What an AI Agent Actually Is
Strip the marketing off and the definition is short. An AI agent is software that takes a goal, works out the steps, carries them out using tools it has been given, and reports what it did. On a phone call the goal arrives as a sentence from a customer, the tools are your calendar, your CRM, your job management system and your messaging, and the report is both a spoken confirmation to the caller and a record left behind for your team.
The word doing the work in that definition is tools. A system with no tools can only talk. It can talk extremely well, understand a broad Australian accent, handle an interruption gracefully, and give a genuinely correct answer about whether you open on the Saturday of a long weekend. That is useful. It is not an agent, and the difference shows up in your week rather than in the transcript.
The plain version
An assistant answers questions. An agent finishes jobs. If the caller still has to ring back, fill in a form, or wait for somebody to listen to a recording before anything happens, you bought an assistant. That may be exactly what you need and it is considerably cheaper, but it will not reduce anybody's workload, and you should not be paying agent prices for it.
Agentic is the adjective attached to the same idea. It has been stretched to cover almost anything with a language model behind it, which is why it has stopped meaning much in a sales conversation. Used properly it describes a system with three properties: it decides the sequence of steps itself rather than following a fixed script, it can use more than one tool in a single interaction, and it can recognise when it has reached the edge of what it should do and hand over. Take away the third property and you do not have an agent, you have a liability with a pleasant voice.
The Five Rungs, and Where the Line Sits
Everything currently sold as AI phone handling in Australia sits on one of five rungs. The rungs are cumulative and each is a legitimate product. The confusion is entirely about which one you are being quoted for.
| Rung | What it does | What the caller experiences | Work it removes |
|---|---|---|---|
| 1. Touch tone menu | Press 1 for sales. Fixed tree, no understanding. | Listening to options, guessing, pressing 0. | Routing only. Adds caller effort. |
| 2. Speech menu | Same tree, spoken. "Say sales or accounts." | Slightly faster. Still a tree. | Routing, marginally better. |
| 3. Scripted assistant | Natural voice, fixed conversation flows written in advance. | Sounds modern until the question is off script. | The most common two or three questions. |
| 4. Retrieval assistant | Answers from your real content: hours, services, pricing, policies. | Genuinely helpful for questions. Cannot do anything. | Answering repeat questions. Message taking. |
| 5. Task completing agent | All of the above, plus it acts: books, reschedules, cancels, raises, updates, sends. | The call ends and the thing is done. | The work itself. |
The line sits between four and five, and it is not a matter of degree. Rungs one to four all read from your business. Rung five writes to it. Reading is comparatively easy and carries little risk. Writing means the system can change a booking, create an obligation, and be wrong in a way that costs somebody a morning, which is why it demands integration, permissions, confirmation and audit that the other four do not need. When a vendor demonstration shows only questions being answered beautifully, you have watched a rung four product. Ask to see a write.
The One Question That Settles It
You do not need to understand model architectures to buy this well. You need one test call and one question.
Ask
Show me a call where the outcome appears in the calendar or the CRM, and nobody types it in afterwards.
Watch
The screen, not the transcript. The transcript always looks impressive. The record either exists or it does not.
Then ask
What happens when it gets that wrong, who finds out, and how fast can it be undone.
Three answers are common and only one is a rung five product. "It sends an email to your team who then enter it" is rung four with extra steps. "It creates a task for someone to action" is rung four with a queue attached. "It appears in the calendar, with the customer's details, and the customer has the confirmation" is an agent. The distinction is not pedantry: the first two leave the same amount of work in your business and simply move it to a quieter part of the day, which has some value, but it is not the value being priced.
A demonstration on the vendor's data proves very little
Every one of these systems performs beautifully on a fictional business with twelve services and no exceptions. Yours has a service that is only offered on Tuesdays, a technician who does not do the northern suburbs, a price that depends on whether the customer is on a maintenance agreement, and a rule about deposits that everybody knows and nobody has written down. Insist the trial runs on your real data, with your real exceptions, on your real calendar. The interesting failures only appear there, and they appear in the first afternoon.
