Guides

AI agents, chatbots or workflow automation in South Africa: which fits which job

What an AI agent is, how it differs from a chatbot, RPA and workflow automation, which suits which job, and how to start safely under POPIA.

Last checked

The short answer

Use the simplest tool that does the job. If the steps never change, use workflow automation. If the steps never change but the only way into a system is its screen, use robotic process automation (RPA). If people need answers in plain language from a known body of information, use a chatbot. Use an AI agent only when the work needs judgement: exceptions, messy documents, or decisions a rulebook cannot hold.

The model providers say the same. Anthropic, which builds the Claude models, advises "finding the simplest solution possible, and only increasing complexity when needed". OpenAI's guide to building agents sets three tests a use case must meet first, and adds: "Otherwise, a deterministic solution may suffice."

What an AI agent is, and how it differs from a chatbot

An AI agent is software that uses a language model to choose its own next step and to act through other systems, where a chatbot only answers.

OpenAI defines agents as "systems that independently accomplish tasks on your behalf". It is just as clear about what falls outside: simple chatbots, single-turn LLMs and sentiment classifiers use a model but are not agents, because the model does not control how the work runs.

Anthropic draws the line in the same place. In a workflow, models and tools run "through predefined code paths". In an agent, models "dynamically direct their own processes and tool usage".

A scripted chatbot is sometimes sold as an agent. Three questions sort one from the other:

  • Does it choose the next step itself, or follow a script someone wrote?
  • Can it act in another system: update a record, file a document, open a ticket?
  • Does it know when the job is done, and hand back to a person when it is stuck?

Workflow automation, RPA, chatbots and agents side by side

What each tool is, what it suits and where it fails:

  • Workflow automation: fixed steps between systems that have connectors or an interface for software. Suits approvals, routing forms, notifications and copying records between systems. Fails on anything the rules did not foresee.
  • RPA: a software robot that works through a screen the way a person does. Microsoft describes its desktop flows as built for "simple or complex rule-based tasks", able to reach "legacy applications, such as terminal emulators" through on-screen elements, images or coordinates. Suits old systems with no other way in. Fails when a screen changes, and on judgement.
  • Chatbot: answers questions in plain language, from scripts or from a model limited to your documents. Suits frequent questions, policy lookups and first-line sorting of queries. Fails at finishing work in other systems.
  • AI agent: a model that plans steps and uses tools to carry them out. Suits exceptions, unstructured documents and judgement calls. Fails on speed, cost and predictability. Anthropic notes that agentic systems "trade latency and cost for better task performance", and that autonomy brings "higher costs, and the potential for compounding errors".

The labels blur inside products. Microsoft's Copilot Studio calls its fixed processes agent flows, then says of them: "The same input always produces the same output." Ask whether the path is fixed in advance or chosen by the model as it goes.

When RPA or plain workflow automation still wins

Choose workflow automation or RPA when the rules are known and stable:

  • The steps can be written as a checklist and rarely change.
  • An auditor will ask why each item was handled as it was, and "the rule said so" is the answer they need.
  • The data arrives structured: fields on a form, rows in a spreadsheet.
  • The only way into an old system is its screen (this is where RPA earns its place).
  • Volume is high and every run must cost the same.

OpenAI puts it in one line: "A traditional rules engine works like a checklist", while an agent weighs context like an investigator.

Choose an agent where OpenAI's three tests hold: complex decision-making, difficult-to-maintain rules, and heavy reliance on unstructured data.

Which tool for which job

Examples by task, from simplest tool to most capable:

  • Reminding a customer when an invoice passes its due date: workflow automation.
  • Copying policy data out of an old administration system that offers no interface for software: RPA.
  • Answering "where is my order?" or "when are you open?" on the website: a chatbot connected to the order system.
  • Reading supplier invoices in many layouts, matching them to orders and flagging mismatches: an agent, with a person approving the exceptions.
  • Deciding a refund when the customer's story does not fit the policy: an agent drafts the recommendation, a person decides.
  • Sorting a home insurance claim from a written description and photos: an agent preparing the file for a claims handler.
  • Calculating monthly payroll: neither chatbot nor agent; payroll software and fixed rules.

Good systems often combine them: a fixed workflow that calls an agent for one hard step, then puts the result in front of a person.

Four risks: made-up answers, hijacked instructions, irreversible actions and runaway costs

Each risk has a known control, and none of the controls is perfect, so design for the failure.

Made-up answers. Anthropic's own documentation says even the most advanced models "can sometimes generate text that is factually incorrect", and that its recommended techniques "don't eliminate them entirely". Those techniques include letting the model say it does not know, making it quote and cite the source documents, and restricting it to the documents supplied.

