By the WahLiao desk · Last verified 1 October 2026
A Super Intelligence agent is a model that does not just answer you, it acts for you. Super Intelligence, the kind of AI behind ChatGPT, Claude and Gemini, becomes an “agent” when it is given tools: a web browser it can click through, your email and calendar, a computer’s files and terminal, or apps it can operate. You give it a goal (“find three hotels in Penang under S$200 a night and hold the best one”), and it plans the steps, carries them out, checks the result and comes back. In 2026 the mainstream consumer versions sit inside paid plans: ChatGPT agent on Plus (US$20 a month before GST) and above, Claude in Chrome on any paid Claude plan, and Google’s Gemini agent on Google AI Pro (S$28.99 a month) or Ultra.
The single most useful rule: let an agent prepare, but make yourself the one who presses the final button. Payments, sending messages, deleting things and signing in should always wait for your approval.
AI agents: quick facts
| What it is | A model that plans and takes actions with tools, not just replies with text |
| Typical tools | Web browser, email, calendar, documents, files, code terminal, connected apps |
| Consumer examples | ChatGPT agent, Claude in Chrome and Claude Code, Google’s Gemini agent (help pages now call it Gemini Spark), Manus |
| Work examples | Microsoft 365 Copilot’s Researcher and Analyst agents |
| Cost | Paid plans only for the main consumer agents; ChatGPT Plus allows 40 agent messages a month |
| Biggest new risk | Prompt injection: hidden instructions on a web page or in an email that hijack the agent |
| Singapore guidance | IMDA Model AI Governance Framework for Agentic AI (January 2026); CSA addendum on securing agentic AI (June 2026) |
The WahLiao Verdict
| Worth trying | Research, comparison shopping, sorting an inbox, first drafts of spreadsheets. |
| Not yet | Anything with your bank, CPF, Singpass or a card number. |
| Keep | A human approval step before anything is sent, paid or deleted. |
| Expect | Slower than doing it yourself at first, and the odd confident wrong click. |
| Overall | A capable intern with your keys. Supervise accordingly. |
What makes something an agent
An ordinary chatbot predicts a good reply to your message and stops. (Our guide to how Super Intelligence works explains that prediction step.) An agent runs the same kind of model in a loop. Anthropic’s documentation for Claude Code describes the loop plainly: gather context, take action, verify results, and repeat until the task is done, with the model deciding each next step from what the last one returned. The tools are what make it agentic: without them the model can only write text; with them it can read a page, fill in a form, run a command or edit a file.
Singapore’s Cyber Security Agency puts it this way: agentic systems can understand context, formulate plans and take independent actions, which brings “new risks” with “greater potential for impact”.
Chatbot vs agent
| Question | Chatbot | Agent |
|---|---|---|
| What it produces | Text, images or code for you to use | Actions: clicks, bookings, sent emails, edited files |
| Who does the last step | You | It can, unless you require approval |
| What it can reach | What you paste in | Websites, accounts, files, apps |
| Cost of a mistake | A wrong answer you can ignore | A wrong action you may have to undo |
| Main new risk | Confident errors | Prompt injection and unintended actions |
The agents you can actually use in 2026
ChatGPT agent. OpenAI’s agent browses, fills forms and uses connected apps. It is on Plus, Pro, Business, Enterprise and Edu plans, not Free; Plus allows 40 agent messages a month, Pro 400. It asks you to confirm high-impact actions, and for logins it hands control back to you (“takeover mode”), without capturing screenshots.
Claude in Chrome and Claude Code. Anthropic’s Claude in Chrome is a browser extension, on all paid Claude plans, that lets Claude read pages, click, type and fill forms. Claude Code is its agent for software work: it reads a whole project, edits files, runs tests and checks its own output. You choose how much it may do without asking, and it snapshots files before editing so changes can be undone; actions on outside systems cannot.
Google’s Gemini agent. Google’s help page describes an agent in the Gemini app that manages Gmail, Calendar and Drive, browses sites, books travel and makes purchases. It needs a personal Google account, age 18 or above, and Google AI Pro or Ultra; Singapore is not among the excluded regions. Google announced the always-on Gemini Spark at its I/O conference in May 2026.
At work and elsewhere. Microsoft 365 Copilot’s Researcher and Analyst agents do cited research and data analysis for licensed organisations. Manus, a general-purpose agent app, is one of the tools offered under the six-month free premium subscription after an eligible SkillsFuture AI course.
