AI agents can now make phone calls for you
· Fox News

There are certain phone calls I would happily hand off to almost anyone. Calling my wireless carrier to fix a billing problem comes to mind. So does chasing a restaurant reservation that I cannot book online. Now, AI wants the job. A new generation of personal artificial intelligence agents can handle tasks across apps, websites and connected accounts. Instinct and Meta's newly launched Muse are pushing that idea further. Instinct can now place phone calls to businesses for some early-access users, while Meta is testing a similar capability with Muse. Instead of asking AI what number to call, the idea is that I can tell the agent what I need and let it handle the conversation. I know that sounds incredibly convenient, but it also raises a bigger question. How comfortable are you letting software speak and make decisions in your name?
Missed CyberGuy LIVE? Watch the replay and discover 5 ways AI can help you get better healthcare.
Visit michezonews.co.za for more information.
Our free CyberGuy LIVE class Get Better Healthcare with AI has ended, but you can still watch the full replay. Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you prepare for appointments, remember important details, understand complicated medical information, research prescription questions and organize your next steps. No technical experience is needed.
Plus, recordings of all our past classes are available, including How to Stop Spam, Phone Security and Financial Protection, each with a free downloadable checklist.
Watch the free replays and get your checklists at CyberGuyLive.com
AI AGENT HACKS GYM SYSTEM TO MOVE UP WAITLIST
Instinct founder Noah Shinn announced Instinct Concierge on Sept. 16. The feature lets the company's AI personal assistant handle phone calls and other service tasks for users. Shinn gave examples that will sound familiar to anyone who has wasted part of an afternoon on hold. Instinct could call a restaurant that does not take online reservations. It might get you onto your dentist's cancellation list. The AI could also try to sort out a problem with your cable bill. The company is rolling Concierge out in early access to some users, with plans to expand availability over time.
Calling fits with what Instinct has already been building. Its AI assistant can work across connected services and take actions on a user's behalf. Instinct has also given its assistants dedicated email addresses. Those addresses can help with account sign-ups and management. Users can also add other people to a trusted network. That allows their assistants to communicate with one another for certain tasks.
All of this has drawn serious investor interest. Instinct raised $250 million in an August Series B round that valued the company at $2.5 billion. Then, on Sept. 28, Instinct announced a $1 billion Series C round from investors including Sequoia Capital, Benchmark and Coatue, valuing the company at $10 billion.
Meta launched Muse on Sept. 8 as a personal AI agent that can work across connected services. Muse can browse the web, fill out forms and complete tasks on a user's behalf. Meta has reportedly been testing an outbound-calling capability that lets some Muse users ask the agent to call U.S. businesses. The feature remains in limited testing rather than being broadly available to Muse users. Muse is now available in the U.S. and Canada.
Muse can also keep working after you close the app. Meta says users choose which services Muse can access and how much permission it receives. Interest has moved quickly. Muse climbed to the top of Apple's U.S. App Store after its Sept. 8 launch, and subsequent reports put its downloads above 3 million by late September. That puts Meta and Instinct in a fast-moving race to turn AI assistants into something closer to digital stand-ins.
Instinct is still available through private access, and the company does not currently publish a monthly subscription price. It also has not announced a separate price for Instinct Concierge or its phone-calling feature. Meta's Muse has a free tier with a usage limit. If you reach that limit, you can upgrade to a paid plan or wait for the free allowance to refresh. Meta says most people should be able to use Muse within the free tier. Paid plans have also been reported at $20 a month and $100 a month, depending on how much additional usage you need. Meta has not announced separate pricing for the phone-calling capability it is testing. I'd also be careful when searching the App Store for "Muse" because there are unrelated apps using that name.
The appeal grows once the AI can handle the back-and-forth for you. Give it a goal, and the agent can carry the conversation without pulling you away from whatever else you are doing. That could be especially useful for tasks that take several steps or require waiting on someone else. The AI can stay on the job, gather the answer and bring the result back to you.
But the more useful these agents become, the more control you are handing over. If the AI can confirm details, make changes or agree to something in your name, you want to know exactly where its authority begins and ends.
The convenience is easy to see. The privacy tradeoff takes a little more digging. Instinct's privacy policy says its assistant can access information from connected apps and services when you grant permission. That can include messages, emails and other private communications. Depending on how you use the assistant, it may also handle voice data, account credentials and payment information. Instinct says health-related information could also enter the system. One example would be asking the agent to book a medical appointment.
That kind of access can make an AI assistant much more useful. It also gives the service a deeper window into your digital life. We have already looked at this broader issue in our article on AI chatbot privacy. Phone calls add another layer because the assistant can now use what it knows while interacting with someone outside the app.
Instinct says users can opt out of having certain information used to train its AI models. However, that choice applies going forward. The company says models previously trained or improved using your information may still retain those improvements. There is also an exception for material flagged for a safety review. Instinct says that information can still be used for AI training related to harmful content detection or safety research.
Google Workspace information gets separate treatment. Instinct says data received directly through Google Workspace APIs does not go toward training or improving its AI models. There is another setting worth knowing about. Disconnecting a third-party integration does not automatically delete information previously collected from it. Instinct says users can separately delete data indexed from outside sources. That is the sort of privacy setting I would check before connecting a large inbox or another account packed with personal information.
