Straight answers to the questions teams ask — and ask AI assistants — about autonomous AI sales agents: what they are, how they differ from chatbots, whether they really book meetings, what’s legal, and how Zian works. Where a claim isn’t ours, it links to the third-party study or regulator it comes from.
At a glance
- Direct answers first, sources linked inline — Harvard Business Review, G2, Deepgram, PNAS, ACMA and others.
- Covers the technology, the evidence, compliance, deployment options and Zian’s agent line-up.
- Zian is currently in partnership-application beta — apply for partnership for access.
The technology
What are autonomous AI sales agents?
Autonomous AI sales agents are software agents that carry out real sales work — calling, texting, emailing, qualifying, following up and booking meetings — end-to-end, without a human driving each step. Unlike automation that fires a fixed sequence, an autonomous agent decides message, channel and timing per prospect and adapts to replies. Full explainer: what are autonomous AI sales agents?
How are AI sales agents different from chatbots?
A chatbot waits on your website and answers questions; a sales agent works a pipeline. The agent initiates outbound contact across phone, SMS, email and WhatsApp, pursues a goal (a booked, confirmed meeting), and follows up over days and weeks. The chatbot’s job ends at the conversation; the agent’s job ends at the outcome. Honest comparison: AI sales agents vs chatbots.
Can AI agents really book sales appointments automatically?
Yes — this is the most proven use case, because it plays to the machine’s strengths: instant response and unlimited persistence. The evidence on speed is one-sided: the Lead Response Management study found the odds of contacting a lead fall roughly 100x when response slips from 5 to 30 minutes, and Harvard Business Review’s audit of 2,241 companies found firms responding within an hour were nearly 7x more likely to qualify the lead. An AI agent responds in seconds, every time. On Zian, the appointment-setting agent books 40+ meetings a week for many teams — how it works: AI appointment setting.
Do AI voice agents work for real outbound sales calls?
Yes, within honest limits. In Deepgram and Opus Research’s State of Voice AI survey of 400 business leaders, 80% of organisations reported using some form of voice technology (including legacy IVR) — adoption is mainstream. Modern voice agents handle structured sales calls — qualification, booking, reminders, reactivation — well, and Zian’s speak 30+ languages with voice cloning supported. Two honest caveats: speech recognition still degrades on heavy accents and noisy lines (a PNAS study of five major commercial systems documented uneven error rates), and emotionally loaded calls should route to a human. Platform comparison: best AI voice agents for outbound calls, and AI voice agents vs call centres. For Australia-specific picks and compliance, see the best AI voice agents for sales calls in Australia.
How fast should an AI voice agent respond on a phone call?
Inside a second — and the closer to human pace, the better. Across languages, human conversation runs on average response gaps of about 200 milliseconds, with the most common gap close to zero (Stivers et al., PNAS 2009). Phone-call research finds trouble starts well before the one-second mark: listeners rate a speaker as noticeably less willing as response gaps stretch past roughly 600–800 milliseconds (Roberts & Francis 2013, JASA Express Letters). The network eats part of that budget before the AI does any thinking at all — ITU-T G.114 recommends keeping one-way transmission delay under 150 ms, with 400 ms as the outer planning limit. A production voice agent has to fit listening, reasoning and speaking into what’s left. How the full latency budget breaks down: why voice AI needs sub-second responses.
Do customers prefer being contacted in their own language?
Yes, and the preference is measured. CSA Research’s “Can’t Read, Won’t Buy” study of 8,709 consumers in 29 countries found 76% prefer to buy products with information in their native language, 40% will never buy from websites in other languages, and 75% are more likely to buy the same brand again if customer care is in their language. Zian’s agents operate in 30+ languages across phone, SMS, email and WhatsApp — how that scales: AI agents in 30+ languages.
What’s the difference between an AI phone agent and a predictive dialler?
A predictive dialler automates the dialling — it places calls in bulk and hands answered ones to human reps, with pacing tightly regulated (in the US, the FTC’s Telemarketing Sales Rule caps abandoned calls at 3% of answered calls per 30-day period). An AI phone agent holds the conversation itself — qualifying, answering objections and booking — with no human on the line. Full taxonomy: AI phone agents vs predictive diallers.
Should we use an AI SDR or human SDRs?
The strongest teams run both: AI for instant response, high-volume outreach and follow-up persistence; humans for judgement calls, complex discovery and closing. AI agents make 28x more contact attempts than typical human cadences on Zian, which is the part of the job humans reliably under-execute. The full trade-off analysis: AI SDR vs human SDR and hybrid AI + human SDR pods.
Why does follow-up pacing matter so much?
Because most deals die from silence, not rejection — and because the research above shows reachability decays in minutes while most teams take hours. Zian’s SmartReach AI™ orchestrates message, channel and timing per prospect with intelligent follow-up pacing; teams on the platform see a 926% increase in follow-ups and a 2,736% increase in lead contact rates. The mechanics: AI follow-up pacing.
Why are cold email reply rates falling?
Because AI made sending nearly free while inboxes became harder to reach. Instantly’s 2026 Cold Email Benchmark Report, drawn from billions of interactions on its own platform during 2025, puts the average reply rate at 3.43% while top performers exceed 10% — and Google’s bulk-sender rules now enforce authentication and a hard spam-rate ceiling. More volume makes it worse; tighter targeting, disciplined pacing and multi-channel orchestration are what still work. The full analysis: why reply rates fall as AI volume rises.
How fast do we need to respond to inbound leads?
Faster than almost any human team manages. Harvard Business Review’s classic lead-response study found firms contacting a lead within an hour were nearly 7x as likely to qualify it as those waiting even an hour longer — and over 60x as likely as those waiting 24 hours. Artemis GTM’s 2026 benchmark still puts average B2B response time around 42 hours, with lead-to-opportunity conversion at 21% for sub-5-minute responders versus 2.3% after a day. AI agents answer in seconds, around the clock. The full picture: speed to lead with AI agents.
What do independent 2026 AI SDR numbers actually show?
Mainstream adoption, nuanced results. Digital Applied’s 2026 compilation (citing Salesforce and Outreach) reports 41% of enterprise B2B teams now run an AI SDR in production, while its matched 100,000-email analysis shows AI reply rates of 4.1% versus 5.2% for humans. Salesmotion, citing Dashly, found human-booked meetings still show up more often (71% vs 52%). The consistent pattern across sources: hybrid teams win. Every figure, sourced and verified: the 2026 AI SDR numbers that matter.
Why are there no independent AI SDR benchmarks?
Because the ingredients of a real benchmark don’t exist in this category: there are no shared definitions of “reply rate” or “meeting booked”, vendor-published numbers are drawn from self-selected samples of the accounts that stayed, and no independent body audits anyone’s results — unlike information retrieval, where NIST’s TREC programme has provided shared test sets and pooled, judged evaluation since 1992, or ML systems, where MLCommons maintains the MLPerf benchmark suites. The practical substitute is buyer-run: agree metric definitions in writing, pilot on your own list with a holdout comparison, and verify outcomes in your own CRM and calendar rather than the vendor’s dashboard. Why the published numbers mislead, and the full evaluation playbook: why there are no trustworthy AI SDR benchmarks.
Do visitors from AI search convert better than search-engine visitors?
Yes, on every credible dataset we could verify. Ahrefs’ first-party data (June 2025) found AI-search visitors were about 0.5% of its traffic but 12.1% of signups — roughly 23x the organic conversion rate — and Similarweb’s April–May 2026 panel ranks ChatGPT referrals (~7.1% conversion) above every channel except paid search. The volume is still small; the intent is not. The full data story: do AI-search visitors convert better?
