This is the 13th instalment of AI Fluency Corner, a 16-part weekly series in Business Day building one connected mental model of artificial intelligence (AI), in plain language.
Until recently AI’s signature act was the answer. It summarised the report, drafted the email, analysed the spreadsheet and waited for a person to decide what happened next. Agentic AI changes the verb. It can search records, choose a sequence of steps, call other systems, create or change information, check whether the action worked and continue towards a defined outcome.
The frontier is therefore no longer only what AI can say, but what software may be permitted to do without waiting. Last week we examined what happens when organisational knowledge enters an AI system. This week: what changes when that intelligence acquires tools, memory and authority.
From assistance to agency
An assistant predicts and generates. It waits for an instruction, processes it and returns an output for a person to use. An agent receives a goal, plans the steps, calls tools, reads the result, adjusts and continues. The assistant helps you drive; the agent has been given keys — ideally not to the entire building.
Agentic AI is not a new species of model. It is a system assembled around one: a reasoning engine, an orchestration loop, approved data, tools or application programming interfaces (APIs), and a control layer for permissions, logs and human approval.
Autonomy is not intelligence. It is permission. The same model can be a harmless drafting tool or a consequential actor, depending on the systems and authority placed around it.
This separates augmentation from automation. Augmentation improves what a person can do: an agent assembles the evidence but the person makes the decision. Automation removes the person from a step: the agent completes a bounded task itself. Confusing the two promises automation-level savings while retaining augmentation-level work — buying a dishwasher and washing every plate first.
Where agents earn their keep
Agency is a spectrum of trust: copilot, where AI drafts; supervisor, where it stages work before approval; delegate, where it acts within hard limits; and autonomous actor, where it completes a bounded process and reports afterwards.
Use agents where the destination is clear but the route varies: reconciling an audit file, tracing shipments across systems, resolving routine IT incidents or monitoring service-level breaches. Use a workflow when every step is predictable, and an assistant when the work is ambiguous, judgment-heavy or difficult to reverse.
The sharpest test is reversibility. Delegate an action only when the cost of undoing an error is lower than the time saved by automating it. A miscategorised spreadsheet row is a filter. An incorrect invoice sent to the 10 largest clients is a meeting — probably several.
Agents also accumulate risk across steps. A 10-step process that is 95% reliable at each step is only about 60% reliable end-to-end. That arithmetic is why a polished demonstration may become an expensive optimist once connected to live systems.
The more money, rights, safety or reputation an action affects, the earlier human approval should appear.
How agentic systems are assembled
Many agents now arrive inside CRM, ERP, service-desk and productivity platforms. They inherit the platform’s data, workflows and permissions, simplifying deployment but leaving less freedom over models, controls and pricing, which may be charged per action rather than per user.
More tailored agents sit in a low-code or orchestration layer connecting a chosen model to approved documents, databases and APIs. The organisation defines the goal, available tools and limits while the platform manages the loop of planning, acting and checking. This middle ground offers customisation without requiring a full engineering team.
The same architecture may run in the cloud, on-premise or across both. Cloud deployment offers rapid scale and access to leading models; on-premise deployment gives more direct control over sensitive data and infrastructure. A hybrid arrangement can keep protected records locally while using cloud capability for approved, de-identified tasks.
Fully custom agents use a selected model and orchestration framework hosted where the organisation chooses. They provide the greatest control, but make security, maintenance and evaluation a permanent internal responsibility.
Whatever the form, production readiness is established by replaying historical cases: normal work, missing information, conflicting instructions and attempts to exceed the mandate. The outcome matters more than the elegance of the explanation. A powerful model with vague permissions is simply a faster route to an unexplained result.
Authority moves, accountability does not
Section 71 of the Protection of Personal Information Act also restricts certain solely automated decisions with legal or substantial effects unless the required justification and safeguards exist.
Three controls make this practical. Guardrails define what the agent may access, spend, change and never do. An audit log reconstructs what it saw, decided and changed — a trail that cannot replay step three is a receipt, not an audit. A circuit breaker freezes errors or out-of-scope action and calls a human.
Within two years organisations will stop counting agents and start reporting the authority each holds. The meaningful measures will be the value of autonomous actions, the exception rate and the time required to reconstruct a decision.
Our task this week
Choose one recurring process — invoice approval, debtor follow-ups, customer refunds or candidate screening — and place it honestly on the spectrum: copilot, supervisor, delegate or autonomous actor.
Then answer four questions. Is the workflow mapped? Does the agent have write access only where genuinely necessary? At what point does a human inspect the work? Who is named as accountable for the outcome?
If the fourth answer is unclear, the agent has not been deployed. It has been released.
• Mafinyani is senior partner in financial engineering & artificial intelligence at specialised finance, risk and applied technology firm Intellica Analytics.
Next week: AI security, containment and resilience — how autonomous systems can be attacked, manipulated or exceed their guardrails, and why operational redundancy now matters.










Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.
Please read our Comment Policy before commenting.