6: Analysis, Automation, and Agents
- Page ID
- 67041
\( \newcommand{\vecs}[1]{\overset { \scriptstyle \rightharpoonup} {\mathbf{#1}} } \)
\( \newcommand{\vecd}[1]{\overset{-\!-\!\rightharpoonup}{\vphantom{a}\smash {#1}}} \)
\( \newcommand{\dsum}{\displaystyle\sum\limits} \)
\( \newcommand{\dint}{\displaystyle\int\limits} \)
\( \newcommand{\dlim}{\displaystyle\lim\limits} \)
\( \newcommand{\id}{\mathrm{id}}\) \( \newcommand{\Span}{\mathrm{span}}\)
( \newcommand{\kernel}{\mathrm{null}\,}\) \( \newcommand{\range}{\mathrm{range}\,}\)
\( \newcommand{\RealPart}{\mathrm{Re}}\) \( \newcommand{\ImaginaryPart}{\mathrm{Im}}\)
\( \newcommand{\Argument}{\mathrm{Arg}}\) \( \newcommand{\norm}[1]{\| #1 \|}\)
\( \newcommand{\inner}[2]{\langle #1, #2 \rangle}\)
\( \newcommand{\Span}{\mathrm{span}}\)
\( \newcommand{\id}{\mathrm{id}}\)
\( \newcommand{\Span}{\mathrm{span}}\)
\( \newcommand{\kernel}{\mathrm{null}\,}\)
\( \newcommand{\range}{\mathrm{range}\,}\)
\( \newcommand{\RealPart}{\mathrm{Re}}\)
\( \newcommand{\ImaginaryPart}{\mathrm{Im}}\)
\( \newcommand{\Argument}{\mathrm{Arg}}\)
\( \newcommand{\norm}[1]{\| #1 \|}\)
\( \newcommand{\inner}[2]{\langle #1, #2 \rangle}\)
\( \newcommand{\Span}{\mathrm{span}}\) \( \newcommand{\AA}{\unicode[.8,0]{x212B}}\)
\( \newcommand{\vectorA}[1]{\vec{#1}} % arrow\)
\( \newcommand{\vectorAt}[1]{\vec{\text{#1}}} % arrow\)
\( \newcommand{\vectorB}[1]{\overset { \scriptstyle \rightharpoonup} {\mathbf{#1}} } \)
\( \newcommand{\vectorC}[1]{\textbf{#1}} \)
\( \newcommand{\vectorD}[1]{\overrightarrow{#1}} \)
\( \newcommand{\vectorDt}[1]{\overrightarrow{\text{#1}}} \)
\( \newcommand{\vectE}[1]{\overset{-\!-\!\rightharpoonup}{\vphantom{a}\smash{\mathbf {#1}}}} \)
\( \newcommand{\vecs}[1]{\overset { \scriptstyle \rightharpoonup} {\mathbf{#1}} } \)
\(\newcommand{\longvect}{\overrightarrow}\)
\( \newcommand{\vecd}[1]{\overset{-\!-\!\rightharpoonup}{\vphantom{a}\smash {#1}}} \)
\(\newcommand{\avec}{\mathbf a}\) \(\newcommand{\bvec}{\mathbf b}\) \(\newcommand{\cvec}{\mathbf c}\) \(\newcommand{\dvec}{\mathbf d}\) \(\newcommand{\dtil}{\widetilde{\mathbf d}}\) \(\newcommand{\evec}{\mathbf e}\) \(\newcommand{\fvec}{\mathbf f}\) \(\newcommand{\nvec}{\mathbf n}\) \(\newcommand{\pvec}{\mathbf p}\) \(\newcommand{\qvec}{\mathbf q}\) \(\newcommand{\svec}{\mathbf s}\) \(\newcommand{\tvec}{\mathbf t}\) \(\newcommand{\uvec}{\mathbf u}\) \(\newcommand{\vvec}{\mathbf v}\) \(\newcommand{\wvec}{\mathbf w}\) \(\newcommand{\xvec}{\mathbf x}\) \(\newcommand{\yvec}{\mathbf y}\) \(\newcommand{\zvec}{\mathbf z}\) \(\newcommand{\rvec}{\mathbf r}\) \(\newcommand{\mvec}{\mathbf m}\) \(\newcommand{\zerovec}{\mathbf 0}\) \(\newcommand{\onevec}{\mathbf 1}\) \(\newcommand{\real}{\mathbb R}\) \(\newcommand{\twovec}[2]{\left[\begin{array}{r}#1 \\ #2 \end{array}\right]}\) \(\newcommand{\ctwovec}[2]{\left[\begin{array}{c}#1 \\ #2 \end{array}\right]}\) \(\newcommand{\threevec}[3]{\left[\begin{array}{r}#1 \\ #2 \\ #3 \end{array}\right]}\) \(\newcommand{\cthreevec}[3]{\left[\begin{array}{c}#1 \\ #2 \\ #3 \end{array}\right]}\) \(\newcommand{\fourvec}[4]{\left[\begin{array}{r}#1 \\ #2 \\ #3 \\ #4 \end{array}\right]}\) \(\newcommand{\cfourvec}[4]{\left[\begin{array}{c}#1 \\ #2 \\ #3 \\ #4 \end{array}\right]}\) \(\newcommand{\fivevec}[5]{\left[\begin{array}{r}#1 \\ #2 \\ #3 \\ #4 \\ #5 \\ \end{array}\right]}\) \(\newcommand{\cfivevec}[5]{\left[\begin{array}{c}#1 \\ #2 \\ #3 \\ #4 \\ #5 \\ \end{array}\right]}\) \(\newcommand{\mattwo}[4]{\left[\begin{array}{rr}#1 \amp #2 \\ #3 \amp #4 \\ \end{array}\right]}\) \(\newcommand{\laspan}[1]{\text{Span}\{#1\}}\) \(\newcommand{\bcal}{\cal B}\) \(\newcommand{\ccal}{\cal C}\) \(\newcommand{\scal}{\cal S}\) \(\newcommand{\wcal}{\cal W}\) \(\newcommand{\ecal}{\cal E}\) \(\newcommand{\coords}[2]{\left\{#1\right\}_{#2}}\) \(\newcommand{\gray}[1]{\color{gray}{#1}}\) \(\newcommand{\lgray}[1]{\color{lightgray}{#1}}\) \(\newcommand{\rank}{\operatorname{rank}}\) \(\newcommand{\row}{\text{Row}}\) \(\newcommand{\col}{\text{Col}}\) \(\renewcommand{\row}{\text{Row}}\) \(\newcommand{\nul}{\text{Nul}}\) \(\newcommand{\var}{\text{Var}}\) \(\newcommand{\corr}{\text{corr}}\) \(\newcommand{\len}[1]{\left|#1\right|}\) \(\newcommand{\bbar}{\overline{\bvec}}\) \(\newcommand{\bhat}{\widehat{\bvec}}\) \(\newcommand{\bperp}{\bvec^\perp}\) \(\newcommand{\xhat}{\widehat{\xvec}}\) \(\newcommand{\vhat}{\widehat{\vvec}}\) \(\newcommand{\uhat}{\widehat{\uvec}}\) \(\newcommand{\what}{\widehat{\wvec}}\) \(\newcommand{\Sighat}{\widehat{\Sigma}}\) \(\newcommand{\lt}{<}\) \(\newcommand{\gt}{>}\) \(\newcommand{\amp}{&}\) \(\definecolor{fillinmathshade}{gray}{0.9}\)Up to this point the tools in this book have produced things: text, summaries, drafts, explanations. This chapter is about systems that do things — that look something up, run a calculation, consult a calendar, or take an action on a person's behalf. This capability is qualitatively different from other AI outputs, and it changes what can go wrong. This chapter builds in three steps. It begins by separating the intelligence in these systems from the tools they operate, because conflating the two is the most common source of confusion about what an "AI agent" is. It then defines an agent precisely enough to be useful. It closes with what follows from giving a system both memory and the ability to act, which is where the question of human oversight stops being abstract.
What Makes a System an Agent?
The word "agent" is used loosely in marketing material, which makes it worth defining precisely. An agent is a model placed inside a loop with tools. It examines a goal, decides whether a tool would help, uses it, reads the result, and repeats — continuing until the goal is met or it fails. That loop is the entire difference between an agent and the ordinary assistant discussed in earlier chapters, which responds once, in text, with no means of checking anything or acting in the world. It is possible to create multiple agentic systems in parallel for different purposes and use an orchestration layer to direct agents to complete portions of a large and complex project. For example, one agent could manage data analysis, while another creates charts and graphs, while a third compiles a written report incorporating all of those elements. Four components make a system agentic. There is the model, which makes the decisions. There are standing instructions telling it which tools it may use and how. There are the tools themselves, each performing one narrow function. And there is the loop: the surrounding mechanism that actually executes each tool call and returns the result for the next round of decision-making.

