Skip to content
@ Retention Marketers
Explainer

What is agentic AI in retention marketing?

Agentic AI selects and revises actions within a retention workflow. Learn what distinguishes it from a preset flow or AI-written copy, and what control to check.

7 min read Published Updated How this was sourced

Agentic AI in retention marketing is a system that can choose and carry out steps toward a retention goal within boundaries set by a team. It might select a permitted message, channel or next step using customer context, then use feedback to revise a later decision. The useful question is which decisions does the system control? A scheduled flow with AI-written copy is still a scheduled flow if its path never changes.

Agentic AI in retention, in short. Look past the label: identify the goal, the decisions the system makes, the data and actions it can access, and the point where a person takes over. “Agentic” does not require an LLM to write every message. It also does not prove that customers buy again or renew. The agent’s actual permissions and results matter more than its name.

What makes a retention system agentic?

There is no single boundary everyone uses. Anthropic’s architecture guide notes that some people call prescribed workflows “agents,” then makes a narrower distinction: a workflow follows code paths set in advance, whereas an agent directs its own process and tool use. OpenAI’s agent guide uses an LLM-specific definition: the model manages the steps, chooses tools, and can stop or hand back control. Under that definition, an LLM chatbot or classifier is not an agent simply because it produces an intelligent answer.

For a retention team, decision ownership is a more useful test than the word on a product page:

SystemWho chooses the next step?What “AI” changes
Preset win-back flowThe marketer’s fixed trigger and branchesNothing is required to run it.
Preset flow with an AI churn score or drafted subject lineThe preset branches still decide the pathAI supplies an input or content inside that path.
Agentic decision systemThe system chooses among permitted actions using current context and may revise later choices from feedbackAI controls at least part of the action policy, subject to the boundaries the team sets.

The first two rows follow the fixed-workflow side of Anthropic’s distinction. A score that feeds a branch may be useful, and generated copy may save work, but neither alone shows that AI chooses the next action. A next-best-action system addresses which action to take; an agent may also manage the steps needed to take it and respond to what happens afterward.

Does “agentic” mean an LLM writes the campaign?

No. OWASP’s agentic AI guide says agentic systems predate modern LLMs. The term can describe autonomy in a decision system, while OpenAI’s narrower “LLM agent” describes a particular way to implement it.

A concrete retention example appears in a 2026 preprint by Jeunen, Hanna and Wheeler. Their reactivation system observes a customer’s past interactions and app use, then selects message components, timing and channel. Marketers supply the component library; the system chooses and assembles from it using a sequential decision policy that includes Thompson sampling. The paper’s authors work for the agent platform. This example explains what that system controlled. It does not establish that every agentic campaign uses the same method or that a language model wrote its messages.

An LLM-enabled service agent could have a different job. OpenAI’s guide describes data tools that can read a CRM and action tools that can update a record or hand off a ticket. Its model could decide which tool to use as a conversation unfolds. The same word, “agent,” can therefore cover a message-selection policy and a tool-using service assistant. Ask about the controlled action before comparing them.

How would an agent handle a win-back journey?

Illustrative setup, not a description of a deployed product: suppose a retailer allows a system to contact eligible inactive customers with one of three approved messages. It may send email or choose no contact. It can read purchase and contact history, but it cannot create a discount, change an order or exceed a contact limit. A person approves any new offer. The agentic version selects an allowed action from context and revises its next step after feedback; a preset flow follows the same path each time.

At the first decision, the system reads the permitted context and chooses among those options. At the next eligible moment, it checks what happened and chooses again within the same limits. If the decision path is always “inactive for 60 days → send email A → wait seven days → send email B,” it is a preset flow even if an AI model wrote A and B. If the system selects an allowed action from context and can revise its next step after feedback, the decision has moved to the system. The Jeunen et al. implementation illustrates the latter pattern for content components, timing and channel; the retailer and its options here are invented solely to show the boundary.

The choice to send nothing is an action worth specifying. Without a permitted no-contact option, an agent asked to maximize responses could choose between messages even when the team’s preferred policy is to leave a customer alone. The AI customer retention guide explains why defining the action and its comparison process comes before judging an AI output.

What control should a team keep?

More autonomy means the system can take more steps without a person choosing each one. It does not require access to every customer record or permission to publish every action. For an LLM agent, OWASP’s guidance on excessive agency identifies three avoidable sources of risk: too many functions, too much permission and too much autonomy. It recommends limiting tools to the job, enforcing access in the connected systems, and requiring human approval for high-impact actions. A prompt saying “do not send an unauthorized offer” is not a substitute for the send tool rejecting one.

The practical boundary is specific to the task. A proposed email can wait for approval; a routine CRM lookup can be read-only; an unfamiliar complaint can go to a person. OpenAI recommends a handoff after repeated failure or before high-risk actions. Anthropic recommends checking real tool results as an agent proceeds and setting stopping conditions. These are controls to decide in advance, not evidence that an agent improves retention.

When a path is stable and well-defined, a fixed flow may serve it. Anthropic favors workflows for predictable tasks, and OpenAI says a deterministic solution may suffice when an agent’s flexibility is unnecessary. The extra freedom is useful only if the task actually needs the system to choose among changing steps or handle context that fixed branches cannot cover economically. That is an architecture decision; it does not settle the customer outcome.

How can you check an “AI agent” claim?

Ask for one ordinary customer case and one exception, then have the system’s owner walk through both. Check the goal, the inputs and allowed actions, who selects the next step, what happens after a changed signal, and when the system stops or hands off. That reveals where decisions happen.

Ask to seeWhat the answer reveals
The goal and eligible customer groupWhich job the system is authorized to do.
The inputs and allowed actions, including no contactWhat it can read, choose and actually execute.
The owner of each branch or next stepWhether AI directs the path or supplies a score or copy inside a preset path.
A changed customer signal and the next decisionWhether the system revises an action when context changes.
A failed or sensitive caseWhat stops the system and when a person must approve or take over.

This is a due-diligence exercise drawn from the architecture and guardrail sources, not an agent certification. A convincing demonstration can establish what the system does. To establish whether it retains more customers, compare its customer outcomes with the process it replaces. The separate AI agents and customer retention guide covers that evidence and test.

Sources

  1. Anthropic — Building effective agents · 19 Dec 2024
  2. OpenAI — A practical guide to building agents
  3. OWASP — Agentic AI: Threats and Mitigations · 17 Feb 2025
  4. Jeunen, Hanna and Wheeler — Sustained Impact of Agentic Personalisation in Marketing · 9 Apr 2026
  5. OWASP — LLM06:2025 Excessive Agency
Keep reading