Photo-Illustration: Intelligencer; Photo: Getty Images
In September, small businesses around the country started receiving strange phone calls. “Hi, this is [Name],” they would begin before informing the recipient they were calling on someone else’s behalf. “I’ll be transcribing this call,” they would disclose, then launch straight into a request: “I’m looking for a quote to install three bidets”. Or: “I’d like to book a karaoke room.” Or: “I’d like to place a cake order for pickup today.” Some businesses simply proceeded, asking follow-up questions about the cake, getting answers, and logging the order. Others were more reluctant to continue. “Are you AI?” asked an employee at a Seattle karaoke place. “I need the real person.” Asked if he could help with the “customer-supplied” bidet job, a Colorado plumber replied with a question of his own, which was automatically transcribed, sort of: “Can you soak my dick?”
The mysterious calls came through Muse, an AI-assistant tool released by Meta last month, which the company says “handles it all” — including online shopping, purchasing flights, making reservations, managing inboxes, and, for some users, booking things over the phone. While internal documents leaked to 404 Media indicate that some of the calls in question may have been joint AI-human enterprises — with a call-center employee taking a handoff from an AI agent before sending the task back again — from the recipients’ side, it didn’t really matter. Suddenly, they weren’t talking directly to their customers anymore.
Early adopters on X have been sharing their experiences with their AI, or AI-ish, executive assistants. “It’s really cool when it works,” wrote one AI YouTuber. “Half the companies hang up on my agent.”
I wanted to hear about this weird new phenomenon from the other side. The Colorado plumber laughed and once again hung up the phone. The woman at the karaoke place was more patient but sounded confused: Was I AI? Was I selling AI? Could she speak to a real person? No and no, I said, and yes: I was a cold-calling human being who wanted to hear about her experience getting cold-called by bots. (After failing to book a room with Muse, the customer dispatched another agentic solution for the job and claims to have gotten through.) “Ah,” she said. “Okay. We don’t like AI calling our restaurant. We hate it.” End of call.
In the parts of the economy where small-business owners are used to taking calls or emails from potential customers, agreeing on prices, and then providing services, these interactions feel novel, odd, and more than a bit antisocial. If the tech industry gets its way, they’re also about to become much more common. Muse, which has been downloaded millions of times, was released after Instinct, an invite-only “personal assistant” that has been “trained to use a phone and a computer,” became a Bay Area sensation valued at $10 billion and a couple of weeks before OpenAI’s Dots, which the company calls “always-on agents built to handle everything.” While agentic plumber booking is the definition of an edge case, businesses and services that are more thoroughly online — restaurants in big cities, concert venues, and tech-hub recreational facilities — have been dealing with more primitive bots for years and are bracing for the coming wave.
The vision is straightforward and familiar — everyone gets a tireless automated assistant working on their behalf — and tech companies are spending hundreds of billions of dollars to see if they can get it to work this time. Soon, millions or billions of agents will come online, where they’ll be following instructions, at least in theory — moving cursors, smashing buttons, typing out requests, testing every available human interface for an advantage, and occasionally picking up the phone to say, “What can you do for us?”
Well before Muse started calling people, nonconsensual encounters with AI had become routine. Tech companies filled their interfaces with chatbots and AI features; there’s hardly a text box left to type in that doesn’t offer to fill itself, and productivity apps are full of magic buttons and sparkle icons. Mostly, what we’ve gotten used to is the slop: the endless AI-generated content that has clogged social-media feeds, glutted music-streaming sites and the Kindle store, filled up comment sections around the web, overwhelmed job portals and public submission forms, and started to alter the aesthetics of the physical world. The arrival of infinite generated images and text took a lot of the internet’s systems by surprise and left many of them broken. If this all serves as a preview of how things might look in a world where Muse makes all your customer-service calls, it’s not a particularly inspiring picture.
Earlier this year, a team of researchers analyzed 84 suspected AI-driven spikes in the use of online government services — freedom-of-information requests, public-comment processes, benefit enrollments, fine appeals — around the world and modeled the risks presented by more capable AI going forward. They coined a term for a rising phenomenon: agentic flooding. It’s what happens “when frictions that were de facto rate limits disappear,” said lead researcher Chris Schmitz in an interview.
In cases where administrative burdens prevent people from accessing government services or where individuals might not be aware of them in the first place, “there’s the potential for AI to be massively good,” Schmitz said. But in situations where automated submissions could overwhelm, say, a public-comment channel, AI use can quickly produce a “tragedy of the commons.” Before the release of Muse, when this research took place, AI submissions and more primitive agentic tools were already creating strain. Governments have been drawn to two diverging responses. One, the researchers wrote, was increasing capacity to meet new demand, either by hiring more people or using AI themselves. The other was less encouraging: creating more friction to re-suppress demand. “My biggest worry,” said Schmitz, “is that if governments really want to, building in friction is cheap, has precedent, and will be very attractive on short notice.”