Is ChatGPT still where most AI referral traffic comes from?
Yes, but its lead is shrinking fast. Goodie’s 2026 AI Search Market Share report measured ChatGPT at 89.1% of B2B AI referrals across 41 brand sites in May–August 2025; by its March–April 2026 wave, ChatGPT’s brand-averaged share had fallen to 62.6%, with Claude at 18.5%, Gemini at 10.6% and Perplexity at 7.3%. The practical consequence: an AI-visibility strategy tuned to a single engine now misses more than a third of the traffic. What’s driving the shift and what to do about it: ChatGPT’s shrinking share of AI referrals.
Do half of B2B buyers really start their research in AI chatbots?
The figure is real, but it needs its comparator. G2’s 2026 AI Search Insight Report — a March 2026 survey of 1,076 B2B decision makers across North America, EMEA and APAC — found 51% of B2B software buyers “start their research with an AI chatbot more often than Google”. That is a relative-frequency comparison between two starting doors, not evidence that half of all buying journeys begin in a chatbot — though the trend is steep: the same measure was 29% in G2’s April 2025 survey. What the number actually says, and what it changes for a vendor: half of B2B buyers now start in an AI chatbot.
What is zero-click AI search, and can a brand still win from it?
Zero-click means the answer ends the journey: SparkToro’s 2026 analysis of Similarweb panel data found 68.01% of US Google searches ended without a click in the first four months of 2026, and Ahrefs measured all AI chatbots combined at about 0.28% of total web traffic in March 2026 — so most of the value of appearing in an AI answer is the recommendation itself, not the visit. A brand wins by being named and cited inside the answer. How to do that deliberately: zero-click AI answers.
Why does a brand appear in one AI answer and vanish from the next?
Because AI answers are drawn fresh each time, not read from a fixed list. seoClarity’s tracking found ChatGPT citation volumes fell 86–94% across five markets between February and April 2026, then rebounded in May, and Profound measured only 11.0% overlap between the domains ChatGPT and Perplexity cite for identical prompts. The practical response is breadth (many citable pages) and repeated measurement rather than one hero page and one snapshot. The full mechanics: AI answer volatility.
Which websites do AI engines actually cite most?
Citations concentrate hard on a small set of trusted surfaces. 5W’s AI Platform Citation Source Index 2026 — an aggregation of six citation studies covering 680M+ citations — puts Reddit first across every major engine (~40% frequency) and finds the top 15 domains capture about 68% of consolidated citation share, while Profound’s own data has Wikipedia at 7.8% of ChatGPT’s total citations. Peec AI’s separate 30M-source analysis independently finds Reddit the #1 or #2 most-cited source on every engine it tested. For a SaaS brand that means presence on trusted third-party surfaces matters alongside owned content. Full analysis: the few sites AI engines trust, and the Reddit playbook.
How often do AI answers actually cite a source?
Rarely — but four times more often than a year ago. Similarweb’s AI search data shows citations appeared in roughly 1.6% of US ChatGPT prompts in June 2025, rising to about 6.8% by May 2026 — so even after quadrupling, more than 93% of prompts produce answers that cite nobody. The rate varies sharply by category: about 23% for travel and hospitality prompts, under 4% for professional services. Citations concentrate in retrieval modes — long, question-shaped, freshness-sensitive and comparison prompts — which is where citable pages should aim. The base rates and what they mean for AEO targets: how often AI answers actually cite a source.
Where on a page do AI engines quote from?
Mostly the top. CXL’s March 2026 analysis of 100 Google AI Overview citations found “55% of citations came from the first 30% of content, while only 21% came from the bottom 40%” — with one structural exception: a meaningful share of bottom-of-page citations came from FAQ blocks, because each question-and-answer pair works as a self-contained unit. It is a small, single-engine sample, so treat it as direction rather than law: put the answer in the first 150–200 words and open each section with its conclusion. The mechanism the engine owners document, and the fixes: front-loading for AI citation.
How do you measure AI referral traffic in GA4?
Mostly, you can’t by default — much AI-driven traffic arrives with no referrer or gets bucketed under generic Referral/Direct. Google’s default channel group now includes an “AI Assistants” channel (sources such as ChatGPT, Gemini, Deepseek, Copilot and Grok), but it does not include Perplexity and cannot see zero-referrer visits. The practical stack is three layers: GA4’s native channel, a custom channel group with a regex on session source, and server logs counting on-demand AI fetchers (ChatGPT-User, OAI-SearchBot, PerplexityBot) as a leading indicator. Step-by-step: how to actually measure AI-driven visits.
Does Google Search Console show AI search performance?
Yes — since 3 June 2026. Google’s Search Central announcement introduced dedicated Search Generative AI performance reports in Search Console, showing impressions, pages, countries, devices and dates for your URLs inside generative AI features — AI Overviews and AI Mode in Search, plus generative AI features in Discover. On rollout, the Search Console help page carries two statements side by side, and both are printed here because Google prints both: “As of August 31, 2026, we’ve rolled out these insights to all websites worldwide” and “Not all properties have access to the report, as we’re rolling out over time” (checked 6 September 2026). Two further limits: the data covers Google’s own AI surfaces only — ChatGPT, Claude and Perplexity visibility still needs log-file and referral measurement — and no dimension splits AI Mode from AI Overviews. What the report answers, what it can’t, and how to fold it into an AEO routine: Search Console’s generative-AI reports, explained.
Should we block AI crawlers in robots.txt?
Block by function, not wholesale. The owners separate training crawlers from search crawlers and user-driven fetchers, and blocking each costs something different. OpenAI’s crawler documentation says disallowing GPTBot opts a site out of training generative AI foundation models, while sites opted out of OAI-SearchBot “will not be shown in ChatGPT search answers”. Google’s crawler documentation likewise states Google-Extended controls use of content for Gemini training and grounding and “does not impact a site’s inclusion in Google Search”. A blanket block therefore trades away AI-answer visibility, not just training. The decision framework: the AI crawler allowlist for B2B SaaS; the full bot taxonomy: training bots vs on-demand fetchers.
How do I verify an AI crawler is really who it claims to be?
Never trust the user-agent string alone — scanners routinely spoof AI bot names to borrow their welcome. The major operators publish machine-readable verification data: OpenAI’s bot documentation lists published IP addresses for each of its bots (openai.com/gptbot.json, searchbot.json, chatgpt-user.json), and Google’s verification guide documents both reverse-DNS lookup and published IP ranges for its crawlers and fetchers. The two-step check: reverse-DNS the requesting IP or match it against the published JSON ranges, and treat any “GPTBot” or “ChatGPT-User” arriving from an unlisted network as an impostor. The per-vendor walkthrough: verifying AI bot traffic with rDNS and IP ranges.
What is “share of model” in AI search?
Share of model is how often — and how favourably — a brand appears in AI assistants’ answers across a set of buyer prompts, measured by repeatedly running the same prompts and logging mentions, citations and recommendations. The term entered the vocabulary via Jellyfish’s trademarked Share of Model™ platform in 2024, and rank-position thinking doesn’t transfer: SE Ranking found repeat runs of the same 10,000 queries in Google’s AI Mode shared on average just 9.2% of cited URLs, so visibility is a sampled rate, not a fixed position. How to measure it, including with no tooling budget: share of model, explained.
What is entity consistency and why does it matter for AI search?
