Practical answer · Build

What is an AI agent and should my business use one?

An AI agent is a system that uses an AI model, instructions, context and tools to pursue an outcome across one or more steps. Unlike a chatbot that mainly responds, or fixed automation that follows a predetermined path, an agent can choose which action to take next. A business should use one only when that flexibility solves a real problem. Start with a narrow, low-risk workflow, restrict its access, require approval for consequential actions, log what it does and keep a reliable way to stop it.

An AI agent is software that can work towards an outcome rather than merely produce a single reply. It combines a model with instructions, context and tools, then uses those parts to decide what to do next.

That definition matters because almost every AI feature now seems to be called an agent. Some genuinely plan and act across systems. Others are ordinary chatbots or fixed workflows with a more fashionable label.

The useful question is not whether something is marketed as agentic. It is whether the system can choose actions, what it can reach and what happens when its judgement is wrong.

What can an AI agent actually do?

Depending on the system and the permissions it has been given, an agent may be able to:

  • retrieve information from files or connected services;
  • break a goal into smaller tasks;
  • choose and use tools;
  • create or delegate work to sub-agents;
  • update records or prepare communications;
  • pause for approval;
  • check its progress and adjust its next step;
  • run on a schedule or from an external trigger.

OpenAI's workspace-agent documentation describes agents that can use apps, tools, Skills and files, run in ChatGPT or Slack, operate on a schedule and be triggered through an API. Those are product-specific capabilities, not a universal checklist for every agent platform.

An agent can only use the tools, data and channels that its platform supports and that an administrator or user has made available. It does not acquire access merely because a prompt asks for it.

Workspace agent or custom-built agent?

The choice is not simply between buying an agent and building one. It is usually between three starting points: configuring an agent inside a product your team already uses, building a custom agent through an API, or keeping the process as ordinary automation.

NeedBetter starting point
A repeatable team workflow using approved files and connected business toolsA configured workspace agent
A custom product, customer experience or workflow embedded in your own softwareAn API-built agent
A fixed sequence with dependable rulesOrdinary automation
A process the business does not yet understand wellA manual pilot with AI recommendations only

OpenAI introduced its Agents API in public beta on 10 September 2026. It gives developers a managed agent harness for long-running sessions, tool use, context management and sub-agents, with a choice of an OpenAI-hosted sandbox, the developer's own infrastructure or a supported sandbox provider.

That can remove a substantial amount of plumbing. It does not remove the business work. Someone still has to define the process, limit permissions, choose data sources, create evaluations, monitor cost and quality, handle failures and decide who is accountable for the result.

For many Scottish SMEs, a workspace agent or a fixed workflow with one AI-assisted step is the more proportionate first move. A custom API build becomes sensible when the workflow is valuable, repeated and genuinely needs to live inside the organisation's own systems or customer experience.

Agent, chatbot, automation or Skill?

These terms describe different parts of a system.

CapabilityMain jobTypical behaviour
ChatbotRespond to a personProduces an answer from the current conversation and available context
Fixed automationFollow a defined pathRuns predetermined triggers, conditions and actions
AI agentPursue an outcomeSelects or sequences actions based on context and intermediate results
AI SkillSupply a reusable methodGives an AI instructions, examples, resources and checking rules for a type of work

They can work together. An agent may use a Skill to review a report, call an app to retrieve the source data and pass an approved result into a fixed workflow. The agent provides flexible coordination. The Skill provides the method. The app provides access. Deterministic software should still handle exact calculations and rules.

When does a business need an agent?

Use an agent when the work has a clear outcome but a variable route. Good candidates usually involve several of the following:

  • information arrives in different formats;
  • the system must investigate before choosing the next step;
  • different tools may be needed for different cases;
  • the work has natural checkpoints for human review;
  • exceptions can be recognised and escalated;
  • the outcome is valuable enough to justify monitoring and maintenance.

For example, an agent could review an incoming supplier request, retrieve the relevant policy, identify missing information, prepare a recommendation and place it in an approval queue. It should not quietly approve the supplier, change bank details and send payment simply because all of those actions are technically available.

