Skip to content
Getting Digital

Agentic AI

Also: AI agents, autonomous agents, agent systems

Agentic AI is software that wraps a language model in a loop where it can request actions from real tools, read what each action returns, and choose the next move until the job is finished or a rule stops it.

Assessment. The autonomy is the marketing; the tool layer is the product. An agent is judged by what its tools return when they fail, because a system that cannot tell an empty result from a broken connection will report success on work it never did.

The loop, the tools, and the moment one breaks

Agentic AI is what you get when a language model is given a way to act rather than only to answer. A runtime hands the model a catalogue of permitted actions: run this query, fetch that page, write a file, call an internal service. The model replies with a request to use one of them. The runtime, not the model, carries the action out and feeds the result back in. Then the cycle repeats. Notice what the model itself never touches. It opens no connection, holds no credential and sees no file system; it emits structured text naming a tool and its arguments, and ordinary code decides whether to honour that request. Everything a demo presents as planning or initiative is that cycle running several times, with each result shaping the next request. Which is why the engineering that decides whether an agent works sits outside the model entirely.

  • The tool surface is the real design work. Every action needs a name, an argument list and a description precise enough that a model under pressure picks the right one.
  • Return values matter more than prompts. A tool that answers an impossible request with a blank string has just taught the model that the request succeeded.
  • Permissions and budgets set the size of the accident. Reading a production database and writing to it are different products with different approval paths.
  • Stop conditions have to be explicit: a cap on steps, a cap on spend, and a rule for what a repeated identical action means.
  • Traces, meaning a readable record of every call and everything it returned, are the only way to debug a run. Without them you are reading tea leaves.

Failure is where this category earns or loses its money. One wrong answer from a chat assistant costs the reader a minute; one wrong step inside a loop becomes the input to the step after it. The model has no way to distinguish a tool that returned nothing because the correct answer is nothing from a tool that returned nothing because a credential expired overnight. So the useful work is defensive and dull. Make every tool describe its own failures in words the model can act on. Require a human signature for anything destructive. Halt the run when the same call repeats. Log enough that somebody can reconstruct afterwards what happened and why. Do that and agents pay off on bounded work with a verifiable result, where a person can look at the output and say whether it is right. Skip it, or apply agents to open-ended work with no such check, and what you have built is an expensive generator of plausible activity.

In practice

Take a monthly supplier reconciliation: match every invoice received against the purchase ledger and hand a human the discrepancies. The agent gets three tools, one to list and read invoice documents, one to query the ledger, one to append rows to a report. It works beautifully while every invoice is a clean digital document.

Then a supplier photographs a paper invoice. The document tool returns a blank string instead of an error, the model reads blank as nothing to reconcile, and the report comes back clean with that invoice silently missing from it. No wording in the prompt caused this and no rewriting of the prompt will cure it. The repair lives in the tool layer: return an explicit unreadable-document result carrying the file name, give the model a way to push an item into a human queue, and refuse to emit a final report while anything remains unresolved. That is the whole discipline in one worked case.

Often confused with

Generative AI
Generative AI names what the model produces. Agentic AI names the scaffolding that lets that production change something outside the chat window.
Prompt Engineering
Prompting shapes a single call. An agent is many calls plus the code deciding what happens between them, and most of its behaviour comes from that code.
Retrieval-Augmented Generation
Retrieval is a read: it pulls context in before an answer is written. An agent reads and also writes, which is the moment permissions and rollback start to matter.

Key takeaways

  • →An agent is a model, a set of tools and a loop. The model only ever asks; ordinary code decides whether the action happens.
  • →Tool return values, not prompt wording, govern how an agent behaves when something goes wrong.
  • →Scope agents to work whose output somebody can verify. With no check in place, autonomy produces activity rather than results.

Related concepts

Courses that teach this

Where this concept sits in the field

Certifications that test this

Vendor exams whose syllabus covers this concept: facts, cost and a preparation path on each page.

FAQ

What makes something an agent rather than a chatbot with plugins?
Nothing crisp, and the vocabulary is not worth defending. A workable line: if the system decides how many steps to take and can act on the outcome of its own last action, calling it an agent is fair. If a person presses a button before every action, it is a chat interface with attachments.
Do I need an agent framework to start?
No. The core cycle is a model call, a tool call and a state update, which is a short piece of code you should write once yourself so you know what a framework is hiding. Libraries start to pay for themselves when you have many tools, persistent state across sessions, or a team that needs shared observability.
Why do agents get stuck repeating the same step?
Because a failed action tends to return the same unhelpful result every time, and nothing in a naive loop treats repetition as evidence. Counting identical calls and halting on a repeat is a few lines of code that prevents most runaway bills.

Sources

The primary text this definition rests on. Read it before relying on this one.

Last reviewed 26 September 2026 · Getting Digital