The difference between a chatbot and an agent is the ability to act. An agent can search, read a database, send an email or call an API, look at what came back, and decide what to do next. That loop is what makes agents useful for work that has no fixed shape, and it is also what makes them a different security proposition entirely.
Every tool an agent can reach is reachable by anyone who can influence its input, which for a customer-facing agent means the public. The design question is not whether the model can be tricked — assume it can — but what the worst outcome is when it is. An agent that can read a knowledge base is a small problem. The same agent with write access to a CRM and an outbound mail API is a different one.
Related terms
Prompt injection
An attack where text the model reads as data is treated by it as instructions instead.
MCP (Model Context Protocol)
An open protocol for exposing tools and data to a model, so one integration works with any client that speaks it.
Tool calling
The mechanism by which a model asks the surrounding application to run a named function, and gets the result back as text.
OWASP LLM Top 10
A community list of the most significant security risks specific to applications built on large language models.
The bench this belongs to
AI automationThe repetitive half of your week, handed to software that does not get bored. Inbox triage, follow-ups, reporting, data entry between tools that were never meant to talk.
