Agentic AI is the most heavily marketed term in higher education software right now, and one of the least consistently used. Some vendors selling "AI agents" ship systems that can genuinely plan and execute multi-step admissions work. Others have renamed a chatbot. This guide separates the two, as of September 2026, so that admissions directors, enrolment leaders, CIOs and CRM owners can compare what is actually on offer.
As of September 2026, only a small number of platforms document genuine AI-agent capabilities relevant to admissions. Among the platforms reviewed, Element451's Bolt and the CollegeVine Agent Platform are two of the clearest higher-education-specific agent implementations: both document agents that listen for events, pursue configured objectives, choose and execute actions through defined tools, and escalate to staff. Salesforce Agentforce, deployed with Agentforce Education (formerly Education Cloud), provides configurable education agents that can execute defined admissions actions such as creating applications and event registrations within the Salesforce architecture, and DRUID AI offers a horizontal enterprise agent platform that institutions can implement across admissions systems.
A second group of credible platforms provides AI that is valuable in admissions but works differently from autonomous agents. Full Fabric combines contextual, tool-enabled AI inside a governed higher education platform with deterministic workflow automation that executes admissions actions under explicit rules. Ivy & Ocelot from Gravyty and Mainstay remain better classified as conversational and proactive AI: they provide engagement at scale, proactive outreach, escalation to staff and deep campus integrations, but do not document independent multi-step planning against open-ended goals.
The platforms in this guide are not ranked from best to worst. They were selected because current first-party evidence shows meaningful AI-agent or closely related admissions capabilities, and they vary significantly in degree of autonomy. The right choice depends less on which system is "most agentic" and more on which level of autonomy your institution can safely govern for the task at hand.
Agentic AI admissions software is AI that can work towards a defined admissions goal by interpreting institutional and applicant context, deciding what steps are needed, using permitted tools or platform functions to take actions, observing the results and continuing or escalating within boundaries the institution has set. The defining feature is not intelligence or conversation quality. It is the combination of goal orientation, tool use and bounded independent action.
The Association for Institutional Research describes agentic AI as autonomous AI that can act independently towards a pre-determined goal, in contrast to traditional AI that needs prompting and step-by-step guidance, and cites admissions examples such as transcript processing, identifying missing documentation, contacting applicants and routing cases for staff review. EDUCAUSE's coverage of agentic AI in higher education work makes a similar distinction: where generative AI answered questions and produced content on request, agentic systems can carry out tasks, connect multiple steps, use tools and act across workflows with varying levels of human oversight.
Two clarifications keep the definition honest. First, agentic does not mean unsupervised. Most credible admissions agents operate under permissions, approval gates and escalation rules, and are more accurately described as bounded agents. Second, agentic does not mean the system makes admissions decisions. An agent can autonomously chase a missing transcript; that says nothing about whether it should, or lawfully could, decide who is admitted. That boundary is examined throughout this article and in more depth in Full Fabric's guide to AI in college admissions, which sets out the assist, recommend, decide framework this article builds on.
Vendor language blurs four genuinely different categories of software. Buyers should insist on knowing which one they are looking at.
Conventional workflow automation is deterministic. Staff write explicit rules: if an application is incomplete after ten days, send a reminder; when an offer is accepted, start the enrolment workflow. There is no AI reasoning involved, which is precisely why this category is predictable, auditable and appropriate for a large share of admissions operations. Full Fabric's guide to automating admissions without losing the personal touch covers how to design this layer well; this article does not repeat that blueprint.
AI assistants and chatbots answer, draft and summarise when asked. A well-grounded admissions chatbot can resolve thousands of enquiries, but it responds to individual messages. It does not hold a goal, plan steps or take actions in institutional systems beyond replying.
AI copilots with tools can inspect institutional data and suggest or execute specific actions a staff member requests, such as building a segment or drafting a communication from live applicant data. The human initiates each task; the AI executes it with visible steps.
