What Is an AI Agent, and Where Must It Stop?

By Marco Kohns, Co-founder of ENLIX, lecturer in AI and growth

· 13 min read

An AI agent is a program that runs a language model in a loop: it is given a goal, picks its own steps, uses tools, and decides for itself when it is finished. That last part is what separates it from a chatbot. A chatbot answers and waits. An agent keeps working until a stop condition fires.

This article was written by one of them. It runs on Mondays, Wednesdays and Fridays, takes the top open row from our editorial queue, researches, writes, checks itself against 197 tests and publishes. So what follows is not a product description but an operating report. Below is what that agent is made of, what it is allowed to do on its own, and the three places where it stops and waits for a person.

What is an AI agent?

A language model plus two things the model does not have on its own: access to tools, and a loop. The model sees a goal, picks a tool, reads the result, and uses that result to decide the next step.

Anthropic describes this shape in Building effective agents (Erik Schluntz and Barry Zhang, 19 December 2024) in a single sentence: agents are "typically just LLMs using tools based on environmental feedback in a loop".

Three terms get used interchangeably and mean different things:

TermWho fixes the stepsWhen it ends
ChatbotThe user, fresh with every questionAfter the answer
Automation or workflowA person, once, in codeWhen the last step is done
AI agentThe model, fresh on every passWhen a stop condition fires

What separates an agent from a workflow?

Who decides the order of the steps, and nothing else. Anthropic draws the line in exactly that place: workflows are systems where models and tools are "orchestrated through predefined code paths", agents are systems where models "dynamically direct their own processes and tool usage".

This is not a word game, it is the question of who is accountable when something goes wrong. In a workflow a person wrote every step down, and a wrong step is a bug. In an agent a person wrote down only the goal and the limits, and a wrong step is a decision the model made inside those limits. Whoever does not write the limits down does not have any.

Who decides what happens next

Step a person fixed in advance

Workflow

  1. Trigger fires
  2. Step 1, fixed in code
  3. Step 2, fixed in code
  4. Step 3, fixed in code
  5. Result goes out

a person fixes 3 of 5 steps

Agent

  1. Trigger fires
  2. Model reads the goal
  3. Model picks a tool
  4. Model reads the result and decides again
  5. Stop condition, set by a person
  6. Result goes out

a person fixes 1 of 6 steps

Split follows Anthropic, Building effective agents, 19 Dec 2024.

From which comes the practical rule: if you can write the steps down in advance, write them down. A workflow is cheaper, faster and auditable. Anthropic says to add complexity "only" when it demonstrably improves outcomes, because autonomy means higher costs and the potential for compounding errors.

What is an AI agent made of?

Three parts. Every agent that survives contact with production has all three, and most projects that get shut down are missing the third.

PartWhat it answersWhat happens without it
TriggerWhen does it startA person starts it by hand, so it is a tool, not an agent
ToolsWhat may it touchIt can talk and do nothing
Stop conditionWhen does it finish, and when does it hand overIt keeps going, including when the situation is wrong

The trigger is the dullest part and the one that turns a chat into a system. Ours is a schedule: Monday, Wednesday, Friday. It could equally be an incoming email, a new row in a database, or a commit.

The tools are the part everyone talks about. More interesting than the list is the boundary: may the agent only read, may it write, or may it do something visible on the outside. Those three levels are the real risk cut, not the number of tools.

The stop condition is the part a demo run never needs and production decides everything on. It is two sentences: how does the agent know it is finished, and how does it know it is stuck and has to hand over.

What does an AI agent actually look like in production?

Like this, and this is the agent that wrote this text. We name the three parts because they are the same three in every agent.

Trigger: a schedule, Monday, Wednesday and Friday mornings. No person starts it.

Tools: the queue in our editorial plan, the Git checkout of this site, web search, the test suite, and permission to publish. It may read, write and publish, which is the highest of the three levels above. That is exactly why there is a gate in front of publishing.

Stop condition: it has to pass the test suite and the site has to build. On 2 October 2026, before this article, that was 197 tests across 8 files, measured with npx vitest run in the project directory.

What the agent has to pass before it may publish

Webinar logic81Languages and URLs29Blog posts23Digistore integration20Tool registry18Pricing10Thank-you pages10Waiting list6

197 tests across 8 files, measured on 2 October 2026 with `npx vitest run`. If one of them is red the agent does not publish and reports what failed instead.

