Chatbot, vibe code, agent, automation: a compliance leader’s field guide

  • Photo of Ethena Team
    Ethena Team

Halfway through one of our recent AI in Compliance Certification classes, a participant typed a question into the Zoom chat that's probably crossed your mind too: am I correct that the term "agent" in Copilot is different from what an agent is as previously described?

Short answer: yes. The longer answer is that the four AI tool categories compliance leaders need to know are blurring fast, and the same word means different things across different products. Here's the field guide that would've saved us a few confused meetings.

Chatbot

ChatGPT, Claude, Gemini, Microsoft Copilot in its chat form. You type a question, it answers. Hannelore, one of our instructors, calls it "a better Google." That undersells it. A chatbot will summarize a 200-page enforcement memo, draft a first version of your conflict-of-interest policy, or explain what a SAR is to a new compliance hire.

What a chatbot doesn't do: take actions. It tells you what to do. It doesn't open your email, log into your training platform, or pull files from your shared drive. That distinction is the entire reason "agent" exists as a separate category.

Vibe coding tool

Lovable, Replit, Bolt, Cursor, Claude Code. You describe what you want to build in plain English. The tool generates a working app. Hannelore again: "It's great for little apps or tools to support your daily operations."

The use case for compliance: a regulatory tracker that pulls from the DOJ, OFAC, and SEC feeds you actually care about. A conflict-of-interest screener that flags entries against your policy. An onboarding game that quizzes new hires on the parts of your code of conduct that get the most disclosures. None of these need IT to scope a six-month build. You can prototype them yourself in an afternoon.

Agent

An agent is a chatbot that can take actions. Read files. Send emails. Schedule meetings. Query a database. Roxanne, who led the session, put it best: "Ask a chatbot how to make lasagna, it gives you a recipe. Ask an agent how to make lasagna, it just starts making lasagna."

For compliance, this is where it gets interesting. Ethena's platform runs on four agents that review disclosures, flag policy gaps, screen third-party risk, and update training from your real data. The compliance leader stays in the loop for every judgment call. The agent does the administration. You make the decision.

Automation

Zapier, Make, n8n. These have been around longer than the current AI hype, and most compliance teams are already using them somewhere. They run on rules you set: when this email arrives, file it there. When that form is submitted, send a Slack notification.

Some automation tools have added AI features recently, which is what blurs the line between this category and the others. The honest test: if the tool follows a flowchart you built, it's automation. If it makes judgment calls based on what it sees, you're in agent territory.

A word about Copilot

Microsoft's Copilot is where these categories collide. In its chat form, Copilot is a chatbot. The "agents" Microsoft has been adding (like the ones you build in Copilot Studio) are agents in the sense above: they can take actions. But Copilot also lives inside Outlook, Word, Excel, and Teams in ways that feel like automation more than chat.

You don't need to memorize which Copilot feature lives in which category. You do need to ask the question when someone says "agent" in a meeting: which kind?

You'll combine them

Most real compliance work uses two or three of these together. Hannelore called it a relay race during the session. You use a chatbot to refine your idea, a vibe coding tool to build the prototype, an automation tool to connect it to the rest of your stack.

A regulatory tracker in Lovable can pull from a Zapier feed that watches DOJ press releases. A disclosure agent can route flagged submissions through an automation that pings your inbox at noon every Friday. Each tool specializes.

The good news

The vocabulary is messy right now and it's going to get messier before it gets clearer. The good news, also from Hannelore: today is the worst these tools will ever be. They're only getting better from here.

If you want to work through the four categories live, with real builds and real questions from a room full of compliance peers, check out the AI in Compliance Certification. Otherwise, save this post for the next meeting where someone says "agent" and nobody's sure what kind they mean.

Articles

View All

Phishing Defense levels up: reporting a phish now counts

Employees can finally get credit for reporting a phishing test, and your click rates just got a lot more honest. Meet Reporter, the newest part of Phishing Defense.

2 min read

Ethena Announces Record First Half of 2026 and new CECO as Compliance Leaders Embrace Agentic Compliance

Accelerating enterprise demand for Ethena's AI agents drives more than 60% year-over-year growth; company names Chief Ethics & Compliance Officer NEW YORK, August 10, 2026 — Ethena, the AI compliance...

3 min read

Policy Bot turns one. Meet the Policy Agent.

“Do I have to tell HR if I’m dating my coworker?” One year ago, we shipped Policy Bot because of questions exactly like that one. Every workplace generates them by...

3 min read

Quarterly Compliance Round-up: June 2026

A quarterly round-up of ethics and compliance enforcement and rulemaking from March to June 2026: EU foreign investment screening reform, BIS export enforcement, expanding whistleblower programs, anti-boycott, sanctions, and FCPA developments.

5 min read