Post 4 of 8
Types of AI agents: where they run and how they're built
Agents differ along three axes: where they run (chat, IDE, terminal, cloud, CI), how they're built (workflow, single agent, orchestrator with workers) and how much they may do without a human. We go through each axis with Claude Code, Codex, Cursor and Copilot.
Alexander Mihalkevich · Fact-checked October 5, 2026 · 5 min read
Today the word “agent” is applied to everything, from a chatbot to a system that writes code for a week without a human. To keep things straight, it helps to place agents on three independent axes: where the agent runs, how it is built, and how much it is allowed to do on its own.
Axis 1. Where the agent runs
Chat assistant. It answers with text, and you carry out the actions: you copy the code and run the commands. This is not yet an agent in the strict sense: it has no tools to act with on its own.
Agent in the IDE or terminal. It runs on your machine, in the project folder: it reads files, edits code, runs commands and tests. Examples are Agent mode in Cursor, Claude Code, Codex CLI. The Claude Code documentation calls this agentic coding: the AI reads files, runs commands and makes changes on its own, while you watch, correct course or step away.
Cloud (background) agent. It runs in a separate virtual machine with a clone of the repository and delivers a result, usually a pull request. You can turn your computer off. Examples:
- Cloud Agents in Cursor: isolated VMs with a full environment; launched from the desktop app, the web, Slack or a
@cursorcomment on GitHub; - Codex Cloud: tasks in OpenAI's cloud;
- Copilot cloud agent: you assign an issue to Copilot, the agent works in an environment based on GitHub Actions and prepares changes in a branch;
- Claude Code cloud sessions: launched from claude.ai/code or with the
claude --cloudcommand.
Agent in CI. It is triggered by an event: a new issue, a PR comment, a schedule. Claude Code GitHub Actions responds to a @claude mention, and the non-interactive claude -p or codex exec mode fits into any pipeline.
Axis 2. How the agent is built
In Building effective agents, Anthropic distinguishes workflows, where the model and tools follow paths defined in code, from agents, where the model directs the process and its choice of tools itself. The building block for both is the “augmented LLM”: a model with retrieval, tools and memory.
Workflow patterns:
- Prompt chaining: the task is split into steps, each call processes the output of the previous one, and you can put programmatic checks between steps.
- Routing: the input is classified and sent to a specialized branch.
- Parallelization: independent parts run at the same time, or one task is solved several times and the results are compared by voting.
- Orchestrator and workers: a central model dynamically breaks down the task, hands parts out to workers and combines the result.
- Evaluator and optimizer: one model generates, another evaluates and sends it back with feedback, in a loop.
An autonomous agent works in a loop: it gathers context, acts, checks the result and repeats until the task is solved. The Claude Code documentation describes this agentic loop in exactly these terms.
Multi-agent systems
An orchestrator with workers is the basis of multi-agent setups. Anthropic describes its research system: a lead agent on Claude Opus 4 with subagents on Claude Sonnet 4 outperformed a single agent on Opus 4 by 90.2% on an internal evaluation. The price is tokens: agents use about 4 times more tokens than ordinary chat, and multi-agent systems about 15 times more. The same article adds a caveat: the setup is a poor fit for tasks where all agents need shared context and there are many dependencies between parts. According to the authors, this applies to most programming tasks.
Axis 3. How much the agent may do without a human
Autonomy is a setting, not a property of the product. In Claude Code these are the permission modes: from plan, where the agent only reads and proposes a plan, through default (confirming every action) and acceptEdits, to auto, where a separate classifier model checks the actions, and bypassPermissions, only for isolated containers and VMs. In Codex the same role is played by the sandbox mode (read-only, workspace-write, danger-full-access) and the approval policy.
OWASP points out that excessive agency is a separate class of vulnerabilities: excessive functionality, excessive permissions, and high-impact actions without human review.
How to choose
| Situation | What fits |
|---|---|
| The steps are known in advance | Workflow: chaining or routing |
| You need to see and steer every action | Agent in the IDE or terminal |
| The task is long, self-contained, with a clear check | Cloud agent |
| Reacting to events in the repository | Agent in CI |
| Many independent parts and a token budget | Orchestrator with workers |
The rule from the same Anthropic article: pick the simplest solution and add complexity only when the simple one stops being enough.
Agents you build yourself
If off-the-shelf products don't fit, you can build an agent on an SDK:
- Claude Agent SDK (Python and TypeScript) gives you the same harness as Claude Code: tools, context, permissions. See the Agent SDK overview.
- OpenAI Agents SDK is built on a few primitives: agents with instructions and tools, handoffs between agents, guardrails for checking input and output, and built-in tracing. See the documentation.
The sixth post covers what you need to get such an agent of your own, and the eighth covers how a fleet of several agents works.
Terms in this post
Practise it in
Sources
- Anthropic — Building effective agents
- Anthropic — How we built our multi-agent research system
- Claude Code — Glossary
- Claude Code — Choose a permission mode
- Cursor — Cloud Agents
- OpenAI — Codex Cloud
- GitHub Docs — About Copilot cloud agent
- Claude Code — GitHub Actions
- OpenAI Agents SDK
- OWASP — LLM06:2025 Excessive Agency
