Treadstone Associates
Article · 9 min read

What an AI agent actually does

“AI agent” gets used loosely enough across products that the word alone tells you little. The distinction that survives contact with reality is simpler than the marketing: an agent can take an action in another system, not just produce text describing one.

Treadstone Associates · Updated 2026

Key takeaways

  • • The dividing line isn’t intelligence, it’s permission plus a loop — a model that can call a defined tool, see what happened, and decide what to do next.
  • • Canada’s federal and provincial privacy regulators already distinguish “developers and providers” of a generative AI system from “organizations using” one — worth keeping straight before stacking “agent” on top of either role.
  • • An agent inherits whatever access it’s given. The design decision that matters is what it’s allowed to touch, not how capable the underlying model is.
  • • Being able to act and acting correctly are two separate questions — the first is what makes something an agent, the second is what makes it trustworthy.

A chat window has no hands

Canada’s Cyber Centre draws a plain line between two kinds of AI in its own guidance: “traditional AI systems can recognize patterns or classify existing content, generative AI can create unique content in many forms, including text, image, audio or software code.” Neither half of that sentence describes acting on the world. A model that only classifies or only generates text is, by itself, incapable of doing anything to a calendar, a CRM record, or a payment. It can describe an action in convincing detail and never come close to taking one.

That gap is exactly where “agent” earns its keep as a separate word. Something has to sit between the model’s output and the outside system: code that reads what the model proposed, checks it against a defined set of allowed operations, and actually calls one.

What changes when a model can call a tool

Model vendors document this mechanism directly, because it’s the part their customers have to build against. Anthropic’s tool-use documentation separates the job into distinct pieces — defining which tools exist and what parameters they take, handling the specific tool call a model proposes, and running more than one tool call in the same turn where the task calls for it. None of those pieces is the model “deciding” anything in a human sense; each is a defined interface the surrounding program enforces.

The practical shape is a loop, not a single step: the model is given a task and a list of tools it may call, it proposes a call, the surrounding system executes that call and returns the result, and the model continues from there — possibly calling another tool, possibly stopping to hand the result to a person. Strip away any one of those pieces and you’re back to a chat window: no tools, no acting; no observed result fed back in, no loop; no stopping point, no oversight.

Two roles worth keeping separate

Canada’s federal, provincial and territorial privacy commissioners, in their joint principles for generative AI, define two roles before saying anything else: “Developers and Providers” are the “individuals or organizations that develop…or that put such services onto the market,” and a separate category covers “organizations using generative AI.” The document adds that an organization “might shift between or play multiple roles at once.”

Agent behaviour is almost always built by the organization in the “using” role, on top of a model built by a provider. A brokerage that connects a general-purpose model to its own CRM and gives it a defined set of tools has not built a new model — it has built the loop, the tool list and the permission boundary around one. That distinction matters because accountability for what the agent does sits mostly with whoever built the loop and chose what it could reach, not with whoever trained the underlying model.

The loop is doing the agentic work, not the model alone

Once there’s more than one tool, more than one possible next step, or a point where the system has to decide whether to keep going or hand off to a person, the coordinating logic above the individual calls becomes its own design problem — see what orchestration means in AI for how that layer is usually built.

Agents versus scripts

It’s worth being precise about what does not count as agent behaviour, because the word gets applied loosely in the other direction too. A script that always moves a file from one folder to another when a new one arrives is not an agent, no matter how it’s marketed — it has no decision to make, because the same input always produces the same output. The distinguishing feature isn’t whether code executes automatically; a scheduled job does that too. It’s whether the system observes a result it couldn’t fully predict in advance and uses that observation to choose among more than one possible next step. A fixed sequence with no branching, however sophisticated the individual steps, is automation — see how automation and AI fit together for where that line sits in more general terms.

Capable of acting is not the same question as trustworthy

The Cyber Centre’s footnote-16 chain into the NIST AI Risk Management Framework, which Canada’s privacy regulators cite for how to evaluate validity and reliability, is explicit that “accuracy and robustness…can be in tension with one another” in an AI system. Giving a model the ability to act does nothing to resolve that tension — if anything, it raises the stakes of getting it wrong. See where AI agents still fail and why AI agents need guardrails for what follows from that.

A worked example

Take a mortgage brokerage that wants renewal reminders to stop falling through the cracks. A chat-only setup can summarize a renewal date if someone pastes in the details and asks. An agent setup is different in kind: it is given a tool to read a shared inbox, another to check a client record, and a third to draft — but not send — an email. The loop reads a new message, extracts a renewal date, checks it against the client record, and produces a draft; a person still has to approve the send. Every one of those steps is a defined tool call the surrounding program controls. Adding a fourth tool that actually sends the email would change what kind of mistake is possible — from a wrong draft someone catches, to a wrong message that has already gone out — without changing anything about how capable the underlying model is.

Related: for the boundary between a system that only talks and one that also acts, see how AI agents differ from chatbots; for what determines how far an agent’s actions can reach once it is connected to real systems, see what an AI can reach once it’s connected.

Common questions

Is a voice assistant that books an appointment an agent?

By this definition, yes, if it actually calls a calendar tool to create the booking rather than just telling the caller what it would do. A voice interface that only reads back availability and asks the caller to book elsewhere is not acting on the calendar itself, whatever it’s branded as.

Does an agent have to be built on a single model?

No. Orchestration — see what orchestration means in AI — can combine several models and tools behind one workflow. What makes the result an agent is the ability to act via defined tools, not which or how many models sit behind it.

What’s the smallest thing that counts as agent behaviour?

A single tool call whose result the system observes and then uses to decide what happens next — even one step, if the loop can act on what it sees rather than only describing it, crosses the line a plain chat response does not.

Is a scheduled script that runs every night an agent?

No — if it does the same thing on the same schedule regardless of what it finds, it’s automation, not an agent. Add a step where it has to decide among several possible actions based on what it observes, and it starts to cross into agent territory.

See how this plays out once a model is wired into real systems.

The concept is the easy part — the design choices are in what an agent is allowed to reach and who signs off before it acts.