Why AI needs tools

MIS 752 · Lab 6 Lite · Book Ch. 19 · no coding · every patient and drug here is invented
In the clinic
DoctorDoctor
➜
places a lab orderplaces a lab order
➜
the lab runs itthe lab runs it
➜
sends the resultsends the result
➜
the team decidesthe team decides
In AI
🧠Model
➜
📝asks for a tool
➜
🏥your system runs it
➜
📋sends the facts
➜
💬model answers
A good doctor does not guess the potassium. She orders the lab. A tool is the lab order: the model never runs anything itself. It asks, your system does the work, and the model answers from the facts.
📖 Read Chapter 19, Agentic Workflows I: The Operational Engine (p. 438) in the course textbook ➜
Same book on Canvas: course files
Photos: Josh Hawkins and Benjamin Richards, UNLV Photo Services. Real UNLV nursing and medical-school spaces; the patients and drugs in this lab are invented.

0 · Connect a model

Paste the free OpenRouter key from Lab 1. It stays in this browser tab only: it is never saved and never sent anywhere except OpenRouter.

1 · Four things a model cannot do alone

It learned from text that stopped in the past. It cannot see your records, cannot do exact math, cannot check your formulary, and cannot act.

When a model "uses a tool," does it run code on your server?

No. It only writes a request: the tool's name and what to fill in. Your system decides whether to run it, runs it, and sends the result back. That is why permissions and approvals live in your system, not in the model.

Why can't even the biggest model know patient 1042's eGFR?

Because that number lives only in your hospital's records, which were never in its training text, and it changes over time. Size does not help: the fact is not in the model, so it has to be looked up.

If a tool returns the right number, can the final answer still be wrong?

Yes. The model reads the result and writes the answer, and it can copy a number wrong, skip a lookup it needed, or misread the result. That is why this page shows every step: check what was looked up, not just what was said.

📖 Read more in the book: What Makes an Agent: Observe, Plan, Choose Tools, Execute, Evaluate (p. 439)

7 · What the model actually reads

It never sees your code or your database. For each tool it sees one order form. That paragraph decides when the tool gets used.

Does the model ever see your database or your code?

No. It sees only the order form (the tool's name, the paragraph about what it is for, and the blanks to fill in), and then whatever your system chooses to send back. Everything else stays on your side, which is exactly where access control belongs.

A form says "Use this for any question about a patient." Someone asks a drug's price. What should happen?

The model should not call the patient tool, because nothing on the form covers prices. If no tool fits, a well-behaved model says it cannot look that up instead of forcing the wrong tool. Testing this "don't call it" case matters as much as testing that the right calls happen.

🤔 Think it through: if the get_drug_info form said "Use only for cancer drugs," would the model still check zephadril? So who really controls when a tool gets used: the programmer, or whoever writes that paragraph?
📖 Read more in the book: Prompt Injection Through Clinical Data (p. 456)
Screenshot of the Berkeley Function Calling Leaderboard
Screenshot: Berkeley Function Calling Leaderboard

🌐 Try it live: how good are real models at using tools?

Researchers at UC Berkeley test many models on tool calling and publish the scores. Free, no account.
  1. Open the leaderboard and sort by overall accuracy (click the column header).
  2. Find a maker from this lab's model list (OpenAI, Google, Qwen, DeepSeek, Mistral) and note where its models rank.
  3. Look for the multi-turn scores: several tool calls in a row, like the drug check in example 3.
Open the Berkeley Function Calling Leaderboard ➜

8 · Design your own tool

This is the real skill. Think of a moment in your own work when an AI assistant would need a fact or an action it cannot have on its own. Write the order form for it. No code: just plain English.

📖 Read more in the book: Should You Build This? (p. 461) 📖 Workshop: Building a Prior Authorization Agent (p. 463)

9 · Your turn

Ask about patient 1042 or 2077, any invented drug (zephadril, renavex, cardiomyst, glycofane, pulmosyn, neurvolan), some math, a booking, or something no tool covers, such as a dose.

🤗 Try it live on Hugging Face

Hugging Face, the home of open AI models, runs a free course on AI agents. Its chapter on tools explains what this lab just showed you, with pictures.

Screenshot of Hugging Face Agents Course: What are Tools?
Screenshot: Hugging Face Agents Course, Unit 1

Hugging Face Agents Course: What are Tools?

Free to read; no account needed (skip the sign-up box).
  1. Read “What are AI Tools?” and look at the table of common tools.
  2. Pick the tool in that table closest to a job in a hospital, and say what it would look up or do.
  3. Find “How do we give tools to an LLM?” and compare it with the order forms in section 7 of this lab.
Open it on Hugging Face ➜
The course says a model cannot call a tool on its own. Where did you see that in this lab, and why does it matter for patient safety?

Every example showed the same split: the model only wrote an order (the tool's name and what to fill in), and your system ran it and sent back the result. That split is where safety lives: the hospital's system can check permissions, log every call, and require a person's approval before anything is booked or changed. If the model could act on its own, none of those checks would have a place to sit.

10 · Hand it in (Canvas, Lab 6)

1. Download your submission with the button below, then upload the file to the Lab 6 assignment on Canvas. It holds every question, your predictions, both answers, every lookup, your own tool, and everything you wrote.

2. Answer these five, a few sentences each. Each asks why:
  1. When your prediction was wrong, what had you assumed about the model that turned out not to be true?
  2. The "Check" example needed two lookups in a row. If the model made only the first and answered anyway, what would it get wrong, and how would you catch that from the steps without knowing the right answer?
  3. The "Act" tool only drafts. Imagine it booked the visit directly. Describe one way that could hurt a patient or the clinic, and the control you would add.
  4. Your own tool. Describe the moment in your work that needed it, why the model could not do it alone, and whether the model used your tool the way you meant. What did you change in the "what it is for" paragraph, and why?
  5. Your tool sent back an example answer. In real life, what if that answer were wrong or out of date? Who downstream would act on it, and what would have to be in place for someone to catch it?

Nothing you type is stored anywhere. Download your file before you close the tab.