
What is Sierra fleming-1?
fleming-1 is the newest model in what Sierra calls its "constellation of models", the set of fine-tuned models behind its Agent OS. Sierra, one of the bigger agentic customer service platforms, named it on stage at Sierra Summit 2026 alongside Curie, a model that runs the core loop of a conversation. The summit recap describes Fleming as the model that "detects when the caller on the phone is another agent, enabling businesses to handle bots and fraud as well as personal agents."
A dedicated post titled "Caller ID in the age of agents" followed, written by Ajeet Grewal and Venu Satuluri and dated October 8, 2026. Bret Taylor, Sierra's co-founder, shared it the evening before.

I've spent my time at eesel building the AI agents that sit in support queues, and the most useful thing about this launch is how narrow it is. fleming-1 does one job: it answers "is this voice synthetic?" while the call is still happening. It does not authenticate anyone, it does not judge intent, and it does not touch chat or email. Keep that scope in your head and the rest of the launch makes sense.
Here is everything Sierra has confirmed, in one place:
| Detail | What Sierra says |
|---|---|
| What it detects | Callers whose speech is likely AI-generated |
| Channel | Phone calls only |
| When | In real time, during the call |
| Default tuning | Conservative, so real people are not flagged by mistake |
| Output | A flag on calls it identifies as likely AI |
| What happens next | Your business decides |
| Who can use it | Any voice agent built on Sierra |
| How to enable | "You just need to turn it on" |
| Price | Not published |
| Accuracy, false positives, latency, languages | Not published |
Why Sierra built a detector for AI callers
Sierra says it first hit the problem in 2025, "when agents built on Sierra started calling agents built on Sierra in healthcare." Then the consumer side took off. Personal agents such as Meta Muse and Instinct now wait on hold, work phone trees and talk to reps on their owners' behalf. Sierra's post warns that "a large share of the calls companies receive could come from AI acting on behalf of consumers."
The people on the other end of those calls often cannot tell. One researcher described what happened when Muse called a company for him:
"This week, Muse called customer service on my behalf. It navigated the phone tree, waited on hold, spoke with a human rep, and resolved the issue (worked great!). The crazy thing for me (besides that it works) is that the rep didn't blink. Talking to a bot was completely natural to them."
Some agents do say what they are. A Muse user on Reddit noticed their agent opening calls by naming who it worked for:
"It says Hi I am Brett calling on behalf of gadgetneil and im taking notes etc."
That is the polite case. The worry is the agent that does not introduce itself, at scale. How big is the volume already? The closest public number comes from a fraud vendor, not Sierra: Pindrop says that in two months it identified 727,000 AI agents or bots on the calls it screens, roughly 1 in 80 calls, according to its BotStopper page. That is Pindrop's own customer base, not the whole market, but it is a useful order of magnitude.
The most-shared take on where this goes was blunt about the incentive problem:
"AI agents reduce the cost of complaints/requests to ~ zero. Anything free is consumed at much higher rates, so we should expect the total volume of this category to explode."
Sierra's answer is not to shut that traffic out, which fits how it pitches AI call center agents generally. Its post is careful to say some automated callers are fraudsters testing account security, while "others will be customers who handed off a chore to an agent, or people who rely on text-to-speech." That last group is the reason a blunt "block all AI voices" rule would be a mistake. Text-to-speech users are real customers.
How fleming-1 works
Sierra has shared the shape of the system, not the internals. fleming-1 "analyzes callers' speech in real time, scoring the audio for signs that it was generated by AI." Sierra says it looks "beyond how a voice sounds to a human listener", which matters because synthetic voices now fool people easily, and background noise or a bad line hides the clues a person might catch.
When the score crosses the threshold, Sierra flags the call as likely AI. From there, it is your call.

