An API (Application Programming Interface) is a defined set of requests a piece of software will answer, and the rules for making them — the contract that lets one program, including an AI system, ask another for data or an action without seeing how it works inside.
The standard technical definition, from Mozilla’s developer documentation: “An API (Application Programming Interface) is a set of features and rules that exist inside a software program (the application) enabling interaction with it through software”, which “can be seen as a simple contract (the interface) between the application offering it and other items, such as third-party software or hardware”. An AI agent that “uses a tool” is, underneath, calling an API someone documented and agreed to expose.
When that API carries a Canadian customer’s personal information — a name, an address, a file number — sending it does not make it someone else’s problem. PIPEDA Schedule 1’s accountability clause 4.1.3 is explicit, in full: “An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party”. Wiring a business system to an AI vendor’s API is exactly this kind of transfer: the business stays accountable for what happens to the data on the other side of that call.
A scheduling tool doesn’t retype a client’s address into a mapping service by hand; it calls the mapping provider’s API with the address and gets back coordinates and a travel time in the same request. The API is the documented door the scheduling tool is allowed to knock on — not a shared database the two systems both reach into directly.
See also: what is a webhook, what is tool use in AI, what an integration does, in plain terms.
Deciding which APIs an AI system may call, and with what data, is integration work — ai-integration-automation covers how that connection is actually built.