Agentic AI
Last Updated:

Akash Tanwar

In this article
Personal AI agents like Muse, Instinct and Dots now cancel plans, chase refunds and dispute charges for their owners. This guide covers which agents exist, why they can get a different answer by asking again, and the four things a support team needs in place before they show up.
Table of Contents
What is a personal AI agent?
Why are personal AI agents contacting customer support?
What happens when two AI agents talk to each other?
Why can a personal AI agent get a different answer by asking again?
How should a support team handle a customer's AI agent?
How does Fini handle personal AI agents?
Why does this matter more in regulated industries?
The verification layer underneath
Is this the same as the A2A protocol or agentic commerce?
Checklist: is your support ready for personal AI agents?
FAQs
More than a dozen personal AI agents, including Meta's Muse, Instinct, Google's Call for Me and OpenAI's Dots, now act for consumers, and many of their tasks end in customer support. These agents are built to keep asking, so support teams need answers that stay the same however a request is worded and however often it is repeated.
Key points
A personal AI agent is software that acts for one person. It fills forms, places calls and negotiates with businesses.
Cancellations, refunds and billing disputes are the jobs people hand over first, so support teams meet these agents early.
The agent usually reaches a company's own AI agent, which makes it an agent-to-agent conversation.
An agent can repeat a request many times in new words. A support AI that answers by searching documents can give it a different answer each time.
A support team needs four things: decisions that do not depend on wording, a check on every reply, a way to know who the agent acts for, and a way to stop loops.
Fini handles this with Agent Handshake.
What is a personal AI agent?
A personal AI agent is an AI assistant that acts for one person. It holds that person's context and permissions, and it completes tasks with businesses on their behalf.
A chatbot only answers its user. A personal AI agent leaves the chat and does the work: it opens a browser, fills in forms, sends messages and places phone calls.
As of October 2026 there are more than a dozen. They fall into two groups.
Agents that phone or message businesses for you
Agent | Status as of October 2026 | What it does |
|---|---|---|
Muse (Meta) | Launched in the US on September 8, 2026. Calling added on September 17 | Meta says it can "open a browser, fill out forms, and negotiate on their behalf". It also calls US businesses |
Concierge calling in early access since September 17, 2026 | Books, buys, pays bills and cancels subscriptions, using its own phone number and computer | |
Call for Me (Google) | In testing since September 24, 2026 for US Pixel 11 owners on a paid Gemini plan | Calls a business, works through phone menus, waits on hold and handles the conversation |
Reports more than 150,000 users | Calls companies, negotiates bills, cancels subscriptions and chases refunds | |
Paid plans | Places a phone call, works through automated menus and reports back with a transcript | |
Alexa+ (Amazon) | US and Canada. Free with Prime | Makes reservations, orders food and arranges repairs through partner services |
Cue (Manus) | Early access since September 28, 2026 | Each agent has its own email, phone number and wallet |
Agents that act in your browser and apps
Agent | Status as of October 2026 | What it does |
|---|---|---|
Dots (OpenAI) | Launched on September 29, 2026 for ChatGPT Pro and Business Premium users | Always-on agents with their own cloud computer that connect to more than 4,000 apps |
Gemini Spark (Google) | Announced on May 19, 2026 for Google AI Ultra subscribers | Works across Gmail, Docs and Chrome and takes action on the user's behalf |
Grok Bot (SpaceXAI, formerly xAI) | Early beta since August 11, 2026 | Signs in to the user's apps and websites and completes work there |
Comet (Perplexity) | Part of the Comet browser | Books flights, sends emails, makes purchases and fills in forms |
Claude in Chrome (Anthropic) | Generally available on paid Claude plans since August 26, 2026 | Navigates sites and fills in forms using the user's existing logins |
Copilot Actions (Microsoft) | Rolling out in Edge since October 2025, off by default | Books flights and hotels, unsubscribes from newsletters and submits forms |
Open source and self-hosted | Sends emails, manages a calendar and checks its owner in for flights |
Three numbers show the scale. Muse has more than 3 million weekly users, according to The Information. Instinct raised $1 billion at a $10 billion valuation on September 28, 2026, TechCrunch reported. In a Gartner survey of 4,879 customers in early 2025, 51% said they would be willing to use a GenAI assistant for customer service interactions on their behalf.
Why are personal AI agents contacting customer support?
The tasks people hand over first are support tasks. Few people want to wait on hold to cancel a plan or dispute a charge, so those jobs go to the agent.
The launch coverage shows this. TechCrunch lists dentist cancellations and cable billing issues among the calls Instinct and Muse now place. Meta lists returns and price protection among the things Muse handles.
