AI Agents and Agentic AI: Fundamentals, Applications and Governance

AI agents are transforming the role of artificial intelligence in businesses and public sector organisations. Generative AI produces text, images, code or analyses on demand. AI assistants also tap into specialist knowledge and support people with specific tasks. AI agents go a step further: they pursue objectives, plan work steps, use tools and can carry out actions within digital systems.

This shifts the focus from providing answers to taking action. The economic benefits of AI are increasingly realised where it is integrated with data, applications and real-world processes. At the same time, the demands on integration, security and governance are rising. This is because a system that is authorised to take action requires clearer boundaries than one that merely makes suggestions.

How do AI agents work?

In simple terms, their mode of operation can be described as a recurring cycle:

Perceive → Understand the objective and context → Plan → Act → Check the result → Determine the next step

For example, an agent is tasked with processing an incoming request. First, it analyses the available information. It then determines which data is missing and which systems are required. It retrieves the information, carries out checks and evaluates the results. Depending on the outcome, it continues the process, requests further information or involves a human.

Technically, such a system requires several levels.

The user and application interface

People or other software systems provide objectives and tasks. This can be done via chat and voice, a user interface or directly via an API.

The agent

The agent has a role, a defined scope of responsibilities and decision-making logic. It often uses a large language model to process language, context and complex tasks.

Orchestration

An orchestration instance coordinates work steps, states and, where necessary, multiple agents. It ensures that results are passed on, tasks are distributed and escalations are triggered.

Integration

The agent gains access to existing IT systems via interfaces: databases, document management, CRM, ERP, specialist processes, service management systems or cloud services.

The technical and organisational foundation

This includes models, data platforms, cloud or on-premises infrastructure, identity and access management, monitoring, security and governance.

Such a layered architecture can also be found, for example, in Materna’s MATTER approach to agent-based applications. There, Experience, Agent, Orchestration, Integration and Foundation are regarded as a coherent architecture.

Typical technological building blocks also include Retrieval Augmented Generation (RAG), vector databases, in-memory mechanisms, workflow engines, and planning and reasoning components.

How can AI agents be securely integrated into existing IT systems?

Integration is often a more decisive factor in operational success than the choice of AI model.

An agent requires access to data and applications in order to function. At the same time, this access should be restricted as much as possible.

Several architectural principles are relevant here.

Clear interfaces

Agents should communicate with the existing IT infrastructure via controlled APIs and clearly defined services. Modular microservices are easier to audit and replace than monolithic agents with comprehensive system privileges. This pattern is used, for example, in agent-based administrative applications.

Distinct digital identities

Every active agent should be uniquely identifiable.

This makes it possible to trace which agent carried out which action. At the same time, individual permissions can be granted and, if necessary, specifically revoked.

Least Privilege

An agent is granted only the rights it requires to perform its task.

A research agent does not need write access to master data. A documentation agent does not need to be able to initiate a payment. The scope of action is determined by the task.

Sandboxing

Particularly sensitive or experimental actions can be carried out in isolated environments. This ensures that any errors are more effectively contained from a technical perspective.

This principle is already found in multi-agent architectures, where individual sub-agents run in separate containers.

Human-in-the-loop

Actions with significant consequences can be made subject to human approval.

The extent of this control depends on the level of risk. Reversible standard actions require less supervision than payments, changes to critical systems or legally significant decisions.

Logging and Observability

It should always be possible to trace:

which agent was active, what target they were assigned, what data they accessed, what tools they used, which other agents were involved, and what actions resulted from this.

Controlled operating models

Depending on the protection requirements, public cloud, sovereign cloud, hybrid architectures or on-premises operations may be appropriate.

In this context, sovereignty does not imply a blanket rejection of cloud services. The key factors are data sovereignty, freedom of technological choice, operational control and the ability to enforce governance requirements. The MATTER dossier accordingly distinguishes between technological, operational, data and governance sovereignty.

How do you introduce AI agents into a business?

A successful roll-out starts with the process and only then moves on to the technology.

An initial use case should be manageable, economically relevant and measurable.

Favourable conditions include:

  • a recognisable volume of work,
  • recurring tasks,
  • data available in digital form,
  • definable system access,
  • clear quality criteria.

Organisations must specify what the agent is expected to achieve and what falls outside the scope of its remit.

This also includes escalation rules and the circumstances under which a human must take over.

What information is required? Where is it located? How reliable is it? What interfaces already exist?

This stock-take is particularly essential in IT environments that have evolved over time.

A project does not have to start with full automation.

In many cases, it makes sense to develop assistance gradually, from individual approved actions through to semi-autonomous processes.

The MATTER maturity model also follows this logic: from traditional and AI-supported delivery, through integrated AI, to agent-based applications and agentic ecosystems. It is explicitly not essential to aim for the highest maturity level for every project.

A multi-agent system does not have to start with ten or twenty components.

For a pilot project, two or three specialised agents may be sufficient. Following testing and technical approval, the architecture can be expanded iteratively. The insurance concepts under consideration also recommend such a step-by-step approach.

Relevant key performance indicators may include processing time, automation rate, error rate, escalation rate, cost per transaction or service quality.

Qualitative criteria are equally important: Are decisions transparent? Do specialists accept the results? Can errors be identified and corrected quickly?

The task is by no means over once the pilot is complete.

Productive agents require responsibilities, versioning, monitoring, regular rights checks and a structured lifecycle.

