[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:en":3,"public-menus:all":38,"post:agentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act:en":205,"related:post:agentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act:en:1":2212},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","en","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":2211},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":1538,"featuredImage":1539,"featuredImageAlt":1540,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":1541,"publishedAt":1542,"createdAt":1543,"updatedAt":1544,"seoLocalePaths":1545,"categories":1554,"author":1567,"translations":1572},"489","Agentic AI Explained: When an AI System Can Plan, Use Tools and Act","agentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","{\"time\":1791487185746,\"blocks\":[{\"id\":\"intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"Agentic AI is an AI system in which a model can pursue a goal across multiple steps by deciding what to do next, using tools or other capabilities, observing the results, updating its working state and continuing until it reaches a stopping condition. The model alone is not the agent. A usable agent also needs a runtime or harness that manages context, tool execution, state, permissions, approvals, errors and the loop between decisions and observations.\"},\"tunes\":{}},{\"id\":\"direct\",\"type\":\"callout\",\"data\":{\"variant\":\"info\",\"title\":\"Direct answer\",\"body\":\"A normal model call is usually \u003Cstrong>input → model → output\u003C\u002Fstrong>. An agentic system is closer to \u003Cstrong>goal → decision → tool\u002Faction → observation → updated decision → … → result\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The critical distinction is not whether an application uses an LLM or function calling. It is whether the system gives the model meaningful control over the next step of a multi-step process while a runtime constrains what the model is actually allowed to do.\"},\"tunes\":{}},{\"id\":\"boundary\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Capability is not authority\",\"body\":\"A model may know how to call a tool. A runtime may expose that tool. Neither fact means the current user or agent is authorized to execute the underlying business action. \u003Cstrong>Tool capability, tool permission and business authority are separate layers.\u003C\u002Fstrong>\"},\"tunes\":{}},{\"id\":\"current\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Current-source note — 8 October 2026\",\"body\":\"Agent terminology still varies across vendors and research communities. OpenAI currently defines agent runtimes around multi-step work, tools, state and orchestration. Anthropic's practical distinction remains useful: workflows follow predefined code paths, while agents dynamically direct their own process and tool use. This article therefore treats “agentic AI” as an architectural spectrum rather than one standardized product category.\"},\"tunes\":{}},{\"id\":\"toc\",\"type\":\"tableOfContents\",\"data\":{\"title\":\"Contents\",\"minLevel\":2,\"maxLevel\":3},\"tunes\":{}},{\"id\":\"h-meaning\",\"type\":\"header\",\"data\":{\"text\":\"What agentic AI really means\",\"level\":2},\"tunes\":{}},{\"id\":\"p-meaning-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The important shift from ordinary generative AI to agentic AI is control over process. A normal assistant can answer a question using the context it receives. An agent can decide that answering requires additional steps: inspect a file, search a repository, query an API, ask for clarification, run a test, update a ticket, delegate a subtask or retry after a failed action.\"},\"tunes\":{}},{\"id\":\"p-meaning-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"This does not require unlimited autonomy. An agent can operate inside a narrow sandbox, under strict permissions, with approval required before every consequential action. The system is still agentic if the model dynamically chooses among permitted next steps.\"},\"tunes\":{}},{\"id\":\"p-meaning-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture therefore matters more than the label. “Agent” should describe a system behavior: iterative model-driven decision making over tools, state and feedback — not merely a chatbot with a larger prompt.\"},\"tunes\":{}},{\"id\":\"h-simple\",\"type\":\"header\",\"data\":{\"text\":\"The simplest example\",\"level\":2},\"tunes\":{}},{\"id\":\"p-simple-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Suppose a developer asks an AI system: “Find why the test suite fails and fix the bug.” A single model call could only suggest likely causes from the text it was given.\"},\"tunes\":{}},{\"id\":\"p-simple-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"An agentic coding system can inspect the repository, search for the failing test, read relevant files, propose a change, edit the code, run the test, observe the failure, revise the implementation and run the test again.\"},\"tunes\":{}},{\"id\":\"p-simple-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The agentic part is not simply that shell and file tools exist. It is that the model can use environmental feedback to choose the next step instead of following one completely predefined sequence.\"},\"tunes\":{}},{\"id\":\"simple-loop\",\"type\":\"processFlow\",\"data\":{\"title\":\"The basic agent loop\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Receive a goal\",\"description\":\"The user or upstream system defines the objective and relevant constraints.\"},{\"label\":\"2. Build current context\",\"description\":\"The runtime supplies instructions, state, history, memory, tools and current evidence.\"},{\"label\":\"3. Model decides next step\",\"description\":\"The model may answer, call a tool, request information, delegate or stop.\"},{\"label\":\"4. Runtime validates the request\",\"description\":\"Permissions, schemas, approvals and policy determine whether the proposed action may execute.\"},{\"label\":\"5. Execute tool or action\",\"description\":\"The external environment changes or returns new information.\"},{\"label\":\"6. Observe the result\",\"description\":\"The runtime feeds structured tool output, errors or state changes back into the next model step.\"},{\"label\":\"7. Continue or stop\",\"description\":\"The loop repeats until success, refusal, escalation, budget limit, timeout or another stopping condition.\"}]},\"tunes\":{}},{\"id\":\"h-stops\",\"type\":\"header\",\"data\":{\"text\":\"Where the simple example stops\",\"level\":2},\"tunes\":{}},{\"id\":\"p-stops-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Not every multi-step AI system is equally agentic. A workflow may use several LLM calls and tools while every step is predetermined in code. Another system may let the model decide which tool to call, in which order, how many times and when to stop.\"},\"tunes\":{}},{\"id\":\"p-stops-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Both can be useful. The difference is where control lives. Predefined workflows put more control in application code. Agents move more tactical process decisions into the model\u002Fruntime loop.\"},\"tunes\":{}},{\"id\":\"h-workflow\",\"type\":\"header\",\"data\":{\"text\":\"Agent vs workflow\",\"level\":2},\"tunes\":{}},{\"id\":\"workflow-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Predefined workflow and agentic control\",\"layout\":\"table\",\"columns\":[{\"id\":\"workflow\",\"label\":\"LLM workflow\"},{\"id\":\"agent\",\"label\":\"Agent\"}],\"rows\":[{\"id\":\"path\",\"label\":\"Process path\",\"values\":[\"\",\"\"]},{\"id\":\"tools\",\"label\":\"Tool sequence\",\"values\":[\"\",\"\"]},{\"id\":\"strength\",\"label\":\"Strength\",\"values\":[\"\",\"\"]},{\"id\":\"risk\",\"label\":\"Risk\",\"values\":[\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"p-workflow-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Anthropic explicitly separates these two patterns: workflows orchestrate models and tools through predefined code paths, while agents let models dynamically direct their own processes and tool usage. This is not the only possible terminology, but it is a useful architecture boundary.\"},\"tunes\":{}},{\"id\":\"h-spectrum\",\"type\":\"header\",\"data\":{\"text\":\"Agentic behavior is a spectrum, not a binary label\",\"level\":2},\"tunes\":{}},{\"id\":\"spectrum-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Level\",\"Example\",\"Who decides the next step?\"],[\"Single model call\",\"Summarize this document\",\"Application calls model once\"],[\"Tool-assisted response\",\"Model may use web search before answering\",\"Model selects from bounded tools for one response\"],[\"Structured workflow\",\"Classify → retrieve → generate → validate\",\"Application workflow determines stages\"],[\"Adaptive workflow\",\"Model can choose among several branches and retry\",\"Shared control between application and model\"],[\"Agent loop\",\"Model repeatedly chooses tools\u002Factions based on observations\",\"Model directs tactical execution inside runtime constraints\"],[\"Long-running agent\",\"Agent pauses, resumes, manages artifacts and continues\",\"Model + persistent runtime manage evolving execution\"]]},\"tunes\":{}},{\"id\":\"p-spectrum-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Calling every system above an “agent” can obscure important operational differences. The stronger the model's control over sequence, duration and actions, the more important runtime isolation, permissions, tracing, stopping conditions and trajectory evaluation become.\"},\"tunes\":{}},{\"id\":\"h-anatomy\",\"type\":\"header\",\"data\":{\"text\":\"The minimum architecture of an agentic system\",\"level\":2},\"tunes\":{}},{\"id\":\"anatomy-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Component\",\"Responsibility\"],[\"Goal \u002F task\",\"Defines what the system is trying to accomplish.\"],[\"Model\",\"Interprets context and decides the next action or output.\"],[\"Instructions\",\"Define role, constraints, priorities and task-specific policy.\"],[\"Context assembler\",\"Builds the information visible to the model on each step.\"],[\"Tool catalog\",\"Defines capabilities the model may request.\"],[\"Runtime \u002F harness\",\"Runs the loop, executes tools, manages state and handles stopping conditions.\"],[\"Authorization layer\",\"Determines whether a proposed action is permitted for the current principal.\"],[\"State \u002F session\",\"Preserves task progress across turns or execution steps.\"],[\"Observation channel\",\"Returns tool results and environment changes to the next model step.\"],[\"Approvals \u002F human control\",\"Pauses consequential actions where review is required.\"],[\"Tracing \u002F audit\",\"Records model calls, tools, transitions, approvals and failures.\"],[\"Evaluation\",\"Measures outcomes and execution trajectories against acceptance criteria.\"]]},\"tunes\":{}},{\"id\":\"h-model-agent\",\"type\":\"header\",\"data\":{\"text\":\"A model is not an agent\",\"level\":2},\"tunes\":{}},{\"id\":\"p-model-agent-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A language model produces outputs from inputs. It does not by itself own a filesystem, execute a shell command, maintain durable task state, enforce permissions or automatically call itself again.\"},\"tunes\":{}},{\"id\":\"p-model-agent-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Those capabilities come from the surrounding runtime. The same model can behave as a simple chat model in one application and as the decision engine inside an agent loop in another.\"},\"tunes\":{}},{\"id\":\"model-agent-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Architecture rule\",\"body\":\"\u003Cstrong>Model capability determines what decisions can be proposed. Runtime architecture determines what can actually happen.\u003C\u002Fstrong>\"},\"tunes\":{}},{\"id\":\"h-tools\",\"type\":\"header\",\"data\":{\"text\":\"Tool use is central — but tool use alone does not make an agent\",\"level\":2},\"tunes\":{}},{\"id\":\"p-tools-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Tools let the model acquire information and affect external systems. Examples include database reads, file operations, shell execution, web search, browser control, API calls, ticket updates or delegated specialist agents.\"},\"tunes\":{}},{\"id\":\"p-tools-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A single model call can use one tool and still remain a bounded tool-assisted response rather than a long-running agent. Agentic behavior appears when tool observations feed an adaptive loop in which the model chooses what to do next.\"},\"tunes\":{}},{\"id\":\"p-tools-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Tool design matters because tools are the contract between model reasoning and external reality. Ambiguous or overlapping tools create routing errors; large unstructured outputs pollute context; broad side-effect tools increase blast radius.\"},\"tunes\":{}},{\"id\":\"h-capability-permission\",\"type\":\"header\",\"data\":{\"text\":\"Tool capability, permission and authority are different\",\"level\":2},\"tunes\":{}},{\"id\":\"permission-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Layer\",\"Question\"],[\"Capability\",\"Can this runtime technically perform the operation?\"],[\"Tool exposure\",\"Is that capability available to this agent?\"],[\"Permission\",\"May this agent\u002Fsession use it under the current policy?\"],[\"User authorization\",\"Is the requesting principal allowed to cause this operation?\"],[\"Business authority\",\"Is the operation valid under domain rules, approvals and limits?\"],[\"Execution\",\"Did the operation actually occur?\"],[\"Audit\",\"Can the system prove who requested, approved and executed it?\"]]},\"tunes\":{}},{\"id\":\"p-permission-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"These layers are frequently collapsed in prototypes. A model sees a refund tool and therefore appears able to issue refunds. In production, the tool should still validate account, user, transaction, amount, policy and approval conditions independently of the model's request.\"},\"tunes\":{}},{\"id\":\"h-runtime\",\"type\":\"header\",\"data\":{\"text\":\"The runtime or harness is the actual execution system\",\"level\":2},\"tunes\":{}},{\"id\":\"p-runtime-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"OpenAI's current agent documentation makes the runtime distinction explicit. Different runtimes can manage orchestration, state, tools, sandboxes and execution in different places, while the model remains only one part of the system.\"},\"tunes\":{}},{\"id\":\"p-runtime-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The Agents SDK describes a loop that repeatedly calls the current model, inspects the output, executes requested tools or handoffs, and continues until the model returns a final answer or another real stopping point.\"},\"tunes\":{}},{\"id\":\"p-runtime-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"This means agent architecture decisions include where orchestration runs, where state lives, who executes tools, which sandbox contains side effects, and who owns retries, timeouts and resumability.\"},\"tunes\":{}},{\"id\":\"h-planning\",\"type\":\"header\",\"data\":{\"text\":\"Planning is useful, but an explicit plan is not required\",\"level\":2},\"tunes\":{}},{\"id\":\"p-planning-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Agents are often described as systems that “plan.” In practice, planning can be explicit or implicit. An agent may first produce a visible multi-step plan, or it may choose one next action at a time and revise after every observation.\"},\"tunes\":{}},{\"id\":\"p-planning-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"For highly uncertain tasks, short-horizon planning can be safer because the environment can invalidate a long plan. The architectural requirement is the ability to choose and revise actions based on the goal, current state and new evidence.\"},\"tunes\":{}},{\"id\":\"h-feedback\",\"type\":\"header\",\"data\":{\"text\":\"Environmental feedback is what makes the loop useful\",\"level\":2},\"tunes\":{}},{\"id\":\"p-feedback-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An agent becomes operationally meaningful when it can observe whether its action worked. Tool output, test results, API responses, filesystem state, browser state and application records provide external evidence that the system can use to revise its next decision.\"},\"tunes\":{}},{\"id\":\"p-feedback-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Anthropic's agent guidance emphasizes this feedback loop: agents use tools, obtain ground truth from the environment, assess progress and continue or request human input.\"},\"tunes\":{}},{\"id\":\"feedback-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Self-report is not environmental proof\",\"body\":\"An agent saying “the task is complete” does not prove completion. Where possible, verify the final state through an external system, test, file, transaction record or other observable outcome.