What the agent has to pass before it may publish
Webinar logic81
Languages and URLs29
Blog posts23
Digistore integration20
Tool registry18
Pricing10
Thank-you pages10
Waiting list6

The second half of the stop condition is the one we care about more: an empty run is an allowed outcome. If the agent cannot source a number, or the top row of the queue is blocked, it publishes nothing, writes down what stopped it, and ends. That single line is the difference between an agent you can leave running and one that puts nonsense on the internet every Wednesday.

What comes out of that can be read off the queue. The editorial plan had 30 rows this morning:

The queue the agent read this morning

open20published7blocked by a person3

30 rows in the Academy editorial plan, as of 2 October 2026. This article is the eighth.

The queue the agent read this morning
open20
published7
blocked by a person3

The three blocked rows are the most honest part of that chart. One is a business decision two people made that the agent is not allowed to make. Two hang on a legal text we have so far not been able to retrieve in the official original, and the agent is not allowed to back-translate a legal norm from English. It skips those rows and takes the next one. It does not resolve them, and it does not invent anything.

What kinds of AI agents are there?

The most useful split is not by industry but by what the agent is allowed to touch. That is what decides how much checking belongs in front of it.

LevelWhat it may doExampleWhat a person has to check
Read-onlyFetch, summarise, assess dataResearch agent, inbox sorterNothing, as long as only you see the result
Writing, internalChange files and recordsCode agent on its own branch, data cleanupThe result before it is merged
Acting, outwardSend, publish, payThis publishing agent, a support agent with mail accessA gate before the action, not after it

The whole difference sits between level two and level three. An agent working on its own branch costs you a discarded change at worst. An agent allowed to send costs you, at worst, an email to customers you cannot take back.

What are some examples of AI agents?

The useful examples are small and dull. Each of the following reduces to the three parts, and that is how you tell whether something really is an agent.

ExampleTriggerToolsStop condition
Research agentA question in a listWeb search, a notes documentThree sources found, or none after five attempts
Code agentA new branchRead and write files, run testsTests green, or red twice in a row
Inbox sorterA new mailRead and set labelsEvery mail filed once
This publishing agentA scheduleQueue, repository, web search, testsTests green and the site builds, otherwise an empty run

What stands out in that table: in three of four cases the stop condition is a count or a test result, which is to say something measurable. A stop condition that reads "when it is good enough" is not one.

What does not belong in the table is what gets sold as an agent most often: a chatbot on your own documentation, a one-click text summary, a form that fires an email. All three are useful. None of them picks its own steps.

What does an AI agent cost to run?

More than the same result in a workflow, and that is not a drawback but the price of autonomy. Anthropic names it directly: autonomy means higher costs and the potential for compounding errors.

The cost has three lines, and only the first is obvious:

  1. Model cost per run. It varies, because the number of steps varies. An agent that is done on the first attempt costs a fraction of one that corrects itself seven times. That is why a budget per run makes a sensible second stop condition. For Claude Code, our cost calculator works your case through.
  2. A person's checking time. It only disappears when the gate in front of the action checks automatically. An agent whose output someone reviews by hand every time has not saved the work, it has moved it.
  3. Maintaining the tools. Every connected system changes its interface eventually, and then the agent stops. That is the line demos never show and the one that decides whether an agent is still running in the second quarter.

How do you know your agent is still healthy?

From three numbers you have to record, because they cannot be reconstructed later: how often it ran, how often it stopped, and how often a person had to fix its output.

The third one matters most and almost nobody keeps it. An agent that never stops looks perfect in a statistic and can still generate work that someone quietly straightens out every week. When the fix rate climbs, it is usually not that the model got worse but that an assumption in the instructions no longer holds.

Hence the rule: the stop rate is a measurement, not a fault. An agent with zero empty runs is either perfect or it is not checking itself. Here, empty runs are explicitly allowed and get reported the same way a published article does.

Why do so many agent projects get shut down?

Because they are built as a demo and not as an operation. Gartner predicts that over 40 percent of agentic AI projects will be canceled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls (press release of 25 June 2025).

