An AI agent is an AI system that does not just answer you, it carries out a task. IBM describes an agent as a system that autonomously performs tasks by designing workflows with the tools it has. Anthropic puts it as a system where the AI model directs its own process and decides which tools to use, rather than following a fixed script.
What an agent is
A chatbot waits for your next message and replies with text. An agent is given a goal and then works through the steps itself: it might open web pages, click buttons, fill in forms, run code or use connected apps, checking the results as it goes. IBM notes that ordinary chatbots need continuous input from you, while agents can break a job into smaller subtasks and use tools such as web search to fill gaps in what they know.
In practice, you describe what you want and the agent gets on with it while you watch or do something else. OpenAI says ChatGPT agent works on its own virtual computer with a browser and other tools, and asks permission before consequential actions such as purchases. You can interrupt it or take over at any point.
Agents suit open-ended jobs where you cannot predict every step in advance. The trade-off, as Anthropic points out, is higher cost and the risk that a small mistake early on is built upon later. That is why Anthropic, IBM and OpenAI all stress human oversight, such as checkpoints and asking permission before important actions.
Not in the UK yet: Google says its Gemini agent (Gemini Spark) isn't available in the UK, and Gemini in Chrome's auto browse is US-only. Where tips below quote Google's guidance, it still applies to agents in general.
Built into assistants and browsers
They act on websites or your computer for you.
ChatGPT agent (agent mode)
OpenAI
Inside ChatGPT, it carries out multi-step tasks such as research, planning a purchase or creating a slide deck, using its own virtual computer and browser. It asks permission before consequential actions such as purchases, and you can interrupt or take over.
Access: Plus, Pro, Business, Enterprise and Edu plans; not on Free or Go. Monthly limits apply (e.g. 40 messages a month on Plus, 400 on Pro).
A web browser with ChatGPT built in. Its agent mode lets ChatGPT take actions in the browser for you, and in logged-out mode the agent won't use your existing cookies or be logged into your accounts without your approval.
Access: At launch (October 2025, macOS first) the browser was available to Free, Plus, Pro and Go users; agent mode was in preview for Plus, Pro and Business.
Takes on multi-step knowledge-work tasks for you, so you can describe an outcome, step away and come back to finished work. It asks before permanently deleting files.
Access: Paid Claude plans (Pro, Max, Team, Enterprise). Anthropic lists the desktop app for macOS and Windows, the web, mobile apps and a Chrome side panel.
A Chrome browser extension that lets Claude read, click and navigate websites alongside you, including filling in forms. You can switch it to 'Manually approve' to review every action.
Access: All paid Claude plans (Pro, Max, Team and Enterprise).
You describe a goal and Copilot plans and carries out the steps, now or on a schedule. It can browse and use websites, create or edit files and use services you have connected, and asks before payments or sending messages.
A web browser with Perplexity's assistant built in, which can do tasks such as comparing how news outlets cover a story, drafting email replies and finding products to buy.
Access: Available for Mac, Windows, iOS and Android.
A general-purpose agent that carries out tasks rather than just answering, such as research, building slides or websites, and operating a browser. Available on the web and as mobile and desktop apps.
No-code tools for agents that run tasks across your apps.
Zapier Agents
Zapier
Build AI 'teammates' without code, give them your company knowledge, and let them work across thousands of connected apps on command or on a schedule. Templates cover sales, marketing, support and HR.
Access: Free plan available; paid tiers for more use.
Build agents on Make's visual canvas that reason over unstructured inputs like messages and documents, then act across thousands of apps. A Reasoning panel shows each decision and you can add manual approvals.
Access: Make says AI Agents are available on all plans.
A visual workflow automation tool for building AI agents, with the option to add code. You can inspect each decision and add human approval steps. Best suited to the more technically minded.
Access: Hosted cloud version, or self-host it yourself.
An AI 'teammate' that connects to your work tools (email, Slack, CRM and more) to handle jobs like inbox management, reports and CRM updates. Actions that send or write data can wait for your approval.
Access: Free plan with a one-off credit allowance for 7 days, no card needed; paid Team plan per user per month.
A platform for businesses to build and manage their own agents, either by describing them in plain English or with a graphical editor, for internal use or customer-facing services.
