What an AI agent is. And what it may do alone.
The companies that build the models define an agent as a model that chooses its own steps. The rules for clinics, banks and law firms already say where a person has to stand.
Tyler Gibbs. . 4 minute read.

Every vendor now sells an agent. A buyer at a bank, a clinic or a law firm hears the word in every pitch and is left to work out two things alone: what the word means, and how much of the job it should be allowed to do without a person.
The companies that build the models have published plain definitions, and the regulators in each of those three fields have already written down where a person has to be. Put together, they answer both questions.
An agent is a model that chooses its own steps.
Anthropic draws the line most clearly. In a workflow, the model and its tools are “orchestrated through predefined code paths.” Somebody wrote the steps, and the model fills in judgment at fixed points. Agents are systems where models “dynamically direct their own processes and tool usage.” The model decides what to look up, what to do next, and when it is finished. OpenAI’s guide says the same in fewer words. Agents are systems that “independently accomplish tasks on your behalf.”
Whether a product is an agent, then, depends on who chose the steps. If your team or your vendor wrote them, it is a workflow with a model in it. If the model picks them as it goes, it is an agent.
Most office work does not need one.
Anthropic’s first piece of advice is to find “the simplest solution possible” and add complexity only when it is needed. That advice suits regulated work, where most tasks already have written steps: check these six fields, compare this file to that policy, route it to this desk. Fixed steps can be read, tested and shown to an examiner. A model choosing its own path is harder to explain afterward.
An agent earns its place when the steps cannot be written in advance. Research is the usual case. What to look up next depends on what the last lookup found, and no checklist covers it.
The rules already say where a person stands.
None of the three fields has a rule written for agents. Each has a rule about who answers for the decision, and that rule does not care what kind of software did the preparation.
In healthcare, CMS told Medicare Advantage plans in February 2024 that an algorithm or software tool can assist a coverage decision, and that algorithms or artificial intelligence “alone cannot be used as the basis to deny admission.” Under Medicare Advantage rules, a denial on medical necessity must be reviewed by a physician or another appropriate health care professional.
In law, the American Bar Association’s Formal Opinion 512 says a lawyer needs a reasonable understanding of what the tool can and cannot do, and that relying on its output without “an appropriate degree of independent verification or review” can breach the duty of competence.
In banking, the picture changed this year. The Federal Reserve, the FDIC and the OCC replaced their 2011 guidance on model risk in April 2026. The new guidance is aimed mainly at banks with more than $30 billion in assets. It keeps the principle of effective challenge by objective experts, and a footnote says generative and agentic AI models are not within its scope. A bank cannot point to that guidance and call its agent covered. It has to decide for itself who checks the agent’s work, and write that down.
NIST’s voluntary AI framework asks for the same thing from everyone: that processes for human oversight be “defined, assessed, and documented.” It also allows that the right arrangement can sit anywhere from fully automatic to fully manual. The framework asks you to choose on purpose and be able to show the choice.
Let it act alone only where a mistake is cheap to undo.
OpenAI’s guide names two moments to bring a person in: when the agent keeps failing, and before a high-risk action. That gives a working test for any step you are thinking of handing over. Ask what happens if the agent gets it wrong, and whether you can take it back.
Looking up a record, drafting a summary, or assembling a file can be redone at no cost, so an agent can do those alone. Sending a denial, releasing a payment, or filing a document with a court cannot be taken back, and each has a named person who answers for it. The agent prepares those. The person decides.
One agent, drawn that way.
For a hospital system, we built an agent that researches and prepares prior authorizations. Which records it pulls depends on the request, so the steps cannot be fixed in advance, and that is why it is an agent. It gathers from the health record system, internal databases and outside sources, and prepares the case. Staff review it wherever a person needs to decide. The work page describes it.
This post explains published guidance and is not legal advice. Your counsel and your compliance lead decide how these rules apply to you. What the sources agree on is short enough to carry into any vendor meeting: ask who chose the steps, and ask which person answers for each step that cannot be undone.
Sources
- Anthropic, “Building Effective AI Agents,” 19 December 2024
- OpenAI, “A practical guide to building agents,” 2025
- NIST, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” January 2023
- Federal Reserve, FDIC and OCC, SR 26-2, “Revised Guidance on Model Risk Management,” 17 April 2026
- American Bar Association, Formal Opinion 512, “Generative Artificial Intelligence Tools,” 29 July 2024
- CMS, “Frequently Asked Questions related to Coverage Criteria and Utilization Management Requirements in CMS Final Rule (CMS-4201-F),” 6 February 2024
- 42 CFR § 422.566(d), who must review organization determinations