An AI agent is a system where a language model chooses its own steps and tools. When an agent makes sense in a business, what it costs, the FADP and the AI Act.

An AI agent is a program in which a language model itself decides which step to take next and reaches for tools on its own: a calendar, a CRM, mail, a document base. A chatbot answers a question; an agent receives a goal and plans the way to it. That is how Anthropic, the maker of the Claude models, draws the line in its text "Building effective agents" of 19 December 2024. In a workflow, models and tools are orchestrated through predefined code paths. In an agent, the model dynamically directs its own process and tool usage.
OpenAI draws the line from the other side. In its guide "A practical guide to building agents" (2025) it writes that applications which integrate language models but do not use them to control workflow execution are not agents. Its examples are a simple chatbot, a single-turn model call and a sentiment classifier.
Cost, risk and legal duties depend on that distinction. Below: the three conditions under which an agent makes sense in a business, a calculation of token costs, the rules after the July 2026 change to the AI Act, the Swiss data protection law and data on how many Swiss companies use AI at all. State of the law, prices and data on 8 October 2026.
An AI agent is a system that receives a goal, plans steps itself, calls tools and decides what to do next on the basis of their results, with varying involvement of a person. Four companies that build or sell such systems define it in a similar way:
The common core of these definitions: a goal instead of a single question, a language model that plans, tools through which the agent acts in other systems, a decision loop (take a step, check the result, choose the next) and autonomy: the model chooses the order of steps, not the programmer. All four definitions come from companies that earn money from agents. The law does not define an agent: the AI Act has no such definition.
"Agentic AI" is the same family of terms in adjectival form: agentic systems, that is systems built from agents or acting like an agent. "AI agents" is the plural of the same concept.
The boundary of the concept is not sharp. In an expert report prepared under the European Data Protection Board's Support Pool of Experts programme (I. Barberá, "AI Privacy Risks & Mitigations — Large Language Models", 10 April 2025), the author writes that "the concept of agentic AI remains an evolving and not yet fully defined domain". The report expresses the views of its authors, not the official position of the EDPB. The practical conclusion for a buyer: the word "agent" on a product guarantees nothing. You check who chooses the next step in it.
The simplest test: who chooses the next step — a person, a workflow written in advance or the model? The answer tells you whether you are buying a chatbot, an assistant, automation or an agent.
From answer to decision: chatbot, assistant, automation, agent
Anthropic, Building effective agents (19 December 2024); OpenAI, A practical guide to building agents (2025); Gartner (26 August 2025); Digital Vantage analysis, read 8 October 2026
Horizontal diagram in four columns, from answer to decision, no numbers. Chatbot: answers questions, a person chooses the next step. AI assistant: helps with a task but depends on human input and does not operate independently, a person chooses the next step. Automation, that is a workflow: runs a flow written in advance in code, a model can be one of the steps, the pre-written flow chooses the next step. Agent: receives a goal and chooses the tools and the order of steps itself, the model chooses the next step; examples from the OpenAI guide are refund approval, vendor security review and processing an insurance claim.
In the same press release of 26 August 2025 Gartner writes that the most common misconception is referring to assistants as agents, and calls it "agentwashing". In its press release of 25 June 2025 it describes "agent washing" as the rebranding of existing products, such as AI assistants, robotic process automation (RPA) and chatbots, without substantial agentic capabilities. It also estimates that only about 130 of the thousands of agentic AI vendors are real. That is an analyst estimate, not a register.
Anushree Verma of Gartner gives a simple rule of division in the same release: use AI agents when decisions are needed, automation for routine workflows and assistants for simple retrieval.
How integration between systems differs from an RPA robot and from automation with AI is covered in the article on business process automation. Here one thing is enough: an agent is automation in which the model, not a rule, chooses the way.
An agent works in a loop: the model plans a step, calls a tool, reads the result and decides on that basis what next, until the task is done or a stop condition is met. Anthropic describes agents as language models using tools in a loop, guided by feedback from the environment. At each step the agent should check the ground truth, that is the result of the tool call, to assess its progress. It may pause for human feedback at checkpoints or when it hits a blocker.
A tool is in practice the API of one of your systems. Anthropic gives a customer-support example: tools fetch customer data, order history and knowledge-base articles, and actions such as issuing a refund or updating a ticket are performed programmatically.
