n8n AI agent: how it works, and when your process needs one
By the E-Solutions Web editorial team. Published , updated . How we write
The short answer
An n8n AI agent is a workflow built around n8n’s AI Agent node. You connect a chat model and at least one tool, write a system message, and the agent decides which tools to call to finish the task. A memory node keeps a conversation going, human review can pause a risky tool call, and ordinary n8n nodes handle the fixed steps around the agent.
Every feature on this page was read in n8n’s own documentation and pricing page on October 1, 2026. n8n ships new versions often, so node names and plan contents can move; the documentation linked in the sources is the reference. If you are still choosing between n8n and other tools, start with our comparison of n8n vs Zapier vs Make.
What an n8n AI agent is made of
An n8n AI agent is one root node, the AI Agent node, with sub-nodes plugged into it: a chat model, one or more tools, and optionally a memory and an output parser. n8n’s documentation sums it up in one line: “Connect a chat model and one or more tools, and the agent decides which tools to call to complete a task.”
Since n8n 1.82.0, every AI Agent node works as a Tools Agent, the setting most people already used. The documentation says it “implements Langchain’s tool calling interface”: the model receives the list of tools with their schemas and picks the ones it needs.
| Part | What it does | Examples in n8n |
|---|---|---|
| Trigger | Starts the workflow | Chat Trigger, Webhook, Schedule, a new email or form entry |
| AI Agent node | Reads the input, plans, calls tools, returns the answer | One per agent; you must connect at least one tool |
| Chat model | The language model that reasons | OpenAI, Groq, Mistral Cloud, Anthropic, Azure AI Foundry; Ollama for a model you host |
| Tools | What the agent is allowed to do | Call n8n Workflow, HTTP Request, Code, app nodes such as Gmail, HubSpot, Postgres or Slack, MCP Client Tool |
| Memory | Keeps the conversation history | Simple Memory, Postgres Chat Memory, Redis Chat Memory |
| Output parser | Forces a fixed format for the answer | Structured Output Parser, Auto-fixing Output Parser |
Two options of the node matter more than they look. The system message is where you write the agent’s job, its limits and what to do when a tool is refused. Max iterations caps how many times the model runs to reach an answer; it defaults to 10, which stops an agent from looping on a case it cannot solve.
If your team runs n8n through our n8n agency, each agent sits in the same instance as your other workflows, with the same credentials store and the same error alerts.
First decide: agent, or workflow with one AI step?
Most processes need a workflow with a single AI step, and a few need an agent. Anthropic draws the line clearly: workflows orchestrate models and tools “through predefined code paths”, while agents “dynamically direct their own processes and tool usage”.
n8n reflects that split in its nodes. Its documentation notes that the Basic LLM Chain “supports chatting with a connected LLM, but doesn’t support memory or tools”; the AI Agent node is the one that chooses tools. Anthropic’s advice applies here too: find “the simplest solution possible”, which “might mean not building agentic systems at all”.
| Your task | What to build in n8n | Why |
|---|---|---|
| Same steps every time, structured data | A plain workflow, no AI | Cheapest, fully predictable, easy to test |
| Same steps, but one input is messy (an email, a PDF) | A workflow with one AI step: Information Extractor, Text Classifier or a chain | The model reads; the workflow decides |
| Next step depends on the case: look up a customer, then an order, then a contract | An AI agent with a few narrow tools | The model chooses the path, inside the limits you set |
| Conversation with staff or customers | An agent with a Chat Trigger and memory | It keeps context from one message to the next |
| Action that cannot be undone: payment, deletion, an email to a client | An agent whose tool sits behind human review | A person says yes before it happens |
A quick test: write the steps on one page. If they never change, build the workflow. If the page fills with “it depends”, the agent earns its place.
How to set up an n8n AI agent, step by step
The build itself is short. Most of the work is in choosing the tools and testing on real cases.
