The expensive part of your AI agent is not the model

For many AI-agent projects, a useful working hypothesis is that the model may be the more interchangeable part. The durable work is connecting that agent to the company’s identity, permissions, APIs, databases and business rules so it can take a useful action without taking an unauthorized one.

Editorial illustration of an AI system connected to identity, CRM, ERP, database and API services, with the integration layer illuminated.

By Reynier RiveroSoftware engineer

It answered a question from a carefully prepared document, in a clean interface, with a response that sounded almost suspiciously competent.

Then the operations manager asked for the next step.

“Can it check the customer’s account?”

The room changed temperature.

Salesforce needed authentication. The ERP had an API nobody had touched in three years. The inventory database used a field called available_qty, even though half the team called it “stock”. The invoice action had a business rule hidden in a spreadsheet.

Disclosure: the opening scene is composite and hypothetical.

The model had been the easy part.

As an engineering hypothesis, it was also the part the team could plausibly swap as requirements or providers changed.

The demo ends where the project starts

On 8 September 2026, Accenture and Google Cloud announced a new Gemini Enterprise business group and said it would establish a 1,000-person workforce of forward-deployed engineers to help enterprises scale agentic AI. The operational emphasis is the useful signal here.

That is a market signal, not a universal rule.

One interpretation is that when the model is the headline but a thousand engineers are sent into the field, the product may be the layer that makes the conversation useful.

The real cost appears in the layer around the model

The cost is not a single line item. It appears in the integration work around the model: connecting to a CRM, ERP or legacy API; defining permissions and authentication; adding observability and safe retries; handling data, security and compliance; and maintaining the system with clear ownership after launch.

The UK Business Data Survey 2026 reported that, among businesses using AI, 21% said their tools were integrated into existing business systems; the figures were 57% for large businesses and 31% for small businesses. The survey was published on 18 June 2026 and covered businesses surveyed between October 2025 and January 2026.

The figures do not show that the remaining businesses have failed. They point to a practical distinction: using AI and connecting AI are different stages of adoption.

The first stage drafts an email.

The second finds the right customer, checks a rule, updates a record, asks for approval and leaves an audit trail.

That second stage is where software engineering returns to the center of the conversation.

The four questions the model cannot answer for you

An agent connected to a business needs a clear answer to four questions.

What can it see?

Give it the minimum data needed for the task. A support agent may need order status and delivery ZIP code; it may not need the customer’s full billing history or every internal note.

What can it do?

Reading a CRM record and changing a CRM record are different capabilities. Tool permissions should distinguish read_customer, create_ticket, issue_refund and delete_customer, not collapse them into “CRM access”.

Who approves the dangerous parts?

Sending a routine appointment confirmation may be automatic. Issuing credit, changing a contract or sending an email to a regulator may need a human approval gate.

What happens when a system changes?

APIs add fields. Vendors retire models. Policies change. A production agent needs versioned prompts, tool contracts, regression tests and observability that records the action without leaking the customer’s PII into logs.

The system prompt is not an access-control system.

As a comparison, the UK Business Data Survey 2026 found that, among businesses using AI, 21% said their tools were integrated into existing business systems. The UK figure is not a US benchmark, but it reinforces the same practical distinction: using AI is easier than connecting it safely to the systems, permissions and rules that make it useful.

The business lesson

If a vendor shows you a beautiful agent, ask what sits behind the button.

Which identity provider does it use? Which systems does it call? Can the access be revoked? Is the response grounded in a versioned source? Can you replay the action after an incident?

The model is the voice. The integration is the operating system.

If those answers are unclear, the next purchase should probably not be another model license. It should be a short architecture exercise that maps the workflow, the data and the actions that are genuinely worth automating.

Prontavel helps teams design and build that layer through AI agents that can use business tools, automation and API integrations and custom software when the existing stack has reached its limit. If your current agent can answer but cannot safely complete a task, that is a useful place to start the conversation.

The service this article is about: Stop moving data by hand

Kickoff in 1-2 weeks

Tell us what you need

We reply with a written scope and a price range, not a sales pitch.