
Every business software vendor now has an AI story. Open any pricing page and you will find a sparkle icon, a paragraph about intelligence, and a tier that costs more. Very little of it changes what the software does.
This is not a complaint about marketing. It is a practical problem for anyone trying to buy: the word covers three genuinely different things, and they are worth very different amounts of money.
Three things that all get called AI
1. AI features
A summarise button. A tone rewriter on an email. Autocomplete in a description field. These are useful and increasingly table stakes, but they sit at the edge of the product and save seconds, not hours. If a feature only acts on the text currently in front of you, it belongs here.
Nothing wrong with it. Just don't pay ERP money for it.
2. AI as an interface
A chat box over your data. Ask "how many orders shipped late last month" and get an answer instead of building a report. This is a real improvement — reporting is a genuine bottleneck in most businesses, and removing the SQL-shaped barrier between a question and its answer matters.
But notice what it does not do: it answers questions about work. It does not do work. When the answer is "fourteen orders shipped late", something still has to chase them, and that something is a person.
3. AI that acts
The third category is different in kind. Here the AI has permission to change state in your system: raise the purchase order, draft and send the follow-up, reconcile the delivery note against the invoice, flag the project trending over budget and reassign the task.
This is the only version that removes labour rather than accelerating it. It is also the only version that requires the software to be built for it, which is why it is rare in off-the-shelf products.
Why the third kind is hard to buy
An agent that acts needs three things that a chat feature doesn't.
One data model. An agent reconciling a delivery against an invoice needs both to mean something precise and related. If purchasing lives in one product, inventory in a second and finance in a third, the agent is doing integration work before it does any useful work — and integration built on guesses about other systems' data is exactly where automation goes wrong quietly.
Real permissions. "Can draft, cannot send" and "can raise a PO under €5,000, must escalate above" are not prompt instructions. They are authorisation rules, and they belong in the same permission system that governs your human users. Bolted-on AI rarely has access to that.
An audit trail. When an agent does something wrong — and it will — you need to know what it did, on what evidence, and be able to reverse it. If the agent's actions are indistinguishable from a user's in the log, you cannot audit the automation.
Those three requirements are architectural. You cannot add them to a product later, which is why "AI-powered" versions of established software so often turn out to be category one or two.
A test you can run on any demo
Ask the vendor: what has the AI changed in the system since we started this call?
If the answer is "nothing, it summarised something for you", it is a feature. If the answer is "it answered three questions", it is an interface. If the answer names a record it created, updated or flagged — and can show you the audit entry — it is the third kind.
A follow-up worth asking: what is it not allowed to do? A vendor with a real agent layer will answer immediately and specifically, because those boundaries were decided during the build. A vague answer usually means the boundaries don't exist yet.
What this looks like in practice
The useful work for agents is repetitive, well-bounded, and evidenced in data you already hold. Chasing missing timesheets. Drafting the monthly client report from real project figures rather than from someone's memory. Watching every account for budget drift and raising it while there is still time to talk to the client. Generating the purchase requirement from the production plan, for a human to approve.
None of that is glamorous. All of it is work someone currently does on a Friday afternoon, and none of it is judgement work with consequences — which is precisely why it suits an agent. We go into where that line sits in what AI agents really automate.
The question is not whether the software has AI. It is whether the AI can do anything you would otherwise pay a person to do.
So what should you buy?
If your processes are standard and your stack is small, buy a good product with category-one and category-two AI and get on with your day. That is genuinely the right answer more often than a company like ours likes to admit, and we have written about where that line falls in custom software vs off-the-shelf SaaS.
The calculation changes when one workflow spans four products, when nobody trusts the numbers because they exist in four places, or when the work you would most like to automate is exactly the work that crosses system boundaries. At that point the constraint is not the AI. It is that there is no single system for an agent to act inside.
That is the problem divisionAI exists to solve: one system shaped around how a business actually runs, with agents operating inside it under explicit permissions. Not a sparkle icon on a form.
If you want to know what that would look like for your operation, the FAQ covers cost, timelines and ownership, or you can just book a call.