AI agents are given an outcome rather than an instruction. "Help move incomplete applicants towards submission" rather than "draft an email". The agent determines which applicants qualify, decides what to do for each, executes permitted actions across channels or systems, observes what happens and adapts, escalating exceptions to staff.
A practical way to hold the distinction: a chatbot talks, a copilot helps you act, an agent acts. Each category has legitimate admissions uses. The mistake is buying one while believing you have bought another.
Because "best" claims need a methodology, this article applies two editorial tools. Both are this article's evaluation frameworks, not formal industry standards.
A system qualifies as meaningfully agentic to the extent that it demonstrates, in current documentation, most of the following: understanding of relevant admissions context (applicant record, programme, lifecycle stage, deadlines, missing items); acceptance of goals rather than only single instructions; multi-step planning; use of real tools or platform functions (querying records, updating data, creating tasks, sending communications, triggering workflows); execution of authorised actions rather than only recommendations; retention of state about what has already happened; a feedback loop that adapts the next step to the result of the last; configurable guardrails over actions, data access and approvals; recognition of exceptions with handoff to a person; and auditability, so the institution can reconstruct what the agent accessed, decided and did, and under whose authority.
No product needs to satisfy every criterion to contain agentic functionality. The test produces a spectrum, not a binary.
Level 4 deserves particular caution in admissions. Higher autonomy is not better software; it is a larger governance surface. The most defensible admissions architecture today is bounded autonomy: agents that are demonstrably useful at Level 3 while still requiring human approval for consequential actions, operating with limited tools and defined escalation points.
Inclusion in the shortlist required real admissions relevance, current availability rather than roadmap, first-party evidence of AI capabilities as of September 2026, and enough documentation of controls, permissions and auditability to evaluate governance. Vendor performance statistics were treated as claims, not evidence.
Not every platform in this table is agentic; that is the point of comparing them side by side. The classifications are this article's editorial categories, applied through the agentic test above, not formal industry labels.
| Platform | Classification | Agentic behaviour | Actions and workflows | Human controls | Best fit |
|---|---|---|---|---|---|
| Element451 (Bolt) | Higher-ed bounded agent platform | Goal-directed agents that act proactively across admissions tasks | Outreach across channels, application first reads, transcript analysis, fraud checks, scheduling, tasks | Enabled skills, approved actions, optional approval per action, audit | Institutions wanting admissions-specific agents, with or without changing CRM |
| CollegeVine | Higher-ed agent platform | Custom agents that listen for events, follow objectives and choose actions via tools | Email, SMS and phone outreach, reminders, document processing, browser automation, form submission, escalation | Per-workflow tool selection, guardrails, action logging, escalation | Institutions wanting configurable higher-ed agents across admissions and operations |
| Salesforce Agentforce Education | Enterprise agent platform with education data model | Configurable agents executing defined actions; scope depends on build | Answer with knowledge, create cases, applications, event registrations; extensible via flows | Topic and action configuration, escalation rules, Salesforce permissions | Salesforce institutions with admin and integration capacity |
| DRUID AI | Enterprise agent platform | Vendor documents agentic flows that check data, route exceptions and write back to systems | Eligibility checks, SIS write-back, routing, conversational actions | Flow design, approvals and permissions defined in implementation | Institutions wanting cross-system agents and owning the build |
| Full Fabric | Contextual, tool-enabled AI plus deterministic automation | Contextual AI with configurable agents and MCP tool use in defined areas; no open-ended goal pursuit | Queries, summaries, segments, drafting; AI tools create or update events and campaigns; workflows send comms, update states, create tasks | Role permissions, AI audit logs, explicit workflow rules and exits | European and international institutions prioritising control and auditability |
| Ivy & Ocelot (Gravyty) | Conversational AI | Proactive engagement and routing; no documented multi-step goal pursuit | 24/7 multilingual support, workflow triggers, handoff to staff | Central governance, grounded content, escalation | Campus-wide enquiry support across departments |
| Mainstay | Proactive conversational AI | Behaviourally targeted outreach; conversational rather than agentic | Two-way SMS and chat, nudge campaigns, staff escalation | Campaign design, human takeover | Text-first engagement and melt prevention |
What it is. Element451 is an AI-native higher education CRM, and Bolt is its agent platform, launched as a standalone product in May 2026 so institutions can run its agents alongside an existing CRM or SIS. Element451 states that Bolt agents can work alongside Slate, Salesforce, Ellucian, Canvas and other systems without migration.