Tools are permissions. Every tool you give an agent is access: to customer data, to sending messages, to changing an order. OpenAI stresses that guardrails should be coupled with robust authentication and authorization protocols, strict access controls and standard software security measures. An agent connected to a mailbox and a drive sees everything in them, so before you connect it, check where your company's data really lives and who should have access to it. The same goes for tools attached through MCP (Model Context Protocol), a standard for connecting AI applications to company systems and data: through it the model can do as much as the account the server uses allows.
Without context an agent guesses. In its press release of 11 May 2026 Gartner quotes Rita Sallam: without a clear understanding of the specific relationships and rules within an organisation's data, AI agents cannot operate accurately and are far more likely to hallucinate, that is to state falsehood as fact. Companies approach this with caution. In a Gartner survey of 30 September 2025 only 19% of 360 IT leaders had high or complete trust in their vendor's ability to provide adequate hallucination protection, and 74% believed AI agents represent a new attack vector into their organisation. The survey covered organisations with at least 250 full-time employees in North America, Europe and Asia/Pacific, with no breakdown by country.
A common way to give an agent context is RAG (retrieval-augmented generation): before the model answers, the system searches matching fragments of company documents and gives them to the model along with the question. The quality of answers then depends on the quality of those documents.
The loop that gives an agent flexibility is also its biggest cost risk. When an instruction is unclear or a tool returns an error, the model can keep trying: call the tool again, get another error, try differently. Every turn of the loop is another model call, and you pay for each by the number of tokens. Anthropic says outright that the autonomous nature of agents means higher costs and the potential for compounding errors.
Both vendors give the same safeguard: a hard stop condition. Anthropic writes in the same text that the task usually terminates upon completion, but it is also common to include stopping conditions such as a maximum number of iterations to maintain control. OpenAI's guide lists reaching a maximum number of turns among typical exit conditions. Its toolkit for building agents (the Agents SDK) has a max_turns parameter for this: once it is exceeded, the SDK raises a MaxTurnsExceeded exception (OpenAI Agents SDK documentation, read 8 October 2026). The limit can be switched off, so whether it exists is decided by the implementer, not the tool.
The conclusion for a buyer: an agent's specification must contain a step limit per task and a monthly budget limit, and once either is exceeded the case goes to a person. What one step costs, we calculate below.
The loop of an AI agent and its three exits
Anthropic, Building effective agents (19 December 2024); OpenAI, A practical guide to building agents (2025); OpenAI Agents SDK documentation, read 8 October 2026; diagram by Digital Vantage
Diagram without numbers. A person gives the agent a goal, that is a task to complete, not a single question, and the agent works in a loop of four steps: the model plans a step, that is it chooses a tool and the order of actions; it calls the tool, that is the API of a company system such as a CRM, calendar or mail; it reads the result, that is the actual state instead of guessing; it decides what next: another turn of the loop or an exit. Every turn is another model call, paid by tokens, and the context grows with the tool results. Three exits: task done, when the success criterion is met; step or budget limit exceeded, then the case goes to a person, and in the OpenAI Agents SDK the max_turns parameter serves this purpose; an irreversible action or the agent is stuck, then a person approves, for example a refund, a payment or a cancellation. The agent chooses the next step, but a person designs the exits from the loop.
An agent makes sense where ordinary automation fails: decisions with exceptions, rules that cannot be maintained and data that cannot be laid out in a table. OpenAI advises starting with workflows that have previously resisted automation and gives three criteria, each with its own example:
OpenAI adds a precondition: before you commit to building an agent, validate that your use case clearly meets these criteria. Otherwise a deterministic solution may suffice, that is one that always does the same thing with the same data.
Anthropic describes the same area from the side of the task. An agent suits open-ended problems where it is hard or impossible to predict the number of steps and you cannot hard-code a fixed path. It adds the most where the task combines conversation with action, has clear success criteria, enables a feedback loop and includes meaningful human oversight. As an example it gives customer support, where success can be measured clearly by resolutions.
The fourth condition concerns limits: a person approves what cannot be undone. In the same guide OpenAI writes that actions that are sensitive, irreversible or high-stakes should trigger human oversight until confidence in the agent's reliability grows. It lists cancelling customer orders, authorising large refunds and making payments. An agent can therefore prepare a refund, gather documents and propose a decision, but the "approve" button stays with an employee.
