AI agents are starting to act outside software. That's the important bit.

An AI that finds a phone number has produced information. An AI that calls, asks questions and books an appointment has represented someone in the world. The change is not the telephone: it is the authority to act.

A person monitors an AI-assisted business call with a visible option to take over

A phone call is a useful test of agent authority

Google’s Gemini calling feature can call a business for hours, product availability, quotes, appointments or reservations, and navigate phone menus or wait on hold. Its current help page limits it to eligible adults in the US using a Pixel 11, US SIM, Google AI subscription, public-beta Phone app, latest Gemini app and an English device setting. It calls US numbers only, so this is not a generally available service for UK organisations.

Google says the user reviews a summary of the task, number and information to be shared, then taps to start the call. Gemini introduces itself as a Google AI assistant calling on the user’s behalf on a recorded line and states the user’s name. The user can follow a live transcript or audio, cancel before connection, take over during the call, and review the transcript and recording afterwards. Google prohibits emergency calls, payments and financial transactions, sharing sensitive personal information and telemarketing. See Google’s current Gemini calling help page.

From objective to external action

A small property-maintenance company might ask an agent to find a contractor for an urgent repair. A search tool can return a list. An external agent might identify contractors, call them, explain the issue, compare availability and prices, then report back—or make a booking if explicitly authorised.

Is it allowed to share the tenant’s address? Can it agree to an attendance fee? May it accept a date, cancel another appointment or promise access? A request such as “sort this out” does not answer those questions. An agent can have permission to gather quotes without permission to accept one. The boundary between enquiry and commitment should be explicit and enforced by its tools.

Give the agent a mandate, not an open-ended goal

This is also a brand decision. If an agent speaks for a business, an inaccurate statement or unauthorised promise can affect a customer or supplier relationship. Identify the agent honestly, define approved claims, and give the receiving person a way to request a human.

Autonomy does not have to mean invisibility

Decide when a person must approve an action in advance, when monitoring is sufficient and when an after-action record is enough. Reviewing a low-cost enquiry may be proportionate; accepting contractual terms or committing spend may require approval before the agent confirms anything.

Test exceptions as well as the happy path: the supplier offers a different service; the price exceeds the limit; someone asks for sensitive details; or the agent misunderstands a date. A reliable system should stop, explain what is unresolved and return control—not improvise a new mandate.

If a customer’s agent calls a business’s agent, both sides still need to preserve human intent through identity, authority, transaction limits and evidence of agreement. Structured confirmations and a route to a person will matter more than making the exchange sound natural.

The move is from suggestion to responsibility

A call is one example of a broader change: AI can move from producing a recommendation to carrying a task across systems and people. That can remove repetitive coordination, but it requires permissions, a stop mechanism, traceable outcomes and someone accountable for the process. For a boundary checklist, see Your AI Agent Needs a Job Description — and Boundaries. If actions can reach equipment, read What changes when an AI agent can act in the physical world?.

AI becomes consequential when it can pick up the phone—not because the phone is special, but because the system is now acting on someone’s behalf.

Review AI Agent and Automation Risk