\"},\"tunes\":{}},{\"id\":\"h-state\",\"type\":\"header\",\"data\":{\"text\":\"Agent state is not the same as model context\",\"level\":2},\"tunes\":{}},{\"id\":\"p-state-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A long-running task may need state that cannot or should not remain in the model context: task IDs, checkpoints, artifacts, approvals, external object identifiers, retry counters and workflow status.\"},\"tunes\":{}},{\"id\":\"p-state-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The runtime can preserve this durable state outside the model window and reconstruct the context required for the next step. This keeps model-visible context focused while maintaining continuity and resumability.\"},\"tunes\":{}},{\"id\":\"h-memory\",\"type\":\"header\",\"data\":{\"text\":\"Memory is optional, not the definition of an agent\",\"level\":2},\"tunes\":{}},{\"id\":\"p-memory-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An agent can operate successfully without long-term memory if the complete task fits inside one bounded run. Memory becomes useful when information must persist across sessions, tasks or long execution horizons.\"},\"tunes\":{}},{\"id\":\"p-memory-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"RAG, memory, state and context solve different problems. Treating a vector database as “the agent memory” or conversation history as “the state machine” usually hides important lifecycle and authority boundaries.\"},\"tunes\":{}},{\"id\":\"ref-memory\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context\",\"title\":\"AI Agent Memory Is Not RAG: How to Separate Memory, Retrieval, State and Context\",\"excerpt\":\"A practical architecture separating persistent memory, authoritative application state, retrieval and the context supplied to the model.\",\"ctaLabel\":\"Read the memory architecture article\"},\"tunes\":{}},{\"id\":\"h-context\",\"type\":\"header\",\"data\":{\"text\":\"Context engineering becomes dynamic in agents\",\"level\":2},\"tunes\":{}},{\"id\":\"p-context-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Every tool call can produce new context. Every step can also make earlier information obsolete. A strong agent runtime therefore rebuilds or curates context as execution progresses rather than replaying everything indefinitely.\"},\"tunes\":{}},{\"id\":\"p-context-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Tool definitions, task state, retrieved evidence, observations and memory all compete for the model's attention. Long-running agents need trimming, compaction or just-in-time loading so context remains relevant to the current decision.\"},\"tunes\":{}},{\"id\":\"h-sideeffects\",\"type\":\"header\",\"data\":{\"text\":\"Read tools and side-effect tools have different risk\",\"level\":2},\"tunes\":{}},{\"id\":\"sideeffect-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Information access versus external action\",\"layout\":\"table\",\"columns\":[{\"id\":\"read\",\"label\":\"Read \u002F observe\"},{\"id\":\"write\",\"label\":\"Write \u002F act\"}],\"rows\":[{\"id\":\"examples\",\"label\":\"Examples\",\"values\":[\"\",\"\"]},{\"id\":\"mainrisk\",\"label\":\"Main risk\",\"values\":[\"\",\"\"]},{\"id\":\"control\",\"label\":\"Typical control\",\"values\":[\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"h-approval\",\"type\":\"header\",\"data\":{\"text\":\"Human-in-the-loop is a control mechanism, not the opposite of agentic AI\",\"level\":2},\"tunes\":{}},{\"id\":\"p-approval-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An agent does not stop being agentic because a human approves consequential steps. The model can still autonomously inspect, reason, search and prepare an action while the runtime requires human confirmation before execution.\"},\"tunes\":{}},{\"id\":\"p-approval-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"OpenAI's current agent safety guidance explicitly recommends approvals for tool operations in higher-risk workflows. Anthropic likewise emphasizes checkpoints and human judgment where agents encounter blockers or consequential decisions.\"},\"tunes\":{}},{\"id\":\"p-approval-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The useful architecture question is not “human or autonomous?” but which decisions can be delegated, which require review and which must remain deterministic?\"},\"tunes\":{}},{\"id\":\"h-stopping\",\"type\":\"header\",\"data\":{\"text\":\"Agents need explicit stopping conditions\",\"level\":2},\"tunes\":{}},{\"id\":\"stop-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Stopping condition\",\"Purpose\"],[\"Successful verified outcome\",\"End when the external target state is confirmed.\"],[\"Maximum steps\",\"Prevent runaway loops.\"],[\"Time budget\",\"Bound wall-clock execution.\"],[\"Cost\u002Ftoken budget\",\"Limit resource consumption.\"],[\"Repeated-action detector\",\"Stop loops that are no longer making progress.\"],[\"Permission boundary\",\"Pause or stop when the next required action is not permitted.\"],[\"Human approval checkpoint\",\"Wait before consequential execution.\"],[\"Unrecoverable tool failure\",\"Escalate instead of retrying indefinitely.\"],[\"Uncertainty threshold\",\"Ask for clarification when the task cannot be safely inferred.\"]]},\"tunes\":{}},{\"id\":\"h-errors\",\"type\":\"header\",\"data\":{\"text\":\"Recovery is part of agent behavior\",\"level\":2},\"tunes\":{}},{\"id\":\"p-errors-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Agents operate in environments that fail: APIs time out, files change, credentials expire, webpages move and tools return malformed output. A useful agentic system therefore needs recovery behavior, not just a happy-path tool loop.\"},\"tunes\":{}},{\"id\":\"p-errors-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Recovery can include retry with limits, choosing another tool, re-reading current state, asking the user, rolling back a partial action or escalating to a human.\"},\"tunes\":{}},{\"id\":\"p-errors-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Retries also need idempotency awareness. Repeating a read is usually low risk; repeating a payment or message send can create duplicate side effects.\"},\"tunes\":{}},{\"id\":\"h-single-multi\",\"type\":\"header\",\"data\":{\"text\":\"Agentic AI does not require multiple agents\",\"level\":2},\"tunes\":{}},{\"id\":\"p-multi-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A single agent with a clear tool set is often simpler and easier to evaluate than a multi-agent architecture. Multiple agents are useful when specialization materially improves tool isolation, policy isolation, prompt clarity, ownership or trace legibility.\"},\"tunes\":{}},{\"id\":\"p-multi-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"OpenAI's current orchestration guidance explicitly recommends starting with one agent where possible and adding specialists only when the contract or ownership boundary materially changes.\"},\"tunes\":{}},{\"id\":\"p-multi-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Multi-agent systems add new problems: delegation quality, duplicated context, conflicting state, handoff semantics, identity, cost and distributed failure handling.\"},\"tunes\":{}},{\"id\":\"h-protocols\",\"type\":\"header\",\"data\":{\"text\":\"Agent protocols are interoperability layers, not the agent itself\",\"level\":2},\"tunes\":{}},{\"id\":\"p-protocols-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Protocols such as MCP and A2A can make an agent architecture interoperable, but they do not create the agent loop by themselves. MCP can expose tools and resources. A2A can connect independently implemented agents. The application still needs runtime, authorization, state, evaluation and domain logic.\"},\"tunes\":{}},{\"id\":\"p-protocols-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"This is why protocol capability must remain separate from business authority. Discovering a tool through MCP does not prove the current principal is allowed to use it. Receiving a task through A2A does not prove the remote agent may perform every requested action.\"},\"tunes\":{}},{\"id\":\"ref-protocols\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fde\u002Fblog\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained\",\"title\":\"MCP vs A2A vs UCP vs AP2 vs A2UI: The Agent Protocol Stack Explained\",\"excerpt\":\"A protocol-responsibility map showing why tool access, agent collaboration, commerce, payment authority and agent-driven UI belong to different interoperability boundaries.\",\"ctaLabel\":\"Read the agent protocol stack\"},\"tunes\":{}},{\"id\":\"h-reliability\",\"type\":\"header\",\"data\":{\"text\":\"The trajectory is part of agent reliability\",\"level\":2},\"tunes\":{}},{\"id\":\"p-rel-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A final answer is insufficient evidence for an agentic system because an agent can reach the right result through an unsafe or invalid path. It may use an unauthorized tool, skip a required check, retry a side effect, rely on stale state or accidentally succeed.\"},\"tunes\":{}},{\"id\":\"p-rel-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Evaluation therefore needs execution traces: decisions, tool calls, approvals, observations, state changes and final outcome. Current OpenAI safety guidance recommends trace graders and evals; Anthropic's 2026 agent-evaluation guidance similarly treats multi-turn tool trajectories as first-class evaluation objects.\"},\"tunes\":{}},{\"id\":\"p-rel-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The stronger reliability question is: Did the agent reach an acceptable outcome through an acceptable, recoverable and auditable trajectory?\"},\"tunes\":{}},{\"id\":\"ref-reliability\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-reliability-why-the-final-answer-is-not-enough\",\"title\":\"AI Agent Reliability: Why the Final Answer Is Not Enough\",\"excerpt\":\"Why production evaluation must inspect trajectories, tool use, state transitions and recoverability rather than only final answers.\",\"ctaLabel\":\"Read the reliability article\"},\"tunes\":{}},{\"id\":\"h-security\",\"type\":\"header\",\"data\":{\"text\":\"Agentic systems increase the security surface\",\"level\":2},\"tunes\":{}},{\"id\":\"security-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Risk\",\"Why agents amplify it\",\"Architecture response\"],[\"Prompt injection\",\"Untrusted content can influence future tool decisions\",\"Separate instructions from data; constrain tools; sanitize or structure external input where possible\"],[\"Excessive permissions\",\"Reasoning errors can become real side effects\",\"Least privilege, scoped credentials, per-tool policy and approvals\"],[\"Credential exposure\",\"Tools may need powerful secrets\",\"Keep secrets outside model context; broker access through trusted runtime\"],[\"Confused deputy\",\"Agent may act with authority broader than the requesting user\",\"Bind execution to user\u002Fservice identity and re-authorize consequential actions\"],[\"Runaway loops\",\"Model repeatedly calls tools without progress\",\"Step, time and cost budgets plus loop detection\"],[\"State drift\",\"Environment changes after the agent formed a plan\",\"Re-read authoritative state before consequential actions\"],[\"Indirect injection\",\"Tool\u002Fweb\u002Fdocument content contains instructions aimed at the model\",\"Treat external content as untrusted data, not instruction authority\"],[\"Audit gap\",\"Final result cannot show what was executed\",\"Trace tool calls, approvals, identities and state changes\"]]},\"tunes\":{}},{\"id\":\"h-observability\",\"type\":\"header\",\"data\":{\"text\":\"Agent observability must follow the loop\",\"level\":2},\"tunes\":{}},{\"id\":\"p-obs-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Traditional service observability records requests, latency and errors. Agent observability needs an additional execution model: which agent was active, which model version made the decision, what context was available, which tool was selected, what arguments were sent, what result came back and why execution stopped.\"},\"tunes\":{}},{\"id\":\"p-obs-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"For sensitive systems, traces themselves require access control and retention policy because prompts, tool outputs and artifacts can contain confidential data.\"},\"tunes\":{}},{\"id\":\"h-eval\",\"type\":\"header\",\"data\":{\"text\":\"How to evaluate an agentic system\",\"level\":2},\"tunes\":{}},{\"id\":\"eval-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Dimension\",\"Question\",\"Example evidence\"],[\"Task success\",\"Did the requested outcome occur?\",\"External state, tests, business outcome\"],[\"Trajectory quality\",\"Were the steps acceptable?\",\"Tool\u002Faction trace\"],[\"Tool selection\",\"Did the agent choose appropriate capabilities?\",\"Expected vs actual tool calls\"],[\"Permission adherence\",\"Did it stay inside allowed authority?\",\"Authorization logs and denied-action tests\"],[\"State handling\",\"Did it use current authoritative state?\",\"Freshness checks and state-change tests\"],[\"Recovery\",\"Did it respond correctly to failures?\",\"Injected timeout\u002Ferror scenarios\"],[\"Stopping behavior\",\"Did it stop at the right point?\",\"Step counts, loop detection, final-state proof\"],[\"Human escalation\",\"Did it ask when review was required?\",\"Approval\u002Fescalation traces\"],[\"Cost\u002Flatency\",\"Was autonomy worth the operational cost?\",\"Tokens, tool calls, duration\"],[\"Robustness\",\"Does it survive realistic environment variation?\",\"Repeated and adversarial trials\"]]},\"tunes\":{}},{\"id\":\"h-use\",\"type\":\"header\",\"data\":{\"text\":\"When an agent is appropriate\",\"level\":2},\"tunes\":{}},{\"id\":\"use-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Use an agent when\",\"Prefer a workflow or simple call when\"],[\"The number or order of steps cannot be known reliably in advance\",\"The sequence is stable and deterministic\"],[\"The system must inspect the environment and adapt\",\"A single retrieval + generation step is sufficient\"],[\"Several tools may be useful depending on intermediate results\",\"One known API call solves the task\"],[\"The task benefits from iterative verification or repair\",\"The answer can be produced directly from supplied context\"],[\"Failures require flexible recovery behavior\",\"Failure branches are simple and can be encoded explicitly\"],[\"Human review can be inserted at meaningful checkpoints\",\"Every step is high-risk and must be manually controlled anyway\"],[\"Expected value justifies extra latency, cost and complexity\",\"Predictability and low cost matter more than flexibility\"]]},\"tunes\":{}},{\"id\":\"p-use-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A strong default is to start with the simplest solution that works and increase agentic complexity only when flexibility produces measurable value. Agents trade predictability, latency and cost for adaptive execution.\"},\"tunes\":{}},{\"id\":\"h-implementation\",\"type\":\"header\",\"data\":{\"text\":\"Original implementation evidence\",\"level\":2},\"tunes\":{}},{\"id\":\"h-client\",\"type\":\"header\",\"data\":{\"text\":\"Aaasaasa AI Client: model, runtime and permission are separate\",\"level\":3},\"tunes\":{}},{\"id\":\"p-client-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Aaasaasa AI Client explicitly separates agent\u002Fclient, provider, model, runtime location and permissions. Its architecture documentation treats permissions as central tool\u002Fworkspace policy rather than a model property.\"},\"tunes\":{}},{\"id\":\"p-client-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The same application can expose Direct Chat with no filesystem or shell tools while a Codex runtime operates under a selected workspace and permission profile. This demonstrates a core agentic architecture boundary: changing the runtime\u002Ftool surface changes what the system can do even when model access remains available.\"},\"tunes\":{}},{\"id\":\"p-client-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The repository also distinguishes a local Codex runtime from model location: a local runtime can call a cloud model. This prevents the common mistake of equating “agent runs locally” with “inference is local.”\"},\"tunes\":{}},{\"id\":\"p-client-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"The implementation disables embedded execution paths whose approval semantics do not satisfy the required permission model. This supports the principle that agent capability should not bypass runtime authorization simply because an underlying framework can execute tools.\"},\"tunes\":{}},{\"id\":\"h-sot-agent\",\"type\":\"header\",\"data\":{\"text\":\"Source of Truth Research Engine: bounded agentic research stages\",\"level\":3},\"tunes\":{}},{\"id\":\"p-sot-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The Source of Truth Research Engine uses a bounded research pipeline: discover → acquire → extract → verify → contradict → synthesize. Research jobs can execute through an AI runtime while evidence, sources, claims and contradictions remain in an external persistent store.