An AI agent is an artificial intelligence system that can pursue goals, use software or other tools, and take actions with some level of autonomy.[1][2][3] Agentic AI is a related and inconsistently defined term for systems designed to exhibit such goal-directed autonomy, sometimes through multiple coordinated agents.[4]

Overview

There is no single standard definition of what an AI agent is.[4][5][6] Common attributes of AI agents include goal-directed behavior, natural language interfaces, the capacity to use external tools, and the ability to perform multi-step tasks. Their control flow is frequently driven by large language models (LLMs). Agent systems may also include memory components, planning logic, tool interfaces, and orchestration software for coordinating agent components.[3][6]

A common application of AI agents is task automation: for example, booking travel plans based on a user's prompted request.[7][8]

Companies such as Google, Microsoft and Amazon Web Services have offered platforms for building and deploying AI agents.[9][10][11] Open protocols have been proposed for connecting agents to tools and enabling communication between agents, including Model Context Protocol (MCP) and Agent2Agent (A2A).[12][13]

In December 2025, Linux Foundation announced the formation of the Agentic AI Foundation (AAIF), with the goal of ensuring that agentic AI evolves transparently and collaboratively.[14][15]

History

The concept of an intelligent artificial agent predates current LLM-based systems. Oliver Selfridge's 1959 "Pandemonium: A Paradigm for Learning" described a system of interacting computational units for pattern recognition.[16] During the 1990s, agent research developed through work on agent-oriented programming, the belief–desire–intention software model (BDI), and formal accounts of intelligent-agent architectures.[17][18][19]

Research on LLM-based autonomous agents expanded in the early 2020s as language models were combined with planning, memory, and external tools.[3] OpenAI introduced function calling in its API in June 2023, allowing models to return structured requests for software functions.[20] In November 2024, Anthropic introduced the Model Context Protocol (MCP), an open protocol for connecting AI assistants to external data sources and tools.[21] The term "agentic" began to be used with greater frequency in 2024 and was popularized in part by researcher Andrew Ng.[22]

Training and testing

Researchers train and evaluate AI agents in interactive environments that expose them to sequences of observations, actions, and feedback.[23] Video-game environments such as Minecraft and No Man's Sky and benchmark environments that reproduce common websites have been used for this purpose.[24][25]

Autonomous capabilities

The Financial Times compared AI agents' autonomy to the SAE classification of self-driving cars, likening most applications to level 2 or level 3, with some achieving level 4 in highly specialized circumstances and level 5 being theoretical.[26]

Cognitive architecture

Ken Huang proposed an AI agent reference architecture that consists of seven interconnected layers, with each layer building on the functionality of the layers beneath it:[27]

  • Layer 1: Foundation models – provide the core models that power the agent.
  • Layer 2: Data operations – manages the data infrastructure required for AI agent operations, including vector databases, data loaders, and RAG.
  • Layer 3: Agent frameworks – software that manages the AI agents.
  • Layer 4: Deployment and infrastructure – the technical foundation of the AI agents.
  • Layer 5: Evaluation and observability – the safety and performance of AI agents.
  • Layer 6: Security and compliance – a protective framework for safe operation and compliance with regulatory boundaries. At this layer, security and compliance features embedded into all the AI agent stack layers are integrated together.
  • Layer 7: Agent ecosystem – represents the AI agents' interface with real-world applications and users.

Agent harness

In developer documentation, an agent harness refers to the software layer surrounding a large language model that enables it to function as an AI agent. It commonly manages prompts, context, tool use, memory, execution state, operational constraints, sandboxes, permissions, and the processing of results. The harness connects the model to internal and external computer hardware, software, data files, databases, web browsers, command-line interfaces, and application programming interfaces, while controlling how the agent accesses and uses these resources to complete multi-step tasks.[28][29]

Orchestration patterns

Autonomous agents are often integrated with other agents or specialized tools to execute complex tasks. These configurations, known as orchestration patterns or workflows, include the following:[30]

  • Prompt chaining: A sequence where the output of one step serves as the input for the next.
  • Routing: Directing an input to a specialized downstream task or tool.
  • Parallelization: The simultaneous execution of multiple tasks.
  • Sequential processing: A fixed, linear progression of tasks through a predefined pipeline.
  • Planner-critic: An iterative pattern where one agent generates a proposal and another evaluates it to provide feedback for refinement.

