Understand the shift to AI agents
Artificial intelligence is evolving from systems that respond to requests into systems that can take action.
Many AI experiences help users by generating summaries, recommendations, or drafted content. While these experiences improve productivity, the user is still responsible for deciding what happens next.
AI agents introduce a different approach. Instead of responding to individual prompts, they can work toward a defined goal by retrieving data, invoking tools and services, and completing one or more tasks within the permissions they're granted.
AI experiences compared to AI agents
Understanding these differences is important because AI agents can interact with business systems and perform actions, introducing security considerations that don't typically apply to AI experiences that only generate responses.
The following table compares AI experiences with AI agents.
| AI experiences | AI agents |
|---|---|
| Generate responses to prompts | Perform actions to achieve a goal |
| Support user decision-making | Complete tasks on behalf of users or organizations |
| Wait for user input before each step | Can execute multiple steps with minimal user input |
| Typically work within a single interaction | Can connect across applications, tools, and services |
Scenario: Preparing for a customer meeting
Imagine an organization deploying an AI agent to help employees prepare for customer meetings.
Instead of simply summarizing information, the agent retrieves customer records, reviews recent emails, schedules a meeting, and drafts follow-up communications. This shift - from generating responses to completing tasks - introduces new security considerations.
As organizations adopt AI agents, they expand the role AI plays in everyday work. An agent might:
- Gather information from multiple business systems.
- Access approved data needed to complete a task.
- Update records in connected applications.
- Generate draft follow-up communications.
- Complete a sequence of actions with minimal user input.
As AI agents become more capable, organizations must think beyond the quality of AI-generated responses. They also need to consider how agents access data, interact with business systems, and perform actions securely.
Tip
To learn more about securing AI agents on Windows, see the Windows platform security for AI agents article.
The shift from assistance to action introduces new considerations for security, governance, and control—especially when AI agents interact with business systems and perform actions across connected environments. In the next unit, you explore the security risks AI agents introduce and why traditional application security alone is no longer sufficient.