
AI agents in the company with open source: What is already possible today
AI agents complete tasks independently across multiple steps: They read a request, use tools such as calendars, CRM or document search, and store the result. With open-source building blocks – open models, n8n, Nextcloud Assistant and the open standard MCP – this is already possible today on your own servers in Germany, ideally with clear boundaries and human approval.
The most important points at a glance
- AI agents act across multiple steps with tools.
- Building blocks: open model, n8n, RAG, MCP, Nextcloud Assistant.
- Realistic today: Requests, appointments, research, documents.
- Required: minimum permissions, approval, logs, protection against tampering.
AI agents carry out tasks independently across multiple steps: they understand a request, use tools like calendars, CRM, or document search and store the result. With open-source components – open language models, n8n, the Nextcloud Assistant and the open standard MCP – can this be implemented today on your own servers in Germany? Ideally with clear boundaries and human approval at important steps.
What defines an AI agent
A chatbot responds. An agent acts: It decides which step makes sense next, calls a tool for it, checks the result, and continues until the task is completed. The basics are explained by What is an AI agent?, the difference from classic automation AI agents vs. RPA.

The open-source building blocks
- Language model: an open model with good tool use, operated locally or by a German provider – see Open-source AI models.
- Orchestration: n8n provides its own agent building blocks, allowing a model to use defined tools.
- Tools: Interfaces to calendar, CRM, ticketing system, document search, email.
- Knowledge: a knowledge base via RAG, so the agent can access company information.
- MCP (Model Context Protocol): an open standard through which tools and data sources are provided uniformly for AI models.
- Work environment: The Nextcloud Assistant can already perform actions, such as creating appointments or sending messages.
What is realistically possible today
- Process requests: Read emails, identify the issue, look up customer data, draft a reply, create a case.
- Coordinate appointments:Match requests from email or phone with available times and suggest options.
- Research in company knowledge:Answer and summarize questions across multiple documents.
- Process documents:Classify incoming mail, extract data, file it, and inform the responsible people.
- Prepare reports:Compile data from multiple systems and draft a proposal.
Describes examples from customer service AI agents in customer service.
What does not (yet) work well
- Long, open taskswithout a clear structure – agents get bogged down.
- Decisions with major consequenceswithout human review.
- Unclear tools:If interfaces are poorly documented, the agent uses them incorrectly.
- Small models in complex processes:Tool use requires powerful models.
Safety rules for agents
- Minimum privileges: Each agent receives only the tools and data it needs.
- Read before write: first agents that only read and create drafts; write actions later.
- Human approval: Sending to customers, payments, or changes to master data only after confirmation.
- Logs: Every step is recorded in a traceable way.
- Protection against manipulation: Incoming texts (emails, documents) may contain hidden instructions – agents must not follow them blindly.
- Operated in Germany: Models and tools on servers under your control.
How to get started
- Choose a clearly defined, common process.
- Define the tools and data the agent is allowed to use.
- Start with a read-only agent and drafts, then review the results.
- Gradually give more autonomy – with measurement and logs.
Our AI agents run on the same infrastructure as the automaisa Hub – with language model, automation, and connected systems on servers in Germany.
For technology enthusiasts
- Agents use “Function Calling” or “Tool Use”: the model outputs in a structured way which tool should be called with which parameters.
- MCP servers provide tools in a standardized way; many open-source tools now offer MCP integrations.
- Prompt Injection is the biggest security risk – always treat inputs from external sources as data, never as instructions.
bettersorted relies on open, transparent building blocks – operated on servers in Germany and bundled in the automaisa Hub. We provide vendor-neutral advice, are a BAFA-registered consultant and authorized INQA coach. The consulting and guided implementation can be covered through the INQA-Coaching with 80% funding; the right path is shown by the Funding Check. For a non-binding initial consultation: Contact.
Example: Agent in the citizen services office
An illustrative scenario: A municipality uses an agent that reads emails to the citizen services office, identifies the request, looks up the relevant information in the bylaws, drafts a reply, and creates a case in the ticketing system. It is only sent after approval by a caseworker. The agent runs on a server in Germany with an open model and is only allowed to read and create drafts.
Maturity levels for getting started
- Level 1 – Assistant: suggests, human decides and acts.
- Level 2 – Partially automated: Agent handles standard cases, human approves.
- Level 3 – Autonomous within limits: Agent completes clearly defined tasks independently, with logging and spot checks.
Most companies should start with Level 1 and only move on after measurable success.
Costs and funding
For AI agents, there are no license costs for open-source tools. Costs arise for Setup (planning, installation, integration, testing), Operation (server or hosting in Germany, updates, monitoring, data backup) and Support (training, rules, contact person). We do not quote fixed prices because scope and starting conditions vary greatly.
Eligible for funding is the consulting and guided implementation: The INQA-Coaching covers 80% of coaching costs nationwide (up to €11,520, vouchers until 30.06.2028); a preliminary analysis is subsidized by the BAFA consulting grant at 80% in the new federal states, Lüneburg and Trier, otherwise 50% – for applications submitted by 31/12/2026.
Frequently asked questions
What are AI agents?
AI systems that complete a task independently over multiple steps by using tools such as calendars, CRM or document search and checking intermediate results.
Can AI agents be operated with open source?
Yes. Open language models, automation tools such as n8n and open standards such as MCP make it possible to run agents on your own servers in Germany.
Are AI agents safe?
With clear boundaries, yes: minimal permissions, human approval for important steps, logs, and protection against manipulated inputs. Without these rules, they are risky.
What is MCP?
The Model Context Protocol is an open standard through which tools and data sources are provided uniformly for AI models. It makes it easier to build agents with different models and tools.
As of October 2026. Models, versions, and licenses change quickly — before making a decision, check the current license with the provider.

Muhamed Alahmed
With over 10 years’ experience in IT, I develop solutions that not only work from a technical perspective, but also create real added value and open up new possibilities.
More about bettersorted →More articles

What is an AI agent? The difference from chatbots and classic automation
AI agent, chatbot, or classic automation: what distinguishes the terms and when an agent is actually the right approach.

Self-host n8n: automation without cloud dependency
Self-host n8n: benefits for data protection and costs, what the license allows, what operation requires, and what SMEs use n8n for. Find out more now.

AI agents in customer service: let inquiries be handled autonomously
How AI agents in customer service handle simple inquiries independently and pass complex cases to people with full context.
Stay up to date on AI topics
Short updates on AI automation, funding programs and new posts — no spam, unsubscribe anytime.