\"},\"tunes\":{}},{\"id\":\"p-sot-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"This is intentionally more controlled than an unconstrained autonomous research agent. The stages provide guardrails around what kind of work should happen next while still allowing model-driven research inside each bounded task.\"},\"tunes\":{}},{\"id\":\"p-sot-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"That distinction is useful evidence for agent design: autonomy can be placed inside a structured delivery envelope rather than applied uniformly to the entire process.\"},\"tunes\":{}},{\"id\":\"impl-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Implemented pattern\",\"Agentic architecture lesson\"],[\"Direct Chat has no OS tools\",\"A model can exist without agentic execution capability.\"],[\"Codex runtime has workspace permission profile\",\"Tool authority belongs to runtime policy, not model capability.\"],[\"Provider\u002Fmodel\u002Fruntime are separate concepts\",\"Agent harness location and inference location are independent decisions.\"],[\"Permission broker for tool-capable runtimes\",\"Capability exposure can be centralized and governed.\"],[\"Bounded research stages\",\"Autonomy can operate inside explicit process boundaries.\"],[\"Persistent claims\u002Fevidence outside model context\",\"Agent state and evidence do not need to live only in conversation history.\"]]},\"tunes\":{}},{\"id\":\"impl-boundary\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Evidence boundary\",\"body\":\"These projects demonstrate concrete agent\u002Fruntime, permission and bounded-research patterns. They are not presented as proof of large-scale commercial autonomous-agent deployment.\"},\"tunes\":{}},{\"id\":\"h-failures\",\"type\":\"header\",\"data\":{\"text\":\"Common agentic AI failure modes\",\"level\":2},\"tunes\":{}},{\"id\":\"failure-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Failure mode\",\"What actually failed\"],[\"“Agent” is only a chatbot with tools listed in the prompt\",\"No reliable runtime loop or tool execution architecture exists\"],[\"Tool support is treated as permission\",\"Capability and authorization boundaries are collapsed\"],[\"Agent trusts its own completion statement\",\"Outcome is not verified against external state\"],[\"Every task becomes multi-agent\",\"Complexity increases without a real ownership or specialization boundary\"],[\"Conversation history is used as durable state\",\"Resumability and authoritative state become fragile\"],[\"Agent retries side effects blindly\",\"Duplicate messages, payments or state changes become possible\"],[\"No step\u002Fcost limits\",\"Agent can loop indefinitely or consume uncontrolled resources\"],[\"Tool output is trusted as instruction\",\"Indirect prompt injection can redirect behavior\"],[\"Correct final answer is the only evaluation\",\"Unsafe or invalid trajectories remain invisible\"],[\"Model upgrade is treated as transparent\",\"Tool selection, planning and stopping behavior can change\"],[\"One broad tool exposes many privileged operations\",\"Blast radius increases and intent becomes harder to validate\"],[\"Human approval exists but reviewer lacks context\",\"Approval becomes ceremonial rather than effective\"]]},\"tunes\":{}},{\"id\":\"h-misconceptions\",\"type\":\"header\",\"data\":{\"text\":\"Common misconceptions\",\"level\":2},\"tunes\":{}},{\"id\":\"misconceptions-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Misconception\",\"Correction\"],[\"“An LLM is an agent.”\",\"The model is the decision component; the agent is the surrounding system that manages tools, state and iteration.\"],[\"“Tool calling automatically means agentic AI.”\",\"A single bounded tool call may not involve an adaptive multi-step agent loop.\"],[\"“Agents must be fully autonomous.”\",\"Agentic systems can require approvals and operate under narrow permission boundaries.\"],[\"“Agents need long-term memory.”\",\"Memory is optional; many useful agents complete bounded tasks without cross-session memory.\"],[\"“Agents must create a written plan first.”\",\"Planning can be explicit or implicit and can occur one step at a time.\"],[\"“Multi-agent is more advanced than single-agent.”\",\"It is more complex; use it only when specialization or ownership boundaries justify it.\"],[\"“MCP creates an agent.”\",\"MCP exposes tools\u002Fresources; the runtime still needs an agent loop and authorization model.\"],[\"“A local runtime means the model is local.”\",\"Runtime location and inference\u002Fprovider location are separate.\"],[\"“If the final result is correct, the agent worked correctly.”\",\"An unsafe or unauthorized trajectory can still produce a correct result.\"],[\"“Human approval removes autonomy.”\",\"Approval can constrain selected actions while the rest of the process remains model-directed.\"]]},\"tunes\":{}},{\"id\":\"h-design\",\"type\":\"header\",\"data\":{\"text\":\"A practical agent design sequence\",\"level\":2},\"tunes\":{}},{\"id\":\"design-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"Design the agent from authority outward\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Define the outcome\",\"description\":\"State what external result or artifact proves task success.\"},{\"label\":\"2. Decide whether an agent is actually needed\",\"description\":\"Prefer a simple call or deterministic workflow when the path is predictable.\"},{\"label\":\"3. Identify state and Source of Truth\",\"description\":\"Define which systems own current facts, task progress and business state.\"},{\"label\":\"4. Define the tool surface\",\"description\":\"Expose the smallest set of clear capabilities required for the task.\"},{\"label\":\"5. Bind identity and permissions\",\"description\":\"Separate user authority, agent\u002Fruntime permissions and tool capabilities.\"},{\"label\":\"6. Choose autonomy boundaries\",\"description\":\"Specify what the model may decide dynamically and what remains deterministic.\"},{\"label\":\"7. Add approval checkpoints\",\"description\":\"Require review before consequential or irreversible actions where appropriate.\"},{\"label\":\"8. Define stopping and recovery\",\"description\":\"Set success proof, budgets, timeouts, retries, escalation and loop controls.\"},{\"label\":\"9. Design context\u002Fstate management\",\"description\":\"Keep current state, memory, tool observations and durable artifacts in the correct layers.\"},{\"label\":\"10. Trace the trajectory\",\"description\":\"Record enough execution structure to debug and audit model\u002Ftool decisions.\"},{\"label\":\"11. Evaluate realistic failures\",\"description\":\"Test stale state, tool errors, prompt injection, ambiguous requests and changed environments.\"},{\"label\":\"12. Expand autonomy only from evidence\",\"description\":\"Increase permissions or execution horizon when evaluation shows the benefit justifies the risk.\"}]},\"tunes\":{}},{\"id\":\"h-checklist\",\"type\":\"header\",\"data\":{\"text\":\"Agentic AI architecture checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"checklist-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Question\",\"Expected evidence\"],[\"What proves success?\",\"External outcome, artifact, test or authoritative state.\"],[\"Why is an agent needed?\",\"The path genuinely depends on intermediate observations.\"],[\"Which decisions are model-driven?\",\"Explicit autonomy boundary.\"],[\"Which tools exist?\",\"Small, documented, unambiguous capability set.\"],[\"Who may use each tool?\",\"Identity- and context-aware authorization policy.\"],[\"Which actions need approval?\",\"Consequence-based review rules.\"],[\"Where does task state live?\",\"Application-owned state separate from transient model context.\"],[\"How does the agent recover?\",\"Retry, re-read, rollback, clarification and escalation behavior.\"],[\"How does it stop?\",\"Verified completion plus step\u002Ftime\u002Fcost limits.\"],[\"How are side effects protected?\",\"Validation, idempotency, least privilege and confirmation.\"],[\"Can execution be reconstructed?\",\"Tool, approval and state-transition traces.\"],[\"How is it evaluated?\",\"Outcome + trajectory + robustness tests.\"],[\"What changes after a model\u002Fruntime update?\",\"Regression suite for tool selection, permissions, stopping and recovery.\"]]},\"tunes\":{}},{\"id\":\"h-edge\",\"type\":\"header\",\"data\":{\"text\":\"Edge cases and limitations\",\"level\":2},\"tunes\":{}},{\"id\":\"p-edge-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Some systems are “agentic” only in a narrow routing sense: the model selects one specialist or tool and then the rest of the workflow is deterministic. That can still be useful, but it should not be described as equivalent to a long-running autonomous agent.\"},\"tunes\":{}},{\"id\":\"p-edge-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Highly consequential domains may intentionally restrict agent autonomy. An AI system can inspect evidence, prepare recommendations and fill structured forms while a human remains the only actor allowed to commit the final transaction.\"},\"tunes\":{}},{\"id\":\"p-edge-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Some environments are well suited to agents because feedback is objective. Coding agents can run tests; infrastructure agents can inspect metrics; data agents can validate query results. Open-ended domains with weak feedback require more cautious evaluation.\"},\"tunes\":{}},{\"id\":\"p-edge-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"An agent can operate entirely locally, entirely through managed cloud services or in a hybrid architecture. Agentic behavior describes control flow, not hosting location.\"},\"tunes\":{}},{\"id\":\"p-edge-5\",\"type\":\"paragraph\",\"data\":{\"text\":\"The term “reasoning” should not be used as proof that the agent's internal process is correct. Production assurance should rely on observable inputs, actions, outputs, state and evaluation rather than unverifiable claims about hidden reasoning.\"},\"tunes\":{}},{\"id\":\"h-change\",\"type\":\"header\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Vendor APIs and agent frameworks will continue to evolve, but the architecture boundary is stable: a model proposes decisions, a runtime manages the loop, tools connect to the environment, permissions constrain actions and external observations determine what actually happened.\"},\"tunes\":{}},{\"id\":\"p-change-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"As models become more reliable, systems may safely delegate longer horizons or more complex recovery behavior. As runtime verification and authorization improve, some approval steps may become automated. Those are changes in autonomy level, not changes to the fundamental responsibility layers.\"},\"tunes\":{}},{\"id\":\"p-change-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The recommended architecture also changes by consequence. A research agent that only reads public sources can tolerate different controls from an agent that writes production configuration or moves money.\"},\"tunes\":{}},{\"id\":\"h-related\",\"type\":\"header\",\"data\":{\"text\":\"Related canonical knowledge\",\"level\":2},\"tunes\":{}},{\"id\":\"p-related-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Agentic AI sits above several prerequisite layers: context engineering determines what the model sees; Source-of-Truth architecture determines which information is authoritative; retrieval supplies external evidence; runtime architecture determines what can execute.\"},\"tunes\":{}},{\"id\":\"p-related-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Downstream nodes include tool calling, MCP, A2A, agent identity, permissions, auditability, human-in-the-loop, orchestration, memory and multi-agent systems.\"},\"tunes\":{}},{\"id\":\"p-related-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The protocol stack article should therefore be read after the basic agent concept: protocols standardize boundaries around agents; they do not define agentic behavior itself.\"},\"tunes\":{}},{\"id\":\"h-faq\",\"type\":\"header\",\"data\":{\"text\":\"Frequently asked questions\",\"level\":2},\"tunes\":{}},{\"id\":\"faq\",\"type\":\"faq\",\"data\":{\"title\":\"Agentic AI FAQ\",\"items\":[{\"id\":\"faq1\",\"question\":\"What is agentic AI?\",\"answer\":\"Agentic AI is an AI system in which a model can pursue a goal over multiple steps by choosing actions or tools, observing results, updating its state and continuing until a stopping condition is reached.\"},{\"id\":\"faq2\",\"question\":\"What is the difference between an LLM and an AI agent?\",\"answer\":\"An LLM produces outputs from inputs. An agent combines a model with a runtime, tools, state, permissions, context management and an iterative execution loop.\"},{\"id\":\"faq3\",\"question\":\"Does tool calling make a system an agent?\",\"answer\":\"Not necessarily. A single tool-assisted model response can be bounded and non-agentic. Agentic behavior appears when tool observations drive an adaptive multi-step loop.\"},{\"id\":\"faq4\",\"question\":\"What is the difference between an agent and an AI workflow?\",\"answer\":\"A workflow usually follows a process path defined in application code. An agent has more model-driven control over which steps and tools to use based on intermediate observations.\"},{\"id\":\"faq5\",\"question\":\"Do agents need memory?\",\"answer\":\"No. Long-term memory is useful for persistent information across sessions, but many agents complete bounded tasks using only current task state and context.\"},{\"id\":\"faq6\",\"question\":\"Do AI agents need multiple agents?\",\"answer\":\"No. A single agent is often simpler. Multi-agent systems are justified when specialization, tool isolation, policy isolation or ownership boundaries materially improve the system.\"},{\"id\":\"faq7\",\"question\":\"Can an agent be human-in-the-loop?\",\"answer\":\"Yes. The agent can autonomously perform low-risk analysis and preparation while the runtime pauses for human approval before consequential actions.\"},{\"id\":\"faq8\",\"question\":\"Is MCP an agent framework?\",\"answer\":\"No. MCP is an interoperability protocol for exposing tools, resources and prompts. An agent runtime can use MCP, but still needs its own loop, state, authorization and evaluation.\"},{\"id\":\"faq9\",\"question\":\"How do you know an agent actually completed a task?\",\"answer\":\"Where possible, verify success through external state, tests, artifacts or authoritative system records rather than trusting the model's own completion statement.\"}]},\"tunes\":{}},{\"id\":\"h-glossary\",\"type\":\"header\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"tunes\":{}},{\"id\":\"glossary\",\"type\":\"glossary\",\"data\":{\"title\":\"Key agentic AI terms\",\"entries\":[{\"term\":\"Agentic AI\",\"definition\":\"AI system behavior in which a model dynamically directs multi-step execution using tools, observations and state toward a goal.\",\"anchor\":\"agentic-ai\"},{\"term\":\"AI agent\",\"definition\":\"A model-centered system with runtime, tools, state and an execution loop that can pursue a task over multiple steps.\",\"anchor\":\"ai-agent\"},{\"term\":\"Agent loop\",\"definition\":\"Repeated cycle of model decision, tool\u002Faction execution, observation and updated model decision until stopping.\",\"anchor\":\"agent-loop\"},{\"term\":\"Runtime \u002F harness\",\"definition\":\"The execution layer that manages the model loop, tools, state, approvals, context, errors and stopping conditions.\",\"anchor\":\"runtime-harness\"},{\"term\":\"Tool\",\"definition\":\"A capability exposed to the model for reading information, computing, delegating or changing external state.\",\"anchor\":\"tool\"},{\"term\":\"Observation\",\"definition\":\"Information returned from a tool or environment and supplied to a later agent step.\",\"anchor\":\"observation\"},{\"term\":\"Agent state\",\"definition\":\"Persistent task or execution information that exists outside a single model output and may survive across steps or pauses.\",\"anchor\":\"agent-state\"},{\"term\":\"Autonomy boundary\",\"definition\":\"The explicit limit defining which decisions and actions the model may control dynamically.\",\"anchor\":\"autonomy-boundary\"},{\"term\":\"Human-in-the-loop\",\"definition\":\"A control pattern in which human review, input or approval is required at selected points in an AI-driven process.\",\"anchor\":\"human-in-the-loop\"},{\"term\":\"Trajectory\",\"definition\":\"The sequence of relevant states, decisions, tool calls, actions and observations between task request and final outcome.\",\"anchor\":\"trajectory\"},{\"term\":\"Idempotency\",\"definition\":\"Property that allows an operation to be repeated without unintentionally applying the same side effect multiple times.