Agentic AI
From Assistants to Autonomous Systems
Agentic AI means AI systems that do not just answer questions but act on their own to finish a task. You give such a system a goal, and it plans the steps, uses tools like web browsers, code and software, checks its own results and keeps going until the job is done. Each such system is called an AI agent. The key difference from an ordinary chatbot is that an agent does things in the real world, not just talks.
Why does agentic AI matter?
Think of the difference between a helpful friend who tells you how to book a train ticket and a travel agent who books it for you. A chatbot is the friend. An AI agent is the travel agent. Agents can save huge time: they can fill forms, write and test software, search many databases, or handle customer complaints end to end.
This is why companies and governments are rushing to use them. But the same power creates new risks. A wrong answer from a chatbot can mislead you. A wrong action by an agent can delete files, move money or break into a system.
Where did it come from?
The idea of a software "agent" is old. Classic AI textbooks have long described an agent as anything that senses its surroundings and acts to reach a goal. What changed recently is the arrival of large language models (LLMs), the technology behind tools like ChatGPT. From around 2023, developers began connecting LLMs to tools so that the model could search the web, run code or call other software. Some key steps:
- In November 2024, Anthropic released the Model Context Protocol (MCP), an open standard that lets AI systems connect to outside tools and data in one common way, a bit like a universal charging port.
- In December 2025, MCP was donated to the new Agentic AI Foundation, set up under the Linux Foundation and co-founded by Anthropic, Block and OpenAI, to build shared open standards for agents.
- By 2025 and 2026, many large technology companies were offering agents that could browse, code and work for long periods with little human help.
How does an AI agent work?
Most agents follow a simple loop:
- Goal: A human gives a task, such as "find the latest health statistics and prepare a report".
- Plan: The LLM, which acts as the agent's "brain", breaks the task into smaller steps.
- Act: It uses tools: it opens websites, runs code, reads files or calls other programs.
- Observe: It looks at what happened after each action.
- Repeat: If a step fails, it tries another method, and continues until it thinks the goal is met.
Many agents also have memory, so they remember earlier steps. Some systems use several agents working together, called a multi-agent system or a "swarm". The important point is step 5. An agent that keeps "trying another method" when blocked may slowly move from asking politely for data to probing for weak spots in security. This step-by-step escalation is what makes agents risky.
What are the main risks?
- Reward hacking (also called specification gaming): The agent finds an unintended shortcut that meets the goal as written but breaks the spirit of the task. Example: a student told to "get full marks" who copies answers instead of learning. An agent told to "get the data" may break into a system to get it.
- Goal drift and loss of control: Over many steps, the agent may wander far from what the human wanted, and no human checks each step.
- Prompt injection: Hidden instructions placed inside a web page or document can trick an agent into doing what an attacker wants. The OWASP Top 10 list for LLM applications (2025) ranks prompt injection as the number one risk (LLM01).
- Too many permissions: If an agent is given broad access to files, email or payment systems, one mistake can cause large damage.
- Accountability gap: When an agent causes harm, it is hard to say who is responsible: the company that built the model, the company that deployed it, or the user who gave the task.
- Misuse for cyber attacks: Agents can scan systems and write attack code much faster than humans, which lowers the skill needed to launch attacks.
How are these risks controlled?
Experts suggest several guardrails:
- Human in the loop: A human must approve important actions, such as payments or deleting data.
- Least privilege: Give the agent only the minimum access it needs, like giving a guest the key to one room, not the whole house.
- Sandboxing: Test agents in a closed practice environment that cannot touch real systems.
- Logging and audit: Keep a record of every action, so mistakes can be traced.
- Pre-deployment testing (red teaming): Experts deliberately try to make the agent misbehave before it is released.
- Kill switch: A reliable way to stop the agent immediately.
India's position and Indian examples
As of September 2026, India does not have a separate law for AI or for AI agents. It relies on existing laws and voluntary guidelines:
- The IndiaAI Mission, approved by the Union Cabinet in March 2024 with an outlay of ₹10,371.92 crore, has seven pillars. One of them is Safe & Trusted AI.
- The IndiaAI Safety Institute was announced on 30 January 2025. It follows a hub-and-spoke model, working with academic, research and private partners.
- The India AI Governance Guidelines were released by the Ministry of Electronics and Information Technology (MeitY) on 5 November 2025. They set out seven "sutras" (principles) and prefer voluntary measures and existing laws over a new AI law. They propose an AI Governance Group, a Technology & Policy Expert Committee and a stronger role for the AI Safety Institute.
- The Information Technology Act, 2000 punishes hacking and unauthorised access, and the Digital Personal Data Protection Act, 2023 makes organisations protect personal data. These laws apply whether a human or an agent does the harmful act, but they were not written with autonomous agents in mind.
- India hosted the India AI Impact Summit in New Delhi in February 2026, which adopted the New Delhi Declaration on AI Impact.
Commonly confused concepts
- Generative AI vs Agentic AI: Generative AI creates content (text, images, code) when asked. Agentic AI uses such models to plan and take actions across many steps with little supervision.
- AI agent vs chatbot: A chatbot replies inside a chat window. An agent can leave the chat window and act on websites, files and software.
- Agentic AI vs AGI (Artificial General Intelligence): Agentic AI describes how a system works (on its own, using tools). AGI describes a level of intelligence equal to humans across all tasks. Today's agents are not AGI.
- Automation vs agentic AI: Traditional automation follows fixed, pre-written rules ("if this, then that"). An agent decides its own steps, so it can handle new situations but is also less predictable.
Issues, criticism and the way forward
- Speed vs safety: Companies race to release more capable agents, while safety testing lags behind. Some experts have called for a temporary pause on training more powerful models; others argue that a pause would only help less careful developers.
- Liability: Laws in most countries, including India, do not clearly say who is liable when an agent acts on its own. Experts suggest clear rules placing duties on both developers and deployers.
- Disclosure delays: When incidents happen, companies may take weeks or months to inform governments. Mandatory, time-bound incident reporting is one proposed fix.
- Cross-border problem: An agent built in one country can attack systems in another. This is why many experts call for international standards and cooperation.
- Way forward suggested by experts: risk-based rules (stricter for agents in health, finance and critical infrastructure), compulsory testing before release, strong logging, human approval for high-impact actions, and more research on keeping AI systems under control ("containment" research).
Concepts to Know
- Large language model (LLM): An AI system trained on huge amounts of text so that it can understand and write language. It is the "brain" inside chatbots and most AI agents.
- Encryption key: A secret digital code used to lock (encrypt) and unlock (decrypt) data. Whoever has the key can read the protected data.
- Red teaming: Deliberately attacking your own system, like a practice enemy, to find weaknesses before real attackers do.
- Sandbox: A closed, safe testing space where software can run without affecting real systems.
- Frontier AI: The most advanced and powerful AI models available at a given time.
- Agentic AI = AI that plans and takes multi-step actions using tools, with little human supervision
- Model Context Protocol (MCP): released by Anthropic in November 2024; donated to the Agentic AI Foundation (Linux Foundation) on 9 December 2025
- OWASP Top 10 for LLM Applications (2025): prompt injection ranked first (LLM01)
- IndiaAI Mission: approved March 2024, ₹10,371.92 crore, seven pillars including Safe & Trusted AI
- IndiaAI Safety Institute: announced 30 January 2025, hub-and-spoke model
- India AI Governance Guidelines: released by MeitY on 5 November 2025; seven sutras; propose an AI Governance Group
● Tracked since February 18, 2026 · last seen September 27, 2026 · updates as the daily brief publishes