6 min readAI Agents · Cybersecurity
What Is Agent Washing? How to Spot Fake AI Agents
By Michelle Savage, Experience Design Director, PayPal

TL;DR: Agent washing is selling rebadged chatbots, RPA flows, workflow automation, and AI assistants as "agentic AI." Gartner counts only about 130 real agentic vendors among thousands making the claim. Five technical tells expose a washed product, and seven procurement questions filter most of the fakes in 15 minutes.
Last updated October 6, 2026. This piece was rebuilt from the ground up around the tells and the procurement script, so you can run both before the next vendor meeting.
Gartner counted thousands of vendors claiming to ship agentic AI. About 130 of them actually do. The rest are chatbots, RPA tools, workflow automation, and AI assistants with the word "agent" pasted on the box. This is agent washing, and your procurement team is probably buying it right now. The damage isn't just wasted budget. It's audit exposure and security incidents that get blamed on agentic AI in general, when the actual cause was a washed product that never had agent-level controls in the first place.
What is agent washing?
The marketing practice of selling existing AI products as agentic AI without the autonomy, planning, tool use, or separate identity that define a real agent. Gartner popularized the term in mid-2025 alongside a forecast that 40 percent of agentic AI projects will be canceled by the end of 2027, mostly from vendor mismatch and unclear business value. The pattern is now so widespread that Gartner analysts called it the single biggest reason agentic projects go sideways.
And the scale is worth sitting with. If roughly 130 of thousands of vendors are real, more than 95 percent of agentic AI marketing in 2026 is washed. That's not a calibration error. It's the dominant pattern in the market, which means the right default is to treat every claim as washed until proven otherwise.
What are the five tells of a washed agent?
A real AI agent does five things a chatbot or an RPA flow can't. A product that fails any of them is washed.
Capability | A real agent | A washed product |
Tool use | Picks tools at runtime and chains them | Calls one API per turn |
Multi-step reasoning | Plans a sequence and adjusts when steps fail | Follows a fixed flow |
State persistence | Carries context across actions and sessions | Resets every time |
Bounded autonomy | Acts without per-step approval, inside a policy envelope | Needs a human click for every action |
Identity model | Has its own identity, separate from the user | Runs on the user's session token |
The last row is the one that decides audits. A product with no separable identity can't answer the first question any examiner asks, which is who did this. The whole identity layer is covered in the AI agent identity problem.
What seven questions filter the fakes in 15 minutes?
Procurement keeps buying washed products because security and architecture aren't at the table when the demo happens. Send these seven to every agentic vendor before the second meeting.
Show me a single transaction where the agent picked between three tools and chose one based on the input.
No demo means no real tool use.
What happens when a step fails mid-task?
Real agents retry, reroute, escalate, or pause for a human. Washed products error out.
How is the agent's identity provisioned, and what's its blast radius?
A real answer involves a non-human identity, scoped credentials, a policy engine, and an expiry date.
Show me an action log for a multi-step run, with the agent's reasoning at each step.
Real agents produce a reasoning trace. Washed products produce a flat API log.
What's the kill switch, and how fast does it cut?
Real agents revoke credentials and halt in-flight tasks in seconds. Washed products haven't thought about this.
What happens to the agent if the underlying model deprecates?
Real vendors have an abstraction layer. Washed products are hard-coded to one model.
Map your product to the OWASP Top 10 for Agentic Applications 2026.
Real vendors have an answer. Washed vendors don't know the framework exists.
How does agent washing show up in an audit?
Painfully, because the EU AI Act's high-risk obligations, enforceable since August 2, 2026, don't distinguish between real agents and washed ones. If the product makes a decision that affects a person's credit, employment, education, or healthcare, it's high-risk regardless of how autonomous the underlying tech is, and the deployer, meaning you, carries the liability. Penalties run up to 35 million euros or 7 percent of global turnover, a bill we broke down in AI agent regulation is already here.
Auditors now ask the same five Agentic Trust Framework questions for every system labeled "AI agent" in your stack, and a washed product fails every one. Identity isn't separable. Behavior baselining doesn't exist. Blast radius is undefined. The kill switch is theoretical. You end up paying for a washed product and then cited for it, which is the worst trade in enterprise software. The audit script is in the five questions your AI agent auditor will ask.
Frequently asked questions
Who coined the term agent washing?
Gartner popularized it in mid-2025, alongside the forecast that 40 percent of agentic AI projects would be canceled by the end of 2027. The term echoes earlier patterns like AI washing and blockchain washing.
Is every vendor that markets agentic AI washing?
No. Gartner's roughly 130 real vendors exist. The point is that the base rate of real agentic AI in 2026 marketing is low enough that you should treat every claim as washed until proven otherwise.
How do I tell washing apart from a vendor early in their roadmap?
Ask about identity and policy. Vendors building toward real agentic capability talk openly about their identity model. Washing vendors redirect to AI capabilities and avoid identity questions. The redirect is the answer.
What's the legal exposure of buying a washed product?
Under the EU AI Act's obligations, the deployer is liable for how the system is used, with penalties up to 35 million euros or 7 percent of global annual turnover. The vendor's marketing language doesn't transfer the risk.
Key takeaways
Roughly 130 of thousands of self-described agentic AI vendors ship a real agent, so treat every claim as washed until proven.
The five tells: runtime tool choice, multi-step reasoning, state persistence, bounded autonomy, and a separable identity.
Seven procurement questions filter most fakes in 15 minutes, and question three, about identity and blast radius, does the most work.
Regulators don't care whether the agent was real. The deployer carries the liability either way.
A washed product fails all five Agentic Trust Framework questions, which means it fails your audit too.
Before you evaluate any vendor, know what you need them to cover. The free self assessment takes about ten minutes and shows which of the five elements your stack is missing.
The vendors who can answer the identity question were building agents before the word was fashionable. The ones who redirect to a demo were building something else, and no rebrand changes what's under the box.