
VapiCon is back November 11-12! Tickets now available•Register Now

VapiCon is back November 11-12! Tickets now available•Register Now

Your next customer may send a personal agent to call you. Tell it to "have the customer call us themselves," and you risk losing a booking without ever hearing a complaint.
A personal agent is an AI assistant that carries out tasks on your behalf, from booking appointments to resolving billing issues. Products like Meta's Muse, Instinct, Grok Bot, and OpenAI's dots are starting to bring personal agents into everyday use. I expect this to become a normal way for people to deal with businesses and to be widely adopted by the general public.
At Vapi, we've launched Personal Agent Calling in beta. You can sign in with Vapi and make calls through your personal agent without setting up an API key.
Making the call is easy. When an agent calls, the business on the other end has to answer it, check who the agent is acting for, and confirm what it's allowed to do. If any of that forces the customer to start over, the call fails. Businesses that get this right will take customers from those that don't.
Consider a customer who asks their personal agent to move a brake inspection to later in the week, after 3 PM. They haven't authorized any repairs.
In the future I'm describing, that instruction becomes permission from a human. The assistant calls the shop and schedules an appointment; the shop checks that the change is allowed, and the new appointment is confirmed. The customer gets a confirmation without having to join the call.
A shop that insists on speaking to the customer personally forces them back to the phone. While the customer's intent is clear, the business lacks a way to recognize and act on the permission already given, creating friction between the brand and consumer.
An agent should return to its owner only when the task needs a new decision. A slot before 3 PM falls outside the instruction. Approving repairs requires more authority. Moving the appointment within the agreed limits should happen without another interruption.
To the customer, the agent is an extension of themselves. Right now, to the business, it's software claiming to represent and speak for someone.
The business needs to check three things: who the agent represents, what it's allowed to do, and whether that permission still applies. The customer needs a trusted way to grant that permission, limit it, and revoke it.
Those checks belong in the systems that perform the action. A convincing conversation should never expand an agent's permissions.
We imagine a future where the business can ask for fresh approval when a request exceeds that permission or a legitimate security requirement calls for it. Otherwise, complete the task under the business's rules and report the outcome.
Agent2Agent, or A2A is an open standard that gives AI agents a shared set of rules for working together, even when different companies built them. It lets one agent find out what another can do, request a task, and track its progress. Businesses still decide which requests to allow. OAuth standards provide a way for customers to grant software permission to act on their behalf.
The challenge is getting personal agents and businesses to agree on what an agent is allowed to do. The business must then verify that each request stays within the customer's permission. A business also needs access to its own systems to complete the task: an agreed appointment has to reach the calendar.
Phone calls let personal agents reach businesses today. Over time, I expect more of the exchange to happen directly between systems. The requested change, the customer's limits, and the business's confirmation could travel together as structured information.
People still need a clear account of the outcome. The customer should see that the inspection moved and no repairs were approved. The shop should be able to check who authorized the change and what its system recorded. Visibility should let people understand and challenge an outcome without requiring them to supervise every step.
For Vapi, the immediate work is helping businesses that handle calls improve their customer support. It is also about handling the scale of calls expected with personal agents without turning away customer business. On top of that, Personal Agent Calling gives us a signal on which tasks customers delegate, whether those tasks get completed, and whether people come back.
We may need new protocol work in the future, but for now we should build on existing standards and let real usage guide what we build next. That's how we test this prediction.
If you run a business, start with one common request. Define what an agent may do and what proof of permission you'll accept. Then follow the request through to a confirmed result. Every unnecessary handoff is work your customer thought they'd delegated.
Your customer has already chosen to delegate. Make them start over, and you give them a reason to go elsewhere.
