Somewhere around January, every pricing page in enterprise software discovered the word “agent.” The chatbot became an agent. The RPA suite became agentic. A workflow builder with an if-statement became an autonomous digital employee, which is a remarkable career arc for an if-statement.
The industry has a name for this: agent washing. And it’s not a fringe complaint: Gartner estimates that of the thousands of vendors claiming agentic AI, only about 130 are the real thing, and predicts over 40% of agentic AI projects will be canceled by the end of 2027, mostly for escalating costs, unclear value, or inadequate risk controls. Some meaningful share of those cancellations will be projects that were never agentic to begin with. You can’t get ROI from autonomy you didn’t actually buy.
The label decides the governance
If the mislabeling only cost money, it would be procurement’s problem and I’d leave it alone. But the label decides how you govern the thing, and both directions of the error hurt.
Call a chatbot an agent, and you’ll wrap a glorified search box in approval workflows and risk reviews it doesn’t need, and your teams will learn that AI governance is theater. Call an agent a chatbot (or never classify it at all) and something that can send emails, move tickets, and touch production data is sitting in your stack governed like a FAQ page. The trench coat works in both directions, and the second one is how you end up with entries missing from the agent inventory nobody owns.
Ignore the nameplate and put two questions to the product itself: can it decide, and can it act? If a human approves every consequential step, you bought a very good assistant: fine, useful, priced wrong. If it decides and acts on its own, it needs an owner, scoped credentials, and limits, no matter how friendly the demo felt.
Three questions for the demo
You don’t need to be technical to run this play. Ask the vendor, in this order:
- What can it decide without a human? Every demo shows what it can do; the interesting list is which decisions ship with nobody watching. If the honest answer is “none,” you now know what you’re buying, and the price conversation just changed.
- What can it touch when it decides wrong? For an agent, wrong is an operating condition, like rain. Which systems can it write to, which messages can it send, which records can it change? “It integrates with everything” is a threat model wearing a value proposition’s clothes.
- What did it do the last time it failed? Real agents running in real production have failure stories, and a vendor who’s operated one will tell you a specific, slightly painful one, along with what they changed after. If they can’t name a single failure, the first two answers were marketing.
There’s a genuinely exciting product category underneath all this. Real agents exist, some of them are excellent, and the honest vendors will happily answer all three questions because they’ve been waiting for a buyer who asks. The people the trench coat really hurts are the honest vendors, because it teaches a generation of buyers that “agent” means “chatbot plus forty percent.”
Ask the third question first if you’re short on time. It’s the one the coat can’t answer.