We have the most powerful tool of the past twenty years in our hands, and we use it as a faster dictionary.
TL;DR — Most people use AI as a chatbot: open a conversation, request some copy, then copy and paste the answer. That is perhaps five per cent of what is available. An AI agent is different. You give it an objective and it executes the work inside your systems — CRM, email and invoicing — because it has three things a chatbot lacks: the context of your company, memory that does not reset and tools with which to act. This article explains the difference between the door and the brain, the two families of agents, what an agent does during a real day at Futuria, how to write a useful brief, the three mistakes we see most often and where to start on Monday morning. The rule before every other rule: process first, automation second.
I see the same scene in almost every company I speak with.
The owner opens ChatGPT and types: “Write an email chasing a quotation.” They copy the answer into Gmail, adjust it slightly and then tell me, quite pleased: “I use artificial intelligence too now.”
I have no dataset to prove it; this is simply my photograph of the country. We have become a nation of prompt writers. We take the most powerful tool of the past twenty years and treat it as a turbocharged proofreader.
It works. It is also only the tip of the iceberg.
This article maps everything beneath the surface. It is not an encyclopaedic definition, but an account of how we use AI agents every day at Futuria Marketing to run the agency, including real examples and the moments when things went wrong. You will not leave with a magic prompt. You will leave with a map that can be adapted to your company.
Who it is for: SME owners and marketing managers who already “use AI” and suspect they are only scratching the surface. Who it is not for: anyone looking for a shortcut to paste into a chat. There is no such shortcut here, and you will shortly see why.
Table of contents
- ChatGPT is the door, not the brain
- The two families of agents
- What an agent does during a real day at Futuria
- A complete follow-up built live in five minutes
- Campaigns read from data rather than instinct
- Administration — where the pain is greatest
- An audit performed while the conversation continues
- The agent’s hands
- The four limits of AI — and how to overcome them
- The four-part brief
- The three mistakes we see most often
- What should not be delegated to AI
- Does it work the same if you start from zero or already have a CRM?
- Where to start on Monday morning
- What to do now
- Frequently asked questions
ChatGPT is the door, not the brain
Let us start with a misunderstanding that blocks everything else.
ChatGPT is not artificial intelligence itself. It is an interface: the window in which you type. The underlying brain is the model. The distinction is like the dashboard and the engine of a car: you interact with the dashboard, but the engine is what takes you somewhere.
That may sound pedantic. It is not. While you believe that “AI equals chat”, you remain stuck in one pattern: you type, it answers, you copy. Question and answer, forever. You have built an extraordinarily fast assistant and locked them in a room without a telephone, filing cabinet or office key.
An AI agent is a system to which you assign an objective rather than a question. It plans the steps, uses external tools to execute them, checks the result and corrects course when something is wrong. A chatbot gives you text. An agent delivers an outcome.
I often use a distinction associated with Andrej Karpathy, one of the clearest voices on the subject: knowledge and competence can be delegated to AI; understanding cannot. Knowledge is knowing how an advertisement is written. Competence is writing it well. Understanding is knowing why this customer, at this moment, with this product, needs this particular message. That remains yours.
Keep that trio in mind. We will return to it at the end, because it explains what can be handed to AI and what cannot.
The prompt writer stays at the entrance asking reception for information. The agent enters the building and works in the offices. The rest of this article explains what happens after it goes inside.
The two families of agents
When I discuss agents in person, I divide them into two categories. It helps people stop thinking “AI equals chat” and start asking “Which work can this remove from my hands?”
1. The personal assistant. An extremely capable colleague who works inside your company. You talk and reason together, but above all the assistant touches the work: preparing, organising, correcting and executing. It is conversational without stopping at conversation. Use it when a task benefits from discussion: “A customer sent this unusual request. Read the CRM history, recommend our response and prepare the draft.”
