What is an AI agent? Prompts, agents and what they can already do
Share
An agent acts with your login
China's AI industry is moving its attention from building models to running agents. Here is what an agent actually is, how it differs from typing a prompt, what it already does at work, at home and at school, and what criminals did with the same technology this year.
By Shrinivas G · September 2026 · 7 minute read
China Mobile has set up a Token Office. Tokens are the small pieces of text that AI software reads and writes, so counting them shows how much work the machines are doing. Last year the company's systems produced about 3.4 trillion of them a day, and the report behind that figure says agents are driving the demand.
That detail comes from Qian Ling, chief expert at China Mobile Group, speaking about a new report from the China Telecom Research Institute called Research Report on AI Infrastructure Development in the Agent Era (2026). China Central Television carried the findings on Saturday, and Bloomberg reported the main point: China's AI industry is moving its money and attention from building big models to putting agents to work and charging for them.
The rest of the report is about what that does to demand. Rao Shaoyang, who runs the Industry and Enterprise Strategy Research Institute at the China Telecom Research Institute, puts China's token use at 100 quadrillion in 2026 and above 3,500 quadrillion by 2030. A quadrillion is a thousand trillion. The report also expects the country's computing demand to grow by an average of nearly ten times a year for the next two to three years.
Computing splits into two jobs. Training is the computing used to build a model in the first place, which happens once and takes months. Inference is the computing used every time somebody actually asks that model to do something. The report expects inference to take 80 per cent of China's computing market by 2029, which means the money moves from building models to running them.
An agent uses tokens on every step it takes.
Here is why those demand figures and the move to agents belong together. A person types a prompt a few times an hour and stops to read each answer. An agent repeats the same cycle as fast as the computer allows, for as long as the job takes, and it pays in tokens each time round. The numbers in the report are counting software doing that, rather than people typing.
The difference between a prompt and an agent
A prompt is one question and one answer. You type the question, the model writes the answer, and anything that happens next is done by you. You read it. You copy the paragraph into the email. You press send.
An agent is the same model given three extra things: a job to finish, a set of tools, and permission to use them. A tool here is any software the agent is allowed to operate. Your inbox is a tool. So is your calendar, a web browser, a spreadsheet, or the screen where you refund a customer. The agent works out a step, does it, reads what came back, then works out the next step. It keeps going until the job is finished or it gets stuck. People call that repetition a loop.
The part that matters is the permission. An agent is logged in as you. When it books the meeting, the invitation arrives under your name. When it issues the refund, real money leaves a real account. A prompt gives you a draft and leaves the decision to you. An agent makes the decision and does the thing, and you are responsible for what it did.
An agent keeps working after you close the laptop.
What that looks like at work, at home and at school
Start with the small jobs, where most people will meet an agent first. A work agent reads the overnight email against rules you wrote, files anything routine, and leaves you the few messages that need a person. It pulls last month's ad spend out of four different dashboards and writes one summary into a spreadsheet. It takes the receipts sitting in your inbox and matches them against the card statement. It types your order into a supplier's website, box by box, when that supplier has no way to connect to your system.
Bigger jobs work the same way. A support agent reads the customer's message, finds the order in your store's admin screen, checks the delivery with the courier, then either answers or hands it to a person. A sales agent reads a request for a quote, prices it from your price list, and writes the reply for a person to sign. Each of those jobs used to need someone with a login. Now the software has the login.
At home the same software compares energy plans, fills in the switching form and books the technician. It reads the parking fine and drafts the appeal. At school it marks the practice paper, finds the pattern in the mistakes, and builds the next worksheet aimed at that pattern. A teacher can have one worksheet rewritten at four reading levels before the bell. A student gets a tutor with unlimited patience, and that same tutor will happily do the thinking the student was supposed to do.

What criminals did with agents this year
Anthropic published its fourth threat intelligence report on 10 September. It covers attacks the company found and shut down between December 2025 and August 2026. Anthropic says most of the operations in it were run by AI doing the work or directing it, rather than by a person asking a chatbot for advice. These are the cases Anthropic caught on its own service, and it calls them notable examples rather than a full picture.
Two of them show the speed. In one break-in, attackers started with a single stolen login belonging to a software developer and had complete control of everything that company kept online about three hours later. In another, they broke into one software supplier and reached the data of roughly 200 businesses that were customers of that supplier. Inside about 34 hours they copied more than 2,100 sets of Microsoft sign-in details covering more than 40 company accounts. Anthropic says AI agents did nearly all of that work.
Another case shows how much one person can now cover. A single French-speaking individual, working alone, went after 42 organisations and got inside at least 14 of them. The same person built a search engine stocked with tens of millions of stolen personal records. Anthropic calls it the clearest case it has seen of AI-written software built for a mass attack on people's privacy. All of this is Anthropic's own assessment rather than anything proven in court.
One case in the report reaches an ordinary small business directly. Criminals built websites offering cheap access to the best-known AI models. People who signed up were quietly served a cheaper model, and the program they downloaded copied the passwords saved on their computer and sent them on. Anthropic describes a Russian and Ukrainian speaking group running that as a business.
Stolen AI logins are worth having for three reasons, and the report names all three. Reason one, they sell. Working keys and accounts have a price in criminal marketplaces. Reason two, they are free computing. The attacker runs their own work on your account, and your card pays for it. Reason three, they are a disguise. In the records, everything the attacker does looks like you doing your job.
One flag on the figures above. The China Telecom Research Institute report describes China's infrastructure and China's demand, so every number from it belongs to that market. I also think the same change is arriving in Australian businesses through the software already on their desks. That part is my own conclusion rather than something the report says.
Three things worth doing this month
Make a list of what each agent can open. Write down every account you have connected to an AI tool. Email. Calendar. The admin screen of your online store. Your ad accounts. Your accounting software. Your shared drive. Your customer list. Beside each one write "can look" or "can change". Every account marked "can change" is one where the software can send, buy, edit or delete something under your name, without asking you first. Anthropic tells organisations to guard the logins they hand to AI tools as carefully as the passwords to their live systems. The criminals in its report went hunting for exactly those.
Buy AI tools from the company that makes them. An API key is a long password that lets your own software sign in to an AI service. The cheap resellers in the report took the payment and took their customers' passwords as well. Buy from the vendor's own website. Keep the API key in a password manager. Change it the day a staff member leaves.
Make a person approve anything that cannot be undone. Some things can be fixed in a minute. A draft can be rewritten and a spreadsheet can be corrected. Other things stay done. Money that leaves the bank account. An email that lands in a customer's inbox. A post that goes live. A file that is deleted. Data that is sent to another company. Set your tools so an agent prepares that second kind and a person clicks the final button. Let the agent finish the first kind on its own, which is most of the work in a week.
Write down what your AI tools can change, then take one of them off the list today.
Sources. Bloomberg News, 12 September 2026, and China Central Television, 12 September 2026. Token, computing, spending and agent population figures from the China Telecom Research Institute, Research Report on AI Infrastructure Development in the Agent Era (2026), with the daily token figure from Qian Ling of China Mobile Group. Attack figures from Anthropic, Detecting and countering misuse of AI: September 2026, published 10 September 2026.
Mashed Avocado · Marketing Sideways · MashedAvocado.com