Why it qualifies. Element451 is one of the clearest examples of a vendor whose current first-party documentation matches this article's agentic test. Its Bolt Agents documentation describes agents trained on higher education workflows that act proactively rather than waiting to be asked, and its admissions agent pages describe goal setting, approved actions and configurable oversight in concrete product terms.
What the agents can actually do. Documented capabilities include answering enquiries across chat, SMS, email, voice and WhatsApp; proactively following up with incomplete and admitted applicants; scheduling appointments; promoting forms; reading and analysing transcript data, including pushing results to an SIS for transfer credit articulation; application fraud detection; and performing rubric-based first reads of applications with human-readable rationales and routing for second reads. Element451 describes its agents with terms such as "AI workforce"; that is the vendor's language, and outcome statistics in its case studies are vendor claims rather than independent evidence.
Degree of autonomy and controls. On this article's spectrum, Bolt agents are bounded Level 3 agents. Element451's own documentation is notably specific about guardrails: institutions decide the goals, the approved actions and the oversight level, agents only use skills the institution enables, and every action can require human approval or be self-approved within defined boundaries. Element451 states it is SOC 2 Type II certified and FERPA-aligned.
Best suited to. US-centred institutions that want admissions-specific agents quickly, either inside Element451's CRM or layered over an existing stack. Institutions comparing the underlying CRMs directly can see Full Fabric's Element451 comparison.
What to verify. Which agent skills are generally available versus early access; exactly which actions your institution would allow to self-approve; how application-reading agents are governed against your evaluation policy; and how vendor-published pilot results were measured before relying on them.
What it is. CollegeVine describes itself as a platform for deploying AI agents to power university operations: institutions build, deploy, manage and monitor custom agents that support admissions, retention, marketing, finance and other operational areas by handling outreach, processing documents, monitoring workflows and performing behind-the-scenes tasks. CollegeVine's earlier AI Recruiter work, launched as Trellis, has evolved into this broader Agent Platform, and current documentation should be read on the platform's own terms rather than through the original recruitment framing.
Why it qualifies. CollegeVine's current agent documentation maps closely onto this article's agentic test: agents listen for events such as incoming messages, data changes or scheduled triggers; follow objectives and instructions the institution configures; and carry out actions across processing and analysis, operational coordination, communication and direct hands-on assistance, including submitting forms, scheduling appointments and updating approved fields in connected data sources. The same documentation is equally explicit about boundaries: agents cannot make policy decisions or grant exceptions, cannot fill gaps in institutional guidance, must escalate sensitive situations, and cannot act outside configured workflows, permissions and guardrails.
The tool layer. CollegeVine's toolbox documentation is one of the more transparent action inventories in the category. In its own formulation, agents decide what to do, and tools define how to do it once a decision has been made. Admissions-relevant tools include email, SMS and outbound phone contact, scheduled reminders with cancellation, document processing and transcript summarisation, knowledge base lookup, a planning tool for multi-step workflows, escalation to staff, and a browser automation tool for interacting with external websites and portals. Institutions grant tools per workflow, which is exactly the least-privilege pattern this article's governance section recommends.
