← Back to concepts
8 min read

Agentic AI

Agentic AI describes AI systems that act with a degree of autonomy: they can plan, make decisions, use tools, and pursue a goal without a human directing every action. It is a descriptive term used loosely, not a formal capability level. Agents describes a specific system built this way. “Agentic” describes the broader style or quality of behavior.

The key distinction is adaptive, goal-directed control. The next step depends on what just happened, not only on a fixed script. A system can take many steps and still be only lightly agentic if every step was predetermined. A shorter system can feel more agentic if it chooses tools, changes plan, or asks for new context based on observations.

You can build an AI feature that is not agentic at all — for example, a single prompt that summarizes a document. You can also build something highly agentic — a system that plans a research task, checks its own work, and adjusts its plan as it learns new information.

Agentic as a spectrum

Agentic behavior is not all-or-nothing. It helps to think of it as a spectrum:

  • Not agentic: one input, one output. A prompt that classifies an email as spam or not.
  • Lightly agentic: a fixed number of steps, like retrieve-then-answer.
  • More agentic: the system decides how many steps to take, which tools to use, and when it is done.
  • Highly agentic: the system sets sub-goals, evaluates progress, and can change its plan when things do not go as expected.

Most real products sit somewhere in the middle. Production systems are bounded even when they feel highly autonomous. They still have budgets, permission limits, approval gates, and stop rules.

Agentic AI as a spectrum of autonomy Four cards show increasing agentic behavior from left to right. Not agentic is one input and one output. Lightly agentic is a fixed retrieve then answer workflow. More agentic chooses tools and the number of steps. Highly agentic sets sub-goals, checks progress, and changes plan. A bottom arrow marks autonomy increasing, while a note says control work also increases. Illustrative spectrum; real products often sit between these points. Not agentic one input one output classify an email or summarize once Lightly agentic fixed steps limited choice retrieve then answer More agentic chooses tools and step count search, inspect, then decide Highly agentic sets sub-goals checks progress changes plan when evidence changes autonomy increases As autonomy rises, the system needs stronger limits, review, and tests.
Agentic AI is better understood as a degree of autonomy than as a yes-or-no category.

Behaviors like sub-goals, progress checks, and retries may be implemented by the host workflow, not only by the model. The model may provide reasoning or tool choices, while the surrounding software enforces policy.

Dimensions of agency

Agency is not one dial. A system can be high on one dimension and low on another:

  • Autonomy: how much it can do without asking.
  • Tool access: what systems it can read or call.
  • Authority: what it may change, such as read-only data, drafts, production records, or money.
  • Planning horizon: how many steps it can plan and revise.
  • Adaptability: how much the next step can change when observations change.

For example, a research assistant may have high tool access and a long planning horizon, but only read-only authority. A deploy bot may have high authority to change infrastructure, but low autonomy because it follows a fixed checklist and requires approval.

Agency is a set of separate dials Two example systems are compared across five dimensions. The research assistant has high autonomy, high tool access, low authority, high planning horizon, and high adaptability. The deploy bot has low autonomy, medium tool access, high authority, low planning horizon, and low adaptability. The diagram shows that a system can be highly agentic on one dimension and tightly bounded on another. Illustrative levels, not measured scores RESEARCH ASSISTANT DEPLOY BOT Autonomy Tool access Authority Planning horizon Adaptability Flexible, but read-only authority Powerful, but tightly gated
Agency is a design profile: high autonomy is very different from high authority.

What makes a system feel agentic

A few qualities tend to show up together in agentic systems:

  • Goal-directed behavior: the system works toward an outcome, not just a single response.
  • Multi-step reasoning: it takes more than one action to get there.
  • Tool use: it can search, call APIs, or otherwise affect the world.
  • Adaptability: it changes its approach based on results, not just a fixed script.
  • Some degree of self-monitoring: it can notice when something did not work and try a different approach.

A system does not need every one of these to count as agentic, but the more of them it has, the more autonomous it feels.

