What is agentic AI? It is software in which a language model decides and acts over several steps toward a goal, using tools, with code setting the limits. Agentic is an adjective for how much of the control flow the model owns, and the label is applied to far more systems than fit that description.
If you searched the question this week, I’d guess the word reached you before its meaning did: in a vendor deck, in an analyst headline that got to the board, or on a slide your own company wrote. One forum reader counted. “They refer to their system as agentic 35 times but there is not attempt at explaining what they mean by that” (Hacker News comment, March 2025).
This post is for the meeting that follows. It separates the idea, which is small and real, from the label, which misleads in two directions, and it gives you three questions to ask in a demo without reading any code. The book this site belongs to, AI Agents, Engineered, never uses “agentic AI” as a term of its own. It supplies the question underneath, and I’ll say along the way which parts are the book’s and which are mine.
What is agentic AI, and what does the word claim?
The word claims one thing: a language model chooses some of what the system does next, over more than one step. How much it chooses is left open, which is why agentic works as an adjective and fails as a specification.
Agent is the noun. It names a system in which the model owns the sequence of steps, and the companion post on what an AI agent is gives a five-check test for it. Agentic is the adjective, and adjectives come in degrees. One vendor explainer states the grammar well: “An AI agent is a noun” and “agentic AI is descriptive” (Red Hat, updated May 2026).
What varies is one quantity, which Chapter 1 of the book puts on a dial and names in a clause: “how much of the control flow the model owns,” in the chapter’s words. Control flow is the order in which a program’s steps run. At one end, code fixes every step and a model fills in content; at the other, the model picks each step after seeing the last result.
The adjective was adopted for that looseness. A widely read newsletter argued in June 2024 that “it would be more useful to think of systems as being agent-like to different degrees” (Ng, 2024). Six months later an engineering essay put fixed workflows and agents under one heading: “we categorize all these variations as agentic systems, but draw an important architectural distinction between workflows and agents” (Schluntz and Zhang, 2024).
So a vendor can call a fixed pipeline with two model calls “agentic” and stay inside two respected published usages. The word names a family. You still have to ask which member is in front of you, and the question is Chapter 1’s: “does the model decide the next step, or does code?”
Why do published definitions disagree?
Published definitions disagree because the sources use one word to answer four different questions: whether agentic is a degree or a kind, whether it takes one agent or several, whether a fixed workflow counts, and whether it belongs inside generative AI. The table gives eight examples, each labeled by type and date.
| Source (type, date) | What it says, in its own words | What that makes “agentic” |
|---|---|---|
| Chan et al. (research paper, February 2023) | “Rather than providing a definition of agency as a binary property,” it lists four characteristics that increase agency | A degree |
| Shavit et al. (AI lab white paper, December 2023) | “AI systems that can pursue complex goals with limited direct supervision” | A degree, which the paper calls “agenticness” |
| Ng (practitioner newsletter, June 2024) | “agent-like to different degrees” | A spectrum |
| Schluntz and Zhang (engineering essay, December 2024) | “we categorize all these variations as agentic systems” | An umbrella over workflows and agents |
| AWS (vendor explainer, no date shown, read October 2026) | “an autonomous AI system that can act independently to achieve pre-determined goals” | A kind of system |
| Google Cloud (vendor explainer, updated September 2026) | “a subset of generative AI”; “agentic AI employs multiple agents to handle complex workflows” | Several coordinated agents |
| Red Hat (vendor explainer, updated May 2026) | “Agentic AI refers to the behavioral characteristics of a system.” | A description of behavior |
| Merriam-Webster (dictionary, read October 2026) | “acts autonomously or with little human supervision to complete the tasks necessary to accomplish a goal” | An adjective of autonomy |
Each row shows how one kind of source answered “what is agentic AI” on the date given, and none is endorsed here. The right-hand column is my reading. Three of the eight treat the word as a degree, one as an umbrella that includes fixed workflows, and one reserves it for several agents working together.
One law sidesteps the word. The EU AI Act, a regulation dated June 2024, defines an “AI system” as one “designed to operate with varying levels of autonomy” (Article 3(1), read in an unofficial consolidated edition), which is a degree again.