Entity consistency means keeping the facts about your brand — name, what you do, who it’s for, key claims — identical everywhere AI systems read them: your own site, directories and third-party mentions. HubSpot’s 2026 AEO trends article lists it among the year’s answer-engine-optimisation trends, warning that inconsistent facts across your site, directory listings and third-party mentions make your authority questionable and can reduce citation likelihood. Answer engines reconcile what they read about an entity before naming it in an answer, so a description that drifts from page to page is a citation handicap. How to audit and fix yours: entity consistency for AI search.
How do I structure content so AI buying agents can parse it?
Lead with the answer, then make everything extractable: an answer-first capsule near the top, question-shaped headings in a clean sequential hierarchy, tables for comparable facts, entity facts kept identical on every page, Article and FAQPage schema, and no important content locked behind client-side JavaScript — agents extract answers rather than rank pages, so a page they can’t parse is a page they can’t cite. The llms.txt proposal standardises a single /llms.txt file to help agents use a website — cheap to serve, though no major engine documents reading it. Every pattern, practised as it’s described: writing for agentic parsing.
Do AI engines actually read llms.txt?
No engine says so. None of the four companies whose engines dominate AI answers — OpenAI, Anthropic, Google or Perplexity — documents consuming llms.txt from third-party websites; their crawler docs name exactly one control file, robots.txt. Google’s AI features documentation is explicit: “You don’t need to create new machine readable files, AI text files, or markup to appear in these features.” The AI labs do publish llms.txt for their own docs sites, but producing a courtesy file is not consuming yours. Serving one is cheap; treat claims that it drives AI citations as unproven. The owner-by-owner evidence: does any AI engine actually read llms.txt?
Does a B2B website need an MCP server?
For most marketing sites, not yet. The Model Context Protocol is a real open standard for connecting AI applications to external systems — now governed under the Linux Foundation’s Agentic AI Foundation — but it is authenticated, developer-driven infrastructure, and AI buying agents don’t crawl the web looking for MCP endpoints on brand sites. What moves the needle for a marketing site today is schema and parseable answer-shaped content; pilot an MCP server if your product is an API or platform. The full assessment: does your site need MCP for AI buying agents?
How do I prepare my website for AI buying agents that browse and fill forms?
Work three fronts. Forms: standard HTML inputs with proper labels and autocomplete attributes, so an agent completing a buyer’s details can parse the fields the way a browser’s autofill does. Entry points: schema and answer-shaped pages that state plainly what you sell and how to start. Bot-blocking: rethink the blanket wall — OpenAI’s bot documentation distinguishes its crawlers (GPTBot, OAI-SearchBot) from ChatGPT-User, a fetcher that is “not used for crawling the web in an automatic fashion” but visits a page when a person asks — so a CAPTCHA or bot-wall that stops everything non-human also turns away an agent acting for a real buyer. That trade-off deserves a decision, not a default. The full readiness audit: preparing your site and funnel for agentic buyers.
Can I buy products inside ChatGPT?
Mostly not any more — checkout has moved back to the merchant. OpenAI’s Instant Checkout launched in September 2025, letting US users buy from US Etsy sellers inside the chat; in March 2026 OpenAI announced the initial version “did not offer the level of flexibility” it aspired to and shifted merchants to their own checkout experiences while ChatGPT focuses on product discovery. The underlying Agentic Commerce Protocol (developed with Stripe, specification public on GitHub) survives, and OpenAI’s commerce documentation now centres on product feeds that let ChatGPT index catalogues — the discovery data outlived the transaction plumbing. What that arc teaches B2B SaaS teams, where the “checkout” is a demo booking: the Agentic Commerce Protocol for B2B SaaS.
Should an AI agent connect to a CRM natively, through Zapier or via API?
Match the pattern to the load. Middleware such as Zapier is quick to stand up, but Zapier’s own documentation puts polling intervals at 1 to 15 minutes depending on plan — fine for prototyping, too slow for an agent that needs mid-call CRM lookups. Native connectors handle standard objects well; direct API integrations (webhook-driven) are what real-time write-back and custom objects usually demand. Autonomous agents stress integrations harder than form-fill tools because every conversation writes activity history, and a failed write-back corrupts follow-up pacing. Decision framework: native vs Zapier vs API.
Do the Gmail bulk-sender rules apply if we send fewer than 5,000 emails a day?
Yes, in a lighter form. Google’s email sender guidelines set requirements for all senders: SPF or DKIM authentication on the sending domain, valid forward and reverse DNS (PTR) records for the sending domain or IP, TLS for transmission, RFC 5322 message formatting, and spam rates in Postmaster Tools kept below 0.3%. Full DMARC is only required above roughly 5,000 messages a day — and there, Google states the enforcement policy “can be set to none”. The outbound checklist: the 2026 bulk-sender rules.
How do I verify Perplexity and Claude bot traffic, not just OpenAI and Google?
Both publish IP lists, so the same two-step check works. Perplexity’s bot documentation names PerplexityBot (indexing) and Perplexity-User (user-initiated fetches) and publishes ranges at perplexity.ai/perplexitybot.json and perplexity-user.json. Anthropic’s crawler article names ClaudeBot, Claude-User and Claude-SearchBot and links a published IP list, stating that “If a crawler has a source IP address on this list, it indicates that the crawler is coming from Anthropic”. Match the IP first, then believe the user-agent: verifying AI bot traffic.
What is Web Bot Auth, and will AI agents start proving their identity cryptographically?
It is the cryptographic alternative to IP allowlists. Cloudflare’s Web Bot Auth documentation describes using “cryptographic signatures in HTTP messages” to verify a request comes from an automated bot: the agent publishes Ed25519 keys at /.well-known/http-message-signatures-directory and attaches Signature, Signature-Input and Signature-Agent headers. Those two individual drafts (draft-meunier-web-bot-auth-architecture and draft-meunier-http-message-signatures-directory) expired on 3 September 2026 and the IETF datatracker now marks them Replaced; the work sits with the webbotauth working-group draft, draft-ietf-webbotauth-httpsig-protocol-00, updated 1 September 2026 — a working-group draft, not yet an RFC (checked 12 September 2026).
Does a hit from ChatGPT-User mean our page was cited in an answer?
No. OpenAI’s crawler documentation says ChatGPT-User fires when a user asks ChatGPT or a CustomGPT a question and it visits a web page, and for GPT Actions — and it states that “ChatGPT-User is not used to determine whether content may appear in Search”. So a fetch proves your page was opened inside someone’s session, not that it was quoted, and not that you rank. Count citations separately from crawls: training bots vs on-demand fetchers.
Does a B2B SaaS need a product feed for ChatGPT?
Almost certainly not. OpenAI’s product feed specification is built for retail catalogues — product identifiers, variants, weights, shipping methods and return windows — fields a software subscription cannot honestly populate. For B2B software the discovery surface is still crawlable pages, clear capability and packaging explanations, and consistent structured data. Read the agentic-commerce arc before building anything: the Agentic Commerce Protocol for B2B SaaS.
What should an AI sales agent write back to the CRM after every conversation?
Six things, minimum: the outcome (booked, callback, not interested, wrong number), a timestamped summary or transcript, the consent and disclosure state, the channel and identifier used, objections raised, and the next scheduled touch. Autonomous agents pace their own follow-up from that record, so a silent write-back failure does not merely dent reporting — it corrupts the sequence. Integration patterns: AI agent CRM integration and native vs Zapier vs API.
Why do AI answer engines cite pages that don’t rank in Google’s top 10?
