Advanced· AI at work· 11 min read

Agents, tools and automation: what changes next

When systems act rather than answer, the questions about oversight and accountability change too.

Dr. Michael D’Rosario
Host & Editor · September 29, 2026
↗ in ✉

For the first phase of generative AI, most people experienced the technology through a fairly simple exchange. You asked a question, supplied some information and received an answer. The model might write an email, summarise a report, generate some code or analyse a document, but the basic relationship remained familiar: a person initiated the task, the AI produced something, and the person decided what happened next.

That model of interaction is beginning to change.

The important development is not simply that language models are becoming more capable. It is that they are increasingly being connected to tools, data, software and other systems that allow them to do something with the conclusions they reach. An AI system can search for information, query a database, read a calendar, execute code, update a customer record, create a document, call another piece of software or initiate a business process. Once those capabilities are combined with some ability to decide which action should happen next, AI begins to move from producing outputs within a workflow to participating in the workflow itself.

This is the significance of the current interest in AI agents. The term is used rather loosely, and not every piece of software marketed as an agent represents a fundamentally new form of artificial intelligence. What matters is the shift in the operating model. Instead of asking AI to complete one tightly specified task, we can increasingly give a system an objective, provide it with tools and constraints, and allow it to determine some of the intermediate steps required to reach that objective.

The difference sounds subtle, but it changes what can be automated, where judgement sits and how organisations need to think about control.

A model produces an answer, a tool lets it do something

A large language model on its own principally transforms information into an output. You provide a prompt and some context, the model processes that information and generates a response. It might produce an excellent recommendation, but the recommendation remains text until someone or something acts on it.

Tools extend that capability.

Imagine asking an AI assistant:

Find a time next week when everyone on the project team is available and schedule a 45-minute meeting.

A language model without access to anything else can explain how you might find a suitable time, or perhaps draft a message asking participants about their availability. It cannot establish when people are actually free because it does not have access to their calendars, and it cannot create the meeting because it has no mechanism for changing the calendar system.

Give the AI access to a calendar tool and the task changes. The system can potentially retrieve availability, compare schedules, identify a suitable period and create the event. The language model has not suddenly acquired knowledge of everyone’s calendar. It has acquired a means of obtaining that information and taking an action based upon it.

The same principle applies throughout an organisation. A model connected to a customer database can retrieve account information. Connected to an analytics system, it can run a query. Connected to a document repository, it can locate internal policies. Connected to an email system, it can draft, read or potentially send messages. Connected to business software through application programming interfaces, it can begin to interact with many of the systems employees already use.

The model provides a capacity to interpret information and decide what might need to happen. Tools provide the means through which those decisions can affect the world outside the conversation.

Automation is not new, but the interface to it is changing

Organisations have automated processes for decades. Payroll systems calculate salaries, enterprise software routes transactions, scripts transfer data between applications and workflow systems trigger actions when predefined conditions are met. None of this required generative AI.

Traditional automation works particularly well when the process can be specified clearly in advance. If an invoice exceeds a particular value, send it for additional approval. If a customer has not paid within 30 days, issue a reminder. If inventory falls below a threshold, create a replenishment request.

The difficulty comes when the decision depends on information that is difficult to represent as a fixed set of rules.

Consider an organisation receiving thousands of emails from customers. Before a conventional workflow can decide where each email should go, somebody or something needs to interpret what the customer is asking. A carefully constructed rules system might search for keywords, but language is variable, context matters and customers do not reliably describe the same problem in the same way.

A language model can interpret the message, classify the request and extract relevant information before handing the result to a conventional workflow. Suddenly a process that previously required a person to read and categorise unstructured information becomes much more amenable to automation.

This is one of the more important changes introduced by generative AI. It does not replace conventional automation so much as extend the range of information and decisions that automation can work with.

An agent adds another layer

The next step is to allow the AI system to determine which tools and intermediate actions are required.

Suppose a customer writes:

I was charged twice for my subscription this month and I want the second payment refunded.

A relatively simple AI-enabled workflow could classify the email as a billing issue and send it to the finance team.

A more capable system might extract the customer’s identity and transaction details, retrieve the relevant account, compare the payments, determine whether a duplicate charge occurred, check the organisation’s refund policy and prepare a recommended action for an employee.

An agent with sufficient authority could potentially go further. It could determine that the duplicate payment meets the refund criteria, initiate the refund, update the customer record and send confirmation.

The objective remains the same throughout: resolve the customer’s problem. What changes is how much of the path between the request and the outcome has been delegated to the system.

This provides a useful way of thinking about agency. It is not primarily about whether the AI appears autonomous or speaks as though it has intentions. The practical question is how much discretion the system has over the sequence of actions between an objective and an outcome.

