For an n8n AI agent vs workflow decision, use a workflow when the sequence is fixed, an agent when the job is open-ended or back-and-forth, and an agent with approvals when actions are sensitive. If a wrong step is costly and the job is rare, skip both and keep a human.

Quick answer: let the agent decide only when the steps can't be written down in advance

The agent adds exactly one thing: it chooses the order of steps and which tools to call, at run time. Everything deterministic stays a workflow. That is the whole idea, and most of the confusion comes from forgetting it. We call the sorting method the two-question test. The grid and a cost rule follow.

Want one honest agent or automation verdict at a time? The newsletter does that.

What changed: the AI Agent node vs the new standalone n8n Agents

The classic AI Agent node sits inside a workflow, and the workflow stays in charge. Per n8n, everything you built keeps working and the node keeps its name.

The new Agents are a separate object. Per n8n's announcement, you reach them from chat, Slack, a schedule, or from a workflow through the Message an Agent node (documented as a regular node). An agent can use workflows, MCP servers (you can exclude individual tools), and sub-agents.

n8n describes a workflow tool as “a whole process you've already built, run exactly the way you defined it.” The agent decides when it runs. What happens inside is fixed. That split is the part worth remembering.

AI Agent nodeStandalone n8n Agent
Where it livesOne node inside a workflowIts own object
Who decides the sequenceThe workflowThe agent
What it can callTools attached to the nodeWorkflows, MCP servers, sub-agents
How it startsYour workflow triggerChat, Slack, schedule, or Message an Agent

Availability, per n8n's docs at preview launch: Cloud users can use Agents. Self-hosted Community needs n8n 2.32.3 or later with the agents module enabled, and queue mode is not supported yet. The docs also warn: “They can make mistakes, and their behavior may change.” Hosting: self-hosting guide.

The two-question test: who should control the steps?

  1. Can you write the steps down in advance? If you can list them, a workflow can run them.
  2. What does a wrong step cost? Money, trust, or a deleted record means a human or a gate in the loop.

Per n8n, agents suit “open-ended or back-and-forth” jobs and workflows suit fixed sequences. That covers the first question. The grid below adds the second, which is the one people skip.

Wrong step is cheapWrong step is costly
Steps are knowablePlain workflow. Invoice routing to the right folder and sheet.Workflow in charge, human at the risky step. Refunds above a threshold, queued for a person.
Steps depend on the requestAgent in charge, workflows as scoped tools.An internal “ask the ops bot” desk.Agent with approvals, or skip it. If every tool needs sign-off, keep a human and a workflow.

A fixed pipeline with one fuzzy step (enrich a lead, then draft a one-off reply) is a workflow with an agent step (Pattern 1).

For the generic “do I need AI at all” version, see how to tell if a task needs AI or just automation.

Pattern 1: workflow in charge, agent as one step

Use this when the pipeline is fixed but one step needs judgment: classify an email, draft a reply, extract fields from messy text. n8n's wording: “Sometimes you want the workflow in charge, with the agent as a step inside it.”

Two ways to build it: the classic AI Agent node, or the Message an Agent node to call a standalone agent.

Why it is the safe default: a bad model answer stays inside one node, and the rest of the run carries on as designed. A practitioner on X put it well on 2026-10-02: in workflow automation “someone architects the path” (@Kcodess). With a step-agent, you still architect the path.

The honest con: you pay for model calls on every run, even when an IF node could handle the obvious cases for free.

A r/n8n thread titled “I added an AI agent to my n8n booking workflow” (2026-07-01) suggests this is what people reach for first. Reports on standalone Agents are scarce, because the preview is days old.

Pattern 2: agent in charge, workflows as scoped tools

Pattern 1 keeps you in control. This one hands over the wheel, so be pickier. Use it when requests are conversational and the order depends on what the user says.

The upside: each tool is a workflow you trust. Per n8n, “the agent never holds the keys to your instance,” so credentials stay inside the workflow. Scope is what you expose, minus what you exclude.

The risk is the mirror image: the wrong tool or the wrong order. n8n's debugging content, citing LangChain's 2026 report, lists wrong tool selection among six failure modes.

Sub-agents come last, only when one agent clearly can't hold the job. n8n's multi-agent post (2025-12-22) cites Anthropic research: multi-agent beat single-agent by 90.2% at 15x the tokens. See multi-agent systems.

Approvals: what to mark as sensitive

Per n8n: “Mark a tool as sensitive and the agent pauses for Approve or Reject before using it.” The docs describe approving in the chat.

  • Mark sensitive: anything that sends an external message, moves money, deletes, or writes to a system of record.
  • Leave unmarked: read-only lookups.

A sourced cautionary case: per the Guardian (2026-04-29), a coding agent deleted PocketOS's production database and backups in nine seconds, according to its founder. Not n8n, and no failure rate, but a reason to start where the blast radius is small.