Because the engine is not answering your query — it is answering several. Google’s own AI features documentation states that both AI Overviews and AI Mode may use a “query fan-out” technique — “issuing multiple related searches across subtopics and data sources — to develop a response” — so the pages that win are often the ones ranking on the sub-queries. Ahrefs has measured the gap twice. Its 11 August 2025 study of a 15,000-prompt dataset found that “only 12% of links cited by ChatGPT, Gemini, and Copilot appear in Google’s top 10 results for the same prompt”, with Perplexity the outlier at 28.6%. Its 2 March 2026 update, across “863K keyword SERPs, and a grand total of 4M AI Overview URLs”, found “37.9% of URLs cited in AI Overviews also appeared within the first 10 blocks” — down from roughly 76% in its July 2025 run. Both are single-vendor samples from one tool’s index, so read them as direction, not law. What to do with the gap: rank versus AI citation overlap.
Our AI crawler traffic spiked — is that a good sign?
Not until you split it by status code. A 200 means you actually served a fresh copy; RFC 9110, section 15.4.5 defines 304 as indicating “that a conditional GET or HEAD request has been received and would have resulted in a 200 (OK) response if it were not for the fact that the condition evaluated to false” — the bot already held a valid copy and was only revalidating. A spike made mostly of 304s is a re-check loop, not new interest, and it costs you almost no bandwidth. Then check the requester is who it claims: OpenAI’s crawler documentation publishes per-bot IP lists (openai.com/gptbot.json, searchbot.json and chatgpt-user.json), and user-agent strings are trivially spoofed. Finally, remember a fetch is not a citation. The full log-reading method: AI crawler logs and 304 revalidation.
Why did my AI voice agent call drop?
Read the platform’s own field before you form a theory. Vapi’s published OpenAPI document lists 629 endedReason entries, 597 of them distinct; Retell’s disconnection_reason enum carries 34 values; Twilio’s Call resource has 8 statuses. Same incident, three vocabularies. Field-by-field mapping and a four-branch triage flow: why AI voice agent calls drop.
What is Web Bot Auth, and is it a standard yet?
Web Bot Auth lets an AI agent cryptographically sign its HTTP requests so a site can verify the caller instead of trusting a user-agent string. It builds on RFC 9421 HTTP Message Signatures. As at 8 September 2026 the IETF webbotauth working group is active with an approved charter and has adopted draft-ietf-webbotauth-httpsig-protocol-00, updated 1 September 2026 — a working-group draft, not yet an RFC. Full explainer: Web Bot Auth and signed AI agents.
Will an AI agent create the meeting in our calendar itself, or only send an invitation?
That turns on two request parameters most demos never show you. Google’s Calendar API creates the event with events.insert, and its reference states that conferenceDataVersion defaults to 0, a version that “assumes no conference data support and ignores conference data in the event’s body” — so an agent that does not send conferenceDataVersion=1 books a meeting with no Meet link. The same reference puts the sendUpdates default at false, meaning no invitation email goes out unless the agent asks for one. Microsoft Graph is a straight POST /me/events needing the Calendars.ReadWrite permission. Ask a vendor which parameters its agent sets: how deep the calendar integration really goes.
Our agent’s transfer to a human keeps failing. Where do we look first?
At the call leg, before the prompt. A warm transfer on a SIP call is a REFER request — the method defined in RFC 3515, which also defines the Refer-To header and the refer event package used to watch the outcome. Twilio’s Refer documentation says the verb generates a SIP REFER to the target URI and then listens for SIP NOTIFY messages to report state back to your application, and states plainly that PSTN and Twilio Voice SDK calls “are not supported and will result in an error”. A transfer that works over SIP in testing but fails on a real PSTN call is usually the leg type, not the script. Fault tree: why AI voice agent transfers fail.
Why does a reverse DNS lookup not verify OpenAI’s crawlers?
Because OpenAI publishes IP lists rather than reverse DNS records for them. OpenAI’s crawler documentation gives a JSON file per agent — openai.com/gptbot.json, searchbot.json, chatgpt-user.json and adsbot.json — and documents no reverse-DNS method alongside them, while Google’s verification guide documents both a reverse-DNS lookup and published ranges. A single verification routine that rDNS-checks everything will therefore fail every OpenAI fetch and label real traffic as spoofed. Match OpenAI by IP, Google by either: verifying AI bot traffic with rDNS and IP ranges.
How many different OpenAI bots might hit our site?
Four, as at 12 September 2026, and the newest one catches people out. OpenAI’s crawler documentation lists GPTBot (training crawl), OAI-SearchBot (search indexing), ChatGPT-User (fetches triggered by a person’s question) and OAI-AdsBot, which “is used to validate the safety of web pages submitted as ads on ChatGPT” and only visits pages submitted as ads. Each has its own published IP file, and the page says the robots.txt settings are independent of one another. Collapsing all four into a single “ChatGPT bot” row in your logs will make an ad review look like organic interest. The taxonomy: training bots vs on-demand fetchers.
What breaks when an AI agent writes to HubSpot at the speed of a live call?
Locks and timeouts, and both are documented. HubSpot’s error-handling reference says a 423 is returned when a record is locked, that “Locks will last for 2 seconds”, and that a 429 means your account or app is over its API rate limits. A 477 signals an account migration and carries a Retry-After header “indicating how many seconds to wait before retrying the request (typically up to 24 hours)”. Webhook subscriptions time out if your service takes longer than 5 seconds to respond, and failed notifications retry up to 10 times spread over the next 24 hours. An agent writing mid-call needs a queue, not an assumption. Patterns: AI agent CRM integration.
Does the Search Console generative AI report for Discover count impressions the same way as the Search one?
No, and three differences will distort a combined trend line. Google says all data in the Discover report is aggregated by page, so “if two generative AI results from the same property appear in the same Discover list, each impression is counted separately”, where the Search report’s chart aggregates by property and counts the pair as one. A Discover impression also requires the link to be “scrolled into view (for example, as a standard Discover card, or embedded in a carousel)”, and “Only one impression is counted per result per session”. The Pages dimension is “the page that served as the source of the information shown to the user” rather than the landing page, and the report offers Pages, Countries and Dates only, with no Devices dimension (Search Console Help, generative AI performance report for Discover, read 20 September 2026). The Search-side report, its limits and how to trend it: the Search Console generative AI performance report for AEO.
Will Google-Extended ever appear in our server logs?
No, so a bot inventory built from log lines will always be missing it. Google states that “Google-Extended doesn’t have a separate HTTP request user agent string. Crawling is done with existing Google user agent strings; the robots.txt user-agent token is used in a control capacity” (Google, list of Google crawlers, read 20 September 2026). There is therefore no IP file and no reverse DNS record to match, because nothing ever identifies itself as Google-Extended in a request. It is a robots.txt control only, governing whether content Google crawls may be used for training future generations of Gemini models and for grounding, and the same page adds that it “does not impact a site’s inclusion in Google Search nor is it used as a ranking signal in Google Search”. How to verify the bots that do arrive: verifying AI bot traffic with rDNS and IP ranges.
Our logs show Google-GeminiNotebook. Is that the bot we used to see as Google-NotebookLM?