Agents make workflows less predetermined

Traditional workflows are usually designed as explicit sequences. Step A leads to Step B, which leads to Step C, with conditional branches specified by the people who designed the process.

Agentic systems can make parts of that sequence dynamic.

Imagine asking an AI research agent to prepare an assessment of a new market. It might begin by identifying the information required, search for market data, inspect competitor websites, retrieve relevant internal sales information, calculate growth rates, identify gaps in the evidence, conduct additional searches and then prepare an analysis.

Another market might require a different sequence because different information is available. The objective remains stable while the path changes.

This is potentially powerful because many forms of knowledge work are not fixed processes. An analyst does not necessarily know at the beginning of an investigation every source they will consult or every calculation they will perform. They respond to what they find, changing the next step as new information becomes available.

Agentic systems begin to bring that adaptive quality into automation.

The important word, however, is “begin”. The fact that a system can select its next action does not mean it will select the correct one, recognise when evidence is inadequate or understand all of the organisational consequences of an action. Greater flexibility creates additional capability, but it also creates additional ways for the process to fail.

The unit of automation begins to get larger

Early generative AI largely automated components of work. Write the paragraph, summarise the meeting, generate the formula, classify the feedback or create the image.

Agents create the possibility of automating larger units of work because they can connect several component tasks.

Consider recruitment. AI might already be used separately to draft a job advertisement, summarise applications, schedule interviews and prepare candidate communications. An agentic system could potentially coordinate several of these activities as part of one process, subject to appropriate constraints and human decisions.

The same applies to sales. Instead of generating an individual prospecting email, a system might identify potential prospects from approved sources, research the organisation, update a CRM, draft a tailored message, schedule a follow-up and alert a salesperson when a response requires attention.

In software development, the shift is from generating a function to working across a codebase, running tests, identifying failures, modifying files and checking whether the change solved the problem.

The economic significance is that AI begins to affect processes rather than isolated tasks. Most jobs consist of bundles of tasks connected through judgement, information flows and organisational routines, so the ability to coordinate several steps changes the potential scope of automation considerably.

More autonomy means more attention to permissions

A chatbot that gives a poor answer creates one kind of risk. An agent that can take an incorrect action creates another.

This makes permissions central to agent design.

An AI system might be permitted to read customer records but not modify them. It might draft an email but require approval before sending it. It might issue refunds below a specified threshold while escalating larger cases. It might modify code in a development environment but have no authority to deploy changes into production.

These boundaries determine the practical consequences of an error.

If an AI research assistant misunderstands a question, the result may simply be an unhelpful report. If an AI financial agent misunderstands an instruction while possessing authority to initiate transactions, the consequences can be considerably more serious.

The question for organisations is therefore not simply whether an agent is capable of performing a task. It is what authority the system should have while performing it.

This is familiar territory in organisational design. Employees are given different levels of access, expenditure authority and decision rights according to their roles. Software systems have long used permission structures to restrict what particular users and applications can do. AI agents extend the same problem to systems capable of interpreting situations and selecting actions dynamically.

Human approval is one control, but not the only one

A common response is to place a human approval step before every consequential action. For some processes, particularly during early deployment, that may be sensible. Applied indiscriminately, however, it can produce a peculiar form of automation in which employees spend their time approving large volumes of machine-generated decisions.

A more mature approach is to design controls around risk.

Low-consequence and readily reversible actions may be automated with monitoring. Higher-risk cases can be escalated according to predefined conditions. Transactions above particular thresholds can require approval. Samples of routine decisions can be audited. Systems can be prevented from accessing particular data or performing particular classes of action. Unusual behaviour can trigger intervention.

This allows human judgement to operate at the level of system design and exception management rather than requiring a person to manually reproduce every step of the automated process.

The distinction becomes increasingly important as the volume of agentic activity grows. If one employee supervises an AI system performing hundreds of actions, meaningful oversight cannot consist of reading every action after the fact. Organisations will need mechanisms for observing patterns of behaviour, measuring error rates and identifying when systems are operating outside expected boundaries.

Agents also change the role of software

For decades, software has largely required people to adapt their behaviour to the structure of applications. We learn where information is stored, which menu contains a function, what fields a system expects and which sequence of screens completes a process.

Agents introduce the possibility that the user increasingly describes an objective while software determines how existing applications should be used to achieve it.

Instead of opening a CRM, filtering customers, exporting a list, opening a spreadsheet, calculating a measure, creating a chart and pasting it into a presentation, a user might ask:

Show me which customer segments experienced the largest decline in retention this quarter, identify the principal changes relative to last quarter and prepare the results for tomorrow’s management meeting.