A test for your process: can you write down the rule? Describe the process as a list of "if… then…". If the list closes and covers nearly every case, you need automation, not an agent: it will be cheaper, faster and predictable. If the list grows with every new case and people settle the exceptions anyway on the basis of emails and documents, you have a candidate for an agent. On one condition: the systems the agent is to use must have APIs.
In many business tasks an agent is not needed — the model vendors say so themselves. Anthropic recommends finding the simplest solution possible and increasing complexity only when needed, "which might mean not building agentic systems at all". For many applications, it adds, optimising single model calls with retrieval and in-context examples is usually enough. Agentic systems often trade latency and cost for better task performance, and you decide whether that trade makes sense.
In its press release of 25 June 2025 Gartner predicts that over 40% of agentic AI projects will be cancelled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls. That is an analyst prediction, not a measurement. More important is the sentence from Anushree Verma in the same release: many use cases positioned as agentic today do not require agentic implementations.
An agent does not make sense when:
You pay for an agent by tokens, and an agent uses many times more of them than a chat, because at every step the model receives the whole course of the task so far. A token is a fragment of text in which vendors count what you send to the model and what the model returns; token counts differ between languages. Anthropic quotes prices in dollars per million tokens (Claude API pricing, read 8 October 2026), and OpenAI bills in the same unit (OpenAI API pricing, read 8 October 2026).
We calculated an example on Anthropic's price list: the Claude Sonnet 5.5 model costs $2 per million input tokens and $10 per million output tokens. Anthropic publishes prices in US dollars; we leave them in dollars rather than convert. The token counts are our assumptions, not a market average.
What a chat reply and an agent task cost in tokens — our example
Anthropic, Claude API pricing (prices in US dollars); example assumptions and calculation by Digital Vantage, not a market average; API prices read 8 October 2026
Bar chart, an illustration with assumptions, not a market average. Assumptions: Claude Sonnet 5.5 model, $2 per million input tokens and $10 per million output tokens, no discounts for caching or batch processing. Chat reply: 3,000 input tokens and 300 output tokens, $0.009. Agent task: 10 model calls, on average 8,000 input tokens and 500 output tokens per step, $0.21, about 23 times more than a chat reply. 1,000 agent tasks a month: $210.
The calculation step by step (our arithmetic):
Anthropic's price list also gives lower rates for batch processing and for data from the cache; our calculation does not include them. On the other hand, an agent that gets stuck in a loop pays for every further turn: in our example about $0.021 per step, and in practice more, because the context keeps growing. The step limit from the previous section sets the upper bound on the cost of one task.
Gartner confirms the order of magnitude. In its press release of 17 August 2026 it writes that routing a task to an agentic reasoning model increases provider inference costs by at least five times compared with a basic chatbot interaction, and often much more as task complexity grows. That is a cost on the model provider's side, not a price for the customer. Running costs already hold companies back: in McKinsey's "The state of AI in 2026" (25 August 2026, 1,719 respondents from 97 countries, self-reported) about 20% said AI-related operating costs, including token costs, constrained their AI use.
Tokens are only the running cost. The cost of building an agent, that is integrations, permissions, tests and an observation period, depends on the number of tools and systems, and we found no independent study of these prices in Switzerland. One rule holds regardless of price: the budget should be built into the agent itself, not checked on an invoice after a month. In the design of the chat for our own website, exceeding the monthly token budget is one of the conditions after which a person takes over the conversation.
Switzerland has no AI act, and the EU AI Act does not define an agent. An agent is subject to the Federal Act on Data Protection (FADP) whenever it processes personal data, and to the AI Act only where the agent or its output reaches the EU. The Federal Chancellery writes on Regulation of AI: "In Switzerland, there is not yet any overarching legislation that deals specifically with AI." On 12 February 2025 the Federal Council decided that Switzerland will ratify the Council of Europe's AI Convention, with sector-specific amendments as far as possible (OFCOM); a consultation draft is due by the end of 2026, and as of 8 October 2026 we found no consultation opened.
The FADP applies to agents now. The Federal Data Protection and Information Commissioner (FDPIC) states that the FADP, in force since 1 September 2023, "is directly applicable to AI-supported data processing" (FDPIC). That is the FDPIC's reading, not a court ruling. Two provisions matter most for agents. Under Art. 21(1) FADP the controller informs the data subject of any decision based exclusively on automated processing that has a legal consequence or a considerable adverse effect, for example an agent that accepts or rejects applicants, and the person may ask for the decision to be reviewed by a natural person (Art. 21(2)). Art. 22(1) requires a data protection impact assessment beforehand where processing is likely to result in a high risk to personality or fundamental rights. Wilful breaches of the information duties in Arts 19 and 21 are punishable, on complaint, by a fine of up to CHF 250,000 on the responsible private person (Art. 60), prosecuted by the cantons (FDPIC). The English version of the Act on Fedlex has no legal force; the French text is authoritative.
