Get started
AI agentsAI agentsAgentic AIGovernance

What is an AI agent?

Adam Cowles2026-10-05T13:00:00.000Z5 min read
A single bright node reaching out to act on a grid of tools and systems, cyan and violet over near-black

A chatbot answers you. An agent goes and does the thing. The gap between those two sentences is the whole subject.

An AI agent is software that pursues a goal by taking actions, not just by producing text. You give it an objective, and it reasons about what to do, calls tools to do it, reads what happened, and keeps going until the job is done or it gets stuck. A language model is the part that thinks. An agent is the model wired to hands: the tools, the memory, and the loop that lets it act in the world rather than only describe it.

That is the line that matters. Ask a chatbot to "sort out the failed payment on order 4192" and you get a well-written explanation of how you might sort it out. Ask an agent the same thing and it looks up the order, checks the payment processor, retries the charge or issues the refund, updates the record, and tells you what it did. Same request, completely different thing on the other end.

What makes it an agent

Three capabilities turn a model into an agent. Take any one away and you have something simpler.

  • It acts through tools. The agent can call out to the real world: an API, a database, a shell, a browser, another service. Tools are how thought becomes effect. A model with no tools can only talk.
  • It carries state. It remembers what it was asked, what it has already tried, and what each step returned, so a multi-step task stays coherent instead of resetting every turn.
  • It runs a loop. It decides the next action, takes it, observes the result, and decides again, repeating until the goal is met or a limit is hit. The loop is what makes it autonomous rather than a single call.

Put plainly: a chatbot is a model you talk to; an agent is a model you delegate to. The delegation is the point, and it is also where the risk moves.

Agent, assistant, automation: where the lines actually fall

The words get used loosely, so it helps to be precise about the spectrum.

A plain workflow or automation follows a fixed script: when X happens, do Y. It is predictable and it does not decide anything. An assistant answers and drafts but waits for you to act on its output. An agent chooses its own steps toward a goal and takes them. A multi-agent system is several agents, often with an orchestrator, splitting a larger job between them.

Most real deployments sit somewhere in the middle: an agent that can act freely on low-risk steps and has to stop and ask a human before anything that spends money, touches customer data, or cannot be undone. That pause is not a weakness in the design. On any system that matters, it is the design.

A worked example

Say the goal is "chase the three overdue invoices from last month." A workflow would email a fixed template to anyone past 30 days and stop there. An assistant would draft three chase emails and leave them in your outbox for you to send. An agent would pull the overdue list, check whether each customer had already paid or part-paid since the data was last synced, draft a chase appropriate to each case, send the two that are clearly overdue, and flag the third for you because the payment status was ambiguous.

The agent did more, and it also made judgement calls a script never could. That is the appeal. It is also precisely why the next question stops being "can it do the task" and becomes "can I see what it did, and was it allowed to do it."

Why the definition matters: an agent acts, so an agent is accountable

Here is the part most explainers skip. The moment software stops answering and starts acting, the questions you have to answer about it change completely. For a chatbot the worst case is a wrong answer you can ignore. For an agent the worst case is a wrong action against your systems: a payment sent, a record changed, a message that went out. When that happens, "the AI did it" is the start of the problem, not the end.

So the real requirements for an agent that touches anything important are not about intelligence. They are about accountability. Was this agent allowed to do that, acting as whom, on whose authority? What did it actually do, step by step, and can that be reconstructed later without taking anyone's word for it? Can a human stop it, and does anything high-stakes wait for a human yes?

That is the problem Quox is built for: agents whose every action is governed, pauses for human approval where it should, and leaves a tamper-evident record of what happened. Identity answers who acted (an agent is not a user, and treating it like one is its own trap), a cryptographic audit trail answers what it did, and governance controls answer what it was allowed to do. An AI agent is software that acts. The useful follow-on question, the one worth building for, is whether you can hold it to account when it does.