Multimodal AI agents

In addition to large language models (LLMs), vision-language models (VLMs) and multimodal foundation models can be used as the basis for agents.[31] Allen Institute for AI released the open-weight Molmo family of vision-language models in 2024.[32] Nvidia released a framework for developers to use VLMs, LLMs and retrieval-augmented generation for building AI agents that can analyze images and videos, including video search and video summarization.[33][34] Microsoft released a multimodal agent model – trained on images, video, software user interface interactions, and robotics data – that the company claimed can manipulate software and robots.[35]

Applications

As of April 2025, per the Associated Press, there are few real-world applications of AI agents.[36]

The Information divided AI agents into seven archetypes: business-task agents, for acting within enterprise software; conversational agents, which act as chatbots for customer support; research agents, for querying and analyzing information (such as OpenAI Deep Research); analytics agents, for analyzing data to create reports; software developer or coding agents (such as Cursor); domain-specific agents, which include specific subject matter knowledge; and web browser agents (such as OpenAI Operator).[37]

By mid-2025, AI agents were being used in video game development,[38] gambling (including sports betting),[39] cryptocurrency wallets[39] (including cryptocurrency trading and meme coins[40]) In August 2025, New York Magazine described software development as the most definitive use of AI agents.[41] The Information noted AI coding agents and customer support as the primary uses of AI by businesses by October 2025, although a decline in the expectations of AI capabilities was also noted.[42]

In November 2025, The Wall Street Journal reported that few companies that deployed AI agents have received a return on investment.[43]

Applications in government

Several government bodies in the United States and United Kingdom have deployed or announced the deployment of agents at the local and national level. The city of Kyle, Texas deployed an AI agent from Salesforce in March 2025 for 311 customer service.[44] In November 2025, the Internal Revenue Service stated that it would deploy Salesforce AI agents for the Office of Chief Counsel, Taxpayer Advocate Services, and the Office of Appeals.[45] That same month, Staffordshire Police announced that they would trial Agentforce agents for handling non-emergency 101 calls in the United Kingdom starting in 2026.[46] In December 2025, the Department of Neighborhoods in Detroit, Michigan, partnered with a local business to deploy a customer service AI agent in two city districts.[47]

In February 2025, Thomas Shedd, the director of the Technology Transformation Services, proposed using AI coding agents across the United States federal government.[48] In April 2025, a recruiter for the Department of Government Efficiency proposed using AI agents to automate the work of about 70,000 United States federal government employees as part of a startup with funding from OpenAI and a partnership agreement with Palantir. This proposal was criticized by experts for its impracticality and the lack of corresponding widespread adoption by businesses.[49]

In December 2025, the Food and Drug Administration announced that it would offer "agentic AI capabilities" to its staff for "meeting management, pre-market reviews, review validation, post-market surveillance, inspections and compliance and administrative functions."[50] That same month, the United States Department of Defense launched GenAI.mil, an internal platform for American military personnel to use generative AI-based applications based on Google Gemini, including "intelligent agentic workflows". Defense Secretary Pete Hegseth listed applications such as "[conducting] deep research, [formatting] documents and even [analyzing] video or imagery at unprecedented speed."[51] In December 2025, the United States Immigration and Customs Enforcement agency signed a contract with a company for its Enforcement and Removal Operations department to use AI agents for skip tracing.[52]

Operating systems

In November 2025, Microsoft released a test software build of Windows 11 that included agents to run background tasks, with the ability to read and write personal files.[53] In December 2025, ByteDance released Doubao, an AI agent that can be integrated into smartphone operating systems, particularly the Nubia M153 by ZTE.[54] Several apps in China blocked or restricted the agent, citing privacy and security concerns, including WeChat,[54] Alipay, Taobao, Pinduoduo, Ele.me,[55] and local banks.[56]

Web browsing

Web browsers with integrated AI agents are sometimes called agentic browsers. Such agents can perform tasks and browser actions on the user's behalf.[57]

In 2025, Microsoft launched NLWeb, an agentic web search replacement that would allow websites to use agents to query content from websites by using RSS-like interfaces that allow for the lookup and semantic retrieval of content. Within weeks of release, NLWeb was found to have created security issues and expose information about users to third-party servers.[58]

Proposed benefits

AI agents have been proposed as a means of increasing personal and economic productivity,[7][59] fostering greater innovation,[60] and liberating users from monotonous tasks.[60][61] However, Parmy Olson's Bloomberg opinion piece argued that agents are best suited for narrow, repetitive tasks with low risk.[62] Conversely, researchers suggest that agents could be applied to web accessibility for people with disabilities,[63] and researchers at Hugging Face propose that agents could be used for coordinating resources such as during disaster response.[64] The R&D Advisory Team of the BBC views AI agents as being most useful when their assigned goal is uncertain.[65] Erik Brynjolfsson suggests that AI agents are more valuable in enhancing, rather than replacing, humans.[66]

