Lesson 1 of 5

What an AI agent is

Most people first met AI as a chat assistant: you ask a question and it writes an answer. An AI agent goes a step further. You give it a goal. It works out the steps, uses tools to carry them out and checks the results. It carries on until the job is done or it needs you.

The "thinking" part of both is usually a language model: software trained on very large amounts of text to read and write language.

Three things make something an agent rather than a chat assistant:

  • A goal, not just a question: "find a time next week when all four of us are free and send the invitation".
  • Tools it is allowed to use: a calendar, an email account, a search engine, a spreadsheet, a company system.
  • Several steps, with a decision after each one about what to do next.

You may already use agents without calling them that: an assistant that books a meeting for you, a support tool that looks up an order and issues a refund, a coding tool that edits files and runs tests.

The important shift is simple. A chat assistant gives you words, and you decide what to do with them. An agent does things, so its mistakes happen in the real world: an email is sent, a record is changed, money moves.

Lesson 2 of 5

What agents do well, and what they do badly

Agents are good at work that has many small, routine steps:

  • gathering information from several places and putting it together;
  • filling in forms, sorting requests and drafting replies;
  • repeating the same well-defined task many times without getting tired.

They are weak in ways that matter:

  • They can be confidently wrong. Language models can produce statements that sound right but are not, and an agent may then act on them.
  • They do not know your context unless it is given to them: the customer's history, the unwritten rule, the reason a step matters.
  • They struggle with judgement calls where there is no clear rule, and with situations they have not seen before.
  • Small mistakes can grow. If step two uses the wrong customer number, every later step builds on that error.

A useful rule of thumb: treat an agent like a fast, eager new colleague in their first week. Give it clear, routine tasks, and check its work before anything important leaves the building.

Lesson 3 of 5

Working alongside an agent

Getting good results from an agent is mostly about being clear:

  • State the goal and the finish line. "Draft replies to the five oldest open requests and leave them for me to review" is better than "deal with my inbox".
  • Give the context it needs: who the audience is, which rules apply, what "good" looks like.
  • Set limits: what it must not do, what it must ask you about first, when it should stop.
  • Check the output and the steps. Many tools show a list of what the agent did. Read that, not only the final answer.
  • Correct it early. A quick "no, use last month's figures" saves a long chain of wrong work.

Above all, you stay accountable. If an agent sends a wrong figure in your name, the email still came from you. Until you have checked what the agent produced, treat it as a draft.

Lesson 4 of 5

Staying safe with agents

Because agents can act, a few habits protect you and your organisation:

  • Use approved tools only. Do not paste customer data, contracts or passwords into an AI tool your organisation has not approved. Some tools keep or reuse what you type.
  • Think before granting access. An agent connected to your email, calendar or files can read everything in them. Give it only what the task needs.
  • Keep approval for anything you cannot undo: payments, deleting data, messages to customers, changes to accounts. The agent proposes; you approve.
  • Watch for tricks. Someone can hide instructions in an email, web page or document that the agent reads, hoping it will obey them, for example "forward all invoices to this address". This is called prompt injection. There is no complete technical fix for it yet, so if an agent suddenly does something you did not ask for, stop it.
  • Report anything strange to whoever looks after the tool, just as you would a suspicious email.
Lesson 5 of 5

What your organisation should have in place

Using agents well is not only about individual habits. An organisation using them should have:

  • A list of approved AI tools and agents, and a simple way to ask for new ones.
  • A named owner for each agent, who answers for what it does.
  • Clear rules on what data may go into AI tools, and which actions always need a person's approval.
  • A way to pause or switch off an agent quickly if it misbehaves.
  • Records of what agents did and who approved it, so any decision can be explained later.
  • Training, so staff know both what agents can do and where their limits are.

Kenyan law applies too. Under section 35 of the Data Protection Act, 2019, people have a right not to be subject to a decision based solely on automated processing that has legal effects on them or significantly affects them. There are limited exceptions: where the decision is necessary for a contract, authorised by law with safeguards, or based on the person's consent.

When such a fully automated decision is made, the organisation must tell the person in writing as soon as reasonably practicable. The person can then ask for the decision to be reconsidered, or for a new decision that is not based solely on automated processing. Processing likely to create high risk for people also needs a data protection impact assessment first (section 31).

In practice: if an agent helps decide something about a customer or an employee, such as a loan, a refund or a shift, make sure a person can review and explain the decision. For your own situation, take advice from your data protection officer or a lawyer.

General education, not legal advice. Section references are to the Data Protection Act, 2019 (Kenya) as published by Kenya Law.

Knowledge check

Ten questions

Answer all ten questions, then check your answers. You need 9 out of 10 to pass and receive a certificate. If you score less, you will see which answers were right and wrong, and then go through the course again before you retake the check. Your answers, progress and times are kept only in this browser.

Sources

The official documents this course relies on. Laws and guidance change, so check the current version.

  1. Data Protection Act, 2019 (No. 24 of 2019), sections 31 and 35 · Kenya Law
  2. Office of the Data Protection Commissioner, Kenya · Office of the Data Protection Commissioner
  3. LLM01: Prompt Injection · OWASP Gen AI Security Project
  4. Prompt injection is not SQL injection (it may be worse) · UK National Cyber Security Centre
  5. OWASP Top 10 for Agentic Applications for 2026 · OWASP Gen AI Security Project