Learn AI
Agentic AI: what AI agents are, and what they can be trusted with
Agentic AI is the shift from AI that answers to AI that does. A chatbot tells you how to compare three suppliers; an AI agent goes and compares them, builds the spreadsheet and hands it back. That is useful, and it is also why agents need more care than chatbots.
This guide explains what agentic AI means in plain words, which agents you can use today, what they can and cannot be trusted with, and what it means for a South African business.
Agentic meaning: from answers to actions
“Agentic” describes AI that acts as an agent on your behalf. An AI agent works in a loop:
- It takes your goal, such as “find last quarter’s figures and draft a summary”.
- It plans the steps.
- It uses tools: web search, your files, email, a spreadsheet, a browser or code.
- It checks what came back and decides the next step.
- It finishes, or stops to ask you something.
Anthropic describes an agent’s tools in two groups. Read tools let it see things, such as your inbox or a web page. Write tools let it change things, such as sending an email, deleting a file or clicking a button. Write tools carry more risk, which is why Anthropic recommends human oversight for high-stakes tasks.
Everyday examples of AI agents
The vendors’ own examples give a feel for what agents do:
- Research a set of products, write up a comparison and have it ready when you come back.
- Summarise new messages in your team’s channels every weekday morning.
- Pull account history, recent emails and documents into a brief before a customer meeting.
- Sort an inbox, draft replies and flag the threads that need a person.
- Fix a bug in software, run the tests and open a pull request.
AI agents you can use today
| Agent | Company | What it does |
|---|---|---|
| ChatGPT Work | OpenAI | Longer, multi-step work and finished deliverables: research, analysis, documents, spreadsheets and presentations, using connected apps and a browser |
| Codex | OpenAI | Software development in the ChatGPT desktop app |
| Claude | Anthropic | Takes on whole tasks in one conversation, keeps working in the cloud, and returns finished files |
| Claude Code | Anthropic | A coding agent for the terminal, IDEs, the desktop app and the web |
| Microsoft 365 Copilot Cowork | Microsoft | Plans and carries out work across Microsoft 365 apps, pausing for approval before sending an email or making a big update |
| Researcher and Analyst | Microsoft | Built-in Microsoft 365 Copilot agents for research and data analysis |
OpenAI retired its earlier ChatGPT agent and now points people to ChatGPT Work for multi-step tasks. ChatGPT’s pricing page shows limited Work access on the free plan in the desktop app, with more on paid plans. Anthropic merged Claude Cowork into Claude, rolling out first to Pro and Max plans. For coding, our Claude Code guide covers costs and safety settings.
Claude Managed Agents, for developers
Claude Managed Agents is Anthropic’s option for businesses that want to build their own agents. It is a set of APIs that runs Claude as an autonomous agent on Anthropic’s infrastructure, with sandboxed code execution, long-running sessions, scoped permissions and tracing handled for you. Anthropic launched it in public beta on 8 April 2026. Its pricing page lists US$0.08 per session-hour of active runtime, about R1 before VAT, on top of normal token costs.
What agents can and cannot be trusted to do
Agents are good at gathering, summarising, drafting and organising: work where a mistake is easy to spot and cheap to fix. They are not yet safe to leave alone with anything that is hard to undo, such as sending money, messaging customers, deleting records or making decisions about people.
The biggest new risk is prompt injection. An agent that reads the web or your email can meet text written by an attacker to hijack it. OpenAI’s own example is an agent booking a group dinner that reads a malicious comment telling it to fetch a password reset code from your email and send it to a stranger’s website. Anthropic’s example is an email that tells the agent to ignore your instructions and transfer money.
Anthropic says such an attack needs two things at once: the agent can read content from outside your trusted sources, and it can take actions that could harm you. Remove either one and attacks become much harder. The vendors build in safeguards: Microsoft says Cowork pauses for approval before sending an email, and Anthropic says Claude always asks before permanently deleting files. Anthropic and OpenAI both say their safeguards reduce the risk but do not remove it.