\",\"anchor\":\"idempotency\"}]},\"tunes\":{}},{\"id\":\"h-conclusion\",\"type\":\"header\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"tunes\":{}},{\"id\":\"p-conclusion-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Agentic AI is not simply a smarter model or a chatbot with more tools. It is a system architecture in which a model participates in an iterative control loop: decide, act, observe, update and continue.\"},\"tunes\":{}},{\"id\":\"p-conclusion-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The model provides flexible decision making, but the surrounding runtime must own execution reality: permissions, tool access, state, approvals, retries, budgets, stopping conditions, tracing and verification.\"},\"tunes\":{}},{\"id\":\"p-conclusion-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The most useful design principle is therefore: delegate tactical choice to the model only inside explicit technical and business boundaries. Agentic capability becomes production capability only when autonomy, authority and evidence remain separable.\"},\"tunes\":{}},{\"id\":\"h-sources\",\"type\":\"header\",\"data\":{\"text\":\"Primary sources and current guidance\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sources-note\",\"type\":\"paragraph\",\"data\":{\"text\":\"The sources below support the current architectural distinctions around agents, workflows, loops, tools, orchestration, safety and evaluation. Project sections are original implementation evidence and are explicitly bounded to what the repositories demonstrate.\"},\"tunes\":{}},{\"id\":\"src-openai-agents\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Agents\",\"description\":\"Current developer guidance defining runtime choices for multi-step work, tools, state, orchestration and agent execution.\"}},\"tunes\":{}},{\"id\":\"src-openai-definitions\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents\u002Fdefine-agents\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Agent definitions\",\"description\":\"Current documentation describing an agent as a model plus instructions and optional runtime behavior including tools, guardrails, MCP servers and handoffs.\"}},\"tunes\":{}},{\"id\":\"src-openai-running\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents\u002Frunning-agents\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Running agents\",\"description\":\"Current documentation of the agent loop: model call, tool execution or handoff, continuation and final stopping point.\"}},\"tunes\":{}},{\"id\":\"src-openai-orchestration\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents\u002Forchestration\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Orchestration and handoffs\",\"description\":\"Current guidance on handoffs, agents-as-tools and when specialist agents add useful ownership or capability boundaries.\"}},\"tunes\":{}},{\"id\":\"src-openai-safety\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagent-builder-safety\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"OpenAI — Safety in building agents\",\"description\":\"Current safety guidance covering tool approvals, prompt injection, guardrails and trace-based evaluation.\"}},\"tunes\":{}},{\"id\":\"src-anthropic-agents\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Fbuilding-effective-agents\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Anthropic — Building effective agents\",\"description\":\"Engineering guidance distinguishing predefined workflows from model-directed agents and describing tool-based environmental feedback loops.\"}},\"tunes\":{}},{\"id\":\"src-anthropic-context\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Feffective-context-engineering-for-ai-agents\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Anthropic — Effective context engineering for AI agents\",\"description\":\"Practical framing of agents as LLMs autonomously using tools in a loop, with dynamic just-in-time context management.\"}},\"tunes\":{}},{\"id\":\"src-anthropic-evals\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Fdemystifying-evals-for-ai-agents\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Anthropic — Demystifying evals for AI agents\",\"description\":\"2026 guidance on evaluating multi-turn agents that call tools, modify state and adapt to intermediate results.\"}},\"tunes\":{}}],\"version\":\"2.31.6\"}",{"time":212,"blocks":213,"version":1537},1791487185746,[214,220,228,235,242,250,255,260,265,270,275,280,285,290,319,324,329,334,339,371,376,381,414,419,424,468,473,478,483,490,495,500,505,510,515,544,549,554,559,564,569,574,579,584,589,594,599,605,610,615,620,625,630,635,644,649,654,659,664,689,694,699,704,709,714,749,754,759,764,769,774,779,784,789,794,799,804,812,817,822,827,832,840,845,885,890,895,900,905,953,958,987,992,997,1002,1007,1012,1017,1022,1027,1032,1037,1042,1068,1074,1079,1123,1128,1166,1171,1213,1218,1264,1269,1274,1279,1284,1289,1294,1299,1304,1309,1314,1319,1324,1329,1334,1339,1381,1386,1434,1439,1444,1449,1454,1459,1464,1474,1483,1492,1501,1510,1519,1528],{"id":215,"data":216,"type":218,"tunes":219},"intro",{"text":217},"Agentic AI is an AI system in which a model can pursue a goal across multiple steps by deciding what to do next, using tools or other capabilities, observing the results, updating its working state and continuing until it reaches a stopping condition. The model alone is not the agent. A usable agent also needs a runtime or harness that manages context, tool execution, state, permissions, approvals, errors and the loop between decisions and observations.","paragraph",{},{"id":221,"data":222,"type":226,"tunes":227},"direct",{"body":223,"title":224,"variant":225},"A normal model call is usually \u003Cstrong>input → model → output\u003C\u002Fstrong>. An agentic system is closer to \u003Cstrong>goal → decision → tool\u002Faction → observation → updated decision → … → result\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The critical distinction is not whether an application uses an LLM or function calling. It is whether the system gives the model meaningful control over the next step of a multi-step process while a runtime constrains what the model is actually allowed to do.","Direct answer","info","callout",{},{"id":229,"data":230,"type":226,"tunes":234},"boundary",{"body":231,"title":232,"variant":233},"A model may know how to call a tool. A runtime may expose that tool. Neither fact means the current user or agent is authorized to execute the underlying business action. \u003Cstrong>Tool capability, tool permission and business authority are separate layers.\u003C\u002Fstrong>","Capability is not authority","warning",{},{"id":236,"data":237,"type":226,"tunes":241},"current",{"body":238,"title":239,"variant":240},"Agent terminology still varies across vendors and research communities. OpenAI currently defines agent runtimes around multi-step work, tools, state and orchestration. Anthropic's practical distinction remains useful: workflows follow predefined code paths, while agents dynamically direct their own process and tool use. This article therefore treats “agentic AI” as an architectural spectrum rather than one standardized product category.","Current-source note — 8 October 2026","note",{},{"id":243,"data":244,"type":248,"tunes":249},"toc",{"title":245,"maxLevel":246,"minLevel":247},"Contents",3,2,"tableOfContents",{},{"id":251,"data":252,"type":42,"tunes":254},"h-meaning",{"text":253,"level":247},"What agentic AI really means",{},{"id":256,"data":257,"type":218,"tunes":259},"p-meaning-1",{"text":258},"The important shift from ordinary generative AI to agentic AI is control over process. A normal assistant can answer a question using the context it receives. An agent can decide that answering requires additional steps: inspect a file, search a repository, query an API, ask for clarification, run a test, update a ticket, delegate a subtask or retry after a failed action.",{},{"id":261,"data":262,"type":218,"tunes":264},"p-meaning-2",{"text":263},"This does not require unlimited autonomy. An agent can operate inside a narrow sandbox, under strict permissions, with approval required before every consequential action. The system is still agentic if the model dynamically chooses among permitted next steps.",{},{"id":266,"data":267,"type":218,"tunes":269},"p-meaning-3",{"text":268},"The architecture therefore matters more than the label. “Agent” should describe a system behavior: iterative model-driven decision making over tools, state and feedback — not merely a chatbot with a larger prompt.",{},{"id":271,"data":272,"type":42,"tunes":274},"h-simple",{"text":273,"level":247},"The simplest example",{},{"id":276,"data":277,"type":218,"tunes":279},"p-simple-1",{"text":278},"Suppose a developer asks an AI system: “Find why the test suite fails and fix the bug.” A single model call could only suggest likely causes from the text it was given.",{},{"id":281,"data":282,"type":218,"tunes":284},"p-simple-2",{"text":283},"An agentic coding system can inspect the repository, search for the failing test, read relevant files, propose a change, edit the code, run the test, observe the failure, revise the implementation and run the test again.",{},{"id":286,"data":287,"type":218,"tunes":289},"p-simple-3",{"text":288},"The agentic part is not simply that shell and file tools exist. It is that the model can use environmental feedback to choose the next step instead of following one completely predefined sequence.",{},{"id":291,"data":292,"type":317,"tunes":318},"simple-loop",{"steps":293,"title":315,"orientation":316},[294,297,300,303,306,309,312],{"label":295,"description":296},"1. Receive a goal","The user or upstream system defines the objective and relevant constraints.",{"label":298,"description":299},"2. Build current context","The runtime supplies instructions, state, history, memory, tools and current evidence.",{"label":301,"description":302},"3. Model decides next step","The model may answer, call a tool, request information, delegate or stop.",{"label":304,"description":305},"4. Runtime validates the request","Permissions, schemas, approvals and policy determine whether the proposed action may execute.",{"label":307,"description":308},"5. Execute tool or action","The external environment changes or returns new information.",{"label":310,"description":311},"6. Observe the result","The runtime feeds structured tool output, errors or state changes back into the next model step.",{"label":313,"description":314},"7. Continue or stop","The loop repeats until success, refusal, escalation, budget limit, timeout or another stopping condition.","The basic agent loop","auto","processFlow",{},{"id":320,"data":321,"type":42,"tunes":323},"h-stops",{"text":322,"level":247},"Where the simple example stops",{},{"id":325,"data":326,"type":218,"tunes":328},"p-stops-1",{"text":327},"Not every multi-step AI system is equally agentic. A workflow may use several LLM calls and tools while every step is predetermined in code. Another system may let the model decide which tool to call, in which order, how many times and when to stop.",{},{"id":330,"data":331,"type":218,"tunes":333},"p-stops-2",{"text":332},"Both can be useful. The difference is where control lives. Predefined workflows put more control in application code. Agents move more tactical process decisions into the model\u002Fruntime loop.",{},{"id":335,"data":336,"type":42,"tunes":338},"h-workflow",{"text":337,"level":247},"Agent vs workflow",{},{"id":340,"data":341,"type":369,"tunes":370},"workflow-comparison",{"rows":342,"title":360,"layout":361,"columns":362},[343,348,352,356],{"id":344,"label":345,"values":346},"path","Process path",[347,347],"",{"id":349,"label":350,"values":351},"tools","Tool sequence",[347,347],{"id":353,"label":354,"values":355},"strength","Strength",[347,347],{"id":357,"label":358,"values":359},"risk","Risk",[347,347],"Predefined workflow and agentic control","table",[363,366],{"id":364,"label":365},"workflow","LLM workflow",{"id":367,"label":368},"agent","Agent","comparison",{},{"id":372,"data":373,"type":218,"tunes":375},"p-workflow-1",{"text":374},"Anthropic explicitly separates these two patterns: workflows orchestrate models and tools through predefined code paths, while agents let models dynamically direct their own processes and tool usage. This is not the only possible terminology, but it is a useful architecture boundary.",{},{"id":377,"data":378,"type":42,"tunes":380},"h-spectrum",{"text":379,"level":247},"Agentic behavior is a spectrum, not a binary label",{},{"id":382,"data":383,"type":361,"tunes":413},"spectrum-table",{"content":384,"stretched":43,"withHeadings":14},[385,389,393,397,401,405,409],[386,387,388],"Level","Example","Who decides the next step?",[390,391,392],"Single model call","Summarize this document","Application calls model once",[394,395,396],"Tool-assisted response","Model may use web search before answering","Model selects from bounded tools for one response",[398,399,400],"Structured workflow","Classify → retrieve → generate → validate","Application workflow determines stages",[402,403,404],"Adaptive workflow","Model can choose among several branches and retry","Shared control between application and model",[406,407,408],"Agent loop","Model repeatedly chooses tools\u002Factions based on observations","Model directs tactical execution inside runtime constraints",[410,411,412],"Long-running agent","Agent pauses, resumes, manages artifacts and continues","Model + persistent runtime manage evolving execution",{},{"id":415,"data":416,"type":218,"tunes":418},"p-spectrum-1",{"text":417},"Calling every system above an “agent” can obscure important operational differences. The stronger the model's control over sequence, duration and actions, the more important runtime isolation, permissions, tracing, stopping conditions and trajectory evaluation become.",{},{"id":420,"data":421,"type":42,"tunes":423},"h-anatomy",{"text":422,"level":247},"The minimum architecture of an agentic system",{},{"id":425,"data":426,"type":361,"tunes":467},"anatomy-table",{"content":427,"stretched":43,"withHeadings":14},[428,431,434,437,440,443,446,449,452,455,458,461,464],[429,430],"Component","Responsibility",[432,433],"Goal \u002F task","Defines what the system is trying to accomplish.",[435,436],"Model","Interprets context and decides the next action or output.",[438,439],"Instructions","Define role, constraints, priorities and task-specific policy.",[441,442],"Context assembler","Builds the information visible to the model on each step.",[444,445],"Tool catalog","Defines capabilities the model may request.",[447,448],"Runtime \u002F harness","Runs the loop, executes tools, manages state and handles stopping conditions.",[450,451],"Authorization layer","Determines whether a proposed action is permitted for the current principal.",[453,454],"State \u002F session","Preserves task progress across turns or execution steps.",[456,457],"Observation channel","Returns tool results and environment changes to the next model step.",[459,460],"Approvals \u002F human control","Pauses consequential actions where review is required.",[462,463],"Tracing \u002F audit","Records model calls, tools, transitions, approvals and failures.",[465,466],"Evaluation","Measures outcomes and execution trajectories against acceptance criteria.",{},{"id":469,"data":470,"type":42,"tunes":472},"h-model-agent",{"text":471,"level":247},"A model is not an agent",{},{"id":474,"data":475,"type":218,"tunes":477},"p-model-agent-1",{"text":476},"A language model produces outputs from inputs. It does not by itself own a filesystem, execute a shell command, maintain durable task state, enforce permissions or automatically call itself again.",{},{"id":479,"data":480,"type":218,"tunes":482},"p-model-agent-2",{"text":481},"Those capabilities come from the surrounding runtime. The same model can behave as a simple chat model in one application and as the decision engine inside an agent loop in another.",{},{"id":484,"data":485,"type":226,"tunes":489},"model-agent-rule",{"body":486,"title":487,"variant":488},"\u003Cstrong>Model capability determines what decisions can be proposed. Runtime architecture determines what can actually happen.