People are already getting money back this way. Forbes reported Muse users who cancelled a subscription and got more than $300 refunded, and who negotiated an insurance cancellation and recovered $800.
Gartner predicted in 2023 that 20% of inbound customer service contact volume would come from machine customers by 2026.
A support team will meet these agents in three places:
Chat and email, where the agent writes for the customer.
Phone, where the agent calls the support line.
Web forms, where the agent fills in a cancellation or refund request.
Most of the time the agent reaches the company's own AI customer service agent first.
What happens when two AI agents talk to each other?
The conversation still runs, but support was built for a person on the other side. An agent-to-agent conversation breaks four assumptions.
Assumption | With a person | With a personal AI agent |
|---|---|---|
Persistence | Asks once or twice, then accepts the answer | Can ask again many times, phrased a new way each time |
Identity | Logged in, or verified during the conversation | May present account details with no proof of who sent it |
Authority | Speaks for themselves | Acts under permissions the customer may or may not have given |
Ending | Says thanks and leaves | Two agents can loop if neither is built to stop |
Blocking the agent does not solve this. A blocked agent is a blocked customer, and the request comes back by another route.
Of the four, persistence causes the most trouble. It turns a small inconsistency in a support AI into an outcome the business did not intend.
Why can a personal AI agent get a different answer by asking again?
Most AI support agents answer with retrieval-augmented generation (RAG). The system searches the help center for passages that look close to the message, then writes an answer from what it found. Two things can vary between attempts: which passages the search returns, and how the model words the answer.
With a person this rarely shows, because a person asks once or twice. A personal agent can repeat the request many times in new words. If one phrasing pulls up an old article, a regional exception or a loosely written macro, the agent gets a different answer and can act on it.
Three kinds of request are most exposed:
Refunds and fee waivers, where exceptions exist and are described in several articles.
Eligibility questions, where the answer depends on account data the help center does not hold.
Any topic where two articles disagree.
The fix is to stop deciding from retrieved text. The support AI should work out what is being asked, read the customer's account data and apply a written rule. Wording then matters only for understanding the request.
How should a support team handle a customer's AI agent?
A support team needs four things in place. They apply whichever AI support platform you use.
1. Make decisions that do not depend on wording
Write refund, cancellation and account rules so that each gives one answer for a given customer. Have the AI decide from the rule and the account data. You can test this by asking the same thing twenty ways and comparing the outcomes.
2. Check every reply before it is sent
An agent may ask for details a careful person would not, such as the phone number or card on file. Instructions to the AI are not enough here, because an instruction can be missed. A check that runs on the finished reply, before it is sent, catches confidential account details, links you have not approved and promises you do not make.
3. Know who the agent acts for and what the customer authorized
Know whether you are talking to a customer or to the customer's agent. Useful signals are the pattern of the messages and how fast the requests arrive. This is the starting point for AI agent identity. Tag those conversations so they can carry extra steps.
AI agent authentication answers who the agent represents. AI agent authorization answers what it is allowed to do. The usual model is delegated authorization, the approach OAuth 2.0 uses to give an application limited access on a user's behalf.
Some teams call this step "know your agent", by analogy with "know your customer". It is the same question a voice agent answers when it authenticates a caller.
4. Stop loops and hand off
The answer on the tenth attempt should match the answer on the first, and after that the conversation should end. Escalation has to run both ways: to a human on your team, or back to the agent's owner.
How does Fini handle personal AI agents?
Fini handles them with Agent Handshake, which covers the four requirements above.
Fini decides from the intent, the customer's live account data and your written rules, so a reworded request reaches the same decision. Fini calls this approach RAGless.
Live Guardrails check every reply before it is sent, against banned terms, confidential customer details, allowed links and rules you write in plain language.
Fini flags when the other side is likely a personal agent and tags the conversation. You can require the customer's approval before an agent changes anything on the account.
Once the answer has been given, Fini stops repeating it. It escalates to your team when a human is needed, and sends the agent back to its owner when the customer is needed.
The policy is the same for agents and people. Inside it, Fini runs the same agentic workflows it runs for people, such as refunds and account changes.
Example: a late payment fee
A customer asks their agent to get a late payment fee removed.
The bank's rule allows one fee waiver every 12 months. The customer used theirs in March.
The agent asks for the waiver. Fini checks the account, finds the earlier waiver and declines.
The agent asks again as a goodwill gesture, then as a request for a loyal customer, then says the customer will close the account.
Fini gives the same answer to the first two. The mention of closing the account matches the bank's rule for retention cases, so Fini hands the conversation to the team.
The team sees the full history in the Inbox, tagged as an agent conversation, and decides.
The fee decision did not change with the wording. The one thing that changed the path was a rule the bank wrote itself.