South African business examples (hypothetical)
These are made-up examples of sensible first agents:
- A plumbing business in Durban. An agent reads WhatsApp enquiries, drafts a quote from the price list and books a provisional slot. A person approves each quote before it goes out.
- An accounting practice in Pretoria. An agent collects documents clients upload, checks what is missing and drafts a reminder email. Staff send the reminders and never give the agent SARS eFiling logins.
- A guesthouse on the Garden Route. An agent answers availability questions and flags complaints to the owner, but cannot change bookings or issue refunds.
- An online shop. An agent checks stock levels each morning and drafts purchase orders. The owner approves every order before any money moves.
The risks: money, customer data and a person in the loop
- Money. Do not give an agent a card, a banking login or a payment tool without spending limits and human approval. Anthropic warns that scheduled tasks run while you are not watching, so avoid scheduling anything that spends money or sends messages on your behalf.
- Customer data and POPIA. If an agent handles customers’ personal information, your business stays the responsible party. POPIA section 71 limits decisions with legal consequences, or that affect someone substantially, made solely by automated processing of their personal information. If the agent runs on servers abroad, section 72’s rules on cross-border transfers apply too. Our guide to AI and POPIA covers the basics.
- A person in the loop. Decide in advance which steps need approval, keep a log of what the agent did, and start with manual approval for anything new. Loosen it only once the agent has earned it.
If you want an agent built around your own systems with these controls in place, that is what Zaiq’s AI automation work covers.
Related guides
Questions people ask
What does agentic AI mean?
Agentic describes AI that acts on your behalf. Instead of giving one answer and stopping, an AI agent takes a goal, breaks it into steps, uses tools such as web search, files, email or a browser, checks the results and carries on until the task is done or it needs your input.
What is the difference between an AI agent and a chatbot?
A chatbot answers what you ask, one message at a time, and you do the work with its answer. An AI agent does the work: it can research, fill in a spreadsheet, draft and file documents or change code across many steps. That makes agents more useful, and also riskier, because they can take actions, not just give advice.
What are some examples of AI agents?
OpenAI's ChatGPT Work handles longer, multi-step tasks and finished deliverables, and Codex does software work. Anthropic's Claude can take on whole tasks and return finished files, and Claude Code works on codebases. Microsoft 365 Copilot Cowork plans and carries out work across Microsoft 365, alongside agents such as Researcher and Analyst.
What are Claude Managed Agents?
Claude Managed Agents is a set of APIs from Anthropic for developers who want to build and run their own agents on Anthropic's infrastructure, with sandboxing, long-running sessions and scoped permissions handled for them. It launched in public beta on 8 April 2026 and costs US$0.08 per session-hour of active runtime, about R1, plus normal token costs.
Is agentic AI safe for a small business?
It can be, with limits. Start agents on low-risk jobs such as research and drafts, give them access only to the files and apps they need, and require a person to approve anything that sends messages, spends money or changes customer records. Agents can be tricked by malicious content, so treat them like a new employee on probation.
Can an AI agent make decisions about my customers?
Be careful. POPIA section 71 says a person may not be subject to a decision with legal consequences, or one that affects them substantially, based solely on automated processing of their personal information, apart from limited exceptions with safeguards. For credit, pricing or eligibility decisions, keep a person making the final call.
Sources
- ChatGPT Work and Codex (OpenAI Help Center)
- ChatGPT agent (OpenAI Help Center)
- ChatGPT pricing (OpenAI)
- Claude Cowork and chat are one Claude (Claude Help Center)
- Use Claude Cowork safely (Claude Help Center)
- Claude Managed Agents: get to production 10x faster (Claude blog)
- Claude Managed Agents overview (Claude Platform Docs)
- Claude pricing (Anthropic)
- Microsoft 365 Copilot Cowork (Microsoft South Africa)
- What's the difference between Microsoft Copilot (free) and Copilot in Microsoft 365 (Microsoft Support)
- Protection of Personal Information Act 4 of 2013 (South African Government)
Checked September 2026. Prices and features change, so confirm on the official site before you buy.