Last week Meta executives announced that its AI agent, Muse, could place outbound calls to book appointments. In reality, the company is testing a system where human workers in call centers make these calls on users’ behalf.
Ryan Fox, a principal engineer at Meta, posted on X on Sept. 16 that the team had expanded the @muse beta for outbound calls to US businesses. Meta’s chief AI officer, Alexandr Wang, shared a similar update on the same day.
we’re expanding our ☎️ 📞 beta for muse! https://t.co/ZJnXM2vb4U
— Alexandr Wang (@alexandr_wang) September 16, 2026
Internal messages sent to employees stated that the company had added a human agent layer to complete calls. The post noted that “Muse human agent calls is ready for company dogfooding,” or internal testing.
An internal document read, “Muse doesn’t just dial a number. It calls a business on your behalf, handles the conversation, completes your request, and reports back with a transcript and a summary.” It added, “It also no longer works alone. Muse is now able to hand requests to a trained human agent, who places the call and works it through.”
The post labelled the product as “confidential, pre-launch” and asked staff not to share it or any output with people outside the company.
Meta employees raised concerns about the privacy implications of sharing user requests with other humans. One worker asked why this was a feature, noting it could lead to negative press coverage portraying the AI as inadequate.
This situation follows a pattern where companies launch AI products only to reveal later that human beings perform some or all of the work. Meta is passing potentially sensitive information to human contractors. A user might ask Muse to make a doctor’s appointment without knowing a person is making the call.
Internal communications suggested that data shared with the AI and passed to humans was safe because contractors had undergone extensive training. An employee commented that training is not a security mechanism.
Another worker wrote, “This is absolutely going to create a ton of outcry if we publicly launch this as default-on. It will kill all the goodwill and organic press we’re getting from early adopters.” They warned that headlines might scream “Meta uses humans behind the scenes to make calls” or “Muse AI is actually independent contractors,” resulting in bad press about data handling.
Other testers called it a “bad bad idea.” One employee noted they were not made aware that a human was making the call until after the interaction. They stated the user was concerned about information shared with the assumption that a secure AI was making the call. Even with clear indication of a human caller, the employee noted many scenarios where they would not be comfortable with this.
Various Meta employees and regular users have shared their experiences with Muse’s calling ability. Ravid Shwartz Ziv, who does AI research at Meta, posted on X that Muse called customer service on his behalf. The agent navigated the phone tree, waited on hold, spoke with a human rep, and resolved the issue. Ziv noted the rep did not blink and talking to a bot felt completely natural.
Others reported that the call function did not work, or that the person on the other end hung up on the agent. Some said Muse did what it was supposed to do.
A Meta spokesperson told 404 Media, “Internal testing, aka dogfooding, is core to the product development process. While the response from employees has been overwhelmingly positive, the entire point is to get feedback so we can implement safety and privacy protections and improve features before we release them publicly.” The spokesperson added, “We’re working with merchants to continue improving this potential calling feature, and will only roll it out when it’s ready and with the proper disclosures.”
What it means
Users who rely on AI assistants for tasks like booking appointments may find themselves interacting with live agents rather than software. This creates uncertainty about what information is shared and who is handling sensitive requests. The company plans to wait until the feature is ready before a public launch, but the internal friction suggests significant hurdles remain regarding privacy and user trust.




