Doppel Email Security is now generally available! | Register for the webinar to learn more
Research

What Does Agentic AI Mean? Definition, Autonomy Levels, and Business Impact

Agentic AI means software that works out its own next step toward a goal. Here is the definition, the five levels of autonomy, and what the shift changes for security.

How Agentic AI Ends the Abuse Inbox Bottleneck

Agentic AI means software that pursues a goal across multiple steps and works out those steps itself while it runs. The agentic label (opens in new tab) now covers so much ground that two products a vendor describes in identical terms can behave very differently, and that gap tends to surface once the software is running unattended.

What separates agentic software from the rest of your stack is how much of the deciding you have handed to it.

This article defines agentic AI, separates it from the terms it gets confused with, sets out the five levels of autonomy, looks at what enterprises have actually deployed, and explains what the shift means for security.

Key takeaways

  • An agent turns a goal and live results into its next action without waiting for a person to direct each handoff.
  • Deployment teams set autonomy across five levels independently of the underlying model's capability.
  • Handing steps to software hands over judgment, so the practical question for any deployment is how much.

Agentic AI produces its own sequence of steps at runtime

Agentic AI systems make their own decisions, learn from interactions, and adapt to changing environments (opens in new tab). An agentic system takes a goal, works out the sequence of actions that reaches it, carries those actions out through tools it can call, checks what came back, and adjusts: perceive, reason, act, check, repeat.

The origin of that sequence earns the system the label.

The system builds the sequence while the work runs

Give an agentic system the goal "reconcile this month's invoices against the purchase orders," and it works out which records to pull, which mismatches are worth flagging, and what to do about each one while the job runs.

Each next step comes from the result of the last. In an agentic system, the model directs its own processes and tool usage (opens in new tab) while it works.

Agency requires a goal, tools, memory, and standing permission

Four components define the practical threshold for agency and distinguish agentic software from useful software of some other kind.

Together, these let the agentic system choose and execute its next action without a new human instruction.

The words people use for agentic AI, and what each one names

Five terms circulate in the same sentences, and each names something specific. The axis that separates them is how much input (opens in new tab) the system needs from you, which is also what decides how the software behaves once it is running unattended.

  • AI agent: the unit. A model, tools, and a loop that a goal directs.
  • Agentic AI: a deployment property (opens in new tab). It describes where the system's steps come from, which is why two products can both carry the description and work very differently.
  • Agentic workflow: orchestration. Several steps or agents follow a predefined path, even when a model drives each individual step.
  • Multi-agent system: multiple coordinating agents (opens in new tab), each with its own loop, tools, and scope. The agents coordinate toward a shared objective.
  • AI assistant or copilot: the counter-case. At the lowest autonomy level, it provides support on demand (opens in new tab). The person carries the task from one step to the next and makes the decision at each handoff.

The line between these five is how many consecutive steps the software takes before it needs you again. To pressure-test a specific vendor's claim, start with this guidance on evaluating agentic claims (opens in new tab).

Autonomy is a designed range with five levels

Deployment teams choose the autonomy setting. As the system's autonomy rises, the person's role falls from directing the work to watching it.

Autonomy runs across five levels (opens in new tab), and the person's remaining role names each one:

  1. Operator: the person remains in charge throughout, and the agent supplies support on request.
  2. Collaborator: the person and agent divide planning and execution responsibilities.
  3. Consultant: the agent takes the initiative in planning and executing, while the person supplies feedback, preferences, and higher-level guidance.
  4. Approver: the agent runs the work and comes back when it encounters a block or needs sign-off on a consequential action.
  5. Observer: the person monitors an agent operating with full autonomy but does not intervene in individual decisions or actions.

The levels settle a question the word obscures on its own. A highly capable model sits at the first level when the deployment leaves it answering on request, and a modest one can sit at the fifth when its work goes unchecked.

Autonomy is a design decision the deployment team makes independently of how capable the model is, and increasing it requires deliberate tradeoffs (opens in new tab) among checkpoints, speed, and accountability.