Yes, renamed, and it is a user-triggered fetcher rather than a crawler. Google’s fetcher list gives Gemini Notebook a mobile and a desktop user-agent string carrying the token Google-GeminiNotebook and records the “Former agent (supported until August 2026)” as Google-NotebookLM, describing the fetcher as one that “requests individual URLs that Gemini Notebook users have provided as sources for their projects” (Google, list of Google user-triggered fetchers, read 20 September 2026). So a hit means a person pasted your page into a notebook, not that Google indexed it. Two operational notes from the same page: user-triggered fetchers “generally ignore robots.txt rules”, and their reverse DNS mask is ***-***-***-***.gae.googleusercontent.com or google-proxy-***-***-***-***.google.com depending on whether the fetcher is Google or user owned. Verify before you count: verifying AI bot traffic with rDNS and IP ranges.
Is there a Google fetcher that acts as an agent on a user’s behalf, and how would we verify it?
Yes, and it is verified from a different file than either the crawlers or the other fetchers. Google documents Google-Agent as “used by agents hosted on Google infrastructure to navigate the web and perform actions upon user request”, with mobile and desktop agent strings and the note that “It uses IP ranges from user-triggered-agents.json” (Google, list of Google user-triggered fetchers, read 20 September 2026). The same entry adds that “Google is also experimenting with the Web Bot Auth protocol, using the https://agent.bot.goog identity”, which is the first Google agent identity a site can check cryptographically rather than by address. The page also carries the blunt caution that “The user agent string can be spoofed”, so match the IP or the signature before you treat an agent visit as a buyer in your funnel. The signing scheme itself: Web Bot Auth and signed AI agents.
Does the Agentic Commerce Protocol expect us to host a product feed for agents to pull?
No, the direction is the opposite of a crawl. The 2026-04-17 release notes add what they call “an unreleased Feed API surface for feed metadata and product catalog management” and describe it as “a push model: merchants push product catalog metadata and product records to Agents, rather than Agents pulling catalog data from merchant-hosted endpoints”, with the endpoints “hosted by Agents and called by merchants”. Ingestion is a metadata.json file plus a products.jsonl file holding one Product object per line, and file ingestion “performs full replacement of the feed’s product set” (Agentic Commerce Protocol changelog, version 2026-04-17, read 20 September 2026). For a B2B SaaS with no catalogue that is a reason to leave it alone rather than to build it. What agentic commerce actually asks of a software seller: the Agentic Commerce Protocol for B2B SaaS.
How would an AI agent discover that we support the Agentic Commerce Protocol at all?
Through a well-known document, which is specified but not yet stable, and the repository says both things. The 2026-04-17 release notes list a discovery document at /.well-known/acp.json, “A static, publicly accessible JSON document served at the origin root per RFC 8615” that lets agents “determine ACP support, discover the API base URL, check version compatibility, and learn available capabilities before creating a checkout session”, with a transports field advertising rest or mcp (ACP changelog, version 2026-04-17, read 20 September 2026). The design document that defines it is still headed “Status: Proposal” and “Version: unreleased” (ACP discovery RFC, read 20 September 2026), and the protocol as a whole is marked beta on its own repository. Read the version header before you build to it: the Agentic Commerce Protocol for B2B SaaS.
Our agent looks a caller up in HubSpot mid-call and finds nothing. What is different about the search endpoint?
Three things, and the phone-number one is usually the fault. HubSpot says that when searching for phone numbers it “uses special calculated properties to standardize the format”, all of which begin hs_searchable_calculated_, and that “As a part of this standardization, HubSpot only uses the area code and local number. You should refrain from including the country code in your search or filter criteria”. So a lookup keyed on the caller ID exactly as the carrier delivered it can miss a contact that is plainly in the CRM. The same page rate limits the search endpoints to five requests per second per account and caps any single query at 10,000 total results (HubSpot CRM search API, page last modified 9 September 2026, read 20 September 2026). Third, search sits outside the general app limits and HubSpot states that “Responses from the search API endpoints will not include any of the rate limit headers” (HubSpot API usage guidelines and limits, read 20 September 2026), so the agent cannot read its remaining budget on the call it is making. Field-level patterns for an agent writing mid-call: AI agent CRM integration.
Is our site even eligible to appear as a Google preferred source?
Only at domain or subdomain level, and only if you have not excluded yourself from Google’s AI surfaces. Google states that “Only domain-level and subdomain-level sites are eligible to appear in the source preferences tool”, giving https://www.example.com/ and https://code.example.com/ as eligible and “the subdirectory https://www.example.com/blog” as not, and that to be eligible for display as a preferred source in AI Mode and AI Overviews “you must make sure your site is included in Search generative AI features in Search Console” (Google Search Central, preferred sources, read 20 September 2026). On reach, the same page says the feature “is available globally for the ‘Top Stories’ feature in all languages where Google Search is available”, with AI Mode and AI Overviews following wherever those features exist. Check the source preferences tool for your domain before you install the button: Preferred Sources as an AEO lever.
Can an AI voice agent answer WhatsApp calls?
Yes. Meta’s WhatsApp calling FAQ says it only provides the raw media stream, that how it is processed is entirely flexible, and that many businesses use automated voicebots, including AI bots, to answer calls from WhatsApp users. It points to the WhatsApp Business Solution Terms for restrictions on AI use cases. Calling out is narrower: Meta’s Calling API overview requires a messaging limit of at least 2,000 unique recipients a day. Setup and limits: the WhatsApp Calling API for AI voice agents.
Can a Genesys Audio Connector bot stay on the call after the transfer to an agent?
No. The Genesys Audio Connector overview states that the bi-directional streaming session is active only in the IVR channel and does not transfer to an agent, and allows up to five Audio Connector integrations per org. What the bot learned reaches the human as key/value pairs in Architect output variables, not as a live voice. If the AI agent must keep speaking after a person joins, use a SIP transfer or put it in front at the carrier: AI voice agents on Genesys and Amazon Connect.
Can I connect an external AI voice agent to Amazon Connect without the PSTN?
Yes, by two documented routes. With agent-to-agent voice streaming, Connect sends the caller’s audio to your agent as PCM at 8 kHz, 16 kHz or 24 kHz, and the AWS voice configuration page notes that audio handback is not supported mid-stream. The SIP route, CONNECT_CALL_TRANSFER_CONNECTOR, transfers calls and metadata without the public telephone network, but the Amazon Chime SDK API reference calls it a gated feature arranged through your account team. Both compared: the contact-centre integration surfaces.
Does the second AI agent remember the conversation after a handoff?
Not by default in LiveKit Agents. LiveKit’s handoff documentation says each new agent or task starts with a fresh conversation history for its LLM prompt and only sees its own instructions unless you explicitly pass conversation history using chat_ctx. In Pipecat, each LLMContextWorker gets its own context by default. Decide per transition whether to pass the full history, a summary or key facts only. When one agent is enough: one voice agent or many.
Should I use Twilio ConversationRelay or Media Streams for an AI voice agent?
ConversationRelay if your agent works in text: Twilio’s ConversationRelay TwiML docs say your application receives transcribed caller speech and sends responses as text. Media Streams if you run a speech-to-speech model or your own STT and TTS, because it carries raw audio, always audio/x-mulaw at 8000 Hz per Twilio’s Media Streams message reference. On Twilio’s US voice pricing, current as of August 2026, they cost $0.07 and $0.0044 a minute. Full comparison: Twilio ConversationRelay vs Media Streams.
How do I write a system prompt for an AI voice agent?
As eight short, labelled sections: role, spoken-output rules, turn rules, detail capture, tools, escalation, three example exchanges and per-call context. Keep it under 2,000 tokens: ElevenLabs’ prompting guide says no universal limit exists but prompts over 2,000 tokens increase latency and cost. The complete eight-section template in our guide measures 778 tokens. Menus, FAQs and long workflows belong in retrieval tools, backend agents or flow nodes. The template: how to write a system prompt for a voice AI agent.