Degree of autonomy and controls. On this article's spectrum, configured CollegeVine agents operate as bounded Level 3 agents within their granted toolset. CollegeVine states that the platform logs every agent action in detailed reports, that guardrails prevent unauthorised or unintended actions such as contacting ineligible students, and that built-in evaluations track outcomes, accuracy, tone and compliance. Those are vendor statements about its own controls; they describe the governance surface buyers should test rather than proof of outcomes.
Best suited to. Institutions that want configurable, higher-education-specific agents across recruitment, admissions and adjacent operations, deployed alongside existing systems, and that are prepared to own workflow and tool configuration decisions.
What to verify. CRM and SIS integration depth for your stack; exactly what the browser automation tool is permitted to do in external portals, since it extends the write surface beyond CollegeVine itself; which fields agents may update and under what approval; how a bad action is corrected or rolled back; how consent and communications governance apply to agent-initiated phone and SMS outreach; and which tools you would enable for each workflow.
What it is. Agentforce is Salesforce's platform for building and running AI agents, and Agentforce Education is the education product formerly named Education Cloud, which provides education-specific data objects and modules for recruitment and admissions, academic operations and student success.
Why it qualifies. Salesforce documents a specific recruitment and admissions agent use case with named actions the agent can invoke: answering questions with knowledge, creating cases, creating educational information requests and academic interests, registering prospective students for campus tours and creating new applications, working against education data objects such as Individual Application and Application Timeline. A Student Recruitment Agent can be deployed on applicant-facing channels and configured to escalate enquiries requiring human intervention.
Degree of autonomy and controls. Agentforce agents execute defined actions within configured topics rather than pursuing open-ended goals, which places typical deployments between Level 2 and bounded Level 3. Importantly, much of Agentforce is generic platform capability; the education-specific value comes from the data model and prebuilt actions, and anything beyond them requires configuration with flows, prompts and integrations. Salesforce documentation does not position Agentforce as a native application-review or decisioning agent, and buyers should not treat it as one.
Best suited to. Institutions already committed to Salesforce architecture, with the administrator and integration capacity to configure, test and govern agents, and a desire for enterprise-wide agent tooling beyond admissions.
What to verify. Which actions are prebuilt for education versus custom builds; licensing and consumption pricing for agent usage; how permissions map to your Salesforce security model; and what your implementation partner considers generally available versus recently released.
What it is. DRUID AI is a horizontal enterprise platform for conversational and agentic AI, not an admissions product. It appears here because it markets directly to higher education admissions and because DRUID documents its capabilities in exactly the terms of the category distinction this article draws: in its published material on admissions automation, the vendor states that conversational AI answers questions while agentic AI plans, decides and acts, checking eligibility, routing exceptions and writing back to the SIS without a human initiating every step. That is DRUID's own description of what its platform can be configured to do, not independent validation.
Degree of autonomy and controls. Capability depends heavily on implementation. DRUID provides the agent framework, integrations and flow tooling; the institution or a partner designs what the agents may read, write and decide. Deployed well, that supports bounded Level 3 behaviour across systems. It also means governance is largely something the institution builds rather than inherits. Its higher education results, such as the Georgia Southern University deployment it describes, are vendor-reported case studies.
Best suited to. Institutions that want agents operating across multiple systems (CRM, SIS, service desk) and have the technical ownership to design, integrate and maintain them.
What to verify. The real implementation effort and timeline; which admissions flows are templated versus custom; who maintains the agent logic after go-live; and how SIS write-back is permissioned, logged and reversible.
Several strong admissions AI platforms do not, on current evidence, meet the full agentic test. That is a classification, not a criticism. For many institutions these architectures are the safer and more appropriate choice.
What it is. Full Fabric is a higher education platform covering CRM, admissions, student information and payments, with contextual AI built into the platform as a layer across the student lifecycle rather than as a separate product.
