# AI agents, each with a job and a person in charge

We build, connect and run AI agents for marketing, sales, customer service, finance, operations, IT, legal and people teams, and for insurers, financial firms and healthcare providers.

Each agent does one set task inside the systems you already use, and hands the decisions that matter to a person. We advise on where agents pay for themselves, build them, and run them.

[Plan your first agent](https://gateway-global.co.uk/contact/engineering/) See the agents by team

Last updated 26 September 2026

## Agents by team

Start with one task that costs your team time every week. Each agent below names what it does and what a person still decides.

### Marketing

- **Marketing content agent**
   Drafts campaign copy, emails and posts in your brand voice.
   A person approves: Every piece, before it is published.
- **AI search visibility agent**
   Tracks how AI assistants describe your brand, and suggests content changes.
   A person approves: Any change to your content.

### Sales and CRM

- **Sales research agent**
   Researches target accounts and drafts outreach for your sales team.
   A person approves: Every message, before it is sent.
- **Lead qualification agent**
   Qualifies inbound enquiries, books meetings and updates your CRM.
   A person approves: The rules it qualifies by, and any enquiry it is unsure of.
- **CRM data quality agent**
   Finds duplicate and incomplete records, and keeps your CRM accurate.
   A person approves: Merges and deletions.

### Customer service

- **Customer service agent**
   Answers customer questions by chat and email, and passes complex cases to your team.
   A person approves: Refunds, exceptions and anything it is unsure of.
- **Voice agent**
   Answers calls, books appointments and records a summary of every call.
   A person approves: Calls it cannot resolve go straight to your team.
   For healthcare, this is [Prime Assist](https://gateway-global.co.uk/products/prime-assist/).

### Finance and operations

- **Finance operations agent**
   Reads supplier invoices, matches them to orders and flags exceptions.
   A person approves: Payments and exceptions.
- **Document intake agent**
   Extracts data from forms, letters and PDFs into your systems, with checks.
   A person approves: Any field it reads with low confidence.

### IT and knowledge

- **IT help desk agent**
   Resolves routine IT requests, such as access and password resets, and logs tickets.
   A person approves: Access to sensitive systems.
- **Knowledge search agent**
   Answers staff questions from your own documents, with sources.
   A person approves: Who can see what. Each person gets answers only from what they may read.

### Legal and people

- **Contract review agent**
   Checks contracts against your playbook and marks clauses for legal review.
   A person approves: A lawyer signs off every contract.
- **Recruitment coordination agent**
   Schedules interviews, answers candidate questions and prepares onboarding.
   A person approves: Every hiring decision stays with people. It never screens or ranks candidates.

Need an agent for something else? [Tell us the task](https://gateway-global.co.uk/contact/engineering/). Code review has its own product, [Gateway Assay](https://gateway-global.co.uk/products/gateway-assay/).

## Agents for your sector

Some tasks belong to one sector: a claim in insurance, a financial crime alert in a bank, a referral letter in a GP practice. Each sector's page names its agents, what a person decides, and the systems they connect to.