2. The background assistant. This agent runs repetitive, non-conversational work in the background. You do not chat with it. You assign a recurring task — a report every Monday, follow-up after every event, reconciliation at month end — and it performs the task autonomously each time. Configure it once, then leave it alone until the process changes.
Neither category is inherently better. The important change is moving from dialogue to execution. Stop asking “What can I ask AI?” and ask “Which part of my work can I delegate in full?”
It is the difference between a consultant who gives advice and a colleague who removes items from your desk. You listen to the first. The second changes your day.
This is where the first misconception appears: people assume the background assistant is “more advanced”. It is not. These are two different ways of working. The personal assistant is your right hand; the background assistant is autopilot. Most companies start with the personal assistant because conversation feels natural, and discover the background version only when they notice that some tasks repeat identically every week.
What an agent does during a real day at Futuria
Enough theory. Here are four things that happen in our agency. I will include the difficulties because an article containing only victories would sound fabricated.
A complete follow-up built live in five minutes
During one of our webinars, I asked my agent — in front of the audience — to prepare the post-event workflow. Not merely “write an email”, but complete an objective: create the participant-survey email, the form for collecting answers and the corresponding CRM fields, all while following our design system.
It took five minutes and thirty-seven seconds. During that time it read our design system from the SecondBrain, wrote the email in our tone, created the form with the correct fields, connected them to the contact record and prepared the send schedule.
At one point it got stuck because something in the browser was not working. I unblocked it as I would a colleague: “Try the API route and use the credential from the protected environment.” It continued. It did not stop to request permission for every harmless step. It tried, failed and changed approach.
The point is not speed. At the end, I did not have a piece of copy to fix. I had a configured piece of the company: the difference between a suggestion and an outcome.
Campaigns read from data rather than instinct
For a customer whose Google advertising we manage, the agent performs work that previously consumed half a day. It analyses search volumes, writes advertisement variants, keeps negative keywords clean — the terms for which we do not want to appear and which waste budget — prepares landing pages and then reads CRM data to understand not which advertisements received the most clicks, but which produced genuine customers.
That closes a crucial loop. Most companies optimise for clicks because clicks appear immediately. Real customers appear weeks later, at the other end of the funnel, inside the CRM. An agent that reads both sides can connect them.
It does not replace strategy; we decide that. It removes manual error and the phrase “it seemed to me”. Here is an honest question: how many advertising decisions have you made by feel because examining the figures properly required time you did not have?
Administration — where the pain is greatest
This example always surprises people. The agent that saves me the most time does not write anything: it works on accounts payable.
It downloads transactions, cross-references them with invoices in Fatture in Cloud, matches payments and reports only the exceptions — a missing invoice, an incorrect charge or a duplicate payment. I no longer enter everything manually. I review exceptions. That is a different job.
Think of the usual process. At the end of the quarter, someone — often the owner, in the evening — compares the bank statement with invoices one by one, searching for the gap. It is low-value work performed while tired and therefore prone to error. The agent performs it every day in the background and raises the gap while it is still small, not in March when the accountant raises an eyebrow.
This is a pure background assistant: configured once and then allowed to run.
An audit performed while the conversation continues
A few days ago, while speaking with a prospective customer, I asked the agent to inspect their website as our conversation continued.
A few minutes later it returned the finding: the site contained a noindex tag. In plain language, one line of code was telling Google, “Do not show me.” The site had been invisible in search for months and nobody had noticed. They were paying for a site that effectively did not exist for Google.
We left the call with the problem identified and the solution decided. It was not an opinion or a promise to send an audit quotation later, but a check performed during the work, in real time, while the conversation continued.
These four scenes share one thread. In none of them did the agent merely answer a question; in every one, it did something. None is science fiction. They involve emails, invoices, campaigns and checks: ordinary office work delegated.
The agent’s hands
How does an agent enter a CRM, read invoices or inspect a site? It needs hands. An agent has three: APIs, connections through MCP and the browser.
