The era of Artificial Intelligence agents, not without problems
In the field of Artificial Intelligence, the tools called agents have been in the spotlight in recent months. Beyond the chatbots that answer textual questions, these agents can perform different tasks in a totally autonomous way, from organizing and responding to our mail to automating complex systems with multiple variables. But since, like chatbots, agents are based on the technology of LLM or Great Language Models and, as we know, these technologies are not perfect, the world of agents is also full of problems and doubts.
It has spread a lot and we have heard the term Agentic AI everywhere lately. This expression that would be translated into Basque as something like “agentiko AA” refers to the agents of Artificial Intelligence that are spreading a lot. But what exactly are these agents? How do they differ from a chatbot or a RAG system? We will try to answer these questions in this article.
In the previous issue we explained what the MCP protocol was: A standard protocol for AI systems to interact with the outside world. We saw how the RAG systems (in the penultimate number) used this protocol to call different sources of information in the same way. Well, beyond chatbots and RAG systems that provide textual answers to a question, AA agents are also AA systems that are based on LLM but can perform actions. The operation is as simple as we have seen for the case of the RAG: Pass information about the MCP services to the LLM, request it to respond to the user’s request, and the orchestration of these MCP services will be performed by the LLM itself, the agent being only the mediator for the function calls that it decides.
An agent, for example, can be a contributor to our city council's website but will also have the ability to make reservations for cultural or sporting events. Or an assistant who, after giving the option to inspect the catalog on the website of an online store, will also make the purchase and tell a courier company to pick it up and where to send the package.
Autonomous agents
In addition, they can have a fixed function and operate continuously autonomously activated with a certain frequency. And they can carry out these actions derived from the decisions they make without the need for supervision. For example, an agent can be prepared to look at our mail every hour and, when there are requirements of a certain type, look at the information needed to answer the question in some of the documents in the folders on our hard drive and write and send reply emails directly. Or another that keeps track of all the posts that are published on a social network about a specific topic and writes and sends response messages in the line that we want.
Although we have said that it is simple, in order to be able to do things like the ones mentioned now, an AA agent can also have other components, such as a timer, which can be activated with the indicated frequency, and a memory system to remember the above interactions.
Most agents of the type mentioned in the examples are made by companies and organizations for their own internal use, or for the attention and support of their customers. But it will also be easier to automate the tasks of our computer. We are already seeing that chatbots are integrated into operating systems that will increasingly make them agents, giving them the ability to carry out actions. There is also the OpenClaw, a free software agent created by an Austrian programmer, which can be installed on our computers.
There are also problems
But in this life, nothing is perfect and without problems, and so it happens in the case of the agents. One of the problems is the cost of agents. The LLMs that take advantage of them are usually owned by technological giants, they run on their servers, and they are paid for each order and according to the length of the order. An agent can make many calls to MCP servers in response to one of our requests and with their responses make many other and long requests to the LLM, which will result in bills being much higher than expected.
“The main risk of giving agency to LLMs does not come from the possibility of becoming too fast, conscious and evil and intentionally causing harm.”
Another problem is that the number of publications and transactions that can occur as a result of automation is excessive. For example, if more and more agents launch agents to post comments on their ideology on websites, media and social networks, too much content is generated to moderate and even read by users. On the other hand, if human inspection is to be carried out (it should be) in purchases, in important types of consultations, etc., it will be necessary to provide sufficient means for the inspection of all orders automatically managed by agents. The case of GitHub, the free software repository, is significant: new or modified software shipments have multiplied due to agents, but many are of poor quality, require a lot of review
The issue of privacy is also an issue to consider. We have said that agents use the LLM of technological giants. Well, if we use their agents, these companies can know much more about us than they have done so far and take advantage of it to make advertising even more intrusive or to make us even more dependent.
The big problem, agency
Some of the problems we have mentioned can be solved with smaller and free LLMs running on our machines and under our control, such as the Kimu developed by Orai. However, most and most of the problems (and let’s face it) come from the agency’s cause that the agents have. In the context of Artificial Intelligence, agency means the ability of a system to execute actions autonomously. It is, quite rightly, the hallmark of an agent, which differentiates it from other AI systems (chatbots, RAG systems...).
The agency is currently the primary source of AI risk, according to Yoshua Bengio et al. This Canadian researcher is considered one of the parents of AI, currently one of his main lines of research is the safety of AI, and he is one of the most significant figures who really and seriously care about this issue. in 2023 he was commissioned by 30 countries to coordinate the International AI Safety Report and to write it with 96 researchers worldwide. the first version was released in 2025. It says that an AI system needs two things to cause harm: purpose and ability.
As for the purpose, they say that some current LLMs have shown malicious or self-reserving behaviors, and they have no doubt that this will continue to increase and that they will have enough intellectual capacity to damage future systems. Therefore, among the measures they propose is not to give them the capacity to harm for the moment, that is, not to give them agencies, until more research is done to ensure that LLMs are safe and aligned with the objectives of humanity.
The well-known multinational IBM has also warned about the risks of the agency in a guide that it has published this year. They say that AA agents should be treated as an infiltrator or an internal informant and that we should analyse and manage their risks in the same way as any other internal threat. They propose a series of measures to reduce these risks and, at least in part, they are against this agency, which is the differential and advantage of the agents.

Seeing how the agents have been deployed, it's clear that they haven't been paid much attention... Well, we'll assume they haven't yet automated nuclear power plants by agent (Homer Simpson preferred!) or that the study of nuclear threats and control of arsenals have not been given to an AA agent (did we not learn anything from the WarGames film of 1983? ;-).
Not too smart, defective
However, I believe that the main danger of giving the agency to the LLM today does not come from the possibility of becoming too fast, conscious and evil, and intentionally causing harm. On the contrary, today’s artificial intelligence is often quite idiotic and makes a lot of mistakes. Therefore, the damage that agents can cause at present will be greater due to the cause of insignificance.
In fact, there have already been incidents with AA agents. For example, OpenClaw, which we mentioned earlier, has exceeded the scope of its functions and deleted user documents. Some programming assistants have deleted production databases; on the other hand, it is known that they can often generate defective code or with security holes, and as you can be told to take it directly to production or publish it without going over it... And on the net, cases are mentioned in which the user has had to pay more or in some even less than he would have to pay for the errors of the chatbots or purchasing agents.
In addition to the mistakes that LLMs themselves can make, there are also problems caused by people who take advantage of the security flaws they have. By verbally cheating on LLM, or by a slightly more sophisticated means called prompt injection, they have obtained ridiculous prices from chatbots or purchasing agents: for example, a new Chevrolet for a dollar. Or if OpenClaw is set to automatically respond to emails, confidential information can be obtained if the agent is misled.
You, reader, with your experience with ChatGPT, Gemini or similar chatbots, would you give an agent based on these LLMs the possibility not only to access the documents on your hard drive, but also to modify and delete them? Or going further, would you commission him to plan a trip, including places to visit, accommodation reservations and plane tickets? Well, if you dare, know that there are many agents like this.
Buletina
Bidali zure helbide elektronikoa eta jaso asteroko buletina zure sarrera-ontzian



