Table of Contents

Stay up to date

Sign up for the latest news & content.

Published on
October 5, 2026

When the customer is an agent: A roadmap for consumer agent-to-agent service

Table of Contents

Every customer will soon have an agent

Personal AI agents are moving from novelty to default. Major technology companies now market assistants that act on users’ behalf: comparing prices, running errands, and pursuing requests their owners never had time for. We expect that many consumers will delegate at least some service interactions to one in the near future. That makes personal agents a new channel. As with every new channel before it, brands that design for it will pull ahead, and brands that resist it will fall behind. Three pressures arrive with the change:

  • Volume. Agents will bring back contacts that brands have spent years removing. Unlike people,  agents will chase a $10 credit as relentlessly as a $1,000 refund, and if allowed, they will escalate all the way to executive relations.
  • Loyalty. Agents shop around without brand habits. Brands their agents can’t work with risk losing the business.
  • Compliance. In telecom, financial services, and other regulated industries, legal teams are already asking whether an account can be considered verified when an AI is operating it and what regulated data may be disclosed to one.

Our point of view, in short: ‍

Rather than block agents, govern them. The rest of this paper explains where we believe this is heading, what brands can do now, and where ASAPP is taking its platform.

Reframing the problem

Delegating to an AI agent works similarly to  asking a personal assistant to call on your behalf. What changes are the economics. An AI agent’s time is nearly free, so it can be more persistent, patient, knowledgeable, and relentless than almost any person would be.

Many service policies on refunds, goodwill credits, cancellations, and retention have quietly relied on friction that came with the process: the hold, the transfer, and the effort of asking twice. That friction is disappearing. Where it served a purpose, it now has to be designed in deliberately, and in a way that brings the human account holder back in at the moments that matter, without burdening every customer.

It also helps to separate two questions that are easy to blur: Is this an AI? and Is this fraud? A legitimate request made through automation is not a security vulnerability. Brands generally have three ways to respond:

Posture What it means Trade-off
Block Refuse or shut down AI-driven contact. An arms race brands can't win. It penalizes legitimate self-service and pushes customers who rely on agents toward competitors their agents can work with.
Treat as human Give the agent the same access and latitude as the account holder. Discretionary policies become easy to exploit at machine scale.
Delegated actor (recommended) Recognize the agent as acting on a customer's behalf, with access scoped to the risk of each action. Requires deliberate policy design, but is sustainable as agents become common.

Why the best counterpart to an AI agent is an AI agent

A consumer’s agent arrives prepared. It has read every published policy in seconds, it doesn’t tire, and it doesn’t get flustered. Put it against a new representative working from memory, and the odds shift to the consumer’s AI agent: it can potentially out-argue, out-wait, and out-persist a human. It will find gaps between policies that people never noticed.

The answer isn’t better detection alone. Detection that catches 80% of agents still leaves a gap someone will find. The answer is a service layer that can’t be argued, rushed, or brute-forced into a different outcome: AI that resolves requests through predefined steps, applies policy the same way every time, and brings in a person when judgment is needed. When both sides are AI, the brand’s side has to be the predictable one.

That points to a contact center organized into three lanes:

Agent-to-agent

Transactional requests

Status checks, changes and refunds that are owed, resolved quickly and cheaply in a structured exchange between AI agents.

AI with a human in the loop

Complex, risky or discretionary

The AI runs the conversation; a person reviews and approves the decisions that carry real cost or risk.

Human-to-human

Moments that build loyalty

When a bot collects the refund, the customer never feels the empathy that used to come with it. Reserve people for where connection counts, and measure more than handle time.

1  Re-engineer policy with deliberate friction

  • Target the moments that matter. Add friction to high-value, discretionary actions such as compensation beyond what’s owed, cancellations and account changes, not to every interaction. Human customers shouldn’t pay the price.
  • Confirm with the human, out of band. An agent inside the customer’s logged-in session is already past any pre-login check, and one with full account access may relay a one-time passcode. The strongest checks sit outside the agent’s reach: approval in the brand’s app on the customer’s device, or a live confirmation from the account holder. Many brands already give employees a verification tool for suspicious activity; let policy trigger it automatically at sensitive steps.
  • Keep a human in the loop for discretionary decisions, with clear limits on what any single case can receive.
  • Make decisions stick to the case. A denial should hold across transfers, channels and repeat contacts, so persistence alone doesn’t change the outcome. In practice this takes three layers: the decision is recorded on the case in the system of record and checked by the AI agent before it acts; guardrails recognize the same request repeated within a conversation; and the policy knowledge base sets clear rules for repeat requests.
  • Something to consider: fair-use policies. If automated contact grows, brands may want authenticated access with a reasonable allowance of interactions per period. Beyond that allowance, rate limits or service fees could apply.

