Solutions · Use cases
AI agents
Models that take actions, with guard rails.
An agent is a model that can use tools: search a system, draft an email, update a record or run a workflow. Agents can take real work off people's plates, but every tool you give them is a new way for things to go wrong.
01 / Where AI helps
Opportunities
Workflow automation
Multi step tasks such as gathering information from several systems and preparing a draft for approval.
Scheduled research
Agents that monitor sources and prepare a briefing each morning.
Operations support
Triage of tickets or alerts, with a suggested next action for a person to confirm.
02 / Australian rules to check
What to get right
Least privilege
Give an agent only the tools and permissions the task needs. Prefer read only access, and require approval for actions that change data or reach outside the organisation.
Prompt injection
Content an agent reads, such as an email or web page, can contain instructions. The OWASP Top 10 for LLM Applications covers this and related risks, and ASD's ACSC publishes guidance on securing AI systems.
Accountability
A named person should own each agent, its permissions and its outcomes. Keep an audit trail of what it did and why.
This is general information, not legal advice. See our Australian AI compliance guide for the wider landscape and links to official sources.
03 / Getting started
Where to run it
Agents often touch internal systems, so where the model runs matters. Running it inside your network keeps tool calls and the data they return off the internet, and makes the audit trail yours.
First steps
- Start with an agent that drafts but never sends, and measure how often people accept its work.
- List every tool it can call and what the worst misuse of each would be.
- Add approval steps for anything irreversible.
- Log inputs, tool calls and outputs, and review them regularly.