Behind that instruction, an AI system may need to interact with several applications and data sources. The user increasingly interacts with the objective rather than manually operating each piece of software involved in producing the result.

If this pattern develops, it changes more than productivity. It changes the interface between people and digital systems.

Software applications do not disappear, because the underlying databases, permissions, business rules and specialised functions remain necessary. What may change is how often people interact with those systems directly. Some software increasingly becomes infrastructure used by agents rather than an interface used by humans.

This also changes what organisations need to make AI useful

A highly capable model cannot compensate indefinitely for inaccessible information and poorly connected systems.

If customer data are fragmented across incompatible databases, policies exist in outdated documents, permissions are inconsistent and business processes are poorly defined, an AI agent inherits those problems. Giving the system more autonomy may simply allow it to encounter them faster.

This makes the less glamorous parts of digital capability increasingly important. Organisations need usable data, clear access controls, reliable APIs, current documentation, consistent identifiers and some understanding of how their processes actually operate.

The organisations best positioned to use agents may therefore not be those that purchase the most advanced model first. They may be those that have made their information and systems sufficiently coherent for AI to work across them safely.

Agentic AI turns information architecture into operational capability.

The economics of software may change as well

If agents can interact directly with software, the value of software may shift away from the quality of its human interface towards the quality of the capabilities it makes available programmatically.

An application that is awkward for a person to operate but exposes reliable, well-documented functions to an AI agent may become more useful in an agent-mediated environment. Conversely, a beautifully designed application that cannot communicate effectively with other systems may become relatively isolated.

This creates a different kind of customer for software providers. The person using the service still matters, but increasingly an AI system may be the entity querying the database, requesting the price, comparing the product, submitting the form or initiating the transaction.

That possibility extends beyond enterprise software. If consumers increasingly delegate research, comparison and purchasing tasks to AI agents, businesses may need to communicate not only with people but with the systems acting on their behalf.

The implications for search, marketing, e-commerce and digital competition could be substantial because many existing online business models assume that a person will visit a website, view an interface, encounter advertising and manually make a choice. Agents can alter each stage of that sequence.

Automation becomes a question of orchestration

The popular image of automation has often been substitution: a machine performs a task previously completed by a worker.

Agents suggest a more complicated picture in which economic value may come from coordinating many different forms of intelligence and software.

A business process might involve a language model interpreting an enquiry, a specialist predictive model estimating risk, a database supplying customer information, conventional software applying business rules, another AI system generating communication and a person making the final decision in unusual cases.

No single component performs the entire job.

The capability comes from how the components are arranged.

This is why orchestration is likely to become an increasingly important part of AI implementation. Organisations need to decide which model should perform which task, what information each component should receive, when deterministic software is preferable to generative AI, which actions require human judgement and how the entire process should respond when something goes wrong.

The most sophisticated solution is not necessarily the one containing the most AI. A deterministic rule remains preferable when the rule is known, stable and easy to specify. A conventional database remains preferable when an exact record needs to be retrieved. A calculator remains preferable for arithmetic. A human remains important where contextual judgement, accountability or consequence requires it.

The value lies in assigning each part of the process to the mechanism best suited to it.

What changes next is not simply the model

Much of the public discussion about AI remains organised around model releases. A new model scores higher on a benchmark, accepts a larger context window, generates better video or performs more difficult reasoning tasks.

Those improvements matter, but the next stage of adoption is increasingly about what happens around the model.

The consequential questions are becoming whether AI can access the information required to perform useful work, whether it can use the necessary tools, whether different systems can communicate, what actions it is authorised to take and how its behaviour can be observed and controlled.

This moves the conversation from intelligence in isolation towards intelligence embedded in organisations.

The first wave of generative AI showed that machines could produce surprisingly capable outputs from ordinary language instructions. The next phase is about connecting that capability to the systems through which work actually happens.

Once AI can move from answering a question to retrieving information, selecting tools, performing intermediate tasks and taking authorised actions, the relevant unit of change is no longer simply the prompt or even the individual task. It becomes the workflow.

And once workflows can adapt rather than simply follow a predetermined sequence, the boundary between AI, software and automation becomes considerably less distinct.

The question facing organisations will therefore move beyond “What can this model do?” towards something more operationally important: what should this system be allowed to do, what does it need in order to do it well, and where should human judgement remain decisive?

Listen to the episode
What is the Intelligent Economy

More AI Literacy

Intermediate · 10 min read

Using AI at work without giving up judgement

By Dr. Michael D’Rosario

Advanced · 10 min read

AI literacy as public infrastructure

By Dr. Michael D’Rosario

Advanced · 12 min read

AI regulation explained: from principles to practice

By Dr. Michael D’Rosario