\u003C\u002Fstrong>","Architecture rule","success",{},{"id":491,"data":492,"type":42,"tunes":494},"h-tools",{"text":493,"level":247},"Tool use is central — but tool use alone does not make an agent",{},{"id":496,"data":497,"type":218,"tunes":499},"p-tools-1",{"text":498},"Tools let the model acquire information and affect external systems. Examples include database reads, file operations, shell execution, web search, browser control, API calls, ticket updates or delegated specialist agents.",{},{"id":501,"data":502,"type":218,"tunes":504},"p-tools-2",{"text":503},"A single model call can use one tool and still remain a bounded tool-assisted response rather than a long-running agent. Agentic behavior appears when tool observations feed an adaptive loop in which the model chooses what to do next.",{},{"id":506,"data":507,"type":218,"tunes":509},"p-tools-3",{"text":508},"Tool design matters because tools are the contract between model reasoning and external reality. Ambiguous or overlapping tools create routing errors; large unstructured outputs pollute context; broad side-effect tools increase blast radius.",{},{"id":511,"data":512,"type":42,"tunes":514},"h-capability-permission",{"text":513,"level":247},"Tool capability, permission and authority are different",{},{"id":516,"data":517,"type":361,"tunes":543},"permission-table",{"content":518,"stretched":43,"withHeadings":14},[519,522,525,528,531,534,537,540],[520,521],"Layer","Question",[523,524],"Capability","Can this runtime technically perform the operation?",[526,527],"Tool exposure","Is that capability available to this agent?",[529,530],"Permission","May this agent\u002Fsession use it under the current policy?",[532,533],"User authorization","Is the requesting principal allowed to cause this operation?",[535,536],"Business authority","Is the operation valid under domain rules, approvals and limits?",[538,539],"Execution","Did the operation actually occur?",[541,542],"Audit","Can the system prove who requested, approved and executed it?",{},{"id":545,"data":546,"type":218,"tunes":548},"p-permission-1",{"text":547},"These layers are frequently collapsed in prototypes. A model sees a refund tool and therefore appears able to issue refunds. In production, the tool should still validate account, user, transaction, amount, policy and approval conditions independently of the model's request.",{},{"id":550,"data":551,"type":42,"tunes":553},"h-runtime",{"text":552,"level":247},"The runtime or harness is the actual execution system",{},{"id":555,"data":556,"type":218,"tunes":558},"p-runtime-1",{"text":557},"OpenAI's current agent documentation makes the runtime distinction explicit. Different runtimes can manage orchestration, state, tools, sandboxes and execution in different places, while the model remains only one part of the system.",{},{"id":560,"data":561,"type":218,"tunes":563},"p-runtime-2",{"text":562},"The Agents SDK describes a loop that repeatedly calls the current model, inspects the output, executes requested tools or handoffs, and continues until the model returns a final answer or another real stopping point.",{},{"id":565,"data":566,"type":218,"tunes":568},"p-runtime-3",{"text":567},"This means agent architecture decisions include where orchestration runs, where state lives, who executes tools, which sandbox contains side effects, and who owns retries, timeouts and resumability.",{},{"id":570,"data":571,"type":42,"tunes":573},"h-planning",{"text":572,"level":247},"Planning is useful, but an explicit plan is not required",{},{"id":575,"data":576,"type":218,"tunes":578},"p-planning-1",{"text":577},"Agents are often described as systems that “plan.” In practice, planning can be explicit or implicit. An agent may first produce a visible multi-step plan, or it may choose one next action at a time and revise after every observation.",{},{"id":580,"data":581,"type":218,"tunes":583},"p-planning-2",{"text":582},"For highly uncertain tasks, short-horizon planning can be safer because the environment can invalidate a long plan. The architectural requirement is the ability to choose and revise actions based on the goal, current state and new evidence.",{},{"id":585,"data":586,"type":42,"tunes":588},"h-feedback",{"text":587,"level":247},"Environmental feedback is what makes the loop useful",{},{"id":590,"data":591,"type":218,"tunes":593},"p-feedback-1",{"text":592},"An agent becomes operationally meaningful when it can observe whether its action worked. Tool output, test results, API responses, filesystem state, browser state and application records provide external evidence that the system can use to revise its next decision.",{},{"id":595,"data":596,"type":218,"tunes":598},"p-feedback-2",{"text":597},"Anthropic's agent guidance emphasizes this feedback loop: agents use tools, obtain ground truth from the environment, assess progress and continue or request human input.",{},{"id":600,"data":601,"type":226,"tunes":604},"feedback-rule",{"body":602,"title":603,"variant":233},"An agent saying “the task is complete” does not prove completion. Where possible, verify the final state through an external system, test, file, transaction record or other observable outcome.","Self-report is not environmental proof",{},{"id":606,"data":607,"type":42,"tunes":609},"h-state",{"text":608,"level":247},"Agent state is not the same as model context",{},{"id":611,"data":612,"type":218,"tunes":614},"p-state-1",{"text":613},"A long-running task may need state that cannot or should not remain in the model context: task IDs, checkpoints, artifacts, approvals, external object identifiers, retry counters and workflow status.",{},{"id":616,"data":617,"type":218,"tunes":619},"p-state-2",{"text":618},"The runtime can preserve this durable state outside the model window and reconstruct the context required for the next step. This keeps model-visible context focused while maintaining continuity and resumability.",{},{"id":621,"data":622,"type":42,"tunes":624},"h-memory",{"text":623,"level":247},"Memory is optional, not the definition of an agent",{},{"id":626,"data":627,"type":218,"tunes":629},"p-memory-1",{"text":628},"An agent can operate successfully without long-term memory if the complete task fits inside one bounded run. Memory becomes useful when information must persist across sessions, tasks or long execution horizons.",{},{"id":631,"data":632,"type":218,"tunes":634},"p-memory-2",{"text":633},"RAG, memory, state and context solve different problems. Treating a vector database as “the agent memory” or conversation history as “the state machine” usually hides important lifecycle and authority boundaries.",{},{"id":636,"data":637,"type":642,"tunes":643},"ref-memory",{"url":638,"title":639,"excerpt":640,"ctaLabel":641},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","AI Agent Memory Is Not RAG: How to Separate Memory, Retrieval, State and Context","A practical architecture separating persistent memory, authoritative application state, retrieval and the context supplied to the model.","Read the memory architecture article","referralArticle",{},{"id":645,"data":646,"type":42,"tunes":648},"h-context",{"text":647,"level":247},"Context engineering becomes dynamic in agents",{},{"id":650,"data":651,"type":218,"tunes":653},"p-context-1",{"text":652},"Every tool call can produce new context. Every step can also make earlier information obsolete. A strong agent runtime therefore rebuilds or curates context as execution progresses rather than replaying everything indefinitely.",{},{"id":655,"data":656,"type":218,"tunes":658},"p-context-2",{"text":657},"Tool definitions, task state, retrieved evidence, observations and memory all compete for the model's attention. Long-running agents need trimming, compaction or just-in-time loading so context remains relevant to the current decision.",{},{"id":660,"data":661,"type":42,"tunes":663},"h-sideeffects",{"text":662,"level":247},"Read tools and side-effect tools have different risk",{},{"id":665,"data":666,"type":369,"tunes":688},"sideeffect-comparison",{"rows":667,"title":680,"layout":361,"columns":681},[668,672,676],{"id":669,"label":670,"values":671},"examples","Examples",[347,347],{"id":673,"label":674,"values":675},"mainrisk","Main risk",[347,347],{"id":677,"label":678,"values":679},"control","Typical control",[347,347],"Information access versus external action",[682,685],{"id":683,"label":684},"read","Read \u002F observe",{"id":686,"label":687},"write","Write \u002F act",{},{"id":690,"data":691,"type":42,"tunes":693},"h-approval",{"text":692,"level":247},"Human-in-the-loop is a control mechanism, not the opposite of agentic AI",{},{"id":695,"data":696,"type":218,"tunes":698},"p-approval-1",{"text":697},"An agent does not stop being agentic because a human approves consequential steps. The model can still autonomously inspect, reason, search and prepare an action while the runtime requires human confirmation before execution.",{},{"id":700,"data":701,"type":218,"tunes":703},"p-approval-2",{"text":702},"OpenAI's current agent safety guidance explicitly recommends approvals for tool operations in higher-risk workflows. Anthropic likewise emphasizes checkpoints and human judgment where agents encounter blockers or consequential decisions.",{},{"id":705,"data":706,"type":218,"tunes":708},"p-approval-3",{"text":707},"The useful architecture question is not “human or autonomous?” but which decisions can be delegated, which require review and which must remain deterministic?",{},{"id":710,"data":711,"type":42,"tunes":713},"h-stopping",{"text":712,"level":247},"Agents need explicit stopping conditions",{},{"id":715,"data":716,"type":361,"tunes":748},"stop-table",{"content":717,"stretched":43,"withHeadings":14},[718,721,724,727,730,733,736,739,742,745],[719,720],"Stopping condition","Purpose",[722,723],"Successful verified outcome","End when the external target state is confirmed.",[725,726],"Maximum steps","Prevent runaway loops.",[728,729],"Time budget","Bound wall-clock execution.",[731,732],"Cost\u002Ftoken budget","Limit resource consumption.",[734,735],"Repeated-action detector","Stop loops that are no longer making progress.",[737,738],"Permission boundary","Pause or stop when the next required action is not permitted.",[740,741],"Human approval checkpoint","Wait before consequential execution.",[743,744],"Unrecoverable tool failure","Escalate instead of retrying indefinitely.",[746,747],"Uncertainty threshold","Ask for clarification when the task cannot be safely inferred.",{},{"id":750,"data":751,"type":42,"tunes":753},"h-errors",{"text":752,"level":247},"Recovery is part of agent behavior",{},{"id":755,"data":756,"type":218,"tunes":758},"p-errors-1",{"text":757},"Agents operate in environments that fail: APIs time out, files change, credentials expire, webpages move and tools return malformed output. A useful agentic system therefore needs recovery behavior, not just a happy-path tool loop.",{},{"id":760,"data":761,"type":218,"tunes":763},"p-errors-2",{"text":762},"Recovery can include retry with limits, choosing another tool, re-reading current state, asking the user, rolling back a partial action or escalating to a human.",{},{"id":765,"data":766,"type":218,"tunes":768},"p-errors-3",{"text":767},"Retries also need idempotency awareness. Repeating a read is usually low risk; repeating a payment or message send can create duplicate side effects.",{},{"id":770,"data":771,"type":42,"tunes":773},"h-single-multi",{"text":772,"level":247},"Agentic AI does not require multiple agents",{},{"id":775,"data":776,"type":218,"tunes":778},"p-multi-1",{"text":777},"A single agent with a clear tool set is often simpler and easier to evaluate than a multi-agent architecture. Multiple agents are useful when specialization materially improves tool isolation, policy isolation, prompt clarity, ownership or trace legibility.",{},{"id":780,"data":781,"type":218,"tunes":783},"p-multi-2",{"text":782},"OpenAI's current orchestration guidance explicitly recommends starting with one agent where possible and adding specialists only when the contract or ownership boundary materially changes.",{},{"id":785,"data":786,"type":218,"tunes":788},"p-multi-3",{"text":787},"Multi-agent systems add new problems: delegation quality, duplicated context, conflicting state, handoff semantics, identity, cost and distributed failure handling.",{},{"id":790,"data":791,"type":42,"tunes":793},"h-protocols",{"text":792,"level":247},"Agent protocols are interoperability layers, not the agent itself",{},{"id":795,"data":796,"type":218,"tunes":798},"p-protocols-1",{"text":797},"Protocols such as MCP and A2A can make an agent architecture interoperable, but they do not create the agent loop by themselves. MCP can expose tools and resources. A2A can connect independently implemented agents. The application still needs runtime, authorization, state, evaluation and domain logic.",{},{"id":800,"data":801,"type":218,"tunes":803},"p-protocols-2",{"text":802},"This is why protocol capability must remain separate from business authority. Discovering a tool through MCP does not prove the current principal is allowed to use it. Receiving a task through A2A does not prove the remote agent may perform every requested action.",{},{"id":805,"data":806,"type":642,"tunes":811},"ref-protocols",{"url":807,"title":808,"excerpt":809,"ctaLabel":810},"https:\u002F\u002Fstajic.de\u002Fde\u002Fblog\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained","MCP vs A2A vs UCP vs AP2 vs A2UI: The Agent Protocol Stack Explained","A protocol-responsibility map showing why tool access, agent collaboration, commerce, payment authority and agent-driven UI belong to different interoperability boundaries.","Read the agent protocol stack",{},{"id":813,"data":814,"type":42,"tunes":816},"h-reliability",{"text":815,"level":247},"The trajectory is part of agent reliability",{},{"id":818,"data":819,"type":218,"tunes":821},"p-rel-1",{"text":820},"A final answer is insufficient evidence for an agentic system because an agent can reach the right result through an unsafe or invalid path. It may use an unauthorized tool, skip a required check, retry a side effect, rely on stale state or accidentally succeed.",{},{"id":823,"data":824,"type":218,"tunes":826},"p-rel-2",{"text":825},"Evaluation therefore needs execution traces: decisions, tool calls, approvals, observations, state changes and final outcome. Current OpenAI safety guidance recommends trace graders and evals; Anthropic's 2026 agent-evaluation guidance similarly treats multi-turn tool trajectories as first-class evaluation objects.",{},{"id":828,"data":829,"type":218,"tunes":831},"p-rel-3",{"text":830},"The stronger reliability question is: Did the agent reach an acceptable outcome through an acceptable, recoverable and auditable trajectory?",{},{"id":833,"data":834,"type":642,"tunes":839},"ref-reliability",{"url":835,"title":836,"excerpt":837,"ctaLabel":838},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-reliability-why-the-final-answer-is-not-enough","AI Agent Reliability: Why the Final Answer Is Not Enough","Why production evaluation must inspect trajectories, tool use, state transitions and recoverability rather than only final answers.","Read the reliability article",{},{"id":841,"data":842,"type":42,"tunes":844},"h-security",{"text":843,"level":247},"Agentic systems increase the security surface",{},{"id":846,"data":847,"type":361,"tunes":884},"security-table",{"content":848,"stretched":43,"withHeadings":14},[849,852,856,860,864,868,872,876,880],[358,850,851],"Why agents amplify it","Architecture response",[853,854,855],"Prompt injection","Untrusted content can influence future tool decisions","Separate instructions from data; constrain tools; sanitize or structure external input where possible",[857,858,859],"Excessive permissions","Reasoning errors can become real side effects","Least privilege, scoped credentials, per-tool policy and approvals",[861,862,863],"Credential exposure","Tools may need powerful secrets","Keep secrets outside model context; broker access through trusted runtime",[865,866,867],"Confused deputy","Agent may act with authority broader than the requesting user","Bind execution to user\u002Fservice identity and re-authorize consequential actions",[869,870,871],"Runaway loops","Model repeatedly calls tools without progress","Step, time and cost budgets plus loop detection",[873,874,875],"State drift","Environment changes after the agent formed a plan","Re-read authoritative state before consequential actions",[877,878,879],"Indirect injection","Tool\u002Fweb\u002Fdocument content contains instructions aimed at the model","Treat external content as untrusted data, not instruction authority",[881,882,883],"Audit gap","Final result cannot show what was executed","Trace tool calls, approvals, identities and state changes",{},{"id":886,"data":887,"type":42,"tunes":889},"h-observability",{"text":888,"level":247},"Agent observability must follow the loop",{},{"id":891,"data":892,"type":218,"tunes":894},"p-obs-1",{"text":893},"Traditional service observability records requests, latency and errors. Agent observability needs an additional execution model: which agent was active, which model version made the decision, what context was available, which tool was selected, what arguments were sent, what result came back and why execution stopped.",{},{"id":896,"data":897,"type":218,"tunes":899},"p-obs-2",{"text":898},"For sensitive systems, traces themselves require access control and retention policy because prompts, tool outputs and artifacts can contain confidential data.",{},{"id":901,"data":902,"type":42,"tunes":904},"h-eval",{"text":903,"level":247},"How to evaluate an agentic system",{},{"id":906,"data":907,"type":361,"tunes":952},"eval-table",{"content":908,"stretched":43,"withHeadings":14},[909,912,916,920,924,928,932,936,940,944,948],[910,521,911],"Dimension","Example evidence",[913,914,915],"Task success","Did the requested outcome occur?","External state, tests, business outcome",[917,918,919],"Trajectory quality","Were the steps acceptable?","Tool\u002Faction trace",[921,922,923],"Tool selection","Did the agent choose appropriate capabilities?","Expected vs actual tool