When is ordinary automation better?

Do not use an agent because it makes a straightforward workflow sound more advanced.

Prefer fixed software or conventional automation when:

  • the trigger and sequence are already known;
  • the decision can be expressed as a dependable rule;
  • a calculation must be exact;
  • every case should follow the same path;
  • the cost of an unpredictable action is high;
  • the organisation cannot monitor or maintain the system.

Sending a reminder seven days before a renewal date does not need an agent. Calculating VAT from validated fields does not need a language model. Moving a record between two known states after approval is normally a deterministic task.

A strong business workflow may contain one bounded agentic step inside an otherwise fixed process. That is often more dependable than giving an agent ownership of the entire operation.

Practical uses for Scottish SMEs

The useful opportunities are not uniquely Scottish, but the scale of many Scottish businesses makes proportionality important. A small team does not need an enterprise agent programme to learn whether one workflow is worth improving.

Research and briefing

An agent can search approved sources, compare evidence, identify gaps and prepare a cited briefing. A person should check important claims and make the decision.

Customer enquiries

An agent can classify an enquiry, retrieve relevant guidance and draft a response for review. Fixed rules should protect required acknowledgements, priority customers and topics that always need escalation.

Document intake

An agent can inspect varied documents, choose the relevant extraction method, flag contradictions and route uncertain cases. Required fields and final record updates should still be validated deterministically.

Internal operations

An agent can collect updates from approved systems, assemble a weekly summary and propose actions. It should show its sources and avoid making commitments on behalf of the business without approval.

Start with a process your team already understands. If nobody can describe the current work, exceptions and acceptable outcome, an agent will automate the confusion.

What can go wrong?

Agent risks are not limited to an inaccurate sentence. An agent may have permission to read data, use credentials, contact another service or change a record.

The UK's National Cyber Security Centre says agentic systems can access data, remember context, make decisions, use tools, act towards a goal and sometimes create sub-agents. It also warns that broader access and extra autonomy can increase the attack surface and make behaviour harder to predict, test and govern.

Common failure modes include:

  • treating malicious instructions inside a document or webpage as trusted directions;
  • using a correct tool with the wrong record, recipient or parameters;
  • pursuing a vague goal in an unexpected way;
  • exposing information through an unnecessary connection;
  • repeating an action after a partial failure;
  • losing an important constraint during a long task;
  • giving a confident summary that the evidence does not support.

Adding another AI model to check the first agent may help in some circumstances, but it does not turn probabilistic judgement into proof. Important constraints should also be enforced by permissions, rules and system design.

Seven controls before an agent reaches live systems

  1. Name one outcome. Define what the agent is responsible for and what remains outside its scope.
  2. Use the least access possible. Give it only the data, tools and credentials needed for that task.
  3. Separate reading from writing. A first pilot can often retrieve and recommend without being allowed to send, edit or delete.
  4. Set approval gates. Require a person before external communications, purchases, publishing, deletions and important record changes.
  5. Create realistic tests. Include missing data, conflicting instructions, malicious content, duplicates and tool failures.
  6. Keep logs and an owner. Record actions and outcomes, protect the logs and make a named person responsible for review.
  7. Maintain a stop mechanism. Be able to revoke credentials, disable tools, stop schedules and return to a manual process.

The NCSC's August 2026 guidance adds practical detail on sandboxing, short-lived credentials, network restrictions, observability, incident response and emergency shutdown. Its point is sensible: model-level safeguards are useful, but they are not a complete security system.

A sensible first pilot

Choose one frequent, low-risk task where investigation or interpretation changes the next step.

Run the agent in recommendation-only mode first. Compare its proposed actions with what an experienced member of staff would do. Record accuracy, missed exceptions, review time, usage cost and the effort required to maintain its instructions and connections.

Only add write access after the evidence supports it. Even then, approve the actions whose consequences exceed the organisation's tolerance for error.

The goal is not maximum autonomy. It is the minimum autonomy needed to make the process materially better.

Sources and further reading

Discuss a proportionate AI-agent pilot →