- **[NHS and public sector](https://gateway-global.co.uk/industries/nhs/)**
   - [Clinical correspondence agent](https://gateway-global.co.uk/industries/nhs/#clinical-correspondence-agent)
   - [Online requests agent](https://gateway-global.co.uk/industries/nhs/#online-requests-agent)
   - [Waiting list validation agent](https://gateway-global.co.uk/industries/nhs/#waiting-list-agent)
   - [Referral intake agent](https://gateway-global.co.uk/industries/nhs/#referral-intake-agent)
- **[Private healthcare](https://gateway-global.co.uk/industries/private-healthcare/)**
   - [Recall and reminders agent](https://gateway-global.co.uk/industries/private-healthcare/#recall-agent)
   - [Treatment plan follow-up agent](https://gateway-global.co.uk/industries/private-healthcare/#treatment-plan-agent)
   - [Insurer authorisation and billing agent](https://gateway-global.co.uk/industries/private-healthcare/#insurer-authorisation-agent)
   - [Group reporting agent](https://gateway-global.co.uk/industries/private-healthcare/#branch-reporting-agent)
- **[Insurance and payers](https://gateway-global.co.uk/industries/insurance/)**
   - [Claims intake agent](https://gateway-global.co.uk/industries/insurance/#claims-intake-agent)
   - [Claims triage agent](https://gateway-global.co.uk/industries/insurance/#claims-triage-agent)
   - [Claims integrity review agent](https://gateway-global.co.uk/industries/insurance/#claims-integrity-agent)
   - [Recovery and subrogation agent](https://gateway-global.co.uk/industries/insurance/#recovery-agent)
   - [Underwriting submission agent](https://gateway-global.co.uk/industries/insurance/#submission-intake-agent)
   - [Policy wording agent](https://gateway-global.co.uk/industries/insurance/#wording-comparison-agent)
   - [Bordereaux and delegated authority agent](https://gateway-global.co.uk/industries/insurance/#bordereaux-agent)
   - [Prior authorisation agent](https://gateway-global.co.uk/industries/insurance/#prior-authorisation-agent)
   - [Policyholder service agent](https://gateway-global.co.uk/industries/insurance/#policyholder-service-agent)
   - [Customer outcomes agent](https://gateway-global.co.uk/industries/insurance/#customer-outcomes-agent)
- **[Financial services](https://gateway-global.co.uk/industries/financial-services/)**
   - [Onboarding and KYC agent](https://gateway-global.co.uk/industries/financial-services/#onboarding-kyc-agent)
   - [Financial crime alert agent](https://gateway-global.co.uk/industries/financial-services/#financial-crime-alert-agent)
   - [Scam and fraud case agent](https://gateway-global.co.uk/industries/financial-services/#scam-case-agent)
   - [Complaints handling agent](https://gateway-global.co.uk/industries/financial-services/#complaints-handling-agent)
   - [Service voice agent](https://gateway-global.co.uk/industries/financial-services/#banking-voice-agent)
   - [Payment data agent](https://gateway-global.co.uk/industries/financial-services/#payment-data-agent)
   - [Business credit paper agent](https://gateway-global.co.uk/industries/financial-services/#credit-paper-agent)
   - [Reconciliation agent](https://gateway-global.co.uk/industries/financial-services/#reconciliation-agent)
   - [Regulatory change agent](https://gateway-global.co.uk/industries/financial-services/#regulatory-change-agent)

## How we build agents

Advise, build and run, in four steps, so you see results before you commit to more.

1. **Choose the task**
   An AI readiness assessment: the task, your data, the risks and what a person must approve, with a costed plan.
2. **Pilot it**
   A fixed-scope pilot on real work, measured against how the task is done today.
3. **Connect it to your systems**
   Salesforce, your CRM, email, phones and document stores, through their own interfaces and MCP.
4. **Run and improve it**
   We monitor it, review its logs, test every change and report what it has done.

## How do agents connect to your systems?

Through Model Context Protocol (MCP) servers that we build and harden for your own systems. People reach them through your own sign-in, each agent signs in as itself, and each uses only the tools and permissions your security lead has signed off.

What is changing in agent standards

- **MCP servers for your own systems**
   We build MCP servers for the systems you run, such as your CRM, case system or document store, and harden any you already have. We work to the current specification, published on 28 July 2026: its tighter authorisation rules, servers that sit behind your usual load balancers and gateways, and tool calls that wait for a person to confirm them where the task needs it.
   Source: [MCP specification 2026-07-28: key changes](https://modelcontextprotocol.io/specification/2026-07-28/changelog)
- **Access set in your identity provider**
   With MCP's enterprise-managed authorisation, stable since June 2026, access to your MCP servers is set in your identity provider, alongside the rest of your staff's access. Each person authorises once, and you keep one record of who connected to which server. Support among identity providers is still limited, so we check yours before we plan on it, and use its standard sign-in where it does not yet offer this.
   Source: [MCP blog: enterprise-managed authorisation](https://blog.modelcontextprotocol.io/posts/enterprise-managed-auth/)
- **Agents that sign in as themselves**
   Each agent signs in as itself, never through a shared service account or a long-lived key. Its permissions are scoped to its task and short-lived, it can call only the tools on its allow-list, and it can send data only to destinations you have approved. We build this on the OAuth and workload identity your platforms already use, because shared standards for agent identity are still drafts.
- **Working with other organisations' agents**
   When your agent must deal with another organisation's agent, a supplier's or a customer's, we connect the two through version 1.0 of the Agent2Agent protocol (A2A), released in March 2026, with OAuth or mutual TLS so each side can check who it is dealing with. You choose which outside agents yours may talk to. Who answers for what between the two organisations is agreed in your contract with them, which your legal advisers draw up, and every exchange is logged.
   Source: [A2A releases on GitHub](https://github.com/a2aproject/A2A/releases)
- **Systems and data ready for agents**
   Where a system has no clean way in, we build one: documented APIs and MCP endpoints over data that is tidy and described, on open standards, so a change of agent or model supplier need not mean a new connection. Your data owner chooses what each interface exposes.

