Technology

What is an AI agent?

"AI agent" is one of the most overused labels in tech. Here is what it actually means, how agents use tools, where they go wrong, and how to judge a company's agent claims.

Illustrative cover: What is an AI agent?
Illustration: Pointales

An AI agent is a system in which an AI model works towards a goal by deciding, step by step, which tools to use and what to do next, rather than just replying once to a message. A chatbot answers your question. An agent might search the web, open a spreadsheet, run some code, check the result and try again, until it judges the task done. Four parts make it an agent: a model, a set of tools, a loop, and a goal.

If you are new to how the underlying models work, start with our guide to how large language models work.

A working definition

The clearest definitions come from the companies building these systems. In a December 2024 engineering guide, Anthropic separates two kinds of system:

  • Workflows: “systems where LLMs and tools are orchestrated through predefined code paths”. The developer decides the steps; the model fills them in.
  • Agents: “systems where LLMs dynamically direct their own processes and tool usage, maintaining control over how they accomplish tasks”.

The difference is who decides the next step. In a workflow, a programmer does. In an agent, the model does. Many products marketed as “agents” are really workflows, which is not a bad thing; workflows are often more predictable.

How tool use actually works

A language model on its own only produces text. It cannot click, send or look anything up. Tools are how it reaches outside.

Anthropic’s developer documentation describes the mechanism, also known in the industry as “function calling”:

  1. The developer gives the model a list of tools, each with a name, a description and the inputs it needs (for example, “get_weather: needs a location”).
  2. When a request matches a tool, the model does not run it. It replies with a structured request: “call get_weather with location = Pune”.
  3. The developer’s software actually runs the tool and sends the result back to the model.
  4. The model reads the result and either answers, or asks for another tool.

An agent is this cycle repeated: the model keeps choosing tools and reading results until it decides the goal is met, hits a limit, or hands back to a person.

This detail matters. The model only ever proposes actions; the surrounding software decides whether to carry them out. That is where safety controls belong.

What agents are used for

Described generically, typical agent tasks include:

  • Research: search several sources, read the pages, and compile a summary with links.
  • Software work: read a codebase, make a change, run the tests, and fix what fails.
  • Data tasks: pull figures from files, run calculations, and produce a report.
  • Operations: triage a support queue, draft replies and route difficult cases to a person.

Anthropic’s guide suggests agents fit “open-ended problems where it’s difficult or impossible to predict the required number of steps”. For tasks with fixed, known steps, a simpler workflow is usually cheaper and more reliable.

Chatbot vs agent

ChatbotAI agent
What it doesReplies to a messagePursues a goal over many steps
Who decides the stepsYou, one message at a timeThe model, within limits set by developers
ToolsNone, or one or two (such as web search)Several, chosen as needed
Can it take actions?Generally noYes, if given tools that act (send, edit, buy, run code)
Typical failureA wrong answer you can read and rejectA wrong action, possibly repeated across steps
Cost per taskLowHigher: many model calls per task

The risks

Errors compound. Anthropic’s guide states it directly: “The autonomous nature of agents means higher costs, and the potential for compounding errors.” A small mistake early, such as misreading a figure, feeds into every later step. And because agents are built on language models, they inherit those models’ tendency to state wrong things confidently; see why AI chatbots “hallucinate”.

Too much power. The OWASP Top 10 for LLM Applications (2025), a widely used security checklist, lists Excessive Agency (LLM06) as a core risk. It names three root causes: excessive functionality, excessive permissions and excessive autonomy. An agent that only needs to read your email should not be able to delete or send it.

Prompt injection. OWASP ranks Prompt Injection (LLM01) first. For agents, the dangerous form is indirect injection: instructions hidden inside a web page, email or file that the agent reads while working. The model can mistake that text for a command. NIST’s AI standards centre calls this “agent hijacking”, defined as an attack in which malicious instructions are inserted “into data that may be ingested by an AI agent, causing it to take unintended, harmful actions”. In NIST’s own tests, published in January 2025, new attacks designed by its red team raised the success rate against one tested model from 11% to 81%. OWASP notes that common techniques such as retrieval and fine-tuning “do not fully mitigate” prompt injection.

Cost and runaway loops. Every step is another paid model call. OWASP also lists Unbounded Consumption (LLM10) as a risk.

OWASP’s recommended defences are practical: give the agent the minimum tools and permissions it needs, run actions with the user’s own access rather than broad system access, and require human approval for high-impact actions. Anthropic similarly recommends “extensive testing in sandboxed environments, along with the appropriate guardrails”.

How to judge an “agent” claim

When a vendor, startup or colleague says their product is an AI agent, these questions cut through the marketing:

  1. Who decides the steps? If the sequence is fixed in code, it is a workflow. That may be fine, but call it what it is.
  2. What tools can it use, and what can those tools change? Reading data is low-risk; sending money, emails or code to production is not.
  3. Where does a human approve? Ask which actions need sign-off before they happen.
  4. What happens when it fails? Look for step limits, logs of every action, and an easy way to undo.
  5. How is it protected against prompt injection? A vague answer is a red flag, given OWASP ranks it the top risk.
  6. What does a task cost? Many-step agents can cost far more than a single chatbot reply.
  7. Was it tested on tasks like yours? Demos are chosen to succeed; ask for results on realistic cases.

The point: An AI agent is a language model given tools and allowed to choose its own next step in a loop until a goal is met. That makes it useful for open-ended, multi-step work, but errors, permissions and hidden instructions in the data it reads become real risks. Judge any agent by what it can touch, where a human signs off, and what happens when it gets things wrong.

Sources