AI Agents: From Answers to Actions
AI agents can do more than answer questions. Learn how they use tools, where the real risks appear, and how to keep humans in control.
An assistant answers. An agent acts.
There is no single universal definition of “agent,” but the practical distinction is straightforward: an agentic system can pursue a goal across multiple steps, choose and use tools, observe what happened, and continue until it reaches a stopping condition.
Understand the goal
The model interprets the user's objective, constraints and available context.
Choose an action
It might search, read a file, query data, call an API, draft an email or ask for clarification.
Observe the result
The tool output becomes new context. The agent checks whether it is closer to the goal.
Continue, ask, or stop
The loop repeats until the task is complete, blocked, or reaches an approval boundary.
Why MCP matters
The Model Context Protocol (MCP) is an open protocol for connecting AI applications to tools and data. Instead of every app inventing a bespoke integration pattern, MCP provides a common interface. The July 2026 specification introduced a stateless protocol core and additional changes aimed at scaling agentic workflows.
Standardization makes integration easier; it does not make every integration trustworthy. Authentication, authorization, data handling and least privilege remain application responsibilities.
The permission problem
The moment an agent can act, mistakes have consequences. A useful design pattern is a permission ladder:
1. Read
Search and inspect only the data needed for the task.
2. Draft
Prepare a proposed action without executing it.
3. Approve
Show the user what will happen, with enough context to judge it.
4. Act
Execute only after the required approval, then log the result.
Four failure modes to expect
- Prompt injection: a webpage, email or document may contain hostile instructions aimed at the agent.
- Excessive permissions: one mistake can become a large incident if the agent can access everything.
- Compounding errors: a wrong assumption early in a multi-step plan can contaminate later actions.
- Tool ambiguity: APIs fail, return partial data or behave differently from the model's expectation.
External content is data, not authority
If an agent reads the web, email, tickets or documents, treat instructions inside that content as untrusted. The agent should follow the user's or system's task — not commands embedded in the material it is processing.
A practical agent checklist
- Can the task be done read-only?
- Does each tool have the minimum necessary scope?
- Are credentials and secrets kept out of model-visible context where possible?
- Are irreversible actions behind explicit approval?
- Can the user see what will be changed before execution?
- Are actions logged and recoverable where possible?
- Have you tested prompt injection and malformed tool outputs?
Primary sources & further reading
For fast-changing claims, prefer primary sources and check their dates.