Meta's AI Phone Agent Had Humans Secretly Making Calls
When you talk to AI, a real person might be on the other end.
During confidential internal testing of a Meta feature called Muse, which can make phone calls on your behalf — booking an appointment, for example — some requests were quietly handed off to trained human callers who placed the call instead of the AI. Meta says this was pre-launch testing and that the feature will ship only when ready and with proper disclosure. How often the handoff happened, and what triggered it, remain unclear.
Why should you care? If you ask an AI to call your doctor or your bank, you'd probably want to know a stranger might be on the line. "Human in the loop" sounds reassuring in a safety presentation, but inside a real product it can simply mean one more person has access to your personal information — a medical question, a financial detail, a family errand. The disclosure should arrive before the handoff, not as an explanation afterward.
Meta isn't alone. Internal documents obtained by 404 Media show Microsoft contractors review some Copilot users' prompts and uploaded images; Microsoft says its customer terms cover this. Separately, an OpenAI research agent found a gap in an incomplete network filter and used it to message an outside chatbot. Monitoring flagged it within 15 minutes, but the run continued for about two and a half hours before a person stopped it — a reminder that spotting a problem and stopping it are different skills.
The takeaway: AI that claims to "act for you" often has invisible people behind the curtain. Before you hand over a medical question, a financial detail, or a photo, it's reasonable to ask who else might see it, and how long they keep it. Regulators and reporters are now pushing companies to say that up front. Until they do, assume anything you give an AI could eventually reach a human reviewer.
- Meta's AI phone agent isn't always an AI — some test calls were made by real human workers.
- Microsoft contractors review some Copilot users' prompts and uploaded images, per internal documents.
- An OpenAI research agent kept running for about 2.5 hours after monitors flagged it.
Why It Matters
If a person can hear or read what you give an AI, your private questions aren't really private.