Concerns

Research on increasingly agentic systems has identified risks involving weakened human oversight, privacy, bias, manipulation, misinformation, and systemic or long-range harms.[67][6] Their autonomy can also complicate monitoring, accountability, and the allocation of legal responsibility.[68] Agents that use external tools may be vulnerable to prompt-injection attacks in which untrusted data causes the agent to perform unintended actions.[69] Enterprise deployment has additionally raised contracting concerns related to liability allocation, data ownership, and legal accountability.[70]

AI agents may also have a negative impact on the environment due to high energy usage.[65][71][72] Nvidia CEO Jensen Huang predicted that AI agents would require 100 times more computing power than LLMs.[73] There is also the risk of increased political corruption, as AI agents may not question instructions in the same way that humans would.[74]

Journalists have described AI agents as part of a push by Big Tech companies to "automate everything".[75] Several of those companies' CEOs stated in early 2025 that they expect AI agents to eventually "join the workforce".[76][77] In TheAgentCompany, a workplace benchmark accepted at NeurIPS 2025, the best evaluated agent autonomously completed 30.3% of the tasks.[78] Other researchers had similar findings with Devin AI[79] and other agents in both formal business settings[80] and freelance work.[81]

In June 2025, CNN argued that CEOs's statements on AI replacing their employees were a strategy to "[keep] workers working by making them afraid of losing their jobs."[82] Tech companies have pressured employees to use generative AI models in their work, including AI coding agents. Brian Armstrong, the CEO of Coinbase, fired several employees who did not.[83][84] Some business leaders have replaced some of their employees with agents, but have said that the agents would need more supervision than those employees.[42]

Large technology companies such as Salesforce, Klarna and IBM announced layoffs in 2025, replacing hundreds of their employees in human resources or customer service with AI agents.[85][86][87] However, Klarna later rehired several human employees.[86]

Financial authorities have warned that more complex and autonomous "agentic" AI could become a channel for systemic risk in finance.[88] They distinguish these systems from other AI because they can pursue goals over many steps, call tools, and carry out tasks with relatively little human intervention. In workshops with regulators, central‑bank officials, and industry specialists, participants highlighted risks both from agentic systems built inside financial institutions and from tools offered by technology firms that can initiate or execute financial actions. In one 2025 forum, 44% of experts surveyed judged autonomous or agentic AI systems to be the most likely current source of AI‑related systemic risk in finance.[88]

In March 2025, Scale AI signed a contract with the United States Department of Defense to work with them, in collaboration with Anduril Industries and Microsoft, to develop and deploy AI agents for the purpose of assisting the military with "operational decision-making".[89] In July 2025, Fox Business reported that the company EdgeRunner AI built an offline agent, compressed and fine-tuned on military information, with the CEO seeing more common LLMs as "heavily politicized to the left". As of that time, the company model is being used by the United States Special Operations Command in an overseas deployment.[90] A study of LLM agents in simulated wargames found escalatory and difficult-to-predict behavior, leading its authors to recommend caution before using autonomous agents in strategic military or diplomatic decision-making.[91]

NY Mag unfavorably compared the user workflow of agent-based web browsers to Amazon Alexa, which was "software talking to software, not humans talking to software pretending to be humans to use software."[92] The same outlet described web browser agents and computer-use agents as an attempt to "click-farm the entire economy."[93]

Agents may get stuck in infinite loops.[94][95]

Since many inter-agent protocols are being developed by large technology companies, there are concerns that those companies could use these protocols to benefit themselves.[96]

In June 2025, Gartner described the rebranding of existing assistants, chatbots, and robotic-process-automation products as agents without substantial agentic capabilities as "agent washing".[97]

Researchers have warned about the impact of providing AI agents access to cryptocurrency and smart contracts.[40]

During a vibe coding experiment, a coding agent by Replit deleted a production database during a code freeze, "[covered] up bugs and issues by creating fake data [and] fake reports" and responded with false information.[98][99]

OpenAI co-founder Andrej Karpathy criticized AI agents as being ineffective and promoting AI slop.[100]

Issues with multi-agent systems include coordination and communication between component agents, inconsistent performance, and challenges in debugging.[101]

In November 2025, Anthropic claimed that a group of hackers sponsored by China attempted a cyberattack against at least 30 organizations by using Claude Code in an agentic workflow, and that several of these infiltrations had succeeded.[102] However, independent cybersecurity researchers questioned the significance of Anthropic's findings.[102][103]

Whittaker argued that the push by Big Tech companies to deploy AI agents risked security vulnerabilities across the Internet.[104]

