How AI Agents Actually Work: A Plain-English Guide
Ask ten vendors what an “AI agent” is and you will get ten answers, most of them designed to sell you something. So let us start with the least glamorous definition that is actually true.
An AI agent is a language model that has been given tools and a goal, and is allowed to use those tools in a loop until it decides the goal is met.
That is it. Everything else — “autonomous,” “agentic reasoning,” “digital workforce” — is elaboration on that one idea. Once you see the loop, the whole category stops being mysterious, and its failure modes start making sense.
The one building block: an LLM that can act
Start with a chatbot. You type, it writes text back. It cannot check today’s weather, run code, or send an email; it only produces words.
Now give that same model three things. First, tools: functions it is allowed to call, like “search the web,” “read this file,” or “run this query.” Second, the ability to read the results of those tool calls back into its own context. Third, memory, so it can keep track of what it has already done. Anthropic calls this combination the “augmented LLM,” and describes a modern model as able to “actively use these capabilities — generating their own search queries, selecting appropriate tools, and determining what information to retain.”
The model does not physically run the tools itself. Your software does that. The model just outputs a structured request — call search with the query “Q3 revenue” — your code executes it, and the answer gets handed back to the model as more text. That hand-off is the entire trick.
The loop is the whole thing
Here is the cycle that turns a model into an agent:
- Read the goal and the current state. “Book me a table for four on Friday.”
- Decide on one action. The model picks a tool and arguments — say, search a reservations site.
- Act. Your code executes the call.
- Observe. The result comes back: three restaurants, two booked solid.
- Decide again. The model reads that and picks the next action — try the third restaurant — or declares the task finished.
Then it repeats. IBM frames the same cycle as goal initialization, reasoning with tools, and reflection. This is why people talk about an agent “reasoning”: each pass through the loop, the model re-evaluates what it has learned and what to try next, rather than following a script fixed in advance.
That last distinction is the one worth memorizing, because it separates two things vendors love to blur.
Agents vs. workflows (they are not the same)
Anthropic draws a line that is unusually honest for the industry. A workflow is a system where “LLMs and tools are orchestrated through predefined code paths” — the steps are decided by a human in advance, and the model fills in the blanks. An agent is a system where LLMs “dynamically direct their own processes and tool usage, maintaining control over how they accomplish tasks.”
Most products marketed as “agents” are really workflows, and that is often the smarter engineering choice. A workflow that always does step A, then B, then C is predictable and cheap to debug. A true agent that decides its own path is more flexible but harder to control. Common middle-ground patterns include routing (classify the request, send it to a specialized handler), orchestrator-workers (one model breaks a job into pieces and farms them to others), and evaluator-optimizer (one model drafts, another critiques, loop until good enough). None of these require full autonomy. The rule of thumb from the same Anthropic guidance: use the simplest thing that works, and only reach for an autonomous agent when the path genuinely cannot be mapped ahead of time.
How agents reach the outside world: MCP
For the loop to do anything useful, the model needs tools, and every tool used to be a bespoke integration. That is changing fast because of a standard called the Model Context Protocol (MCP).
Anthropic introduced MCP on November 25, 2024 as an open standard — think of it, as its backers do, as “USB-C for AI”: one connector so any model can plug into any tool or data source without a custom adapter for each. It stuck. OpenAI adopted MCP in March 2025 and Google DeepMind followed in April 2025, which is why fierce competitors now share plumbing. When someone says an agent “connected to our database” or “has access to Slack,” MCP is increasingly what they mean under the hood.
A real example you can picture: the browser agent
The clearest concrete case is an agent that drives a web browser like a person — moving the cursor, clicking, typing.
OpenAI shipped exactly this as Operator on January 23, 2025, a “computer-using agent” that could fill forms, place orders, and book appointments by looking at the screen and acting. It is also a useful reality check. On the WebArena benchmark Operator scored 58.1%, and on OSWorld 38.1% — well short of a reliable human. OpenAI retired Operator (it shut down August 31, 2025), folding its abilities into a broader ChatGPT agent, which was itself reorganized again in 2026. The capability is real and improving; the specific products churn constantly, which is a good reason to learn the underlying loop rather than any one brand name.
Where agents break
Understand the loop and the weaknesses are obvious.
Errors compound. Simple arithmetic shows why: a ten-step task where each step is 95% reliable succeeds only about 60% of the time end to end (0.95 multiplied by itself ten times). Long chains are fragile by construction.
The model can misread an observation — a popup it treats as a page, a near-match contact it treats as the right one — and then confidently build on the mistake.
It can take real actions with real consequences, which is why serious deployments keep a human in the loop (here’s how to lock down your accounts first) for anything that spends money or sends a message, and sandbox the rest.
None of this means agents are fake. It means the honest mental model is an eager, fast, literal-minded intern who can use your tools — not a colleague you can leave unsupervised. Hand it well-scoped tasks with reversible actions and a checkpoint before anything irreversible, and the loop earns its keep. Ask it to run your business while you are at lunch, and you will meet every one of the failure modes above.
That is the whole category, minus the marketing: a model, some tools, a goal, and a loop. Everything flashy is built on those four parts — and so is everything that goes wrong.
Sources
Catherine Crowe covers AI explained for prompt/power: the plain-English guides that break down how the technology works, what the jargon means and what it changes for everyday people. Originally from Canada, she writes from New Zealand.
Latest from prompt/power
- How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
- OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
- When an AI Agent Breaks In, Who Answers for It?Oct 5
- The New AI Models Don’t Talk. They Decide.Oct 5
- Quebec’s First AI Election: ChatGPT Leaned on an AI-Built Voter GuideOct 5
Leave a Reply