Guide · AI agents
AI agents for business, with you in charge.
We build AI agents for UK SMEs as part of our AI automation agency work, in each client's own accounts. Set up carefully, an agent can take real admin off a small team. Set up loosely, it can send the wrong email to the wrong customer.
What is an AI agent?
The UK's Competition and Markets Authority (CMA) describes agents as AI that can be "instructed in natural language to achieve a goal autonomously". It also says what sets them apart: traditional automation "follows predefined rules", while chatbots "primarily generate responses rather than decide what to do next and get it done".
In plain terms:
- Plain automation follows fixed rules, the same way every time.
- A chatbot answers questions, but doesn't go off and do things.
- An AI agent gets a goal and works out the steps, using your email, calendar or files along the way.
Our guide What is AI automation? goes further into the difference.
AI agent examples for small businesses
Agents suit jobs where the input is messy and the next step needs a little judgement. These are examples, not client stories.
- Example: the enquiries inbox. It reads new enquiries from your website form and inbox, works out what each person wants, adds them to your customer list and drafts a reply. A person reads each draft and presses send.
- Example: quotes that have gone quiet. It spots quotes with no reply, reads the last few messages and drafts a short follow-up for you to check. It can't change a price.
- Example: invoice chasing. It finds overdue invoices in your accounts software, then reads your recent emails with each customer. It holds off on anyone who's promised to pay, passes disputes to you and drafts reminders for the rest. It can't edit invoices or move money.
- Example: meeting follow-ups. It reads your notes from a customer meeting, adds a summary to their record and turns each action into a task for the person doing it. It can't email the customer.
In each example, the agent does the legwork, and anything that reaches a customer or touches money goes past a person first.
When you don't need an agent
Agents are flexible, which also makes them less predictable. If a task follows the same rules every time, plain automation is easier to check, and there are no AI usage fees to pay. Our Zapier vs Make vs n8n guide compares three tools for that. And if a task only comes up a few times a year, or a tool you already pay for has the feature built in, we'll suggest building nothing.
Are AI agents safe?
They can be, with limits. An agent isn't safe or unsafe on its own. It depends on what it can reach and what it may do without asking. Four risks are worth knowing:
- It can get things wrong. The CMA's research on agentic AI says agents "may be susceptible to errors", and that AI models can "fabricate incorrect information".
- It can be tricked by what it reads. Text in an email or web page can hide instructions for the AI. This is called prompt injection. The National Cyber Security Centre says not to give an AI that processes "emails from random external people" access to "privileged tools", and to use limits that don't rely on the AI behaving.
- It handles your data. Customer details within its reach are covered by UK GDPR. Start with the ICO's guidance on AI and data protection, which is under review after the Data (Use and Access) Act 2025.
- You answer for it. For agents that deal with customers, the CMA's guidance says "you are responsible for what an AI agent does in the same way you are responsible for what an employee does". That holds even if someone else built it, us included.
This isn't legal advice, but it's why the set-up matters more than the tool.
How to keep a person in charge
The CMA's guidance asks for "a human in the loop". A ladder makes that practical. An agent starts on the bottom rung and moves up only once it has shown it gets that rung right.
- 01
Read and suggest
It reads, summarises and suggests next steps, but changes nothing. If it gets something wrong, nothing has happened yet.
- 02
Draft for a person
It prepares replies, records or documents. A person checks each one before it's sent or saved.
- 03
Act after approval
It can act, but asks before anything that reaches a customer, spends money or deletes something.
- 04
Act alone on small things
Only for steps that are easy to undo, like filing an email or adding a note to a record.
The CMA's agentic AI paper gives the same kind of safeguard as an example: "mandatory confirmation for high-risk actions". Whoever builds your agent, also ask for:
- its own login, with access only to what its job needs;
- a log of what it did, read regularly by a named person on your team;
- an off switch you know how to use;
- testing on real examples, with a person checking the results. Nothing we build goes live without it.
If an agent talks to your customers
An agent that chats on your website or answers your phone needs more care, because your customers see every mistake. The CMA's guidance sets out four steps: tell customers you use an AI agent, train it to comply with consumer law, monitor how it performs, and fix problems quickly. In what we build:
- Standard messages like booking reminders go out automatically, in wording you've approved.
- Anything AI writes for one particular customer is checked by a person before it goes out.
- Live assistants, such as website chats and phone receptionists, always say they're AI, hand over to a person on request, and have their conversations reviewed afterwards. An agent says it's AI in its first message, or the first thing it says on a call. If your team isn't free to take over, it takes a message or books a callback.
- It answers from content you've approved and passes everything else to your team.
- No outbound AI marketing calls.
There's more on our AI receptionists for business page.
Which AI agent is best for a small business?
There isn't a single best one. An agent is an AI model, plus connections to your tools, plus the rules you set. The model might be the one behind ChatGPT, Claude, Google Gemini or Microsoft 365 Copilot. The connections are often built in a workflow tool, and Zapier, Make and n8n all now offer agent features.
So ask which mix suits the job. Start with the tools you already pay for, then compare where each one processes your data, what it costs to run and how easily your team can check its work. Our guide to the best AI tools for business compares the main assistants.
Where to start
Whatever you choose, start small. Pick one task that eats time every week, and write down how it's done today. That's your "before", so you can tell later whether the agent helped.
Our free AI readiness assessment for business is a short set of questions, with no email needed. If you'd like help, every job starts with a free call. We write the hours down before work starts and won't go over them without asking. The tools sit in your own accounts, and once it's paid for, the agent is yours. How we price has the details.
Sources and method
- CMA: Complying with consumer law when using AI agents (9 March 2026), checked 8 October 2026
- CMA: Agentic AI and consumers (9 March 2026), checked 8 October 2026
- NCSC: Prompt injection is not SQL injection (it may be worse) (8 December 2025), checked 8 October 2026
- ICO: Guidance on AI and data protection (under review), checked 8 October 2026
- PECR 2003, regulation 19 (legislation.gov.uk), checked 8 October 2026
- Zapier: Zapier Agents, checked 8 October 2026
- Make: Make AI Agents, checked 8 October 2026
- n8n documentation: AI Agent node, checked 8 October 2026
Written from the official UK guidance above and our own rules for customer-facing AI. The 'Which AI agent is best' question comes from Google UK 'People also ask' boxes, captured on 4 October 2026. Vendor pages were checked on the dates shown. Not legal advice.
Questions
Usually not. An agent takes over parts of a job, like reading, sorting and first drafts, and a person makes the decisions that matter. We don't promise time savings in advance. We note how long the task takes today, so you can see what actually changed.
Not one of ours. Our phone assistants take incoming calls only, say they're AI and can pass callers to your team. Automated marketing calls need prior consent under PECR regulation 19, and we keep AI sales calls out of our work altogether. Not legal advice.
Only what it's connected to, so connect as little as the job needs. Before we build, we tell you in writing which tools will handle your data and where they process it. If customer details are involved, you may need a data protection impact assessment (DPIA), and we'll help with it.
