Chatbot vs AI agent: what the difference is, and when each is enough
Scripted chatbots, LLM chatbots and AI agents that act in your systems: a comparison table, when a simple bot is enough, and the guardrails an agent needs.
Part of the guide: Business automation with AI: a practical guide for small and mid-sized businesses

A scripted chatbot follows a decision tree: buttons and answers written in advance, with no way to step outside the script. An LLM chatbot understands questions in free language and answers from the information it has been given, but it still only answers. An AI agent answers and also acts: it books the appointment, updates the CRM, checks availability in the reservations system and hands the conversation to a person when it should.
The practical difference is not how clever the bot sounds but which systems it can reach and what it is allowed to do in them. Setup time, maintenance, risk and cost all follow from that. Below: a comparison table, when a simple bot is enough, when an agent is worth it, and the limits it needs before it goes live.
Three kinds, not two
Most comparisons set “chatbot” against “agent”, but in practice there are three different things, and it helps to know which one is on the table before asking for a quote.
Rule-based chatbot
A menu of options: “opening hours”, “prices”, “book an appointment here”. Every path is written in advance and every answer is the same for everyone who picks it. It is completely predictable and therefore safe, but it does not understand a question nobody planned for. Someone who types “is there parking nearby?” usually gets “sorry, please choose from the menu”.
LLM chatbot
Here a large language model reads the question as it was written and answers from a defined knowledge base: FAQs, policies, the menu, the price list. It understands different phrasings of the same question and holds a natural conversation. It does not touch any system: it can explain how to book, but it cannot book. An assistant that answers from company documents is an advanced version of this kind, covered in our guide to an AI assistant trained on company documents.
AI agent
An agent is a language model that has been given tools: defined connections to the business’s systems, such as a calendar, a reservations system, a CRM or a ticketing tool. It works out what the customer wants, checks the system, performs the action and confirms what was done. When something falls outside what it is allowed to do, it passes the conversation to a person with a summary. The EMBER example shows such an agent for a fictional chef restaurant: it answers guests on WhatsApp, Instagram, the website and the phone, and books tables directly in the reservations system.
Chatbot vs AI agent: comparison table
| Rule-based chatbot | LLM chatbot | AI agent | |
|---|---|---|---|
| How it works | A decision tree and buttons written in advance | A language model answering from a defined knowledge base | A language model with tools connected to the business’s systems |
| What it can do | Answer expected questions and point to a link or form | Answer freely worded questions and hold a conversation | Answer, check availability, book, update, open a ticket and hand over to a person |
| Setup effort | Low: writing the paths and answers | Medium: gathering and structuring knowledge, setting tone and limits, testing | Higher: all of that, plus each system connection, permissions and testing every action |
| Maintenance | Editing every answer by hand when something changes | Updating the knowledge base, reading conversations, fixing answers | All of that, plus watching the connections, since any system change can break an action |
| Risk of wrong answers | Almost none, since everything is scripted, but many “I didn’t understand” | Real: the model can phrase a confident answer when information is missing | Real, plus the risk of a wrong action in a system, so it needs limits and narrow permissions |
| Cost drivers | Number of paths and channels | Size of the knowledge, languages, model usage by conversation volume | Number of connections and actions, process complexity, channels, model usage and upkeep |
| Best for | A business with a few fixed questions and a simple process | A business with many information questions asked in different ways | A business where most enquiries end in an action: a booking, an order, an update, a lead |
The row that matters most is “what it can do”. If most of your enquiries end in an answer, a chatbot is enough. If most of them end in something a person on your team does by hand after the conversation, that is where an agent saves real work.
When a simple chatbot is enough
- Most enquiries are the same five to ten questions: hours, address, parking, prices, cancellation policy.
- The action after the question already lives somewhere else, such as an online booking link or a form on the site.
- There is no central system worth connecting to, or its data is not in order.
- Volume is low and the team replies in reasonable time without automation.
- The field is sensitive and a fully predictable answer matters more than a natural conversation.
In these cases a rule-based bot, or an LLM chatbot with a narrow knowledge base, is the right step, and it also shows you what people actually ask before you invest in integrations.