Context engineering also matters. An agentic system needs the right goal, state, tool results, retrieved evidence, and user constraints in context at the moment it chooses the next step.

An example

Consider a system that helps triage bugs. A simple version reads a bug report and suggests a label. A more agentic version might:

  1. Read the bug report.
  2. Search the codebase for related code.
  3. Check recent commits touching that area.
  4. Look for similar past issues.
  5. Propose a root cause and a suggested owner.
  6. Ask a human to confirm before assigning.

The second version is agentic because it decides its own steps based on what it finds, rather than following one fixed path. Its behavior depends on a designed agent loop that keeps choosing the next useful step.

How an agentic bug triage system changes steps as it learns A bug report starts a multi-step path. The system reads the report, searches the codebase, checks recent commits, looks for similar issues, and proposes a root cause and owner. Each result changes the next step: a checkout error points to payments code, a recent auth commit changes the suspect area, and a past issue adds evidence. A final human confirmation gate appears before assigning the issue. Goal Triage bug: "checkout fails after login" Read report finds checkout and login clues Search code payment path touches auth Check commits recent auth change found Find issues similar login bug last month Propose owner and root cause evidence changes the next step Human confirmation gate assign only after review
The agentic version is not just more steps; it chooses later steps based on evidence from earlier ones.

Why agentic AI is appealing

Agentic systems can handle work that is hard to script in advance. Real tasks are often messy — the right next step depends on what was just discovered. A rigid, single-pass workflow struggles here. An agentic system can explore, adjust, and recover partway through.

This makes agentic AI attractive for research, coding, operations, and support — anywhere the path to a good outcome is not known upfront.

The trade-offs

More autonomy means less predictability. An agentic system might:

  • Take an unexpected path to reach a goal.
  • Use more time and cost than a simple workflow would.
  • Make a mistake that compounds across several steps before anyone notices.
  • Take an action a human would not have approved.

These risks grow as autonomy increases. A system that can only read data is safer than one that can also send emails, spend money, or modify production systems.

Evaluate agentic systems with outcome and control metrics, not only answer quality. Track task success rate, human intervention rate, average steps and cost, unsafe-action rate, and how often the system stops too early or runs too long. Saved traces make it possible to replay old tasks after changing prompts, tools, or models.

Designing agentic systems responsibly

Teams building agentic AI usually add limits rather than granting unlimited freedom:

  • Start with the least autonomy needed for the task, and add more only when justified.
  • Require approval before high-impact actions with human-in-the-loop AI.
  • Set boundaries on time, cost, and number of steps through harness engineering.
  • Log every decision and action for review.
  • Test the system against realistic failure scenarios, not just the happy path.

Agentic does not have to mean unsupervised. Many production systems are agentic within a constrained space, with humans checking in at key moments.

Security gets more important as autonomy rises. Tool outputs, web pages, and files can carry prompt injection; prompt engineering covers the basic pattern. More autonomous systems also need defenses against data exfiltration, privilege escalation, and unsafe code execution. Use least-privilege tools, sandbox risky actions, and keep secrets out of model context.

Responsible boundaries around an agentic system A central agentic system card contains plan, use tools, adapt, and self-check. Around it are five boundary cards: permission scope, step and cost budget, approval gates, logs and traces, and failure tests. A strong arrow shows useful autonomy inside the boundary, while a warning card on the right lists unexpected path, compounding mistake, and high-impact action as risks that grow without controls. Agentic system plan + use tools + adapt toward a goal autonomy inside a boundary Permission scope read-only or limited write Step and cost budget hard ceilings Approval gates human checks impact Logs and traces review every decision Failure tests try unhappy paths Risks without controls unexpected path compounding mistake high-impact action
Responsible agentic design grants only the autonomy the task needs and surrounds it with limits, review, and evidence.

The key idea

Agentic AI refers to systems that plan, decide, and act across multiple steps toward a goal, rather than producing a single fixed response. The more agentic a system is, the more valuable it can be for complex, unpredictable tasks — and the more carefully it needs boundaries, oversight, and testing.