For the rest of this post I use agentic for the degree and agent for the system where the model owns the path step after step. Whether one agent or several are involved is a separate question, and I leave it aside.
Agentic AI vs generative AI: what changes for the buyer?
The two words answer different questions: generative names what a model produces, which is content, and agentic names who chooses the next step. Every agent this post discusses has a generative model inside it, and what the adjective adds is the loop and the tools around that model. Chapter 1 says of its three example systems, “All three may be built on exactly the same underlying model.”
Pages that answer “what is agentic AI” for a general reader compress the contrast into slogans, such as “If generative AI focuses on creating, agentic AI focuses on doing” (Red Hat, 2026). The slogan is fair, and it gives you nothing to check. What changes for a buyer is the bill, and Chapter 14 of the book prices it line by line.
| Generative AI as a single model call | A system where a model owns the path | |
|---|---|---|
| What the model contributes | Content: a draft, a label, a summary | Decisions: which action runs next, and when to stop |
| What a mistake is (Chapter 14) | Words: “one wrong answer, to one request, with nothing built on top of it” | Deeds: “an action taken, then further actions reasoned on top of the mistake” |
| Cost to run (Chapter 14) | Flat: one round trip per request | The costs “multiply,” and “Latency stops being quotable” |
| Cost to know it worked (Chapter 14) | Sample the outputs and grade them | “Knowing whether an agent worked is the most expensive knowledge on the ladder.” |
A workflow sits between the two columns. Its running costs “add,” in the book’s word, so a fixed quote is possible before launch. Chapter 14 draws all four rungs, from plain code to an agent, as one priced staircase.
The same picture settles “AI agent vs LLM.” The LLM (large language model) is the component that turns text into text. The agent is the arrangement around it: the loop, the tools, the goal and the limits. A three-minute animation, the chatbot, workflow and agent explainer, draws the three arrangements side by side.
Why does the label spread faster than the thing?
The label spreads because it costs nothing to apply and budgets respond to it. Chapter 1 of the book opens on the result: “Vendors label scripted bots ‘agents’; researchers reserve the word for systems that run unattended for hours; and somewhere in between, you have to make actual decisions with actual budgets.”
Founders say the same thing from the other side of the table. One wrote on a forum in April 2025, and said the remark was not sarcasm, that “describing our company as AI Agent for X made it investable” (Hacker News comment). Nothing in that sentence is about architecture.
The adjective itself is old. A dictionary dates its first known use to 1966 and keeps an older sense, about self-assertive human behavior, beside the AI one (Merriam-Webster, read October 2026). The earliest use for machine-learning systems that I fetched is the 2023 research paper listed above, and it comes from researchers studying harms, with nothing to sell.
There is an irony in what happened next. The June 2024 newsletter that argued for the adjective liked it partly because “mainly only technical people use the word ‘agentic’ (for now!),” so an article using it was “less likely to be marketing fluff” (Ng, 2024). The parenthesis turned out to be the accurate part.
Where does the phrase agent-washing come from?
The earliest primary use I could fetch is an analyst firm’s press release dated June 25, 2025, and I do not know who used the phrase first. The release uses “agent washing” for vendors who rebrand products they already sell, with assistants, process-automation scripts and chatbots as its examples, “without substantial agentic capabilities” (Gartner, 2025).
The same release carries the number that reaches boardrooms: “Over 40% of agentic AI projects will be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls.” That sentence is a forecast. It concerns “agentic AI projects,” a population the release does not define, it comes with no published method, and it measures nothing that has already happened.
I cite it for its three reasons, since cost, value and risk controls are what the demo questions below probe. The analyst quoted in the release adds a line worth more than the percentage: “Many use cases positioned as agentic today don’t require agentic implementations.”
The book uses the term agent-washing in its own words and credits it to nobody. Chapter 1 defines the practice in one clause: “because the word sells, scripted pipelines get relabeled as agents.”
What does a wrong label cost in each direction?
A wrong label costs you ceremony in one direction and skipped discipline in the other, and the second is the expensive one. Chapter 14 of the book states the principle: “The cost of the mislabel depends on its direction, and both directions bill you.”