How do I connect an AI voice agent to 3CX or FreePBX?
On 3CX, the native AI Agents need AI Edition, and 3CX’s AI Agents guide says it supports OpenAI and xAI Grok, with one provider active at a time. FreePBX or Asterisk reach an agent platform through a PJSIP trunk with G.711 audio and RFC 4733 DTMF, which LiveKit’s DTMF page carries as telephone-event/8000. A call that answers with one-way audio is most often a NAT problem, per LiveKit’s SIP troubleshooting page. The trunk, line by line: connecting an AI voice agent to 3CX, FreePBX and Asterisk.
Does a successful transfer status mean my AI agent’s transfer to a human worked?
No. Vapi’s blind transfer page says an assistant-forwarded-call ended reason confirms that Vapi initiated the transfer, not that the downstream PBX or provider completed it, and points to the telephony provider’s call detail record and SIP signalling as the source of truth. So read the ended reason, then look for a destination leg in the carrier’s records: no leg means the failure is in your configuration. More causes: why AI voice agent transfers to a human fail.
Why does my AI agent leave a voicemail message when a real person answered?
That is a false machine verdict, and on business numbers it is usually a threshold overlap. Twilio’s AMD FAQ puts business greetings at about 1800 to 3000 ms, while Twilio’s AMD documentation sets MachineDetectionSpeechThreshold to 2400 ms by default, so a receptionist’s full greeting can be scored as a machine. For businesses, Twilio suggests a threshold between 1800 and 3000. The five failure modes: AI voice agent voicemail detection failures.
Can I connect a third-party AI voice agent to Microsoft Teams Phone?
Yes. An auto attendant or call queue routes the call to a resource account linked to the agent’s Azure application, and the agent runs on Azure Communication Services. Microsoft’s third-party voice agent setup article lists the feature as generally available on 15 June, with a known issue: if the agent then tries to conference or transfer an external phone number, the call fails. Microsoft’s voice agents page says it supports voice agent solutions only from certified partners. The setup: connecting an AI voice agent to Microsoft Teams Phone.
Should I connect to the OpenAI Realtime API over WebRTC, WebSocket or SIP?
Pick by where the caller’s audio starts. Audio already on your server, such as a Twilio Media Streams call, goes over a WebSocket, which OpenAI’s WebSocket guide calls a great choice for server-to-server applications, while recommending WebRTC for browser and mobile clients. For a phone number on a SIP trunk, OpenAI’s SIP guide has you point the trunk at sip.api.openai.com with your project ID. On WebRTC or SIP, keep tools and secrets on your server. The decision table: OpenAI Realtime over WebRTC, WebSocket or SIP.
Why does the OpenAI Realtime API say the conversation already has an active response?
Your app sent response.create while another response was still writing to the default conversation. OpenAI’s Realtime client events reference says only one response can write to the default conversation at a time, and the server events reference says response.done is always emitted, whatever the final state. So wait for response.done, or cancel first. Of 17 public reports we read, 5 were interruptions whose cancel was never sent or never awaited, and 4 came from tool results. The five causes: the active response error explained.
Why is my AI voice agent not following its instructions?
Check delivery before wording. In 10 of the 23 public reports we classified on 26 September 2026, the instruction was not in force when the agent broke it: a mid-call change never arrived as an instruction (6), the session config was rejected or beaten by the first turn (3), or a summariser deleted it (1). OpenAI’s Realtime client events reference says server default instructions apply if you set none, and that in Server VAD mode the server creates responses automatically. The eight causes: why a voice agent ignores its instructions.
What is an acceptable hallucination rate for an AI voice agent?
There is no universal figure. Set a threshold for each action, then grade your own calls until the 95% upper bound sits below it; proving under 1% takes at least 299 graded calls with zero hallucinations. Public leaderboards measure something else: Vectara’s hallucination leaderboard ranged from 1.8% to 24.2% across 108 models on 22 September 2026, and it scores summaries of written articles, not phone calls. The method: acceptable hallucination rate for AI voice agents.
Can I put a third-party AI voice agent on RingCentral or Zoom Phone?
Yes, by forwarding, SIP device registration, an SBC trunk, a contact centre path or, on Zoom Phone, a Marketplace-listed virtual agent. Both vendors also sell their own agent: RingCentral’s AI Receptionist pricing page lists it from US$39 a month with 100 minutes as a RingEX add-on. On Zoom, forwarding to an external number may not pass the caller’s number to the agent. The five routes: an AI voice agent on RingCentral or Zoom Phone.
Trust, compliance and deployment
Is AI cold calling legal?
Yes, where it follows the same rules as human calling — the AI gets no exemption. In Australia that means ACMA’s telemarketing rules (permitted hours, caller identification, honouring opt-outs) and the Do Not Call Register; in the US, the TCPA imposes stricter consent requirements for automated calls. Reputable operators announce recording up front and act on every opt-out immediately. Build compliance into the agent’s rules, not the rep’s memory.
Does Australia’s Do Not Call Register apply to AI voice agents?
Yes — by definition, not by analogy. Section 4 of the Do Not Call Register Act 2006 defines a voice call to include “a call that involves a recorded or synthetic voice”, and section 5 makes a voice call with a sales purpose a telemarketing call — so an AI agent calling Australian numbers is a telemarketer, with no AI carve-out. Practically: wash every list against the Register within the 30 days before calling, keep to permitted hours, identify the caller and act on every termination request. What ACMA enforcement actually looks like, with the penalty maths: the Do Not Call Register and AI voice agents.
Do we need to register our SMS sender ID in Australia?
If you send SMS under a brand name, yes. From 1 July 2026, ACMA’s SMS Sender ID Register requires branded (alphanumeric) sender IDs to be registered, and SMS sent using unregistered sender IDs are now being labelled “Unverified” by carriers — a credibility hit no legitimate outreach programme wants. Any AI outreach that texts under your brand should be registered before its next campaign. Australian channel picks: best AI voice agents for sales calls in Australia. The registration steps, timeline and what the register means for AI-driven SMS outreach: Australia’s SMS Sender ID Register, explained.
Do we have to tell people they’re talking to an AI?
Increasingly, yes. In the US, the FCC ruled in February 2024 that AI-generated voices in robocalls count as “artificial” voices under the TCPA, which means prior express consent rules apply. In the EU, Article 50 of the AI Act requires telling people they are interacting with an AI system unless it is obvious, with general application from 2 August 2026. Beyond the law, upfront disclosure measurably protects trust. Jurisdiction by jurisdiction: outreach compliance for AI agents.
Does US law require disclosing that a sales call uses AI?
Not yet as a stand-alone duty — but AI voice calls are already regulated today. The FCC’s February 2024 declaratory ruling means AI-generated and cloned voices count as “artificial” voices under the TCPA, so the existing rules — prior express consent and caller identification — apply to AI sales calls right now. A dedicated duty to disclose that a call uses AI is, as of August 2026, only proposed: the FCC adopted NPRM 24-84 in August 2024, which would require disclosure at the start of a call, but the rule has not been finalised. What’s in force versus what’s still pending: FCC NPRM 24-84 and AI call disclosure, explained.
Does Colorado require telling consumers they’re talking to an AI?
