From response to action
A chatbot typically handles an input and returns text. An agent can break an objective into steps, obtain information, use approved functions and review intermediate outcomes.
What production agents also need
A role, permissions, enterprise knowledge, working context, stop conditions, approvals and traceable handovers turn a demonstration into a controllable process.
- minimum necessary access
- clearly allowed actions
- escalation under uncertainty
- business quality review
The use case determines the right form
A chatbot may be enough when people search for information, prepare drafts or make the decision themselves in a dialogue. An agent becomes relevant only when a multi-step assignment and its permitted actions can be defined clearly.
The further an action reaches into systems, data or decisions, the stronger its approvals and boundaries need to be.
Authority bounds autonomy
An agent needs its own identity or clearly attributable permission, a bounded working context and only the tools necessary for its task. External communication, data changes or financial effects can be gated by human approval.
- need-to-know access
- action and value limits
- confirmation before external effect
- stop when evidence is missing
- documented handover
A demonstration does not prove safe operation
Testing covers successful examples as well as incomplete input, conflicting sources, requests for unauthorised action and unavailable tools. Criteria defined in advance support a deliberate go, adjust or stop decision.
An agent remains unsuitable where consequences cannot be reviewed or an error cannot be detected and contained in time.
Source note
This distinction describes common system forms, not a binding product classification. Risk and control principles follow NIST and BSI primary sources reviewed on 11 August 2026.
Primary sources
Official sources, editorially checked on 11 August 2026.
- AI Risk Management FrameworkNational Institute of Standards and Technology (NIST)
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)National Institute of Standards and Technology (NIST)
- Generative AI Models: Opportunities and Risks for Industry and AuthoritiesBundesamt für Sicherheit in der Informationstechnik (BSI)