Contents
Agentic AI

AI agent, assistant, chatbot: what are the differences

The three words are used interchangeably in sales pitches. Yet they describe three very different levels of autonomy, and therefore three levels of risk. The criterion that separates them is simple: who decides what happens next, and who acts.

Published September 22, 2026

The criterion that separates them: who decides what comes next

A chatbot, an assistant and an agent can all look like a chat window. The interface tells you nothing about what happens behind it. Two questions are enough to tell them apart: who decides the next step, and who produces an effect in the information system.

Chatbot

The path is written in advance. The software recognises an intent and follows the planned script.

AI assistant

A language model answers freely. The person reads, judges and acts themselves.

AI agent

The model chooses which tools to call and chains them. It produces effects in your applications itself.

Three levels of autonomy. The interface can be identical; the risk is not.

The boundaries are not watertight. A modern chatbot often uses a language model to understand the question, and an assistant can call a search engine. But the criterion still holds: as long as a script or a person decides the action, you are not in agentic territory.

The chatbot: a planned path

A classic chatbot relies on a dialogue tree. It recognises an intent (“track my order”, “reset my password”), asks the planned questions and returns an answer or triggers a predefined operation. A developer wrote every branch.

Its strengths come from that rigidity. It is predictable, testable end to end, and does nothing that was not planned. For a high-volume path with few variations, such as booking an appointment or tracking a case, it is often the right answer.

Its limit is the same: anything outside the script fails. A question phrased differently, a combined case, an unexpected request all end in “I didn't understand”. Adding a language model to recognise intents better improves understanding without changing the nature of the tool: the actions remain those of the script.

The AI assistant: the model answers, the person acts

An assistant relies on a language model that answers freely: it summarises a document, drafts a reply, explains a procedure, searches a document base. There is no script, which is what makes it useful on varied requests.

But it does nothing in the user's place. The draft email stays a draft until the person copies and sends it. The summary of a contract does not change the contract. The human is both the filter and the executor: they read, correct, decide, then act in their usual tools.

An assistant's risks are therefore mostly information risks: a plausible but wrong answer, a badly cited source, confidential data sent to a model provider, an answer based on a document the user should not have seen. These are serious issues, but no write happens in the information system without a human gesture.

The AI agent: the model chooses and chains its tools

An agent goes one step further: it is given a goal and decides for itself how to reach it. It has tools (read the mailbox, query the CRM, open a ticket, update a document) and a working loop.

  1. Understand the goal“Handle the refund requests received this morning.”
  2. Pick a toolThe agent decides to read the dedicated inbox.
  3. Read the resultIt finds three requests and their attachments.
  4. RepeatIt checks the customer record, verifies the contract, drafts a reply, proposes an accounting entry.
  5. StopWhen the goal is reached, or when an action requires human confirmation.
An agent's loop: the model, not a script, chooses each step.

This is what lets an agent handle tasks no script would have planned. It is also what changes the nature of the risk. The agent produces effects: a message sent, a record changed, a file deleted. And it can be influenced by what it reads: an email containing a hidden instruction can divert the rest of the loop.

The answer is not to restrain the agent until it becomes an assistant again, but to frame it: permissions limited to the user's own, carefully chosen tools, and human approval on actions that commit. These requirements are detailed in the guide enterprise agentic AI platform.

The three compared, criterion by criterion

CriterionChatbotAI assistantAI agent
Who decides the next stepThe pre-written scriptThe personThe model, within a framework
Who acts in the toolsThe script, on planned operationsThe personThe agent, through connectors
Unexpected requestsFailureHandled wellHandled well
PredictabilityFullVariable answersVariable answers and actions
Main riskUser frustrationWrong or exposed informationWrong or hijacked action
Key safeguardScript testingSources, document permissionsPermissions, human approval, audit trail

The last row is the most useful. Choosing an agent means accepting the safeguards in the right-hand column. A project that buys an agent with an assistant's safeguards takes a risk it has not measured.

How to choose, and mistakes to avoid

Start from the task, not the technology:

  • Repetitive path, few variants, high volume: a chatbot, possibly helped by a model to recognise intents.
  • Need to read, summarise, draft or search, with a person deciding afterwards: an assistant, connected to your documents with their access rights.
  • Multi-step task that crosses several tools: an agent, with the framework that comes with it.

Calling an assistant an “agent”

Many so-called agentic offers are assistants with web search. That is not a flaw, but it should be clear: you are not buying the same thing, and you will not get the same gains.

Giving an agent tools it does not need

An agent that drafts customer replies does not need to be able to delete records. Every tool added widens what an error or a hijack can cause.

Judging on a successful demo

An agent chains ten steps flawlessly in front of an audience. Measure it on your real cases, including ambiguous requests and badly formed documents, before trusting it with a task.

Frequently asked questions

Is ChatGPT an agent or an assistant?

In its usual conversational use, it is an assistant: it answers and the person acts. Vendors of these tools add modes able to chain actions, which then fall into agentic territory. The criterion stays the same: who decides the next action, and who carries it out.

Can an AI agent replace an existing chatbot?

Not necessarily. On a stable, regulated path, a predictable chatbot is often still preferable. An agent adds value when requests are varied and require combining several sources or several tools.

Is an agent necessarily autonomous end to end?

No. A well-designed agent works alone on reading and preparation, then stops and asks for confirmation before actions that write, send or delete. Autonomy is set action by action.

Where SmartAGT fits

SmartAGT is a platform for governed AI agents, deployed on-premise. Agents read, search and draft freely from your documents and connected tools, with the permissions of the connected account.

Any write or execute action is paused deterministically until a person confirms or rejects it, and the decision is logged. The platform overview is on the home page.

SOVEREIGN BY ARCHITECTURE

A question these guides
do not settle?