Not under its AI Act. The original Colorado AI Act’s AI-interaction disclosure duty (SB 24-205) never took effect — the law was repealed and re-enacted on 14 May 2026 as SB 26-189, a narrower automated-decision-making framework effective 1 January 2027 with no general AI-interaction disclosure duty. A separate Chatbot Safety Act (HB 26-1263) does require operators of publicly available conversational AI services to maintain a protocol informing users they’re interacting with AI, with operator duties from 1 January 2027; the Attorney General’s proposed rules (filed 11 August 2026) are expected to sharpen its scope. What survived, what didn’t and what sales teams should do: Colorado’s rewritten AI Act.
Is it legal to use a cloned voice on business calls?
Yes, with layered consent — and unconsented cloned-voice robocalling is unlawful. The FCC’s February 2024 declaratory ruling confirmed AI-generated and cloned voices count as “artificial or prerecorded voice” under the TCPA, so US calls need prior express consent (written consent for telemarketing), caller identification and opt-out. In Australia, voice calls fall under the Do Not Call Register Act 2006 and the telemarketing Industry Standard rather than the Spam Act. You also need the voice owner’s licence to clone their voice. Full breakdown: voice cloning for business calls.
When do Australia’s automated decision-making disclosure rules start?
From 10 December 2026, organisations covered by the Privacy Act must state in their privacy policy the kinds of personal information used in — and the kinds of decisions made using — automated decision-making that could significantly affect individuals’ rights or interests, under the Privacy and Other Legislation Amendment Act 2024. It is a disclosure duty, not a prohibition; the OAIC ran a consultation in May–June 2026 and states it intends to release final guidance by September 2026. Step-by-step preparation: writing an ADM transparency statement; what else the Privacy Act review has queued for outbound teams: the Privacy Act review, mapped; the broader picture: AI agent data sovereignty in Australia.
What happens when an AI agent says something wrong?
Plan for it contractually and technically — the liability is established: in Moffatt v Air Canada (2024), a Canadian tribunal held the airline liable for a policy its chatbot invented. The mitigations: hard boundaries (agents never invent pricing or terms), instant human handoff on sensitive conversations, and complete conversation logs so every interaction is auditable.
Do autonomous sales agents need a human approving every message?
No — but they need defined gates. The 2026 operating consensus is human-in-the-loop: agents run routine outreach autonomously inside written guardrails and escalate to a person when confidence drops or stakes rise (pricing, legal terms, sensitive accounts). Article 14 of the EU AI Act requires that high-risk AI systems be designed for effective human oversight — sales outreach generally isn’t classed high-risk, but the same architecture (override authority, escalation, audit logs) is what buyers now expect. The full playbook: human-in-the-loop controls for autonomous sales agents; the when-to-escalate mechanics: confidence thresholds.
What guardrails should an autonomous AI sales agent have?
Three layers at minimum: written permissions and prohibitions (what the agent may do, and what it must never do — invent pricing, make legal claims, contact opted-out prospects), explicit escalation triggers that hand the conversation to a human, and an audit trail recording every action the agent takes. On the engineering side, OWASP’s guidance on Excessive Agency says what security teams have always said: grant the agent the least privilege its task needs, and require human approval for high-impact actions. Australia’s Voluntary AI Safety Standard makes meaningful human oversight Guardrail 5. How to write each layer, with worked examples: how to write guardrails for autonomous AI agents.
What observability should an AI agent platform expose?
Three layers: reasoning or decision traces (why the agent chose an action), tool-use and action logs (what it actually did — calls, messages, CRM writes), and outcome attribution (which conversations produced booked meetings or revenue). Add conversation transcripts and guardrail-trigger logs and you have both a debugging surface and audit evidence. OpenTelemetry’s generative-AI semantic conventions — still marked “Development” — are emerging as the vendor-neutral way to capture agent traces. The full buyer’s checklist: AI agent observability.
Can a prospect trick an AI sales agent with prompt injection?
It’s a real risk class. Sales agents read untrusted input all day — email replies, live speech, web pages — and OWASP ranks prompt injection the #1 risk for LLM applications. The UK National Cyber Security Centre cautions the problem may never be totally mitigated, so ask vendors about layered defences — least-privilege tool access, human approval gates for sensitive actions, input and output filtering, and logging — rather than accepting claims it has been solved. The buyer’s question list: prompt injection and the OWASP risks.
When should an AI sales agent escalate to a human?
When the cost of a wrong action outweighs the cost of a pause — not simply when a confidence score dips. Production teams combine signals: an explicit request for a person, sentiment degradation, out-of-scope or compliance-sensitive topics, and actions that are hard to reverse. Australia’s Voluntary AI Safety Standard makes “enable human control or intervention in an AI system to achieve meaningful human oversight” one of its ten guardrails. Escalation design in full: confidence thresholds for AI sales agents.
Can Zian’s agents run on our own infrastructure?
Yes — Zian supports private model deployment on customer infrastructure for organisations that can’t send conversation data to shared clouds (banking, government, healthcare-adjacent). Integrations cover HubSpot, Salesforce, HighLevel and Zapier either way. Details: private AI deployment for sales agents.
Does this only work for sales teams?
No — the same agent architecture runs beyond sales. Zian’s digital team includes a 24/7 multilingual customer support agent (30+ languages), plus niched agents for recruitment screening, government and council surveys, university admissions, construction project coordination, IT support and bank KYC onboarding.
What integrations does Zian support?
Native CRM integrations for HubSpot, Salesforce and HighLevel, plus Zapier and a full API for everything else — agents read and write to your existing pipeline rather than creating a parallel one. The full matrix: features and integrations; setup patterns and what to sync: CRM integrations for AI agents. Telephony is a separate question from CRM: platforms differ in whether they will accept a trunk from the carrier you already use or only sell you numbers of their own, and the handover has requirements at both ends — codecs, signalling, authentication and failover — which are set out in connecting an AI agent to your SIP trunk.
What can the agents actually do on a call or in a conversation?
Live phone, SMS, email and WhatsApp outreach in 30+ languages (voice cloning supported), with the ability to research prospects and query the web and your knowledge base mid-conversation — so answers come from your data, not generic patter. Capabilities in detail: features and integrations.
How long has the technology behind Zian been around?
The platform’s conversational-AI lineage runs back to 2018, through multi-channel expansion, private enterprise deployments and a select enterprise rollout in 2025 — this is a productisation of years of deployed agent work, not a wrapper built last quarter. The history, year by year: 2018 foundation and 2025 enterprise rollout.
Is there a free plan?
Yes — the Intel + Widgets tier is free forever, and paid tiers scale up from there. During the current beta, access to all tiers is gated through the partner application.
Did the EU AI Act’s high-risk obligations start on 2 August 2026?
No. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), published in the Official Journal on 24 July 2026, deferred the Annex III high-risk obligations to 2 December 2027 and Annex I product-embedded obligations to 2 August 2028. What did apply from 2 August 2026 is the Article 50 transparency duty — people interacting with an AI system must be told it’s AI unless that’s obvious — alongside the earlier prohibitions and GPAI rules. Full breakdown: what actually applies under the EU AI Act as of August 2026.
What does Article 50 of the EU AI Act require from AI sales and support teams?
Two duties, both applying from 2 August 2026: people interacting with an AI system must be told it’s AI unless that’s obvious, and AI-generated (synthetic) content must be marked in a machine-readable format and detectable as artificially generated. The European Commission’s Article 50 FAQ says the unless-obvious exception is to be interpreted restrictively — the test is whether an average person, reasonably well-informed and observant, would realise they’re talking to AI — so a convincing voice or chat agent should disclose rather than rely on it. The recent deferral didn’t touch this duty: Regulation (EU) 2026/1744 pushed the Annex III high-risk obligations to 2 December 2027, but Article 50 transparency applies now. The team-by-team checklist: the Article 50 compliance checklist.
