Sierra has launched Fleming-1, a new model built to detect when the caller on a business phone line is not a person at all, but an AI agent. Announced on October 7, 2026, Fleming-1 scores a caller's speech in real time and flags audio that appears to be AI-generated, giving companies a signal for a question that is rapidly becoming routine: when the phone rings, what exactly is calling?

According to Sierra, the problem arrived faster than expected. The company said it first ran into agent-to-agent calling in 2025, when agents built on Sierra's own platform began calling other Sierra-built agents inside healthcare workflows. With consumer personal agents such as Meta's Muse and other assistants now placing calls on behalf of their owners, Sierra expects a growing share of inbound business calls to originate from AI acting for customers rather than from people dialing directly.

A caller ID for the agent era

Sierra frames Fleming-1 through the history of Caller ID. According to Unite.AI's coverage of the launch, Sierra described Fleming-1 as answering the modern version of that problem. Caller ID never told a household whether to pick up; it simply identified the caller. Sierra said Fleming-1 works the same way: it tells the business that an agent is likely on the line, and the business decides what happens next.

The detection runs while the conversation is still in progress. According to Sierra, Fleming-1 analyzes a caller's speech in real time, looking beyond how the voice sounds to a human listener and scoring the audio for signs of synthesis. The company said distinguishing synthetic voices over phone lines is getting harder as models improve and as background noise, muffled audio, and poor connections obscure the clues. The model is tuned conservatively by default, the company said, so real customers are less likely to be misidentified, and the resulting flag is intended as information rather than an automatic verdict.

Businesses could use that signal in several ways. As reported by Unite.AI, Sierra gave the example of a bank adding a verification step when an agent calls, or a high-volume contact center measuring how often automated callers appear in its queue. Some automated callers will be fraudsters probing account security at scale, the company noted, while others will be legitimate customers who delegated a chore to an agent, or people who rely on text-to-speech tools.

Why detection landed now

The timing reflects how quickly voice agents moved into production customer service. Sierra raised a $950 million round in May at a $15.8 billion valuation, and its platform now underpins large deployments. Reported by PYMNTS, used-car retailer CarMax now routes all inbound store and customer-experience calls through AI voice agents built with Sierra, with the agents answering routine questions and handing the rest to human associates.

That scale is exactly what makes detection a two-sided problem. The same platform that helps a retailer answer its phones also powers personal agents calling other businesses, which is why Sierra paired the Fleming-1 launch with a second announcement: an identity standard for those calls. The combination amounts to a bet that the phone channel needs both a way to verify declared agents and a way to catch undeclared ones.

The identity half: Personal Agent Protocol

One day before the Fleming-1 announcement, Sierra and Meta unveiled the Personal Agent Protocol, an open standard meant to define how personal AI agents authenticate with businesses, according to Unite.AI's report on the protocol. Industry partners named in the announcement include Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. Sierra plans to publish the v0.1 specification later in October 2026, followed by design workshops and a reference implementation.

The protocol covers how an agent discovers what a company offers, starts a session, signs in on the customer's behalf, and completes a task, with sessions built on the OAuth standard. According to a summary of the announcement on Dev.to, a guest agent can handle light tasks such as checking stock or a returns policy, while account tasks require the customer to sign in and choose read-only or write access, with companies setting the limits on what agents may do.

Analysis by Forkast argues the protocol fills a specific missing layer. As reported by Forkast, the agentic commerce stack is splitting into an execution layer (MCP, A2A), a payment layer (Visa TAP, OpenAI ACP), and an identity and session layer — the space the Personal Agent Protocol aims to occupy. In that framing, Fleming-1 handles the calls where agents do not identify themselves, while the protocol defines the path for agents that do.

The pairing is deliberate. Sierra described the best case as an agent that says who it is, which the protocol is designed for, with Fleming-1 covering the cases where that does not happen. Companies rolling out their own service agents — like the CarMax deployment reported by PYMNTS — get a monitoring tool for inbound automation at the same moment consumer agents begin ringing their lines.

For readers following the agent infrastructure race, the broader context includes record funding rounds for personal agent companies and growing enterprise anxiety about governing agents that act on their own. Whether Fleming-1 becomes as ubiquitous as Caller ID will depend on how quickly businesses find the flag useful — and on whether personal agents start announcing themselves through the protocol first.