Put simply, an AI agent can carry out the same computer-based actions you can. Through APIs it communicates directly with software in the software’s own language. MCP is a standard way to connect the agent to tools without rebuilding every integration. When no technical connection exists, the agent can use a browser with clicks and keyboard input.
This is the difference between an agent and the “AI feature” inside a piece of software. A built-in feature performs the limited actions its developers anticipated, within that product’s boundaries. An agent can work across the systems to which you deliberately grant access. It is not confined to one application.
That is why people choosing tools with the future in mind look for open APIs. If a tool has a documented API, your agent has a reliable way to work with it. A closed tool is a room the agent cannot enter, and may eventually become a burden. We will return to that subject in a dedicated article.
Hands alone are not enough, however. That brings us to the heart of the matter.
The four limits of AI — and how to overcome them
Four limits stop AI in most companies and explain why so many people “tried it and it did not work”. Each has a remedy. Overcoming them separates the prompt writer from someone who delegates seriously.
1. It does not understand the objective. Without a clear outcome, AI feels its way towards the first plausible answer. That is not a defect in the tool so much as the result of a vague request. The remedy is a proper brief, to which the next section is devoted.
2. It does not know your company. A new colleague knows nothing on their first day: how you speak to customers, who owns which task or why three years ago you stopped working with a certain kind of supplier. AI begins from the same position. Without context, it gives answers suitable for anyone — which means suitable for nobody.
3. It has no durable company memory by default. Think of Memento, the film in which the protagonist forgets everything and relies on tattoos as reminders. AI without maintained memory behaves similarly: every new session begins without your company history. It is not necessarily unintelligent; it is simply missing yesterday’s context.
4. It cannot act without tools. Without tools it can only speak. The hands described above turn advice into action.
Limits two and three — not knowing and not remembering — are addressed together through what we call a SecondBrain.
A company SecondBrain is an organised collection of text files — we use Obsidian and Markdown — containing the company’s identity, procedures, policies and decisions together with the reasons behind them. Before acting, the agent reads the relevant material. It resembles a new colleague who has already studied the internal manual, except that the manual continues to improve as work is completed.
The cook metaphor makes this clear. A good cook needs both memory — ingredients in the pantry, dishes on the menu and regular customers’ allergies — and competence: how to prepare a base, how ingredients react and why a particular method works. An agent needs both the company’s facts and the principles by which the company reasons. Give it facts alone and it cooks randomly. Give it principles alone and it cooks in an empty kitchen.
A SecondBrain need not be a months-long project. It begins with a few pages: who we are, how we speak to customers, the three or four rules that cannot be broken and how the main process works. It then grows as useful learning is recorded. The company manual you never had time to write is built while the company works.
What about sensitive data? That is the right question. In our setup, company knowledge is stored in controlled company systems, and credentials are kept in a separate protected store rather than copied into chats or documentation. An agent receives only the access required for the task, with logs and approval boundaries where appropriate. Done properly, this is safer than the “passwords.xlsx” file that still sits on far too many desktops and is occasionally shared over WhatsApp.
The four-part brief
If you take only one practical technique from this article, take this one.
The key skill for using agents is not programming. It is explaining a job. Whenever I delegate a task to an agent, I use the same four parts:
- Objective — what I want to achieve, in one sentence. Not “write something about the new service”, but “prepare the email announcing the new service to customers who have already bought from us at least once”.
- Ideal state — what must be true at the end. “I want a draft ready for review, in our tone, with one call to action: book a call.”
- Guardrails — what it must not do and the boundaries it must not cross. “Do not promise discounts. Do not invent figures. Do not send anything; stop at the draft.”
- Constraints and sources — the rules and data with which it must work. “Use the tone in our SecondBrain. Get names from the active-customer segment in the CRM. Maximum 150 words.”
Compare the two. “Write an email about the new service” is a prompt-writer request: AI guesses and you spend half an hour fixing it. The four-part version is a brief. The agent knows where to go, what to avoid and what information to use. The result can be reviewed and used rather than rebuilt.