The analyst’s definition covers one direction, a lesser product sold as agentic. Chapter 14 prices it: “A workflow sold as an agent overcharges: you inherit oversight ceremony, governance review, and harness anxiety sized for an autonomy the system does not have, and you evaluate it against the wrong bar besides.”
Then it adds the other: “An agent shipped under the label of a ‘pipeline’ or an ‘automation’ undercharges, and this is the direction that hurts.” I have not found that second direction named in the outside sources I read for this post, and my search was not exhaustive.
The first two rows below are Chapter 14’s. The last two are my extension, and they are marked. In every row the governance and budget columns are my reading.
Pick the label you were shown to narrow the table. “Agentic” brings up two rows, because the word is used for a fixed workflow as readily as for a single model call.
| What is underneath | Direction (whose row) | What you over-buy or skip | Governance consequence | Budget consequence | Label you were shown |
|---|---|---|---|---|---|
| A fixed workflow: code chooses every step, a model fills in content | Overcharge (the book, Chapter 14) | Review boards, sign-offs and harness work scaled to an autonomy the system does not have; a pass mark set for the wrong kind of system | Too much: approval boards on a path that cannot deviate | You pay an autonomy premium; the cost per run is a known small sum, so ask for a fixed quote | agent, agentic |
| A loop somewhere inside in which a model chooses the steps; the label may say pipeline or automation (the book’s two examples), or feature or copilot (my additions) | Undercharge (the book, Chapter 14: “the direction that hurts”) | Budgets and stop conditions, a security audit, an eval set, a place for a person | Too little: no cap, no stop rule, no security review, nobody assigned to look | Cost per run has no ceiling until someone sets one, and it grows with the step count | automation |
| One model call, or a chat assistant with a single tool | Overcharge, milder (this post’s extension) | The word itself; you expect multi-step work the system cannot do | Ordinary review of model output is enough | Low and flat; the risk is paying an agent’s price for it | agentic |
| Whatever your team builds to keep the slide true | Either (this post’s extension, from one clause of Chapter 14) | The label drives the design: a loop gets built where a workflow would do | Inherited from whichever row above the team lands in | Funded as an agent, so the cheaper design is never priced | own roadmap |
The fourth row grows out of a sentence in Chapter 14 that I find uncomfortable to read: “You will meet it in vendor pitches, in analyst reports, and—be honest—in your own roadmap slides, because budgets listen for the word too.” The chapter stops there. The consequences in that row are my reading of what follows when a slide is funded before a design exists.
The overcharge is at least visible, because the costume gives it away: Chapter 14 says a fixed pipeline judged as an agent “looks miraculously reliable and suspiciously rigid,” and that both readings mislead. The undercharge wears no costume, which is one reason it gets missed.
Which three questions should you ask in a vendor demo?
Ask for three things a presenter can put on the screen. They are a run on your own input with its step log, the most damaging action the system can take without approval and where that limit is enforced, and a run that went wrong with what caught it and what it cost.
These are different from the three questions in the post on what an AI agent is, which locate the check a system fails. Mine decide what you are buying, what you must govern and what you must budget. The first one uses your input and treats “it is a workflow” as a good answer, often the better one.
| # | Ask this in the demo | A good answer | A bad answer | What the answer decides |
|---|---|---|---|---|
| 1 | “Run it on an input of mine that you have not seen, then show me the step log. Which steps did the model choose, and which were fixed in your code?” | They run it. The log shows steps the presenter could not have predicted, and they point to the ones the model chose after seeing a result. Or they say plainly: “The path is fixed; the model fills in steps 2 and 4.” Both are good answers about different products. | “It’s fully autonomous.” A rehearsed input only. No step log. “The AI decides everything,” with no way to see what it decided. | Whether you are buying a workflow or an agent, whatever the slide says |
| 2 | “What is the most damaging thing it can do without a person approving it, and where is that limit enforced?” | A named action and a named mechanism outside the model: a permission scope, an approval gate before irreversible actions, a spending cap, a kill switch. They can show the limit being hit. | “It’s instructed not to.” “The prompt tells it to ask first.” “It has never done that.” | The size of the governance |
| 3 | “Show me a run that went wrong. What told you it was wrong, how long did that take, and what did the run cost before it stopped?” | A real failed run, the signal that caught it (a failed test, a schema check, a reconciliation, a review queue), and a cost bound per run that code enforces. They quote a range for cost per task and say what makes it grow. | “We haven’t seen failures.” An average cost with no worst case. Success judged only by the model that did the work. | The budget, and how you will verify the work |
A step log is what engineers call a trace: the recorded list of what one run did, in order. In question 2, a limit that lives in the model’s instructions is a request, and the model can be talked out of honoring it.