Access: Pay-as-you-go or pre-purchased credit packs (priced in GBP on Microsoft's UK page); a free trial is offered through an Azure free account.
Plans and availability change often; each card says only what the maker's page said on 5 Oct 2026. Check the official page before you sign up.
How to brief and supervise an agent
Give it one clear goal and a finish line
Say exactly what 'done' looks like. OpenAI warns against vague requests such as 'check my email and handle everything', and advises giving agents specific, narrow tasks rather than broad freedom. A tight brief also gives hidden instructions on web pages less room to steer the agent.
See an example
Find three train times from Leeds to London on Friday morning arriving before 11am, and list them with prices. Do not book anything.
Tell the agent what it must not do and what its boundaries are: budget, dates, which sites to use, and that it should stop and ask before anything that costs money or contacts someone. Specific instructions are one of OpenAI's four recommended protections against manipulation.
See an example
Budget is £150 maximum. Only use the hotel's own website or Booking.com. Stop and ask me before entering any payment details.
Switch off apps and connectors the task does not need, and review app permissions regularly. The UK's ICO flags agents processing personal information beyond what is necessary as a key data protection risk.
If the task does not need your accounts, keep the agent signed out. In ChatGPT Atlas, logged-out mode means the agent will not use your existing cookies without your approval. OpenAI recommends this to limit what sensitive data an agent can reach.
When a site needs you to sign in, take control and log in yourself. ChatGPT's takeover mode does not capture screenshots while you type, which helps protect passwords. Google advises not entering passwords or payment details in the agent's task thread.
Microsoft's Copilot Tasks asks before purchases, sending emails or messages, submitting personal details and changing accounts, and ChatGPT agent asks before consequential actions. Leave these checks switched on. Claude in Chrome lets you switch to 'Manually approve' to review every action.
A confirmation only protects you if you check it. OpenAI advises verifying that each proposed step matches what you actually asked for. Google says to review confirmation requests and stop the task if something looks wrong.
Try research and comparison jobs before anything involving money or contracts. Anthropic advises starting with websites you trust and not using Claude in Chrome for financial accounts, legal documents or health information. Anthropic's engineering guidance also recommends extensive testing in safe, sandboxed environments.
Stay with the agent, especially on sensitive sites such as your bank, as OpenAI and Google both advise; Google calls active supervision the most important protection. If it does something unexpected, stop it straight away. Microsoft and Google both let you stop a task mid-way, and Google also lets you take control of the browser.
Do not assume the job was done right. IBM recommends giving users a log of the agent's actions, and builder tools such as Make and Zapier show each step or decision the agent made. Read it, and check the end result yourself before relying on it.
Prompt injection is when instructions hidden in content the agent reads, such as a web page, email or document, trick it into doing something you did not ask. OpenAI's example is a rental listing secretly telling the AI to recommend that property. The UK's NCSC warned in December 2025 that this may never be fully fixed, because AI models cannot reliably tell data apart from instructions.
Because agents work through many steps on their own, an early error can be built upon. Anthropic warns of 'the potential for compounding errors', and IBM mentions agents getting stuck in loops. Google states plainly that you are responsible for mistakes and unexpected results, such as purchases.
Claude in Chrome takes screenshots of your active browser tab, so anything visible there can be read. In logged-in mode, ChatGPT's agent in Atlas can use sites you are already signed in to. The ICO highlights risks of agents handling more personal information than needed, and of sensitive data being used or inferred unintentionally.
Anthropic says agents mean higher costs, and that Cowork tasks use more of your usage allocation than chatting. ChatGPT agent has monthly caps (40 messages on Plus). Builder tools such as Lindy and Copilot Studio charge by credits.
Anthropic says you remain responsible for what Claude in Chrome does for you, including purchases and anything it publishes or sends; Google says the same for Gemini in Chrome, including mistakes and unexpected purchases. For businesses, the ICO says organisations stay responsible for data protection compliance of the agentic AI they use.
Agents can struggle. Microsoft says Copilot Tasks performs poorly with highly sensitive activities, advanced document layout or design work and websites that restrict automated interaction. Anthropic advises against using Claude in Chrome for financial accounts, legal documents or health information.