Tool use: how an AI acts instead of answering

Tool use lets an AI model trigger an outside action rather than merely producing text.
3 min read
Believemy logo

A model on its own can only produce text. Tool use is the mechanism that lets it do something else: query a database, send a message, calculate an amount. It is what turns a conversation into work done.


Definition

Tool use is the mechanism by which a model requests the execution of an outside action and receives the result in order to continue its work.

The sequence matters, because it is counter-intuitive: the model executes nothing itself. It emits a structured request, your system executes it, and returns the result. The model decides, your code acts.

Good to know

That separation is your main safeguard. Since your system does the executing, it is your system that can refuse. A model can ask to delete a thousand rows, nothing obliges you to comply.


The three tools that change everything

Calculation

A model is bad at arithmetic because it predicts plausible text. Giving it a calculator removes an entire category of errors, and it is often the first tool to connect.

Search in your data

Rather than pasting everything into the conversation, a search tool lets the model ask for what it needs. It is the RAG principle made active: it fetches instead of receiving.

The business action

Create a record, send a quote, update a status. That is where the value is, and where caution is required.


Best practices

Describe each tool as you would to a new hire. The model picks its tool from the description you give. A vague description produces inconsistent tool choices, and that is almost always the cause when an agent takes the wrong action.

Give it few. Three well-chosen tools beat fifteen. Beyond about ten, the quality of the choice degrades noticeably.

Separate reading from writing. Tools that read can be called freely. Those that write, send or delete deserve approval, at least at the start: see Human in the loop.

Return explicit errors. A tool answering "error" does not help the model. A tool answering "this client does not exist, check the identifier" lets it correct itself on the next pass.

Warning

A tool connected to your data acts with the rights you grant it, on the decision of a model that can be wrong or fall for a Prompt injection. Grant the minimum rights needed, never more out of convenience.


Frequently asked questions

Question

How is it different from MCP?

Tool use is the mechanism, MCP is a standard for exposing tools reusably. You can perfectly well do tool use without MCP, by describing your tools yourself.


Question

Can the model chain several tools?

Yes, and that is the normal behaviour of an agent: each pass of the Agent loop can trigger a call whose result shapes the next.


Question

What happens if a tool is unavailable?

It depends on what you return. A clear message lets the model try something else or stop cleanly. This is why the quality of error messages matters as much as the quality of descriptions.


Question

How do you connect your first tool?

By starting with a read-only tool, which cannot break anything while you observe the model's behaviour. Our Claude Code course follows that progression, from read-only to actions with consequences.

Related terms

Discover our aI and automation glossary

The vocabulary of artificial intelligence and automation, explained for people who want to use it in their business, not for people who build the models.

Share this article

Want to help us? Share this article on your networks or even better: on your site, in an article or in your newsletter.