Every customer will soon have an agent
Personal AI agents are moving from novelty to default. Major technology companies now market assistants that act on users’ behalf: comparing prices, running errands, and pursuing requests their owners never had time for. We expect that many consumers will delegate at least some service interactions to one in the near future. That makes personal agents a new channel. As with every new channel before it, brands that design for it will pull ahead, and brands that resist it will fall behind. Three pressures arrive with the change:
- Volume. Agents will bring back contacts that brands have spent years removing. Unlike people, agents will chase a $10 credit as relentlessly as a $1,000 refund, and if allowed, they will escalate all the way to executive relations.
- Loyalty. Agents shop around without brand habits. Brands their agents can’t work with risk losing the business.
- Compliance. In telecom, financial services, and other regulated industries, legal teams are already asking whether an account can be considered verified when an AI is operating it and what regulated data may be disclosed to one.
Our point of view, in short:
Rather than block agents, govern them. The rest of this paper explains where we believe this is heading, what brands can do now, and where ASAPP is taking its platform.
Reframing the problem
Delegating to an AI agent works similarly to asking a personal assistant to call on your behalf. What changes are the economics. An AI agent’s time is nearly free, so it can be more persistent, patient, knowledgeable, and relentless than almost any person would be.
Many service policies on refunds, goodwill credits, cancellations, and retention have quietly relied on friction that came with the process: the hold, the transfer, and the effort of asking twice. That friction is disappearing. Where it served a purpose, it now has to be designed in deliberately, and in a way that brings the human account holder back in at the moments that matter, without burdening every customer.
It also helps to separate two questions that are easy to blur: Is this an AI? and Is this fraud? A legitimate request made through automation is not a security vulnerability. Brands generally have three ways to respond:
Why the best counterpart to an AI agent is an AI agent
A consumer’s agent arrives prepared. It has read every published policy in seconds, it doesn’t tire, and it doesn’t get flustered. Put it against a new representative working from memory, and the odds shift to the consumer’s AI agent: it can potentially out-argue, out-wait, and out-persist a human. It will find gaps between policies that people never noticed.
The answer isn’t better detection alone. Detection that catches 80% of agents still leaves a gap someone will find. The answer is a service layer that can’t be argued, rushed, or brute-forced into a different outcome: AI that resolves requests through predefined steps, applies policy the same way every time, and brings in a person when judgment is needed. When both sides are AI, the brand’s side has to be the predictable one.
That points to a contact center organized into three lanes:
1 Re-engineer policy with deliberate friction
- Target the moments that matter. Add friction to high-value, discretionary actions such as compensation beyond what’s owed, cancellations and account changes, not to every interaction. Human customers shouldn’t pay the price.
- Confirm with the human, out of band. An agent inside the customer’s logged-in session is already past any pre-login check, and one with full account access may relay a one-time passcode. The strongest checks sit outside the agent’s reach: approval in the brand’s app on the customer’s device, or a live confirmation from the account holder. Many brands already give employees a verification tool for suspicious activity; let policy trigger it automatically at sensitive steps.
- Keep a human in the loop for discretionary decisions, with clear limits on what any single case can receive.
- Make decisions stick to the case. A denial should hold across transfers, channels and repeat contacts, so persistence alone doesn’t change the outcome. In practice this takes three layers: the decision is recorded on the case in the system of record and checked by the AI agent before it acts; guardrails recognize the same request repeated within a conversation; and the policy knowledge base sets clear rules for repeat requests.
- Something to consider: fair-use policies. If automated contact grows, brands may want authenticated access with a reasonable allowance of interactions per period. Beyond that allowance, rate limits or service fees could apply.
ASAPP’s line of defense. This is what ASAPP’s Step-based Flows and HILATM workflow are designed for. Step-based Flows move every request through predefined steps that a persistent agent can’t talk its way around, and the HILA workflow routes discretionary decisions to a person for approval while the AI keeps the conversation moving. Together, they apply the rules you set for agents the same way every time.
2 Recognize agents and extend trust progressively
Rather than trying to catch every personal AI agent, we recommend progressive trust. A detected agent gets the narrowest access; one that identifies itself gets more; an authenticated agent more still; and an authenticated agent the consumer has explicitly delegated to gets the most. The brand decides what each level is allowed to do.
- Act on self-identification and other high-confidence signals. When an agent says it is one, or arrives with signals that reliably mark it as one, apply a defined policy action: allow, restrict scope, require additional authorization, escalate to a person, flag or block. Acting on self-identification can usually be configured today, with no new technology.
- Treat detection as a signal, not a gate. Detection is worth having as an input to a risk score, not a deterministic gate. It tells compliance teams whether a request likely came from an AI and, like web analytics, shows how agent traffic is trending.
- Govern disclosure, not just transactions. Set explicit rules for what account and personal data an agent may receive at each trust level, even for simple informational requests. Where regulations require the account holder’s direct consent, require it.
- Block selectively, and for cause. Blocking agents as a category is a losing strategy, but blocking a specific agent for cause can be legitimate, such as one that stores customers’ login credentials on its provider’s servers.
- Align with emerging standards, with care. Web Bot Auth lets agents sign their requests. Major edge and security providers can now verify those signatures, but only a few AI providers sign today, and the approach works only for agents that make their own network connections.
What can actually be detected today:
Across all three, the only fully reliable signal is the agent identifying itself, by saying so or by signing its requests with Web Bot Auth, and that depends on the agent cooperating.
3 Give agents a better front door
When an agent identifies itself, there’s no reason to keep talking to it as if it were a person. We expect the conversation to switch to an agent-to-agent mode: a structured, efficient exchange in place of the chat widget or phone call.
Incentives make this work. Agents that take the governed path get faster resolution and lower handle times. The savings are largest in voice, where both sides currently pay for speech recognition and synthesis just to exchange information. For journeys where the experience matters, the governed channel can bring the consumer back into the brand’s own interface.
The engineering view

Every interaction follows the same governed path, whether the customer arrives as a person or an agent.
Our direction of travel
As the agents and ecosystems around them evolve, here is what brands can do now, and where ASAPP is taking its platform next.
Questions to align on
- Which actions should an agent be able to complete on its own, and which require the account holder?
- What data may be disclosed to an agent at each level of trust, given your regulatory obligations?
- Which journeys belong in each lane: agent-to-agent, human in the loop, or human-to-human?



