# What Is an AI Agent? Types, Examples and How They Work

URL: https://vrisic.com/blog/what-is-an-ai-agent/
Last updated: 2026-09-29

**Short answer:** an AI agent is software that uses a large language model to decide what to do next and then does it through tools, such as searching a database, updating a CRM or sending an email. It works in a loop: read the goal, plan a step, act, check the result and repeat until the task is done or it hands over to a person.

In this guide

1. What an AI agent is
2. Agent vs chatbot vs agentic AI
3. How AI agents work
4. Types of AI agents
5. AI agents examples by team
6. How much autonomy to give
7. Limits and risks
8. How to start
9. What an agent costs
10. How Vrisic can help
11. Sources

Ask ten vendors what an AI agent is and you will get ten answers, most of them shaped by what the vendor sells. This guide gives you the working definition we use when we build agents for companies in the US, UK and UAE, explains what are AI agents made of, walks through the types of AI agents with examples you would recognise from your own business, and is honest about where they break. If you already know you want one built, our [AI agent development service](https://vrisic.com/services/ai-agent-development/) page covers scope, process and pricing.

## What is an AI agent, in plain terms?

An AI agent is a program that is given a goal rather than a script, and that chooses its own next step toward that goal using a language model and a set of tools you allow it to use. The key word is *chooses* . Traditional software follows a path a developer wrote in advance. An agent decides the path at run time, within limits.

Every business agent we have seen is built from the same five parts:

- **A model.** A large language model such as the GPT 5 family from OpenAI, Claude from Anthropic or Gemini from Google. It reads the situation and proposes the next action.
- **Instructions.** A written brief: the goal, the rules, the tone, what it must never do and when to ask a human.
- **Tools.** Functions the agent can call, for example “look up order”, “check calendar”, “create ticket”. Each tool is ordinary code with its own permissions and input checks.
- **Memory and knowledge.** The conversation so far, notes from earlier steps, and access to documents through retrieval, often called RAG (retrieval augmented generation).
- **A loop with a stop condition.** The code that runs plan, act, observe, repeat, and that ends the run when the goal is met, a limit is hit or a person needs to step in.

Remove the tools and you have a chatbot. Remove the model and you have a workflow. The combination is what makes something an agent.

How an AI agent works: goal, reason, act, check, approve and done

## AI agent vs chatbot vs agentic AI: what is the difference?

A chatbot answers, a workflow follows fixed steps, and an AI agent decides and acts. Agentic AI is the wider design approach of building systems out of agents. The table shows how the four terms differ in practice.

| Compared on | Rule based chatbot | LLM assistant (like ChatGPT) | Workflow automation | AI agent |
| --- | --- | --- | --- | --- |
| Understands free text | Keywords only | Yes | Only if a model step is added | Yes |
| Who decides the steps | The script | The user, turn by turn | The developer, in advance | The model, within rules |
| Takes actions in your systems | Rarely | Limited to built in tools | Yes, fixed actions | Yes, chosen per case |
| Handles unusual cases | Fails or loops | Talks about them | Stops or errors | Adapts or escalates |
| Predictability | Very high | Medium | Very high | Medium, needs testing |
| Best for | Menus and simple FAQs | Individual productivity | High volume, identical tasks | Varied tasks with clear goals |

Anthropic’s engineering team draws the same line in its guide [Building effective agents](https://www.anthropic.com/engineering/building-effective-agents) (December 2024): workflows follow predefined code paths, while agents direct their own process and tool use. Their advice, which matches ours, is to use the simplest option that works. Many problems sold as “agent” projects are really workflows with one model step, and they are cheaper and more reliable that way. Our guide to [AI workflow automation](https://vrisic.com/services/ai-workflow-automation/) covers that route.

**Agentic AI** is the umbrella term. It describes systems that plan, use tools and pursue goals over several steps, whether that is one agent or several working together. An AI agent is a single working unit inside an agentic system.

## How do AI agents work, step by step?

AI agents work by running a loop in which the model reads the current state, picks a tool, receives the tool’s result and decides again, until it reaches the goal or a stop rule. Here is that loop on a real type of task.

*Example scenario:* a supplier emails an invoice that does not match the purchase order. A finance agent is asked to resolve it.

