When Your Next Caller Is a Bot
Your next customer might not call you directly. Instead, their AI agent could make the call.
A call arrives in the contact centre. The caller says:
“I’m an AI assistant acting for Martin. His mobile bill is going up to $125 a month. I’m looking for the same plan at $100 or less, and I can’t extend his contract without asking him.”
The company’s voice bot checks the account and comes back with an offer: $105 a month, but only if Martin signs for another two years.
So, what happens next?
Not long ago, this was just a topic for conference discussions. Now, it is becoming a real customer service issue. The challenge is no longer about whether an AI can make a call or if your bot can hold a conversation. The tougher questions are about identity, authority, policy, and accountability. Who authorized the caller? What can it agree to? What happens if it asks for a person? And how do you prove the promised change happened?
This is already happening.
Meta’s Muse is one of the clearest signals. Meta launched the personal AI agent in the United States on September 8. It can work across apps, fill out forms and negotiate on a user’s behalf. Meta has specifically highlighted examples such as lowering a bill. Within roughly two weeks of launch, Muse had accumulated more than 2.5 million downloads and reached the top of the U.S. app charts.
Google is moving in the same direction with Gemini. Its new “Call for Me” capability is being tested in the U.S. and lets Gemini place calls to businesses for tasks such as making a reservation or asking for a service quote. The user can review what information Gemini will share, follow a live transcript, listen to the call and take over when needed. That last point matters. Google is already designing around the idea that the AI can act for you, but that you may still need to step in.
This is where it matters for contact centres. During Meta’s testing of Muse, Reuters reported that an employee trying to reach an insurer had the call repeatedly disconnected after revealing it was an AI. Meta also tried using human contractors to handle some calls made through Muse, raising new privacy and disclosure questions.
This shows us something uncomfortable: some contact centres already have an AI-caller policy, even if it is not written down. Each hang-up, transfer, and agent decision shapes these policies.
It also shows how quickly the line between human and machine can blur. A call made through an AI service might involve a human, while a caller who sounds completely natural could be automated. Listening to the voice alone won’t be enough.
Muse and Gemini are not the only examples. Kudos offers an AI service that can call providers and negotiate bills, and Google has already used automated calls for local pricing and availability. We are still in the early stages, and downloads or demos do not mean AI callers will soon take over contact centre traffic. Still, it is getting harder to ignore this trend.
Are the CCaaS platforms ready?
To some extent. The industry already has many of the necessary building blocks. However, a key difference remains between enterprise AI agents working together behind the scenes and a customer-controlled AI agent calling in directly.
Genesys Cloud is expanding Agentic Virtual Agent and A2A interoperability so enterprise agents can collaborate with external agents on platforms such as Salesforce and ServiceNow. In that model, Genesys keeps control of the customer-facing conversation. The bigger question for this article is different: how does an independently operated personal assistant prove that it is authorized to act for the customer?
NiCE is addressing the issue more explicitly. Its Agentic Engagement Plane is designed to authenticate, mediate, route and govern interactions involving customers, employees, AI agents and systems. NiCE has also publicly discussed personal AI agents entering customer service through existing voice and digital channels.
Five9’s Voice AI Agents can authenticate customers, use tools, complete service tasks and transfer to a human with context. The unresolved issue is what changes when the caller itself is an external AI acting for the customer.
Talkdesk supports AI handling through voice channels and escalation into the human contact centre. Again, the key question is not whether the call can be answered. It is how the business verifies what the external agent is authorized to do. That is why I think this is more than just a CCaaS feature discussion. Platforms can already receive AI-generated phone calls. The bigger challenge is building a trusted system for identity, delegated authority, negotiation, escalation, and proof of outcome. outcome.
Identity may become the real front door
One clue to how this could develop is already appearing outside the contact centre. Microsoft Entra Agent ID, for example, treats an AI agent as its own digital identity. An agent can be authenticated, assigned specific permissions, restricted by policy and have its actions recorded for audit purposes.
That model could become important for customer service. Instead of a personal assistant simply saying, “I’m acting for Martin,” the interaction could eventually carry verifiable information showing who the agent is, who authorized it, and what it is allowed to do.
Think of it as a chain of authority: Customer → AI identity → delegated permissions → permitted actions → audit trail.
That could allow a contact centre to distinguish between an agent permitted to check an account balance, one that can negotiate a bill, and one authorized to accept a new contract. High-risk actions could still require direct customer approval.
