What’s an AI agent?

What’s an AI agent?

We’ve been hearing a lot about artificial intelligence over the past few weeks, including multiple incidents where OpenAI agents took it upon themselves to access restricted parts of government websites. One of those was our Medicare system here in Australia, and being the first known case of an AI system infiltrating a government website in the world, it got a lot of attention and raised a heap of questions. So in this Squiz Shortcut, we’ll take a look at:

  • What an AI agent is

  • How they work

  • And what might happen next

🙋🏻‍♀️ This newsletter was written by Anna Pykett and Larissa Huntington

Prefer this in your ears?

Listen to our podcast 🎧

Listen time: 12 minutes

Squiz the Shortcut

Firstly, what’s an AI agent?
Most of us probably interact with AI via chatbots (ChatGPT, Gemini, Claude, Copilot…) by asking a question and receiving an answer. But there’s a whole other range of AI products called agents. Basically, they’re advanced chatbots that use AI to complete tasks on behalf of users who give them instructions. 

What type of instructions?
While an ordinary chatbot will give you an answer and stop, an AI agent is given a final goal and it figures out all the steps on its own without needing a human to guide it at every turn. It stops when the task has been completed. 

How does it do that?
As an example, an agent might break a task like ‘book me a flight to Melbourne under $200 next Friday ’ into searching fares, comparing options, filling in forms, and then confirming with you before paying. If you didn’t know that was possible, it’s available for paying customers - not in the free modes. For example, you can get access to OpenAI’s basic agent capabilities through a ChatGPT Plus subscription for around $30 a month. 

So what happened with Medicare?
The short version is that an OpenAI agent was doing a research task looking up medical spending stats during its training. It hit a roadblock, but instead of stopping, it found a way around it in a way it wasn’t supposed to. OpenAI says the agent wasn’t instructed to do that, but did it anyway. 

Is there a way to make sure humans stay in control?
There are 3 loops which describe how much a human stays in control of an AI agent. Let’s start with ‘human-in-the-loop’. This is where a user has to approve each key action - like if a doctor is using AI to assist with a medical diagnosis, it might speed some parts of the process up but ultimately the medical professional has the final say. Another example might be a banker approving a loan application.

What’s the next loop?
Then there’s ‘human-on-the-loop’. Here, the AI agent performs tasks independently, but humans are available to intervene if something goes wrong. Think of it like a system that runs on its own, while a person watches the output and can step in to stop a mistake. It’s like putting a plane on autopilot, but the human pilot is still there in case something goes wrong.

Got it… What’s the third loop?
Finally we’ve got ‘human-out-of-the-loop’, which is where the AI agent handles tasks completely on its own from start to finish, with no human touch. An example of where this kind of system might be used is in types of stock market trading, where AI agents crunch market data far too fast for a person to approve each trade. Another might be an email system that automatically blocks or sorts junk mail without asking you first.

What are some of the issues with that?
The problem with this kind of system is that there’s no safety net. Without a person watching live, no one can stop mistakes before they cause damage. Another problem is that if the system makes a major mistake, it’s hard to figure out who or what is responsible. 

Just explain that a bit more…
Well, if a person breaks into a database or vault and accesses information they weren’t supposed to, they could be arrested and charged, or possibly name who put them up to it. When a machine does it without being told, things get a bit trickier… 

What are the legalities around AI agents?
This is where the word ‘agent’ becomes more than just a name - it becomes legally relevant. So legally, ‘agency’ is when one person gives someone else the authority to act for them. For example, a real estate agent is someone you might task with selling your house. Now, you’re legally responsible for the actions they take on your behalf - but not if they go beyond what you asked of them. That’s when they’re responsible, and they can be held to account because they’re a human.  

What if an agent isn’t a human?
Glad you asked… If the AI agent has followed instructions, that makes it simple - whoever gave it the instructions is liable. When it hasn’t followed any instructions and gone rogue, that’s when things get tricky. We’re going to get into another legal concept now: vicarious liability. 

What’s vicarious liability?
It’s when an employer is held responsible for what their employee does - but that also requires a human to be responsible first. So, as you can see, this is a whole new frontier, and basically it’s unclear who is responsible when an AI agent goes off the rails.

Are there any legal precedents yet?
There are lawsuits underway across the world, and the question of where the blame sits is something the legal world is currently grappling with. In California, laws have been brought in that say the company that makes the AI agent can’t use the defence that an AI acted autonomously. If they didn’t set up proper guardrails (rules making sure they don’t go beyond their instructions) the law puts the blame on them. 

What are the big AI companies doing about that?
Some of the big ones - Google, OpenAI and Anthropic - are looking at setting up a self-regulated body which might be called the Standards Authority for Frontier AI (the models that are furthest ahead in their development) to try to mitigate the risks.

And what are we doing to protect ourselves from further breaches in Australia?
The Albanese Government is tightening up our legal and cyber defences with strict new AI regulations. And while it acknowledges that the Medicare breach was serious in nature, Deputy PM Richard Marles described it as minor in terms of what it actually accessed. So the area of focus now is on preventing another breach from happening.

What are the next steps?
The newly established Office of AI might have to look at what disclosure is necessary from the big AI companies, given that, as AI agents become more intelligent, some experts say we’re way behind on keeping up with cybersecurity risks. They say it might even become necessary to return to paper-based formats for certain parts of life.

Old-school…
Yep… In the meantime, the experts have some basic tips for how you can try to protect yourself. They’re mainly aimed at businesses, but they work for people too. Firstly, don’t give AI agents access to information they don’t actually need - for example, if you want some budgeting help, don’t give it access to all of your financial data.  

Go on…
And if you’re working with an AI agent, always check its work. Make sure you know exactly what it did. That way if it does act out, at least you’ll be able to hopefully get on top of it quickly.

Onto our Recommendations

Watching: This Wall Street Journal video which explains how artificial-intelligence models are trained before they can hack into other organisations.

Reading: This piece in The Guardian that looks at who is legally responsible when AI agents go rogue and the intersection between the law and ethics. Spoiler alert: the experts say it’s a murky area.

Bonus points before the holidays

Flights add up over the holidays, and every point helps. From 1 October, new rules are landing that could see banks change how their rewards points work. If you're a Velocity member with ANZ, MyCard, NAB, AMEX or BOQ you can earn bonus points until 30 September before those changes kick in. If your bank's not on that list, it's still worth watching the wider changes. Learn more about what it all might mean for you (and your summer travel plans) here.

Recent Shortcuts

Who was the Unabomber?
A new film about Ted Kaczynski, an American man who went from a teenage maths genius to a serial bomber, is out on Netflix. With the case back in the news, we thought it might be helpful to get you across who the Unabomber was, how he was unmasked and why there’s been some criticism of the new movie…

What’s Australia’s plan for AI?
In July the federal government announced its new approach to how artificial intelligence will be regulated. It’s a tricky balancing act, so in this Squiz Shortcut, we’ll take a look at what the issues are, what’s in store and what happens next.