What is an AI agent,and what sets it apartfrom a chatbot?
A chatbot answers questions; an AI agent gets work done. This article covers what an agent is made of, how it compares with chatbots and AI assistants, what companies use agents for and what tends to be underestimated when you get started.
Get in touch- What is an AI agent?
- What is an AI agent made of?
- How does an AI agent differ from a chatbot and an AI assistant?
- What do companies use AI agents for today?
- Where are the limits and risks of AI agents?
- What do companies underestimate when they build an AI agent themselves?
- How can you tell whether an AI agent is worth it for your business?
- Frequently asked questions
- How to test whether an AI agent fits
- Where the information on this page comes from

Let's talk about your project.
First we check whether the project fits your business model. Then you get a proposal with phases and effort.
Discuss AI agents for your business or call: +49 151 1576 5566An AI agent is a software system that uses a language model to pursue a given goal, planning its own steps, using tools and feeding the result of each step into the next. A chatbot answers a question and then waits for the next one. An AI assistant helps you with a task, but the decision stays with you. An agent works through a task in several steps, calls on software and data along the way and keeps checking whether it is getting closer to the goal. That independence is what makes agents useful, and it is also why they need clear limits.
- An AI agent pursues a goal over several steps and uses tools such as software, databases or web search to get there.
- The difference from a chatbot is autonomy: the chatbot answers, the agent acts.
- According to Bitkom, 11 per cent of German companies that use or are considering AI already run AI agents, and another 29 per cent plan to (September 2026).
- The biggest risks are overly broad permissions and manipulated input; a person should approve any step with real consequences.
On this page
- What is an AI agent?
- What is an AI agent made of?
- How does an AI agent differ from a chatbot and an AI assistant?
- What do companies use AI agents for today?
- Where are the limits and risks of AI agents?
- What do companies underestimate when they build an AI agent themselves?
- How can you tell whether an AI agent is worth it for your business?
- Frequently asked questions
- How to test whether an AI agent fits
- Where the information on this page comes from
What is an AI agent?
An AI agent is a system that breaks a task into steps on its own and carries out those steps with the tools available to it. IBM describes an agent as a system that performs tasks autonomously by designing workflows with the tools it has. Google Cloud highlights three traits: agents pursue goals on behalf of a user, show reasoning, planning and memory, and have some latitude to make decisions themselves.
A useful distinction comes from the AI company Anthropic, published in December 2024. It separates two kinds of system: workflows, where the language model and tools work together along predefined paths, and agents, where the model itself decides which steps to take, in what order and with which tools. By that definition, many products sold as agents today are really workflows. That is not a flaw: for well defined tasks, fixed paths are often more predictable.
For a mid-sized business the practical question is therefore not whether something carries the label “agent”, but how much the system may decide on its own and where a person steps in.
What is an AI agent made of?
Whatever the vendor, every agent has four building blocks. Anthropic describes the core as a language model extended with retrieval, tools and memory that works in a loop: it acts, looks at the result and decides on the next step.
- 01
01
ModelA large language model does the understanding and planning. It reads the task, splits it into sub-tasks and drafts intermediate results. How well the agent performs depends heavily on how well the model suits the job.
- 02
02
GoalThe agent needs a clear brief with a recognisable end, for example “sort this week's open enquiries by urgency”. Without a defined goal and a stopping condition, it has no way of knowing when it is done.
- 03
03
ToolsTools are everything that lets the agent act beyond producing text: a search, a database query, a calendar, an inventory system, saving a draft. Tools are what turn a conversation partner into something that acts.
- 04
04
FeedbackAfter each step the agent gets feedback from its environment, such as the result of a query or an error message. Anthropic calls this the ground truth the agent uses to judge its progress. Checkpoints where a person reviews the work belong here too.
How does an AI agent differ from a chatbot and an AI assistant?
The difference is the degree of autonomy. Google Cloud puts it like this: bots typically follow pre-programmed rules and are the least autonomous. AI assistants respond to requests and can recommend actions, but the user makes the decision. AI agents have the highest degree of autonomy and can make decisions independently to reach a goal. IBM adds that chatbots without tools, memory or reasoning can only reach short-term goals and cannot plan ahead.
In practice the lines blur. Modern chatbots can call individual tools, and an agent can sit behind a chat window. The table therefore shows typical characteristics rather than strict categories.
| Feature | Chatbot | AI assistant | AI agent |
|---|---|---|---|
| Basic principle | Answers questions from rules or a model | Supports you step by step with a task | Completes a multi-step task itself |
| Who decides | The rules or the user | The user | The agent, within the limits it is given |
| Tools | None or very few | A few, usually built into one application | Several, combined as the task requires |
| Planning | None, one answer per question | Little, follows your instructions | Breaks the goal into sub-tasks itself |
| Typical task | Answering frequent questions on a website | Drafting text, analysing a spreadsheet, writing an email | Sorting enquiries, gathering data, preparing a draft |
| Risk | A wrong or made-up answer | A wrong suggestion the user adopts | A wrong action with consequences in other systems |
What do companies use AI agents for today?