This may ultimately be more important than whether the conversation arrives by voice, chat or an A2A connection. The real challenge is creating a trusted way for one organization’s AI to recognize the identity and authority of an AI controlled by somebody outside that organization.
What changes inside the contact centre?
The first changes are not particularly futuristic. They are basic service design questions that need to be reconsidered for calls from machines.
Front door: Recognize a disclosed AI caller, but do not treat its voice, phone number or confidence as proof that it can act for the customer. Decide what can safely be disclosed before identity and authority are verified.
Routing: Let automation handle low-risk requests, but recognize when the customer’s AI asks for a human. Pass the conversation, verification status and offer history with it so the customer does not end up in another bot loop.
Policy: Define what your own AI can approve for credits, refunds, cancellations, pricing and contract changes. A customer’s AI can state its mandate, but the business still needs a reliable way to verify it before making a binding change.
Operations: Be ready for persistence. A personal agent will not get tired of calling back, waiting on hold, or disputing a small charge. This could change demand patterns and make traditional measures like containment and calls handled less useful.
Channels: Voice might be the first way personal agents contact many businesses, but authenticated digital and A2A connections could eventually offer a better way to exchange identity, permissions, and transaction records.
Back to Martin’s bill
Imagine the process working as it should. Martin’s assistant shows it is authorized to act on his account and explains the goal: keep the same plan at $100 or less, with no new contract term. The company’s agent checks that authority, finds the approved offers, and replies with $105 on a 24-month term.
At this point, both agents reach their limits. Martin’s assistant cannot accept a new contract, so it can either make a counteroffer within its authority or bring the offer back to Martin. The company’s agent cannot offer a lower price or waive the term if policy does not allow it, so any exception must go to someone with the right authority.
That gives us a simple answer to the question of who has the last word:
The customer decides whether to accept a new commitment made in their name.
The business decides what it is prepared, or required, to offer within its policies, contracts and applicable customer rights.
Each AI agent operates only within the authority its side has given it.
A bot saying “agreed” does not mean the transaction is complete. The real proof is an update in the system of record, along with a clear confirmation of what changed.
What if one bot asks for a human?
This could be the first big challenge for contact centres. If the customer’s assistant asks for a person, the response should not be another automated loop. The call needs to reach a representative who gets the conversation, the verification details, and the offers already discussed.
The same idea applies for the company. If its AI reaches a policy limit, it should be able to pause and bring in someone with the authority to make the needed decision. If a human needs to speak directly with the customer, the process should allow for a warm transfer or callback, not force everyone to start over.
Escalation only works if it reaches someone who can solve the problem. Otherwise, two capable bots might create a perfect transcript but still leave the customer with the same issue.
Four things I would do now
1. Create an AI-caller policy. Decide if you will serve disclosed AI callers, what requests they can handle, and what employees should do instead of just hanging up.
2. Check what is disclosed before verification. Review what your IVR, bots, and agents reveal before you confirm identity and authority, keeping in mind that a machine could be listening and recording.
3. Set up a real escalation path. Make sure a bot-to-human request reaches someone who can make decisions, with all the context passed along.
4. Begin tracking. Tag disclosed or suspected AI callers so you can understand the volume, reasons for calling, repeat attempts, and outcomes before this becomes a major part of your demand.
The harder test
Soon, we might see two advanced AI agents discussing a customer’s problem. Their ability to have a natural conversation will likely be the least interesting part.
The real test is whether both sides can confirm who is represented, what authority has been given, what was agreed, who is responsible, and whether the promised action took place. And when either AI reaches its limit, there must still be a clear way to reach a person.
Is your contact centre ready to help a customer whose first contact is an AI agent, or do your policies still assume every caller is human?
Sources and further reading
Meta, “Introducing Muse: The World’s First Personal AI Agent Built for Everyone,” September 8, 2026.
Reuters, “Meta testing a ‘human concierge’ for its new personal AI agent Muse,” September 22, 2026.
Google Gemini Apps Help, “Ask Gemini to handle your everyday phone calls,” accessed September 2026.
TechCrunch, “Google tests letting Gemini call businesses for you,” September 24, 2026.
Genesys, “About external agentic integrations” and Agentic Virtual Agent A2A documentation, September 2026.
NiCE, “Personal AI agents just went mainstream. Is your CX ready?”, September 23, 2026.
NiCE, “Agentic Engagement Plane,” 2026.
Five9, Voice AI Agents announcement, June 23, 2026.
Talkdesk, CXA Autopilot and Navigator PSTN documentation.
Kudos Help, AI bill negotiation documentation.