calls",[925,926,927],"Permission adherence","Did it stay inside allowed authority?","Authorization logs and denied-action tests",[929,930,931],"State handling","Did it use current authoritative state?","Freshness checks and state-change tests",[933,934,935],"Recovery","Did it respond correctly to failures?","Injected timeout\u002Ferror scenarios",[937,938,939],"Stopping behavior","Did it stop at the right point?","Step counts, loop detection, final-state proof",[941,942,943],"Human escalation","Did it ask when review was required?","Approval\u002Fescalation traces",[945,946,947],"Cost\u002Flatency","Was autonomy worth the operational cost?","Tokens, tool calls, duration",[949,950,951],"Robustness","Does it survive realistic environment variation?","Repeated and adversarial trials",{},{"id":954,"data":955,"type":42,"tunes":957},"h-use",{"text":956,"level":247},"When an agent is appropriate",{},{"id":959,"data":960,"type":361,"tunes":986},"use-table",{"content":961,"stretched":43,"withHeadings":14},[962,965,968,971,974,977,980,983],[963,964],"Use an agent when","Prefer a workflow or simple call when",[966,967],"The number or order of steps cannot be known reliably in advance","The sequence is stable and deterministic",[969,970],"The system must inspect the environment and adapt","A single retrieval + generation step is sufficient",[972,973],"Several tools may be useful depending on intermediate results","One known API call solves the task",[975,976],"The task benefits from iterative verification or repair","The answer can be produced directly from supplied context",[978,979],"Failures require flexible recovery behavior","Failure branches are simple and can be encoded explicitly",[981,982],"Human review can be inserted at meaningful checkpoints","Every step is high-risk and must be manually controlled anyway",[984,985],"Expected value justifies extra latency, cost and complexity","Predictability and low cost matter more than flexibility",{},{"id":988,"data":989,"type":218,"tunes":991},"p-use-1",{"text":990},"A strong default is to start with the simplest solution that works and increase agentic complexity only when flexibility produces measurable value. Agents trade predictability, latency and cost for adaptive execution.",{},{"id":993,"data":994,"type":42,"tunes":996},"h-implementation",{"text":995,"level":247},"Original implementation evidence",{},{"id":998,"data":999,"type":42,"tunes":1001},"h-client",{"text":1000,"level":246},"Aaasaasa AI Client: model, runtime and permission are separate",{},{"id":1003,"data":1004,"type":218,"tunes":1006},"p-client-1",{"text":1005},"Aaasaasa AI Client explicitly separates agent\u002Fclient, provider, model, runtime location and permissions. Its architecture documentation treats permissions as central tool\u002Fworkspace policy rather than a model property.",{},{"id":1008,"data":1009,"type":218,"tunes":1011},"p-client-2",{"text":1010},"The same application can expose Direct Chat with no filesystem or shell tools while a Codex runtime operates under a selected workspace and permission profile. This demonstrates a core agentic architecture boundary: changing the runtime\u002Ftool surface changes what the system can do even when model access remains available.",{},{"id":1013,"data":1014,"type":218,"tunes":1016},"p-client-3",{"text":1015},"The repository also distinguishes a local Codex runtime from model location: a local runtime can call a cloud model. This prevents the common mistake of equating “agent runs locally” with “inference is local.”",{},{"id":1018,"data":1019,"type":218,"tunes":1021},"p-client-4",{"text":1020},"The implementation disables embedded execution paths whose approval semantics do not satisfy the required permission model. This supports the principle that agent capability should not bypass runtime authorization simply because an underlying framework can execute tools.",{},{"id":1023,"data":1024,"type":42,"tunes":1026},"h-sot-agent",{"text":1025,"level":246},"Source of Truth Research Engine: bounded agentic research stages",{},{"id":1028,"data":1029,"type":218,"tunes":1031},"p-sot-1",{"text":1030},"The Source of Truth Research Engine uses a bounded research pipeline: discover → acquire → extract → verify → contradict → synthesize. Research jobs can execute through an AI runtime while evidence, sources, claims and contradictions remain in an external persistent store.",{},{"id":1033,"data":1034,"type":218,"tunes":1036},"p-sot-2",{"text":1035},"This is intentionally more controlled than an unconstrained autonomous research agent. The stages provide guardrails around what kind of work should happen next while still allowing model-driven research inside each bounded task.",{},{"id":1038,"data":1039,"type":218,"tunes":1041},"p-sot-3",{"text":1040},"That distinction is useful evidence for agent design: autonomy can be placed inside a structured delivery envelope rather than applied uniformly to the entire process.",{},{"id":1043,"data":1044,"type":361,"tunes":1067},"impl-table",{"content":1045,"stretched":43,"withHeadings":14},[1046,1049,1052,1055,1058,1061,1064],[1047,1048],"Implemented pattern","Agentic architecture lesson",[1050,1051],"Direct Chat has no OS tools","A model can exist without agentic execution capability.",[1053,1054],"Codex runtime has workspace permission profile","Tool authority belongs to runtime policy, not model capability.",[1056,1057],"Provider\u002Fmodel\u002Fruntime are separate concepts","Agent harness location and inference location are independent decisions.",[1059,1060],"Permission broker for tool-capable runtimes","Capability exposure can be centralized and governed.",[1062,1063],"Bounded research stages","Autonomy can operate inside explicit process boundaries.",[1065,1066],"Persistent claims\u002Fevidence outside model context","Agent state and evidence do not need to live only in conversation history.",{},{"id":1069,"data":1070,"type":226,"tunes":1073},"impl-boundary",{"body":1071,"title":1072,"variant":240},"These projects demonstrate concrete agent\u002Fruntime, permission and bounded-research patterns. They are not presented as proof of large-scale commercial autonomous-agent deployment.","Evidence boundary",{},{"id":1075,"data":1076,"type":42,"tunes":1078},"h-failures",{"text":1077,"level":247},"Common agentic AI failure modes",{},{"id":1080,"data":1081,"type":361,"tunes":1122},"failure-table",{"content":1082,"stretched":43,"withHeadings":14},[1083,1086,1089,1092,1095,1098,1101,1104,1107,1110,1113,1116,1119],[1084,1085],"Failure mode","What actually failed",[1087,1088],"“Agent” is only a chatbot with tools listed in the prompt","No reliable runtime loop or tool execution architecture exists",[1090,1091],"Tool support is treated as permission","Capability and authorization boundaries are collapsed",[1093,1094],"Agent trusts its own completion statement","Outcome is not verified against external state",[1096,1097],"Every task becomes multi-agent","Complexity increases without a real ownership or specialization boundary",[1099,1100],"Conversation history is used as durable state","Resumability and authoritative state become fragile",[1102,1103],"Agent retries side effects blindly","Duplicate messages, payments or state changes become possible",[1105,1106],"No step\u002Fcost limits","Agent can loop indefinitely or consume uncontrolled resources",[1108,1109],"Tool output is trusted as instruction","Indirect prompt injection can redirect behavior",[1111,1112],"Correct final answer is the only evaluation","Unsafe or invalid trajectories remain invisible",[1114,1115],"Model upgrade is treated as transparent","Tool selection, planning and stopping behavior can change",[1117,1118],"One broad tool exposes many privileged operations","Blast radius increases and intent becomes harder to validate",[1120,1121],"Human approval exists but reviewer lacks context","Approval becomes ceremonial rather than effective",{},{"id":1124,"data":1125,"type":42,"tunes":1127},"h-misconceptions",{"text":1126,"level":247},"Common misconceptions",{},{"id":1129,"data":1130,"type":361,"tunes":1165},"misconceptions-table",{"content":1131,"stretched":43,"withHeadings":14},[1132,1135,1138,1141,1144,1147,1150,1153,1156,1159,1162],[1133,1134],"Misconception","Correction",[1136,1137],"“An LLM is an agent.”","The model is the decision component; the agent is the surrounding system that manages tools, state and iteration.",[1139,1140],"“Tool calling automatically means agentic AI.”","A single bounded tool call may not involve an adaptive multi-step agent loop.",[1142,1143],"“Agents must be fully autonomous.”","Agentic systems can require approvals and operate under narrow permission boundaries.",[1145,1146],"“Agents need long-term memory.”","Memory is optional; many useful agents complete bounded tasks without cross-session memory.",[1148,1149],"“Agents must create a written plan first.”","Planning can be explicit or implicit and can occur one step at a time.",[1151,1152],"“Multi-agent is more advanced than single-agent.”","It is more complex; use it only when specialization or ownership boundaries justify it.",[1154,1155],"“MCP creates an agent.”","MCP exposes tools\u002Fresources; the runtime still needs an agent loop and authorization model.",[1157,1158],"“A local runtime means the model is local.”","Runtime location and inference\u002Fprovider location are separate.",[1160,1161],"“If the final result is correct, the agent worked correctly.”","An unsafe or unauthorized trajectory can still produce a correct result.",[1163,1164],"“Human approval removes autonomy.”","Approval can constrain selected actions while the rest of the process remains model-directed.",{},{"id":1167,"data":1168,"type":42,"tunes":1170},"h-design",{"text":1169,"level":247},"A practical agent design sequence",{},{"id":1172,"data":1173,"type":317,"tunes":1212},"design-flow",{"steps":1174,"title":1211,"orientation":316},[1175,1178,1181,1184,1187,1190,1193,1196,1199,1202,1205,1208],{"label":1176,"description":1177},"1. Define the outcome","State what external result or artifact proves task success.",{"label":1179,"description":1180},"2. Decide whether an agent is actually needed","Prefer a simple call or deterministic workflow when the path is predictable.",{"label":1182,"description":1183},"3. Identify state and Source of Truth","Define which systems own current facts, task progress and business state.",{"label":1185,"description":1186},"4. Define the tool surface","Expose the smallest set of clear capabilities required for the task.",{"label":1188,"description":1189},"5. Bind identity and permissions","Separate user authority, agent\u002Fruntime permissions and tool capabilities.",{"label":1191,"description":1192},"6. Choose autonomy boundaries","Specify what the model may decide dynamically and what remains deterministic.",{"label":1194,"description":1195},"7. Add approval checkpoints","Require review before consequential or irreversible actions where appropriate.",{"label":1197,"description":1198},"8. Define stopping and recovery","Set success proof, budgets, timeouts, retries, escalation and loop controls.",{"label":1200,"description":1201},"9. Design context\u002Fstate management","Keep current state, memory, tool observations and durable artifacts in the correct layers.",{"label":1203,"description":1204},"10. Trace the trajectory","Record enough execution structure to debug and audit model\u002Ftool decisions.",{"label":1206,"description":1207},"11. Evaluate realistic failures","Test stale state, tool errors, prompt injection, ambiguous requests and changed environments.",{"label":1209,"description":1210},"12. Expand autonomy only from evidence","Increase permissions or execution horizon when evaluation shows the benefit justifies the risk.","Design the agent from authority outward",{},{"id":1214,"data":1215,"type":42,"tunes":1217},"h-checklist",{"text":1216,"level":247},"Agentic AI architecture checklist",{},{"id":1219,"data":1220,"type":361,"tunes":1263},"checklist-table",{"content":1221,"stretched":43,"withHeadings":14},[1222,1224,1227,1230,1233,1236,1239,1242,1245,1248,1251,1254,1257,1260],[521,1223],"Expected evidence",[1225,1226],"What proves success?","External outcome, artifact, test or authoritative state.",[1228,1229],"Why is an agent needed?","The path genuinely depends on intermediate observations.",[1231,1232],"Which decisions are model-driven?","Explicit autonomy boundary.",[1234,1235],"Which tools exist?","Small, documented, unambiguous capability set.",[1237,1238],"Who may use each tool?","Identity- and context-aware authorization policy.",[1240,1241],"Which actions need approval?","Consequence-based review rules.",[1243,1244],"Where does task state live?","Application-owned state separate from transient model context.",[1246,1247],"How does the agent recover?","Retry, re-read, rollback, clarification and escalation behavior.",[1249,1250],"How does it stop?","Verified completion plus step\u002Ftime\u002Fcost limits.",[1252,1253],"How are side effects protected?","Validation, idempotency, least privilege and confirmation.",[1255,1256],"Can execution be reconstructed?","Tool, approval and state-transition traces.",[1258,1259],"How is it evaluated?","Outcome + trajectory + robustness tests.",[1261,1262],"What changes after a model\u002Fruntime update?","Regression suite for tool selection, permissions, stopping and recovery.",{},{"id":1265,"data":1266,"type":42,"tunes":1268},"h-edge",{"text":1267,"level":247},"Edge cases and limitations",{},{"id":1270,"data":1271,"type":218,"tunes":1273},"p-edge-1",{"text":1272},"Some systems are “agentic” only in a narrow routing sense: the model selects one specialist or tool and then the rest of the workflow is deterministic. That can still be useful, but it should not be described as equivalent to a long-running autonomous agent.",{},{"id":1275,"data":1276,"type":218,"tunes":1278},"p-edge-2",{"text":1277},"Highly consequential domains may intentionally restrict agent autonomy. An AI system can inspect evidence, prepare recommendations and fill structured forms while a human remains the only actor allowed to commit the final transaction.",{},{"id":1280,"data":1281,"type":218,"tunes":1283},"p-edge-3",{"text":1282},"Some environments are well suited to agents because feedback is objective. Coding agents can run tests; infrastructure agents can inspect metrics; data agents can validate query results. Open-ended domains with weak feedback require more cautious evaluation.",{},{"id":1285,"data":1286,"type":218,"tunes":1288},"p-edge-4",{"text":1287},"An agent can operate entirely locally, entirely through managed cloud services or in a hybrid architecture. Agentic behavior describes control flow, not hosting location.",{},{"id":1290,"data":1291,"type":218,"tunes":1293},"p-edge-5",{"text":1292},"The term “reasoning” should not be used as proof that the agent's internal process is correct. Production assurance should rely on observable inputs, actions, outputs, state and evaluation rather than unverifiable claims about hidden reasoning.",{},{"id":1295,"data":1296,"type":42,"tunes":1298},"h-change",{"text":1297,"level":247},"What would change this answer?",{},{"id":1300,"data":1301,"type":218,"tunes":1303},"p-change-1",{"text":1302},"Vendor APIs and agent frameworks will continue to evolve, but the architecture boundary is stable: a model proposes decisions, a runtime manages the loop, tools connect to the environment, permissions constrain actions and external observations determine what actually happened.",{},{"id":1305,"data":1306,"type":218,"tunes":1308},"p-change-2",{"text":1307},"As models become more reliable, systems may safely delegate longer horizons or more complex recovery behavior. As runtime verification and authorization improve, some approval steps may become automated. Those are changes in autonomy level, not changes to the fundamental responsibility layers.",{},{"id":1310,"data":1311,"type":218,"tunes":1313},"p-change-3",{"text":1312},"The recommended architecture also changes by consequence. A research agent that only reads public sources can tolerate different controls from an agent that writes production configuration or moves money.",{},{"id":1315,"data":1316,"type":42,"tunes":1318},"h-related",{"text":1317,"level":247},"Related canonical knowledge",{},{"id":1320,"data":1321,"type":218,"tunes":1323},"p-related-1",{"text":1322},"Agentic AI sits above several prerequisite layers: context engineering determines what the model sees; Source-of-Truth architecture determines which information is authoritative; retrieval supplies external evidence; runtime architecture determines what can execute.",{},{"id":1325,"data":1326,"type":218,"tunes":1328},"p-related-2",{"text":1327},"Downstream nodes include tool calling, MCP, A2A, agent identity, permissions, auditability, human-in-the-loop, orchestration, memory and multi-agent systems.",{},{"id":1330,"data":1331,"type":218,"tunes":1333},"p-related-3",{"text":1332},"The protocol stack article should therefore be read after the basic agent concept: protocols standardize boundaries around agents; they do not define agentic behavior