Pedagogical Agents: When AI Moves from Assistant to Actor
Autonomous tutors, teacher co-pilots, multi-agent systems: agentic AI promises more than answering — acting. Evidence, architectures and guardrails.
Autonomous tutors, teacher co-pilots, multi-agent systems: agentic AI promises more than answering — acting. Evidence, architectures and guardrails.
A chatbot answers. An agent acts: it plans, uses tools, orchestrates several steps, coordinates other agents. This shift from assistant to actor opens new educational uses — but it also raises the stakes of reliability, ethics and control. Where do we really stand in 2025-2026?
The strongest evidence concerns the co-pilot. In the Tutor CoPilot trial, an agent whispering real-time suggestions improved student mastery, especially for those tutored by the least experienced tutors [1]. On the tutor-agent side, a Harvard trial shows a well-designed AI tutor can teach more than an active-learning class — the authors explicitly noting this is not about replacing teachers [2]. Another trial reports an instructional agent raising learners' sense of control and task efficiency [3].
A promising application is generating teaching material via role-specialised agents. The Instructional Agents system produces classroom-ready materials while sharply cutting prep time, maintaining quality [4]. The FACET architecture combines a learner-simulation agent, a teacher agent and an evaluator agent to generate personalised, stable worksheets [5].
Caution is also warranted on the evidence. Some deployments of agents as primary instructors report only preliminary observations from a single course [7]. And several ambitious frameworks announce flattering metrics — for example very high recommendation rates — that remain self-reported and not independently validated [8]. The gap between demo and proof remains wide.
An agent that acts without being audited is not a pedagogical advance: it is a risk disguised as a feature.
Learnya synthesis
Agentic AI is worth all the more when it stays under human supervision and within a controlled data framework — a crucial point for European and Swiss institutions. Well designed, agents free teacher time and extend support; poorly governed, they spread errors at scale and obscure decisions.
The real paradigm shift is not model power but autonomy: an agent that plans, calls tools and chains decisions without human validation at each step. This autonomy multiplies usefulness — and risk. A chatbot's error stays local; an acting agent's error propagates through a chain of actions. Hence the importance of defining checkpoints where humans retain control over high-stakes decisions.
The most recent scoping review stresses persistent blind spots: privacy, accuracy, learner autonomy [6]. These are not compliance details; they touch the heart of the educational relationship. An agent that decides a student's path alone, or collects and exploits their traces without transparency, can erode trust even if it is technically capable.
The maturity of an agentic system is therefore judged less by its announced metrics — often self-reported and unaudited [8] — than by its traceability: can we know why it acted, roll back, correct? For European and Swiss institutions, this requirement aligns with data sovereignty: keeping control of what the agent sees, remembers and transmits. Responsible agentic AI is supervisable agentic AI.
The central question for pedagogical agents is not 'how far can they go?' but 'how far should we let them go?'. An agent can prepare a lesson almost autonomously with little risk; it should not decide a student's academic path alone. Setting this dial, task by task, is a job of instructional engineering as much as of technology.
The coming years will likely see best practices stabilise: agents confined to clear roles, human validation checkpoints on sensitive decisions, action traceability, and a strict framework for the data handled. Only on these conditions will agentic AI keep its promise — freeing time and extending support — without turning school into a black box. Supervision is not the enemy of automation; it is its condition of legitimacy.