A person approves: Your security lead signs off the tools each agent may call and the permissions it holds before it goes live, and again before either changes.

## In control from the first day

Agent governance is built into every agent we deliver, so you can show your board, your customers and your auditors what each one does.

[Assurance for AI you already run](https://gateway-global.co.uk/services/ai-assurance/)

- **A person approves what matters**
   Every agent has a named checkpoint: the decisions it must hand to a person, written down before it goes live.
- **Every action logged**
   What each agent read, decided and did is recorded, so it can be reviewed, explained and shown to auditors.
- **Tested before launch and after every change**
   We test each agent on real examples of its task, and again whenever its model, instructions or tools change.
- **Only the access it needs**
   Each agent gets the smallest set of permissions its task needs, and nothing more.
- **Data stays where it should**
   Agents can run on your own infrastructure or in the region your data must stay in, with Prime Edge AI deciding where each request is answered.
   [About Prime Edge AI](https://gateway-global.co.uk/technology/prime-edge-ai/)
- **People know it is an AI**
   Agents that talk to people say they are an AI, and offer a person when one is needed.

## The rules we build to

We check where each rule stands at the start of every project, and work alongside your legal advisers rather than giving legal advice.

- **The EU AI Act**: People must be told when they are talking to an AI, and AI-generated content must be marked. Some uses, such as screening job candidates or scoring people for credit, are high risk.
- **Automated decisions**: Under UK and EU GDPR, decisions with legal or similarly significant effects on people need safeguards and a route to a person.
- **Calls and messages**: Consent rules for automated calls and marketing: PECR in the UK, the TCPA in the US, and the UAE rules on telemarketing hours and do-not-call registers.
- **Healthcare**: Agents that touch patient care are built under DCB0129 clinical safety, with the medical device rules checked for each market.

## Where are AI agents going next?

The technology under agents is settling into open standards, and the rules around them are arriving on fixed dates. What is in use now, and what is coming, with the source for each.

### In use now

- **One open standard for connecting agents to tools**
   The Model Context Protocol (MCP) now sits with the Agentic AI Foundation, a neutral home under the Linux Foundation. Its July 2026 specification hardened authorisation and lets servers run behind ordinary gateways, and a company's own identity provider can now decide which MCP servers each person may reach.
   Sources: [MCP joins the Agentic AI Foundation](https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/) (Model Context Protocol, 2025); [The 2026-07-28 specification](https://blog.modelcontextprotocol.io/posts/2026-07-28/) (Model Context Protocol, 2026); [Enterprise-managed authorization: zero-touch OAuth for MCP](https://blog.modelcontextprotocol.io/posts/enterprise-managed-auth/) (Model Context Protocol, 2026)
- **Agents talking to agents**
   The Agent2Agent protocol (A2A) reached version 1.0 in March 2026 and joined the same foundation in August 2026. MCP connects an agent to tools and data; A2A connects agents to one another, including across organisations.
   Sources: [A2A releases](https://github.com/a2aproject/A2A/releases) (A2A project on GitHub, 2026); [A new chapter for A2A: joining the Agentic AI Foundation](https://a2a-protocol.org/latest/blog/2026/08/27/a-new-chapter-for-a2a-joining-the-agentic-ai-foundation/) (A2A Protocol, 2026)
- **Security lists now cover agents**
   OWASP's 2026 Top 10 for LLM applications keeps prompt injection first and moves excessive agency, an agent allowed to do more than its task needs, up to third. A separate OWASP Top 10 covers agentic applications: goal hijacking, tool misuse and privilege abuse among them.
   Sources: [OWASP GenAI LLM Top 10 2026](https://github.com/GenAI-Security-Project/GenAI-LLM-Top10) (OWASP GenAI Security Project, 2026); [OWASP Top 10 for Agentic Applications](https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/) (OWASP GenAI Security Project, 2025)
- **New UK rules on automated decisions**
   Since 5 February 2026, UK GDPR, as amended by the Data (Use and Access) Act 2025, allows significant automated decisions with safeguards, including information for the person, a route to human review and the right to contest. Health and other special category data keep tighter limits.
   Sources: [Data (Use and Access) Act 2025, section 80](https://www.legislation.gov.uk/ukpga/2025/18/section/80) (legislation.gov.uk, 2025); [The Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026](https://www.legislation.gov.uk/uksi/2026/82/regulation/5/made) (legislation.gov.uk, 2026)