A few weeks after Schmitz’s paper was published, Meta released Muse. One of its suggested uses, presented to anyone who downloaded the app, was to send it to state unclaimed-property websites, where it would open its own browser, click, scroll, and enter users’ information. My first attempt to do this failed when the New York State Comptroller Office’s website turned away Muse for being a bot. The next attempt got through with some help from my human-controlled mouse cursor, after which the agent produced a list of three claims, offering to file them right away. The path of least resistance for me, the user, would have been to just agree. When I asked for more details, though, Muse came back with an update. One of the claims, a tiny check from a media company that Muse incorrectly reported as worth thousands of dollars, did look like mine. The other two were clearly associated with other people. I filed the real one by hand; Muse had been ready to file all three, leaving them to the State of New York to reject. And why wouldn’t it? Muse has all the time and compute in the world. What’s a couple more forms to one of the world’s largest data centers?
Some Muse and Instinct users talk of being liberated from drudgery, freed up from busywork by a virtual assistant that can finally do things like a human, while companies are suggesting that agentic logic can extend all the way to the chat:
There is something to this – computers really do work differently now and can be asked to handle tasks that used to require a human touch (or at least a cursor). But in addition to expanding the boundaries of automation, the agent-assisted power users of today are also mowing down soft and unsuspecting targets — websites, interfaces, services, and people who haven’t decided how, or if, they want to respond to the replacement of customers, clients, and even friends with agents — with the advantages that come with deploying them first. Once everyone has, as Mark Zuckerberg describes it, an “exceptionally capable personal agent,” does anyone?
One thing government portals, brick-and-mortar businesses, small contractors, and even dental insurers have in common is that they’re nowhere near the center of the AI boom: They didn’t ask for this, weren’t consulted, and, for the most part, haven’t yet been forced to worry about what it could soon mean for the way they work (or get in the way of their work). Closer to the AI core, things are changing faster. Birju Kadakia, the CEO of Rec, a start-up that handles local sports and recreation for municipalities across the country, says he’s noticing early signs of a flood in San Francisco. “In our booking flows, we’re seeing a little bit of increased agentic traffic,” he said, which isn’t just there for research — LLMs have been scanning the city’s recreational pages en masse for a couple of years now — but to complete transactions. To the extent this can be tracked, Kadakia said, it still accounts for a single-digit percentage of traffic, even for activities particularly exposed to the most AI-pilled population in the world. (“We see this coming first in our San Francisco audience with tennis and pickleball,” he said.) But the real numbers are likely higher. “There are a whole bunch of agents that we can’t detect now,” he said. “We’re seeing agents that use a browser just like a human would.”
After restaurant platforms like Resy, systems like Rec are probably among the most AI-probed services on the internet. “Booking platforms are becoming almost like a traffic cop here,” Kadakia said. Going forward, Rec is thinking about a world in which, say, “50 percent going into booking flows are some form of agent,” he said. He has some ideas. Agents should be tied to a single human identity, Kadakia suggested, perhaps with some sort of agentic “passport” to minimize individual flooding, although the industry can’t yet agree on what such a system would look like. Where in-demand bookings open up at a specific time, as in the case of San Francisco’s infamously botified 8 a.m. tennis-slot openings, swarms of assistant agents could instead be thrown into a randomized lottery drawn from a three-minute window. Maybe Rec could use its own agents to suggest other facilities around the city, he said, moving people away from overburdened resources to underutilized ones; beyond that, he suggested, agent-versus-agent dynamics could become collaborative with agent-to-agent partner matching and scheduling. “It’s really cool to think about the coordination of agents,” Kadakia said.
The founders of Spot, an invite-only restaurant-reservation service that trawls for and books spots on services such as Resy and OpenTable, triggering backlash last month, made a similar case from another angle. “New York was already living in the AI-bot flood,” co-founder Andreas Larsen told me. Aggressive AI agents could force the issue in a good way, pushing booking platforms and restaurants to adapt, Larsen said. They could also leave space for a service like Spot to expand beyond reservation-sniping into an “all-purpose dining concierge,” booking but also discovering and recommending restaurants and thus layering a new class of companies over or between the ones that already exist.
If you squint, you can see it, maybe someday: agents shaking hands with other agents, allocating the world’s resources — and tables at Semma — with the power of magnanimous superintelligence. Or not. Spot, like Meta, sees no point in holding back. “We were like, ‘Okay, pretty soon everyone will have AI and their own reservation bot,’” Larsen said. “‘Let’s just give everybody one and see what happens.’”
So far, outside of the tech industry — and even within it — the arrival of AI has more often been seen first as a threat, treated more like an emergency to be mitigated than an opportunity to rebuild or rethink things. In other words, like a flood. Today, Muse might be able to get in touch with an insurance company, provide your info, wait on hold, and connect you when it’s time to talk to a real person, as Eli Tan attested in the New York Times; tomorrow, the same company that spent all that time and money to build a miserable phone-attrition machine in the first place might decide it doesn’t want to be the one yelling “Human, human, need to speak to human!”
Already there are companies selling solutions to this problem. Some claim to be able to detect AI calls and either “let useful automation through,” “require verification,” or “protect [human] agent capacity”; others talk euphemistically about “agent concierges” that can intercept incoming AI traffic and allow it to proceed “within appropriate constraints.” Some of the barriers AI can currently overcome aren’t there by mistake. They were left there, or designed for purpose, and can be built again.