Image generated by Nano Banana 2 through Google Gemini
There are two implications to the way these systems are built. First, it is important to note that the intelligence resides entirely in the model, not in the loop or the tools, which is why substituting a more capable model into the same arrangement produces better decisions within an unchanged structure. Second, an agent is not free: every pass through the loop costs time and money and introduces another opportunity for error. The arrangement earns its cost on open-ended, multi-step work that benefits from iteration, and is poor value for a single lookup or a one-shot piece of writing, where a direct request is faster and more predictable. Agentic systems function best for complex but repeatable process where the outputs can be dialed in so that the system functions consistently and dependably.
The Model and the Tools Are Different Things
When an AI assistant searches the web, checks a calendar, or performs a calculation correctly, the natural conclusion is that the assistant has become more capable. It has not. As we touched on in Chapter 3, two separate components are at work, and keeping them separate is the key to understanding the whole category. The language model's job is to interpret what is being asked, determine which tool, if any, would help, translate the request into the precise form that the tool requires, and then incorporate the tool's raw result into a readable answer. The tool's job is much narrower: perform one specific operation reliably and do nothing else. The intelligence lies in recognizing that a task should be delegated and to what — not in the delegated operation itself. This distinction is foundational for understanding agentic systems, but it also has diagnostic value as well. When an agentic system produces a bad result, the failure is locatable. Did the model misunderstand the request, select the wrong tool, or phrase the query to the tool incorrectly? Those are all failures of the model. Did the tool itself return incorrect or incomplete information? That is a failure of the agent, and no amount of better prompting will fix it. A further point corrects a common assumption. Retrieval — the ability to look something up in an external source and use it — is access, not memory. The model uses the retrieved material for the current response, and unless the system has been specifically built to store it, that material is gone afterwards. A retrieved fact can be wrong without becoming a permanent, trusted part of what the system believes. Memory is a different capability, and as the next section shows, a more consequential one.
Memory, Persistence, and Responsibility
A simple assistant that forgets everything when the window closes has a limited capacity to cause harm. A system that persists — retaining preferences, holding a calendar, acting on someone's behalf — belongs to a different category, and the difference is practical rather than philosophical. Consider what happens to an error in each case. In a system without memory, a hallucination is an isolated mistake: it can be dismissed, and the next conversation begins clean. In a system with long-term memory, the same fabricated detail may be stored and then resurface weeks later as though it were established fact, shaping later answers without anyone having verified it. The initial error is not corrected by time; it is entrenched by it. The stakes rise again once a system can act rather than only write. A misunderstood instruction that produces a poor paragraph is an inconvenience. A misunderstood instruction that books the wrong travel, sends the wrong message, or deletes the wrong file produces consequences that are financial, reputational, or irreversible. The ability to act converts an information source into something that operates in the world, and the standard of reliability required rises accordingly.
Keeping the Human in the Loop
The practical question raised by everything above is not whether to permit automation but where to place the point at which a person must approve. That placement is a judgment no tool makes for you, and it follows directly from the risk analysis in Chapter 4: the checkpoint belongs wherever the cost of being wrong is concentrated. Current agentic systems can be given approval to do almost anything automatically, but without guardrails costly mistakes can easily be made. It is best to build instructions into the loop that tell the model when to stop and ask for permission, while also enabling a second layer of controls at the system administration level. Typical controls include token budgets (without which agent costs can easily escalate), specific folder or file editing limitations, and level of permission requirements. In addition, it is important to be deliberate about what a persistent system is permitted to retain, since stored information shapes future behavior invisibly. Treat a system's recollection of earlier interactions as something that can be wrong, and verify it when it matters, rather than assuming that anything remembered has been checked. Insist on human approval for actions that are expensive, irreversible, or visible to other people — which is a narrower category than approving everything, and a far safer one than approving nothing.
Conclusion
The unifying idea of this chapter is that capability and responsibility increase together. Adding tools to a model does not make it more intelligent; it extends the reach of a system whose judgment is unchanged. Adding memory does not make it more reliable; it makes its errors more durable. Adding the ability to act does not make it more trustworthy; it raises the cost of the errors it was always capable of making. None of this is an argument against using such systems, which are genuinely useful for open-ended, multi-step work. It is an argument for designing the oversight deliberately rather than discovering afterwards that none was in place. Chapter 7 takes up the professional dimension of that responsibility: disclosing how AI was used, explaining it to people who are not technical, and applying it honestly to your own career.

