Autonomous AI Agent
Autonomous AI Agent is one of the two Webex AI Agent types. Cisco documents it as operating independently without direct human intervention: it interprets customer intent on voice and digital channels, uses a configured knowledge base, gathers required information through slot filling, and executes administrator-configured actions. Actions are of three documented kinds: fulfillment actions that run a selected Webex Connect flow, MCP client actions that invoke registered third-party tools during live conversations, and custom transfer actions that move the conversation to another AI agent, a human agent, or another destination. A maximum of 10 actions can be configured per agent, and agent handover is enabled by default.
Recorded characteristics
- Function
- Cisco documents the Autonomous AI Agent as working independently to fulfil defined goals, making decisions using available information and predefined rules, automating repetitive or time-consuming tasks, and using a knowledge repository to answer customer queries. The runtime is built on three documented building blocks: an Action (a task the agent performs by understanding user intent and completes by connecting to external systems), an Entity or slot (the information the agent asks the customer for in order to fulfil the intent, which triggers the action), and Fulfillment (how the agent completes the action by connecting with external systems). Fulfillment is configured either as a selected Webex Connect service and flow, or as "Manage in the source flow (voice only)" using custom events that return control to the Webex Contact Center Flow Designer. MCP client actions let the agent automatically invoke registered third-party tools during live conversations. Custom transfer actions exit the escalated path of the Virtual Agent V2 activity with metadata so the next path can be orchestrated in Flow Builder, and can be announced or silent. Guardrails are documented as preventing unethical or harmful responses.
- Data access
- The agent uses a knowledge base built from uploaded files, articles and extracted website sources; Cisco limits each knowledge base to 2 GB, 100 files, 10 MB per file (2 MB for .txt, 300 pages per PDF) and instructs customers not to upload PCI, PII, PHI or other sensitive data. Custom data passed from the Flow Designer can update design-time parameters such as welcome message, instructions, action descriptions and slot descriptions, and is currently supported through the voice channel only. Fulfillment and MCP actions exchange input entities and response payloads with external systems. Sessions records store the full conversation, actions performed, slot filling and fulfillment details, knowledge utilisation, and voice recordings; transcript access is off by default and must be granted explicitly by a full administrator.
- Actions
- Can take actions
- External actions
- Conditional
- Human confirmation
- Not required
- Permission basis
- Separate permissions
- Administrative control
- Administrators sign in to Webex AI Agent Studio from Control Hub. Documented controls include creating, deleting, exporting and importing agents (up to 100 agents per organisation, scripted and autonomous combined); choosing the Autonomous agent type; editing agent name and system ID; selecting the AI engine; building and assigning knowledge sources; adding up to 10 actions per agent; configuring fulfillment (Webex Connect service and flow, or source-flow custom events); adding MCP client actions from tools registered on the Webex Developer Portal and authorised in Control Hub; creating custom transfer actions with transfer conditions and announced or silent visibility; toggling the default-enabled Agent handover action off; conversation settings covering language, voice, speaking rate, custom vocabulary, interruptions, fulfillment timeout (10-30s, default 30), caller turn and no-input timeouts, and DTMF; previewing in chat and voice; publishing named versions; and reviewing Sessions, Version history, Change logs and Analytics. Change logs are restricted to Admin or AI agent developer roles, or custom roles with the Get Audit log permission. Transcript decrypt access is granted per user by a full administrator.
- Default state
- Disabled
- Availability
- Documented for Webex Contact Center and for Contact Center Enterprise / Packaged CCE on release 15.0(1) ES202511 or later with Cisco Unified CVP, Cisco VVB and Cloud Connect. Cisco states that access to the autonomous AI agent for voice calls is currently limited to specific customers and directs customers to Cisco support. Digital channel interactions are documented through Webex Connect flows. Regional engine variants are restricted: Webex AI Pro-US is available to US customers only and Webex AI Pro-Europe to EU customers only, and neither supports regional media from remote locations.
- Licensing
- Customers purchase the AI Agent add-on for the Collaboration Flex 3.0 Contact Center licence; Webex Contact Center provisions AI Agent as a service based on entitlements. For Contact Center Enterprise, AI Agent units are ordered through Cisco Commerce Workspace with a hybrid organisation setup. Digital AI Agents are activated as part of the voice subscription order, and the voice AI Agent entitlement grants access to Webex AI Agent Studio. Partners can set up a contact center trial including the Webex AI Agent feature.