itself.",{},{"id":1335,"data":1336,"type":42,"tunes":1338},"h-faq",{"text":1337,"level":247},"Frequently asked questions",{},{"id":1340,"data":1341,"type":1340,"tunes":1380},"faq",{"items":1342,"title":1379},[1343,1347,1351,1355,1359,1363,1367,1371,1375],{"id":1344,"answer":1345,"question":1346},"faq1","Agentic AI is an AI system in which a model can pursue a goal over multiple steps by choosing actions or tools, observing results, updating its state and continuing until a stopping condition is reached.","What is agentic AI?",{"id":1348,"answer":1349,"question":1350},"faq2","An LLM produces outputs from inputs. An agent combines a model with a runtime, tools, state, permissions, context management and an iterative execution loop.","What is the difference between an LLM and an AI agent?",{"id":1352,"answer":1353,"question":1354},"faq3","Not necessarily. A single tool-assisted model response can be bounded and non-agentic. Agentic behavior appears when tool observations drive an adaptive multi-step loop.","Does tool calling make a system an agent?",{"id":1356,"answer":1357,"question":1358},"faq4","A workflow usually follows a process path defined in application code. An agent has more model-driven control over which steps and tools to use based on intermediate observations.","What is the difference between an agent and an AI workflow?",{"id":1360,"answer":1361,"question":1362},"faq5","No. Long-term memory is useful for persistent information across sessions, but many agents complete bounded tasks using only current task state and context.","Do agents need memory?",{"id":1364,"answer":1365,"question":1366},"faq6","No. A single agent is often simpler. Multi-agent systems are justified when specialization, tool isolation, policy isolation or ownership boundaries materially improve the system.","Do AI agents need multiple agents?",{"id":1368,"answer":1369,"question":1370},"faq7","Yes. The agent can autonomously perform low-risk analysis and preparation while the runtime pauses for human approval before consequential actions.","Can an agent be human-in-the-loop?",{"id":1372,"answer":1373,"question":1374},"faq8","No. MCP is an interoperability protocol for exposing tools, resources and prompts. An agent runtime can use MCP, but still needs its own loop, state, authorization and evaluation.","Is MCP an agent framework?",{"id":1376,"answer":1377,"question":1378},"faq9","Where possible, verify success through external state, tests, artifacts or authoritative system records rather than trusting the model's own completion statement.","How do you know an agent actually completed a task?","Agentic AI FAQ",{},{"id":1382,"data":1383,"type":42,"tunes":1385},"h-glossary",{"text":1384,"level":247},"Glossary",{},{"id":1387,"data":1388,"type":1387,"tunes":1433},"glossary",{"title":1389,"entries":1390},"Key agentic AI terms",[1391,1395,1399,1402,1405,1409,1413,1417,1421,1425,1429],{"term":1392,"anchor":1393,"definition":1394},"Agentic AI","agentic-ai","AI system behavior in which a model dynamically directs multi-step execution using tools, observations and state toward a goal.",{"term":1396,"anchor":1397,"definition":1398},"AI agent","ai-agent","A model-centered system with runtime, tools, state and an execution loop that can pursue a task over multiple steps.",{"term":406,"anchor":1400,"definition":1401},"agent-loop","Repeated cycle of model decision, tool\u002Faction execution, observation and updated model decision until stopping.",{"term":447,"anchor":1403,"definition":1404},"runtime-harness","The execution layer that manages the model loop, tools, state, approvals, context, errors and stopping conditions.",{"term":1406,"anchor":1407,"definition":1408},"Tool","tool","A capability exposed to the model for reading information, computing, delegating or changing external state.",{"term":1410,"anchor":1411,"definition":1412},"Observation","observation","Information returned from a tool or environment and supplied to a later agent step.",{"term":1414,"anchor":1415,"definition":1416},"Agent state","agent-state","Persistent task or execution information that exists outside a single model output and may survive across steps or pauses.",{"term":1418,"anchor":1419,"definition":1420},"Autonomy boundary","autonomy-boundary","The explicit limit defining which decisions and actions the model may control dynamically.",{"term":1422,"anchor":1423,"definition":1424},"Human-in-the-loop","human-in-the-loop","A control pattern in which human review, input or approval is required at selected points in an AI-driven process.",{"term":1426,"anchor":1427,"definition":1428},"Trajectory","trajectory","The sequence of relevant states, decisions, tool calls, actions and observations between task request and final outcome.",{"term":1430,"anchor":1431,"definition":1432},"Idempotency","idempotency","Property that allows an operation to be repeated without unintentionally applying the same side effect multiple times.",{},{"id":1435,"data":1436,"type":42,"tunes":1438},"h-conclusion",{"text":1437,"level":247},"Conclusion",{},{"id":1440,"data":1441,"type":218,"tunes":1443},"p-conclusion-1",{"text":1442},"Agentic AI is not simply a smarter model or a chatbot with more tools. It is a system architecture in which a model participates in an iterative control loop: decide, act, observe, update and continue.",{},{"id":1445,"data":1446,"type":218,"tunes":1448},"p-conclusion-2",{"text":1447},"The model provides flexible decision making, but the surrounding runtime must own execution reality: permissions, tool access, state, approvals, retries, budgets, stopping conditions, tracing and verification.",{},{"id":1450,"data":1451,"type":218,"tunes":1453},"p-conclusion-3",{"text":1452},"The most useful design principle is therefore: delegate tactical choice to the model only inside explicit technical and business boundaries. Agentic capability becomes production capability only when autonomy, authority and evidence remain separable.",{},{"id":1455,"data":1456,"type":42,"tunes":1458},"h-sources",{"text":1457,"level":247},"Primary sources and current guidance",{},{"id":1460,"data":1461,"type":218,"tunes":1463},"p-sources-note",{"text":1462},"The sources below support the current architectural distinctions around agents, workflows, loops, tools, orchestration, safety and evaluation. Project sections are original implementation evidence and are explicitly bounded to what the repositories demonstrate.",{},{"id":1465,"data":1466,"type":1472,"tunes":1473},"src-openai-agents",{"link":1467,"meta":1468},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents",{"image":1469,"title":1470,"description":1471},{"url":347},"OpenAI — Agents","Current developer guidance defining runtime choices for multi-step work, tools, state, orchestration and agent execution.","linkTool",{},{"id":1475,"data":1476,"type":1472,"tunes":1482},"src-openai-definitions",{"link":1477,"meta":1478},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents\u002Fdefine-agents",{"image":1479,"title":1480,"description":1481},{"url":347},"OpenAI — Agent definitions","Current documentation describing an agent as a model plus instructions and optional runtime behavior including tools, guardrails, MCP servers and handoffs.",{},{"id":1484,"data":1485,"type":1472,"tunes":1491},"src-openai-running",{"link":1486,"meta":1487},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents\u002Frunning-agents",{"image":1488,"title":1489,"description":1490},{"url":347},"OpenAI — Running agents","Current documentation of the agent loop: model call, tool execution or handoff, continuation and final stopping point.",{},{"id":1493,"data":1494,"type":1472,"tunes":1500},"src-openai-orchestration",{"link":1495,"meta":1496},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents\u002Forchestration",{"image":1497,"title":1498,"description":1499},{"url":347},"OpenAI — Orchestration and handoffs","Current guidance on handoffs, agents-as-tools and when specialist agents add useful ownership or capability boundaries.",{},{"id":1502,"data":1503,"type":1472,"tunes":1509},"src-openai-safety",{"link":1504,"meta":1505},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagent-builder-safety",{"image":1506,"title":1507,"description":1508},{"url":347},"OpenAI — Safety in building agents","Current safety guidance covering tool approvals, prompt injection, guardrails and trace-based evaluation.",{},{"id":1511,"data":1512,"type":1472,"tunes":1518},"src-anthropic-agents",{"link":1513,"meta":1514},"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Fbuilding-effective-agents",{"image":1515,"title":1516,"description":1517},{"url":347},"Anthropic — Building effective agents","Engineering guidance distinguishing predefined workflows from model-directed agents and describing tool-based environmental feedback loops.",{},{"id":1520,"data":1521,"type":1472,"tunes":1527},"src-anthropic-context",{"link":1522,"meta":1523},"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Feffective-context-engineering-for-ai-agents",{"image":1524,"title":1525,"description":1526},{"url":347},"Anthropic — Effective context engineering for AI agents","Practical framing of agents as LLMs autonomously using tools in a loop, with dynamic just-in-time context management.",{},{"id":1529,"data":1530,"type":1472,"tunes":1536},"src-anthropic-evals",{"link":1531,"meta":1532},"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Fdemystifying-evals-for-ai-agents",{"image":1533,"title":1534,"description":1535},{"url":347},"Anthropic — Demystifying evals for AI agents","2026 guidance on evaluating multi-turn agents that call tools, modify state and adapt to intermediate results.",{},"2.31.6","Agentic AI uses models inside multi-step execution loops where they can choose tools, observe results, update state and adapt their next action within explicit runtime and permission boundaries.","\u002Fuploads\u002F2026\u002F10\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act-1791481499084-wnji2a.webp","agentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act-1791481499084-wnji2a","PUBLISHED","2026-10-08T11:43:00.000Z","2026-10-08T17:43:28.373Z","2026-10-08T19:19:47.140Z",{"en":1546,"de":1547,"sr":1548,"es":1549,"fr":1550,"it":1551,"ru":1552,"zh":1553},"\u002Fblog\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","\u002Fde\u002Fblog\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","\u002Fsr\u002Fblog\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","\u002Fes\u002Fblog\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","\u002Ffr\u002Fblog\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","\u002Fit\u002Fblog\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","\u002Fru\u002Fblog\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","\u002Fzh\u002Fblog\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act",[1555,1559,1563],{"id":1556,"name":1557,"slug":1558},84,"Policy & Data Boundaries","policy-and-data",{"id":1560,"name":1561,"slug":1562},57,"Data Boundaries","data-boundaries",{"id":1564,"name":1565,"slug":1566},59,"Governance & Auditability","governance",{"id":1568,"login":1569,"email":1570,"displayName":1571},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[1573],{"lang":7,"title":208,"content":210,"contentJson":1574,"excerpt":1538},{"time":212,"blocks":1575,"version":1537},[1576,1579,1582,1585,1588,1591,1594,1597,1600,1603,1606,1609,1612,1615,1626,1629,1632,1635,1638,1653,1656,1659,1670,1673,1676,1693,1696,1699,1702,1705,1708,1711,1714,1717,1720,1732,1735,1738,1741,1744,1747,1750,1753,1756,1759,1762,1765,1768,1771,1774,1777,1780,1783,1786,1789,1792,1795,1798,1801,1814,1817,1820,1823,1826,1829,1843,1846,1849,1852,1855,1858,1861,1864,1867,1870,1873,1876,1879,1882,1885,1888,1891,1894,1897,1910,1913,1916,1919,1922,1937,1940,1952,1955,1958,1961,1964,1967,1970,1973,1976,1979,1982,1985,1996,1999,2002,2019,2022,2037,2040,2056,2059,2077,2080,2083,2086,2089,2092,2095,2098,2101,2104,2107,2110,2113,2116,2119,2122,2135,2138,2153,2156,2159,2162,2165,2168,2171,2176,2181,2186,2191,2196,2201,2206],{"id":215,"data":1577,"type":218,"tunes":1578},{"text":217},{},{"id":221,"data":1580,"type":226,"tunes":1581},{"body":223,"title":224,"variant":225},{},{"id":229,"data":1583,"type":226,"tunes":1584},{"body":231,"title":232,"variant":233},{},{"id":236,"data":1586,"type":226,"tunes":1587},{"body":238,"title":239,"variant":240},{},{"id":243,"data":1589,"type":248,"tunes":1590},{"title":245,"maxLevel":246,"minLevel":247},{},{"id":251,"data":1592,"type":42,"tunes":1593},{"text":253,"level":247},{},{"id":256,"data":1595,"type":218,"tunes":1596},{"text":258},{},{"id":261,"data":1598,"type":218,"tunes":1599},{"text":263},{},{"id":266,"data":1601,"type":218,"tunes":1602},{"text":268},{},{"id":271,"data":1604,"type":42,"tunes":1605},{"text":273,"level":247},{},{"id":276,"data":1607,"type":218,"tunes":1608},{"text":278},{},{"id":281,"data":1610,"type":218,"tunes":1611},{"text":283},{},{"id":286,"data":1613,"type":218,"tunes":1614},{"text":288},{},{"id":291,"data":1616,"type":317,"tunes":1625},{"steps":1617,"title":315,"orientation":316},[1618,1619,1620,1621,1622,1623,1624],{"label":295,"description":296},{"label":298,"description":299},{"label":301,"description":302},{"label":304,"description":305},{"label":307,"description":308},{"label":310,"description":311},{"label":313,"description":314},{},{"id":320,"data":1627,"type":42,"tunes":1628},{"text":322,"level":247},{},{"id":325,"data":1630,"type":218,"tunes":1631},{"text":327},{},{"id":330,"data":1633,"type":218,"tunes":1634},{"text":332},{},{"id":335,"data":1636,"type":42,"tunes":1637},{"text":337,"level":247},{},{"id":340,"data":1639,"type":369,"tunes":1652},{"rows":1640,"title":360,"layout":361,"columns":1649},[1641,1643,1645,1647],{"id":344,"label":345,"values":1642},[347,347],{"id":349,"label":350,"values":1644},[347,347],{"id":353,"label":354,"values":1646},[347,347],{"id":357,"label":358,"values":1648},[347,347],[1650,1651],{"id":364,"label":365},{"id":367,"label":368},{},{"id":372,"data":1654,"type":218,"tunes":1655},{"text":374},{},{"id":377,"data":1657,"type":42,"tunes":1658},{"text":379,"level":247},{},{"id":382,"data":1660,"type":361,"tunes":1669},{"content":1661,"stretched":43,"withHeadings":14},[1662,1663,1664,1665,1666,1667,1668],[386,387,388],[390,391,392],[394,395,396],[398,399,400],[402,403,404],[406,407,408],[410,411,412],{},{"id":415,"data":1671,"type":218,"tunes":1672},{"text":417},{},{"id":420,"data":1674,"type":42,"tunes":1675},{"text":422,"level":247},{},{"id":425,"data":1677,"type":361,"tunes":1692},{"content":1678,"stretched":43,"withHeadings":14},[1679,1680,1681,1682,1683,1684,1685,1686,1687,1688,1689,1690,1691],[429,430],[432,433],[435,436],[438,439],[441,442],[444,445],[447,448],[450,451],[453,454],[456,457],[459,460],[462,463],[465,466],{},{"id":469,"data":1694,"type":42,"tunes":1695},{"text":471,"level":247},{},{"id":474,"data":1697,"type":218,"tunes":1698},{"text":476},{},{"id":479,"data":1700,"type":218,"tunes":1701},{"text":481},{},{"id":484,"data":1703,"type":226,"tunes":1704},{"body":486,"title":487,"variant":488},{},{"id":491,"data":1706,"type":42,"tunes":1707},{"text":493,"level":247},{},{"id":496,"data":1709,"type":218,"tunes":1710},{"text":498},{},{"id":501,"data":1712,"type":218,"tunes":1713},{"text":503},{},{"id":506,"data":1715,"type":218,"tunes":1716},{"text":508},{},{"id":511,"data":1718,"type":42,"tunes":1719},{"text":513,"level":247},{},{"id":516,"data":1721,"type":361,"tunes":1731},{"content":1722,"stretched":43,"withHeadings":14},[1723,1724,1725,1726,1727,1728,1729,1730],[520,521],[523,524],[526,527],[529,530],[532,533],[535,536],[538,539],[541,542],{},{"id":545,"data":1733,"type":218,"tunes":1734},{"text":547},{},{"id":550,"data":1736,"type":42,"tunes":1737},{"text":552,"level":247},{},{"id":555,"data":1739,"type":218,"tunes":1740},{"text":557},{},{"id":560,"data":1742,"type":218,"tunes":1743},{"text":562},{},{"id":565,"data":1745,"type":218,"tunes":1746},{"text":567},{},{"id":570,"data":1748,"type":42,"tunes":1749},{"text":572,"level":247},{},{"id":575,"data":1751,"type":218,"tunes":1752},{"text":577},{},{"id":580,"data":1754,"type":218,"tunes":1755},{"text":582},{},{"id":585,"data":1757,"type":42,"tunes":1758},{"text":587,"level":247},{},{"id":590,"data":1760,"type":218,"tunes":1761},{"text":592},{},{"id":595,"data":1763,"type":218,"tunes":1764},{"text":597},{},{"id":600,"data":1766,"type":226,"tunes":1767},{"body":602,"title":603,"variant":233},{},{"id":606,"data":1769,"type":42,"tunes":1770},{"text":608,"level":247},{},{"id":611,"data":1772,"type":218,"tunes":1773},{"text":613},{},{"id":616,"data":1775,"type":218,"tunes":1776},{"text":618},{},{"id":621,"data":1778,"type":42,"tunes":1779},{"text":623,"level":247},{},{"id":626,"data":1781,"type":218,"tunes":1782},{"text":628},{},{"id":631,"data":1784,"type":218,"tunes":1785},{"text":633},{},{"id":636,"data":1787,"type":642,"tunes":1788},{"url":638,"title":639,"excerpt":640,"ctaLabel":641},{},{"id":645,"data":1790,"type":42,"tunes":1791},{"text":647,"level":247},{},{"id":650,"data":1793,"type":218,"tunes":1794},{"text":652},{},{"id":655,"data":1796,"type":218,"tunes":1797},{"text":657},{},{"id":660,"data":1799,"type":42,"tunes":1800},{"text":662,"level":247},{},