Two design choices stand out.
It is tuned conservative. Sierra says the model is set so "real people don't inadvertently get flagged." That is the right default for a support line, because flagging a real customer as a bot is a much worse experience than missing a bot. The trade-off is that some AI callers will pass unflagged. So treat a missing flag as "unknown", not "human".
It reports, it does not act. Sierra leans on the caller ID comparison: "Caller ID never told you whether to pick up." The model gives your Sierra agent a signal, and the agent's own logic, which you write, decides what to do with it.
What Sierra has not said is just as important for anyone planning around it. There are no published figures for accuracy, false positive rate, how many seconds of audio the model needs before it scores, which languages it covers, or which voice generators it was tested against. Compare that with Pindrop, which publishes a 5,000+ AI voice registry and makes accuracy claims on its page. If you are a Sierra customer, ask your account team for numbers on your own recordings before you write policy that depends on the flag.
How fleming-1 fits with the Personal Agent Protocol
fleming-1 shipped the day after Sierra and Meta announced the Personal Agent Protocol, and the two are meant to be read together. Sierra's post puts it plainly: "The best case is an agent that says who it is, and that's what Personal Agent Protocol is for. For the calls where it doesn't, there's fleming-1."
The difference is in what you learn about the caller.

The protocol, which I covered in the PAP breakdown, runs on OAuth. A personal agent starts a session, the customer decides whether it gets read or write access, and the business decides what agents may do through its website, its APIs (MCP or OpenAPI) or its own agent (see MCP for customer support). When an agent uses it, "the company knows it's an agent and who it's acting for."
fleming-1 knows much less. It can tell you a voice is probably synthetic. It cannot tell you whose agent it is, whether the customer approved the call, or whether the caller is a person using text-to-speech. That is why Sierra frames it as information. A "likely AI" flag is a reason to slow down on sensitive actions, not proof of fraud.
Sierra is not the only vendor building both halves, and it competes with Parloa and Cresta on voice too. Decagon announced its own Personal Agent Gateway on October 1, which detects personal agents in chat and voice and routes them to a separate channel, plus the PACT protocol for agents to prove who they represent. Decagon has since said it is joining the PAP working group.
Who can use fleming-1, and what it costs
Short version: Sierra customers running voice agents. Sierra's post says "fleming-1 works with any voice agent built on Sierra. You just need to turn it on." There is no standalone fleming-1 API, no listing for other contact center platforms, and no self-serve signup.

On price, Sierra has said nothing specific to fleming-1. That fits how Sierra sells in general: it publishes no price list, and its contracts are built around outcomes, with consumption-style pricing where outcomes do not fit. I would expect fleming-1 to sit inside your existing Sierra agreement rather than show up as its own line item, but that is an expectation, not something Sierra has confirmed. The Sierra AI pricing guide has what is publicly known about the contracts.
Sierra's reach makes the feature matter even with that limit. The summit recap says Sierra works with almost 50% of the Fortune 50, one in three of the leading banks and 80% of the Fortune 50 healthcare companies. Banks and healthcare are exactly the two places Sierra's post uses as examples, and they are the industries where a synthetic caller asking for an account change is a real risk. If that is your world (or you are weighing Sierra vs Zendesk), the AI customer service for fintech and healthcare guides cover the wider rollout questions.
What to do with a flagged call
The model is the easy part. The hard part is deciding what a flag should change, and Sierra leaves that to you on purpose. Its two examples are a good starting frame: "A bank might want to add a verification step when the caller is an agent. A company with high call volume might start by measuring how often it happens."
I'd treat the options as a ladder and climb it only as far as your data justifies.