The version below is written to paste into the meeting invite or send ahead, so that the vendor can prepare the evidence.
Before the demo: three things we will ask to see
1. A run on our input, with the step log.
We will bring an input you have not seen. After the run, please show
the list of steps it took and tell us which steps the model chose and
which are fixed in your code. "The path is fixed" is a fine answer.
2. The worst action it can take without a person approving it.
Please name that action and show where the limit is enforced
(permissions, an approval step, a spending cap, a stop switch).
If possible, show the limit being hit.
3. A run that went wrong.
Please show one failed run: what signal told you it was wrong, how
long that took, and what the run cost before it stopped. We would
also like a cost range per task and what makes it grow.
We are not scoring the label. We want to know who chooses the next
step, what bounds it, and how a failure gets noticed.
How do you size governance and budget from the answers?
Size governance to the worst action the system can take without a person, and size the budget to who owns the path, code or a model. The answers to the three questions supply both, and the label on the contract supplies neither.
Chapter 14 gives the contrast in phrases short enough to carry into a budget meeting. The table arranges them; the quoted words are the book’s and the rest is my summary.
| Code owns the path (a workflow or simpler) | A model owns the path (an agent) | |
|---|---|---|
| Cost per run | A known small sum; “you can quote it before you ship it” | Rises faster than the step count, and varies from day to day |
| Failure | Contained in its step and caught at the seam between steps | An action, then actions built on it, bounded only by the limits you enforce |
| Audit | “a code-chosen path is a document you can hand to a regulator” | “a model-chosen path is a probability you must defend” |
| What you must also buy | A check per step and a gate at each seam | Budgets, stop conditions, a security review, an eval set, traces, a place for a person |
If answer 1 was “the path is fixed,” remove ceremony. Ordinary change control and a test per step will do, and you can hold the vendor to a fixed price per run.
What do you buy when a model owns the path?
When a model owns the path you buy five things the workflow did not need. They are a budget with a stop condition held in code, an approval gate before the worst action, a security review, an eval set (a graded bank of test tasks rerun on every change), and a named person who looks.
The fifth item answers a question someone who works in outsourced call centers put in plain words, “who is accountable when a decision goes wrong” (forum post, October 2026). Decide before launch who signs for the worst action in answer 2, because a label on the product moves none of that responsibility to the vendor.
Start from answer 2. The worst unapproved action sets the blast radius, the damage one wrong run could do, and the gates are sized to it.
Public guidance starts in the same place. As one dated example, Singapore’s framework of January 2026 lists first “Assessing and bounding the risks upfront by selecting appropriate agentic use cases and placing limits on agents’ powers such as agents’ autonomy and access to tools and data” (IMDA, 2026). The consequence tier classifier sorts a list of actions into the gate each one needs.
Then budget from answer 3, twice: once for running and once for checking. Chapter 14 warns that “a quote is per task, and nobody buys one task,” so multiply by your volume. Checking is a standing cost; a university explainer of February 2026 reports one researcher’s advice to make monitoring “a permanent operational expense, not a one-time project cost” (Stackpole, 2026).
Chapter 14 has the line I would put on the slide: “The sticker price of an agent is a prompt. The cost of ownership is a harness, a ledger, and a standing claim on your attention.” The agent cost-per-task estimator turns a step count into a range. For the policy side, see an AI agent governance framework for a small company; for what the machinery around the loop consists of, see the AI agent architecture guide.
What can three questions in a demo not tell you?
Three questions in a demo tell you what kind of system you are looking at. They cannot tell you how often it is right, what it costs at your volume, how it behaves under attack, or whether the task needed an agent at all.
A rate. One good run proves little. Chapter 14 calls a green run “an anecdote about one path through a distribution,” and a success rate needs many runs on your own cases, which means a pilot with an eval set. The agent verifiability scorecard scores how checkable a system’s work is before you commit to one.