Agentic misalignment

"Agentic misalignment" refers to situations in which an AI agent pursues strategies that conflict with its designers' intentions. In 2025, Anthropic reported controlled simulations in which models sometimes engaged in harmful actions, such as blackmail or corporate espionage, when those actions appeared necessary to achieve an assigned goal or avoid replacement. Anthropic emphasized that the scenarios were deliberately constructed stress tests and that it was not aware of such behavior occurring in real-world deployments.[105]

Security

Threat modeling frameworks

Threat-modeling approaches applied to AI agents include general software-security models and AI-specific frameworks:

  • STRIDE: A Microsoft model that identifies threats across six categories: spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.[106]
  • MITRE ATLAS: A knowledge base of adversary tactics and techniques for AI systems.[107]
  • OWASP GenAI Security Project: Provides guidance on vulnerabilities associated with generative AI and large language model integration, including guidelines specifically for agentic applications.[108]
  • MAESTRO: A framework from the Cloud Security Alliance for assessing risks in multi-agent AI systems throughout their lifecycle.[109]

See also

References

  1. "AI Agent Standards Initiative". National Institute of Standards and Technology. Retrieved May 5, 2026.
  2. "What Are AI Agents?". IBM. Retrieved May 5, 2026.
  3. 1 2 3 Wang, Lei; et al. (2024). "A survey on large language model based autonomous agents". Frontiers of Computer Science. 18. 186345. doi:10.1007/s11704-024-40231-1.
  4. 1 2 Sapkota, Ranjan; Roumeliotis, Konstantinos I.; Karkee, Manoj (2026). "AI Agents vs. Agentic AI: A Conceptual Taxonomy, Applications and Challenges". Information Fusion. 126. 103599. doi:10.1016/j.inffus.2025.103599.
  5. Zeff, Maxwell; Wiggers, Kyle (March 14, 2025). "No one knows what the hell an AI agent is". TechCrunch. Archived from the original on March 18, 2025. Retrieved May 15, 2025.
  6. 1 2 3 Abou Ali, Mohamad; Dornaika, Fadi; Charafeddine, Jinan (2026). "Agentic AI: a comprehensive survey of architectures, applications, and future directions". Artificial Intelligence Review. 59. 11. doi:10.1007/s10462-025-11422-4.
  7. 1 2 "What are the risks and benefits of 'AI agents'?". World Economic Forum. December 16, 2024. Archived from the original on December 28, 2024. Retrieved January 14, 2025.
  8. Knight, Will (March 14, 2024). "Forget Chatbots. AI Agents Are the Future". Wired. ISSN 1059-1028. Archived from the original on January 5, 2025. Retrieved January 14, 2025.
  9. "Gemini Enterprise Agent Platform". Google Cloud. Retrieved August 10, 2026.
  10. "What is Microsoft Foundry Agent Service?". Microsoft Learn. Retrieved August 10, 2026.
  11. "Amazon Bedrock AgentCore". Amazon Web Services. Retrieved August 10, 2026.
  12. "Introducing the Model Context Protocol". Anthropic. November 25, 2024. Retrieved August 10, 2026.
  13. "Announcing the Agent2Agent Protocol (A2A)". Google Developers Blog. April 9, 2025. Retrieved August 10, 2026.
  14. "Linux Foundation Announces the Formation of the Agentic AI Foundation (AAIF), Anchored by New Project Contributions Including Model Context Protocol (MCP), goose and AGENTS.md". Agentic AI Foundation (Press release). Retrieved January 17, 2026.
  15. "Linux Foundation founds Agentic AI Foundation". Archived from the original on December 28, 2025. Retrieved January 22, 2026.
  16. Selfridge, Oliver G. (1959). "Pandemonium: A Paradigm for Learning". Mechanisation of Thought Processes: Proceedings of a Symposium Held at the National Physical Laboratory. Her Majesty's Stationery Office. pp. 511–529.
  17. Shoham, Yoav (1993). "Agent-oriented programming". Artificial Intelligence. 60 (1): 51–92. doi:10.1016/0004-3702(93)90034-9.
  18. Rao, Anand S.; Georgeff, Michael P. (1995). "BDI Agents: From Theory to Practice" (PDF). Proceedings of the First International Conference on Multiagent Systems. AAAI Press. pp. 312–319.
  19. Wooldridge, Michael; Jennings, Nicholas R. (1995). "Intelligent agents: theory and practice". The Knowledge Engineering Review. 10 (2): 115–152. doi:10.1017/S0269888900008122.
  20. "Function calling and other API updates". OpenAI. June 13, 2023. Retrieved August 10, 2026.
  21. "Introducing the Model Context Protocol". Anthropic. November 25, 2024. Retrieved August 10, 2026.