AI agents have arrived in German businesses, but they are not yet widespread. In a representative Bitkom survey of 603 companies with 20 or more employees, published on 14 September 2026, 57 per cent of companies use AI. Among companies that use AI or are planning or discussing it, 11 per cent already use AI agents, 29 per cent plan to and 31 per cent are discussing it.
According to the same survey, AI is used most often in customer contact, for example handling enquiries (72 per cent of AI users), and in marketing and communications (54 per cent). These are natural areas for agents too, because many processes consist of several similar steps: read an enquiry, look up the customer record, prepare a draft reply, suggest an appointment.
As a rule of thumb, Anthropic recommends agents for problems where the number of steps cannot be predicted and a fixed path cannot be hard-coded. For recurring tasks that always follow the same route, a fixed workflow is usually the better choice. Good candidates in a company are therefore tasks where information has to be gathered from several sources and assessed before a person decides.
of German companies that use, plan or are discussing AI already use AI agents.
Where are the limits and risks of AI agents?
The biggest risk arises when an agent is allowed to do more than its task requires. The security organisation OWASP lists this as “Excessive Agency” in its 2025 top ten risks for applications built on large language models. It names three causes: tools with unnecessary functions, permissions that are too broad, and high-impact actions without human approval. OWASP recommends keeping permissions to the minimum and requiring a person to approve high-impact actions.
The second risk is manipulated input. Number one on the same OWASP list is prompt injection. In its indirect form, an attacker hides instructions in content the agent reads later, such as a web page or a file. Germany's Federal Office for Information Security (BSI) calls indirect prompt injection an intrinsic weakness of language models built into applications. The more an agent reads and the more it is allowed to do, the more this matters.
Third, not everything labelled an agent is one. The research firm Gartner calls this “agent washing”: existing products such as AI assistants, robotic process automation or chatbots are rebranded without substantial agent capabilities. Gartner estimates that only about 130 of the thousands of vendors calling themselves agentic AI providers offer the real thing.
Finally, there are legal duties in the EU. Since 2 August 2026, Article 50 of the AI Act requires AI systems that interact directly with people to inform them that they are dealing with an AI, unless that is obvious. What this means for chatbots and agents in customer contact is covered in our article on AI disclosure for chatbots.
What do companies underestimate when they build an AI agent themselves?
Putting together a first agent does not take long these days. Running one reliably in day-to-day operations is a different job. In June 2025 Gartner predicted that more than 40 per cent of agentic AI projects will be cancelled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls.
The effort goes into data and integration, not the model. In the Bitkom survey from September 2026, AI users named infrastructure such as cloud and computing power (51 per cent), data preparation (50 per cent) and integration with existing systems (41 per cent) as major cost items. An agent working with outdated or scattered data will make poor decisions, however good the model is.
More autonomy costs time and money. Anthropic points out that agentic systems often trade latency and cost for better results, and advises starting with the simplest solution and adding complexity only when it is needed. Not every task needs an agent.
Permissions and approvals are planned too late. Which systems may the agent read, which may it change, and what must it never do without sign-off? These questions belong at the start, not the end. Then there are questions a prototype never raises: where does the data live, what happens when the AI provider changes its prices or models, and who on the team understands what the agent is doing? Building that understanding is what our AI training is for, and our article on the AI literacy obligation under Article 4 explains the legal side.
How can you tell whether an AI agent is worth it for your business?
The fastest way to find out is to look at a specific process rather than the technology. Pick a task that comes up regularly, involves several steps and several systems, and currently ties up skilled staff. Describe what a good result looks like and at which point a person has to decide. If the whole process can be defined in advance, conventional automation is often enough.
If an agent does make sense, the framework it runs in is what counts. Our AI agent system for businesses is built for exactly this: it runs on your own server, is not tied to a single AI provider, works with the software you already use and knows how your business operates. Before anything leaves your company, a person signs it off.
If you first want to understand what AI can do in your team's daily work, start with AI training for your team. That way, your decision about an agent rests on your own experience rather than on marketing promises.
Frequently asked questions
What are AI agents in simple terms?
AI agents are programs that use a language model to pursue a goal and carry out several steps on their own to reach it. They use tools such as databases, search or business software and check after each step whether they are getting closer to the goal.
What is the difference between an AI agent and a chatbot?
A chatbot answers questions and then waits for the next input. An AI agent completes a task over several steps, uses tools along the way and decides on the next step itself, within the limits it has been given.
Is every AI automation an AI agent?
No. If a task follows a fixed, predefined path, it is better described as a workflow. An agent decides for itself which steps to take and in what order. Gartner also warns about “agent washing”, where products without real agent capabilities are marketed as agents.
What are examples of AI agents in a business?