Proof. Spoken answers are claims. A step log on the screen is evidence, and so is a limit you watch being hit. Where the product shows you neither, weigh the answers as you would any other sales statement.
Mixed systems. Most products are a fixed shell with one or two steps where a model chooses. Ask question 1 about each step, and expect the honest answer to be “mostly workflow, agentic here.”
Security. Text a system merely reads can steer what it does next. The questions show where limits sit; they do not test them against a hostile input, and a real review does.
Fit. Knowing what a system is says nothing about what your task wanted. That decision has its own procedure in the agent-or-workflow decision rule and in the Should this be an agent? decision tool.
One limit is mine. The reader questions behind this post came from engineering forums, where buyers are thinly represented, and the cancellation forecast quoted above had not reached its date when I wrote this.
The takeaway
The useful reply to “what is agentic AI” is a request: show me how much of the control flow the model owns in this system. The idea is a model choosing its own next steps inside limits held by code. The label is a claim about degree that nobody has to substantiate until you ask.
So ask the three questions, accept “it is a workflow” gladly, and size the governance and the budget from what you were shown. Chapter 1 gives the reason in a clause: “an agent is only as trustworthy as the signal you can use to verify it.” More of the basics are collected on the agent fundamentals page.
Chapter 1, “What Is an Agent?” is free to read online and contains the control-flow question, the dial and the first mention of agent-washing. Chapter 14, which prices each direction of the mislabel and every rung below an agent, is in the full book; see the formats.
Questions readers ask
- What is agentic AI in simple terms?
- Agentic AI is software in which a language model decides and acts over several steps toward a goal, using tools, with code setting the limits. The word describes how much of the deciding the model does, so it covers a range of systems and tells you little until you ask which one you are looking at.
- Is agentic AI the same as generative AI?
- No. Generative names what a model produces, which is content. Agentic names who chooses the next step. Every agent of this kind has a generative model inside it; the loop and the tools around the model are what the adjective adds. What changes for the owner is the bill: mistakes become actions, running costs multiply, and checking the work gets expensive.
- What is the difference between agentic AI and an AI agent?
- Agent is the noun for a system in which a model chooses the sequence of steps. Agentic is the adjective for a degree of that property. Some sources reserve agentic AI for several coordinated agents; that is one usage among several, and the sources do not agree.
- What is agent-washing?
- Agent-washing is calling a system an agent because the word sells, whatever the architecture underneath. An analyst firm’s press release of June 2025 used the phrase for rebranded assistants, automation scripts and chatbots. The book this site belongs to adds the opposite case, an agent shipped as an “automation,” and calls it the direction that hurts.
- How can I tell whether a vendor’s AI agent is real?
- Ask the vendor to run an input of yours and show the step log, then say which steps the model chose. Ask what the most damaging action is that it can take without approval, and where that limit is enforced. Ask to see a run that went wrong, what caught it and what it cost. “It is a workflow” is an acceptable answer.
Sources
- Gartner (2025). Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027
- Andrew Ng (2024). Welcoming Diverse Approaches Keeps Machine Learning Strong (The Batch)
- Erik Schluntz and Barry Zhang (Anthropic) (2024). Building effective agents
- Alan Chan et al. (2023). Harms from Increasingly Agentic Algorithmic Systems (arXiv:2302.10329)
- Yonadav Shavit, Sandhini Agarwal, Miles Brundage et al. (OpenAI) (2023). Practices for Governing Agentic AI Systems (white paper)
- Red Hat (2026). What is agentic AI? (updated May 14, 2026)
- Google Cloud (2026). What is agentic AI? (last updated September 16, 2026)
- Amazon Web Services. What is Agentic AI? (no date shown; read October 6, 2026)
- Merriam-Webster. agentic (dictionary entry; read October 6, 2026)
- Infocomm Media Development Authority (IMDA), Singapore (2026). Singapore Launches New Model AI Governance Framework for Agentic AI
- European Union (2024). Regulation (EU) 2024/1689 (EU AI Act), Article 3: Definitions (unofficial consolidated reader; read October 6, 2026)
- Beth Stackpole (MIT Sloan) (2026). Agentic AI, explained