Back to blog
AI in OperationsAutomationProcessesSoftware

AI Agents in Business: What They Can Do Reliably Today

NDVDL Team9 min read
Connected systems in a company to which an AI agent is linked via interfaces

AI agents in business are language models that do not just write text but independently call tools – such as the ERP system, mailbox or calendar – and complete a task in several steps. Today they work reliably on clearly defined routines with few tools and restricted permissions. As soon as an action has external impact, human approval is needed, and every step should be logged, because agents can make mistakes.

What sets an AI agent apart from a chatbot?

A chatbot answers a question with text; an AI agent works towards a goal and takes actions to get there. A chatbot can explain how to check open orders. An AI agent queries the open orders in the ERP system, compares them with incoming delivery notes, identifies missing items and prepares a follow-up message to the supplier.

For a business, the difference has consequences. A wrong chatbot answer remains text that a person reads and discards. A wrong agent step can change a record, send an email or move an appointment. With the ability to act comes responsibility for the permissions an agent is given.

How do AI agents access tools and systems?

AI agents access tools via interfaces. Each tool is a clearly described function, such as “find customer by number”, “query open orders” or “create draft in mailbox”. The language model decides which tool to call with which inputs, receives a real result and uses it to plan the next step.

One open standard for this is MCP (Model Context Protocol). A system such as the CRM or warehouse management is made available via an MCP server that describes which queries and actions are possible. An AI application connects to it and can use those functions without a separate integration having to be programmed for each combination of model and system. MCP does not, however, govern who may access what – those rights have to be set up separately.

How MCP connects AI applications to your own systems and where the standard's limits lie is explained in our glossary.

MCP in the glossary

What can AI agents do reliably today?

AI agents are reliable today where the task is clearly described, only a few tools are involved and the result is checked before it has any external effect. Typical SME routines suited to this:

  • Gathering information from several systems, for example to prepare a customer meeting: open orders, the latest complaint, current quotes.
  • Reconciling orders, delivery notes and invoices and presenting discrepancies as a list for review.
  • Classifying incoming requests, asking for missing details and creating the case in the ticketing system.
  • Preparing reply drafts with data from the ERP system, which an employee checks and sends.
  • Producing recurring reports from several sources and pointing out anomalies.

Agents are less reliable with open-ended goals such as “take care of purchasing”, with a very large number of available tools and with long chains of steps without intermediate checks. Every additional step is another opportunity for a misinterpretation that carries over into the following steps.

Why does an AI agent need a human in the loop?

An AI agent needs a human in the loop because it is based on a language model that states wrong information just as convincingly as correct information. “Human in the loop” means the agent stops at defined points and asks for approval before doing anything irreversible: sending an email to a customer, placing an order, deleting a record or moving money.

A rule of thumb: the agent may read and create drafts on its own, but may change and send only with approval. As experience grows, individual, well-observed steps can be released. Going the other way – allowing everything first and restricting it when problems occur – ends up more expensive in day-to-day operation.

Never give an agent more rights than a new employee would have in their first week. A dedicated user account with tightly limited permissions instead of administrator access prevents a mistake from growing larger than necessary and makes it visible in the log what the agent did.

What happens when an AI agent hallucinates?

Hallucination means a language model produces a statement that sounds plausible but is not true, such as an item number that does not exist or a delivery date that appears nowhere. In a chatbot that is annoying; in an agent it can lead to a wrong action. The risk drops when the agent always retrieves facts from tools instead of formulating them itself, when tools reject invalid inputs and when results are checked before they take effect. It cannot be ruled out entirely.

Why is logging essential for AI agents?

Logging is essential for AI agents because otherwise nobody can trace why an action happened. A good log records which task was given, which tools were called with which inputs, which results came back and who granted which approval. This makes it possible to find errors, improve workflows and answer questions from customers or auditors.

When is classic automation better than an AI agent?

Classic automation is better than an AI agent when a workflow is always the same and can be fully expressed in fixed rules. If every order above a certain value goes to management for approval, or every new invoice from a specific mailbox is passed to accounting, no language model is needed. In such cases rule-based automation is cheaper to run, predictable and easier to check. Which workflows suit this approach is covered in our article on process automation for SMEs.

An AI agent makes sense where inputs are unstructured and decisions require some understanding of text: a customer enquiry in their own words, a delivery note with an unusual layout, a complaint that first has to be classified. In practice the two approaches often complement each other: the agent understands and classifies, the fixed automation carries out the actual posting or forwarding.

  • Fixed rules, consistent inputs: classic automation.
  • Unstructured text, varying wording, classification needed: AI agent with approval.
  • Both in the same workflow: agent for understanding, automation for execution.

How do you introduce an AI agent step by step?

  1. 01Choose a routine: a recurring, multi-step task that costs time today and follows clear rules.
  2. 02Check the systems: do the programs involved have interfaces, and is the data there organised and up to date?
  3. 03Scope tools narrowly: provide only the functions needed for the routine, with a dedicated, restricted user account.
  4. 04Define approval points: where does the agent stop and wait for a person?
  5. 05Set up logging before the agent sees real data for the first time.
  6. 06Test in shadow mode: the agent makes suggestions, employees work as before and compare.
  7. 07Release step by step and keep monitoring whether results still fit after changes to systems or workflows.

How does NDVDL implement AI agents in your business?

NDVDL does not start with the agent but with the workflow. We come to your premises and have you show us how the routine is handled today, which systems are involved and where decisions are made. You then receive a written proposal: which steps an agent can take over, where a person approves and which interfaces are needed.

We build the connections to the ERP, CRM, mailbox or ticketing system, via MCP where needed, give the agent only the rights it requires, and set up logging and approvals. After that we run and maintain the agent and adapt it when systems or workflows change. If a workflow is better solved with classic automation without a language model, we tell you. You have one fixed contact person for technology and workflow.

Describe a routine that is handled step by step by hand today. We will show you which steps an agent could take over and where a person should approve.

Discuss your routine

Frequently asked questions

A chatbot writes answers, an AI agent carries out steps. The agent calls tools such as a database, a mailbox or the ERP system, checks intermediate results and decides on the next step itself until a task is done.

AI agents are reliable on clearly described, recurring tasks with few tools and restricted permissions, such as gathering information from several systems, reconciling orders with delivery notes or preparing reply drafts. They become unreliable with open-ended goals, many tools and long chains of steps without intermediate checks.

MCP (Model Context Protocol) is an open standard for connecting AI applications to your own systems and data. It defines how an agent learns which queries and actions a system offers, so a separate interface is not needed for every combination of model and system. MCP does not govern who may access what; that has to be set up separately.

Yes. AI agents are based on language models that can state wrong information convincingly, and a misunderstood intermediate step affects the ones that follow. That is why restricted permissions, human approval for actions with external impact and logging of every step are needed.

Yes, for narrowly defined routines AI agents make sense in small businesses too, such as pre-sorting requests or reconciling orders, provided the systems involved have interfaces and the data is organised. An agent that independently replaces entire departments does not exist today in a reliable form.

Questions about your IT infrastructure?

Talk directly to our team — no obligation, no detours.