Home · AI Security & Identity · Agent-Ready Business

Soon your customers' AI will call you.
Know who you're really dealing with.

People are starting to send AI assistants to book appointments, chase orders, get quotes and complain on their behalf. When an AI rings your line or emails your inbox, how do you know it's acting for a real customer, and what should it be allowed to see and change? We write the rules, build them into your systems, and test them.

Customer's AI callsIdentified as AIloggedWhat's the request?Low riskOpening hours ·availabilityAnswer itMediumConfirm or movea bookingOne-time code tothe customerHighChange address, bankor account detailsA person, witha call-back

When the caller isn't a person

🤳

Assistants that book and buy

Phone and browser assistants can now call businesses and fill in forms for their owners.

📞

Your voice agent will talk to theirs

AI-to-AI calls are coming. Both sides need to know the rules.

🕵️

Impersonation gets easy

An AI claiming to act for a customer is a perfect cover for fraud.

❓

No policy

Nobody has decided what a third-party AI may be told or change.

🧾

Data protection questions

Giving a customer's details to “their” AI is a disclosure. UK GDPR still applies.

🚪

Staff left guessing

Front-of-house has no script for “I'm calling on behalf of…” from a machine.

Clear rules, built in and tested

  • ✓An agent policy: what visiting AI agents may ask, be told and change, and what they may not
  • ✓Verification steps for AI callers and emailers, matched to the risk of each request
  • ✓Your voice agent, chat and forms configured to recognise and handle AI callers properly
  • ✓Scripts and a one-page guide for staff when an AI, or someone claiming to be one, gets in touch
  • ✓Logging so every AI-to-business interaction is recorded and traceable
  • ✓A UK GDPR note covering disclosures to third-party agents, written for your records

Verification that matches the risk is the heart of identity work. Confirming a booking is light-touch. Changing a delivery address or bank details is not.

The agent policy

What a visiting AI may do, by request type.

RequestAI may…Check
Opening hours, pricesBe toldNone
Is a slot free?Be toldNone
Book an appointmentBookCustomer's mobile confirmed
Move or cancelChangeOne-time code
Change address or cardNothingA person · call-back
Ask about another personNothingRefused · logged

Illustrative policy for a clinic. Yours is written in the workshop.

Decide, design, build, test

For a firm with a phone line, email and a website form, this is typically two to three weeks. You get a timeline up front.

1

Decide

A workshop to agree what agents may do, by request type, and where a person must step in.

2

Design

Verification steps and disclosure rules written down, in plain English.

3

Build

Rules built into your voice agent, chat, email handling and forms. Staff guide issued.

4

Test

We call and email you as a “customer's assistant”, including hostile attempts, and tune until it holds.

What this looks like in practice

A dental practice's voice agent would read out appointment times to anyone who gave a patient's name. After the work, it confirmed or moved a booking only after a one-time code went to the patient's registered mobile, and it logged every caller that identified as an AI. Routine bookings got faster. Data leaks stopped.

Illustrative example, drawn from typical findings. Not a named client.

“Access control is the part most AI suppliers wave at. It's the part we came from.”

Michael LewisFounder, Eutaxis · 13 years in identity & access management

The things everyone asks first

Is this really happening yet?

Yes, early. Phone and browser assistants can already call businesses and hold conversations on their owner's behalf, and adoption is growing. Firms with rules ready will handle it smoothly. The rest will improvise.

Can't we just refuse to deal with AI callers?

You can, and for some requests you should. But for routine bookings and queries, refusing turns away real customers. The better answer is clear rules: what's fine, what needs a check, and what needs a person.

How do you verify an AI is acting for a real customer?

The same way you'd verify a person, scaled to the risk: details only the customer would know, a one-time code to a registered number or email, or a call-back. Low-risk requests need little. Changes to money or personal data need more.

Does this fit with your AI Voice Agents service?

Yes. If we build your voice agent, these rules go in from day one. If you already have one, from us or someone else, we configure it.

What about data protection?

Telling a third-party AI about a customer is a disclosure under UK GDPR. We write down the lawful basis and the checks for your records, and keep disclosures to what each request needs.

How much does it cost?

A fixed price after a free discovery call, depending on how many channels are involved (phone, chat, email, forms) and whether we built your voice agent.

The other AI Security & Identity services

See how the five fit together →

Ready for the day a customer's AI rings?

Let's write the rules before you need them.