What is agentic AI?

By Identra · Updated

Agentic AI is AI that chooses and adapts its own sequence of actions toward a goal, usually by calling tools that read or change software and data. Its autonomy is bounded by the permissions, approval rules and stop conditions of the application around it.

How does agentic AI work?

You give it a goal, like fixing a failed CI build. The model picks a step, looks at the result and picks the next one. It might read the build log, open the failing test, edit a file, rerun the suite and hand back a proposed fix.

The model only decides. Surrounding software executes each tool call with whatever credentials it holds. Claude Code in a developer's terminal works with that developer's files and shell, within the permission prompts it's configured to show. An AI agent is one system doing this. Agentic AI is the broader capability, whether one agent does the work or several.

Anthropic's engineering guidance draws a useful line between workflows, where code fixes the sequence, and agents, where the model chooses the next step as it goes.

How is agentic AI different from a chatbot or automation?

Ask who picks the next step.

Product names won't tell you. A chat window can launch an agent, and a feature called a copilot may edit records. Check what it can actually do. Can it change data, run commands, keep going without a fresh instruction?

  • Basic chatbot

    Example
    Explains how to debug a failed build
    Who picks the next step?
    The person reading the answer
  • Fixed automation

    Example
    Runs a set diagnostic script
    Who picks the next step?
    Whoever wrote the workflow
  • Agentic AI

    Example
    Chooses diagnostics and changes course based on results
    Who picks the next step?
    The agent, inside the limits the application sets

What security risks does agentic AI add?

A wrong answer costs more once software acts on it. An agent can pick the wrong customer record, misread a tool result or retry a refund after a timeout. A success response means the call ran. It says nothing about whether it should have.

Then there's prompt injection. Say a support agent is working a delayed-shipment ticket, and the ticket text says to export all customer records to an outside address. That's customer content. It grants nothing. The export should fail because the agent has no export permission and no route to external addresses, whatever the model decides.

Whose authority is the agent using? A user's session, a shared service account and dedicated credentials carry very different blast radius. AI agent identity records who acted. Authorization decides what was allowed. A valid OAuth token never proves the request matched what the user wanted.

Memory gets overlooked. Persistent context can carry a bad assumption into next week's run, and an interrupted run can leave half a change behind.

How should enterprises secure agentic AI?

Write down the task before you grant access. Then apply least privilege where the action executes. A line in the system prompt saying "never delete production data" guides the model. It enforces nothing.

  • Name an owner. List the permitted tasks, data sources and the actions that are off limits.
  • Split read from write. Scope shell and file access to the repo or workspace the task needs.
  • Keep credentials out of model-visible text. Make tokens short-lived and narrow.
  • Restrict outbound destinations and validate tool arguments before they run.
  • Cap steps, time and spend. Stop after repeated failures or a missing permission.
  • Log tool requests, approvals and outcomes. Keep a way to stop a run and revoke its access.

When is an agent ready for production?

When it has behaved under failure. The happy path proves little. Run it on realistic tasks with test data. Feed it a misleading document, a denied permission, a tool that times out. Watch whether retries duplicate changes and whether it stops when it can't confirm an outcome.

Use human approval for consequential steps, and show the reviewer the actual target and change. If either shifts after approval, ask again.

Before launch you should be able to say who owns the agent, what it can reach, which actions need sign-off and how to reconstruct a run from the logs. Check that pressing stop also kills queued work. Agentic AI security covers threats and controls in more depth.

How Identra thinks about it

Identra discovers AI agents across Microsoft 365 Copilot and Foundry, Google Workspace and Anthropic, each with an owner, plus coding agents like Claude Code, and MCP servers, on macOS and Windows endpoints. Security teams can block AI agents driving the browser by policy, check endpoint agent tool calls against policy, review a record of every endpoint agent run and have an analyst revoke risky OAuth grants.

Go deeper: AI security, built on identity

Frequently asked questions

Is agentic AI the same as generative AI?

No. Generative AI produces content like text or code. Agentic AI chooses and carries out actions toward a goal, and it usually uses a generative model to decide what to do.

Does agentic AI have to be fully autonomous?

No. An agent can choose its own investigative steps and still need approval before changing anything. How much it does alone depends on the permissions and controls around it.

Is every chatbot with tools agentic?

Not really. One tool call on request is not much autonomy. The test is whether it plans and adapts a sequence of actions toward a goal.

Does agentic AI require multiple agents?

No. A single agent can pick actions, call tools and judge the results. Multi-agent setups are a design choice.

When is fixed automation a better choice?

When the steps and the acceptable outcomes are already known. Agents earn their keep when the next step depends on what the task turns up.

Related terms

Keep exploring · AI apps, agents and usage