Anushree Verma, Senior Director Analyst at Gartner, puts it this way: most agentic AI projects right now are early-stage experiments or proofs of concept that are "mostly driven by hype and are often misapplied".

On top of that comes a purchasing problem Gartner calls "agent washing": vendors rename existing assistants, process automation and chatbots as agents without anything changing in how they are built. Of the thousands of vendors using the word, Gartner estimates that around 130 actually offer agentic capabilities.

So the question to ask a vendor is the same one you ask yourself when building, and it fits in one sentence: who decides the order of the steps, and what happens when the thing gets stuck? Anyone who cannot answer that clearly is selling a workflow at the price of an agent.

How do you build an AI agent?

You write the three parts down before you touch code. In this order, because the order is what prevents the mistakes.

  1. The trigger. When exactly does it start, and how often. A schedule is the simplest and almost always the right one for a first agent.
  2. The stop condition, before the tools. How does it know it is finished. How does it know it has to hand over. Write that second sentence down for real, even though the first run will never need it.
  3. The tools, as few as possible. Every tool is one more decision the model can make, and therefore one more place it can reach for the wrong thing.
  4. The instructions. Not a prompt in the chat sense but an operating manual: goal, limits, what happens in case of doubt. Our prompt generator writes the same four-block structure we use for it.

The most common mistake is to start at point 3. Tools are visible and impress in a demo; the stop condition is invisible and decides whether you still let the agent run after four weeks.

Recurring ways of working do not belong in the instructions but in their own versioned files. Where we draw the line between the two is in Claude Code Skills.

When should you not build an agent?

When you already know the steps, when a mistake is expensive, or when nobody reads the output. Those three cases cover almost every project that later gets shut down.

  • You know the steps. Then it is a script. A script is cheaper, faster, and you can read it.
  • A wrong move is expensive and cannot be taken back. Money, customer communication, deletions. A person belongs in front of the action here, and then it is an assistant, not an agent.
  • Nobody reads what comes out. An agent without a reader produces work nobody checks, and that is precisely what gets switched off after four weeks.

If an agent still fits, start small: read-only, one tool, one stop condition, one run a day. How far that goes without programming knowledge, and where the limit sits, is in What Is Vibe Coding.

If you would rather build the three parts into a real agent than read about them, that is the practical half of the Claude Code System.

Frequently asked

What is an AI agent in plain words?

A program that runs a language model in a loop. It is given a goal, picks its own steps, uses tools such as files, search or a database, reads the result and decides the next step from it. It ends when a stop condition fires. A chatbot answers once and waits; an agent keeps working.

What is the difference between an AI agent and a workflow?

Who decides the order of the steps. In a workflow a person fixes the steps in code and the model fills them in. In an agent the model picks the steps itself. Anthropic draws the line in exactly that place in "Building effective agents": workflows orchestrate models through predefined code paths, agents direct their own processes.

How do I build an AI agent?

Write down three things before you build anything: the trigger, the tools and the stop condition. After that the build itself is small. The most common mistake is to start with the tools and never write the stop condition, because a demo run never needs it.

Do I need an AI agent or is a script enough?

A script is enough when you can write the steps down in advance. An agent only pays off when the steps depend on what comes back along the way. Anthropic frames it as a cost question: autonomy means higher costs and the potential for compounding errors.

Why do so many AI agent projects get shut down?

Gartner predicts that over 40 percent of agentic AI projects will be canceled by the end of 2027, because of escalating costs, unclear business value and inadequate risk controls. Analyst Anushree Verma gives the reason that most projects are early-stage experiments driven by hype and often misapplied.

Written by

Marco Kohns

Co-founder of ENLIX, lecturer in AI and growth

Marco worked as a growth product manager at a Silicon Valley scale-up and has been teaching that way of working ever since. Today he runs ENLIX with Tobias and builds two products of his own on the same systems, which is what the courses open up.

  • Growth product manager at a Silicon Valley scale-up, Series A to B, backed by a16z, General Catalyst and Sapphire, with users in over 100 countries and more than 20,000 cities
  • Peer-reviewed research in the Journal of Business Research on generative AI in growth, with Prof. René Bohnsack. The research began in summer 2022, months before ChatGPT was public
  • Executive education lecturer at Católica-Lisbon, over 10 seminars, more than 1,500 people taught

Keep reading