What is AI Agent?
Definition
An AI agent is a software system that uses a language model as its decision-maker to pursue a goal: it plans steps, calls tools such as search, APIs, code execution or file operations, evaluates the results and chooses what to do next. Unlike a single question-and-answer exchange, it carries out a task over multiple steps while interacting with external systems. Reliable agents depend on permission limits, human approval and logging.
Also known as: LLM agent, agentic AI, autonomous agent, AI assistant agent, agentic system

The loop at the centre
Strip away the branding and an agent is a loop. The model reads the goal and everything that has happened so far, picks the next action, the application carries it out, the result goes back to the model, and the cycle repeats until the goal is met or a limit is hit:
steps = 0
while steps < MAX_STEPS:
action = model.decide(goal, history, tools)
if action.kind == "final_answer":
break
if action.irreversible and not user_approves(action):
history.append("User declined this action")
continue
result = run_tool(action) # permission check happens here
history.append(result)
steps += 1The model's only job in that loop is choosing the next step. Executing the tool, checking permissions, enforcing the step limit and asking for approval are always the application's responsibility.
Building blocks
- A model that follows instructions and can emit structured tool calls.
- Tools, the operations the model may request, defined through function calling. Protocols such as the Model Context Protocol let tools from different systems be offered in a standard way.
- Context and memory: the goal, prior steps, intermediate results and, where needed, persistent notes. Deciding what goes into the model's context, and in what order, is the subject of context engineering.
- Planning: breaking the task into sub-steps and revising the plan when a result isn't what was expected.
- Guardrails: permission boundaries, approval checkpoints, budget and step limits, logs.
Guardrails are the design, not an add-on
An agent can only do as much damage as its permissions allow, so the first rule is the principle of least privilege. An agent that only needs to look up order status should not hold an API key that can issue refunds.
- Human approval for irreversible actions: payments, deletions, sending email, publishing.
- Untrusted input: a web page, email or document the agent reads may contain text written to give the model new instructions. That risk is known as prompt injection; tool results should be handled as data, never as commands.
- Limits: maximum steps, total cost and wall-clock time. An agent stuck in a loop hurts both your bill and the systems it calls.
- Traceability: log every tool call with its arguments and result. It's the only way to reconstruct what happened when something goes wrong.
- Isolation: agents that run code belong in a sandbox, separated from production systems.
Not every automation needs an agent
If the steps are known in advance (“when a form arrives, create a CRM record and notify sales”), conventional automation does it cheaper, faster and more predictably. Agents earn their keep where the required steps can't be known up front: investigating a vague problem, gathering information from several sources, debugging a codebase.
“Agent” is also a stretchy marketing word, applied to everything from chatbots to fixed workflows. When evaluating a product, ask concrete questions: which tools can the model call, with what permissions, which steps need human sign-off, and where are the logs when something fails?

