The chatbot phase was just the beginning
The first wave of AI was visible. People wrote prompts, had texts generated, presentations summarised and documents analysed. AI appeared as a tool: productive, accessible, impressive, but mostly still reactive. People asked questions; AI provided answers.
This phase is coming to an end. The next wave of AI operates in the background. It coordinates systems, prioritises tasks, prepares workflows, retrieves data, triggers decisions and dynamically adapts process chains.
The question of ‘where an organisation uses AI’ is no longer sufficient. What will be crucial is how an organisation remains controllable when processes begin to organise themselves.
AI agents pursue objectives, utilise tools to do so, interact with external systems and carry out tasks independently. Assistants become active participants, making AI an integral part of the organisational logic.
AI agents can function well without humans
The appeal of Agentic AI lies in the fact that AI agents do not wait for humans at every step. They plan, decide, prioritise and act within their objectives. That is precisely what makes them productive. That is precisely what makes them risky.
A traditional AI assistant helps with a task. It is familiar with calendars, emails, documents, tickets, contracts, customer data, process steps and system access. It recognises patterns, draws conclusions and selects the next step.
If the objective is to cut costs, reduce response times or increase sales, an agent can become very consistent. Perhaps too consistent. An agent optimising travel arrangements might book a flight with a ten-minute layover. An agent reducing stock levels might, without realising it, jeopardise delivery capacity. An agent sorting out operational disruptions might classify a weak signal as unimportant, even though that is where the real crisis is beginning.
The problem does not lie in ill will. It lies in blind determination. An agent does whatever the objective, the data set, their authorisations and the environment allow. The more access they are given, the greater their scope for action becomes. The poorer the safeguards, the riskier their efficiency becomes.
This is how the dystopian scenario unfolds: the agent achieves its objective. Yet, along the way, nobody understands sufficiently which shortcuts it has taken.
The next wave of AI is disappearing from the interface
Many companies still think of AI in terms of applications: a chatbot for customer service, a co-pilot for Office documents, a knowledge assistant for specialist departments. But this perspective falls short.
The most successful AI of the coming years will operate in areas where it is no longer explicitly called upon. It recognises status changes, evaluates information, prioritises tickets, checks incoming data and initiates workflows. Ideally, it solves problems before they arise.
This creates a new visibility challenge for businesses. What was previously managed via websites, portals, forms and user interfaces may in future be handled by agents. Customers no longer visit a website. They instruct their agent. Employees no longer search through systems. They have results prepared for them. Specialist departments no longer navigate through applications.
Autonomous organisations are changing business logic
Today, many processes run in a static manner: form, ticket, approval, departmental procedure, decision. In future, processes may emerge dynamically. A system recognises the context, retrieves data, evaluates rules, triggers subsequent steps and involves people where approval, liability or specialist judgement is required.
In public administration, an application could in future be generated from existing data, register information and situational requirements. In the insurance sector, AI agents could consolidate claims information, contract data, regulatory requirements and customer communications. In industry, they could coordinate maintenance, spare parts planning, supply chain information and production control.
This can make organisations faster and more resilient. However, it can also exacerbate existing weaknesses. Many companies have only a superficial understanding of their processes. They have ad hoc workflows, data silos, shadow IT, outdated business procedures, Excel workarounds and tacit knowledge that is not documented anywhere.
Anyone who deploys AI agents in such an environment will not turn disorganisation into digital excellence. They will simply make the disorganisation worse. After all, a Formula 1 engine does not turn a shopping trolley into a racing car.
Agents in KRITIS make autonomy a resilience issue
Agentic AI becomes particularly critical in KRITIS environments. In these settings, digital decisions quickly have an impact beyond the organisation itself: energy, water, healthcare, transport, IT, telecommunications, finance or public utilities.
As soon as AI agents are deployed there, autonomy itself becomes a risk and resilience issue. An agent that prioritises faults, interacts with systems or prepares incident response needs more than just a high-quality model. It requires restricted access rights, a clear identity, logging, escalation rules and the ability for human intervention.
An incorrectly prioritised alert, a system action that goes too far, or a recommendation that cannot be traced can trigger a cascade of effects. Then automation becomes an operational risk.
No one can seriously want autonomous agents in critical infrastructure if permissions, data access and escalation paths remain unclear. Agents are useful where they consolidate situational awareness, recognise patterns, suggest priorities and relieve the burden on specialist staff. Decision-making authority must remain controllable in critical situations.
Particularly in KRITIS, Agentic AI must therefore not be allowed to develop as an experiment in shadow processes. It belongs within controlled architectures featuring human-in-the-loop and human-on-the-loop mechanisms, the principle of least privilege, audit-proof documentation and strict stop signals.
Agents need pathways, not just goals
AI agents raise a new question of identity. Until now, the focus has primarily been on people, roles, permissions and technical accounts. Now, digital agents are joining the picture, carrying out tasks, processing data and interacting with systems.
So it must be clear: Which agents exist? Who do they belong to? What objectives do they pursue? What data are they permitted to access? What actions are they permitted to carry out? Which systems are they permitted to interact with? How are decisions documented? Who can stop them?
Without these answers, ‘shadow AI’ emerges at the process level. Agents then operate with overly broad permissions, unclear accountability and a lack of traceability. This is risky because agents can initiate transactions, amend tickets, start workflows, prepare decisions, trigger customer communications or transfer data to other systems.
An agent without a clear identity is not a productivity tool. It is a risk with API access.
Conclusion: AI agents are a leadership issue
When you consider this, it quickly becomes clear: Agentic AI is not an IT issue. AI agents must be treated like very hard-working, very curious and very unscrupulous employees who cannot be sued by anyone. This means they belong on the agenda of senior management, the CIO, the CISO, line organisations and the legal department.
Management must decide what level of autonomy is desired. Which processes are agent-ready? What data may be used? Which decisions remain with humans? What risks are acceptable? What interventions must be possible at all times?
Organisations need partners who approach AI in conjunction with processes, data, governance, security, regulation and operating models. The productive deployment of AI agents begins with the question of whether an organisation is mature enough to allow autonomy.