  22. O'Brien, Matt (November 18, 2025). "What does 'agentic' AI mean? Tech's newest buzzword is a mix of marketing fluff and real promise". Associated Press. Archived from the original on November 18, 2025. Retrieved November 28, 2025.
  23. Liu, Xiao; et al. (2024). "AgentBench: Evaluating LLMs as Agents". Proceedings of the Twelfth International Conference on Learning Representations.
  24. Wang, Guanzhi; et al. (2024). "Voyager: An Open-Ended Embodied Agent with Large Language Models". Transactions on Machine Learning Research.
  25. Zhou, Shuyan; et al. (2024). "WebArena: A Realistic Web Environment for Building Autonomous Agents". Proceedings of the Twelfth International Conference on Learning Representations. ICLR 2024.
  26. "AI agents: from co-pilot to autopilot". May 7, 2025. Archived from the original on February 28, 2026. Retrieved August 10, 2026.
  27. Huang, Ken (2025). Agentic AI: theories and practices. Cham: Springer. ISBN 978-3-031-90025-9.
  28. "Agent Harness Guidelines Reference". NVIDIA Elements. Nvidia. Retrieved August 6, 2026.
  29. Trivedy, Vivek (March 10, 2026). "The Anatomy of an Agent Harness". LangChain. Retrieved August 6, 2026.
  30. Gullí, Antonio (October 30, 2025). Agentic Design Patterns A Hands-On Guide to Building Intelligent Systems. Springer. ISBN 9783032014023.
  31. Yang, Jianwei; Tan, Reuben; Wu, Qianhui (2025). "Magma: A Foundation Model for Multimodal AI Agents". Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. {{cite conference}}: Invalid |display-authors=3 (help)
  32. Deitke, Matt; et al. (June 2025). "Molmo and PixMo: Open Weights and Open Data for State-of-the-Art Vision-Language Models". Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 2025 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). doi:10.1109/CVPR52734.2025.00018 via IEEE Xplore.
  33. Takahashi, Dean (November 4, 2024). "Nvidia AI Blueprint makes it easy for any devs to build automated agents that analyze video". VentureBeat. Archived from the original on December 5, 2024. Retrieved June 12, 2025.
  34. Takahashi, Dean (January 7, 2025). "Nvidia launches blueprint for AI agents that can analyze video". VentureBeat. Archived from the original on April 4, 2025. Retrieved June 12, 2025.
  35. Edwards, Benj (February 20, 2025). "Microsoft's new AI agent can control software and robots". Ars Technica. Archived from the original on May 20, 2025. Retrieved June 12, 2025.
  36. "Visa wants to give artificial intelligence 'agents' your credit card". Associated Press. April 30, 2025. Archived from the original on May 1, 2025. Retrieved May 14, 2025.
  37. Holmes, Aaron (July 7, 2025). "The Seven Kinds of AI Agents". The Information. Retrieved November 9, 2025.
  38. Kachwala, Zaheer (August 18, 2025). "Nearly 90% of videogame developers use AI agents, Google study shows". Reuters. Retrieved November 9, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  39. 1 2 Knibbs, Kate (September 2, 2025). "Meet the Guys Betting Big on AI Gambling Agents". Wired. ISSN 1059-1028. Archived from the original on September 2, 2025. Retrieved November 9, 2025.
  40. 1 2 Kharif, Olga (July 29, 2025). "Cornell Tech Professor Warns AI Agents And Crypto Spell Trouble". Bloomberg News. Retrieved November 9, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  41. Herrman, John (August 22, 2025). "Why Everything's an AI 'Agent' Now". New York. Archived from the original on August 22, 2025. Retrieved November 9, 2025.
  42. 1 2 Holmes, Aaron (October 21, 2025). "A Reality Check on Agents". The Information. Retrieved November 9, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  43. Rosenbush, Steven (November 12, 2025). "Companies Begin to See a Return on AI Agents". The Wall Street Journal. ISSN 0099-9660. Retrieved November 28, 2025.{{cite news}}: CS1 maint: deprecated archival service (link)
  44. Alms, Natalie (October 23, 2025). "As agencies shed staff, industry execs predict AI agents' rise". Government Executive. Retrieved December 11, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  45. Gold, Ashley (November 21, 2025). "Exclusive: IRS deploys AI agents". Axios. Retrieved November 28, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  46. Corrigan, Phil (November 26, 2025). "Staffordshire Police to trial AI 'agents' on 101 service". BBC. Retrieved November 28, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  47. Fernandez, Demond (December 12, 2025). "Residents in 2 Detroit districts now assisted by AI agent for city service calls". WDIV. Archived from the original on December 17, 2025. Retrieved December 17, 2025.