It is exactly how good delegation works with people. Compare the manager who says “Deal with it” with one who says “We need X by Friday, within these constraints, and be careful not to do Y.” The second is more likely to receive good work. The first often has to redo it.
If you can brief a capable colleague, you already understand the core skill of using an agent. The barrier is not code. It is the failure to make your desired outcome explicit — a barrier that existed before AI but is now easier to see.
The three mistakes we see most often
After doing this work for ourselves and customers, the same mistakes repeat. Here they are so you can avoid them.
Mistake 1: automating a broken process. This is the most serious and most common. Automation does not repair a confused process; it breaks it faster. It is like opening the tap further when the pipe is leaking: more water flows, but the cellar floods sooner. AI amplifies what it finds. Disorder in produces faster disorder out. The rule is therefore process first, automation second — always.
Mistake 2: treating AI as a dictionary. This is the prompt-writing pattern from the beginning. You request text, receive text and conclude that “AI saves two minutes”. Of course it does if that is all you ask. You have hired a full-time colleague to stamp documents and then complained about the cost.
Mistake 3: wanting everything immediately. “Let us automate the company.” No. Start with one small process with clear boundaries. People who try to delegate everything in a week often retreat convinced that it does not work. The real problem was haste. An agent is developed like a new colleague: one task at a time, with more responsibility granted as reliability is demonstrated.
There is a fourth, subtler and more dangerous mistake, which deserves its own section.
What should not be delegated to AI
Strategy.
AI can execute extremely well inside the boundaries you provide. Choosing which boundaries, where the company should go and what genuinely matters cannot simply be handed over. This is not conference-stage ethics; it is practical. That work requires understanding, and understanding is the part that remains with you.
I see a concrete risk: an enthusiastic owner starts asking AI not only how to do something, but what the company should do. “What should we focus on next year?” It is a short step from there to avoiding responsibility and allowing a model to make decisions that ought to keep an entrepreneur awake at night.
An agent may be the best executor you have ever had: faster, tireless and capable of handling more work. It is not your replacement at the helm. You keep the course.
That is the difference between using AI as an entrepreneur and using it as a passenger. Over time, passengers do not decide where the ship goes.
Does it work the same if you start from zero or already have a CRM?
I hear this question in two opposite forms. The answer changes the starting point.
If you start from zero — no CRM, contacts scattered across a phone, inboxes, spreadsheets and business cards — the first task is not “add AI”. It is create order. An agent can help collect, clean and unify the data, but the first decision is where that data should live. Without one home, the agent works in a vacuum. For a tradesperson who prepares quotations, first decide where requests live and how they are answered; automate follow-up afterwards, not before.
If you already have a CRM but it is incomplete, full of duplicate records and partly abandoned, the problem is different but the principle is identical. AI amplifies what it finds. A chaotic CRM creates faster chaos. Clean it first — much of that work can itself be assisted — and then delegate operations. An e-commerce business with three thousand unsegmented contacts does not need “more AI”; it needs to know who those people are. The agent can then communicate appropriately.
In both cases, the first step is order rather than technology. AI is a multiplier, and multiplying disorder produces more disorder.
Where to start on Monday morning
Let us turn the argument into something you can actually do.
Process first, automation second. You have now read it several times on purpose. Do not begin by choosing a tool. Write down the real flow of one thing you do frequently: who does what, where the information lives and what happens when something goes wrong. One sheet of paper is enough.
I see this every week. A recent company had contacts split across three different applications and a spreadsheet, and asked: “How do we add AI?” You do not start with AI. You start with order. AI comes later and finds a clean house in which to work.
Then choose one small, high-impact process. Pick the repetitive task that steals the most time and has clear boundaries: quotation follow-up, the Monday report or invoice reconciliation. Choose one. Make it reliable, then move to the second. Build the pipeline piece by piece rather than through a big bang that explodes at the first problem.
