People search “AI agent or chatbot” because a vendor used both words on the same slide. The products are not the same. Mixing them is how a chatbot inherits an API key.
AI agent or chatbot? An agent takes a goal, uses tools, and acts across more than one step without a human prompting each one. A chatbot answers a turn. You type. It replies. The context window is the memory. Close the tab and the work is gone unless you saved it. Useful for drafting. Dangerous the moment you paste its output into a tool it cannot see.
The mix-up is not a branding argument. It is a permission argument. The word agent in a ticket is how a chat window gets a mail token, a payment scope, or a repo write. The word chatbot would have kept the same model in a box that only emits text. What is an AI agent? owns the full definition, the refuse test, and the charter. This page owns the collision.
Three tests
Ask the system in the room these three questions.
- Does it hold a goal overnight, or only the current prompt?
- Does it use tools, or only emit text?
- Does it continue across steps without a human typing each one?
If the answer is no, no, no, you have a chatbot. That is a respectable product. It is not an agent. Stop using the word until the tests pass.
A third box exists and people skip it. Automation runs a fixed script: when a PDF lands in this folder, extract the total into the sheet. No goal. No tool choice. A path you named. An agentic workflow is not an automation is that comparison. This page is agent versus chatbot.
Write the answers out loud. A demo that “feels agentic” is not a test result. The three questions are cheap enough to run in the meeting that is about to mint a credential.
Partial passes are still not an agent
The expensive mix-up is the half-yes. One test passes, the slide still says agent, and someone connects a key.
Goal, no tools, no continuation. A chat window with a system prompt that says “you are the invoice agent.” It holds a persona. It does not hold a goal overnight. Tomorrow you paste the sheet again. That is a chatbot with a costume.
Tools, no goal, no continuation. A plugin that can search mail, but only when you click. You still type the next step. The tool is real. The worker is still you. That is a chatbot with a socket.
Goal and tools, no continuation. A wrapper that can draft one reminder and then waits for you to press send, and then waits for you to start the next row. One tool call is not a run. If the work dies when you leave the tab, you have not given it a goal that survives.
Continuation without a stop. The dangerous yes. The system keeps calling tools after you closed the laptop. If nobody wrote what it must refuse, you did not hire a worker. You lit a fuse. The definition article owns that refuse test. Do not skip it because the first three answers sounded good.
A wrapper around a chat model is still a wrapper. A scheduled script that classifies a ticket is still automation. Calling either an agent does not add a ceiling. It adds permission to connect a tool.
Walk one object through the boxes
Same object, three boxes. If you cannot put the object in one box, you are not ready to name the system.
“Summarise this PDF in the chat” is a chatbot.
“When a PDF lands in this folder, extract the invoice total into the sheet” is automation.
“Chase unpaid invoices this week, using the sheet and the mail tool, and stop if a customer disputes” is an agent, but only if someone wrote the stop.
The stop is the charter: inputs, outputs, an authority ceiling, success criteria, review, escalation. Without those fields you have a demo that can spend money. This page will not restage the template. If you cannot name the stop, you do not have an agent. You have a chatbot you are about to over-permission.
A second object, same three boxes. “Draft a reply to this ticket in the chat” is a chatbot. “When a ticket lands with tag refund, post the canned reply” is automation. “Resolve refund tickets this week, using the order sheet and the mail tool, and stop if the amount is above the ceiling or the customer is angry” is an agent, again only if the stop is written. If the vendor demo used the third sentence and shipped the first machine, you are looking at the mix-up.
How the word becomes a key
The failure mode is vocabulary. It has a sequence.
Someone pastes a chatbot transcript into Slack. It looks competent. The ticket is titled “add the agent.” Ops wires the same window to mail, because agents use tools. Nobody writes a ceiling, because the demo did not ask for one. The first send that should have been a draft goes to a customer. The post-mortem says the model was too aggressive. The model did what a tool-using chatbot does when you hand it a send scope and no stop.
That sequence does not require a new runtime. It requires a wrong noun. The glossary capsule is the short form: chatbot answers a turn, automation runs a script, agent holds a goal under a charter. If you cannot point at the noun that matches the machine in the room, do not mint the credential.
Vendors will keep stacking the words. “Agentic chatbot.” “Chat agent.” “Autonomous assistant.” Recite the three tests anyway. Product names change. The tests do not. A literary representative is a different collision; that page is literary agent or AI agent. Do not email a tool hoping it is a person, and do not give a person-shaped prompt a production key.
Who can fail the next call
The human in the loop is the named person who can fail the next call. If that person is “the team” and the fail line is “looks fine,” you already decided the chatbot may act.
A chatbot does not need that person until you give it a tool. The moment you do, you no longer have a drafting toy. You have a worker with no contract. Name the reviewer before the socket, not after the first send.
Write the three tests on a card. Run them before the demo becomes a credential. If the card says chatbot, call it a chatbot in the ticket, the runbook, and the vendor call. AI Agents for Startup Strategy is live. You do not need the hardcover to refuse the word.