Where it sits on the spectrum. Full Fabric does not currently position its product as an autonomous agentic AI admissions platform, and this article does not classify it as one. Its documented model is best described as contextual, tool-enabled AI plus deterministic admissions automation, and it combines three components. The first is the AI Console, a copilot-style contextual AI that works against the institution's own data within existing user permissions: it understands the module, screen, record and task in use, answers natural-language questions about applications, profiles and cohorts, generates summaries, helps build segments, supports drafting communications, shows the steps it takes in real time, retains conversation history and gives administrators audit logs of AI activity. The second is an AI agent and tool infrastructure documented on Full Fabric's public features list: institutions can create, configure and test custom AI agents with specific prompts and behaviours, connect multiple AI providers, and give AI access to defined platform tools through Model Context Protocol (MCP) integration, including tools that list and create events, manage and update campaigns, query segments and use email templates, with all AI interactions logged for audit. The third is deterministic admissions workflow automation: explicitly configured workflows with entry conditions, actions (including emails, SMS, staff notifications, tags, status transitions and internal tasks), wait steps and exit conditions that execute repeatable admissions work such as document chasing, reviewer routing and offer-holder reminders.
Several of those are agentic building blocks in this article's terms: contextual institutional data, configurable agents, tool use with read and write actions in defined product areas, visible execution, permissions and auditability, alongside deterministic execution. What current public documentation does not establish is the top of the spectrum: Full Fabric does not claim that its AI independently receives an open-ended institutional goal, creates its own multi-step plan, selects arbitrary tools autonomously, observes outcomes and replans towards the goal without staff or configured triggers. Applying the same standard used for every vendor in this guide, that places Full Fabric between a tool-equipped copilot and a bounded agent rather than at Level 3, and the distinction is a deliberate design position rather than a shortfall.
Why that architecture is a legitimate choice. Institutions that want AI-supported operations with tighter institutional control get the benefits of AI comprehension, defined tool actions and automated execution while every consequential action remains either rule-based and inspectable or human-initiated. For European institutions in particular, where the regulatory context for admissions AI rewards explainability and data governance, lower autonomous action is a feature, not a gap. The admissions CRM underneath provides the single applicant record that both the AI and the workflows act on.
Best suited to. European and international universities and business schools that want connected admissions context, controlled workflow execution, permissions, auditability and preserved human judgement, rather than high-autonomy agents.
What to verify. Which AI Console capabilities are enabled in your environment and permission model; which custom agents and MCP tools your institution would configure, and what they may create or update; how AI activity logging maps to your governance requirements; and which workflow actions your team would automate first.
What it is. Ivy & Ocelot is Gravyty's unified AI assistant platform for higher education, launched in October 2025 from the merger of Ivy.ai and Ocelot. It provides 24/7 multilingual AI assistants across chat, SMS, WhatsApp, voice and email, grounded in institution-specific content, with more than 30 prebuilt integrations to SIS, CRM and LMS systems and centralised governance across departmental assistants.
Classification. On current evidence this is a strong conversational AI platform rather than an agentic one. Its documented strengths are grounded answering at scale, proactive assistance and routing complex needs to the right staff. Gravyty does not document agents that accept open-ended goals and independently execute multi-step actions across systems. Institutions should classify it accordingly and not pay an agentic premium for a conversational deployment, however good.
What to verify. Integration depth for your specific SIS and CRM; how grounded content is maintained; escalation and live-handoff workflows; and any newer agent-style capabilities announced after this article's research date.
What it is. Mainstay (formerly AdmitHub) provides behaviourally intelligent chatbots for student engagement, best known for proactive, research-backed text outreach in enrolment and student success, including the long-running Georgia State University collaboration studied in randomised controlled trials. It was acquired by an education nonprofit in 2026.
Classification. Mainstay is conversational AI with proactive campaign capability, not an agent platform. Its outreach is targeted and two-way, and it escalates to staff, but campaigns are designed by people rather than planned by the AI towards goals. Its distinctive strength is the independent research base behind text-first nudging, which few competitors can match.
What to verify. The product roadmap under new ownership; integration coverage for your stack; and how conversational AI capabilities have evolved since the acquisition.