You do not need to be a programmer. Tools such as Claude Code from Anthropic and Codex from OpenAI were created for developers and can resemble an intimidating 1980s terminal. Open them, however, and you can give instructions in natural language: “Prepare the summary of yesterday’s call and add the actions to the CRM.” That is not code. It is an instruction to a colleague. The black background is merely workwear, not a barrier.
This closes the circle with the brief. The required skill is objective, ideal state, guardrails and constraints. If you can delegate to a person, you can learn to delegate to an agent.
One final point about cost, because it is usually the first question. At the time of writing, using these tools seriously may require roughly €100 per person per month across subscriptions. That is an indicative figure, not a permanent tariff: current prices are influenced by enormous investment in market growth and may rise. Compared with the time released, however, the value can be extraordinary. And the agent does not take August off.
What to do now
Take away these four actions, in order:
- Stop requesting text; start delegating outcomes. That is the move from prompt writer to agent operator. Replace “What can I ask AI?” with “What can I delegate?”
- Write the process before automating it. Put the real flow on paper before touching a tool.
- Choose one process to delegate. Small, repetitive and clearly bounded.
- Practise briefing, not coding. Objective, ideal state, guardrails and constraints.
For a deeper look at company memory, read how to build a company SecondBrain. If you want to connect agents safely to Futuria CRM, see the Futuria CRM skill for Codex and Claude Code. Our AI and operations events cover the same ideas in practical sessions.
We work on this through two routes. Some companies want to learn how to build these capabilities internally, and we explain the method without technical theatre through our events. Others prefer to outsource the marketing operation to us and use Futuria CRM as the single operational platform. The sequence remains the same in both cases: process first, automation second.
P.S. I am writing a series on this subject and want it to be useful rather than another AI guide copied from ten others. If you reached the end, tell me what became clear and what remains foggy. I genuinely use that feedback for the next article.
Frequently asked questions
What is the difference between ChatGPT and an AI agent?
ChatGPT is a conversational interface: you ask a question and receive a textual answer. An AI agent receives an objective and executes work across authorised systems — opening the CRM, preparing email, checking invoices — through external tools and course correction. The first gives you text; the second delivers an outcome.
What are AI agents for a company?
They are AI systems to which you delegate complete operational tasks rather than individual questions. Two useful categories are the personal assistant, an interactive digital colleague, and the background assistant, which autonomously handles recurring work such as reports, follow-up and reconciliation.
Do I need to know how to program?
No. Tools such as Claude Code and Codex accept natural-language instructions. The important skill is a clear brief containing the objective, ideal state, guardrails and constraints.
What is a company SecondBrain?
It is an organised collection of text files — often Markdown in a tool such as Obsidian — containing company identity, procedures, policies and decisions. It gives AI the company context and maintained memory required to stop producing generic answers and work according to company rules.
How much does it cost to start using AI agents in an SME?
At the time of writing, a serious setup may require AI subscriptions totalling roughly €100 per person per month, although prices and plans can change. The larger cost is usually the work required to organise processes before automation.
Where should a company start with agentic AI?
Start with the process, not the tool. Write down the real workflow, then choose one repetitive and clearly bounded process to delegate. Automating a disorganised process does not improve it; it accelerates its problems.
Can an AI agent be safe for company data?
Yes, when access is designed properly: company knowledge and credentials are stored in controlled systems, the agent receives only the permissions required, sensitive actions have approval boundaries and activity can be audited. The material risk is failing to decide which data and actions are in scope.
Will AI agents replace employees?
They change the work people do. Repetitive, low-value activities such as data entry, routine follow-up and report preparation can move to agents, leaving people to judge, build relationships and decide strategy. Someone who previously copied data can instead control exceptions and make decisions.
What is the difference between an AI feature in business software and an AI agent?
An AI feature performs the tasks anticipated by its developers inside one product. An agent can work across authorised CRM, email, invoicing and website systems through APIs, connectors and browser tools. The first is a feature; the second behaves more like a colleague using the company’s toolset.





