Short answer

An AI agent is a language model given a goal, a set of tools and permission to take several steps on its own. It decides what to do next, calls a tool, reads the result and repeats until the goal is met or it needs a person. A chatbot answers one message at a time. A workflow automation follows fixed steps someone wrote in advance.

How is an AI agent different from a chatbot or a workflow automation?

The difference is who decides the next step. A chatbot waits for a person. An automation follows a path someone drew. An agent chooses its own path toward a goal, within the tools it has been given.

ChatbotWorkflow automationAI agent
Who decides the next stepThe person, one message at a timeThe rules someone wrote in advanceThe model, toward a stated goal
Takes actions in other systemsUsually notYes, the ones in the flowYes, through the tools it is given
Handles unexpected inputAnswers it, does nothing with itBreaks or skips itAdapts, sometimes wrongly
PredictabilityHigh per replyHighestLowest of the three
Best forQuestions, drafting, one-off analysisThe same steps every timeMulti-step work that needs judgment between steps
Main riskConfident wrong answersSilent failure when inputs changeWrong actions taken at speed

The three often sit together. A form submission triggers an automation, the automation hands one messy step to an agent, and a person reviews the result in a chat window.

What does an agent actually do, step by step?

An agent runs a loop: it holds a goal, chooses a tool, looks at what came back and decides whether to continue, change course or stop. Everything else is detail about that loop.

  1. Goal. A task stated in words, with a definition of done. "Match each new founder to two advisors and propose the pairs for review" is a goal. "Help with matching" is not.
  2. Tools. The specific actions it may take: read a form, search a list, draft a message. Tools are usually exposed through an MCP server or through the model API's function calling.
  3. Observe. It reads each result, including errors and empty results, and adds them to what it knows.
  4. Decide. It picks the next action, asks a person, or reports that it is finished.

The quality of an agent is mostly the quality of those four inputs. A clear goal, narrow tools and honest error messages do more than a cleverer model.

How much autonomy should an agent have?

Only as much as the cost of its worst mistake allows. Most useful business agents sit at the second or third level below, not the fourth.

  1. Suggest. The agent researches and recommends. A person does everything.
  2. Draft for approval. The agent prepares the email, the invoice or the match list. A person approves before anything leaves.
  3. Act within limits. The agent takes low-risk actions on its own, such as updating a status or logging a check-in, and reports what it did.
  4. Run unattended. The agent works on a schedule with nobody watching, and people read the results afterward.

Autonomy can differ by action inside one agent. Reading is usually safe at level four. Sending, paying and granting access usually belong at level two.

Where do AI agents fail?

Agents fail in predictable ways, and most of them come from the setup rather than the model.

  • A vague goal. Without a definition of done, the agent stops early or keeps going.
  • Tools that are too broad. One tool that can "update any record" invites the wrong update. Small tools with typed inputs are easier to control and test.
  • Instructions hidden in content. An email or document the agent reads can tell it to do something else. This is prompt injection, and the fix is to make dangerous actions unavailable or approval-gated, not to hope the model ignores the text.
  • Compounding errors. A small misreading in step two becomes a confident wrong result in step eight.
  • Silent success. A tool that returns "done" when it did nothing looks the same as one that worked. Results need enough detail to check.
  • Loops and cost. An agent retrying a failing call runs up usage. Set step limits and timeouts.
  • Stale or missing data. The agent cannot know what its sources do not hold, so it should say what it could not find.

Where should a person stay in the loop?

Put a person at every point where a mistake would be expensive, external or hard to undo. Everywhere else, let the agent move and review a sample.

  • Before anything is sent to a customer, vendor or regulator.
  • Before money moves or a price is committed.
  • Before access is granted or a record is deleted.
  • When the agent flags low confidence or an input it has not seen before.
  • On a schedule, reading a sample of finished work to catch drift.

Write these checkpoints into the tools themselves. A draft-only email tool is a stronger guarantee than an instruction that says "always ask first".

Are personal AI agents like Meta Muse the same thing?

They are the consumer version of the same idea: a model with tools, working toward a goal, but acting in one person's own accounts rather than a company's systems.

Two examples from this month's news. Meta launched Muse in the US on September 8, 2026, as a personal agent that works across a person's email, calendar, payments and shopping. Instinct, an invite-only agent that can text, call and act across a user's apps, raised a $250 million Series B in late August 2026. Expect staff to arrive with one.

For a business the questions are the ones on this page, with a twist: the agent holds an employee's personal credentials, and it may touch company email or calendars you do not control. What to allow, and what to write into policy, is covered in personal AI agents for business.

What do AI agents look like in a real business?

In practice they are narrow, and the good ones are built around a step that used to need a person's judgment. A few from altr's own work, described in full on each case study:

  • A reviewing agent in production. For Fishin Prints, an agent reviews each customer's catch photo and writes the production brief an artist would have written, then a fixed automation carries the order through generation, human review and export (case study).
  • A scheduled agent with review. For spARK Labs' AIR Supply program, a Claude skill scores founder and advisor pairings and proposes them for the team to confirm, and a second skill runs monthly on its own to send check-ins and log them (case study).
  • Tools with limits built in. The spARK Labs MCP server lets Claude provision building access behind a dry run flag and creates Outlook drafts rather than sending (case study).
  • Stopping at a draft on purpose. Our own invoicing drafts a Stripe invoice from one sentence and cannot finalize or send it (case study).

The pattern is consistent: map the work first, let the agent carry the judgment step, keep fixed steps fixed and keep a person on the outbound side. How we build agents covers the engineering.

Working rule

If you can draw every step of the process in advance, build an automation. If one step needs judgment each time, that step is where an agent belongs, and only that step.

Common questions

Is ChatGPT or Claude an AI agent?

On its own in a chat window, it behaves as an assistant that answers one message at a time. It becomes an agent when it is given a goal, tools it can call and permission to take several steps without a person prompting each one, which both products now support in some modes.

Do AI agents replace employees?

In most small and mid-sized businesses, agents take over steps inside a job rather than the job. The person still owns the outcome, handles exceptions and approves anything consequential. The time that frees up is the usual return.

What is the difference between an AI agent and RPA?

Robotic process automation repeats exact clicks and keystrokes a person recorded, and breaks when the screen or input changes. An AI agent reads the situation and chooses its next action, which handles variety better and is less predictable.

How do you stop an AI agent from doing something wrong?

Limit what its tools can do, require approval before external or irreversible actions, log every tool call, set step and time limits, and review a sample of finished work. Controls built into the tools are stronger than instructions in the prompt.

What is an AI agent for a business?

For a business, an AI agent is software that uses a language model to carry a task forward on its own: it reads the input, calls tools such as your CRM, inbox or accounting system, checks what came back and decides the next step, stopping for a person where your rules say it must.

Should a small business build an AI agent first?

Usually not. Start by doing the task by hand with an AI assistant until the steps and the review points are clear. Build an agent only when a repeated step still needs judgment and the rest of the process is already well defined.

Related reading