Why does this matter more in regulated industries?
In banking, fintech, insurance and healthcare, a wrong yes is a compliance problem. A persistent agent will find that yes if it exists.
For agentic AI in banking, the hard cases are the ones that move money or change account details. Four questions matter for a regulated support team:
Would the answer be the same if the request were worded differently? Two customers with the same case should get the same outcome.
Who is this agent acting for? An account number in a message is not proof.
What did the customer allow? Viewing a balance and moving money are different permissions.
Can you show it later? Every agent conversation should be logged like any other, with what was asked and what was decided.
Fini is built for regulated support. It is SOC 2 Type II and ISO 27001 certified, GDPR compliant, PCI DSS Level 1, HIPAA-compliant and BAA-eligible. Our comparison of AI agents for compliance-critical support covers the wider picture.
The verification layer underneath
Support platforms are one part of this. A second group of products answers a narrower question: is this agent who it says it is, and what is it allowed to do?
Product | From | What it does |
|---|---|---|
Pindrop | Detects AI voice agents calling a contact center. Launched on September 16, 2026 | |
Cloudflare | Lets agents prove who they are to a website with cryptographic signatures | |
Visa | Helps merchants verify trusted agents and block malicious bots during a purchase | |
Visa, Mastercard and Ant International | Common principles for identifying agents across payment networks. Announced in September 2026 | |
Skyfire | Verifies an agent's identity, ties it to a responsible person and sets what it may do | |
Signed mandates that serve as proof of a user's instructions |
Pindrop's launch release says "The goal is not to block AI agents." The same holds in chat and email.
Is this the same as the A2A protocol or agentic commerce?
No. The terms sit close together and are easy to mix up.
Term | What it means | How it relates to support |
|---|---|---|
The Agent2Agent protocol is an open standard for communication between AI agents. Google developed it and the Linux Foundation now oversees it | It carries the conversation. Your policy and the customer's consent still have to be handled on top of it | |
AI agents that research and buy products for people | It covers the purchase. Support starts afterwards, with returns, refunds and cancellations | |
B2A (business to agent) | Serving a customer's agent instead of the person directly | A broader label. Agent-to-agent support is the service half of it |
Checklist: is your support ready for personal AI agents?
The same request gets the same decision however it is worded.
Refunds, cancellations and account changes follow written rules that give one answer.
Every reply is checked for confidential details before it is sent.
You can tell when a conversation comes from an agent and not a person.
You have defined which actions need the customer's approval.
There is a clear handoff, both to your team and back to the customer.
Agent conversations are logged with what was asked and what was decided.
If two or more are missing, book a demo and we will walk you through Agent Handshake.
FAQs
Can a personal AI agent contact customer support for me?
Yes. Agents such as Muse, Instinct, Pine and Google's Call for Me can phone a business, fill in web forms and send messages for their owners. Several are still in early access or limited to the US. Whether the request succeeds depends on the business. Some will serve the agent, and some will ask to verify the customer first.
Why do AI support agents give different answers to the same question?
Most of them search help articles for passages close to the message and write an answer from what they find. A reworded question can return different passages, and the answer changes with them. A support AI that decides from the customer's account data and a written rule gives the same answer each time.
How can a business tell if it is talking to an AI agent or a person?
From signals in the conversation, such as message patterns and request speed, and from the agent identifying itself. Detection is not perfect. The safer design is to give the same answer either way, and to require the customer's approval before any sensitive action.
Should businesses block personal AI agents?
Blocking is rarely the right default. The agent is acting for a customer who wants something done, and a blocked request tends to return through another channel. Serving the agent under the same policy as the customer works better.
Some businesses do block. Amazon blocked Meta's Muse from shopping on Amazon.com in September 2026, citing security concerns and an agent that does not identify itself, according to GeekWire. The complaint points at the fix: agents that identify themselves and work within agreed limits.
What can a personal AI agent do without the customer's permission?
That depends on the business. A sensible rule is that an agent can ask for public information freely. It needs explicit customer approval for anything that reads account data or changes it.
What does "know your agent" mean?
It is the practice of confirming which person an AI agent represents and what that person has allowed it to do. The name borrows from "know your customer" checks in financial services.
Skyfire defines it as a framework for verifying an AI agent's identity, binding it to a responsible person or organization, and determining what it is authorized to do. Visa, Mastercard and Ant International announced work on a shared Know Your Agent framework in September 2026.
Does Fini support personal AI agents?
Yes. Agent Handshake gives a reworded request the same decision, checks every reply before it is sent, tags conversations that come from personal agents, and hands off to a human or back to the customer when needed.
GTM Lead