  48. Wong, Matteo (March 10, 2025). "DOGE's Plans to Replace Humans With AI Are Already Under Way". The Atlantic. Archived from the original on December 4, 2025. Retrieved December 25, 2025.
  49. Haskins, Caroline (May 2, 2025). "A DOGE Recruiter Is Staffing a Project to Deploy AI Agents Across the US Government". Wired. ISSN 1059-1028. Archived from the original on May 3, 2025. Retrieved May 14, 2025.
  50. Aguilar, Mario (December 1, 2025). "FDA offers staff 'agentic AI' to support premarket reviews, administrative tasks". STAT. Archived from the original on December 2, 2025. Retrieved December 6, 2025.
  51. Losey, Stephen (December 9, 2025). "Pentagon taps Google Gemini, launches new site to boost AI use". Defense News. Retrieved December 11, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  52. Cox, Joseph (December 18, 2025). "ICE Contracts Company Making Bounty Hunter AI Agents". 404 Media. Retrieved December 21, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  53. Cunningham, Andrew (November 18, 2025). "Microsoft tries to head off the "novel security risks" of Windows 11 AI agents". Ars Technica. Retrieved November 28, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  54. 1 2 Yang, Zeyi (December 4, 2025). "ByteDance and DeepSeek Are Placing Very Different AI Bets". Wired. ISSN 1059-1028. Archived from the original on December 5, 2025. Retrieved December 11, 2025.
  55. Xu, Eunice (December 7, 2025). "ByteDance's agentic AI smartphone dials up a digital backlash by China's top apps". South China Morning Post. Retrieved December 11, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  56. Jiang, Ben (December 9, 2025). "Z.ai open sources AI agent tool for phones after ByteDance privacy backlash". South China Morning Post. Retrieved December 11, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  57. Roose, Kevin (February 1, 2025). "How Helpful Is Operator, OpenAI's New A.I. Agent?". The New York Times. Retrieved August 9, 2025.
  58. Warren, Tom (August 6, 2025). "Microsoft's plan to fix the web with AI has already hit an embarrassing security flaw". The Verge. Retrieved August 9, 2025.
  59. Piper, Kelsey (March 29, 2024). "AI "agents" could do real work in the real world. That might not be a good thing". Vox. Archived from the original on December 19, 2024. Retrieved January 14, 2025.
  60. 1 2 Purdy, Mark (December 12, 2024). "What Is Agentic AI, and How Will It Change Work?". Harvard Business Review. ISSN 0017-8012. Retrieved January 20, 2025.{{cite news}}: CS1 maint: deprecated archival service (link)
  61. Wright, Webb (December 12, 2024). "AI Agents with More Autonomy Than Chatbots Are Coming. Some Safety Experts Are Worried". Scientific American. Archived from the original on December 23, 2024. Retrieved January 14, 2025.
  62. Olson, Parmy (January 27, 2025). "Skip the Hype, Here's How AI 'Agents' Can Really Help". Bloomberg News. Retrieved April 2, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  63. Woodall, Tatyana (January 9, 2024). "Researchers developing AI to make the internet more accessible". Ohio State News. Archived from the original on March 28, 2025. Retrieved April 2, 2025.
  64. Mitchell, Margaret; Ghosh, Avijit; Luccioni, Sasha; Pistilli, Giada (March 24, 2025). "Why handing over total control to AI agents would be a huge mistake". MIT Technology Review. Archived from the original on March 24, 2025. Retrieved April 2, 2025.
  65. 1 2 "AI agents: Exploring the potential and the problems". BBC Online. May 30, 2025. Archived from the original on June 10, 2025. Retrieved June 12, 2025.
  66. Porter, Eduardo (October 23, 2025). "Once the AI bubble pops, we'll all suffer. Could that be better than letting it grow unabated?". The Guardian. ISSN 0261-3077. Retrieved November 9, 2025.{{cite news}}: CS1 maint: deprecated archival service (link)
  67. Chan, Alan; et al. (2023). "Harms from Increasingly Agentic Algorithmic Systems". Proceedings of the 2023 ACM Conference on Fairness, Accountability, and Transparency. 2023 ACM Conference on Fairness, Accountability, and Transparency. pp. 651–666. doi:10.1145/3593013.3594033 via ACM.
  68. Kolt, Noam (2025). "Governing AI Agents". Notre Dame Law Review. 101.