- Measure it. Turn the flag on and change nothing for a few weeks, the same way you would baseline any call center automation. Count how many calls are flagged, which intents they carry (balance check, cancellation, refund), and how they end. Most teams have no idea what share of their calls are agents today.
- Verify it. Add a step only where the action is sensitive: changing an address, moving money, cancelling a plan. A balance lookup by a flagged caller is low risk; a payout is not.
- Route it. If agent calls turn out to be a big, legitimate share, give them their own path. A shorter flow with fewer pleasantries and clearer confirmations suits an AI caller better than a script written for people.
- Block it. Keep this for clear abuse, like a burst of flagged calls testing account security. Blocking a whole class of callers will also block customers who use text-to-speech, and customers who sent an agent on their behalf.
The step that does the most work is not about detection at all. It is having your money-moving rules written down in the first place, so a flag tightens an existing policy instead of inventing one under pressure. Clear escalation rules do most of the work. I see this every week in eesel's own rollouts. One digital-media support admin taught their Zendesk agent a rule that applies whether the requester is a person or a bot:
"I have a rule in CS where we do not address a cancel or refund request when there is an issue attached to it." / "This is incorrect. You have not provided troubleshooting steps yet."
A digital-media support admin encoding a "troubleshoot before you cancel" policy into the Zendesk agent
A personal agent asking for a refund should hit that same rule. If your AI agent handoff and refund request policies are clear, a "likely AI" flag becomes one more input, not an emergency.
How fleming-1 compares to other ways to detect AI callers
fleming-1 is one of three main approaches on the market right now. They differ most in who can buy them.
| Sierra fleming-1 | Decagon Personal Agent Gateway | Pindrop BotStopper | |
|---|---|---|---|
| What it is | A model inside Sierra's voice agents | A detection layer plus separate channel for personal agents | Standalone AI and bot caller detection |
| Channels | Phone | Chat and voice | Phone |
| Who can use it | Sierra customers | Decagon customers | Enterprises on supported contact center platforms, no other Pindrop product needed |
| Signals | Live audio scoring | Device fingerprints, account history, conversation patterns, request cadence | Live audio plus a registry of 5,000+ known AI voices |
| Tells you who the agent acts for? | No | Through the PACT protocol, when agents use it | Can match a known registered AI voice |
| Published accuracy | None | None | Accuracy and false positive claims on its page |
| Public price | No | No | No |
| Announced | October 2026 | October 1, 2026 | 2026 |

If you already run Sierra, fleming-1 is the obvious first step. It is built into the agent answering your calls, so there is nothing to integrate, and the flag lands where your call logic already lives.
If you run Decagon, the gateway does a similar job with a broader signal set and covers chat as well. The Decagon vs Sierra comparison covers the platforms more broadly.
If you build on developer platforms like Retell AI or Vapi, none of these three plug in directly, so caller detection is something you add yourself.
If you run neither, Pindrop is the option you can actually buy on its own, and it is built for supported contact center platforms. It is also the most fraud-oriented of the three, with a $1M deepfake warranty available on eligible full-suite contracts.
For the wider set of phone tools, including whether AI can answer support calls at all, the best AI voice agents roundup and the guide to AI phone support go deeper.
The part fleming-1 does not cover: agents in your ticket queue
Phone is only one door. Personal agents use chat and email too, often when the phone line fails. That is why the Instinct and Muse support guides spend as much time on tickets as on calls. One Muse user on Reddit described exactly that: the agent "discovered the humans weren't home, went to chat, and successfully made the correct request" to replace a toll transponder, per u/intenost on Reddit. fleming-1 never sees that conversation, because it only listens to calls.
No helpdesk I know of reliably detects an AI-written email today, and I would be wary of anyone who claims to. The practical defence in text channels is the same as step 2 of the ladder above: decide which actions need a person, and make that rule hold no matter who sent the message.
That is the part eesel is built for. eesel does not do voice, and it does not detect personal agents. Its AI helpdesk teammate joins your existing Zendesk, Freshdesk or Gorgias queue and works tickets like a new hire, tagging and routing with ticket classification the same way your team does.
Every action it can take is set to Auto, Needs approval or Disabled, per the actions and approvals docs. So lookups run on their own, while refunds and cancellations wait for a person to approve, whether the request came from a customer or from their agent.
Try eesel
If Sierra's launch has you thinking about what customers' AI agents will ask your support team to do, start with the queue you already have. eesel's helpdesk teammate plugs into Zendesk, Freshdesk or Gorgias in minutes, learns from your past tickets and help center, and lets you put any money-moving action behind an approval before it goes live. You can test it against your own past tickets first, and the free plan includes 100 credits with no card. Try eesel.

Frequently Asked Questions
What is Sierra fleming-1?
Does fleming-1 block AI callers?
How much does Sierra fleming-1 cost?
Can I use fleming-1 without Sierra?
How is fleming-1 different from the Personal Agent Protocol?
How accurate is Sierra fleming-1?
What should a support team do about AI agents contacting them?

Article by
Kira
Kira is a writer at eesel AI with a Computer Science background and over a year of hands-on experience evaluating AI-powered customer service tools. She focuses on breaking down how helpdesk platforms and AI agents actually work so that support teams can make better buying decisions.








