Security1 publisher2 min readPublished
Meta hands some Muse assistant calls to trained humans in a call center
Internal posts seen by 404 Media say Muse can pass a user's request to a trained human agent who places the call, and one tester learned a person had dialed only afterwards. How often it happens is unclear.
The Watch · Security desk

What happened
- Meta executives said last week that Muse, its AI agent, could now phone businesses for users to do things like book a restaurant table or a haircut appointment.
- Internal posts told employees the company had added a human agent layer for calls to get completed, and that Muse can hand a request to a trained human agent who places the call.
- One employee wrote that a tester was not made aware the caller was human and was only told after the call had been made.
- Other employees who tested the system called it a bad bad idea, and 404 Media reported that the human involvement raised privacy questions on the internal board.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The sensitivity ceiling for the product is now set by whoever staffs the call center. A request to book a doctor's appointment can be read and acted on by a contractor, and 404 Media notes the user may not know that.
- decision Buyers of agentic products have a new term to negotiate before signing: human fallback, named explicitly, with the fields an agent can see and the logging of when routing happens.
- constraint When training is the stated safeguard, a customer has nothing to test. There is no access control to review and no boundary to audit, so assurance rests on employment policy.
- precedent A pre-launch product that tells its own testers about the human caller afterwards makes after-the-fact disclosure the working default other assistant vendors can copy.
A trained human agent cannot place the call without the contents of the request. The business, the user's name, the appointment slot, the reason for it, and whatever else was typed into the chat all have to reach whoever dials. Meta's internal announcement describes that handoff in those terms: Muse "is now able to hand requests to a trained human agent, who places the call and works it through" [5]. The same post says Muse "calls a business on your behalf, handles the conversation, completes your request, and reports back with a transcript and a summary" [6].
What Meta told employees was protecting that data was training. The company said the contractors had undergone "a lot of training to make sure all your data is safe and secure," according to internal communications seen by 404 Media [9]. An employee replied that the training was not a security mechanism [10].
Another employee pushed back on shipping it on by default. "This is absolutely going to create a ton of outcry if we publicly launch this as default-on. It will kill all the goodwill and organic press we're getting from early adopters," they wrote [11]. A different employee asked on the same board, "Not sure what I am missing here but why is this a 'feature?'" [16].
The gap that matters for anyone buying this class of product is between the two audiences. Ryan Fox, the principal engineer on Muse, posted on X on Sept. 16, "We just expanded the @muse beta for outbound calls to US businesses" [2]. Meta chief AI officer Alexandr Wang posted, "we're expanding our phone beta for muse!" [3]. The human agent layer was described internally, not in those posts [17].
So the fallback path is the part to write into the contract: whether a person can be handed the task at all, who employs them, which fields of the request they see, whether the end user is told before the call rather than after, and whether the routing decision is logged. None of that is visible from the outside of a product marketed as an AI agent. 404 Media reported that Meta is testing having these calls made by people in call centers, based on internal posts its reporters saw [7], and that it is not clear how often or when a call goes to a human agent instead of being handled entirely by the model [8]. The internal post calls Muse "This is still a confidential, pre-launch product" [14].
What to watch
- Whether Meta launches the human agent layer default-on or as a user preference, and whether users are told before the call.
- Whether Meta publishes the share of Muse calls routed to a person, and who employs those agents.
- Whether other agentic vendors begin disclosing human-in-the-loop routing in product documentation or data processing terms.