- External model or provider
- Cisco exposes AI engines rather than raw models. In September 2026 Cisco stated that Webex AI Agent was upgraded from GPT-4.1 to GPT-5.4, with new engines listed as Webex AI Pro 2.0, Webex AI Pro US 2.0 and Webex AI Pro EU 2.0; support for 1.0 engines ends February 15, 2027. The engine is selected per agent at creation and determines available languages, voices and conversation settings.
- Limitations and uncertainty
- Voice access to the autonomous agent is limited to specific customers, so this is not a fully general availability capability. External action authority is entirely dependent on what an administrator configures: Cisco documents the mechanism (Webex Connect fulfillment flows, MCP tools, transfers) but does not establish a fixed set of writable external operations, so no claim is made that the agent has arbitrary API access. Fulfillment involving debit or credit cards is explicitly unsupported for PCI compliance and must be handled by third-party integration. MCP tool access is managed at organisation level only, group-level access control is not supported, MCP actions are read-only once created, and MCP tools using OAuth 2.0 Authorization Code are not shown in the available actions list. Cisco documents no per-execution employee approval step for configured actions; the MCP documentation states agents can perform actions without human intervention. The system ID is an editable, system-generated identifier and Cisco does not present it as a security principal. Sessions, Version history and Change logs are documented review surfaces; Cisco does not describe them as immutable audit logs. Maximum actions per agent is documented as 10 in the administration guide, while the MCP section states the maximum is defined by organisation configuration.
Evidence
- Webex AI Agent Studio Administration guide
Supports: Function · Actions · External actions · Human confirmation · Permission basis · Admin controls · Default state · Data access · External model · Licensing · Availability · Limitations · General · Primary source
Autonomous AI agents operate independently without direct human intervention, use a knowledge repository, and are built on three building blocks: Action (a task performed by understanding user intent and completed by connecting to external systems), Entity/slot (information gathered from the customer, the trigger for an action), and Fulfillment (how the action is completed by connecting with external systems).
Actions page shows Agent handover enabled by default; +Add Actions offers Browse actions > Select available for MCP client configuration, Add new > Fulfillment, and Add new > Transfer. A maximum of 10 actions can be configured for an AI agent. Fulfillment is configured by selecting a Webex Connect service and flow, or by choosing Manage in the source flow (voice only) with custom events.
Fulfillment determines how the AI agent completes the action by connecting with external systems, executing a selected Webex Connect flow. Custom transfer actions transfer calls to another AI agent, a human agent, voicemail box, hunt group or another number, exiting the Virtual Agent V2 escalated path with metadata; transfers can be announced or silent.
No per-execution employee approval is documented for configured fulfillment, MCP or transfer actions; transfer visibility only controls whether the customer is told about a transfer before it executes.
Webex AI Agent Studio can only access services and flows configured within the Webex Connect client-level workspace. A separate user roles and permissions table defines Full Administrator, Contact Center Service Administrator, Provisioning Administrator, Read-only Administrator and Supervisor access to AI Agent Studio; transcript access is off by default and granted per user by a full administrator.
Administrators create, delete, export and import agents (up to 100), choose the Autonomous type, edit name and system ID, select the AI engine, add up to 10 actions, configure fulfillment, knowledge and transfers, toggle the default-enabled Agent handover off, set conversation settings (language, voice, speaking rate, custom vocabulary, interruptions, fulfillment timeout, caller turn and no-input timeouts, DTMF), preview and publish. Change logs are accessible only to Admin or AI agent developer roles, or custom roles with the Get Audit log permission.
An autonomous agent must be created, given a knowledge base, configured with actions, previewed and then published with a version name before it is live.
Knowledge sources can be files, articles and website sources, with 2 GB per knowledge base, 100 files, 10 MB per file, 2 MB per .txt and 300 pages per PDF; PCI, PII, PHI and other sensitive data must not be uploaded. Sessions record session ID, consumer ID, channel, transcript, voice recordings, actions performed including transfer, slot filling and fulfillment details, and knowledge utilisation.
