Meta has tested a system in which human contractors could take over some phone calls made by its new personal AI agent, Muse, according to internal company communications reviewed by Reuters.
The test was created to help Muse complete calls that its AI could not reliably handle on its own. However, the experiment also raised concerns about privacy and whether users should be informed when a human worker becomes involved.
Meta launched Muse on September 8 as a personal AI agent that can perform tasks for users rather than simply answer questions. It can send emails, book travel, fill out forms, shop online and work on tasks that may take longer to complete.
The human-concierge test highlights one of the challenges facing AI agents. Although these systems can make phone calls and communicate with businesses, some companies may refuse to speak with automated callers. Meta therefore tested whether human workers could step in when Muse was unable to complete a call.
ALSO READ: Meta’s New Muse AI Agent Can Send Emails, Book Travel and Make Payments
Meta Tested Humans Handling Muse Phone Calls
Muse allows users to ask the AI agent to call businesses and handle everyday tasks. These could include making appointments, checking whether a product is available or negotiating certain bills.
The agent can make the call, speak with the person on the other end and then give the user a transcript and summary of the conversation. Meta began testing Muse’s calling feature internally in August. It later tested the human-concierge system with about half of its employees. Employees were given the option to opt out.
During the test, a human contractor could take over a call when Muse struggled to complete it. The worker effectively acted as a backup for the AI. The system was intended to increase the number of calls that Muse could successfully complete. According to reports, internal testing showed that calls handled by humans had success rates of about 95% to 98%.
Why Meta Needed Human Help for Muse Calls
The experiment highlights a practical problem with AI agents that interact with the real world. Muse may understand what a user wants and be capable of making a phone call, but the business on the other end may not cooperate with an automated system. Some companies may end a call after discovering that they are speaking with an AI.
This creates a gap between an AI agent’s ability to understand a task and its ability to complete that task. Human contractors can avoid some of these problems because businesses are generally more accustomed to dealing with people.
For Meta, the test provided a way to see whether human assistance could make Muse more reliable while the company continued improving its automated calling technology. The idea also has a precedent at Meta. Facebook previously developed an assistant called M, which relied on human workers to handle tasks that its automated systems could not complete.
The Muse experiment therefore brings back an important question for AI assistants: how much human involvement can exist behind a service that appears to be fully automated.
Meta Employees Raised Privacy Concerns Over Human Callers
The human-concierge system also raised concerns among some Meta employees because contractors could potentially hear sensitive information during calls. The issue is particularly important because Muse is intended to act as a personal assistant. Users can give the agent access to information and services that may contain private details.
A human who takes over a call could potentially hear information about a user’s bills, purchases, accounts or other personal matters. Some employees questioned whether users had been clearly informed that humans could become involved in their calls. The concerns were notable because Meta had highlighted privacy and security as important parts of Muse.
The situation is different from a standard customer-service chatbot. Muse is designed to act on a user’s behalf, so users may expect the AI itself to complete a task rather than an outside contractor stepping into the conversation.
A Contractor Incident Increased the Concerns
The privacy concerns became more serious after an incident involving one of the contractors. According to Reuters, a Meta employee used Muse to contact an internet and cable provider to negotiate a bill. A transcript of the call showed that the human contractor handling the conversation made a racist reference.
A Meta executive later apologized to the employee and said the contractor would no longer work on Meta projects. The incident highlighted another problem with using human workers as a backup for AI systems. Along with protecting user information, companies must also make sure contractors are properly trained, monitored and held to the same standards expected of the company.
Meta Rolled Back the Human Concierge Test
Meta has since rolled back the human-concierge feature for now. According to reports, a Meta vice president acknowledged internally that launching the test without proper disclosure to users had been a mistake.
Meta has said the experiment was intended to collect feedback and improve Muse’s privacy and safety protections before wider deployment. Meta spokesperson Daniel Roberts said employee feedback on Muse had been overwhelmingly positive, while also saying the company wanted to use the testing process to improve its safeguards.
The rollback does not mean Meta has abandoned Muse’s phone-calling feature. The company is continuing to work on improving the AI’s ability to complete calls without human help.
Muse’s Privacy Protections Face Questions Over Human Access
The human-concierge controversy is especially significant because Meta made privacy and security major parts of Muse’s launch. Meta says Muse operates inside a dedicated Muse Secure VM, a virtual computer environment intended to separate the AI agent and user data from other systems.
The company also says Muse has a separate Sentinel agent that controls its internet access. Muse cannot directly access passwords or payment information stored in secure systems. Users are also asked to approve sensitive actions, such as sending an email or making a purchase.
Muse provides an audit trail that allows users to see what the agent has done. Users can also disconnect services or ask Muse to forget information. Meta has said it plans to introduce Muse Confidential VM later in 2026. The company says this system will encrypt a user’s virtual machine, including data and conversations, with a key controlled only by the user.
However, the human-concierge test raises a separate privacy issue. Technical security measures can protect information inside an AI system, but they cannot by themselves prevent exposure when a human worker is brought into the process.
Meta Expands Its Personal AI Plans With Muse
Meta launched Muse on September 8 as its first personal AI agent intended for broad consumer use. The system runs on Muse Spark, which Meta describes as its most capable model for real-world agent tasks.
Muse can use a browser, fill out forms, work in the background and return to a task when something changes or when it needs the user’s approval.
The agent can also remember information that users have shared and use it in later tasks. For example, Meta says Muse could turn a recipe saved on Instagram into a grocery list while remembering a user’s dietary restrictions when helping plan a dinner.
This makes Muse different from AI tools that mainly generate text or answer questions. Meta wants Muse to have enough access to services and websites to carry out tasks on behalf of users.
That wider access also creates additional privacy and security concerns because the agent may interact with businesses, websites and people outside Meta’s platforms.
Muse Crosses 2.5 Million Downloads in Two Weeks
The human-concierge controversy comes soon after Muse’s launch, as the app has attracted significant early interest. According to Sensor Tower data cited by Reuters, Muse passed 2.5 million downloads within its first two weeks and reached the top of the U.S. app charts.
The early adoption gives Meta a large user base for testing its personal AI strategy. It also means that questions about transparency, privacy and human involvement could become increasingly important as the company expands Muse.