1. **Read the goal and context.** The agent receives the email, the PDF and its instructions: match invoices to purchase orders, approve differences under $50, escalate anything else.
2. **Plan.** The model decides it needs the purchase order and the goods received note first.
3. **Act.** It calls the “get purchase order” tool with the PO number it extracted from the PDF.
4. **Observe.** The tool returns the order. The model sees the invoice charges for 120 units, but only 100 were received.
5. **Decide again.** The difference is above the approval limit, so the rules say escalate. The agent drafts a note to the accounts payable lead explaining the gap and a reply to the supplier asking for a credit note.
6. **Stop and hand over.** It posts both drafts for approval and logs every step it took.

Under the hood, the model does not touch your systems directly. It outputs a structured request, something like “call get_purchase_order with PO 4471”, and your code runs that call with its own permissions. This is called tool calling or function calling, and every major model provider supports it. The [Model Context Protocol](https://modelcontextprotocol.io/) (MCP), introduced by Anthropic in November 2024, is now a common standard for exposing tools to agents so one tool definition works across models.

Developers usually build the loop with a framework such as LangGraph, the OpenAI Agents SDK or LlamaIndex, and track every step with an observability tool such as Langfuse or LangSmith. That trace is what lets you answer “why did the agent do that?” when something goes wrong.

> An agent is only as capable as its tools and only as safe as its permissions. The model supplies judgement; your code decides what that judgement is allowed to touch.

## What are the types of AI agents?

There are two useful ways to classify AI agents: the five classic types from AI textbooks, which describe how an agent decides, and the practical types businesses deploy, which describe what an agent does.

### The five classic types of AI agents

The textbook grouping comes from Stuart Russell and Peter Norvig’s *Artificial Intelligence: A Modern Approach* . It predates language models but still explains the design choices well.

| Type | How it decides | Business example |
| --- | --- | --- |
| Simple reflex agent | If this condition, then that action. No memory. | A rule that routes any email containing “cancel my subscription” to the retention queue |
| Model based reflex agent | Keeps an internal picture of the world and reacts to it | A stock monitor that knows what is in transit, so it does not reorder items already on the way |
| Goal based agent | Plans a sequence of actions to reach a stated goal | A scheduling agent that finds a slot suiting three people, a meeting room and a client’s time zone |
| Utility based agent | Weighs options and picks the one with the best score | A dispatch agent that assigns jobs by balancing travel time, technician skill and customer priority |
| Learning agent | Improves its behaviour from feedback over time | A lead scoring agent whose weights are retuned monthly from which leads actually closed |

Most modern LLM agents are goal based, with utility style scoring added for choices and a learning element supplied by people reviewing results and updating instructions, rather than by the model retraining itself.

### The practical types of AI agents businesses deploy

- **Task agents.** Do one job end to end, such as triaging a shared inbox, checking contracts against a playbook or reconciling a report. The best first project for most companies.
- **Conversational agents.** Talk to customers on web chat, WhatsApp or email and take actions during the conversation, such as rebooking or issuing a return label.
- **Voice agents.** The same idea on the phone, with speech recognition and a synthetic voice. An AI receptionist is the most common version; see our [voice AI development](https://vrisic.com/services/voice-ai-development/) page.
- **Knowledge agents.** Research across company documents and systems and return a sourced answer or report. These sit on top of [enterprise RAG and AI search](https://vrisic.com/services/enterprise-rag-ai-search/) .
- **Computer use agents.** Operate a screen through clicks and typing when a system has no API. Useful for legacy software, slower and more fragile than API tools.
- **Coding agents.** Write, test and fix code inside a repository. Mostly used by engineering teams rather than business units.
- **Multi agent systems.** Several specialised agents coordinated by an orchestrator, for example one that gathers data, one that checks policy and one that writes the output.

## AI agents examples by team and industry

The strongest AI agents examples share a pattern: high volume, clear rules, several systems to touch and a real cost when the work is slow. These are the kinds of agents companies commission most often.

| Team or sector | Agent | What it does |
| --- | --- | --- |
| Sales | Lead response agent | Replies to every enquiry within a minute, asks qualifying questions, books a call and writes the notes into the CRM |
| Customer support | Resolution agent | Answers order, billing and account questions and performs the fix, such as a refund under a set limit |
| Finance | Accounts payable agent | Matches invoices to orders, chases missing documents and prepares exceptions for approval |
| Operations | Dispatch agent | Assigns field jobs, reshuffles the day when a job overruns and texts customers updated arrival times |
| HR | Onboarding agent | Collects documents, creates accounts, schedules training and answers policy questions |
| Healthcare | Patient access agent | Books, moves and confirms appointments and runs intake questions before a visit |
| Legal | Intake agent | Screens new enquiries, gathers facts, runs a first conflict search and books a consultation |
| Real estate | Lead qualification agent | Replies to portal leads, confirms budget and timing and books viewings |
| Ecommerce | Order agent | Handles where is my order, returns and exchanges across chat and email |