### Coming next

- **EU high-risk rules from December 2027**
   Under the EU AI Act, as amended in July 2026, AI used in hiring, credit decisions about people and life and health insurance pricing is high-risk from 2 December 2027, and AI inside regulated products such as medical devices from 2 August 2028.
   Sources: [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng) (EUR-Lex, 2026); [AI Omnibus enters into force](https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force) (European Commission, 2026)
- **An identity for every agent**
   NIST launched an AI Agent Standards Initiative in February 2026, and IETF drafts build agent authentication on OAuth and workload identity. Each agent is heading for its own identity with short-lived, scoped permissions, rather than a shared key. These are still drafts, not settled standards.
   Sources: [Announcing the AI Agent Standards Initiative](https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure) (NIST, 2026); [AI agent authentication and authorisation (draft-klrc-aiagent-auth)](https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/) (IETF, 2026)
- **A common format for agent logs**
   OpenTelemetry's conventions for generative AI now describe agent steps, tool calls and MCP calls, so one agent's actions can be traced in the monitoring tools a company already runs. They are still in development and names may change.
   Source: [OpenTelemetry semantic conventions for generative AI](https://github.com/open-telemetry/semantic-conventions-genai) (OpenTelemetry on GitHub, 2026)
- **AI management systems, audited**
   ISO/IEC 42006:2025 sets the rules for bodies that certify organisations against ISO/IEC 42001, the AI management system standard, and ISO/IEC 42005:2025 covers AI impact assessments. Buyers are starting to ask suppliers where they stand against them.
   Sources: [ISO/IEC 42006:2025](https://www.iso.org/standard/42006) (ISO, 2025); [ISO/IEC 42005:2025](https://www.iso.org/standard/42005) (ISO, 2025)

Checked against these sources on 26 September 2026. Rules and dates change: we check them again at the start of every project.

## Questions people ask

**Will agents take over our team's jobs?**

They take on set, repetitive tasks, so your team spends its time on the work that needs people. A person stays responsible for each agent, and approves the decisions that matter.

**Which systems do they work with?**

The ones you already use, including Salesforce, your email and phone systems, and your document stores. We connect them through the systems' own interfaces and the Model Context Protocol (MCP), an open standard for connecting AI to tools.

**Where does our data go?**

Only where you allow. Agents can run on your own infrastructure or in a region you choose, and each one can reach only the data its task needs.

**How do we start?**

With an AI readiness assessment: a fixed-price review of the task, your data and the risks, with a costed plan. Then a pilot with a fixed scope, measured against how the task is done today.

**How is it priced?**

The readiness assessment and the pilot are fixed-price. Once an agent is live, we run it as a monthly service.

**Do you build agents for healthcare?**

Yes. For calls, Prime Assist is our AI voice infrastructure for healthcare. Every health agent is built under DCB0129 clinical safety, with our Clinical Safety Officer. If you deploy an agent in your practice or trust, we also support your own DCB0160 safety case.

## Pick one task. We will build the agent for it.

[Plan your first agent](https://gateway-global.co.uk/contact/engineering/) [See digitisation and Salesforce](https://gateway-global.co.uk/services/digitisation/)

---

Source: https://gateway-global.co.uk/ai-agents/
Updated: 2026-09-26