Across the platforms above, the admissions work that bounded agents demonstrably perform today, as generally available capability rather than concept, clusters into six areas.
Enquiry management. Answering grounded questions around the clock, gathering missing context, routing enquiries to the right team and creating follow-up tasks. This is the most mature use case across every vendor category.
Applicant follow-up. Identifying incomplete applications, determining what is missing, sending appropriate reminders across channels and stopping or escalating when the applicant replies. Element451 and CollegeVine document this as agent behaviour; Full Fabric and others achieve comparable outcomes through configured workflows.
Document operations. Extracting and classifying information from submitted documents, identifying missing or ambiguous items, requesting what is outstanding and escalating ambiguity. Element451's transcript analysis, with SIS write-back for transfer credit, and CollegeVine's document processing and transcript summarisation tools are the most explicit current examples.
Interview and appointment coordination. Offering slots, scheduling, rescheduling, issuing reminders and creating staff tasks.
Admissions operations. Monitoring workflow stages, identifying stuck cases, routing applications to reviewers and organising review work.
Offer-holder support. Identifying outstanding requirements, sending reminders, answering financial aid and next-step questions in plain language, and routing complex cases to staff.
Application review deserves separate treatment because some vendors now sell application-reading agents. Three tiers must not be conflated. Administrative file preparation (extraction, summarisation, completeness checks, organisation) is low-risk work that agents and copilots handle well. Evaluative recommendation (rubric-based scoring, classification, ranking, first reads with rationales) is a materially different activity that requires calibration against human judgement, monitoring for bias and clear institutional policy; Element451's Application Reader operates here, with human review built into the routing. Decision, the acceptance or rejection itself, is the third tier, and no platform in this guide should be configured to perform it autonomously.
Useful admissions agents can autonomously support operational coordination. That does not mean institutions should delegate acceptance or rejection decisions, discretionary eligibility judgements, scholarship decisions, appeals or complex policy interpretation to an autonomous system. These are the tasks where consequence, ambiguity and fairness converge, where applicants are entitled to meaningful human judgement, and where regulation increasingly requires it.
The design principle that follows is bounded autonomy. An agent can be highly valuable while still requiring human approval for consequential actions, human handling of exceptions, limits on the tools it can use, permissions that constrain what it can read and write, and explicit escalation points. When evaluating vendors, treat "human in the loop" as a claim to be tested, not a reassurance. Ask whether a human can approve actions before execution, whether high-risk actions can be excluded entirely, whether the agent can hand a case over and be overridden or paused, whether individual skills can be disabled, whether administrators can see and understand its history, and whether incorrect actions can be corrected. A vendor that cannot show the product controls behind the phrase is offering a slogan.
Behind the vendor list sit five architecture choices, and the architecture decision often matters more than the vendor decision.
A native admissions CRM with agents, such as Element451, puts AI directly in the system that holds applicant data and workflows. Advantages: rich context, fewer integrations, unified permissions. Trade-offs: deeper vendor dependency, and agent scope largely limited to that platform.
A higher-education agent platform deployed alongside existing systems, such as Element451's standalone Bolt or the CollegeVine Agent Platform, provides purpose-built agents that connect to the institution's current CRM and SIS. Advantages: higher education context without replatforming, transparent tool inventories. Trade-offs: integration depth must be verified per system, and agent write access extends into systems the vendor does not control.
An enterprise agent platform, such as Salesforce Agentforce or DRUID AI, connects agents across institutional systems. Advantages: cross-system reach, enterprise governance tooling, extensibility. Trade-offs: implementation complexity, integration work and higher ongoing technical ownership.
An AI engagement specialist, such as Ivy & Ocelot or Mainstay, focuses on conversations, applicant support and outreach, integrating with the CRM and SIS of record. Advantages: fast deployment, deep channel capability. Trade-offs: a narrower slice of admissions work, and another system to govern.