Telling people they are talking to a machine. The FDPIC writes that, "in the case of intelligent language models that communicate directly, users have a legal right to know whether they are speaking or corresponding with a machine". That is the FDPIC's reading of the FADP, not an express article, and we do not write that Swiss law requires a chatbot label.
When the EU AI Act reaches a Swiss company. Art. 2(1) of Regulation (EU) 2024/1689 covers providers placing AI systems on the market or putting them into service in the Union, whether established in the Union or in a third country, and providers and deployers in a third country "where the output produced by the AI system is used in the Union". A Swiss company that offers an agent to users in the EU is a provider. In that case the Commission's non-binding guidelines on Article 50 of 20 July 2026 state that AI agents are covered by Article 50(1) if they are capable of interacting with natural persons in the execution of their tasks, for example making bookings, managing correspondence or executing purchases, and must disclose both their artificial nature and the person on whose behalf they are acting; the duty applies from 2 August 2026, with a fine of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher (Art. 99(4)); for SMEs the lower of the two (Art. 99(6)). Art. 3(1) defines an "AI system" as "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments"; the AI Act has no separate definition of an agent. Staff competence under Art. 4 (in the wording of Regulation 2026/1744, measures supporting AI literacy but no specific level, and no duty to measure employees' knowledge according to the Commission's questions and answers) and the high-risk rules (Annex III, for example recruitment, from 2 December 2027) also apply only where Art. 2(1) is triggered. A Swiss company that merely uses AI in Switzerland is caught only where the output is used in the Union; where that line runs the texts we read do not settle, so ask a lawyer. Duties by company role, fines and a checklist are in the article EU AI Act for a Swiss business.
This describes the rules; it is not legal advice.
There is no data on agents in Swiss companies; there is only an indicator on AI-based systems in general, from 2023, and it shows around one company in ten. The Federal Statistical Office (FSO) publishes it on its page Other ICT use (in German), based on the KOF innovation survey: data year 2023, companies with five or more employees. The FSO writes that large companies use AI-based systems most often, followed by medium-sized and then small ones, and that use is most widespread in services (our translation from the German). The chart carries no value labels; read off the axis (our reading), it shows around one company in ten overall and about a third of large companies. We do not set it next to Eurostat's figures, because the survey differs and Switzerland is not in Eurostat's AI table. A further signal comes from an insurer's survey relayed by the SECO SME portal, the AXA labour-market study: between 2024 and 2025 the share of SMEs that incorporated AI rose from 22% to 34%. We have not reviewed its method.
Only global surveys speak about agents themselves. In McKinsey's 2026 survey 40% of respondents from large organisations (revenue above $1 billion, 27% a year earlier) and 22% of those from smaller ones, unchanged year on year, reported scaling AI agents. "Smaller" here means revenue below a billion dollars, so these are not Swiss SMEs.
We bring the wider picture of AI in companies, from assistants in office suites to the rules, together in the section AI in business.
Start with one process and the simplest solution that can handle it; add an agent only when a simpler flow does not fit. OpenAI puts it briefly in its guide: start small, validate with real users and grow capabilities over time. In practice that is six steps:
This is how we design the AI chat for our own website. We are deploying it on our site and there are no results yet, so we describe the assumptions, not the effects. The bot's first message says that an AI is answering. During working hours a person takes over the conversation in six situations: when the visitor asks for it, when the bot finds no answer in the knowledge base or has low confidence, when the visitor is rated as a high-value prospect, for a complaint and for legal or financial topics beyond what we have published, when the writer is already our client, and when the monthly token budget is exceeded. Outside working hours the bot does not hand the conversation over automatically, says so plainly and offers a free meeting slot. Once a person has taken over, the bot stays silent. The CRM receives a summary of the conversation, and the full transcript stays in the support mailbox. After launch we will observe the bot for at least four weeks and check every week where it made something up; only then will we propose a similar solution to clients.
