One produces an answer. The other decides what to do next. The gap between them is not a marketing distinction — it is the difference between a tool a person still reads before anything happens, and one that acts on its own.
Key takeaways
Canada’s Cyber Centre defines the mechanism plainly: generative AI is a type of AI that generates new content by modelling features from large datasets that were fed into the model. By contrast with pattern-recognizing systems, it adds that generative AI can create unique content in many forms, including text, image, audio or software code. The output is the end of the process — the system hands back text, an image or code, and a person reads it, edits it, or acts on it. Nothing in that definition involves the system doing anything beyond producing the content itself.
A generative tool can be extraordinarily capable within that boundary — drafting a contract clause, summarizing a call, writing code — and still never once take an action in a system outside the conversation itself. Everything it produces is inert until a person or a separate piece of software does something with it.
An agentic system is given a further capability on top of generation: the ability to call defined tools or functions and decide, step by step, whether and how to use them, rather than only returning text for a person to act on. Anthropic’s own developer documentation describes the mechanism for its Claude models this way: tool use (also called function calling) lets Claude call functions that you define or that Anthropic provides. Claude determines when to call a tool based on the user's request and the tool's description. That single sentence is the whole distinction — the system is no longer just answering, it is choosing an action and then an external system carries it out.
Crucially, the model itself never directly touches your CRM, your inbox or your calendar. What actually happens is that the model decides which predefined action applies and produces a structured instruction describing it; a separate piece of software then carries that instruction out. The “agent” part of agentic is that decision step, not the execution — which matters because it is also the point where a business can choose to insert a review before the instruction is carried out.
A purely generative answer still passes through a human checkpoint before anything happens in the world — a person reads the draft email before it is sent. An agentic system can skip that checkpoint by design, which is exactly why the checkpoint matters more once it is removed. Canada’s privacy principles for generative AI put the underlying expectation this way: organizations should ensure that impacted individuals are provided with an effective challenge mechanism for any administrative or otherwise significant decision made about them, and should go on to allow them the opportunity to request human review of that decision. That expectation assumes a person is available to review and, if needed, reverse a significant decision. An agentic tool that acts without pausing for that review has removed the very step the principle is built around, which is a reason to design the review back in deliberately rather than a reason the principle no longer applies.
This is also why the two categories carry different failure modes. A generative system's worst-case failure is a bad draft — wasted time, at most, before a person catches it. An agentic system's worst-case failure is a bad draft that gets acted on before anyone reads it: an email that goes out, a record that gets changed, a booking that gets made, none of which is trivially reversible the way deleting an unsent draft is.
Canada’s voluntary code for advanced generative AI systems commits developers to the same continuing check from the other side of the relationship: to monitor the operation of the system for harmful uses or impacts after it is made available, including through the use of third-party feedback channels, and inform the developer and/or implement usage controls as needed to mitigate harm, under its Human Oversight and Monitoring principle. That commitment exists precisely because an agentic system can act between one human review and the next; oversight has to continue after deployment, not stop once a demo passes. treadstonelaw.ca’s case study on an AI scheduling tool brought into a small business covers the contract-review side of the same problem: who is liable when the tool acts and gets it wrong.
Official risk-management guidance already treats “generative” as one category of task among several a single AI system might perform. The NIST AI Risk Management Framework’s categorization step states that the specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders) — classifiers and recommenders sit in the same list as generative models, as different jobs a system can be built to do, not as competing definitions of what AI is.
In practice, most tools businesses actually buy blend the two. An inbox assistant might draft a reply to a client — a generative step a person reviews before sending — and, in the same interaction, move that lead to a different pipeline stage or book a follow-up call automatically — an agentic step nobody necessarily reviews before it happens. Those are two different mechanisms bundled into one product, and a business evaluating it should ask which parts of the workflow fall into each category before deciding which ones get a human in the loop.
Consider a customer-service tool that reads an incoming support ticket. Producing a suggested reply for an agent to edit and send is the generative half — the tool never touches the ticketing system directly, and a person remains the last step before anything reaches the customer. If the same tool is also configured to close tickets it classifies as resolved, or to escalate a ticket to a different queue without a person confirming the call, that is the agentic half, and it is doing something structurally different: making a decision that changes a system of record on its own. A business buying “an AI support tool” as a single label is really buying two separate capabilities with two separate risk profiles, and the contract, the testing plan and the sign-off process should treat them as such rather than as one undifferentiated feature.
For the next layer of this taxonomy, see predictive AI vs generative AI and machine learning vs AI vs deep learning.
No. Most chatbots are still generative describe-and-respond systems — they draft a reply and stop there. A chatbot only becomes agentic once it is wired to tools that let it take an action, such as updating a record or booking a slot, on top of drafting text.
No. It is still executing an objective someone configured for it, using tools someone gave it access to. It does not originate intent independent of that configuration — see the understanding myth in common AI myths in business for the related point about what these systems are and are not doing internally.
That is a design choice, not a given. Building the review step back in — a queue the tool populates rather than sends from directly — is how a business restores the checkpoint an agentic system otherwise removes.
Once a tool is taking actions rather than only drafting text, the question shifts to how it connects to the systems it needs to act on. For that, see the three places integrations usually break, and how to avoid them.