ASAPP’s line of defense. This is what ASAPP’s Step-based Flows and HILATM workflow are designed for. Step-based Flows move every request through predefined steps that a persistent agent can’t talk its way around, and the HILA workflow routes discretionary decisions to a person for approval while the AI keeps the conversation moving. Together, they apply the rules you set for agents the same way every time.

2  Recognize agents and extend trust progressively

Rather than trying to catch every personal AI agent, we recommend progressive trust. A detected agent gets the narrowest access; one that identifies itself gets more; an authenticated agent more still; and an authenticated agent the consumer has explicitly delegated to gets the most. The brand decides what each level is allowed to do.

  • Act on self-identification and other high-confidence signals. When an agent says it is one, or arrives with signals that reliably mark it as one, apply a defined policy action: allow, restrict scope, require additional authorization, escalate to a person, flag or block. Acting on self-identification can usually be configured today, with no new technology.
  • Treat detection as a signal, not a gate. Detection is worth having as an input to a risk score, not a deterministic gate. It tells compliance teams whether a request likely came from an AI and, like web analytics, shows how agent traffic is trending.
  • Govern disclosure, not just transactions. Set explicit rules for what account and personal data an agent may receive at each trust level, even for simple informational requests. Where regulations require the account holder’s direct consent, require it.
  • Block selectively, and for cause. Blocking agents as a category is a losing strategy, but blocking a specific agent for cause can be legitimate, such as one that stores customers’ login credentials on its provider’s servers.
  • Align with emerging standards, with care. Web Bot Auth lets agents sign their requests. Major edge and security providers can now verify those signatures, but only a few AI providers sign today, and the approach works only for agents that make their own network connections.

What can actually be detected today:

Agent type How it reaches you How detectable it is
Server-side Calls your systems directly from the AI provider's infrastructure. Still new and not widely adopted, this includes things like datacenter networks, connection fingerprints and Web Bot Auth signatures.
Cloud browser Runs in a browser hosted by the provider and logs in with the customer's credentials. It arrives from the provider’s network and appears as a new device on the account. Providers can adapt quickly, so it’s an arms race.
In-browser Runs inside the customer's own browser, with their device, IP address, cookies and session. It looks like a legitimate human session. Behavioral signals are probabilistic, with meaningful false-positive rates.

Across all three, the only fully reliable signal is the agent identifying itself, by saying so or by signing its requests with Web Bot Auth, and that depends on the agent cooperating.

3  Give agents a better front door

When an agent identifies itself, there’s no reason to keep talking to it as if it were a person. We expect the conversation to switch to an agent-to-agent mode: a structured, efficient exchange in place of the chat widget or phone call.

Incentives make this work. Agents that take the governed path get faster resolution and lower handle times. The savings are largest in voice, where both sides currently pay for speech recognition and synthesis just to exchange information. For journeys where the experience matters, the governed channel can bring the consumer back into the brand’s own interface.

The engineering view

Every interaction follows the same governed path, whether the customer arrives as a person or an agent.

Our direction of travel

 As the agents and ecosystems around them evolve, here is what brands can do now, and where ASAPP is taking its platform next.

Now

  • Tag and monitor agent-driven interactions
  • Act on self-identification with defined policy actions
  • Tie decisions to the case, not the session
  • Policy-triggered verification and human approval on discretionary flows
  • Disclosure rules for regulated data

Next

  • Detect and act on agents
  • Switch to Agent to Agent mode when an agent identifies itself or is detected
  • Trust tiers tied to authentication standards
  • Real-time agent signals to brand systems
  • Fair-use and rate policies for automated contact

On Deck

  • A published, governed agent channel and protocols.
  • Brand-defined permissions, limits and data-sharing rules per trust tier
  • Hand-back to the brand's own interface for experience-critical journeys
  • Visibility into agent traffic and outcomes

‍

Questions to align on

  • Which actions should an agent be able to complete on its own, and which require the account holder?
  • What data may be disclosed to an agent at each level of trust, given your regulatory obligations?
  • Which journeys belong in each lane: agent-to-agent, human in the loop, or human-to-human?

ASAPP is the orchestration layer for your customers, whether they arrive as a person or as an agent. We’d welcome a working session with your team to map your policies to the moments that matter.

Stay up to date

Sign up for the latest news & content.

Loved this blog post?

About the author

Justin Mulhearn
Senior Director, Solutions Engineering

Justin Mulhearn is Senior Director of Solution Engineering at ASAPP, where he works with enterprise contact centers to deploy AI agents that serve customers, and increasingly, the AI agents acting on their behalf. With over more than 16 years in customer experience spanning enterprise technology and conversational AI, he has focused on building the technology foundations that let brands adopt new channels safely and at scale.

‍

‍