Contextual AI plus deterministic automation, the Full Fabric model, keeps AI in an assistive, permission-aware role while explicitly configured workflows execute routine actions. Advantages: control, explainability, auditability and a lower governance surface. Trade-off: less agent autonomy, by design.
Whichever architecture is chosen, an agent is only as useful as the data it can access, the tools it may use, the quality of institutional rules, the workflows around it and the clarity of ownership. Agentic AI does not fix fragmented applicant data, contradictory programme rules or poor CRM configuration; a sophisticated agent operating against bad institutional data simply acts on bad context faster. Institutions consolidating systems, or connecting them properly through documented integrations, are doing agent-readiness work whether or not they buy an agent.
The security question changes when AI can act. A hallucinating chatbot gives a bad answer; a hallucinating agent with write access can take a bad action, and can take several before anyone notices. Procurement should therefore evaluate agentic products on least-privilege access, role-based and action-level permissions, approval gates for consequential actions, comprehensive logging and traceability, mechanisms to correct or roll back actions, and clarity about which external tools and systems the agent can reach.
Two threat classes deserve specific attention. Prompt injection, particularly indirect injection through content the agent reads (an email, a document, a web page), can manipulate agent behaviour, and NIST's updated adversarial machine learning taxonomy, NIST AI 100-2 E2025, explicitly covers direct and indirect prompt injection and the security of AI agents among its generative AI attack categories. Data leakage risks also widen when agents can query records at scale and communicate externally; institutions should scrutinise model and provider data terms, retention and whether institutional data trains external models. The broadest procurement question is simple to state: which systems and records can the agent modify? The wider the write-access surface (CRM records, communication history, tasks, workflow states, the SIS, external services), the more the permissions, approval, audit and rollback controls above become decisive rather than desirable.
This should not become a security project that swallows the evaluation. The proportionate approach is to demand the same evidence for agent actions that institutions already demand for staff actions: identity, permission, log, review.
For European institutions, the EU AI Act (Regulation (EU) 2024/1689) frames part of this procurement. Annex III identifies certain AI systems intended to determine access or admission to educational institutions among the high-risk use cases, subject to the classification rules in Article 6. Under the current implementation timetable, following the 2026 Digital Omnibus amendments, the European Commission's enforcement timeline has the Annex III high-risk rules applying from 2 December 2027.
Three points matter for agent buyers. First, purpose and effect determine classification, not autonomy: an agent answering programme questions is a different use case from an AI system materially influencing who is admitted, and the Commission's AI Act Service Desk guidance on education illustrates where preparatory file-handling tasks may fall outside the high-risk category. Second, an agentic capability procured in 2026 that materially influences admission decisions will need to meet high-risk obligations well within its useful life. Third, none of this is legal advice; classification is a case-by-case exercise, covered in more depth in Full Fabric's article on AI for European admissions teams.
A procurement conversation about agentic AI should get past the demo with specific questions. The following fifteen work as a checklist.
1. What exactly makes this product agentic, in your documentation rather than your marketing? 2. Can it pursue a goal, or only answer prompts and execute single requested actions? 3. Which actions can it execute, and which are generally available today versus beta or roadmap? 4. Which systems and records can it read? 5. Which systems and records can it write to? 6. Can we restrict available actions and skills by role, team or use case? 7. Which actions require human approval, and can we change that per action? 8. How does the agent know when to stop, and what are its exit conditions? 9. How does it recognise and handle exceptions, and where do they land? 10. Does it retain state between actions, and can we inspect that state? 11. Can it show and explain what it did, in terms staff can understand? 12. Is every action logged, and can we reconstruct who or what authorised it? 13. How do we correct or roll back a bad action, including messages already sent? 14. Does our data train your models or any third-party models, and what are the retention terms? 15. Which admissions uses do you explicitly prohibit or decline to support?