By Anthropic's definition this chat is closer to a workflow than to an autonomous agent: it answers from a knowledge base and uses a few tools, such as booking a meeting, but within a fixed flow. It is a deliberate choice, in line with the model vendors' own advice: as much autonomy as the process requires, and not one step more.
A chatbot answers questions, and a person decides what happens next. An agent receives a goal, chooses the next steps itself and calls tools, for example the API of a calendar, a CRM or an order system, and then decides what to do next on the basis of the result. OpenAI says outright in its guide to building agents that a simple chatbot is not an agent, because it does not control the course of the work.
Technically yes, if it is given a tool with that permission. OpenAI recommends, however, that sensitive, irreversible or high-stakes actions, such as cancelling orders, large refunds and payments, are approved by a person until confidence in the agent grows. Every tool is access, so the same rules apply as for any system: authentication, authorisation and strict access control, and read-only tools at the start.
Not by definition. The AI Act does not define an agent, and the risk category depends on the use. An agent used, for example, to filter job applications and evaluate candidates falls under Annex III and the obligations for high-risk systems, which after the July 2026 amendment apply from 2 December 2027. Regardless of the risk category, if an agent talks to people, Art. 50 applies from 2 August 2026: the person has to know they are talking to an AI, and that duty rests on the provider of the system. For a Swiss company all of this matters only where Art. 2(1) of the AI Act is triggered, that is where the agent or its output reaches the EU. In Switzerland itself an agent that decides about people on the basis of personal data is subject to Art. 21 and 22 of the FADP.
It depends on the model, the number of steps and the amount of text in each step. In our example on the Claude Sonnet 5.5 price list ($2 per million input tokens, $10 per million output tokens, prices in US dollars as Anthropic publishes them) a task with 10 steps of 8,000 input and 500 output tokens on average costs about $0.21, and 1,000 such tasks a month about $210. A reply of an ordinary chat in the same calculation costs about $0.009. It is an illustration with assumptions, not a market average, and it does not include the cost of building.
No. An agent can be built on a ready-made model available through an API, for example from Anthropic or OpenAI, paid by the number of tokens; that is how we calculate the cost in this text. The work of your own is the tools, permissions, knowledge base, rules for handing over to a person, and limits. Training your own model is a separate project that an agent built on a ready-made model does not require.
We will go through the process, the systems and the data it has to handle with you, and say plainly whether you need an agent, an automation or one well-configured model call.
AI in business without the hype: where Swiss firms stand, when an assistant is enough and when you need an agent, what it costs, the FADP and the EU AI Act.
ChatGPT Business, Copilot or Gemini in Switzerland: what a business plan changes, price per user in CHF, FADP processor rules and what your suite has.
When the EU AI Act reaches a Swiss company, how the FADP already applies to AI, deadlines to 2028 and fines in euros, with a checklist for small businesses.
Your Partner in Business, Digital Vantage Team
Digital Vantage team is a group of experienced professionals combining expertise in web development, software engineering, DevOps, UX/UI design and digital marketing. Together we carry out projects from concept to implementation - websites, e-commerce stores, dedicated applications and digital strategies. Our team combines years of experience from technology corporations with the flexibility and immediacy of working in a smaller, close-knit structure. We work in agile methodologies, focus on transparent communication and treat each project as if it were our own business. The strength of the team is the diversity of perspectives - from systems architecture and infrastructure, frontend and design, to SEO and content marketing strategy. As a result, the client receives a cohesive solution where technology, aesthetics and business goals go hand in hand.
Rate this article
Back to the guide: AI in business — where to start, what it costs and what the law says

ChatGPT Business, Copilot or Gemini in Switzerland: what a business plan changes, price per user in CHF, FADP processor rules and what your suite has.

When the EU AI Act reaches a Swiss company, how the FADP already applies to AI, deadlines to 2028 and fines in euros, with a checklist for small businesses.

AI in business without the hype: where Swiss firms stand, when an assistant is enough and when you need an agent, what it costs, the FADP and the EU AI Act.

Low code and no code explained: who a citizen developer is, what a low code platform suits, its price limits and what you can take with you when you leave.

Ecommerce customer service in Switzerland: fewer WISMO tickets, complaint handling under Swiss law, chatbot disclosure and two support metrics that matter.

Ecommerce automation: what to automate first, Zapier, Make and n8n pricing, and a formula for ROI in hours worked, not promises.

Ecommerce operations after launch: orders and product data, warehouse and shipping, customer contact, measurement. What to automate, what to outsource.

Business process automation: how it differs from RPA and AI, the QR-bill as a first step, our hands-off funnel, examples by department.