News & perspectives
AI strategy — min read

The best enterprise AI agent may not be an agent at all.

The useful choice for a UK organisation is the smallest system that can deliver an outcome it can explain, operate and govern. Sometimes that system will need to act; often it will serve people better by helping them decide.

A business leader presenting to colleagues in a meeting.

An employee asks whether a hotel charge is covered by the company’s expenses policy. A search tool might find the relevant clause. An AI assistant might explain how it applies to the circumstances and cite the policy. An agent could go further: inspect the claim, find a missing receipt, amend the record and submit it.

All three could be described as AI-enabled help with expenses. They are different systems with different consequences. The question is which part of the work needs intelligence and which part needs a rule, a reliable connection to a system or a person’s decision. “Build an agent” does not answer it.

Choose the job before the architecture

Begin with the outcome. Is the problem that employees cannot find the policy? That claims are missing required information? Or that reviewers spend too long resolving exceptions? Each suggests a different response.

If the rules are clear and the task is simply to flag a missing receipt, conventional software may be enough. If people need help interpreting a lengthy policy, a document assistant that retrieves the current version and shows its source may be useful. If a process requires several authorised steps across applications, a bounded agent may earn its place. Multiple agents coordinating with one another are another design choice, justified only if they improve the task under test.

The UK Government’s AI Playbook tells public-sector teams to start with business and user needs and to consider established technology where it can solve the problem. That is not a restriction on ambition. It is a way to make sure extra complexity has a purpose.

This choice should be made against the organisation’s real circumstances. A policy may have regional variations. A claim may refer to an exception approved by a manager. The expenses system may show a payment status that has changed since the last document was indexed. A tool can retrieve an old clause accurately and still mislead its user. The design needs to identify which source governs, when it was updated and what the system should do when the evidence conflicts.

Count the cost of authority

Finding a clause, drafting an explanation and changing a financial record are different levels of authority. The more a system can do, the more clearly its access, operating limits and recovery steps need to be defined.

For the expenses example, an assistant might identify a missing receipt and prepare a proposed message. An agent that attaches a receipt or edits a claim needs permission to reach the relevant records. Submitting or approving payment raises a further question: who remains accountable for the action and who can reverse it? A fluent explanation from the model does not settle those questions.

The NCSC’s interim advice on agentic AI from August 2026 recommends distinct identities, restricted credentials, controlled environments and logs that allow activity to be investigated. Its advice is explicitly interim while formal guidance is developed. The operational implication is clear: the scope of an agent includes everything it can access or influence, including connected systems and the permissions behind them.

Human review must also have a defined purpose. A reviewer should see the source material, the proposed action and any uncertainty in time to change the result. Requiring a click on every routine step may add delay without improving control; asking someone to approve a consequential exception without evidence is equally weak. The right boundary depends on the task and the effect of an error.

A small system can still demand serious engineering

Choosing a document assistant over an agent does not make the underlying work trivial. Its answers may depend on policy versioning, access controls and the quality of the documents it reads. A rules-based check may need careful handling of exceptions and a way to keep rules current. A bounded agent may require less elaborate reasoning than a general assistant but more demanding integration and monitoring.

Where personal data is involved, those design decisions have a UK data protection dimension. The ICO’s data protection by design and by default guidance, updated in February 2026 calls for privacy to be considered from the start and throughout the life of the processing. Access to an employee’s expenses should be limited by the task and the user’s role, whether the interface is called an assistant, an agent or something else.

The choice should also survive a comparison with the current process. Ask each candidate design to handle representative policy questions, incomplete claims and genuine exceptions. Measure whether it helps employees reach a correct answer, reduces review effort and leaves an understandable record. Include the cost of maintenance and the consequences of a mistake. The UK Government’s 2026 AI Risk Management Toolkit recommends defining success measures, monitoring performance and reassessing risk as a system changes. The toolkit was developed for government departments but is explicitly intended for anyone involved in AI products. Its approach is relevant to enterprise decisions.

Let the work determine the system

At Cybix, we begin by understanding an operation and deciding where intelligence belongs, including where it should be deferred. When a system is warranted, it has to work with what the organisation already runs. The people who inherit it need the skills and governance to question and improve it.

That approach leaves room for agents where they make a measured difference. It also leaves room for a better search experience, a clearer rule or a well-designed assistant. The strongest architecture is the one that delivers the outcome within the organisation’s evidence, permissions and capacity to run it. The label comes afterwards.

Contact

Make the next decision count.

No discovery funnels, no qualification calls with juniors. Write to us and a senior partner will reply, usually the same day.

Contact