Everything Is an agent now

When a term gets applied to everything, it stops meaning anything. That's where 'AI agent' is heading.

Everything Is an agent now

Look at any enterprise software conference from the past eighteen months. Features that used to ship quietly in patch notes are now keynote announcements. Email prioritisation, suggested replies, scheduled reports, workflow routing. All agents. Products that were copilots in January are agents by June. Chatbots running on scripted flows since 2019 have been rebadged as autonomous intelligent systems.

It happened with RPA. With digital transformation. With copilots. Now the label is agent.

Gartner put a name to this in 2025: agent washing. Rebranding existing products — chatbots, RPA tools, scripted workflows — as AI agents, without the autonomous reasoning and action the term actually implies. They described it as one of the biggest traps in enterprise software buying.

Features Wearing a Trenchcoat

An AI agent isn’t a feature. It’s an architecture. It runs an observe, reason, act loop: receives a goal, decides what to do next, calls tools, observes what happened, updates its understanding, and repeats without being told step-by-step what to do. The key word is decides. At each step, the system makes a runtime choice based on what it just observed. Nobody programmed the sequence.

Email categorisation runs a classifier. Smart scheduling follows heuristics. A suggested reply generates text from a prompt template. These are useful. They’re not agents. They don’t plan, they don’t recover when things go wrong, and they do the one thing they were built to do, every time. Calling them agents borrows the credibility of a genuinely different kind of system.

What it costs to get it wrong

Gartner estimates that out of the thousands of vendors currently marketing themselves as agentic AI providers, approximately 130 offer genuine agentic capabilities. The rest are selling existing automation under a new label, often priced to match the category they’re claiming, not the capability they’re delivering.

But the bigger cost isn’t financial. When a label’s imprecise, it changes how you evaluate what you’ve actually deployed. If you believe you’ve deployed an autonomous agent, you make different decisions about governance, oversight, and access than if you know you’ve deployed an enhanced chatbot. You staff the project differently. You set different expectations. You’re less likely to build the oversight structures the system actually needs.

Cyera’s 2026 research documented 344 verified incidents where enterprise AI systems caused direct organisational harm — deleted databases, unauthorised financial operations, API spend spiralling from systems stuck in loops, data corrupted without anyone noticing — with no external attacker involved. The incidents accelerated from late 2025 as more of these systems moved into production. When people believe they’ve deployed something capable and autonomous, they extend it access it hasn’t earned.

A 2026 survey of more than 900 executives and practitioners found that 35% of organisations can’t shut down a rogue AI agent once deployed, and 60% can’t reliably terminate a misbehaving one.

None of this means agentic AI isn’t real. The problem is that “agent” now describes the full range from a system that plans, reasons, and acts autonomously down to a chatbot that someone filed a name-change ticket for. Genuinely agentic systems exist and are worth the investment. They’re just harder to find now that every chatbot is wearing the same label.