The moment an AI agent gets tool access, it stops being a chatbot.

It becomes an actor inside the system.

That actor may be able to search documents, query databases, create tickets, update CRM records, send messages, trigger workflows, or call APIs.

This is where the security model changes.

A text-only assistant is mostly an information risk.