Good fits are tasks that require information from several sources, such as reading incoming enquiries, looking up customer records and preparing a draft reply. According to Bitkom, companies in Germany use AI most often in customer contact and in marketing and communications.
Can I build an AI agent myself?
You can build a simple agent quickly with today's tools. The hard part is running it reliably: clean data, integration with existing systems, tightly scoped permissions, human sign-off and testing with real cases. Anthropic advises starting with the simplest solution that works.
May an AI agent talk to customers without saying it is an AI?
Not in the EU, unless it is obvious to the customer. Since 2 August 2026, Article 50 of the AI Act requires that people be informed when they interact directly with an AI system.
How to test whether an AI agent fits
- 01
Pick a process
Choose a recurring task with several steps and several systems involved that currently takes up noticeable time.
- 02
Define goal and end point
Describe what a good result looks like and when the task counts as done.
- 03
Settle permissions and approvals
Decide what the agent may read, what it may change and what it must never do without human sign-off.
- 04
Prepare the team
Make sure the people involved understand what the agent does, where its limits are and how to check its output.
An AI agent is only as good as the framework it works in: a clear goal, clean data, tightly scoped permissions and a person who signs off at the moments that matter.
Google spam updateGoogle Spam Update: What Can Your Numbers Really Tell You?
LLM costsLLM Cost Optimization: When a Model Switch Pays Off
Detect AI-written textDetect AI-written text: what AI detectors get wrong
AI agentsAgentic AI Explained: What It Means for Your Business
Google AI ModeGoogle AI Mode: What It Means for Your Website
Structured DataStructured Data: What It Really Does for AI Search
AI AssistantAI Assistant for Business: Types, Uses and Data Protection
GEOE-E-A-T: Trust Signals for Google and AI Search
Local AILocal AI for Business: What “Local” Really Means
GEOAI Crawlers in robots.txt: Managing GPTBot and Co.
AI for SMEsAI for SMEs: How to Introduce AI Step by Step
Perplexity SEOPerplexity SEO: How to Get Your Site Cited as a Source
ChatGPT SEOChatGPT SEO: How to Get Your Business Found in ChatGPT
llms.txtllms.txt: What the File Does and When It Pays Off
AI SEOAI SEO: What Changes Compared to Traditional SEO
AI OverviewsGoogle AI Overviews: How Google Picks Its Sources
GEO vs AEO vs LLMOGEO vs AEO vs LLMO: The AI Search Terms Explained
Measure AI VisibilityMeasure AI Visibility: Method, Metrics and Limits
ChatGPT AdsChatGPT Ads: How to Advertise on ChatGPT in Germany
AI Literacy ObligationAI Literacy Obligation: What Article 4 Requires Since 2026
AI DisclosureAI Chatbot Disclosure: Article 50 in Practice
AI Text WatermarkAI Text Watermark: What Claude Marks and What It Doesn't
ShopwareShopware Plugin Development: Buy or Build? A Guide
Where the information on this page comes from
- Anthropic: Building effective agentsaccessed 25 Sep 2026
- Spring: Building Effective Agents with Spring AIaccessed 25 Sep 2026
- Cobus Greyling: Anthropic's Research on GenAI Building Blocksaccessed 25 Sep 2026
- IBM: What are AI agents?accessed 25 Sep 2026
- Google Cloud: What are AI agents?accessed 25 Sep 2026
- Bitkom: Erstmals nutzt die Mehrheit der Unternehmen KIaccessed 25 Sep 2026
- ComputerBase: Mehrheit der deutschen Unternehmen setzt inzwischen KI einaccessed 25 Sep 2026
- retail-news: Erstmals setzt die Mehrheit der deutschen Unternehmen KI einaccessed 25 Sep 2026
- Gartner: Over 40% of Agentic AI Projects Will Be Canceled by End of 2027accessed 25 Sep 2026
- RCR Wireless: More than 40% of agentic AI projects will fail by 2027accessed 25 Sep 2026
- AI Hero: Anthropic thinks you should build agents like thisaccessed 25 Sep 2026
- MarTech: Gartner, 40% of agentic AI projects will failaccessed 25 Sep 2026
- OWASP: LLM06:2025 Excessive Agencyaccessed 25 Sep 2026
- OWASP: LLM01:2025 Prompt Injectionaccessed 25 Sep 2026
- Gravitee: OWASP Top 10 for LLM Applications (2025)accessed 25 Sep 2026
- BSI: Indirect Prompt Injections, intrinsische Schwachstelle in anwendungsintegrierten KI-Sprachmodellenaccessed 25 Sep 2026
- sequire: BSI warnt vor Indirect Prompt Injectionaccessed 25 Sep 2026
- EUR-Lex: Verordnung (EU) 2024/1689 (KI-Verordnung)accessed 25 Sep 2026
- Bundesnetzagentur: Transparenzpflichten nach der KI-Verordnungaccessed 25 Sep 2026


