Most software still has a control flow written by people. A click enters a function and returns a result. An agent hands part of that control flow to a model: look at the goal, then decide whether to search, write code, query a database, or stop.
What an AI agent is
An agent is not a longer prompt. It is a loop. The model proposes an action, the runtime performs it, and the result goes back to the model until the task is done or a boundary is reached.
The boundary matters more than the model. Without a step limit, permissions, and checks, a loop turns one mistake into a sequence of mistakes.
How it differs from a chatbot
A chatbot usually answers once. An agent keeps acting. The first fails by saying something wrong. The second can fail by doing something wrong.
| Chatbot | Agent | |
|---|---|---|
| Control flow | One answer | A loop of steps |
| Tools | Usually none | Search, code, databases |
| Main risk | A wrong statement | A wrong action |
A minimal architecture
Model
The model chooses the next step. It should return a structured action, not touch production systems directly.
Tools
A tool is a capability you explicitly allow. Each one needs a name, arguments, and a result for failure.
Memory
Memory stores what already happened. It is not an infinite transcript. It is the summary the next decision needs.
def run_agent(goal, tools, memory):
steps = []
while len(steps) < 8:
action = model.decide(goal, memory.read(), tools.schema())
if action.type == "finish":
return action.answer
result = tools.call(action.name, action.args)
memory.write({"action": action, "result": result})
steps.append(action)
return memory.summary()
Put RAG back in its place
Retrieval can be a tool inside the loop, or it can happen before the loop starts. Both are valid. Neither one trains the model.
Note
RAG does not train the model. It places retrieved material into the context before an answer is produced.
A model does not become reliable because it sits inside a loop. Reliability comes from what you allow it to do, and from how you check the result.
Boundaries to keep first
Limit the steps, the tools, and the writable surface. Make every action recordable, replayable, and reversible. If ordinary code can make the decision, do not give it to the model.
Conclusion
Agents move the control flow. They do not move the responsibility. The architecture still has to say who may act, how the action is seen, and where a failure stops.
Discussion