Cisco · Webex AI Agent

Autonomous AI Agent

Autonomous AI Agent is one of the two Webex AI Agent types. Cisco documents it as operating independently without direct human intervention: it interprets customer intent on voice and digital channels, uses a configured knowledge base, gathers required information through slot filling, and executes administrator-configured actions. Actions are of three documented kinds: fulfillment actions that run a selected Webex Connect flow, MCP client actions that invoke registered third-party tools during live conversations, and custom transfer actions that move the conversation to another AI agent, a human agent, or another destination. A maximum of 10 actions can be configured per agent, and agent handover is enabled by default.

Recorded characteristics

Function
Cisco documents the Autonomous AI Agent as working independently to fulfil defined goals, making decisions using available information and predefined rules, automating repetitive or time-consuming tasks, and using a knowledge repository to answer customer queries. The runtime is built on three documented building blocks: an Action (a task the agent performs by understanding user intent and completes by connecting to external systems), an Entity or slot (the information the agent asks the customer for in order to fulfil the intent, which triggers the action), and Fulfillment (how the agent completes the action by connecting with external systems). Fulfillment is configured either as a selected Webex Connect service and flow, or as "Manage in the source flow (voice only)" using custom events that return control to the Webex Contact Center Flow Designer. MCP client actions let the agent automatically invoke registered third-party tools during live conversations. Custom transfer actions exit the escalated path of the Virtual Agent V2 activity with metadata so the next path can be orchestrated in Flow Builder, and can be announced or silent. Guardrails are documented as preventing unethical or harmful responses.
Data access
The agent uses a knowledge base built from uploaded files, articles and extracted website sources; Cisco limits each knowledge base to 2 GB, 100 files, 10 MB per file (2 MB for .txt, 300 pages per PDF) and instructs customers not to upload PCI, PII, PHI or other sensitive data. Custom data passed from the Flow Designer can update design-time parameters such as welcome message, instructions, action descriptions and slot descriptions, and is currently supported through the voice channel only. Fulfillment and MCP actions exchange input entities and response payloads with external systems. Sessions records store the full conversation, actions performed, slot filling and fulfillment details, knowledge utilisation, and voice recordings; transcript access is off by default and must be granted explicitly by a full administrator.
Actions
Can take actions
External actions
Conditional
Human confirmation
Not required
Permission basis
Separate permissions
Administrative control
Administrators sign in to Webex AI Agent Studio from Control Hub. Documented controls include creating, deleting, exporting and importing agents (up to 100 agents per organisation, scripted and autonomous combined); choosing the Autonomous agent type; editing agent name and system ID; selecting the AI engine; building and assigning knowledge sources; adding up to 10 actions per agent; configuring fulfillment (Webex Connect service and flow, or source-flow custom events); adding MCP client actions from tools registered on the Webex Developer Portal and authorised in Control Hub; creating custom transfer actions with transfer conditions and announced or silent visibility; toggling the default-enabled Agent handover action off; conversation settings covering language, voice, speaking rate, custom vocabulary, interruptions, fulfillment timeout (10-30s, default 30), caller turn and no-input timeouts, and DTMF; previewing in chat and voice; publishing named versions; and reviewing Sessions, Version history, Change logs and Analytics. Change logs are restricted to Admin or AI agent developer roles, or custom roles with the Get Audit log permission. Transcript decrypt access is granted per user by a full administrator.
Default state
Disabled
Availability
Documented for Webex Contact Center and for Contact Center Enterprise / Packaged CCE on release 15.0(1) ES202511 or later with Cisco Unified CVP, Cisco VVB and Cloud Connect. Cisco states that access to the autonomous AI agent for voice calls is currently limited to specific customers and directs customers to Cisco support. Digital channel interactions are documented through Webex Connect flows. Regional engine variants are restricted: Webex AI Pro-US is available to US customers only and Webex AI Pro-Europe to EU customers only, and neither supports regional media from remote locations.
Licensing
Customers purchase the AI Agent add-on for the Collaboration Flex 3.0 Contact Center licence; Webex Contact Center provisions AI Agent as a service based on entitlements. For Contact Center Enterprise, AI Agent units are ordered through Cisco Commerce Workspace with a hybrid organisation setup. Digital AI Agents are activated as part of the voice subscription order, and the voice AI Agent entitlement grants access to Webex AI Agent Studio. Partners can set up a contact center trial including the Webex AI Agent feature.
External model or provider
Cisco exposes AI engines rather than raw models. In September 2026 Cisco stated that Webex AI Agent was upgraded from GPT-4.1 to GPT-5.4, with new engines listed as Webex AI Pro 2.0, Webex AI Pro US 2.0 and Webex AI Pro EU 2.0; support for 1.0 engines ends February 15, 2027. The engine is selected per agent at creation and determines available languages, voices and conversation settings.
Limitations and uncertainty
Voice access to the autonomous agent is limited to specific customers, so this is not a fully general availability capability. External action authority is entirely dependent on what an administrator configures: Cisco documents the mechanism (Webex Connect fulfillment flows, MCP tools, transfers) but does not establish a fixed set of writable external operations, so no claim is made that the agent has arbitrary API access. Fulfillment involving debit or credit cards is explicitly unsupported for PCI compliance and must be handled by third-party integration. MCP tool access is managed at organisation level only, group-level access control is not supported, MCP actions are read-only once created, and MCP tools using OAuth 2.0 Authorization Code are not shown in the available actions list. Cisco documents no per-execution employee approval step for configured actions; the MCP documentation states agents can perform actions without human intervention. The system ID is an editable, system-generated identifier and Cisco does not present it as a security principal. Sessions, Version history and Change logs are documented review surfaces; Cisco does not describe them as immutable audit logs. Maximum actions per agent is documented as 10 in the administration guide, while the MCP section states the maximum is defined by organisation configuration.

Evidence