What Happens on a Real Call
It helps to see the call broken into its phases, because each one is a place where a system either holds up or quietly falls apart, and because it tells you what to listen for when you test.
| Phase | What the agent does | Where it goes wrong |
|---|---|---|
| Greeting | Identifies the business, states plainly that it is an automated assistant, invites the caller to just say what they need. | Pretending to be a person. Never do this. It is the fastest way to lose the caller's trust for the rest of the call. |
| Intent | Works out what the caller actually wants from an ordinary sentence, including when they give three things at once. | Forcing the caller to rephrase into keywords. If it says "I did not understand that" twice, the design has failed. |
| Identity | Finds the existing customer from the calling number, or asks for the minimum needed to proceed. | Asking for details it could have looked up, or worse, accepting an identity claim before doing anything sensitive. |
| Retrieval | Pulls the facts it needs: the booking, the job status, the balance, the next available slot. | Answering from general knowledge instead of your records. This is the failure that produces confident nonsense. |
| Action | Does the thing. Books, moves, cancels, raises, updates, orders the callback. | Acting without reading back. Every write should be confirmed in the caller's own terms before it commits. |
| Confirmation | States what was done, and sends it in writing by SMS or email while the caller is still on the line. | Verbal only. If the caller has nothing in their hand, they will ring back to check, and you have gained nothing. |
| Escalation | Recognises the limit and moves the call to a person, carrying the context with it. | Escalating with nothing attached, so the customer starts again from the beginning. See the handover section. |
| Record | Writes the transcript, the summary, the outcome and the follow up into the CRM against the right contact. | Writing it somewhere nobody looks. A record in a separate portal is a record that does not exist. |
Notice how much of that list is not about the artificial intelligence at all. Identity, integration, confirmation and record keeping are ordinary systems work, and they are where deployments actually succeed or fail. The conversational part has been more or less solved for two years. The plumbing is what you are buying.
Which Calls Suit an Agent, and Which Do Not
The selection criteria are consistent across every business we have put one into. Good candidates are repetitive, structured, high in volume, and low in emotion. Bad candidates fail on the last one, and emotion is the criterion people underweight.
Automate first
Opening hours, address and parking. Booking, rescheduling and cancelling. Order, job or delivery status. Simple triage that sorts a caller to the right queue. After hours capture with a real outcome. Overflow when everyone is already on a call.
Automate carefully
Quoting anything variable. Taking payment. Account changes. Anything where being wrong creates an obligation. These work, and they need tighter confirmation, narrower permissions and a lower threshold for handing over.
Do not automate
Complaints. Distressed or vulnerable callers. Anything with a safety or medical dimension. Cancellations you would fight to keep. The first call from a large prospective customer. In each case the caller is judging whether you take them seriously.
The volume argument is the real one
Most Australian small businesses do not have a call quality problem. They have a call capacity problem: the phone rings while everybody is already on a job, and a share of those callers simply ring somebody else and are never counted. The value of an agent is rarely that it handles a call better than your best person. It is that it handles the fourteenth simultaneous call at 8:40am, which your best person cannot, because they are on the first one. That is also why the metric that matters is not how well it performs on the calls it takes, but how many enquiries stop disappearing.
The Handover Is the Product
Customers do not judge these systems on the calls that go perfectly. They judge them on the moment it becomes clear the machine cannot help, because that is the moment they find out what your business thinks of them. Get the handover right and a caller will happily use the agent again. Get it wrong once and they will start every future call by saying "operator" over the top of the greeting.
| Rule | Why |
|---|---|
| A person is always reachable, and saying so is not a failure | Every agent should treat "let me talk to someone" as a valid first sentence and act on it immediately, without a negotiation. Hiding the exit is the single most resented pattern in phone automation, and it long predates AI. |
| Context travels with the call | The person who picks up sees who is calling, what was asked, what the agent already did, and what it could not do. A handover that makes the customer repeat themselves is worse than no automation, because now they have explained it twice. |
| Escalate on frustration, not just on failure | Repetition, interruption, raised voice, a second attempt at the same request. These are signals to stop trying and pass it on, even when the agent believes it is capable. |
| Escalate on subject, always | Keep a list of subjects that never get handled automatically, regardless of confidence: complaints, legal, safety, anything involving a vulnerable person. This is a fixed rule, not a judgement call for the model. |
| Have an answer for nobody available | After hours, or when the queue is genuinely empty, escalation cannot mean an unanswered ring. It means a booked callback with a stated time, and it means keeping that time. |
Guardrails, and Saying "I Do Not Know"
The failure mode people fear is the system inventing something. It is a real risk and it is largely a design problem rather than a model problem. Three controls remove most of it.
