People are starting to send AI assistants to book appointments, chase orders, get quotes and complain on their behalf. When an AI rings your line or emails your inbox, how do you know it's acting for a real customer, and what should it be allowed to see and change? We write the rules, build them into your systems, and test them.
Phone and browser assistants can now call businesses and fill in forms for their owners.
AI-to-AI calls are coming. Both sides need to know the rules.
An AI claiming to act for a customer is a perfect cover for fraud.
Nobody has decided what a third-party AI may be told or change.
Giving a customer's details to “their” AI is a disclosure. UK GDPR still applies.
Front-of-house has no script for “I'm calling on behalf of…” from a machine.
Verification that matches the risk is the heart of identity work. Confirming a booking is light-touch. Changing a delivery address or bank details is not.
What a visiting AI may do, by request type.
| Request | AI may… | Check |
|---|---|---|
| Opening hours, prices | Be told | None |
| Is a slot free? | Be told | None |
| Book an appointment | Book | Customer's mobile confirmed |
| Move or cancel | Change | One-time code |
| Change address or card | Nothing | A person · call-back |
| Ask about another person | Nothing | Refused · logged |
Illustrative policy for a clinic. Yours is written in the workshop.
For a firm with a phone line, email and a website form, this is typically two to three weeks. You get a timeline up front.
A workshop to agree what agents may do, by request type, and where a person must step in.
Verification steps and disclosure rules written down, in plain English.
Rules built into your voice agent, chat, email handling and forms. Staff guide issued.
We call and email you as a “customer's assistant”, including hostile attempts, and tune until it holds.
A dental practice's voice agent would read out appointment times to anyone who gave a patient's name. After the work, it confirmed or moved a booking only after a one-time code went to the patient's registered mobile, and it logged every caller that identified as an AI. Routine bookings got faster. Data leaks stopped.
Illustrative example, drawn from typical findings. Not a named client.
“Access control is the part most AI suppliers wave at. It's the part we came from.”
Yes, early. Phone and browser assistants can already call businesses and hold conversations on their owner's behalf, and adoption is growing. Firms with rules ready will handle it smoothly. The rest will improvise.
You can, and for some requests you should. But for routine bookings and queries, refusing turns away real customers. The better answer is clear rules: what's fine, what needs a check, and what needs a person.
The same way you'd verify a person, scaled to the risk: details only the customer would know, a one-time code to a registered number or email, or a call-back. Low-risk requests need little. Changes to money or personal data need more.
Yes. If we build your voice agent, these rules go in from day one. If you already have one, from us or someone else, we configure it.
Telling a third-party AI about a customer is a disclosure under UK GDPR. We write down the lawful basis and the checks for your records, and keep disclosures to what each request needs.
A fixed price after a free discovery call, depending on how many channels are involved (phone, chat, email, forms) and whether we built your voice agent.