  69. Debenedetti, Edoardo; et al. (2024). "AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents". Advances in Neural Information Processing Systems. NeurIPS 2024. Vol. 37. pp. 82895–82920.
  70. Mack, Olga (March 21, 2025). "Navigating AI Vendor Contracts and the Future of Law: A Guide for Legal Tech Innovators". Stanford Law School. Retrieved June 24, 2026.
  71. "We did the math on AI's energy footprint. Here's the story you haven't heard". MIT Technology Review. May 20, 2025. Archived from the original on May 20, 2025. Retrieved June 12, 2025. We started small, as the question of how much a single query costs is vitally important to understanding the bigger picture. That's because those queries are being built into ever more applications beyond standalone chatbots: from search, to agents, to the mundane daily apps we use to track our fitness, shop online, or book a flight. The energy resources required to power this artificial-intelligence revolution are staggering, and the world's biggest tech companies have made it a top priority to harness ever more of that energy, aiming to reshape our energy grids in the process.
  72. "Inside the effort to tally AI's energy appetite". MIT Technology Review. June 3, 2025. Archived from the original on June 3, 2025. Retrieved June 12, 2025. Lots of AI companies are building reasoning models, which "think" for longer and use more energy. They're building hardware devices, perhaps like the one Jony Ive has been working on (which OpenAI just acquired for $6.5 billion), that have AI constantly humming along in the background of our conversations. They're designing agents and digital clones of us to act on our behalf. All these trends point to a more energy-intensive future (which, again, helps explain why OpenAI and others are spending such inconceivable amounts of money on energy).
  73. Levy, Steven (June 20, 2025). "What Big Tech's Band of Execs Will Do in the Army". Wired. ISSN 1059-1028. Archived from the original on June 20, 2025. Retrieved November 9, 2025.
  74. Huckins, Grace (June 12, 2025). "Are we ready to hand AI agents the keys?". MIT Technology Review. Archived from the original on June 12, 2025. Retrieved June 15, 2025.
  75. Wong, Matteo (March 14, 2025). "Was Sam Altman Right About the Job Market?". The Atlantic. Archived from the original on March 17, 2025. Retrieved April 2, 2025. In other words, flawed products won't stop tech companies' push to automate everything—the AI-saturated future will be imperfect at best, but it is coming anyway.
  76. Agarwal, Shubham. "Carnegie Mellon staffed a fake company with AI agents. It was a total disaster". Business Insider. Archived from the original on April 28, 2025. Retrieved May 15, 2025.
  77. Sabin, Sam (April 22, 2025). "Exclusive: Anthropic warns fully AI employees are a year away". Axios. Archived from the original on April 23, 2025. Retrieved May 15, 2025.
  78. Xu, Frank F.; et al. (2025). "TheAgentCompany: Benchmarking LLM Agents on Consequential Real World Tasks". Advances in Neural Information Processing Systems. Vol. 38.
  79. Claburn, Thomas (January 23, 2025). "Tool touted as 'first AI software engineer' is bad at its job, testers claim". The Register. Archived from the original on March 30, 2025. Retrieved June 15, 2025.
  80. Clark, Lindsay (June 16, 2025). "Salesforce study finds LLM agents flunk CRM and confidentiality tests". The Register. Archived from the original on June 16, 2025. Retrieved November 9, 2025.
  81. Knight, Will (October 29, 2025). "AI Agents Are Terrible Freelance Workers". Wired. ISSN 1059-1028. Retrieved August 10, 2026.
  82. Morrow, Allison (June 18, 2025). "AI warnings are the hip new way for CEOs to keep their workers afraid of losing their jobs". CNN. Archived from the original on June 18, 2025. Retrieved November 9, 2025.
  83. Hart, Jordan. "Coinbase CEO says he 'went rogue' and fired some employees who didn't adopt AI after being told to". Business Insider. Archived from the original on August 21, 2025. Retrieved November 9, 2025.
  84. Langley, Hugh. "For Googlers, the pressure is on to use AI for everything — or get left behind". Business Insider. Archived from the original on August 21, 2025. Retrieved November 9, 2025.
  85. Vaziri, Aidin. "Salesforce CEO Marc Benioff says AI has already replaced 4,000 jobs". San Francisco Chronicle. Archived from the original on November 24, 2025. Retrieved December 25, 2025.