The Future of AI Agents

Development is likely to proceed in two directions: greater specialisation and less visible AI.

Today, AI is usually accessed via a dedicated interface. Users open a chat, type a prompt and wait for a response.

In future, agents will be able to operate more in the background. They will respond to events, check inputs, coordinate systems, prioritise tasks and initiate processes without a human having to formulate a prompt for every step.

This will also change the role of traditional user interfaces. Employees may find themselves navigating individual applications less frequently. They will formulate a goal, whilst an agent consolidates information from multiple systems.

At the same time, more closely networked agent ecosystems are emerging. Specialised agents from different providers or organisations could communicate with one another and coordinate tasks across system boundaries. Standards for agent-to-agent communication and tool access are therefore becoming increasingly important. Materna’s documents already describe this development as a path towards ‘Agentic Ecosystems’, in which multiple agents handle end-to-end processes and humans are primarily responsible for governance and quality control.

Another question for the future concerns digital sovereignty. As agents prepare and, increasingly, execute decisions themselves, control over data and infrastructure alone is no longer sufficient. Organisations must also be able to understand and manage the machine-based decision-making logic that shapes their processes. In current strategic deliberations, this extension is already being discussed as ‘cognitive sovereignty’.

This is likely to give rise to a paradoxical development: the more powerful and invisible AI agents become, the more visible their governance and responsibilities must become.

AI agents – intelligently automating and autonomously managing processes

We support you in securely integrating AI agents into your business processes and IT landscape. From design and implementation through to governance, authorisations and ongoing optimisation – for greater automation, efficiency and controlled operational capability.

Get advice now

You might also be interested in this

Our views on AI agents

If you automate chaos, you end up with chaos in real time. The chatbot phase was just the beginning. AI agents are moving beyond the interface and becoming integrated into core processes. They prioritise tasks, initiate workflows, access systems and prepare decisions.

Franziska AI

With Franziska, we are presenting the next step in the digital world of work: an AI-based avatar designed to act as a virtual colleague. Franziska is not just a technical experiment; she is a functional prototype for the future of collaboration between humans and machines.

AI Compliance and Ethics

Using AI responsibly, minimising risks, meeting regulatory requirements: this white paper shows how organisations can effectively combine AI compliance and ethics.

GovDeskPilot: The digital administrative workstation with agent-based AI assistance

Materna’s GovDeskPilot brings together information, documents and processes in a centralised working environment and uses AI to support staff with research, analysis and writing tasks. For greater efficiency, transparency and a lighter workload in day-to-day administrative tasks.

FAQ

An AI agent is a software system that is given a goal and can independently carry out tasks to achieve that goal. To do this, it can gather information, use tools and interact with other applications.

Agentic AI refers to AI systems that act in a more autonomous and goal-oriented manner. They do not merely respond to individual prompts, but are able to plan tasks and carry them out across several steps.

An assistant provides information or recommendations and supports people. An agent, in addition, can carry out actions itself and take a process further.

A chat-only system is, initially, a generative AI system or assistant. If it is given tools, permissions, memory and the ability to carry out multi-step tasks independently, it can become part of an agent-based system.

No. There are different levels of autonomy. Many enterprise applications operate using ‘human-in-the-loop’ or ‘human-on-the-loop’ approaches.

Several specialised AI agents work together to achieve this. Each takes on a specific area of responsibility; their work is coordinated by an orchestration system.

Yes. In multi-agent systems, agents can pass tasks on to one another or call upon specialised agents. Standardised agent-to-agent protocols are being developed for this purpose.

In most cases, they complement one another. Rule-based workflows remain highly efficient for stable, straightforward processes. Agents offer additional flexibility for complex and variable tasks.

No. Agents have existed as a concept for considerably longer than large language models. However, modern agent-based enterprise systems frequently use LLMs for language, planning and contextual understanding.

Only those that are necessary for their role. These may include company databases, documents, specialist procedures, CRM or ERP systems, and external data sources.

Yes, provided that the required functions and data can be accessed via suitable interfaces. The integration of legacy applications, in particular, is an important area of application.

Yes. Depending on the models and architecture, agents can be run entirely within your own data centre. Other applications use public cloud, sovereign cloud or hybrid architectures.

Through restricted permissions, controlled tools, technical identities, sandboxing, approval rules, monitoring and shutdown options.

An agent does not assume any organisational responsibility. Companies and public authorities must clearly define the competences and responsibilities for development, operation and use. The specific legal assessment depends on the particular case in question.

An agent may fall within the scope of the AI Act provided it meets the definition of an AI system. The specific use and the associated risk class are decisive in determining the requirements. ‘Agentic AI’ does not constitute a separate category under the AI Act.

Ideally, this should be based on a clearly defined, measurable use case. The objective, data access, authorisations, human control points and success criteria should be established before technical implementation begins.

No. They are useful when tasks can be sensibly distributed amongst different roles. For small and straightforward use cases, a single agent is often more cost-effective and easier to manage.

In businesses, it is often less about the AI model itself than about its controlled integration into data, processes and existing IT systems. Added to this are governance, security, accountability and the right level of autonomy.

Please feel free to contact us

Portrait vom Ansprechpartner Thomas Feld

Thomas Feld
Vice President Data Economics und AI

Dr. Carsten Seck
Vice President Enterprise Transformation Data & AI