When an AI agent is worth it
- A large share of conversations ends in an action: an appointment, a table, a viewing, a change of details.
- Enquiries arrive in the evening, at weekends and at peak times, and leads or bookings are lost because nobody answered.
- Someone on the team copies information from conversations into another system by hand, several times a day.
- There is a system that holds the truth (a calendar, reservations, a CRM, inventory) and it has an interface you can connect to.
- The same enquiries arrive through several channels and you want them all to land in one place.
Agents that book appointments and viewings over the phone, in Hebrew and English, appear in the Névé and ALBA phone agent example, which we built for a fictional clinic and a fictional sales office. How to plan such an agent for a clinic or a sales office is covered in our article on AI phone agents. If you are not yet sure what is worth automating at all, the guide to business automation with AI walks through the processes, tools and risks from the start.
Guardrails: what an AI agent must never do alone
The more access an agent has, the more a mistake costs. OWASP describes this risk as Excessive Agency: an LLM-based system given too many tools, permissions or too much autonomy, which then takes a damaging action because of a wrong model output or manipulation. Its recommendations are plain: only the tools that are needed, minimal permissions, and human approval for high-impact actions. In practice that looks like this:
What stays with a person
- Refunds, discounts and exceptions to policy.
- Deleting data or cancelling a transaction.
- Any medical, legal or financial advice, and answers about a specific case.
- Complaints, an upset customer, or any conversation where the customer asks for a person.
- Committing to a price, a delivery date or terms that are not in the system.
Human handover
A good handover is not “someone will get back to you”. The agent tells the customer what happens next, opens a ticket with a summary and the details already collected, and whoever takes over does not have to ask everything again. On WhatsApp it is also a requirement: the WhatsApp Business Messaging Policy allows automation as long as customers have a prompt, clear path to a person, through in-chat transfer, phone, email or a support form.
Logging and review
- Every conversation and every action is logged: what the customer asked, what the agent checked, what it did and in which system.
- Someone on the team reads a sample of conversations every week and corrects the knowledge base.
- Permissions are set per tool: read availability, create a booking, never delete.
- The agent introduces itself as a digital assistant in its first message.
Disclosure is also becoming law in some markets: Article 50 of the EU AI Act requires AI systems that interact with people to be designed so that people are told they are dealing with an AI, unless that is obvious from the context.
Knowledge limits
An agent answers only from what it has been given. When the answer is not in its knowledge, it says so and hands over to the team instead of guessing. External content, such as a document a customer sends or a web page, can also carry instructions that try to change the model’s behaviour; OWASP calls this prompt injection. That is why what an agent may do is enforced by the permissions on its tools, not only by the wording of its instructions. Conversations with customers are personal data too, so whoever advises the business on privacy should review what is stored and for how long. We do not give legal advice.

Which channels: website, WhatsApp, Instagram and phone
One agent can work across several channels with the same knowledge and the same actions. The differences are in access and in the shape of the conversation:
- Website: the simplest to set up and fully under your control. Suited to pre-purchase questions and collecting details.
- WhatsApp: in Israel, the market we work in, it is the channel most customers already use. It needs access to the WhatsApp Business Platform through a provider, approved templates for business-initiated messages and Meta’s per-message pricing; see our article on the WhatsApp Business API, and for restaurants and hotels, the article on a WhatsApp AI agent.
- Instagram: direct messages that start from comments on posts and stories. Suited to brands whose customers begin there.
- Phone: a voice agent that answers, understands spoken language and books appointments. Calls are shorter and faster, so the script and the handover need to be sharper.
The rule that works: start with one channel, the one where most enquiries arrive, test it on real conversations, and only then add channels. The connections behind the scenes are usually built in an automation tool; we compare the options in n8n vs Make vs Zapier.

How to start
- Collect your last hundred enquiries from every channel and mark each one as ending in an answer or in an action.
- List the systems that hold the information (calendar, reservations, CRM, price list) and whether they have an interface to connect to.
- Decide what the agent will never do, and who takes the conversation when it stops.
- Write or tidy the knowledge: FAQs, policies, prices, in the words you want customers to hear.
- Test on real conversations before going live, and keep reading conversations afterwards.
For an assistant that answers from professional knowledge without taking actions, there is a separate example: the Varon Kessel assistant, built for a fictional law firm, answers from the firm’s documents and shows the source of every answer.
At Libra we build all three kinds, from mapping the enquiries to connecting the systems, testing and training the team, as described on our automation and AI agents page. Not every business needs an agent, and sometimes our advice is to start with a simple bot. Send a brief with your channels, your systems and a few examples of the enquiries you receive, and we will reply by email with a direction, a written price and a date.
No term matches.
Questions
What is the difference between a chatbot and an AI agent?
A chatbot answers questions, either from a script or in free language from a knowledge base. An AI agent also takes actions in the business’s systems, such as booking an appointment, updating the CRM or opening a ticket, and hands over to a person when needed.
Is ChatGPT a chatbot or an AI agent?
On its own it is an LLM chatbot: it answers and writes. When a model like it is connected to tools and business systems and told what it may do, it becomes an agent.
Can an AI agent replace a customer service person?
It can handle repetitive enquiries that end in a clear action. Complaints, exceptions, money and sensitive cases should stay with a person, and the agent should hand them over with a summary of the conversation.
What happens when an AI agent does not know the answer?
A well-configured agent says it does not know and passes the conversation to the team instead of guessing. That is set in the knowledge base and checked in testing before launch.
Can an AI agent run on a business WhatsApp number?
Yes, through the WhatsApp Business Platform rather than the regular app. WhatsApp’s messaging policy allows automation as long as customers have a clear path to reach a person.
Is a chatbot cheaper than an AI agent?
A chatbot is cheaper to build and maintain. An agent costs more because of the system connections, permissions and testing, and pays off when most enquiries end in an action someone currently does by hand.
Getting started
Want this for your business?
Send a short brief: three required questions, the rest only if you like. We reply by email with a direction, a written price and a date.


