A human concierge inside an AI agent needs an explicit handoff contract
Meta is testing contractors who can complete some Muse phone calls. The control boundary must follow the task from model to person, with consent, purpose limits and an auditable return path.

What happened
Reuters reported that Meta is testing a human-concierge option for phone calls placed through its Muse personal agent.
Why it matters
When a person silently enters an automated workflow, privacy, labour and accountability obligations change even if the user experience looks unchanged.
Reuters reported on September 22 that Meta is testing a “human concierge” for some phone calls made through Muse, its new personal AI agent. The test reportedly uses contractors, covers half of Meta employees with an opt-out, and is intended to inform safety and privacy design before a public release. Muse can place calls, interact with businesses and return transcripts or summaries.
That makes the relevant unit of control the whole task, not the model response. A user who asks an agent to negotiate a bill, arrange care or change travel may reasonably believe the work remains inside an automated system. If a contractor receives the request, the identity of the operator, permitted data, recording status and authority to act all change.
Make the handoff visible before data moves
Require affirmative consent at the moment a human may enter the task. The notice should identify the purpose, the categories of information exposed, whether the call is recorded or transcribed, the contractor organisation, retention rules and whether the user can continue without human handling. A general product notice cannot substitute for a task-specific choice when the content may include financial, health, location or family information.
The system also needs a handoff record: who or what initiated the transfer, why automation stopped, what context was released, which permissions applied, what the contractor did, and which output returned to the agent. Keep the record separate from the conversational transcript so access to operational metadata does not automatically expose the user's full content.
Bound the human role
A concierge should not inherit every permission granted to the agent. Define allowed actions by task class. A contractor might gather opening hours but be barred from accepting a contract, disclosing an account identifier or changing a booking without renewed approval. High-impact steps need a confirmation that shows the exact action, recipient and consequence.
This is also a workforce design issue. Contractors need scripts for identity disclosure, sensitive-data refusal, emergency escalation and complaint handling, plus a protected route to report pressure to bypass controls. Measure error correction, unauthorised data exposure, user reversals and escalation quality—not just completed calls or satisfaction.
The counterargument is that human fallback can improve reliability and safety while the agent is immature. That may be true, but it is an empirical claim. Compare automated-only, disclosed human-assist and user-requested human-assist cohorts for task success, privacy incidents, reversals and complaints. Do not infer benefit from adoption or positive feedback alone.
As with agent actions in CRM, governance must follow every action across system boundaries. The decisive question is not whether Muse is labelled AI or human-assisted. It is whether every transition is visible, permissioned and reconstructable.
Verify the customer-facing boundary
Run red-team scenarios in which the original request contains hidden sensitive data, a business asks for an unexpected identifier, a call crosses jurisdictions, or the contractor recognises an emergency. Check whether the user sees the same operator identity and consent state across voice, transcript, summary and later follow-up. Sample recordings only under a documented quality purpose, with access expiry and an appeal path for both users and workers.
Procurement should follow the subcontracting chain. Require the vendor to identify labour location, screening, training, monitoring, security controls and any secondary use of call content. Test deletion across contractor tools as well as the agent platform. If the service cannot show where context went, the organisation cannot honestly claim that the task remained inside its AI control boundary. A public launch gate should therefore require evidence from the whole sociotechnical route, not only a model safety test.
Set a named owner and a review date for every proposed control. A recommendation without an accountable owner, evidence request and expiry becomes policy theatre. Preserve rejected alternatives and the reason for choosing the final design so later reviewers can distinguish a deliberate trade-off from an undocumented omission.