
Last updated 17 July 2026
An AI agent is a software system that can take actions to complete a goal, not just answer a question. Where a chatbot responds to prompts, an agent can plan a series of steps, use tools and systems, and carry out a task — like processing an enquiry end to end or reconciling records — with limited human input. Agents are powerful for multi-step work, but because they act rather than just advise, they need clear guardrails and oversight.
How is an AI agent different from a chatbot?
A chatbot is reactive: you ask, it answers. An AI agent is goal-directed: you give it an objective, and it works out the steps, calls the systems it needs, and acts to achieve it. The practical difference is autonomy. A chatbot drafts an email; an agent can draft it, check the CRM, schedule the follow-up and log the outcome — which is far more useful and far more consequential if it gets something wrong.
Where do AI agents create real business value?
- Multi-step processes — enquiries, claims or onboarding that involve several systems and decisions.
- Knowledge-heavy work — pulling from policies, documents and records to complete a task, not just summarise it.
- Repetitive coordination — chasing information, updating systems and routing work between teams.
- Always-on support — handling routine requests outside business hours with escalation to humans when needed.
What are the risks of giving AI agents autonomy?
Because agents act, the failure modes are more serious than a wrong answer. An unsupervised agent can take an incorrect action at scale, access data it shouldn't, or make a decision no one can explain later. That's why governance — clear boundaries on what an agent may do, human checkpoints for consequential actions, logging and monitoring — is not optional. The organisations getting value from agents are the ones treating governance as part of the build, not an afterthought.
How should a business start with AI agents?
Start narrow. Pick one well-understood, bounded process, define exactly what the agent is allowed to do, keep a human in the loop for anything consequential, and measure the result before expanding. For New Zealand organisations, that also means checking where the agent's data is processed and whether it touches personal information covered by the Privacy Act before you widen its remit. A readiness assessment helps identify which processes are genuinely suitable and which are too ambiguous or high-risk to hand to an agent yet.
How much control do we keep over an AI agent?
As much as you design in. An agent’s autonomy is a dial, not a switch. You decide which systems it can touch, which actions it can take on its own, and which require a human to approve before they happen — refunding a customer or sending an external email might need sign-off, while drafting an internal summary might not. Well-built agents also keep a complete log of what they did and why, so a person can review, correct or reverse an action. The goal is not an agent that does everything unsupervised; it is one that handles the routine and escalates the consequential.
How do AI agents stay within the Privacy Act 2020?
The same way any system handling personal information does — by design and by governance. Before an agent touches personal data, you should know where that data is processed, limit the agent to only the information it genuinely needs for the task, and keep the audit trail that lets you show what happened. For New Zealand organisations, the safest agent deployments run inside infrastructure you control, so the personal information an agent reads and acts on never leaves your boundary. That makes obligations under the Privacy Act far easier to demonstrate than an agent wired into an offshore service.
Frequently asked questions
No. An agent can run inside a private AI deployment in your own infrastructure or an onshore data centre, which is often the right choice when it handles personal or regulated information and you need to keep that data in New Zealand.
No. Traditional automation and RPA follow fixed, pre-programmed rules. AI agents can reason about how to reach a goal and adapt to new situations, which makes them more flexible but also harder to predict and govern.
More often they take over repetitive coordination and free people for judgement-based work. The realistic near-term pattern is agents handling routine steps with humans supervising and handling exceptions.
They can be, within clear boundaries and human oversight for consequential actions. The risk comes from giving an agent broad autonomy without governance, monitoring and the ability to intervene.
SOVATA