- Pick the trigger. A Chat Trigger for a conversational agent; a webhook, a schedule or a new email for a back-office one.
- Connect the chat model. Choose it on data rules first, then quality and cost. A model you host through Ollama keeps prompts on your servers.
- Write the system message. The job, what the agent may and may not do, the tone, and how to react when a person refuses a tool call.
- Give it few, narrow tools. One tool per action, named clearly. A Call n8n Workflow tool lets you wrap a whole sub-workflow, with its own checks, behind a single tool. On an MCP Client Tool, use “Selected” to expose only the tools the agent needs.
- Fix the output format. Turn on “Require Specific Output Format” and connect a Structured Output Parser when the next node expects precise fields.
- Put risky tools behind human review. See the next section.
- Add an error workflow. n8n’s pricing page lists error workflows and automatic retries on each n8n Cloud plan it compares; each failure should reach a named person.
- Test on real cases before switching on. Evaluations, below, turn this into a routine.
Keep the deterministic steps as ordinary nodes around the agent. An order number is validated by an IF node, never by the model.
Guardrails: human approval, limits and logs
n8n lets you require a person’s approval before the agent runs a specific tool. When the agent picks a gated tool, “the workflow pauses and waits for a person”, who either approves, and the tool runs with the input the AI chose, or denies, and the action is canceled.
The documentation recommends it for tools that “perform irreversible actions”, for compliance requirements and for high-value decisions. Approval requests can go to n8n’s chat, Slack, Microsoft Teams, Gmail, Outlook, Telegram, Discord, WhatsApp Business Cloud or Google Chat, and the reviewer sees which tool the agent wants and with which parameters. You can gate every tool or only some, and the review step can run on a different channel from the conversation: a customer talks to the agent in a chat window, while the approval lands with a manager in Teams.
Three more settings complete the picture:
- Max iterations bounds the number of model runs per request.
- Return intermediate steps adds the agent’s steps to its output, so you can log what it did and why.
- A clear system message about review. n8n asks you to state in the system prompt which tools need approval and how the agent should respond when a request is denied.
For a European company, this human review step is also the simplest way to show that a person stays in control of decisions with real consequences. Our page on AI agents for business describes how we set those thresholds with your team.
Test before production: evaluations
An agent that worked on five examples has proved little. n8n’s documentation puts it bluntly: “AI models are fundamentally different than code”, so you measure them by running data through them.
n8n’s evaluations run a test dataset through the workflow. It describes two levels: light evaluations on a handful of hand-picked cases while you build, then metric-based evaluations on a larger dataset, often taken from production executions, once the agent is live. When you find a bug, you add the input that caused it to the dataset and rerun everything, so a fix in one place does not break another. On n8n Cloud, the pricing page lists metric-based evaluations on the Pro plan.
What a useful test set holds: the ordinary cases, the incomplete ones, the ambiguous ones, and a few that should be refused. Write the expected result for each before you look at the agent’s answer.
Where the agent runs, and where your data goes
Two places matter: where n8n runs, and where the model runs. They are separate decisions.
n8n Cloud stores data in the EU, in Frankfurt, according to n8n’s pricing page, and a self-hosted n8n keeps it wherever you install it. But each call to a hosted chat model sends the prompt and the tool results to that model’s provider. If those contain customer files or personal data, check that provider’s terms and location, or run the model yourself. n8n’s Ollama Chat Model node connects an agent to a local model, and our private LLM page covers what hosting one involves.
On cost, n8n counts executions: its pricing page says that “an execution is a single run of your entire workflow”, whatever the number of steps. An agent that calls six tools to answer one email is still one execution. The model’s tokens are billed separately by the model provider, and for an agent they grow with each iteration, so measure them on your test set before you go live.
If you plan to keep everything on your own infrastructure, our guide to n8n self-hosted covers the license, the setup and the upkeep.