Adoption is broad and shallow

Most organizations have agents somewhere in the business, while scaled deployment remains uncommon and coverage inside any single function stays thin. The gap between experimentation and scale defines the current adoption pattern.

Experimentation is common and scale is rare

In mid-2025, most organizations (opens in new tab) were still moving from experimenting with AI agents toward scaled deployment. In practice, agent deployments spread broadly but stay shallow, and they cluster in a small number of functions.

The label has spread faster than the capability

Among the vendors claiming agentic AI capability, only a small share are genuinely agentic (opens in new tab). The rest is agent washing: assistants, robotic process automation, and chatbots rebranded without substantial agentic capability.

On escalating costs, unclear business value, and thin risk controls, more than 40% of agentic AI projects (opens in new tab) are forecast to be cancelled by the end of 2027. The number worth watching is how many day-to-day decisions have moved from a person to software.

Once software decides, the decision becomes a target

Agentic AI's autonomous reasoning and execution challenge existing risk frameworks (opens in new tab) by changing who or what makes a decision. Permissions, scopes, and credentials settle what an agent is allowed to do. What it decides to do with that access is settled somewhere else, in the instructions and outside context it reads.

Social engineering (opens in new tab) has long worked by targeting whoever is doing the deciding, so it tracks the autonomy levels above. A chained workflow on a fixed path, or an assistant that stops after each answer, leaves the deciding with a person. Security and risk concerns are now the top barrier to scaling (opens in new tab) agentic AI.

In November 2025, Anthropic reported disrupting an espionage campaign (opens in new tab) it attributed to a Chinese state-sponsored group. The operators reached the model with a false cover story: they broke the work into small, innocent-looking tasks and told the model it was an employee of a legitimate cybersecurity firm running defensive testing.

On that footing, the model handled most of the campaign, with humans stepping in at a few decision points. Anthropic also noted the model overstated some findings and at times fabricated data. The move that opened the door was persuasion, applied to software.

Four exposure paths recur when an agent takes input from externally controlled assets:

Each path makes the decision reachable from outside your environment. The specific risks that follow, the controls that bound them, the impersonated identities (opens in new tab) attackers stage, agents running phishing (opens in new tab) at scale, and autonomous defense (opens in new tab) are each their own subject.

How Doppel reaches the assets your agents and your people read

Those assets belong to registrars, marketplaces, ad networks, and platforms, which is what makes them reachable and what puts them outside the controls you run yourself. Doppel is the AI-native Social Engineering Defense (opens in new tab) (SED) platform.

It unifies Digital Risk Protection (opens in new tab) and Human Risk Management (opens in new tab) on the Doppel Threat Graph. The platform treats each externally controlled domain (opens in new tab), cloned page (opens in new tab), listing in an app or extension marketplace (opens in new tab), paid search placement (opens in new tab), or social profile as an asset. Each one carries somebody's name.

The platform's AI detects those assets across those channels through Brand Protection (opens in new tab), executes takedowns (opens in new tab) through provider integrations, and leaves analysts to carry the complex escalations.

The Threat Graph (opens in new tab) correlates an asset the platform finds with the others that the same operators registered and controlled alongside it (opens in new tab), so a single action covers the connected set (opens in new tab). Bringing the whole set down at once turns the operators' standing infrastructure into sunk cost: what remains cannot run without the assets that just came down, and the next campaign costs more to rebuild than it is likely to return.

The same detection feeds the human side. Doppel Simulation (opens in new tab) builds an employee exercise (opens in new tab) from a campaign the platform has detected, in one click, and delivers it through email, voice, SMS (opens in new tab), Microsoft Teams, and Zoom.

Ask how much judgment you have handed over

The honest version of the title question is local. It asks how far along the range your own deployments sit. Each step up can trade a checkpoint for speed, a reasonable trade to make deliberately and an expensive one to make by default. Put one question to each deployment, and the answer surfaces: which decisions does it make without checking?

Request a demo (opens in new tab) to see how Doppel dismantles the impersonation infrastructure attackers aim at an organization's people and the software acting on their behalf. As more decisions move to agents, organizations will need to set autonomy, permissions, and accountability before deployment.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.