Vendors comfortable with these questions tend to have built the controls. Vendors that answer with outcome statistics have been asked a different question and answered it anyway.
The honest answer depends on institutional fit rather than technology enthusiasm. Agentic AI is most defensible where volumes are high, the work is operational rather than judgemental, data is consolidated and governed, someone owns the agent's behaviour, and the institution has the appetite to supervise a system that acts. It is least defensible where applicant data is fragmented, rules are contradictory, ownership is unclear, or the tasks in question involve discretion, sensitivity or admission outcomes.
Many institutions will rationally choose a lower point on the autonomy spectrum: strong deterministic automation for repeatable work, contextual or conversational AI for comprehension and engagement, and human judgement for everything consequential. Others, particularly high-volume US enrolment operations, will get real value from bounded agents today. Both are sound strategies. The failure mode is buying the label rather than the level: paying for autonomy you will not permit, or deploying autonomy you cannot govern. Teams weighing these options alongside their broader stack can start from Full Fabric's overview of software for admissions teams.
Agentic AI in admissions is AI that can work towards a defined goal, such as moving incomplete applicants towards submission, by interpreting applicant and institutional context, planning the necessary steps, taking permitted actions in real systems, observing the results and escalating exceptions to staff. It differs from chatbots, which respond to messages, and from workflow automation, which follows explicit human-written rules.
A chatbot answers when asked; an agent acts towards a goal. An admissions chatbot can resolve enquiries and draft responses, but it does not plan multi-step work or execute actions across systems. An agent can identify which applicants need attention, choose an action, execute it, monitor the outcome and continue or hand over to a person.
There is no single best platform. As of September 2026, Element451's Bolt and the CollegeVine Agent Platform are among the clearest higher-education-specific agent implementations, Salesforce Agentforce Education provides configurable education agents on the Salesforce stack, and DRUID AI offers an enterprise agent platform requiring institutional implementation. Platforms such as Full Fabric, which combines contextual and tool-enabled AI with deterministic automation, and conversational platforms such as Ivy & Ocelot and Mainstay, offer architectures that many institutions will prefer for control and governance reasons.
Currently available agent capabilities centre on enquiry handling, applicant follow-up and reminders, document collection and classification, transcript analysis, interview and appointment scheduling, routing of applications and cases, and offer-holder nudging. These are operational tasks with observable triggers and recoverable errors, which is what makes them appropriate for bounded agents.
Some vendors sell application-reading agents that extract information, check completeness, and perform rubric-based first reads with rationales routed to human reviewers. Administrative file preparation is low-risk; evaluative first reads require calibration, bias monitoring and clear policy; and the admission decision itself should remain a human judgement. Institutions in the EU should also assess such systems against the AI Act's high-risk classification rules.
No platform in this guide should be configured to make autonomous admissions decisions, and this article recommends against delegating acceptance, rejection, discretionary eligibility, scholarship judgement or appeals to any autonomous system. In the EU, AI systems intended to determine access or admission to education fall within the AI Act's high-risk category, subject to Article 6, with Annex III obligations scheduled to apply from 2 December 2027.
Full Fabric currently positions its AI as contextual AI embedded in the platform, combined with deterministic admissions workflow automation. Its public feature documentation also includes agentic building blocks such as configurable AI agent creation and testing, MCP-based tool use in defined areas including events, campaigns, segments and email templates, permission-aware data access, visible action steps and AI audit logs. Institutions should still distinguish these capabilities from high-autonomy agents that independently plan and execute multi-step goals, which Full Fabric does not claim. For institutions prioritising control, explainability and auditability, that is a deliberate architectural position rather than a limitation.
At minimum: least-privilege and role-based permissions over data and actions, approval gates for consequential actions, complete action logging with reconstructable authorisation, mechanisms to pause the agent and correct or roll back actions, defences against prompt injection in content the agent reads, and clear provider terms on data use, retention and model training. The governing test is that AI which can act needs the same accountability as staff who can act.