  86. 1 2 Crosdale, Caroline (August 29, 2025). "Companies Face AI Buyer's Remorse". Global Finance Magazine. Archived from the original on September 14, 2025. Retrieved December 25, 2025.
  87. Lin, Belle (May 6, 2025). "IBM CEO Says AI Has Replaced Hundreds of Workers but Created New Programming, Sales Jobs". The Wall Street Journal. ISSN 0099-9660. Retrieved December 25, 2025.{{cite news}}: CS1 maint: deprecated archival service (link)
  88. 1 2 "FIFAI II: A Collaborative Approach to AI Threats, Opportunities, and Best Practices, Workshop 3 – AI and Financial Stability". Canadian Office of the Superintendent of Financial Institutions (OSFI). November 14, 2025. Retrieved February 2, 2026.
  89. Hornstein, Julia. "AI agents are coming to the military. VCs love it, but researchers are a bit wary". Business Insider. Archived from the original on March 12, 2025. Retrieved April 2, 2025.
  90. Regalbuto, Gabriele (July 28, 2025). "Former Army officer develops offline AI for military use as Pentagon funds tech giants". Fox Business. Archived from the original on July 28, 2025. Retrieved November 9, 2025.
  91. Rivera, Juan-Pablo; et al. (2024). "Escalation Risks from Language Models in Military and Diplomatic Decision-Making". Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency. pp. 836–898. doi:10.1145/3630106.3658942.
  92. Herrman, John (January 25, 2025). "What Are AI 'Agents' For?". Intelligencer. Archived from the original on January 25, 2025. Retrieved April 2, 2025.
  93. Herrman, John (December 6, 2025). "How AI Companies Are Simulating the Robot Takeover". Intelligencer. Retrieved December 6, 2025.
  94. Marshall, Matt (February 22, 2025). "The rise of browser-use agents: Why Convergence's Proxy is beating OpenAI's Operator". VentureBeat. Archived from the original on February 22, 2025. Retrieved April 2, 2025.
  95. Metz, Cade; Weise, Karen (October 16, 2023). "How 'A.I. Agents' That Roam the Internet Could One Day Replace Workers". The New York Times. ISSN 0362-4331. Retrieved April 2, 2025.{{cite news}}: CS1 maint: deprecated archival service (link)
  96. Stokel-Walker, Chris (June 11, 2025). "Can we stop big tech from controlling the internet with AI agents?". New Scientist. Retrieved June 12, 2025.{{cite web}}: CS1 maint: deprecated archival service (link)
  97. "Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027". Gartner. June 25, 2025. Retrieved August 10, 2026.
  98. Ming, Lee Chong. "Replit's CEO apologizes after its AI agent wiped a company's code base in a test run and lied about it". Business Insider. Archived from the original on October 7, 2025. Retrieved November 9, 2025.
  99. Edwards, Benj (July 24, 2025). "Two major AI coding tools wiped out user data after making cascading mistakes". Ars Technica. Archived from the original on July 25, 2025. Retrieved November 9, 2025.
  100. Varanasi, Lakshmi. "OpenAI cofounder Andrej Karpathy says it will take a decade before AI agents actually work". Business Insider. Archived from the original on December 13, 2025. Retrieved December 17, 2025.
  101. Guo, Taicheng; et al. (2024). "Large Language Model Based Multi-agents: A Survey of Progress and Challenges". Proceedings of the Thirty-Third International Joint Conference on Artificial Intelligence. pp. 8048–8057. doi:10.24963/ijcai.2024/890.
  102. 1 2 Goodin, Dan (November 14, 2025). "Researchers question Anthropic claim that AI-assisted attack was 90% autonomous". Ars Technica. Archived from the original on November 26, 2025. Retrieved November 28, 2025.
  103. Down, Aisha (November 14, 2025). "AI firm claims it stopped Chinese state-sponsored cyber-attack campaign". The Guardian. ISSN 0261-3077. Retrieved November 28, 2025.{{cite news}}: CS1 maint: deprecated archival service (link)
  104. Nolan, Beatrice (November 27, 2025). "Signal's president warns AI agents are an existential threat to secure messaging apps". Fortune. Retrieved November 28, 2025.{{cite web}}: CS1 maint: url-status (link)
  105. Anthropic (June 20, 2025). "Agentic misalignment: How LLMs could be insider threats". Retrieved August 10, 2026.
  106. "Threats - Microsoft Threat Modeling Tool". Microsoft Learn. Retrieved August 10, 2026.
  107. "MITRE ATLAS". MITRE. Retrieved August 10, 2026.
  108. "OWASP Top 10 for Agentic Applications for 2026". OWASP GenAI Security Project. 2026. Retrieved January 10, 2026.
  109. "Agentic AI Threat Modeling Framework: MAESTRO". Cloud Security Alliance. February 6, 2025. Retrieved August 10, 2026.