How it works
Agentic AI systems break database assumptions: agents run long, interleaved, uncertain tasks, so databases must become memory and coordination substrate. They should capture events, provenance, embeddings, permissions, and reversible state, not just current truth. Queries become context negotiation, not deterministic lookup. Systems need snapshots, branchable state, audit trails, and concurrency control that tolerates partial failure. Tools must become typed capabilities with explicit contracts, side-effect boundaries, idempotency, sandboxing, cost limits, and observability. Agents must know when a tool is safe, what it costs, and how to recover.
Also worth reading: How Should Organizations Control Agentic AI Systems in 2026? · What Is an Agentic AI Control Plane, and How Should Enterprises Choose One? · How Do Enterprise Teams Build and Implement an Agentic AI Control Architecture in Production?
Control loops must move beyond linear prompts into bounded sense-plan-act-evaluate cycles. That means budgets for time, tokens, money, and risk; clear termination and escalation rules; reflection checkpoints; and human approval where consequences are high. Evaluation cannot wait for final output—it must run continuously against traces, simulations, and feedback. The goal is not autonomy at any cost but reliable delegation: agents that operate over messy state, compose tools safely, and stop or ask for help when confidence drops. Databases, tools, and loops then form one integrated architecture for bootstrapping agentic products.
What it costs
Agentic AI violates implicit assumptions of database design: static schemas, request-response queries, and human-speed transactions. Databases must become dynamic state stores with append-only event logs, provenance, semantic indexing, and transactional memory so agents can checkpoint intent, recover from failure, and coordinate concurrent actions without corrupting truth. Retrieval is not enough; systems need versioned facts, confidence scores, and rollback-aware writes. Tools should be redesigned as constrained capabilities, not loose APIs: typed contracts, explicit permissions, idempotency, dry-run modes, and observable side effects. Every tool call should emit telemetry and be replayable, auditable, and interruptible.
Control loops must shift from single prompts to bounded autonomy. Design loops with budgets, deadlines, checkpoints, and escalation rules; separate planner, actor, critic, and memory roles; and build evaluation harnesses that test failure modes, not just happy paths. The loop should ask when to stop, what to verify, and who owns the outcome. At agustin-otegui.com, the focus is on bootstrapping products where databases, tools, and loops form one adaptive system. The cost of ignoring this is brittle automation that scales mistakes faster than value.
Common mistakes
Treating agentic AI as a conventional application with a chat wrapper leads to brittle databases and unsafe tools. Databases must move beyond static schemas and strict ACID assumptions toward semantic, versioned, and provenance-rich memory. Agents need to record intentions, observations, tool calls, and outcomes as first-class events, then query across vector, graph, and relational views. Eventual consistency, time-travel, and per-agent isolation matter more than single-row latency. Tools should be treated as capabilities with contracts: typed inputs, explicit permissions, idempotency keys, rate limits, rollback paths, and audit trails. Wrapping every API without constraints invites runaway loops and data corruption.
Control loops must also be redesigned. The classic request-response pipeline cannot handle open-ended planning, reflection, and recovery. Instead, design bounded perceive-plan-act-reflect cycles with budgets, checkpoints, interruption, and human escalation. Agents should propose actions, simulate consequences, and verify results before committing state. Common mistakes include unbounded autonomy, ignoring concurrency, missing observability, and no evaluation harness. The right architecture treats databases as shared mutable context, tools as governed actuators, and control loops as supervised feedback systems that can pause, explain, and roll back.
When to act
Agentic AI system design must treat databases less as passive record stores and more as event-sourced memory with provenance, uncertainty, and time. Agents need to query not only current state but why it changed, who or what changed it, and what remains unknown. This means append-only logs, semantic versioning, conflict resolution, and retrieval layers that separate facts from inferences. Traditional CRUD schemas and rigid transactions often break when autonomous loops mutate context, call tools, and recover from partial failures.
Tools should become typed, permissioned, idempotent capabilities with explicit preconditions, side effects, and rollback paths. Control loops must shift from single-pass prompting to observable cycles: plan, act, observe, verify, reflect, and escalate. The system needs budgets, guardrails, checkpoints, and human handoffs. Rather than hiding orchestration in prompts, architects should expose state machines, traces, and policy layers so agentic behavior remains debuggable, safe, and composable across products.
What to check first
Agentic AI systems violate implicit assumptions of database design: transactions assume short, predictable, human-triggered operations, but agents plan, retry, fork, and act over minutes or hours. Databases must expose intent, provenance, versioned state, and idempotent mutation APIs, not just tables. They should support speculative writes, rollback, event sourcing, and policy-aware access. Tools become typed capabilities with contracts, permissions, budgets, and observability, so agents can discover and compose them safely. The database becomes a shared memory and coordination layer, not a passive store.
Control loops must shift from request-response to continuous observe-plan-act-reflect cycles with guardrails. Designers need explicit state machines, checkpoints, cancellation, human approval gates, and cost/latency limits. Evaluation and tracing close the loop, turning every agent action into telemetry that improves routing, memory, and tool selection. The key is to treat databases, tools, and loops as one runtime: stateful, auditable, and safe by construction. That is how agentic products bootstrap reliably rather than demo well.
Agentic Design vs Traditional Database Architecture
| Dimension | Traditional Assumption | Agentic Rethink |
|---|---|---|
| Databases | Central durable truth, fixed schemas, ACID transactions, human queries. | Treat databases as memory substrates: vector, graph, event, and relational stores; support mutable beliefs, provenance, time travel, and agent-scoped views. |
| Tools | Deterministic APIs called by code with predictable side effects. | Tools become typed capabilities with permissions, cost, retries, idempotency, simulation, and audit trails; agents negotiate intent, not just invoke functions. |
| Control Loops | One request-response cycle, centralized orchestration, static workflows. | Multi-agent loops need planner-executor-critic patterns, budgeted autonomy, interruption, reflection, and rollback; control is distributed but governed. |
| Evaluation/Governance | Metrics are latency, throughput, and correctness on fixed schemas. | Evaluate trajectories, tool safety, memory drift, and emergent behavior; enforce policy, human approval, and observability across non-deterministic runs. |