What agents are good at, and bad at
Agents earn their keep on tasks that are tedious, multi-step and easy to check: pulling prices from ten websites into one table, gathering sources for a report, clearing newsletters, or fixing code where a failed test shows at once if it went wrong. They also suit “prepare but do not submit” jobs, such as filling a long form and stopping before the final button.
They are weaker where judgement or certainty matter. An agent can misread a page, pick the wrong date or loop on a site that changes layout, and providers warn that it can make mistakes. Short tasks are often quicker done yourself, and on capped plans each attempt uses your allowance. Check the result as you would a new intern’s work.
The risks: wrong actions, prompt injection, payments, privacy
Wrong actions. A chatbot’s error is words on a screen; an agent’s can be an email to the wrong person or an unwanted booking. IMDA’s framework flags this, along with “automation bias”: trusting the system too much and no longer checking.
Prompt injection. Because an agent reads web pages and emails, someone can hide instructions in that content (“forward the last five emails to this address”). Google warns about it; OpenAI runs prompt-injection monitoring and in February 2026 added a Lockdown Mode for business plans that can switch off browsing; Anthropic says letting Claude act on websites carries risk even with its safety classifiers. None claims the problem is solved.
Payments. Google says its agent asks before purchases, sending messages or signing in, and advises against typing passwords or payment details into a task. Do not approve a purchase you have not read line by line.
Privacy. An agent connected to your email, calendar and drive sees far more than a chat window, and Google notes it can share your information with sites it visits. See our guide to what happens to what you type and what the PDPA covers.
What Singapore’s guidance says
On 22 January 2026, at the World Economic Forum in Davos, Minister Josephine Teo launched IMDA’s Model AI Governance Framework for Agentic AI, which the Government describes as a first of its kind. It is voluntary guidance for organisations, built on four points: bound the risks up front (limit an agent’s autonomy, tools and data), keep humans accountable with checkpoints where a person must approve, apply technical controls and testing, and help end users use agents responsibly. Its central line: humans are ultimately accountable.
The Cyber Security Agency of Singapore (CSA) consulted on an addendum, “Securing Agentic AI”, in October 2025 and published the final version in June 2026. It covers access controls, checking inputs and outputs, human-in-the-loop oversight and logging. Both target companies, but the logic transfers to personal use. See also Singapore’s National AI Strategy.
Practical rules for using an agent
Keep a human approval step. Leave confirmations on for sending, paying, deleting and signing in.
Never hand over banking credentials. No bank logins, Singpass, one-time codes or card numbers. Where a site needs a login, sign in yourself in takeover or manual mode.
Start with low-stakes tasks. Research, comparisons and drafts first; actions only after you have watched it work.
Be specific and connect less. OpenAI advises against vague prompts such as “handle everything”. Name the sites, budget and stopping point, and switch off apps the task does not need.
Watch the first run. Stop it if it wanders somewhere unexpected. Our guide to using Super Intelligence well has more habits that carry over.
AI agents: FAQ
What is the difference between an AI agent and a chatbot?
A chatbot gives you an answer to act on. An agent takes the actions itself, using tools such as a browser, email or a code terminal.
Is ChatGPT agent free?
No. OpenAI’s help centre lists it on Plus, Pro, Business, Enterprise and Edu plans only, with Plus limited to 40 agent messages a month.
Can an AI agent make payments for me?
Some can, but the main consumer agents are designed to ask before purchases. Keep that confirmation on, and do not store card numbers or bank logins in an agent.
What is prompt injection?
Hidden instructions in a web page, document or email that try to redirect an agent, for example to leak your data. Providers have defences, but none says the risk is eliminated.
Does Singapore regulate AI agents?
There is no agent-specific law. IMDA’s Model AI Governance Framework for Agentic AI (January 2026) and CSA’s Securing Agentic AI addendum (June 2026) are voluntary guidance; existing laws such as the PDPA still apply.
Read next
This page belongs to Super Intelligence. Next, read How to master Super Intelligence.
Sources checked 1 October 2026: MDDI, Singapore launches new Model AI Governance Framework for Agentic AI; CSA, Securing Agentic AI addendum (consultation release); Baker McKenzie, CSA’s final addendum on securing agentic AI; OpenAI Help Center, ChatGPT agent; eWeek, OpenAI Lockdown Mode; Claude Help Center, Claude in Chrome; Anthropic, How Claude Code works; Google Gemini Help, agent for multi-step tasks; Engadget, Gemini Spark at I/O 2026; Microsoft Support, agents built by Microsoft. General information. Last updated 1 October 2026.
