Key Terms & Concepts — UPSC Mains
Agentic AI
"AI systems that pursue multi-step goals autonomously, taking a sequence of actions toward an objective without requiring prompting or approval at each step, as distinct from generative AI, which responds to a single prompt at a time."
Agentic AI refers to artificial intelligence systems designed to act with a degree of autonomy toward a goal: planning a sequence of steps, executing actions such as browsing, writing and running code, or interacting with other software systems, and adjusting that plan based on intermediate results, all with minimal or no human intervention at each step. This distinguishes it from generative AI, which produces an output, text, code or an image, in direct response to a single prompt, with a human deciding what happens next. The security significance of this distinction, highlighted in 2026 cybersecurity commentary, is that an agentic system can independently discover vulnerabilities, exploit them, and take further autonomous action, compressing an attack sequence to a speed no human defender can match, while also being capable of obtaining and using legitimate credentials in ways that make it statistically indistinguishable from an authorised human user. This defeats identity- and credential-based defences such as the Zero Trust security model, which were designed to distinguish authorised from unauthorised actors rather than to distinguish human from autonomous-agent actors holding equally valid credentials. The policy response under discussion internationally includes treating every autonomous agent, by default, as an insider-threat risk requiring its own scoped identity and continuous behavioural monitoring, alongside calls to preserve meaningful human control over consequential decisions, particularly in military and critical-infrastructure contexts, where the same autonomy that enables efficient defence also enables offensive operations that outpace human response.
A newly central GS3 concept in AI-governance and cybersecurity discourse, useful for engaging with the generative-versus-agentic distinction that UPSC increasingly probes in science-and-technology and internal-security answers.
- 1 Agentic AI pursues multi-step goals autonomously; generative AI produces output in response to a single prompt.
- 2 Can independently discover and exploit vulnerabilities, compressing attack timelines below human response speed.
- 3 Can obtain and use legitimate credentials in ways statistically indistinguishable from an authorised human user.
- 4 Defeats credential/identity-based security models such as Zero Trust by satisfying rather than failing verification.
- 5 Occupies the 'insider threat' security vector rather than the traditional 'external attacker' vector.
- 6 Raises governance questions about meaningful human control, especially in military and critical-infrastructure applications.
- 7 The number of non-human (agentic/machine) identities in enterprise environments is now understood to vastly exceed human identities.
M.K. Narayanan's 2026 essay used agentic AI to argue that AI and cybersecurity have converged into a single threat architecture, since an autonomous agent with stolen credentials can behave exactly like an authorised insider.