Generative AI and Agentic AI
Syllabusbasics of cyber security
Generative AI produces new content, such as text, images, audio or code, by learning patterns from data. Agentic AI is an AI system that pursues a goal through multiple steps, selecting actions, using tools and adapting to results with some operational autonomy. An agentic system may use a generative model for reasoning or communication, but the two terms are not synonymous.
Core distinction
The distinction concerns the system's primary function and degree of autonomy. Generative AI mainly creates synthetic content in response to an input, whereas agentic AI converts objectives into goal-directed action.
- Generative AI usually follows a prompt and returns an output, while agentic AI can plan and execute a sequence of tasks.
- Generative AI is principally a model capability; agentic AI is generally a broader system combining models, software and external resources.
- An agent monitors outcomes and may revise its plan, while a basic generative application need not maintain goals or act on its own outputs.
How an agentic system operates
An agent commonly combines a model with planning, memory, feedback mechanisms and access to external tools such as databases, application programming interfaces or software environments.
- It receives an objective, decomposes it into tasks and selects actions.
- It can observe the results of actions and alter subsequent steps.
- Its autonomy is bounded by permissions, available tools, programmed constraints and human oversight.
- Multiple specialised agents may coordinate, although multi-agent design is not essential to agentic AI.
Cyber-security significance
Generative AI can scale deceptive content, impersonation and insecure code generation. Agentic AI adds execution risk because compromised instructions may trigger actions through connected tools, accounts or systems.
- Agentic systems expand the attack surface through credentials, memory, plug-ins and external interfaces.
- Prompt injection or manipulated data can redirect an agent's decisions and cause cascading actions.
- Controls should include least-privilege access, tool allow-lists, logging, human approval for high-impact actions and continuous monitoring.
- The same capabilities can support defenders by automating triage and response, but accountability should remain with human organisations.
How UPSC asks this
UPSC may ask candidates to distinguish content generation from autonomous action and evaluate how agentic systems alter cyber threats, attack surfaces, oversight and accountability.
Keep reading
The news behind topics like this, explained every morning
Every morning Gyaanam reads The Hindu, the Indian Express and PIB and picks what matters for UPSC. Each story is written up against the syllabus line it belongs to. Your first 15 days are free.