-learning layer of the nesting, not the generative layer the marketing conversation is usually about.
See also predictive AI vs generative AI and generative AI vs agentic AI.
Not quite. A neural network can be shallow, with only a layer or two, and shallow networks have been used successfully for decades on comparatively simple tasks. “Deep” specifically refers to having many stacked layers — every deep-learning system is a neural network, but not every neural network is deep.
Yes. A hand-coded decision tree or a fixed set of business rules is still commonly described as AI in risk-management terms, even though it never learns from data the way a machine-learning system does. Older expert systems built entirely from rules a specialist wrote down are the clearest historical example.
Both, more precisely: it is a deep-learning system, which is itself a machine-learning system, applied to the generative task of producing text. Asking “which one is it” is really asking which nesting level you want to describe, and the honest answer is all three at once, each one narrower than the last.
Once you know which layer a tool sits at, the next question is usually build-versus-buy for that layer. For that, see scoping a custom AI assistant, from idea to working prototype.