{"id":665,"data":1802,"type":369,"tunes":1813},{"rows":1803,"title":680,"layout":361,"columns":1810},[1804,1806,1808],{"id":669,"label":670,"values":1805},[347,347],{"id":673,"label":674,"values":1807},[347,347],{"id":677,"label":678,"values":1809},[347,347],[1811,1812],{"id":683,"label":684},{"id":686,"label":687},{},{"id":690,"data":1815,"type":42,"tunes":1816},{"text":692,"level":247},{},{"id":695,"data":1818,"type":218,"tunes":1819},{"text":697},{},{"id":700,"data":1821,"type":218,"tunes":1822},{"text":702},{},{"id":705,"data":1824,"type":218,"tunes":1825},{"text":707},{},{"id":710,"data":1827,"type":42,"tunes":1828},{"text":712,"level":247},{},{"id":715,"data":1830,"type":361,"tunes":1842},{"content":1831,"stretched":43,"withHeadings":14},[1832,1833,1834,1835,1836,1837,1838,1839,1840,1841],[719,720],[722,723],[725,726],[728,729],[731,732],[734,735],[737,738],[740,741],[743,744],[746,747],{},{"id":750,"data":1844,"type":42,"tunes":1845},{"text":752,"level":247},{},{"id":755,"data":1847,"type":218,"tunes":1848},{"text":757},{},{"id":760,"data":1850,"type":218,"tunes":1851},{"text":762},{},{"id":765,"data":1853,"type":218,"tunes":1854},{"text":767},{},{"id":770,"data":1856,"type":42,"tunes":1857},{"text":772,"level":247},{},{"id":775,"data":1859,"type":218,"tunes":1860},{"text":777},{},{"id":780,"data":1862,"type":218,"tunes":1863},{"text":782},{},{"id":785,"data":1865,"type":218,"tunes":1866},{"text":787},{},{"id":790,"data":1868,"type":42,"tunes":1869},{"text":792,"level":247},{},{"id":795,"data":1871,"type":218,"tunes":1872},{"text":797},{},{"id":800,"data":1874,"type":218,"tunes":1875},{"text":802},{},{"id":805,"data":1877,"type":642,"tunes":1878},{"url":807,"title":808,"excerpt":809,"ctaLabel":810},{},{"id":813,"data":1880,"type":42,"tunes":1881},{"text":815,"level":247},{},{"id":818,"data":1883,"type":218,"tunes":1884},{"text":820},{},{"id":823,"data":1886,"type":218,"tunes":1887},{"text":825},{},{"id":828,"data":1889,"type":218,"tunes":1890},{"text":830},{},{"id":833,"data":1892,"type":642,"tunes":1893},{"url":835,"title":836,"excerpt":837,"ctaLabel":838},{},{"id":841,"data":1895,"type":42,"tunes":1896},{"text":843,"level":247},{},{"id":846,"data":1898,"type":361,"tunes":1909},{"content":1899,"stretched":43,"withHeadings":14},[1900,1901,1902,1903,1904,1905,1906,1907,1908],[358,850,851],[853,854,855],[857,858,859],[861,862,863],[865,866,867],[869,870,871],[873,874,875],[877,878,879],[881,882,883],{},{"id":886,"data":1911,"type":42,"tunes":1912},{"text":888,"level":247},{},{"id":891,"data":1914,"type":218,"tunes":1915},{"text":893},{},{"id":896,"data":1917,"type":218,"tunes":1918},{"text":898},{},{"id":901,"data":1920,"type":42,"tunes":1921},{"text":903,"level":247},{},{"id":906,"data":1923,"type":361,"tunes":1936},{"content":1924,"stretched":43,"withHeadings":14},[1925,1926,1927,1928,1929,1930,1931,1932,1933,1934,1935],[910,521,911],[913,914,915],[917,918,919],[921,922,923],[925,926,927],[929,930,931],[933,934,935],[937,938,939],[941,942,943],[945,946,947],[949,950,951],{},{"id":954,"data":1938,"type":42,"tunes":1939},{"text":956,"level":247},{},{"id":959,"data":1941,"type":361,"tunes":1951},{"content":1942,"stretched":43,"withHeadings":14},[1943,1944,1945,1946,1947,1948,1949,1950],[963,964],[966,967],[969,970],[972,973],[975,976],[978,979],[981,982],[984,985],{},{"id":988,"data":1953,"type":218,"tunes":1954},{"text":990},{},{"id":993,"data":1956,"type":42,"tunes":1957},{"text":995,"level":247},{},{"id":998,"data":1959,"type":42,"tunes":1960},{"text":1000,"level":246},{},{"id":1003,"data":1962,"type":218,"tunes":1963},{"text":1005},{},{"id":1008,"data":1965,"type":218,"tunes":1966},{"text":1010},{},{"id":1013,"data":1968,"type":218,"tunes":1969},{"text":1015},{},{"id":1018,"data":1971,"type":218,"tunes":1972},{"text":1020},{},{"id":1023,"data":1974,"type":42,"tunes":1975},{"text":1025,"level":246},{},{"id":1028,"data":1977,"type":218,"tunes":1978},{"text":1030},{},{"id":1033,"data":1980,"type":218,"tunes":1981},{"text":1035},{},{"id":1038,"data":1983,"type":218,"tunes":1984},{"text":1040},{},{"id":1043,"data":1986,"type":361,"tunes":1995},{"content":1987,"stretched":43,"withHeadings":14},[1988,1989,1990,1991,1992,1993,1994],[1047,1048],[1050,1051],[1053,1054],[1056,1057],[1059,1060],[1062,1063],[1065,1066],{},{"id":1069,"data":1997,"type":226,"tunes":1998},{"body":1071,"title":1072,"variant":240},{},{"id":1075,"data":2000,"type":42,"tunes":2001},{"text":1077,"level":247},{},{"id":1080,"data":2003,"type":361,"tunes":2018},{"content":2004,"stretched":43,"withHeadings":14},[2005,2006,2007,2008,2009,2010,2011,2012,2013,2014,2015,2016,2017],[1084,1085],[1087,1088],[1090,1091],[1093,1094],[1096,1097],[1099,1100],[1102,1103],[1105,1106],[1108,1109],[1111,1112],[1114,1115],[1117,1118],[1120,1121],{},{"id":1124,"data":2020,"type":42,"tunes":2021},{"text":1126,"level":247},{},{"id":1129,"data":2023,"type":361,"tunes":2036},{"content":2024,"stretched":43,"withHeadings":14},[2025,2026,2027,2028,2029,2030,2031,2032,2033,2034,2035],[1133,1134],[1136,1137],[1139,1140],[1142,1143],[1145,1146],[1148,1149],[1151,1152],[1154,1155],[1157,1158],[1160,1161],[1163,1164],{},{"id":1167,"data":2038,"type":42,"tunes":2039},{"text":1169,"level":247},{},{"id":1172,"data":2041,"type":317,"tunes":2055},{"steps":2042,"title":1211,"orientation":316},[2043,2044,2045,2046,2047,2048,2049,2050,2051,2052,2053,2054],{"label":1176,"description":1177},{"label":1179,"description":1180},{"label":1182,"description":1183},{"label":1185,"description":1186},{"label":1188,"description":1189},{"label":1191,"description":1192},{"label":1194,"description":1195},{"label":1197,"description":1198},{"label":1200,"description":1201},{"label":1203,"description":1204},{"label":1206,"description":1207},{"label":1209,"description":1210},{},{"id":1214,"data":2057,"type":42,"tunes":2058},{"text":1216,"level":247},{},{"id":1219,"data":2060,"type":361,"tunes":2076},{"content":2061,"stretched":43,"withHeadings":14},[2062,2063,2064,2065,2066,2067,2068,2069,2070,2071,2072,2073,2074,2075],[521,1223],[1225,1226],[1228,1229],[1231,1232],[1234,1235],[1237,1238],[1240,1241],[1243,1244],[1246,1247],[1249,1250],[1252,1253],[1255,1256],[1258,1259],[1261,1262],{},{"id":1265,"data":2078,"type":42,"tunes":2079},{"text":1267,"level":247},{},{"id":1270,"data":2081,"type":218,"tunes":2082},{"text":1272},{},{"id":1275,"data":2084,"type":218,"tunes":2085},{"text":1277},{},{"id":1280,"data":2087,"type":218,"tunes":2088},{"text":1282},{},{"id":1285,"data":2090,"type":218,"tunes":2091},{"text":1287},{},{"id":1290,"data":2093,"type":218,"tunes":2094},{"text":1292},{},{"id":1295,"data":2096,"type":42,"tunes":2097},{"text":1297,"level":247},{},{"id":1300,"data":2099,"type":218,"tunes":2100},{"text":1302},{},{"id":1305,"data":2102,"type":218,"tunes":2103},{"text":1307},{},{"id":1310,"data":2105,"type":218,"tunes":2106},{"text":1312},{},{"id":1315,"data":2108,"type":42,"tunes":2109},{"text":1317,"level":247},{},{"id":1320,"data":2111,"type":218,"tunes":2112},{"text":1322},{},{"id":1325,"data":2114,"type":218,"tunes":2115},{"text":1327},{},{"id":1330,"data":2117,"type":218,"tunes":2118},{"text":1332},{},{"id":1335,"data":2120,"type":42,"tunes":2121},{"text":1337,"level":247},{},{"id":1340,"data":2123,"type":1340,"tunes":2134},{"items":2124,"title":1379},[2125,2126,2127,2128,2129,2130,2131,2132,2133],{"id":1344,"answer":1345,"question":1346},{"id":1348,"answer":1349,"question":1350},{"id":1352,"answer":1353,"question":1354},{"id":1356,"answer":1357,"question":1358},{"id":1360,"answer":1361,"question":1362},{"id":1364,"answer":1365,"question":1366},{"id":1368,"answer":1369,"question":1370},{"id":1372,"answer":1373,"question":1374},{"id":1376,"answer":1377,"question":1378},{},{"id":1382,"data":2136,"type":42,"tunes":2137},{"text":1384,"level":247},{},{"id":1387,"data":2139,"type":1387,"tunes":2152},{"title":1389,"entries":2140},[2141,2142,2143,2144,2145,2146,2147,2148,2149,2150,2151],{"term":1392,"anchor":1393,"definition":1394},{"term":1396,"anchor":1397,"definition":1398},{"term":406,"anchor":1400,"definition":1401},{"term":447,"anchor":1403,"definition":1404},{"term":1406,"anchor":1407,"definition":1408},{"term":1410,"anchor":1411,"definition":1412},{"term":1414,"anchor":1415,"definition":1416},{"term":1418,"anchor":1419,"definition":1420},{"term":1422,"anchor":1423,"definition":1424},{"term":1426,"anchor":1427,"definition":1428},{"term":1430,"anchor":1431,"definition":1432},{},{"id":1435,"data":2154,"type":42,"tunes":2155},{"text":1437,"level":247},{},{"id":1440,"data":2157,"type":218,"tunes":2158},{"text":1442},{},{"id":1445,"data":2160,"type":218,"tunes":2161},{"text":1447},{},{"id":1450,"data":2163,"type":218,"tunes":2164},{"text":1452},{},{"id":1455,"data":2166,"type":42,"tunes":2167},{"text":1457,"level":247},{},{"id":1460,"data":2169,"type":218,"tunes":2170},{"text":1462},{},{"id":1465,"data":2172,"type":1472,"tunes":2175},{"link":1467,"meta":2173},{"image":2174,"title":1470,"description":1471},{"url":347},{},{"id":1475,"data":2177,"type":1472,"tunes":2180},{"link":1477,"meta":2178},{"image":2179,"title":1480,"description":1481},{"url":347},{},{"id":1484,"data":2182,"type":1472,"tunes":2185},{"link":1486,"meta":2183},{"image":2184,"title":1489,"description":1490},{"url":347},{},{"id":1493,"data":2187,"type":1472,"tunes":2190},{"link":1495,"meta":2188},{"image":2189,"title":1498,"description":1499},{"url":347},{},{"id":1502,"data":2192,"type":1472,"tunes":2195},{"link":1504,"meta":2193},{"image":2194,"title":1507,"description":1508},{"url":347},{},{"id":1511,"data":2197,"type":1472,"tunes":2200},{"link":1513,"meta":2198},{"image":2199,"title":1516,"description":1517},{"url":347},{},{"id":1520,"data":2202,"type":1472,"tunes":2205},{"link":1522,"meta":2203},{"image":2204,"title":1525,"description":1526},{"url":347},{},{"id":1529,"data":2207,"type":1472,"tunes":2210},{"link":1531,"meta":2208},{"image":2209,"title":1534,"description":1535},{"url":347},{},"Post erfolgreich abgerufen",{"items":2213,"source":2296,"manualIds":2297,"manualMatchedIds":2298},[2214,2221,2228,2235,2242,2249,2256,2262,2269,2276,2283,2290],{"id":2215,"slug":2216,"title":2217,"excerpt":2218,"featuredImage":2219,"publishedAt":2220},"467","the-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","The Answer Validity Boundary: The Missing Layer Between Relevance and Reliable AI Answers","A source can be relevant, authoritative and still be wrong for the question being asked. The missing layer is applicability: the conditions under which an answer holds, and the changes that force it to be reconsidered. This article introduces the Answer Validity Boundary as a source-design pattern for humans, AI search and RAG systems.","\u002Fuploads\u002F2026\u002F09\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers-1790272901306-1g5jly.webp","2026-09-24T11:59:00.000Z",{"id":2222,"slug":2223,"title":2224,"excerpt":2225,"featuredImage":2226,"publishedAt":2227},"480","when-should-an-ai-stop-trusting-its-own-knowledge-the-retrieval-trigger","When Should an AI Stop Trusting Its Own Knowledge? — The Retrieval Trigger","An AI model does not need retrieval for every question. The important problem is knowing when its internal knowledge is no longer enough. The Retrieval Trigger is a practical decision boundary that determines when an AI system should stop relying solely on model knowledge and obtain external evidence before answering.","\u002Fuploads\u002F2026\u002F09\u002Fwhen-should-an-ai-stop-trusting-its-own-knowledge-the-retrieval-trigger-1790574991244-f4rpyg.webp","2026-09-28T01:49:00.000Z",{"id":2229,"slug":2230,"title":2231,"excerpt":2232,"featuredImage":2233,"publishedAt":2234},"478","what-is-rag-the-simplest-explanation-of-how-it-works","What Is RAG? The Simplest Explanation of How It Works","RAG sounds complicated, but the idea is simple: before an AI answers, it first looks up useful information from a knowledge source and gives that information to the language model. This guide explains RAG, LLMs, state, memory and tools using one simple mental model.","\u002Fuploads\u002F2026\u002F09\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works-1790377492124-khjagt.webp","2026-09-25T19:03:00.000Z",{"id":2236,"slug":2237,"title":2238,"excerpt":2239,"featuredImage":2240,"publishedAt":2241},"479","where-does-an-llm-get-its-data-rag-data-sources-in-python","Where Does an LLM Get Its Data? RAG Data Sources in Python","An LLM does not magically know your files, databases or APIs. This practical continuation of the RAG series shows, with simple Python, how external data becomes retrievable evidence: from text files and SQL to full-text search, embeddings, context assembly and the final LLM call.","\u002Fuploads\u002F2026\u002F09\u002Fwhere-does-an-llm-get-its-data-rag-data-sources-in-python-1790517200521-nfsi5i.webp","2026-09-27T05:51:00.000Z",{"id":2243,"slug":2244,"title":2245,"excerpt":2246,"featuredImage":2247,"publishedAt":2248},"471","how-to-know-whether-an-ai-agent-actually-used-the-right-evidence","How to Know Whether an AI Agent Actually Used the Right Evidence","An AI agent can cite sources and still use the wrong evidence. This article introduces a practical method for checking claim support, source authority, applicability, provenance, and whether the evidence actually influenced the answer.","\u002Fuploads\u002F2026\u002F09\u002Fhow-to-know-whether-an-ai-agent-actually-used-the-right-evidence-1790351317188-o5z9ve.webp","2026-09-25T11:47:00.000Z",{"id":2250,"slug":2251,"title":2252,"excerpt":2253,"featuredImage":2254,"publishedAt":2255},"483","what-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs","What Is an AI Solution Architect? System Boundaries, Responsibilities and Trade-offs","An AI Solution Architect turns business requirements into a production-ready AI system across data, models, tools, security, runtime, evaluation and operations.","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs-1791476643267-1st5xz.webp","2026-10-08T12:23:00.000Z",{"id":2257,"slug":2258,"title":836,"excerpt":2259,"featuredImage":2260,"publishedAt":2261},"460","ai-agent-reliability-why-the-final-answer-is-not-enough","Correct output does not prove correct reasoning, safe execution, or a trustworthy system.","\u002Fuploads\u002F2026\u002F09\u002Fai-agent-reliability-why-the-final-answer-is-not-enough-1788955466306-pl0qhz.webp","2026-09-09T04:01:00.000Z",{"id":2263,"slug":2264,"title":2265,"excerpt":2266,"featuredImage":2267,"publishedAt":2268},"495","sovereign-ai-control-of-models-data-infrastructure-and-dependencies","Sovereign AI: Control of Models, Data, Infrastructure and Dependencies","Sovereign AI is about effective control over models, data, infrastructure, software, operations and strategic dependencies — not simply where an AI model is hosted.","\u002Fuploads\u002F2026\u002F10\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies-1791488833132-niy85x.webp","2026-10-08T15:45:00.000Z",{"id":2270,"slug":2271,"title":2272,"excerpt":2273,"featuredImage":2274,"publishedAt":2275},"492","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","MCP Explained: What It Connects, What It Does Not Do and Where It Fits","Model Context Protocol connects AI applications to external tools, resources and prompts through a standard client-server boundary. Learn what MCP does, what it does not do, and where it fits in agent architecture.","\u002Fuploads\u002F2026\u002F10\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq.webp","2026-10-08T15:09:00.000Z",{"id":2277,"slug":2278,"title":2279,"excerpt":2280,"featuredImage":2281,"publishedAt":2282},"487","vector-databases-embeddings-and-reranking-three-different-parts-of-retrieval","Vector Databases, Embeddings and Reranking: Three Different Parts of Retrieval","Embeddings represent meaning, vector databases retrieve candidates, and rerankers refine results. Learn how these three retrieval layers differ and work together in RAG.","\u002Fuploads\u002F2026\u002F10\u002Fvector-databases-embeddings-and-reranking-three-different-parts-of-retrieval-1791480129884-9dtasz.webp","2026-10-08T11:21:00.000Z",{"id":2284,"slug":2285,"title":2286,"excerpt":2287,"featuredImage":2288,"publishedAt":2289},"484","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations","What Is an AI Platform Architect? Models, Data, Runtime, Security and Operations","An AI Platform Architect designs reusable AI foundations across models, providers, retrieval, agents, identity, security, evaluation, observability and operations.","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc.webp","2026-10-08T12:32:00.000Z",{"id":2291,"slug":2292,"title":808,"excerpt":2293,"featuredImage":2294,"publishedAt":2295},"476","mcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained","MCP, A2A, UCP, AP2 and A2UI are often presented as competing agent standards. They mostly solve different interoperability problems. This guide maps each protocol to the boundary it actually standardizes—and shows how they can work together in one production system.","\u002Fuploads\u002F2026\u002F09\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained-1790352625869-2ezle0.webp","2026-09-25T12:09:00.000Z","fallback",[],[]]