Meta says Muse runs inside its own dedicated secure virtual machine in the cloud. Connected credentials go into secure storage. According to Meta, Muse cannot see passwords or payment methods stored there. Muse also asks for approval before certain sensitive actions. Meta gives sending an email or making a purchase as examples. Users can view an audit trail showing what Muse has done and what it plans to do. For purchases, Meta says Link can generate a one-time card number at checkout. That keeps the user's actual card number away from the merchant and the AI agent.
Meta also says Muse conversations and data inside its virtual machine do not get shared with Meta's advertising systems. Users can opt out of having their interactions used for AI model training. Users can change Muse's access or disconnect a connected service whenever they want. Those controls give users ways to limit what services Muse can reach and what actions it can take. Even so, every connected service adds another place where an AI assistant may interact with your personal information.
MALICIOUS BROWSER EXTENSIONS CAN HIJACK AI ASSISTANTS
We are already used to chatbots getting things wrong. Usually, you read the answer first and decide what to do next. AI agents change that equation because they can take action. Instinct spells this out in its own terms. The company says its services can produce incorrect or incomplete information. It also warns that actions may contain errors and may not always be reversible. The terms go further. When you authorize Instinct to act for you, the service can enter certain agreements, commitments or transactions on your behalf. Instinct says those agreements can be binding as though you entered them yourself. That is a pretty good reason to start small.
We covered this concern when autonomous AI agents first began gaining attention in our article on the first autonomous AI agent. Giving software permission to act creates a different kind of risk than asking a chatbot a question. A bot misunderstanding a restaurant reservation may mean an awkward dinner. A mistake involving a purchase or account change could be harder to unwind.
There is also another person in the conversation. Whoever answers the phone may hear your AI assistant share information about you. For a restaurant reservation, that might include your name and the time you want a table. A medical office could require more personal details. An account problem might involve information used to verify your identity. Think about what the AI will need to disclose before assigning the call.
AI voices can create another complication. We already warn readers about criminals using synthetic audio to impersonate real people. Our report on AI voice scams shows how convincing AI-generated calls can become. As legitimate AI agents begin calling businesses, hearing a computer-generated voice may become more common. That makes independent verification even more useful when a caller wants money or sensitive information.
You do not have to write off AI calling features. I would simply begin with low-risk tasks and expand from there if the service earns your trust.
Try asking the AI to check restaurant availability or confirm a store's hours. Those tasks give you a chance to see how well the agent performs without putting much at risk. Pay attention to the result. If the agent misunderstands a simple request, you may want more supervision before trusting it with something complicated.
Review every connected service before letting an agent make calls for you. A dinner reservation probably does not require access to your complete email history. Look at account permissions regularly. Remove connections you no longer use.
Be cautious about giving an AI agent Social Security numbers, PINs or complete financial credentials. Ask whether the task can be completed without exposing that information. The same caution applies to medical details. An appointment request may require some information, but the agent may not need your entire medical history.
Use confirmation controls whenever the service provides them. This becomes especially useful for purchases, cancellations or account changes. Meta says Muse requests approval before certain sensitive actions. Other AI agents may handle approvals differently, so check the settings before relying on them.
Do not assume the task went exactly as planned. Check the reservation, purchase or account change afterward. Instinct itself tells users to independently verify actions taken by its assistant. That is good advice for any AI agent acting on your behalf.
Removing access to a service may stop future access without deleting information already collected. Instinct specifically says disconnecting a third-party integration does not automatically erase previously collected data. If you want that information gone, look for a separate deletion control.
A restaurant call gives an AI limited room to cause damage. A banking problem or medical conversation can carry much more sensitive information. For those calls, I would think carefully about whether the time saved is worth the access required.
AI agents are adding capabilities quickly. A permission that seemed reasonable when an assistant only organized your inbox could carry more weight once that assistant can make calls and transactions. Review connected accounts after major feature updates. Also check whether the company has changed its privacy policy or added new controls.
Use strong, unique passwords for every account you connect to an AI assistant. A password manager can create and store them for you. Also turn on two-factor authentication or passkeys whenever they are available. If someone gets into one of those connected accounts, they may gain access to much more than the AI assistant itself.
Keep strong antivirus software running on the devices you use with AI agents. These assistants may interact with websites, email and other online services where malicious links or downloads can appear. Good security software can help detect malware and other threats before they cause more damage. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.
I can absolutely see the appeal of letting AI deal with a cable company or chase down a hard-to-get restaurant reservation. Those are exactly the kinds of calls many of us would gladly hand off. Where I get more cautious is the amount of access an agent may need to do the job well. Once an AI can read connected information and speak to businesses for you, a mistake can travel much farther than a bad chatbot answer. I would start with tasks where an error is easy to fix. Then watch how the agent handles them before giving it access to anything more sensitive. Convenience is great, but I still want the final say when my money, private information or important accounts are involved.
Would you let an AI assistant handle phone calls for you, and what is one call you would never trust it to make on your behalf? Let us know by writing to us at CyberGuy.com.
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.