Answer from your material, not from the world. The agent should be restricted to your published content and your records for anything factual about your business. If the answer is not in there, the correct behaviour is to say so and offer to have somebody call back, which every reasonable customer accepts. General knowledge has no place in an answer about your pricing.
Write with permission, and narrowly. Booking into a defined calendar, within defined hours, for defined service types is a safe write. Amending an invoice is not, at least not on day one. Give the agent the smallest set of actions that covers the calls you chose, and expand it after you have seen a month of real behaviour.
Confirm before committing. Read the action back in the caller's own words and take an explicit yes before it commits. This single step converts most misunderstandings into a correction on the call rather than a problem discovered on the day of the job.
Prompt injection is now a phone problem too
An agent that reads incoming messages, emails, forms or documents as part of its work can be given instructions by whoever wrote that content. It is the same class of problem as an email link, and the answer is the same: treat anything that arrives from outside as data, never as instructions, keep the actions available to the agent narrow, and require confirmation for anything that moves money or changes an account. Ask your provider directly how they separate the two. A vendor who has not thought about the question is telling you something useful.
What It Has to Know, and Where That Lives
An agent is only as good as what it can see. This is the part of the project that takes real time, and the part that gets underestimated in every quote, including ours if we are not careful.
| What it needs | Where it usually comes from | The work involved |
|---|---|---|
| Services, prices, inclusions, exclusions | Your website, plus the things everyone knows and nobody wrote down | Writing down the unwritten rules. This is the genuinely hard part and it is worth doing anyway. |
| Hours, holidays, locations, coverage area | Your phone system and your own calendar | An hour, and then a habit of keeping it current. |
| Availability and booking rules | Calendar or job management system | Connecting it, and deciding what the agent may and may not book. |
| Customer records and history | CRM | Matching on calling number, and deciding what may be read out to a caller who has not been verified. |
| Job or order status | Job management, ecommerce platform, or a spreadsheet | Usually an integration. Sometimes a decision to stop using the spreadsheet. |
| Escalation map | Your own head, at present | Writing down who handles what, and when. Useful even if the project stops here. |
Businesses that already have their systems connected get an agent working in days. Businesses with a CRM nobody updates, a calendar that lives in one person's phone and pricing that depends on who answers will spend most of the project fixing that, and will get most of the benefit from having fixed it. Our note on phone system integrations and open APIs covers the connection side, and the Australian platforms we see most often covers what typically already fits.
Measuring It Honestly
Containment rate, the share of calls that never reached a human, is the number every vendor reports and the number that most easily flatters a bad deployment. A caller who gave up is contained. A caller who was told to ring back tomorrow is contained. Measure it, and never measure it alone.
| Measure | What it tells you | Watch for |
|---|---|---|
| Resolution rate | Calls where the caller's need was actually met, verified against the record that was written. | This is the real number. If your provider cannot produce it, ask why. |
| Escalation quality | What share of handovers arrived with usable context, and how long the human then spent. | A handover that takes longer than the original call would have is a net loss. |
| Repeat contact within 48 hours | Whether the call actually finished, from the customer's point of view. | Rising repeats with rising containment is the classic false positive. |
| Abandonment inside the agent | People hanging up mid conversation. Almost always a design fault, not a model fault. | Cluster them by intent. The pattern is usually one flow. |
| Answered enquiries, total | The count that matters commercially: enquiries that reached your business at all. | Compare to the same month last year, not to last week. |
| Time to first human | For the calls that should reach a person, whether automation made that faster or slower. | If it went up, your triage is too eager. |
Read a sample of transcripts every week for the first two months. Twenty calls, chosen at random rather than by the system's own confidence score. It takes half an hour and it will teach you more about your customers than the dashboard does. Our guide to the contact centre metrics that actually matter sets out the wider measurement picture.
