What is an AI agent?

Reason
AgentsQuoxMindAgentic TeamsMirror & QuoxHatQuoxLensRemember
QuoxMemoryBrain2CompoundingQuoxPlanCodebase MirrorAct
QuoxFlowQuoxEngineQuoxAgentQuoxChatAutonomyRun
EnterpriseOrganisationsPowers & ToolsmithQlusterQuoxBastionInterfaces
QuoxMCPQuoxCLIQuoxTerminalQuox ConsoleQuoxBoxQuoxVoiceGovern
HITL ApprovalsQuox SecurityAgent HonestyQuoxVaultAI GovernanceAgentic AIProve
For AuditorsVerifiable AI OpsLoggingQuoxSEOEU AI ActCompliance SuiteChannels
Matrix RoomsDiscord ProTelegram ProQuoxSignalCoreCommsAll products A-ZBuild
QuoxProofDeveloper KitPlugin SDKBring your tool to QuoxQuoxpertQuoxSkillsShip and sell
Build and sellBrowse MarketplaceDownloadsProtocolsDev Suite
Dev ServersQuoxBuildQuoxSlotsShared Skills + RulesQlarityDev workflow
RepoBrainGripeTriageFixLoopProofLoopDoneEngineAll products A-ZGet started
OverviewArchitectureProtocols
AEEAOCLVOLTWARDReference
GlossaryAPI ReferencePlugin SDKDockerAll products A-Z
A chatbot answers you. An agent goes and does the thing. The gap between those two sentences is the whole subject.
An AI agent is software that pursues a goal by taking actions, not just by producing text. You give it an objective, and it reasons about what to do, calls tools to do it, reads what happened, and keeps going until the job is done or it gets stuck. A language model is the part that thinks. An agent is the model wired to hands: the tools, the memory, and the loop that lets it act in the world rather than only describe it.
That is the line that matters. Ask a chatbot to "sort out the failed payment on order 4192" and you get a well-written explanation of how you might sort it out. Ask an agent the same thing and it looks up the order, checks the payment processor, retries the charge or issues the refund, updates the record, and tells you what it did. Same request, completely different thing on the other end.
Three capabilities turn a model into an agent. Take any one away and you have something simpler.
Put plainly: a chatbot is a model you talk to; an agent is a model you delegate to. The delegation is the point, and it is also where the risk moves.
The words get used loosely, so it helps to be precise about the spectrum.
A plain workflow or automation follows a fixed script: when X happens, do Y. It is predictable and it does not decide anything. An assistant answers and drafts but waits for you to act on its output. An agent chooses its own steps toward a goal and takes them. A multi-agent system is several agents, often with an orchestrator, splitting a larger job between them.
Most real deployments sit somewhere in the middle: an agent that can act freely on low-risk steps and has to stop and ask a human before anything that spends money, touches customer data, or cannot be undone. That pause is not a weakness in the design. On any system that matters, it is the design.
Say the goal is "chase the three overdue invoices from last month." A workflow would email a fixed template to anyone past 30 days and stop there. An assistant would draft three chase emails and leave them in your outbox for you to send. An agent would pull the overdue list, check whether each customer had already paid or part-paid since the data was last synced, draft a chase appropriate to each case, send the two that are clearly overdue, and flag the third for you because the payment status was ambiguous.
The agent did more, and it also made judgement calls a script never could. That is the appeal. It is also precisely why the next question stops being "can it do the task" and becomes "can I see what it did, and was it allowed to do it."
Here is the part most explainers skip. The moment software stops answering and starts acting, the questions you have to answer about it change completely. For a chatbot the worst case is a wrong answer you can ignore. For an agent the worst case is a wrong action against your systems: a payment sent, a record changed, a message that went out. When that happens, "the AI did it" is the start of the problem, not the end.
So the real requirements for an agent that touches anything important are not about intelligence. They are about accountability. Was this agent allowed to do that, acting as whom, on whose authority? What did it actually do, step by step, and can that be reconstructed later without taking anyone's word for it? Can a human stop it, and does anything high-stakes wait for a human yes?
That is the problem Quox is built for: agents whose every action is governed, pauses for human approval where it should, and leaves a tamper-evident record of what happened. Identity answers who acted (an agent is not a user, and treating it like one is its own trap), a cryptographic audit trail answers what it did, and governance controls answer what it was allowed to do. An AI agent is software that acts. The useful follow-on question, the one worth building for, is whether you can hold it to account when it does.