A South African case shows how far an invented reference can travel. In April 2026 the Minister of Communications and Digital Technologies announced the withdrawal of the Draft National Artificial Intelligence Policy, saying it "contains various fictitious sources in its reference list" and that the most plausible explanation was "AI-generated citations were included without proper verification". Check every source before a document leaves the building.

Hijacked instructions. An agent reads emails, documents and web pages, and any of them can carry instructions aimed at the agent. OWASP, the open security project, calls this prompt injection: "user prompts alter the LLM's behavior or output in unintended ways". Its controls include "Restrict the model's access privileges to the minimum necessary" and "Implement human-in-the-loop controls for privileged operations".

Actions that cannot be undone. OpenAI's guide says that "actions that are sensitive, irreversible, or have high stakes should trigger human oversight until confidence in the agent's reliability grows", and names cancelling orders, authorising large refunds and making payments.

Costs that grow quietly. Some platforms meter every step. Microsoft says each action an agent flow runs "consumes Copilot Studio capacity", and that once prepaid capacity is used up, "new agent flow runs are blocked until capacity is available". Microsoft 365 Copilot licensed users and test runs are not affected, and Microsoft suggests considering pay-as-you-go billing to avoid the interruption. Ask any supplier what is metered, and what happens at the limit.

What POPIA says about automated decisions and model providers

The Protection of Personal Information Act (POPIA) covers the personal information an agent or chatbot handles. Three parts matter most.

Automated decisions. Section 71 says a person may not be subject to a decision that has legal consequences for them, or affects them to a substantial degree, based solely on automated processing meant to profile them, for example their performance at work, credit worthiness or reliability. Exceptions include a decision tied to a contract where the person's request was met or appropriate measures protect their interests. Those measures must let the person make representations, with enough information about the underlying logic to do so. A chatbot giving opening hours is not caught. An agent that declines credit or a claim on its own may be, so keep a person deciding.

Model providers and builders as operators. POPIA defines an operator as someone who processes personal information for you "in terms of a contract or mandate". Section 21 requires a written contract that makes the operator maintain security measures, and makes the operator report a suspected breach to you immediately. Whether an AI platform is your operator depends on the arrangement.

Data sent abroad. Section 72 bars sending personal information to a third party in a foreign country unless a listed ground applies, such as adequate protection where the recipient is, the person's consent, or a contract with them that needs it. Ask each one where your data is processed and stored.

This is not legal advice. Checked against the text of the Protection of Personal Information Act, Act 4 of 2013, on 9 October 2026. Have an attorney check your own arrangement.

How to start

Start small, keep a person in charge, and widen only when the results hold:

  1. Pick one task with real volume where a mistake is cheap to catch, such as drafting replies to routine queries or sorting incoming documents.
  2. Write down how the task is done today, including the exceptions. If it fits a checklist, build a workflow, not an agent.
  3. Give the agent read access first, and the fewest permissions that do the job.
  4. Keep a person approving anything that sends, pays, cancels or decides about a customer.
  5. Ground answers in your own documents, make the agent cite them, and let it say it does not know.
  6. Set limits on retries and a clear handover. OpenAI's guide says that when an agent exceeds them it should "escalate to human intervention".
  7. Measure errors, time and what it costs against the old way, and widen the scope only when the numbers hold.
  8. Settle POPIA before live data: the operator contract, where data is processed, and who makes decisions about people.

Getting an agent built

IAMX's Custom AI agents and copilots service builds AI agents for a business's own tasks, connected to the tools, workflows and data it already uses. They are built with your team and taken into daily use rather than left as a pilot. IAMX is one accountable front door to a vetted network of specialist partners.

Questions buyers ask about AI agents

  • Is a chatbot an AI agent?

    Usually not. A chatbot answers questions; an agent decides its next step and acts in other systems. A chatbot becomes agent-like when it can change a booking or open a ticket on its own.

  • Is RPA obsolete now that AI agents exist?

    No. RPA still wins where the rules are fixed, the screens are stable and an old system offers no other way in. RPA can run the fixed steps, with an agent only for the step that needs judgement.

  • Does POPIA ban decisions made by AI?

    No. Section 71 limits decisions with legal or substantial effect that rest solely on automated profiling, and allows exceptions with safeguards. Answering questions and drafting replies are not caught. Keep a person deciding on credit, claims, jobs and similar matters.

  • Can a WhatsApp chatbot use AI?

    Yes, within Meta's rules. Meta's terms bar providers and developers of AI technologies, general-purpose AI assistants among them, from offering those technologies on the WhatsApp Business Platform where they are "the primary (rather than incidental or ancillary) functionality", as Meta determines in its sole discretion. A business may still use an AI provider as its solution provider, but platform data may then not be used to train AI models, except to fine-tune one for the business's exclusive use. The bot can send free-form replies only inside the customer service window, a 24-hour timer that starts when the customer messages or calls you. Outside it, only pre-approved templates can be sent.