AI engine choices at creation are Webex AI Pro 1.0/2.0, Webex AI Pro-US 1.0/2.0 and Webex AI Pro-Europe 1.0/2.0, with 1.0 engines to be deprecated; the engine determines the available conversation settings.
Customers purchase the AI Agent add-on for the Flex-3.0 Contact Center licence; Webex Contact Center provisions AI Agent based on entitlements. Contact Center Enterprise orders AI Agent units under the Collaboration Flex 3.0 Contact Center Offering.
Contact Center Enterprise requires release 15.0(1) ES202511 or later on Cisco Unified CVP, Cisco VVB and Cloud Connect, with a hybrid organisation setup. Regional engines are restricted to US and EU customers respectively and do not support regional media from remote locations.
As part of PCI compliance, the autonomous AI agent does not support fulfillment involving debit or credit cards. Version history and Change logs record configuration versions and who changed what, but are not described as immutable audit logs.
Analytics reports total sessions, sessions handled by the AI agent without human intervention, total agent handovers, daily averages, message counts and user statistics.
- Use AI agent templates
Supports: Function · Actions · Primary source
Autonomous agents dynamically generate responses and require users to define only the actions the agent performs.
Autonomous templates ship preconfigured actions such as checking appointment availability, creating, looking up and cancelling appointments, plus a disabled-by-default SMS confirmation action requiring a Webex Connect phone number asset.
- AI in Webex - Configure MCP Client Action (Webex for Developers)
Supports: External actions · Permission basis · Human confirmation · Limitations · Admin controls · Actions · Primary source
MCP client capability enables autonomous AI agents to connect to third-party tools, automatically invoke them during live conversations, retrieve real-time data and perform actions without human intervention.
MCP configuration requires the MCP server URL, authentication type and credentials; supported authentication is OAuth2 client credentials, API key or custom header based auth, with tools registered on the Webex Developer Portal and authorised in Control Hub.
MCP tools are invoked automatically during live conversations, with no documented per-invocation human approval.
MCP actions are read-only once created; group-level access control is not supported and access is managed at organisation level only; OAuth 2.0 Authorization Code tools are not displayed; maximum actions per agent is defined by organisation configuration.
After adding an MCP tool, administrators can verify tool name, description, server details, input parameters, output returned, execution state, latency, server name and ID, and transaction ID.
MCP tool details, including action name, description and input entities, are populated automatically from the MCP server definition and synchronised from registration or provisioning changes.
- Use AI agents for customer interactions
Supports: Availability · Function · Primary source
Access to the autonomous AI agent for voice calls is currently limited to specific customers; customers are directed to contact Cisco support.
AI agents are integrated with voice and digital channels; the Virtual Agent V2 activity provides the real-time conversational experience in the call flow, with Handled and other outcome paths.
- What's new for administrators in Webex Contact Center
Supports: External model · Primary source
Webex AI Agent has been upgraded from GPT-4.1 to GPT-5.4; new engines are Webex AI Pro 2.0, Webex AI Pro US 2.0 and Webex AI Pro EU 2.0, and support for 1.0 engines ends February 15, 2027.
- Understand AI engines for AI agents
Supports: External model · Primary source
Cisco documents the AI engine as the component that handles user input, understands intent and generates responses, and that administrators choose per agent.
- Configure custom data and custom events for AI agents
Supports: Data access · Actions · Primary source
Custom data passed from the Flow Designer can update autonomous agent design-time parameters including goal, welcome message, instructions, action description and slot description; custom data is currently supported through the voice channel only.
Custom events allow a defined exit from the AI agent to return control to the Webex Contact Center flow for fulfillment, after which the conversation can resume.
- Supported languages and voices for AI agents
Supports: Availability · Primary source
Supported languages and voices for autonomous AI agents are listed per AI engine with digital and voice support and GA or Beta status.
- Webex AI Agent (Cisco Unified Contact Center Enterprise 15.0(1) Features Guide)
Supports: Function · Availability · Primary source
Webex AI Agent provides two agent types, Scripted AI Agent and Autonomous AI Agent; the autonomous type supports more dynamic and flexible interactions including advanced event handling and transfer scenarios.
Cisco documents Webex AI Agent configuration task flows for both voice channels and digital channels in the Contact Center Enterprise features guide.