Glossary · Rod Amora ·
Agent washing
Agent washing is marketing that relabels assistants, chatbots, or older automation as AI agents without giving them substantial agentic capabilities.
What does agent washing mean?
Agent washing is when a vendor calls a product an AI agent, but it’s still an assistant, chatbot, or older automation without much ability to choose and carry out the work. That’s how Gartner uses the term, and it’s a reason to check what you’re buying, not to assume every product called an agent is useless.
I wouldn’t spend much time arguing over the name. I would want to know what the system actually does in your business, and whether you can see the work and check it.
In June 2025, Gartner estimated that only about 130 of the thousands of vendors claiming agentic AI were real. That’s Gartner’s estimate, I haven’t checked the market myself, and watching the product do your work will tell you more about what you’re buying than that number will.
What is the difference between a chatbot, a workflow, and an agent?
A chatbot waits for you to ask. You open it, paste the customer details, ask for a draft, and then decide what to do with the answer.
An AI workflow follows steps that someone chose before it started. It can use an AI model for a hard part of the job, but the process around it still says what comes next, what to check, and where the result goes.
An AI agent works toward a goal over several steps, and it can choose what to do next based on what it finds, within the actions you’ve allowed. Agentic AI is the name for that behavior, the agent is the software doing it.
Anthropic makes the same distinction, a workflow follows steps set in code, while an agent’s AI model chooses how to proceed and which tools to use as it goes. It also recommends starting with the simplest system that works, because giving the system more freedom adds cost, takes more time, and gives mistakes more chances to carry into the next step.
So a fixed workflow isn’t an agent that fell short. If you already know the steps the work needs, it may be the better choice.
The problem is when you’re sold something you expect to notice what happened, choose the next action, and finish the job, but your team still has to hold the whole process together.
What should I ask before I buy?
I would ask five questions, and I would want the vendor to show me the answers with the system running, not just talk me through the product.
What starts the work without a prompt? A system doing a job in your business can start when a request comes in, information is missing, a payment happens, or something in your systems needs attention. If your team has to open a chat and prepare the whole case every time, you may be buying an assistant with a new name.
What decision changes with the current situation? Calling the AI model several times doesn’t tell you much on its own. I want to see whether what the agent does next changes because of what it found, and if every case follows the same steps with different wording, a workflow may be a better fit.
What can it reach? Ask which records, tools, and applications it can read or change, and whose account it’s acting through.
NIST’s February 2026 concept paper raises these concerns, how the agent is identified, what it’s allowed to do, how its actions can be checked and traced back to it, and how to stop instructions hidden in outside content from taking over. Because once an agent has access to your systems, it can change more than the answer on its screen.
So give it only the access the job needs. Reading an approved account record, drafting a reply, changing a price, and deleting a record are different permissions, even if the vendor bundles them into one account connection.
What proves the job finished? Don’t stop at the chat saying “done.” Look at the right client record and check that it changed, that the task is in the right queue, that you can still see the information the system used, and that it shows what action it took.
This is what I mean when I delegate the inputs and own the outputs. You can say a task is easy to check, but someone still has to make that check part of the work.
What happens when it fails? Ask what it does when a request times out, a record is missing, instructions disagree, or it tries to do something it isn’t allowed to do. Then ask who takes over, what they get to see about the failure, and whether the system can continue without repeating work it already finished.
And if the answer is “someone on your team reviews everything,” ask how much time that takes and what that person can actually reject. I use the same questions in the AI employee hub, what starts the work, what the system can reach, what it produces, and how you check the result.
How do I test an agent claim?
I would start with a job your business already knows how to check, rather than the vendor’s best demo.
Give the system access to read information and ask it to produce a draft or a task for your team. Try the kinds of cases that come up in real work, a clear request, missing information, two records that disagree, and a request the system should refuse.
Include an instruction hidden in a document you don’t trust. And when you let the system save changes, test what happens if a request times out after a change has already been saved.
Use a guardrail, a rule that blocks actions it shouldn’t take, and an eval, a test that scores the finished work against a standard you’ve written down. Keep a human in the loop where someone needs to make a decision the system shouldn’t make alone.
Then check the business record, because a good-looking summary attached to the wrong account is still a failed job. And if the system says it created a task but there’s no task there, it hasn’t finished.
Let it make one kind of change at a time, starting with changes you can undo. Keep a person’s approval before money moves, a client receives a promise, permissions change, or a record is deleted.
You’re trying to find out where letting it act without a person costs more than it saves, not just prove that it can do something.
And it needs the right connections to do the work. An agent that only sees what someone pastes into a chat may help that person work faster, but the person still has to manage the process. Your AI is just a better Google search explains why the original record and how the work moves to the next step matter as much as the answer the AI writes.
Where does agent washing sit on the Delivery Model Ladder?
Agent washing isn’t a stage on the Delivery Model Ladder, and calling a product an agent doesn’t move your business up it.
A chatbot or fixed workflow sold as an agent usually leaves you at Stage 1, Enhanced, because someone still starts the work, gives it the information, decides the next step, and puts the result into your business system. The tool can still help, but the way you deliver the work hasn’t changed as much as the name suggests.
For a system to support Stage 2, Augmented, it needs clear limits, something that starts the work, approved access, a specific job, a check you can rely on, and someone responsible when it fails. That means changing how the work happens, buying an agent subscription doesn’t do it for you.
Stage 3, AI-native, means rebuilding how your business delivers and checks the work. Asking the AI model more times, adding more agents, or buying something with a bigger claim on the label won’t make that change by itself.
Quick answers
Is agent washing the same as fraud? Not automatically. It means what the vendor calls the product doesn’t match what you can see it do, so check how it works and what the contract says before deciding what that mismatch means.
Is a chatbot useless? No. If a person should start the work and take the answer into the next step, a chatbot can be the right choice. You don’t want to pay for a system to work on its own and then find your team still has to guide every step.
What should I buy first? I would buy the simplest system that does one specific job and leaves a record I can check. Ask the vendor to show what starts the work before worrying about whether they call it an agent.
I haven’t seen a product label tell an owner what the system will do in their business. You find that out by watching it work, checking its access, and looking at the record it leaves.
If the vendor can’t show what starts the work and what proves it finished, treat it as a chatbot or workflow until they can show you otherwise.
FAQ
What is agent washing?
Agent washing is calling an assistant, chatbot, or older automation an AI agent without giving it substantial agentic capabilities. Gartner named the pattern in June 2025.
Is agent washing the same as fraud?
Not automatically. The phrase describes a mismatch between a product's agent label and its actual capability. Check the live behavior, contract, permissions, and final business record before deciding what you are buying.
How can I tell whether an AI product is really an agent?
Ask what starts the work without a prompt, what decisions change with the current situation, which tools and records it can reach, what proves the job finished, and who takes over when it fails.
Is a chatbot useless?
No. A chatbot can be the right tool when a person should start the work, supply the context, check the answer, and carry it into the next system. A simpler tool is often easier to test and operate.
Where does agent washing sit on the Delivery Model Ladder?
Agent washing is not a delivery stage. A relabeled chatbot or fixed workflow usually leaves a firm at Stage 1, Enhanced, because the old process still depends on a person. A tested and bounded workflow may support Stage 2.