The honest limit: approvals are a seatbelt, not a design. If every tool needs approval, you wanted a workflow with a manual approval step. The docs we read do not confirm whether approvals cover MCP tools or sub-agents. Scoping: what access an AI agent should have.

The execution-counting cost rule

Per n8n's announcement (2026-09-25): “One turn with an agent is one execution. Tool calls to your workflows and to sub-agents don't count separately, and agents share your workflow execution quota.” The Message an Agent docs say each message counts as one execution. For classic workflows, n8n's pricing page defines an execution as one run of the entire workflow, however many steps it has.

1
execution per agent turn

One agent turn counts as one execution, even when it calls several workflow tools or sub-agents.

Source: n8n, Introducing n8n Agents (announcement, 2026-09-25, preview).
ScenarioExecutions counted, per n8n
One message to an agent, one reply1
That turn calls three workflow toolsStill 1
Classic workflow run with an AI Agent node inside1 per run
A workflow calls an agent via Message an AgentEach message is one execution; the docs we read don't say how it adds up with the calling run

Illustrative, not a measured bill: 100 conversations a day, 5 turns each, 3 workflow tools per turn. By the rule above that is 500 executions, not 2,000. For limits, see n8n's pricing page.

The catch, and it matters: cheap in executions is not cheap overall. A turn with many tool calls is still one execution but runs a model repeatedly. The docs we read don't state per-turn model cost, and model usage runs through your own provider credentials or n8n Gateway credits. Check your provider's billing after week one. Other tools count differently: see tasks vs operations vs credits.

Skip the agent: jobs that should stay a plain workflow

This is the section the vendor won't write. If you can draw the path, keep the workflow:

  • Nightly syncs between two systems
  • Form submission to CRM
  • Invoice number generation
  • Scheduled reports
  • Anything with a fixed schema and a fixed path

Workflows are cheaper, auditable, repeatable, and free of surprise tool choices. A fixed sequence plus an LLM is just a slower, pricier workflow. It is less exciting than an agent demo, and it will still be running correctly next month.

n8n agrees, quietly: “the more fixed the sequence, the better a workflow fits, even if one of the steps is a model making a decision.” Its 2026-08-10 MCP post says to use nodes “wherever the logic doesn't need a decision made.”

Zapier, a competing vendor, reports that workflows reserving AI for reasoning steps cost 71% less to run (375 mid-market and enterprise companies, 2026-07-29). Directional, not an SMB stat.

The symptom of a misused agent: you keep writing “always do X, then Y” in the system prompt. That is a workflow wearing a costume. Cleanup help: how to write instructions for an AI agent and how to fix AI agent automations that keep breaking. For cross-tool angles, see n8n vs Make for AI agents.

A 5-minute migration checklist: should you convert an existing workflow?

Default answer: no. A working workflow is not a problem to fix. Convert only if (a) your branching has become a maze of IFs for fuzzy inputs, or (b) people want to talk to the automation instead of triggering it. Per n8n, the line is movable in both directions, so you don't need to get it right on day one.

  1. Tools: which workflows become tools, and what do you exclude?
  2. Sensitive: which tools send, spend, delete, or write, and are they marked?
  3. Monitoring: how will you spot a wrong tool choice? See how to monitor AI automations.
  4. Fallback: where does a human take over?
  5. Counting: how will you track executions and model usage in week one?

Test first: how to test an AI automation before going live.

FAQ

Do n8n Agents replace workflows?

No. Per n8n, workflows are what agents call as tools, and the classic AI Agent node keeps working. Agents decide when a workflow runs; the workflow runs as you defined it.

Does an n8n agent tool call count as an execution?

Per n8n, no. One agent turn is one execution, tool calls to workflows and sub-agents are not counted separately, and agents share the workflow execution quota.

Can an n8n agent run without my approval?

Yes, for tools you haven't marked sensitive. Unmarked tools run on their own.

Is an n8n agent more expensive than a workflow?

It depends. A turn counts as one execution even with many tool calls, but each turn can run a model repeatedly, and the docs we read don't state per-turn model cost. Check your provider's billing.

Can a workflow call an n8n Agent?

Yes. n8n documents a Message an Agent node for this, and each message counts as one execution. The docs we read don't spell out how that combines with the calling run.

Are n8n Agents available on self-hosted?

Partly, at preview launch. Per n8n's docs, Community needs n8n 2.32.3 or later with the agents module enabled, and queue mode is unsupported. Check current docs.

The short version

Workflow when you can write the steps down. Agent when the next step depends on the request, with every send, spend, or delete tool marked sensitive. Human when a mistake is costly and rare. In one line: knowable steps mean workflow, request-dependent steps mean agent, costly mistakes mean a gate. New to building agents? Start with how to build an AI agent without coding.

Want the next n8n or agent verdict when it lands? The newsletter is the easy way. No pressure.