The Australian Rules That Apply
None of this is exotic, and all of it is easier to build in than to retrofit.
| Obligation | What it means in practice |
|---|---|
| Tell people it is automated | Not currently a specific telecommunications rule, and it is the right thing to do and increasingly expected. A short, plain statement in the greeting. Pretending to be human is a trust problem that outlives the call. |
| Recording and monitoring notification | Recording law in Australia is state based and inconsistent. One organisation wide standard of clear notification at the start of every call, including the automated path, is simpler and errs in the right direction. See our guide to call recording law and setup. |
| Privacy and disclosure | Reforms to the Privacy Act require organisations to disclose in their privacy policy where automated systems make or substantially influence decisions affecting individuals. If your agent decides priority, eligibility or access, that belongs in the policy. Our note on automated decisions and the Privacy Act covers the detail. |
| Where the data goes | Know which country the transcripts and recordings are stored in, and who else can see them. For health, legal, government and NDIS work this is usually a hard requirement rather than a preference. |
| Emergency calls | A call to 000 must never enter an automated flow, on any device, in any circumstance. Check this rather than assume it. Our note on Triple Zero and cloud phone systems explains the surrounding rules. |
| Outbound and the Do Not Call Register | An AI agent making outbound calls is subject to exactly the same rules as a person making them. Washing lists, consent, calling hours and identification all apply unchanged. See the outbound calling rules. |
| Voice cloning and impersonation | Synthetic voice is now also an attack tool. Staff should know that a familiar voice on the phone is not identification, and approvals should not depend on recognising one. Our note on voice cloning and vishing covers the defence. |
What It Costs, and What It Replaces
Pricing in this market is unsettled and comes in three shapes: per minute, per resolved interaction, or included in a platform subscription with fair use. Per minute is predictable and rewards brevity, which is not always what you want. Per resolution aligns the incentives well and requires you to agree what resolution means, in writing, before you sign. Included pricing is simplest and is worth checking against your real call volumes rather than your average ones.
Compare it to the right thing
The comparison people reach for is a receptionist's salary, and it is the wrong one, because most small businesses were never going to hire a receptionist. The honest comparison is with the calls you are currently losing. If you take forty enquiries a week and miss six of them, and one in three of those would have converted at an average job value you can name, the arithmetic takes about two minutes and it usually settles the question without any reference to headcount. Our AI voice agent cost and ROI guide works through it properly, and the cost calculator covers the surrounding system.
Two costs are routinely left out of quotes. The first is the setup work described in the data section, which is real and is usually measured in days rather than hours. The second is ongoing curation: somebody has to read transcripts, notice the three questions it keeps getting wrong, and fix them. Budget an hour a week for the first two months and an hour a month after that. Deployments that fail almost always failed here, quietly, about six weeks in.
A Six Week Rollout
The order matters more than the speed. Every step exists because skipping it produces a specific, predictable failure.
| Week | What happens | Why this order |
|---|---|---|
| 1 | Listen. Pull a month of call records, and sort the last two hundred calls into intents by hand. Count them. | Everybody thinks they know what customers ring about. Almost everybody is wrong about the proportions, and the proportions decide what you automate. |
| 2 | Choose two intents, no more. Write down the exceptions, including the ones that live in people's heads. | Two intents can be made genuinely good. Eight will all be mediocre, and mediocre is what customers remember. |
| 3 | Connect the systems and build the escalation path first, before the conversation. | If the handover works, a rough agent is still safe to put in front of customers. The reverse is not true. |
| 4 | Run it after hours only. Read every transcript. | After hours is the safest possible trial: the alternative was a voicemail nobody returns, so the floor is low and the learning is real. |
| 5 | Add overflow during business hours, when everybody is already on a call. | Second safest. Again the alternative is an unanswered ring, not a person. |
| 6 | Review the numbers from the measurement section. Then either widen to a third intent or fix what is not working. Not both. | The habit of reviewing before widening is the difference between a system that improves and one that quietly decays. |
Tell your team what is happening before week four, not after. Phone automation lands badly when it arrives unannounced, and staff who understand that it is taking the fourteenth simultaneous call rather than their job will help you fix it. They are also the people who know the unwritten rules from week two.
How We Build It
Uniden Voice runs the AI on the same Australian platform that carries the calls, which matters for three practical reasons. Latency is short because the audio is not making a round trip offshore, and on a voice call a delay of half a second is the difference between a conversation and an interrogation. The transcripts, recordings and customer records stay on Australian infrastructure we operate. And when something needs fixing, the phone system, the AI and the integration are one product with one support number rather than three vendors pointing at each other.
We build to the rungs described above and we will tell you plainly which one you need. Plenty of businesses are best served at rung four, and we would rather sell that than have you pay for actions you never turn on. When you do want rung five, the setup work is done with you rather than to you, because the unwritten rules only exist in your head and getting them out is most of the job.