An AI agent is a piece of software, usually built on a large language model, that is given a goal rather than a single question and works out the steps to reach it. It can use tools along the way, such as searching the web, reading files, querying a database or acting in another app, and it checks its own progress before deciding what to do next.
How an AI agent works
A chatbot answers what you ask. An agent keeps going until the job is done or it gets stuck. Most agents run a loop:
- Read the goal and any instructions, such as “find every page on our site with a missing meta description and draft one for each”.
- Plan a first step and choose a tool to carry it out.
- Look at the result, decide whether it worked, and choose the next step.
- Stop when the goal is met, a limit is reached or a person needs to approve something.
The tools are what make an agent useful. The model asks for an action through function calling, and standards such as the Model Context Protocol let one agent connect to many services, from a spreadsheet to an analytics account. What the agent can do is set entirely by which tools it has and what permissions those tools carry.
Why it matters
For a UK business, agents matter in two directions. Inside the business, they can take on multi-step work that used to need a person clicking through several systems: pulling last week’s ad spend and enquiries into one summary, checking a site for broken links, or drafting first versions of product descriptions from a spreadsheet of specifications. The gain is in tedious, well-defined tasks, not in judgement.
Outside the business, agents increasingly act for customers. At the time of writing (October 2026), several AI assistants can browse websites, compare options and in some cases start a purchase or booking on a person’s behalf. A site with clear prices, readable product information and forms that work without tricks is easier for those agents to use, which is the same thing that makes it easier for people.
The risks are real. An agent that can send emails, change ad budgets or edit a live website can make expensive mistakes quickly. Agents can also be manipulated by instructions hidden in the pages or documents they read, a problem known as prompt injection. And any personal data an agent handles is covered by UK GDPR in exactly the same way as data handled by a person.
Common mistakes
- Giving an agent write access to live systems, such as an ad account or a CMS, before it has proved itself on read-only tasks.
- Handing over a vague goal like “improve our SEO” and expecting a sensible result.
- Skipping a human review step for anything customers will see or anything that spends money.
- Letting an agent read untrusted content, such as emails from the public, while it holds permission to act.
- Not keeping a log of what the agent did, so nobody can work out what went wrong afterwards.
How to act on it
Start with one repetitive task that has a clear finish line and a result you can check in minutes. Give the agent the narrowest permissions that will do the job, read-only where possible, and have a person approve every output for the first few weeks. Keep a record of time saved and errors caught, and expand only when the numbers justify it.
Check your privacy notice and supplier contracts before an agent touches customer data. If you want help deciding where agents fit in your marketing and where they do not, that is the kind of question I work through in digital marketing strategy and consulting.