Where n8n agents reach their limits
n8n agents work well inside the tools n8n connects to, for tasks a person could describe on a page or two. They get harder past a few points.
- Systems without a node or an API. The HTTP Request tool reaches any API, but a legacy application with no API needs another route, sometimes a robot that works on its screen.
- Many tools at once. The more tools an agent sees, the more often it picks the wrong one. Split the work into several agents, or into sub-workflows exposed as single tools.
- Strict audit needs. Intermediate steps and execution logs help, but the evidence an auditor expects, per decision and per version, often needs extra logging that you design on purpose.
- Volume and latency. An agent that runs several iterations per case is slower and more expensive than a rule. At high volume, keep the agent for the cases the rules cannot settle.
When a project outgrows these limits, the agent moves into code, next to your systems. Our guide on how to build an AI agent compares the three routes: a platform such as n8n, a framework, or a custom build. To see what an AI step makes of a real, messy document before you design an agent around it, try the document extraction demo.
Put your first n8n agent into production
Picture the inbox sorting itself, with your team stepping in only on the cases that need a person. In a free 30-minute assessment, bring the task you want to hand to an agent and the tools it touches. We tell you whether an agent, a workflow or a single AI step fits, which tools need human approval, and what to build first. A first agent usually takes four to eight weeks, and the scope and price are fixed in writing before we start. Every workflow we deliver ships with an error alert, documentation and accounts in your name.
Book your free 30-minute assessment. We reply within one business day. If your team would rather build its own agents, our n8n training runs on your instance and your processes.
Frequently asked questions
Is the n8n AI Agent node free?
The node is part of n8n, so it is included in the free self-hosted Community edition and in every n8n Cloud plan. A whole workflow run counts as one execution, however many tools the agent calls. The language model is billed separately by its provider, unless you run a local model on your own servers.
Which models can an n8n AI agent use?
n8n’s Tools Agent documentation lists chat models from OpenAI, Groq, Mistral Cloud, Anthropic and Azure AI Foundry. For data that must stay on your infrastructure, the Ollama Chat Model node connects the agent to a model you run yourself. The model is a sub-node, so changing it leaves the rest of the workflow in place.
Does an n8n AI agent remember previous messages?
Only if you attach a memory sub-node. Simple Memory keeps a set length of chat history for the current session; Postgres or Redis chat memory nodes store it in a database. Without memory, every message starts from zero, which is often what you want for a back-office task.
Can a person approve what the agent does?
Yes. n8n lets you put chosen tools behind a human review step. When the agent wants to use one, the workflow pauses and sends the request to Slack, Teams, email or n8n’s chat. The reviewer approves, and the tool runs, or denies, and the agent is told the action was refused.
Can an n8n AI agent use MCP servers?
Yes. The MCP Client Tool node lets an n8n agent call the tools exposed by an external MCP server, and you can choose which of those tools the agent may see. n8n also has an MCP Server Trigger that exposes your own n8n workflows to other AI clients.
When should I use a plain n8n workflow instead of an agent?
When you can write the steps on one page and they are the same every time. A workflow with a single AI step, to read a document or classify a message, is cheaper to run and easier to test. Keep the agent for tasks where the next step depends on what the case turns out to be.
Sources
- AI Agent node, n8n Docs, accessed October 1, 2026.
- Tools Agent, n8n Docs, accessed October 1, 2026.
- Human-in-the-loop for tools, n8n Docs, accessed October 1, 2026.
- How memory works, n8n Docs, accessed October 1, 2026.
- Agents vs chains, n8n Docs, accessed October 1, 2026.
- Understand why to test (evaluations), n8n Docs, accessed October 1, 2026.
- MCP Client Tool node, n8n Docs, accessed October 1, 2026.
- Ollama Chat Model node, n8n Docs, accessed October 1, 2026.
- n8n Plans and Pricing, n8n, accessed October 1, 2026.
- Building effective agents, Anthropic, published December 19, 2024.