Field guide · updated 2026-08-10 · 6 min · 1,197 words
What can an AI assistant actually do?
A practical capability map for AI assistants in 2026, organised by checking effort, risk and the controls needed before an assistant acts in real systems.

Editorial position
aiassistant.sg sells integration in this category. Product mentions carry no affiliate or vendor compensation.
Review policy
Reviewed 2026-08-10. Source links below support details that may change.
The useful answer, upfront
What to carry into the decision
- Capability is not binary: the same task can be low-risk advice, approval-first preparation or a consequential autonomous action.
- Assistants are strongest on language-heavy, repeated work whose output can be checked against a source or observable outcome.
- Tool access increases both usefulness and consequence. Permissions, recovery and records should grow with it.
- The fastest responsible rollout begins with real examples and a correction log, not a broad promise to automate a role.
Section 01
Read capability as a risk ladder
A capability list is useful only when it states the review burden and consequence of error. “Send email” might mean suggesting three lines for a colleague, preparing a customer response from approved facts, or autonomously sending a contractual commitment. The model capability is similar; the operating risk is not.
Use four questions for every proposed task: what source makes the result correct; how will a person or system detect a miss; can the action be reversed; and who owns the exception? NIST’s Generative AI Profile recommends lifecycle risk management rather than treating safety as a model property fixed at purchase.[4]
Working diagram
The delegation ladder
Move upward only when checking becomes reliable and the consequence remains controlled.
01
Advise
Explain, compare, retrieve or suggest. A person decides and acts.
02
Prepare
Draft the message, record or action for explicit approval.
03
Act narrowly
Perform a reversible action inside a written rule and permission boundary.
04
Operate by exception
Handle a stable lane while a person reviews alerts, outcomes and correction trends.
Section 02
Low-risk organisation and understanding
Good starting points transform material without creating an external commitment. An assistant can summarise a meeting, extract actions from a thread, classify incoming messages, compare documents, create a first research map, or turn unstructured notes into a consistent format.
These jobs still need checks. Summaries can omit a qualification; extraction can assign a field incorrectly; research can cite a weak source. The advantage is that mistakes are normally visible against the original material and can be corrected before they propagate.
| Task | Useful output | Minimum check | Common failure |
|---|---|---|---|
| Summarisation | Decisions, actions and unresolved points | Compare material decisions and numbers with the source | Confident omission |
| Extraction | Structured fields from email, forms or documents | Validate required fields and sample edge cases | Wrong field or unit |
| Research | Source map, comparison and open questions | Open the few sources on which the decision turns | Weak or stale authority |
| Classification | Topic, urgency or route | Monitor misroutes and maintain an “uncertain” lane | Forcing an ambiguous case |
| Knowledge answers | Response grounded in approved material | Require citations and a refusal when the source is silent | Plausible invention |
Section 03
Drafting and decision support
Assistants are effective first-pass writers because they can combine instructions, source material and the immediate conversation. They can prepare email, proposals, reports, meeting agendas, translations, interview questions and response options. The person should remain the quality gate wherever tone, commitment or professional judgment matters.
Decision support is useful when it exposes the evidence rather than impersonating the decision-maker. Ask the assistant to organise options against a rubric, identify missing information, show disagreements between sources and state uncertainty. Do not ask it to collapse a consequential decision into a single opaque recommendation.
- Draft customer replies from a maintained fact set; keep price exceptions, refunds and unusual promises behind approval.
- Prepare a supplier comparison; require source links for the few claims that drive the decision.
- Screen material against an explicit rubric; retain the accountable human decision and a way to inspect false exclusions.
- Translate operational material; use qualified review where nuance affects safety, rights or money.
Section 04
Actions across tools and systems
Tool access lets an assistant search a mailbox, read a calendar, query a CRM, update a ticket or send a message. Agent guidance from both OpenAI and Anthropic treats tools as a core part of the system, not an incidental feature.[1][2] Each connected tool should have a narrow purpose, clearly described inputs, scoped credentials and a defined failure response.
The dangerous assumption is that a correct sentence implies a correct action. Tool calls can fail, return stale data, partially complete, act twice after a retry or encounter a permission that changed. A production workflow needs idempotency where possible, confirmation for sensitive actions, logs, retry limits and a handover that preserves state.
Section 05
Monitoring, follow-up and recurring work
The largest difference between a chat subscription and an integrated assistant is often not intelligence but timing. A useful workflow notices that a lead has not replied, a deadline is approaching, a policy changed, a queue is ageing or a threshold was crossed. It can then prepare or take the next approved action.
Recurring work needs a source of truth for state: owner, last action, next action, due time and completion condition. Without it, reminders become repeated messages detached from the actual outcome. The assistant should also know when to stop—a customer opted out, a person took ownership, the source is unavailable or the maximum number of attempts was reached.
Step 01
Observe
Read the smallest source needed to detect a new item, deadline or state change.
Step 02
Decide within rules
Apply a written route, timing rule or threshold; send ambiguity to an exception lane.
Step 03
Prepare or act
Create the approved output with the relevant context and permission.
Step 04
Record and stop
Update owner and next action, then terminate when the completion or stop condition is met.
Section 06
Work that needs engineered controls
Autonomous customer conversations, multi-step updates, refunds, bookings and other consequential actions are possible only as systems, not prompts. They need source ownership, permission boundaries, validation, evaluation, monitoring and recovery. Anthropic’s agent-evaluation guidance notes that multi-turn agents call tools and modify state, so evaluators must inspect the trajectory and environment changes rather than a final answer alone.[3]
Singapore’s agentic AI framework similarly emphasises bounding risk, meaningful human checkpoints, whitelisted services, baseline testing and lifecycle controls.[5] Use those ideas proportionately: a small enquiry workflow does not need an enterprise committee, but it does need someone accountable for its facts and exceptions.
Section 07
A practical way to choose the first task
List repeated work for two weeks. Score each item for frequency, clarity of desired outcome, availability of a reliable source, ease of checking, reversibility and sensitivity. The best first task is rarely the most glamorous; it is the one that creates enough repeated value to justify maintenance while making mistakes visible.
Run the selected task approval-first and group every correction. If most corrections come from stale facts, repair source ownership. If they come from ambiguous policy, rewrite the rule. If they come from missing context, change intake. If they come from model variability, narrow the task or add deterministic validation. Expand only after the correction pattern is quiet and understood.
For a fuller boundary test, read what should remain human. To map a real workflow to a product, package or custom build, use the Assistant Finder.
↗Primary sources
Sources and verification
Citations in the article point to these first-party or authoritative references. Product details can change; the review date above is the verification date for this edition.
→Continue the field guide