  • How do we stop an AI agent from making up answers?

    You reduce it; you cannot remove it. Limit the agent to your own documents, make it quote them, let it say it does not know, and have a person check anything that goes to a customer or into a decision.

Sources

  • Anthropic: Anthropic recommends finding the simplest solution possible, and only increasing complexity when needed, before building agents. Checked .
  • OpenAI: OpenAI's guide names three tests for building an agent (complex decision-making, difficult-to-maintain rules, heavy reliance on unstructured data) and says that otherwise a deterministic solution may suffice. Checked .
  • OpenAI: OpenAI's guide to building agents defines agents as systems that independently accomplish tasks on your behalf. Checked .
  • OpenAI: OpenAI's guide says applications that use a model without letting it control workflow execution, such as simple chatbots, single-turn LLMs or sentiment classifiers, are not agents. Checked .
  • Anthropic: Anthropic defines workflows as systems where models and tools are orchestrated through predefined code paths, and agents as systems where models dynamically direct their own processes and tool usage. Checked .
  • Microsoft Learn: Microsoft says Copilot Studio agent flows are deterministic, follow a rule-based path, and the same input always produces the same output, with AI and human-in-the-loop actions available inside them. Checked .
  • Microsoft Learn: Microsoft describes Power Automate desktop flows, its robotic process automation, as designed for simple or complex rule-based tasks, able to automate legacy applications such as terminal emulators through UI elements, images or coordinates. Checked .
  • Anthropic: Anthropic says agentic systems often trade latency and cost for better task performance, and that their autonomy means higher costs and the potential for compounding errors. Checked .
  • OpenAI: OpenAI's guide says a traditional rules engine works like a checklist, while an agent evaluates context more like an investigator. Checked .
  • Anthropic: Anthropic's documentation says even the most advanced language models can sometimes generate text that is factually incorrect, and that its techniques to reduce this do not eliminate it entirely. Checked .
  • SAnews, South African Government News Agency: On 26 April 2026 the Minister of Communications and Digital Technologies announced the withdrawal of the Draft National Artificial Intelligence Policy, saying it contains various fictitious sources in its reference list and that the most plausible explanation is that AI-generated citations were included without proper verification. Checked .
  • OWASP GenAI Security Project: The OWASP Top 10 for LLM applications (2025 edition) defines prompt injection as user prompts altering a model's behaviour or output in unintended ways, and advises least-privilege access and human-in-the-loop controls for privileged operations. Checked .
  • OpenAI: OpenAI's guide says sensitive, irreversible or high-stakes actions such as cancelling orders, authorising large refunds or making payments should trigger human oversight until confidence in the agent's reliability grows, and that an agent exceeding its retry limits should escalate to human intervention. Checked .
  • Microsoft Learn: Microsoft says every action an agent flow executes consumes Copilot Studio capacity; once prepaid capacity is fully consumed, new agent flow runs are blocked until capacity is available, while Microsoft 365 Copilot licensed users and test runs are not affected, and Microsoft suggests considering pay-as-you-go billing to avoid interruption. Checked .
  • South African Government: Section 71 of POPIA bars decisions with legal consequences or substantial effect based solely on automated processing intended to profile a person, with exceptions for contracts and for decisions governed by a law or code with appropriate safeguards. Checked .
  • South African Government: Section 1 of POPIA defines an operator as a person who processes personal information for a responsible party in terms of a contract or mandate, without coming under its direct authority. Checked .
  • South African Government: Section 21 of POPIA requires a written contract under which the operator maintains security measures, and requires the operator to notify the responsible party immediately of a suspected unauthorised access. Checked .
  • South African Government: Section 72 of POPIA bars transferring personal information to a third party in a foreign country unless a listed ground applies, such as adequate law or binding rules or agreement, consent, or necessity for a contract. Checked .
  • South African Government: The text of the Protection of Personal Information Act, Act 4 of 2013, as published in Government Gazette 37067 of 26 November 2013, was read for this guide on 9 October 2026. Checked .
  • Meta: Section 4.7 of Meta's terms for the WhatsApp Business Platform (last modified 23 September 2026) bars providers and developers of AI or machine learning technologies, including general-purpose AI assistants, from offering them on the platform where they are the primary (rather than incidental or ancillary) functionality, as Meta determines in its sole discretion; a business may still retain an AI provider as its solution provider. Checked .
  • Meta for Developers: Meta's WhatsApp Cloud API documentation says a 24-hour customer service window starts when a user messages or calls the business, free-form service messages can be sent only inside it, and template messages are needed outside it. Checked .

The front door.

Tell us your X