FIELD NOTE

Three different operating models

Traditional workflow automation follows explicit triggers, rules, and actions. A copilot proposes or drafts while a person remains in control. An agent selects and sequences actions towards a goal, often across several tools.

Calling every automation an agent makes architecture harder to discuss. Name the level of discretion the system actually receives.

FIELD NOTE

Where deterministic automation wins

Choose rules when the input is structured, the acceptable outcome is clear, and consistency matters: validation, routing, reminders, record synchronisation, scheduled reporting, and approved calculations. These systems are easier to test and explain.

FIELD NOTE

Where an agent can earn its complexity

An agent can help when the path changes with context: researching across approved sources, preparing a case file, resolving a multi-system exception, or coordinating a task that requires several conditional steps.

  • Constrain accessible tools and records
  • Separate read, draft, approve, and execute permissions
  • Set spend, volume, and time limits
  • Require approval for material external actions
  • Log plans, tool calls, outputs, and overrides
  • Design a safe stop and recovery state

FIELD NOTE

The practical test

If the process cannot be explained, owned, and measured without AI, adding autonomy will usually increase confusion. Stabilise the process first, then grant the smallest amount of discretion that creates measurable value.

DIRECT ANSWERS

Questions operators ask

What is the difference between an AI agent and automation?+

Automation follows predefined logic. An AI agent can choose and sequence actions toward a goal using context and tools, which adds flexibility as well as uncertainty and control requirements.

Does every Malaysian SME need AI agents?+

No. Many high-value problems are better solved with reliable integrations, workflow automation, reporting, or a human-assisted copilot.

What controls should an AI agent have?+

Use least-privilege access, action limits, approval gates, data boundaries, complete logs, monitoring, evaluation, and a tested stop and recovery process.

SOURCE LEDGER

Primary sources

Official material is linked directly. Claims are paraphrased and checked against the source status available on 2026-07-21.
01MOSTI: National Guidelines on AI Governance and Ethics02JPDP: Automated Decision-Making and Profiling Guideline03NIST: AI Risk Management Framework

FRICTION EDITORIAL CONTROL

Original analysis. Visible limitations. No invented certainty.Prepared by Friction Research and reviewed against primary sources. This material is general information, not legal, tax, financial, or regulatory advice. Requirements can change; verify material decisions with the relevant authority or a qualified adviser.Read our editorial policy

READER EXCHANGE

Add to the conversation.

Name and email are required. Suspicious or abusive comments are held before publication.

PUBLIC READER COMMENT1,500 characters maximum

Your email stays private unless you choose to show it.

Loading conversation.