The AI makes the call. But a human was sometimes behind it
Meta's personal AI agent Muse can handle tasks such as email, shopping and travel booking on a user's behalf, and it recently gained the ability to call businesses directly.
Reuters reported an unexpected detail on September 22: in an internal Meta test, some calls made through Muse were handled by outside human contractors under a 'human concierge' setup.
Reuters said the feature had been enabled for roughly half of employees, with an opt-out. It was an internal experiment, not a permanent feature released to the public.
This was not simply a failing AI being replaced by people
Reading the episode as 'AI still cannot do it, so humans took over' misses the more useful signal.
According to Reuters, Muse surpassed 2.5 million downloads about two weeks after launch and reached the top tier of U.S. app charts. Meta itself describes Muse as a personal AI agent that does work on a person's behalf rather than merely answering questions.
Meta says Muse runs inside a dedicated Muse Secure VM with its own browser, and that users control how much access the agent receives. The human-concierge test therefore appeared not in an obsolete service but while Meta was trying to connect a more autonomous agent to real life.
Searching the web and calling a real person are different automation problems
When AI searches the web or drafts text, much of the work remains inside a digital environment.
A real phone call is different. A restaurant may offer an alternative time, a merchant may impose a condition that is not online, identity verification may be required, or sensitive information may enter the conversation. The other person is not guaranteed to answer in a predictable format.
As an agent begins interacting with people, payments and reservations in the real world, exception handling, permissions, privacy and accountability become as important as generation quality.
The moment work is handed to a human, a new privacy boundary appears
That was also the source of concern for some Meta employees cited by Reuters. If a call users believe is being handled by AI is handed to a contractor, sensitive user information may become visible to a person.
A Meta spokesperson described the human-concierge test as part of learning how to improve safety and privacy before any public release.
The central issue is therefore not merely that a human entered the loop. It is whether the user can clearly understand who is actually doing the work. If an AI-to-human handoff occurs, data access and disclosure have to be designed with it.
Automation rate is not the only important metric for an AI agent
When companies deploy agents, automation rate is an obvious number to track: what percentage of tasks can the AI complete, and how much human time can it save?
Operations introduce another set of questions. Under what conditions does the agent stop? Who receives the escalated task? Can that person understand what the AI already did? And does the user know a handoff occurred?
Even a system that automates 95% of tasks can depend heavily on the design of the remaining 5% if those cases involve payments, private data, disputes or safety.
Banks are asking similar questions as agents move into transactions
The issue extends beyond Meta's calling feature.
Reuters reported that banks including NatWest, Bank of America and ING have raised concerns about AI shopping agents becoming involved in purchases and payments, citing fraud, privacy and unclear accountability.
Among the responses discussed were clearer disclosure when AI is involved in a transaction and clearer paths for consumers to seek redress when something goes wrong.
As agents move from the 'answer layer' into the 'action layer,' disclosure, authority and recourse start to look less like compliance footnotes and more like product functions.
The human role may become more specific than simply 'watching the AI'
The existence of humans behind an agent does not mean old call-center work survives unchanged.
If AI resolves routine cases first, the tasks escalated to people may be the unusual, ambiguous and higher-risk ones. Human workload can fall while the judgment density of each case rises.
For organizations, human-in-the-loop is therefore not a complete operating design. They also need to decide which exceptions go to which people, what authority those people have, and how their decisions feed back into the system.
The key question may be whether the handoff is visible, not whether a human exists
Escalation to people is not new. Customer service has escalation paths, finance has approval steps, and healthcare has boundaries for handing cases to specialists.
What becomes harder with AI agents is that the user did not begin by interacting with a person. The user delegated authority to an AI system.
If the handoff is invisible, the user may not know who received the data, who actually made the decision, or where accountability sits when something goes wrong.
BANSEOG VIEW | As agent autonomy grows, handoff design becomes part of the product
It is too early to know whether Muse's human concierge will remain in Meta's final product. What is verified today is an internal employee test in which human contractors handled some calls.
That single case is not enough to conclude that every AI agent ultimately needs a person behind it.
But Meta's published security architecture, Reuters' human-concierge reporting and banks' warnings about agentic commerce point toward a common design problem.
As AI receives more authority to act, companies have to design not only how much can be automated but where the agent stops, who takes over, whether the user knows, and who owns the data and responsibility through the handoff.
AI-agent competition may therefore depend not only on how much an agent can finish alone, but also on how safely and explainably it transfers the work it cannot finish.
BANSEOG VIEW
Banseog View — Handoff design matters as much as agent capability
Muse's human-concierge test is better read as an early example of handoff and privacy problems that appear when agents interact with real people, bookings and transactions, not simply as evidence that AI failed.
An AI-to-human transition introduces disclosure, data-access, exception-authority and accountability questions that automation rate alone does not capture.
As AI agents move into the action layer, companies need to design not only what to automate but where and to whom the work is handed off.
SOURCES
Primary sources and references
- Reuters — Meta testing a 'human concierge' for its new personal AI agent Muse
2026-09-22. Reports the internal human-concierge test in which human contractors handled some Muse calls, exposure to roughly half of employees with opt-out, employee privacy concerns, and more than 2.5 million downloads.
- Meta — Introducing Muse: The World’s First Personal AI Agent Built for Everyone
2026-09-08. Meta's official description of Muse as a personal AI agent that acts on a user's behalf, runs in Muse Secure VM and gives users control over access permissions.
- Reuters — Banks warn AI shopping bots raise scam, fraud and data-privacy risks
2026-09-22. Reports major banks' concerns about fraud, privacy and accountability in agentic commerce, including calls for clearer disclosure of AI involvement and clearer consumer recourse.
Muse's human concierge is an internal Meta employee test, not a permanent public feature. Reuters reports that human contractors handled some calls; it does not say every Muse call was routed to a person. Current evidence does not establish that Meta will keep human concierge in the final product. The banking discussion concerns adjacent agentic-commerce risks rather than an evaluation of Muse's calling feature itself.