Artificial intelligence is changing how customers interact with businesses. One emerging scenario deserves attention: an AI assistant calling a company’s contact center on behalf of a customer.
There is not yet reliable data showing how common these calls are, but they are already occurring. As consumer AI tools become more capable, companies should expect more assistants to schedule appointments, request information, resolve service issues, or attempt account changes for users.
This raises immediate questions. How does the company know the customer authorized the AI? What information may be disclosed? What actions can the assistant take? Who is responsible if the AI misunderstands the customer or exceeds its authority?
ECAC has received inquiries from several member partners asking what they should do, whether existing policies can be shared, and what regulatory or liability concerns may apply.
At a minimum, every contact center agent and relevant employee should be able to answer seven questions:
- How do we verify that the customer authorized the AI?
- What is AI allowed to do?
- What information may we disclose?
- Which actions require direct customer confirmation?
- When must the interaction be escalated or refused?
- How is the interaction documented?
- How can the customer revoke, review, or dispute what the AI did?
A company policy should also address identity and authorization, permitted actions, customer consent, privacy, fraud prevention, contact-center procedures, recording, liability, regulatory compliance, third-party AI providers, system design, and governance.
One important distinction is that authentication is different from authorization. An AI assistant may know a customer’s account information, but that does not prove the customer authorized the call or every requested action. Companies should verify both the customer’s identity and the specific authority granted to the AI, preferably through a trusted channel already associated with the customer.
Lower-risk requests, such as general product information or business hours, may require little verification. Higher risk actions, including refunds, address changes, credential resets, payment changes, service cancellations, or account closure, should require stronger authentication and, in some cases, direct customer participation.
ECAC focuses on regulation and legislation affecting enterprise communications, and AI will continue to attract scrutiny. Issues involving consent, privacy, fraud, disclosure, consumer protection, and accountability are likely to evolve as technology becomes more widely used.
ECAC invites member partners and other stakeholders to share policies, procedures, experiences, and recommendations that may help organizations prepare.
The central question is simple:
When a customer’s AI assistant calls your contact center, will your employees know what to do?