We go deeper on sector patterns for [healthcare providers](https://vrisic.com/industries/healthcare/) , [law firms](https://vrisic.com/industries/law-firms/) , [real estate teams](https://vrisic.com/industries/real-estate/) and [ecommerce brands](https://vrisic.com/industries/ecommerce/) . Many of these agents live inside the CRM; our guide on how to add AI to your CRM shows how that connection is made.

## How much autonomy should an AI agent have?

An AI agent should get the lowest level of autonomy that still saves real time, and move up only when its measured accuracy justifies it. We use four levels with clients:

1. **Suggest.** The agent drafts, a person does. Safe for any task, smallest saving.
2. **Approve.** The agent prepares the action and a person clicks approve. The usual starting point for anything touching money or customers.
3. **Act within limits.** The agent acts alone below a threshold, such as refunds under $50 or bookings inside opening hours, and escalates the rest.
4. **Act and report.** The agent acts freely and people review samples and exceptions afterwards. Only for low risk, well tested tasks.

Moving from level 2 to level 3 is usually where the payback appears, and it should be a decision based on logged results, not a feeling.

## What are the limits and risks of AI agents?

AI agents fail in predictable ways, and each failure has a known defence. The risk is not that agents are unreliable in general; it is that teams launch them without the defences.

- **Errors compound over steps.** This is simple arithmetic: if each step is right 95% of the time, a 10 step task with no checks succeeds about 60% of the time (0.95 to the power of 10). Short tasks, validation between steps and human checkpoints fix most of this.
- **Made up facts.** A model can state a policy or price that does not exist. Agents should answer only from retrieved sources and say “I will check with the team” when nothing is found.
- **Prompt injection.** Text inside an email, web page or document can try to give the agent new orders. The [OWASP Top 10 for LLM Applications 2025](https://genai.owasp.org/llm-top-10/) lists it first, and lists “excessive agency”, giving an agent more power than it needs, as a separate risk. The defence is narrow tool permissions and treating all outside content as data, never as instructions.
- **Runaway cost.** An agent stuck in a loop can make hundreds of model calls. Step limits, spend caps and alerts belong in every build.
- **Privacy.** Agents read personal data. Use business API terms under which the provider does not train on your data, redact what the model does not need, and keep logs where your regulations require. UK and EU teams should read the [ICO guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/) .
- **Unclear value.** Gartner predicted in June 2025 that over 40% of agentic AI projects will be cancelled by the end of 2027 because of rising costs, unclear business value or weak risk controls ([Gartner, 2025](https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027) ). Picking a measurable task first is the cheapest insurance.

The [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) is a good free checklist for thinking through these risks before launch, even outside the US.

## How should a business start with AI agents?

Start with one narrow, frequent, measurable task and prove it before widening the scope. This sequence keeps the first project small enough to finish and clear enough to judge.

1. **List repetitive tasks** that take a person more than five hours a week and follow rules you could write down.
2. **Score each** on volume, systems involved, cost of a mistake and how easy the result is to check. Pick the one with high volume and low mistake cost.
3. **Write the playbook** a new hire would get: the steps, the exceptions, the limits and when to ask for help. This becomes the agent’s instructions.
4. **Collect 50 to 200 real examples** with the correct outcome. These become the test set that tells you if the agent is good enough.
5. **Build at the approve level** , with every action logged, and run it next to your team for two to four weeks.
6. **Measure** accuracy, time saved and escalation rate, then decide whether to raise autonomy, widen scope or stop.

Could an off the shelf agent builder do it? Sometimes, yes, particularly for simple tasks inside one product. Custom builds earn their cost when the agent has to work across several of your systems, follow detailed rules, or run in your own cloud for data reasons. Our [delivery process](https://vrisic.com/how-we-work/) explains how we run that pilot phase.

