Agentic AI
AI systems that plan and carry out multi-step work using tools, rather than only producing text in response to a prompt.
The distinguishing feature is tool use across multiple steps. A chatbot answers; an agent decides what to do, does it, observes what happened, and continues. In an audit context that means the difference between “summarise this control description” and “pull every privileged-access change in the period, match each to an approved ticket, and list the ones without”.
The term is heavily oversold, so it is worth naming the honest limitations. Agents are unreliable in proportion to how ambiguous the task is; they are excellent at mechanical work with a clear definition of done and poor at work requiring judgment about materiality or intent. They fail in ways that look confident. And they are only as good as their access — an agent with no route into the system of record is a very expensive way to reformat a spreadsheet.
Which is why the useful question about any agentic audit claim is not “how smart is the model” but “what can it actually reach, and who approves what it concludes”.
Related