Why an AI agent that places orders is not a chatbot

Dubai startup aradus says it has automated more than 90 per cent of customer orders. Co-founder Karam El Assaad on what that measures and what stays human.

Three glowing purple vertical elements in a dark setting, featuring a server rack with multiple active server units and organized cables, flanked by panels displaying internal cables and circuit board designs.

Much of the enterprise AI market is still piloting chatbots. aradus, a Dubai-based startup launched in May 2026, says its AI agents are already in production with manufacturers and distributors across the Middle East and North Africa, processing orders, answering enquiries and updating records inside the ERP, CRM and messaging tools those businesses already run.

Its headline claim is that it has automated more than 90 per cent of customer orders and inbound enquiries across live workflows. In written answers to The Datatech Times, co-founder and chief executive Karam El Assaad explains what that figure measures, why an agent that acts is a different engineering problem from one that answers, and where integration inside a distributor actually breaks.

The measurement, he says, is taken at the level of the workflow rather than the task. "We measure it at the workflow level: of the real transactions entering a live workflow, what percentage completes end to end without a person having to manually process the transaction?" Proving that path usually takes six weeks, with a further six to 12 weeks in most cases before the figure is extended.

"The important word is complete. If AI reads an order but an employee still has to validate it, enter it into the ERP and send the confirmation, I would not call that an automated order." The remaining share is mostly exceptions, he says, and that is where the company wants people: a customer using a product alias the system has never seen, quantities or prices that breach a commercial agreement, an ERP record that conflicts with the document. "The goal is not to force 100 per cent autonomy. The goal is to make human attention scarce and intentional. Software should process the normal transactions; people should handle the unusual or economically important ones."

A read operation and a write operation

The distinction between a chatbot and an execution agent is, in his account, the whole engineering problem. "A chatbot can be wrong and the cost is often a bad answer. An execution agent can be wrong and create a bad order, send the wrong document or move money. That changes the engineering problem completely."

"The difficult part is not making the model sound intelligent. It is giving it controlled access to real systems and making actions safe. You need permissions, deterministic validation, and audit trails with reasoning." That extends, he says, to making sure the same order is not created twice, to retries and audit logs, to clear rules on when an action needs approval, and to the agent understanding the business context around an action rather than only the text in front of it.

"That is why I think the chatbot framing undersells enterprise AI. Answering a question is a read operation. Running a business requires understanding and manipulating data. The value appears when the software can move from 'here is what I found' to 'I checked the order, reconciled the SKU, created it in the ERP, sent the acknowledgement, and escalated the one thing that needs you.'"

Meaning, not connectivity

Asked where integration proves hardest in a manufacturer or a distributor, El Assaad does not point at the API. "The API is often not the hardest part. The hardest part is meaning. A manufacturer might have the same customer represented slightly differently across an ERP, a CRM and an email thread. The customer uses its own SKU names. Units of measure are inconsistent. SKU codes for the same underlying product might evolve over time." An employee may know that one buyer always means a particular warehouse when they use a certain purchase order reference, he says, and none of that is visible from an API specification.

"So what breaks first is usually what we call entity reconciliation and business context, not connectivity. The integration can technically write to the ERP while still writing the wrong thing." aradus treats connectors as core infrastructure, he says, but the higher-value layer is resolving identities, learning aliases, linking documents to orders and shipments, and encoding a company's actual operating rules.

The company's launch release put avoided demurrage at 100 to 200 US dollars per container through shipment tracking. El Assaad does not present that as a universal saving. "It is an expected avoided-cost range in cases where earlier visibility and action prevent a demurrage, detention or related port charge that would otherwise have occurred." The economics vary by carrier, port, free-time allowance, container type and how quickly an operation can react, he says, and in some cases the value is in avoiding an escalation entirely rather than shaving a fixed amount from every shipment. "The important point is that shipment tracking by itself is not the product. A prettier ETA does not save money. The system has to turn the tracking event into an operational action: flag the risk early, identify the affected shipment or order, notify the right person, chase the required document or trigger the next step."

Evidence, authority and the line to a human

Much of the source material in these businesses is unstructured: email, PDFs, WhatsApp messages and spreadsheets. "The wrong approach is to ask a model to read everything and then treat its answer as truth. We separate understanding from authority." Unstructured sources provide evidence, systems of record provide further evidence, and deterministic checks and company-specific rules are applied before anything is written. For important fields, he says, the system keeps provenance: where a value came from, which document or message supported it, what transformation was applied and which validation rule allowed the action.

"If the purchase order says 500 units and the invoice says 5,000, the agent should not be 'creative'; the system should flag it and stop the agent for a human to take control. Auditability matters more as autonomy increases." AI can handle unstructured information precisely because it is good at interpretation, he adds. "But interpretation should never mean giving the model unlimited authority to invent business facts."

The line between what the agent completes and what is escalated is set by risk and evidence rather than by how capable the model seems. "We do not decide autonomy based on whether a model feels smart. We decide it based on risk and evidence. A low-value, reversible action with strong evidence should have a much higher autonomy threshold than an irreversible action with financial, regulatory or customer consequences. Creating a draft reply is different from releasing a payment." Some conditions require a person regardless of model confidence, he says, and when they do the system should explain the exception and recommend the next action rather than simply ask for a review.

That line has moved since launch, though not for the reason a vendor might be expected to give. "Over time, autonomy levels increase because the system accumulates evidence, not necessarily because the models got smarter. We see which exceptions humans consistently approve, which aliases and corrections recur, and which rules can safely become deterministic. Then more of the normal path becomes autonomous."

Built for fragmentation

The region shaped the product by refusing to let it assume anything tidy. "MENA forced us to build for fragmentation from day one. You cannot assume a single ERP, a clean EDI network or one communication channel. A manufacturer may run a global ERP while customers send orders by email, Excel or WhatsApp." Product names differ between trading partners, documents change by destination, and Arabic and English can coexist in the same operating flow. The principle that followed, in his words, is to "not require the world around the customer to become standard before the customer can automate."

Whether the model travels beyond the region will be decided by architecture rather than by finding the same workflow in another country. "If customer-specific rules, aliases, document types, approval policies and integrations can be configured as context while the underlying execution model stays the same, then the product is portable." Fragmentation, he argues, is not unique to the Middle East. "Every large manufacturer eventually becomes its own fragmented market. Even the biggest companies have a fragmented long tail of customers and suppliers. That is why we think the problem is regional in its early expression, but global in its underlying economics."

aradus was founded in May 2026 by El Assaad and Omar Daouk, its chief product officer. El Assaad previously co-founded Farmlend, a UK business-to-business import and export marketplace, where as chief operating officer he helped grow the business to more than 80 million US dollars in annualised gross merchandise value, and spent four years at NCR in enterprise and channel sales across the Middle East and Africa. The company says it works with manufacturers and distributors in pharmaceuticals and medical supplies, food and beverage, cosmetics, electronics, plastics and packaging, auto parts and industrial goods.