An AI agent is a software system that takes a goal, works out the steps needed to reach it, uses tools and data sources to carry those steps out, and returns a result. The distinguishing feature is not intelligence — it is action. A language model produces text. An agent produces text and does things: queries a database, calls an analysis routine, writes to a document, escalates to a person.
That definition is deliberately plain, because the term has been stretched to cover almost anything with a language model attached. This article sets out what the word means when it means something, which components are actually required, and how agents differ from the automation your institution already runs. For how this plays out in regulated deployment specifically, see our guide to enterprise AI agents.
Four capabilities separate an agent from a model with a prompt attached. A system missing any of them is doing something simpler, which may well be the right choice — but it is not an agent.
Given "produce a summary of the evidence for this indication in this market," an agent determines the sequence: identify relevant sources, retrieve them, extract the outcomes, check them against inclusion criteria, structure the result. That sequence is not written by hand for each request. This is the actual dividing line — traditional automation executes a sequence a person specified in advance; an agent derives the sequence from the goal.
An agent calls things outside itself: search, databases, calculators, document writers, APIs. Tool use is what lets a probabilistic language model produce reliable outputs. In serious deployments the toolset is registered — a fixed, permissioned, versioned list. The agent selects from it and cannot invent new capabilities mid-task.
Agents that matter in professional settings work over the institution's own corpus rather than from the model's parametric memory. The agent finds the relevant material, brings it into context, and carries the citation forward so the output points back at its sources. Without this an agent is a fluent guesser. With it, the output becomes checkable — which is what makes it usable in work that has to be defended.
An agent checks the outcome of each step and responds. A retrieval returned nothing; broaden the query. A calculation failed; report the failure rather than fabricating a number. This loop is what makes agents useful on messy real-world tasks, and it is also what makes them harder to validate than deterministic software — the same run can take different paths.
Against rules-based workflow automation: your existing tools follow paths a person mapped in advance, deterministic and brittle. Agents handle variation — a document in an unexpected format, a source with a different structure — at the cost that behaviour is no longer fully specified in advance, so it has to be bounded rather than fully predicted.
Against machine learning models: a trained model maps inputs to outputs, narrow and validated with established statistical methods. An agent is an orchestration layer that might call such a model as one of its tools — you validate a classifier against a held-out set, but you cannot validate a multi-step agentic workflow that way, since the evaluation has to cover the whole trajectory.
Against a chatbot: the short version is that a chatbot answers, an agent acts. The consequences of that difference for risk assessment and procurement are large enough to deserve their own treatment.
"Agentic AI" has become a label attached to almost anything with a chat window, which makes it close to useless in a procurement conversation. If a vendor describes a product as agentic, the questions that recover the meaning are concrete: which steps run without a person, and which require one? Where is the system required to stop? What tools can it call, and who decided the list? Can the plan be inspected before it executes? What is recorded, and could you reconstruct a specific output twelve months later?
There is a second reason for care. In regulated settings, "autonomous" is not a selling point — it is the property the buyer is trying to constrain. Vendors who lead with autonomy are usually describing a product built for a different market.
For the full deployment picture — architecture, security and governance — see the guide to enterprise AI agents. For how the mechanics actually run, see how AI agents work and AI agents vs chatbots. For where agents are genuinely deployed today, see AI agent use cases in healthcare.
Our proprietary AI orchestration platform for healthcare: one engine, a registry of reusable task modules and domain agents, and a governed knowledge base — deployed inside your walls and run by your team.