Treadstone Associates
Ask an Expert · 3 min read

Can AI work across two different apps?

Yes — it is usually done through “tool use,” where the AI is given a defined set of actions in each app and calls them itself.

Treadstone Associates · Updated 2026

Short answer

Yes. The AI is given a defined set of actions it is allowed to take in each app — look up a record, create an event, send a message — and it decides mid-conversation which of those actions to call, instead of a person copying information between two open windows.

How the connection actually works

The mechanism has a name in the model-provider documentation: tool use, also called function calling. Anthropic’s own developer documentation describes it plainly: “Tool use (also called function calling) lets Claude call functions that you define or that Anthropic provides. Claude determines when to call a tool based on the user’s request and the tool’s description. It then returns a structured call that your application executes (client tools) or that Anthropic executes (server tools).” Bridging two apps, in this framing, is just two tools defined side by side — one wrapping App A’s API, one wrapping App B’s — with the model deciding when each one fires. This is vendor documentation describing what the product can do, not a Canadian regulatory statement, and it should be read that way.

Why defining the task matters more than the plumbing

The wiring between two APIs is the easy part; deciding what the connection is actually for is the part that determines whether it behaves well. The U.S. National Institute of Standards and Technology’s AI Risk Management Framework — the standard Canada’s own privacy regulators point to when assessing an AI tool — opens its risk-mapping function with exactly that requirement: “Map 1: Context is established and understood.” The same subcategory calls for intended purposes, uses and deployment settings to be “understood and documented” before anything runs. Canada’s federal, provincial and territorial privacy commissioners cite this same NIST framework in their own joint generative-AI principles as the reference for evaluating whether a tool is valid and reliable for its intended purpose — so the Canadian anchor for “define the task first” exists even though NIST itself is a U.S. standard.

A concrete shape: an agent reads a new lead recorded in a CRM and creates a matching event on a calendar — two tools, each defined narrowly, each firing only when its own criteria are met. Every action still needs the same access-scoping and accountability treatment as any other connected credential — see whether AI can log into your systems — and see what an integration actually does in plain terms.

Connecting two systems through an AI layer?

See how these connections get scoped, tested and handed over.