Agents AI

Guide
AI Agents
Architecture
Risks

How AI Agents Work: Architecture, Tool Use & Risks Explained (2026)

How AI agents actually work: the plan-act-observe loop, tools, memory, MCP and the real failure modes — plus open, inspectable agents to learn from.

March 17, 2025Updated October 1, 20266 min read

An AI agent is a language model wrapped in a loop: it plans a step, acts through a tool, observes the result, and repeats until the goal is met or it gives up. Everything else — memory, guardrails, orchestration — exists to make that loop reliable. Most agent failures are loop failures: a bad tool call, lost context, or an action nobody approved.

This article is the under-the-hood companion to our definitional guide, What Is an AI Agent?. Read that first if you need the basics; read this if you are choosing, building or auditing one.

Tools worth knowing

If you want to see the architecture rather than read about it, these are the most inspectable options in our directory (overall score out of 10):

  • Watch every tool call, open source: Cline — free, 7.6. Runs in VS Code, shows each file read and command before it runs, and lets you pick the model.
  • Build your own agent loop visually: n8n — free self-hosted, 7.5. Each step is a node you can see, test and replay; the best way to understand orchestration.
  • A production-grade coding loop: Claude Code — from $20/mo (Claude Pro), 8.3. Plans, edits, runs tests and self-corrects, with permission prompts for risky actions.
  • Agents over company data with permissions: Dust — from €24/seat/mo, 7.1. Useful for seeing how retrieval and access control shape what an agent can do.
  • Multi-agent workflows without code: Relevance AI — from $19/mo, 6.6. Easy to assemble, though less transparent than the open-source options.

The core loop

Strip away the branding and nearly every agent runs the same cycle:

  1. Interpret the goal. The model turns an instruction into a plan: "to fix this bug I need to find the failing test, read the code, edit, re-run."
  2. Choose an action. The model emits a structured tool call — a search query, a shell command, an API request.
  3. Execute. The surrounding software (the harness) runs the call and returns the output to the model.
  4. Observe and decide. The model reads the result, updates its plan, and either continues or stops.

The model supplies judgement; the harness supplies capability and limits. The same model inside two different harnesses can behave very differently, which is why integration quality, not raw model power, increasingly separates products.

The four building blocks

Model. The reasoning engine. Larger models plan better but cost more per step; many production systems route simple steps to cheaper models.

Tools. The functions an agent may call: web search, a browser, code execution, databases, calendars, ticketing systems. The Model Context Protocol (MCP) has become the common open standard for exposing tools to agents, which is why the same connector can work across several products. Tool design matters enormously: vague tool descriptions produce wrong calls.

Memory. Short-term memory is the context window — what the model can see right now. Long-term memory is external: a vector store, a notes file, a CRM record. Context windows are finite, so agents summarise and retrieve rather than remember everything, and details get lost. That is a common source of "the agent forgot what I told it".

Guardrails. Permission prompts, allow-lists, spending caps, sandboxing and logging. In Cline and Claude Code you see these directly: the agent asks before running a command or editing a file outside its scope.

Single agent, workflow or multi-agent?

  • Workflow with AI steps: a fixed path (trigger, classify, route, reply) with a model at some nodes. Predictable and cheap; the right default. n8n and other automation tools are built for this.
  • Single agent: the model picks its own steps within a tool set. More flexible, harder to predict.
  • Multi-agent: specialised agents (researcher, writer, reviewer) hand work to each other. Powerful for broad tasks, but errors compound across hand-offs and costs multiply.

A sound rule: use the least autonomy that does the job. Many "agents" in the market are really workflows, and that is often a feature rather than a flaw.

Where agents fail

  • Compounding errors. If each step is 95% reliable, a ten-step task succeeds only about 60% of the time. Long autonomous runs need checkpoints.
  • Prompt injection. Text an agent reads — a web page, an email, a document — can contain instructions that hijack it. OWASP ranks prompt injection first among its LLM application risks. Never give an agent that reads untrusted content the power to send money, data or messages without approval.
  • Over-permissioning. An agent with access to everything can break everything. Grant the minimum.
  • Silent failure. The worst agents fail invisibly. Prefer tools that log every action and escalate when uncertain.
  • Runaway cost. Loops that retry forever burn tokens. Set budgets and step limits.
  • Business reality. Gartner has predicted that over 40% of agentic AI projects will be cancelled by the end of 2027 over cost, unclear value and inadequate risk controls. Klarna is the cautionary example for support: it publicly touted AI handling most chats, then said the push had gone too far and began rehiring human agents in 2025 after quality concerns.

How to evaluate an agent

Judge task completion rate on your own tasks, not demos. Check how it fails (does it escalate or bluff?), what it can touch, whether every action is logged, and what it costs when it loops. Our scores weigh capability, ease of use, value, reliability and support — see the methodology.

Try one yourself

To learn the architecture by watching it work:

  1. Cline (free, bring your own model API key): give it a small coding task and read each tool call it proposes before approving.
  2. n8n (free self-hosted): build a three-node workflow that classifies incoming email with a model and routes it. You will see exactly where the model's judgement ends and the plumbing begins.
  3. Claude Code: ask it to fix a failing test in a throwaway repo and watch the plan, edit and verify cycle.

Which should you choose?

  • Learning how agents work: Cline or n8n — both are free and transparent.
  • Shipping a business workflow: start with a workflow tool in automation, add model steps, and graduate to a true agent only where flexibility pays for itself.
  • Professional software work: Claude Code or the options in our coding agent ranking.

Next step

Compare n8n, Cline and Dust on their agent pages for pricing and weaknesses. To see how autonomy changes risk and evaluation, read Agentic AI vs Generative AI, and revisit the definition and types of AI agents if any term here was new.

Ready to try one?

Check the full scores and pricing first, then go straight to the tool.

Tags

AI Agents
Guide
Architecture
Risks
Agentic AI
A
AgentsAI Team
Editorial