Understand the shift to AI agents

Completed

Artificial intelligence is evolving from systems that respond to requests into systems that can take action.

Many AI experiences help users by generating summaries, recommendations, or drafted content. While these experiences improve productivity, the user is still responsible for deciding what happens next.

AI agents introduce a different approach. Instead of responding to individual prompts, they can work toward a defined goal by retrieving data, invoking tools and services, and completing one or more tasks within the permissions they're granted.

Illustration of an AI agent connecting to data sources, services, and applications to complete tasks.

AI experiences compared to AI agents

Understanding these differences is important because AI agents can interact with business systems and perform actions, introducing security considerations that don't typically apply to AI experiences that only generate responses.

The following table compares AI experiences with AI agents.

AI experiences AI agents
Generate responses to prompts Perform actions to achieve a goal
Support user decision-making Complete tasks on behalf of users or organizations
Wait for user input before each step Can execute multiple steps with minimal user input
Typically work within a single interaction Can connect across applications, tools, and services

Scenario: Preparing for a customer meeting

Imagine an organization deploying an AI agent to help employees prepare for customer meetings.

Instead of simply summarizing information, the agent retrieves customer records, reviews recent emails, schedules a meeting, and drafts follow-up communications. This shift - from generating responses to completing tasks - introduces new security considerations.

As organizations adopt AI agents, they expand the role AI plays in everyday work. An agent might:

  • Gather information from multiple business systems.
  • Access approved data needed to complete a task.
  • Update records in connected applications.
  • Generate draft follow-up communications.
  • Complete a sequence of actions with minimal user input.

As AI agents become more capable, organizations must think beyond the quality of AI-generated responses. They also need to consider how agents access data, interact with business systems, and perform actions securely.

Tip

To learn more about securing AI agents on Windows, see the Windows platform security for AI agents article.

The shift from assistance to action introduces new considerations for security, governance, and control—especially when AI agents interact with business systems and perform actions across connected environments. In the next unit, you explore the security risks AI agents introduce and why traditional application security alone is no longer sufficient.