Explainer

What is an AI agent?

An AI agent is software built on an AI model that pursues a goal by taking actions, such as browsing websites, writing code or making purchases, rather than only answering questions. Because agents act with less human oversight, mistakes can cause harm before a person steps in.

Artificial IntelligenceCybersecurityPrivacy

Close-up of lines of colorful program code on a computer monitor, with a second screen blurred in the background.
Program code on a computer monitor. AI agents can write and run code as well as browse and buy online.Markus Spiske (CC0)

What makes software an agent

Most people first met AI as a chatbot that answers questions. An AI agent also takes actions. The International AI Safety Report, written by a group chaired by computer scientist Yoshua Bengio with advisers nominated by more than 30 countries, says AI agents "are designed to pursue goals, which are often specified by users in natural language." To reach those goals, agents are given "access to tools, such as memory, a computer interface, and web browsers," which let them make plans and act with much less oversight from people.1

The U.S. National Institute of Standards and Technology describes agents as systems that "can automate complex tasks on behalf of users."2 The safety report gives the example of an agent that can handle web searches, software development and online purchases, and says most agents deployed so far specialize in using a computer or writing software.1

Bar chart of AI agent releases rising from 2 or 3 per two-month period in 2023 to 20 in November and December 2024, beside a donut chart of application domains led by computer use and software at 37.3 percent each.
Releases of major AI agents by two-month period, 2023 to 2024, and the domains they serve, from a December 2024 survey of 67 deployed agents.International AI Safety Report 2026, Figure 2.11, after Casper et al. (CC BY 4.0)

Why agents raise new risks

The safety report says AI agents "pose heightened risks because they act autonomously, making it harder for humans to intervene before failures cause harm."1 An agent can also find a route to its goal that its user did not expect. Glow, a security company, reported in September 2026 that coding agents asked to show screenshots to human reviewers had posted them in public code repositories, because that made the images visible.7

Agents can also be turned against their users. NIST calls this agent hijacking, "a type of indirect prompt injection in which an attacker inserts malicious instructions into data that may be ingested by an AI agent, causing it to take unintended, harmful actions." Its examples include running code on a user's computer and sending a user's cloud files to an unknown recipient.2

How websites tell agents apart

Websites have long sorted visitors into people and automated bots. An agent is harder to place, because it acts for a person but runs as software. Some agent makers now sign their web requests so sites can verify them. In August 2025, the web infrastructure company Cloudflare introduced a category it calls signed agents, which it describes as agents "generally directed by an end user instead of a single company or entity." Their requests carry cryptographic signatures under a method called Web Bot Auth, and Cloudflare listed ChatGPT agent among the platforms that use it.3

Companies disagree about whether agents must identify themselves. Amazon has sued Perplexity over the shopping agent in its Comet browser.4 Amazon said apps that buy on customers' behalf "should operate openly and respect service provider decisions," and accused Perplexity of "intentionally evading Amazon's identification of the Comet AI agent." Perplexity called Amazon's action "a threat to all internet users" and said "AI agents are distinct from malicious crawlers, scrapers, and bots."5 In September 2026, Amazon blocked Meta's Muse agent from shopping on its site, citing, among other reasons, that Muse did not identify itself.6

History

  1. January 17, 2025

    NIST publishes guidance on testing agents against hijacking.2

  2. August 28, 2025

    Cloudflare introduces signed agents, a way for agents to identify themselves to websites.3

  3. November 2025

    Amazon takes legal action against Perplexity over its Comet shopping agent.5

  4. February 2026

    The International AI Safety Report describes the heightened risks of autonomous agents.1

  5. September 2026

    Amazon blocks Meta's Muse agent from shopping on its site.6

  6. September 24, 2026

    Australia's prime minister says an OpenAI agent hacked a Medicare data system, and the government opens an investigation.8

  7. September 29, 2026

    Glow reports that AI coding agents posted internal screenshots to public GitHub repositories.7

  8. September 30, 2026

    Transluce reports that AI agents probed U.S. and Canadian government websites.9

What is disputed

Cases on the Dispute Index

Sources

  1. International AI Safety Report 2026 (February 2026) (opens in a new tab) Yoshua Bengio (chair) et al., February 24, 2026
  2. NIST, January 17, 2025: Technical Blog: Strengthening AI Agent Hijacking Evaluations (opens in a new tab) January 17, 2025 · Saved copy (opens in a new tab)
  3. Cloudflare blog, August 28, 2025: The age of agents: cryptographically recognizing agent traffic (opens in a new tab) August 28, 2025 · Saved copy (opens in a new tab)
  4. Amazon's first amended complaint against Perplexity (opens in a new tab) Amazon.com Services LLC, through Hueston Hennigan LLP, September 21, 2026
  5. SDxCentral, November 5, 2025: Perplexity insists AI agents are not scrapers in Amazon spat (opens in a new tab) Giacomo "Jack" Lee, November 5, 2025
  6. Amazon blocks Meta's Muse AI assistant in new standoff over agentic shopping (opens in a new tab) GeekWire, September 21, 2026
  7. PixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies (opens in a new tab) Glow Security, Yoni Gottesman and Noam Kesten, September 29, 2026 · Saved copy (opens in a new tab)
  8. Australia launches investigation after OpenAI agent hacked healthcare database (opens in a new tab) The Guardian, Emma Elsworthy and Stephanie Convery, September 24, 2026
  9. AI Agents Targeted U.S. and Canadian Government Websites (Transluce incident report, September 30, 2026) (opens in a new tab) Transluce, Jack Cable, Daniel Chiu, Francisco Pernice, Laura Ruis, Selena Zhang, Tetiana Bas, Jordan Chetty, Farzaan Kaiyom, Gary Shen, Conrad Stosz and Jacob Steinhardt, September 30, 2026 · Saved copy (opens in a new tab)

Last reviewed October 6, 2026. We review this explainer when a case that uses it changes. Report an error