AI Assistants Are Now Making Phone Calls, Raising Privacy Concerns
Instinct Concierge and Meta Muse can handle tasks via phone, but users must weigh convenience against data access.
New AI personal assistants are stepping beyond text-based interactions to make phone calls on behalf of users, a development that offers convenience but raises significant privacy and security questions. Companies like Instinct and Meta are developing AI agents capable of handling tasks such as booking restaurant reservations, sorting out billing issues, or confirming appointments.
Instinct announced its Concierge feature in September, allowing its AI assistant to make outbound calls for early-access users. The AI can handle tasks that typically involve navigating automated phone systems or waiting on hold, such as checking restaurant availability or assisting with cable bill problems. Instinct's AI assistant can operate across connected services and take actions on a user's behalf. The company has seen substantial investor interest, raising $1 billion in a Series C round that valued it at $10 billion.
Meta launched its Muse AI agent in September, which can also perform tasks across connected services. Reports indicate Meta is testing an outbound calling capability for Muse, enabling some users to have the AI contact U.S. businesses. Muse has seen rapid adoption, reportedly reaching over 3 million downloads on Apple's App Store shortly after its launch. Both Meta and Instinct appear to be competing to develop AI assistants that can act as digital proxies for users.
How These AI Assistants Work
Instinct's AI can be given tasks like calling a restaurant that doesn't take online reservations or getting a user onto a dental office's cancellation list. The AI can also potentially resolve issues with services like cable bills. The Concierge feature is currently in early access, with broader availability planned.
Muse, available in the U.S. and Canada, can browse the web, fill out forms, and complete tasks. The testing of its outbound calling feature signifies a move toward more complex, real-world interactions.
Pricing and Access
Instinct is currently in private access, and specific pricing for its Concierge feature has not been published. Meta's Muse offers a free tier with usage limits, and paid plans are reportedly available for $20 or $100 per month, depending on usage needs. Meta has not announced separate pricing for its tested phone-calling capability.
The Appeal and The Tradeoffs
The primary appeal of these AI agents lies in their ability to handle time-consuming or tedious communication tasks, freeing up users to focus on other activities. The AI can manage conversations, gather information, and complete actions without direct user intervention.
However, this convenience comes with a significant tradeoff in terms of privacy and data access. To perform these tasks effectively, AI assistants may require access to sensitive personal information, including emails, texts, bank accounts, and credit card details. Instinct's privacy policy states its assistant can access information from connected apps and services with user permission, potentially including voice data, account credentials, and payment information. Health-related data could also be involved if the AI is used to book medical appointments.
User Control and Security Measures
Both companies have implemented measures to address privacy concerns. Instinct allows users to opt out of certain data being used for AI model training, though this applies going forward. Users can also separately delete data indexed from outside sources.
Meta states that Muse runs in a secure cloud environment, with connected credentials stored securely. Muse reportedly cannot access stored passwords or payment methods and asks for approval before sensitive actions like sending emails or making purchases. Meta also claims Muse conversations and data are not shared with its advertising systems, and users can opt out of their interactions being used for AI model training. Users can also review an audit trail of the AI's actions and adjust its access permissions.
Potential Risks of AI-Initiated Actions
These AI agents can take actions on behalf of users, which introduces risks if the AI makes errors. Instinct's terms acknowledge that its services can produce incorrect information, and actions taken may contain errors or be irreversible. The company states that authorized actions can be binding as if the user had performed them directly.
Furthermore, the AI's interactions with businesses mean that personal information may be disclosed to third parties during calls. The use of AI-generated voices also presents a risk, as it can be difficult to distinguish from human voices, potentially aiding scams.
Precautions for Using AI Calling Features
Users considering these AI tools are advised to proceed with caution:
- Start with low-risk tasks: Begin with simple requests like checking restaurant availability to gauge the AI's performance.
- Review access permissions: Regularly check and limit what connected services an AI agent can access.
- Minimize sensitive data sharing: Avoid giving AI agents highly sensitive information like Social Security numbers or complete financial credentials unless absolutely necessary.
- Require approval for critical actions: Utilize confirmation controls for purchases, cancellations, or account changes.
- Verify AI actions: Independently confirm that tasks performed by the AI were completed correctly.
- Understand data deletion: Be aware that disconnecting a service may not automatically delete previously collected data; look for separate deletion options.
- Prioritize security for financial and health data: Exercise extreme caution when AI agents handle calls related to financial or medical matters.
- Update privacy settings: Revisit privacy settings as AI agents evolve and gain new capabilities.
- Secure connected accounts: Use strong passwords and enable two-factor authentication or passkeys for all accounts linked to AI assistants.
- Use antivirus software: Maintain up-to-date antivirus protection on devices used with AI agents.