From Chatbots to AI Agents: Can Businesses Keep Humans in Control?

image_pdfimage_print

AI is advancing beyond answering questions. There is a new class of systems that is called AI agents, which can leverage software tools to organize information and perform tasks across different apps. This trend could also alter the way people work but it also brings up a practical issue: what level of authority should be given to a machine? What is important is whether the organizations could make these systems useful without making them too obscure, too extensive and too accountable. As the technology advances, it will be as much about the reliability of its performance and supervision as it will be about technical ability. The debate has gained urgency after recent warnings from tech companies. With the advent of more sophisticated AI agents, interest in increased protections and regulation grows, the Associated Press reports. But the chances or when the worst will happen are not agreed upon by experts. Every forecast of machines out of human control should be considered distinct from actual difficulties. If a company is thinking about adopting, the first thing they must know is what an agent can get, what it can alter and how others can get in the way when something goes awry.

Typically, a chatbot will reply to a request by sending text. An agent can take further steps towards completing a goal. According to anthropic, an agent is a system that plans, acts, observes results and adapts. For instance, an assistant can collect documents, process the information in the documents, and then write a report using multiple tools. This enables opportunities to eliminate repetitive work. But, once you have a set of actions in place you also have more for someone to get wrong. A wrong first choice can affect the subsequent decisions, especially in case of a general order with no limits.

Make sure to think about a customer-service agent who is asked to solve a problem. May retrieve an order, review information relating to the delivery and draft a response. These measures may help prevent a worker from wasting time. When you cancel a subscription or refund, you have a new level of responsibility. The system would have to be aware of company rules and exceptions. This example demonstrates the need to evaluate automation on an individual task basis. Having a system that creates useful summaries does not necessarily mean that the system can make useful decisions that impact customers, finances or contract terms without endangering customers, finances or contract terms. The best business argument is therefore one that has measurable outcomes. The outcome of a successful pilot should be to determine if there is any benefit in accuracy, fewer delays, and less overall effort needed to complete work. Counting what is finished can give the wrong impression. Staff might have to work longer periods of time to correct outputs or investigate unexpected actions. Whole process before and after adoption, including supervision and recovery costs should be compared. The real issue is whether the technology can reliably offer an improvement under normal use and not just during a specific demonstration.

Security is another problem that has to be addressed. Agents can get instructions that are embedded in emails, websites or documents. These attacks, called prompt injections, try to deflect the system from its permitted job. Malicious content might attempt to get an agent to reveal information or to perform an unwanted action, Anthropic says. The situation is particularly grim if the system has access to private data and external communication instruments. Reading a document ought not to confer authority upon the document. It is important to distinguish information from authentic commands, but protection does not guarantee complete protection is provided. Limit access is one possible solution. Microsoft is urging agents to be distinct, have specific permissions, and have ongoing monitoring. These controls assist organisations to track activity and to limit the actions that can be performed by each system. The agent preparing a sales summary shouldn’t need to be given permission to manipulate payroll data. Access should be appropriate for the particular task. The same also applies when the agent acts in an unexpected way, because their side effects are restricted. Clear instructions are helpful, but technical restrictions offer protection in case instructions are misinterpreted, disregarded or misled by hostile information.

There has to be some significant human oversight. If each small change has to be approved by a staff member, it may negate a lot of the efficiency gain. Giving the go ahead to an intricate action with inadequate context does not offer a lot of protection either. A good design reviews at relevant times and displays information to make decisions. It is important for a reviewer to understand what is proposed and what the likely impacts will be before a sensitive message is sent, important records changed, or resources committed. Organizations must also have a process in place to stop operations and investigate incidents. Workflow should include supervision from the outset. When more than one tool and supplier is involved, accountability is a crucial element. When an agent is not successful, the organization must determine if it is because of the instructions provided, the information it received, the software it uses or its model behavior. If you don’t have evidence of what you’ve done, then investigation is a challenge. This responsibility should therefore be given prior to deployment. The job can be specified by the business owner, boundaries can be enforced by technical teams, and failures can be reported by employees. These may vary within organizations but someone has to be left in charge of the service provided. When buying an AI product, no one takes responsibility for the effects of their operation.

This impact on employees should not be overlooked. Routine administration could be eliminated but new work might occur with review, exception handling and quality assurance. Training should include what can and can’t be done. Staff should be aware of uncertain outputs and when it requires escalation. Employees who have intimate knowledge of the process can also spot issues that technical teams may have missed. The greater the involvement of workers in developing workflow and evaluation criteria, the more likely that the adoption process will be successful. It’s easy to overlook these practical details when introducing automation or making it a part of your business process, which could result in replacing a familiar process with a faster but more difficult-to-manage one. While AI agents can certainly be a big step forward in workplace technology, increased autonomy demands increased reliability. There should be clear tasks at the initiation of business that can be judged based on real results and expanded authority should be given step by step. However, considerable failures can be prevented and there may be some support for adoption of the security controls, useful human review, and clear responsibility. There is a simple lesson to be learned from the latest safety debate: capability isn’t enough. The most useful systems will be those that will enable individuals to finish tasks and enable organisations to comprehend, regulate and amend their behavior. Human control is a guiding principle in the process of change, not a topic that is tackled after the event.

image_pdfimage_print

Author

Saddam Tahir

Research Associate, Pakistan House

Check author posts