## What does an AI agent cost to build?

A custom AI agent typically costs $8,000 to $25,000 for a single task agent, $25,000 to $60,000 for an agent working across several channels and systems, and $60,000 to $150,000 or more for a multi agent system. In the UK those tiers are about £6,400 to £20,000, £20,000 to £48,000 and £48,000 to £120,000 or more; in the UAE about AED 29,000 to AED 92,000, AED 92,000 to AED 220,000 and AED 220,000 to AED 550,000 or more.

Typical ranges; you get one fixed price in writing after a free scoping call. Model and hosting usage is billed at cost on top.

Running costs depend on how many tasks the agent completes each month. The full breakdown, including cost per task and hidden costs, is in our [AI agent development cost guide](https://vrisic.com/blog/ai-agent-development-cost/) , and the wider picture across all AI projects is in [how much AI development costs](https://vrisic.com/blog/ai-development-cost/) .

## How Vrisic can help

We design and build custom AI agents for companies in the United States, United Kingdom and United Arab Emirates. A typical engagement starts with a short scoping call where we look at your candidate tasks together and tell you plainly which ones suit an agent, which suit a simpler workflow, and which are better left alone. You then get one fixed price in writing.

We build on your cloud account, with your data staying under your control, test against your real examples before launch and hand over the code and documentation. If you want to talk through a specific task, [book a free scoping call](https://vrisic.com/contact/) or read more [about how we work as a team](https://vrisic.com/about/) .

## Sources

- [Anthropic, Building effective agents](https://www.anthropic.com/engineering/building-effective-agents) , December 2024
- [Model Context Protocol documentation](https://modelcontextprotocol.io/)
- [OWASP Top 10 for LLM Applications](https://genai.owasp.org/llm-top-10/) , 2025 edition
- [Gartner, agentic AI project cancellation prediction](https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027) , June 2025
- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)
- [ICO, guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/)
- Stuart Russell and Peter Norvig, *Artificial Intelligence: A Modern Approach* , 4th edition, Pearson

## Frequently asked questions

### Is ChatGPT an AI agent?

ChatGPT on its own is an AI assistant: it answers and helps you think, and you decide the next step. It becomes agent like when it uses tools, for example browsing the web or running code to finish a task. A business AI agent goes further by connecting to your own systems, following your written rules and completing work end to end without someone steering every turn.

### What are the five types of AI agents?

The five classic types are simple reflex agents, which react to conditions; model based reflex agents, which keep an internal picture of the world; goal based agents, which plan toward a goal; utility based agents, which choose the option with the best score; and learning agents, which improve from feedback. The grouping comes from Russell and Norvig’s textbook on artificial intelligence.

### What is a simple example of an AI agent at work?

A lead response agent is a clear example. When a new enquiry arrives, it reads the message, checks the CRM for an existing contact, asks two or three qualifying questions, offers open slots from a salesperson’s calendar, books the meeting and writes a summary on the contact record. A person only steps in if the lead asks something outside the agent’s rules.

### Do AI agents learn by themselves after they go live?

Most business agents do not retrain their underlying model after launch. They improve because people review logged runs, correct mistakes, add examples to the test set and update instructions or tools. Some agents store notes or preferences between sessions, which feels like learning, but changes to how the agent behaves should always be reviewed and tested before release.

### What is the difference between an AI agent and an AI assistant?

An AI assistant helps a person do a task: it drafts, summarises and answers while the person stays in charge of every step. An AI agent is handed the task itself and decides the steps, calling tools and systems on its own within set limits. Many products blend the two, so ask any vendor exactly which actions the software can take without a human click.

### Can several AI agents work together on one task?

Yes. In a multi agent system, an orchestrator splits a task between specialised agents, such as one that gathers data, one that checks it against policy and one that writes the final output. This helps when steps need very different instructions or tools. It also adds cost and more places to fail, so start with a single agent unless the task clearly needs specialists.

### What does a company need in place before deploying an AI agent?

You need a clearly defined task, written rules a new employee could follow, API access to the systems the agent will use, and 50 to 200 real examples with known correct outcomes for testing. You also need an owner who reviews results each week. Clean data in the systems the agent reads matters more than any choice of model or framework.

### Who is responsible when an AI agent makes a mistake?

The business that deploys the agent remains responsible for what it does, just as it would be for an employee or ordinary software. That is why agents should act only within set limits, log every step and escalate uncertain cases. Contracts with your developer should cover testing standards, fixes and support, and regulated firms should record who approved each level of autonomy.

---
Vrisic · https://vrisic.com/ · Contact: info@vrisic.com · Book a call: https://vrisic.com/contact/