What are the Gmail and Outlook bulk-sender rules for outbound email?
Since February 2024, Google’s email sender guidelines require senders of around 5,000+ daily messages to Gmail to authenticate with SPF, DKIM and DMARC, offer one-click unsubscribe, and keep spam-complaint rates below 0.3% (Google recommends under 0.1%) — with enforcement ramping up from November 2025. Microsoft applied matching authentication requirements to outlook.com, hotmail.com and live.com from May 2025, rejecting mail that fails them with error 550 5.7.515. The rules and an AI-outbound checklist: the 2026 bulk-sender crackdown.
What should an AI-to-human handoff include?
A handoff packet, not a transcript dump: who the prospect is, consent and disclosure state, a short conversation summary, objections already raised, and the next-step commitment — written back to the CRM so the human picks up where the AI left off. Zendesk’s 2026 CX Trends research (11,000+ respondents, 22 countries) found 74% of consumers get frustrated when they have to repeat information. Design guide: the AI-to-human handoff.
Do AI sales agents have to say they’re AI on a phone call?
In many places, yes — and the list is growing. In the US, the FCC’s February 2024 declaratory ruling treats AI-generated voices as “artificial voice” calls under the TCPA (consent and identification duties apply), and NPRM 24-84 — which would require explicit AI disclosure at the start of a call — remains a proposal as of August 2026. State law adds more: Maine’s 10 M.R.S. §1500-DD requires clear and conspicuous notification when an AI chatbot could mislead a consumer into thinking it’s human, Utah requires disclosure on request (proactively in regulated high-risk interactions), and California’s PUC §2874 covers artificial-voice announcements. In the EU, Article 50 of the AI Act applies from 2 August 2026. Scripts and a full jurisdiction table: AI-call disclosure scripts.
What hours can an AI agent make telemarketing calls in Australia?
The same hours as any telemarketer: under the Telemarketing and Research Calls Industry Standard, ACMA’s permitted hours for telemarketing calls are 9:00am–8:00pm weekdays and 9:00am–5:00pm Saturdays, with no calls on Sundays or national public holidays (research calls have slightly wider windows). Calling line identification must be enabled, and numbers must be washed against the Do Not Call Register. The full picture — number types, CLI rules and caller-ID reputation — is in our guide to getting an Australian number for your AI voice agent.
When does Australia’s Telemarketing Standard sunset, and what should AI callers do?
The Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 — the instrument behind Australia’s permitted calling hours, caller-identification and call-termination rules — is scheduled for automatic repeal on 1 April 2027: the Federal Register of Legislation records the sunset under section 50 of the Legislation Act 2003. Before then the ACMA must remake, replace or let it lapse; as at August 2026 no replacement consultation has opened, so any claim about a successor’s content is speculation. The practical position: comply fully with the 2017 Standard now — it binds until at least 1 April 2027 — and watch ACMA’s consultations page, because a remake drafted in the AI era could revisit how synthetic-voice callers identify themselves. The three possible outcomes and a preparation checklist: the Telemarketing Standard sunset, explained.
What is STIR/SHAKEN and does Australia use it?
STIR/SHAKEN is the US caller-ID authentication framework: the originating voice provider cryptographically signs each call with an A, B or C attestation level asserting how confident it is in the caller’s right to the number, and the terminating provider verifies the signature before the phone rings. Australia has no STIR/SHAKEN mandate — instead, ACMA has registered the C661:2022 Reducing Scam Calls and Scam SMs industry code, which requires telcos to identify, trace and block scam calls and SMS. For AI voice agents the practical advice is the same in both countries: call from numbers you control, ask your carrier how your calls are attested, and treat number reputation as an asset. The full comparison: STIR/SHAKEN and what Australia has instead.
What is branded calling (Rich Call Data) and does it work in Australia?
Branded calling puts your business name, logo and call reason on the recipient’s screen — technically, Rich Call Data (RCD) carried with the call and tied to its STIR/SHAKEN attestation, standardised in RFC 9795 and RFC 9796 (July 2025). The US has a live ecosystem: CTIA’s Branded Calling ID programme delivers vetted name, logo and call reason over cryptographically signed calls. Australia has neither STIR/SHAKEN nor an RCD ecosystem — caller-ID trust rests on the C661:2022 Reducing Scam Calls and Scam SMs industry code, which requires telcos to identify, trace and block scam traffic — so for Australian AI voice campaigns the practical play is number hygiene: consistent caller line identification, numbers you control and a reputation you protect. What exists, what’s marketing and what to do in each country: branded calling for AI voice agents.
What should an enterprise check before buying an AI sales agent platform?
Four tiers: identity and access (SAML SSO, SCIM provisioning, role-based access control), data protection (encryption, contractual data residency, sub-processor transparency), governance (immutable audit logs, third-party attestations — a SOC 2 report is an AICPA-defined examination of a service organisation’s controls, so ask for the report and its scope rather than the badge), and operational maturity (SLAs, incident history, observability of what the agent actually did). Private model deployment on your own infrastructure is an architectural alternative to certificate-led assurance. The line-by-line version with vendor questions: the enterprise readiness checklist.
Does the EU AI Act’s Article 50 disclosure duty apply to B2B calls?
Yes. The European Commission’s Article 50 FAQ frames the duty around interaction with natural persons — whether consumers, professionals or other users — so ringing a procurement manager carries the same obligation as ringing a consumer. There is no business-to-business carve-out. The only exception is where it would be obvious to a reasonably well-informed, observant person that they are dealing with AI, and the Commission reads that narrowly. Checklist: the Article 50 compliance checklist.
How do we mark AI-generated content as machine-readable under Article 50?
Article 50(2) requires synthetic output to be marked in a machine-readable format and detectable as artificially generated. Rather than invent your own scheme, the ready-made route is the European Commission’s Code of Practice on Transparency of AI-generated Content, published on 10 June 2026: the Commission and the AI Board confirmed it is “an adequate voluntary tool to demonstrate compliance with the AI Act transparency obligations”, and the Commission reports roughly 190 organisations had signed it by the end of July 2026.
Has the FCC finalised its AI call-disclosure rules?
No — as at 26 August 2026 they remain a proposal. FCC 24-84, adopted on 7 August 2024 in CG Docket No. 23-362, is a Notice of Proposed Rulemaking in which the Commission says it will “propose to define AI-generated calls and propose new rules that would require callers disclose to consumers when they receive an AI-generated call”. Proposing is not binding. What binds now is the February 2024 declaratory ruling treating AI voices as artificial under the TCPA. Full analysis: what NPRM 24-84 would change.
What must a US artificial-voice call say at the start, even without new AI rules?
Identity first, contact number second. 47 CFR §64.1200(b) requires all artificial or prerecorded voice messages to state clearly, at the beginning of the message, the identity of the business responsible for initiating the call — under its registered business name — and to state a contact telephone number during or after the message, one that lets a person make a do-not-call request in business hours. Telemarketing messages also need an automated opt-out mechanism. Wording that satisfies this: AI-agent disclosure scripts.
Can an AI agent screen job candidates lawfully?
Only with the local rules built in. New York City’s Local Law 144 requires an automated employment decision tool to have been subject to a bias audit within one year of the use of the tool, requires information about that audit to be publicly available, and requires notice to candidates — the Department of Consumer and Worker Protection began enforcing the law and rule on 5 July 2023. In the EU, employment-related systems sit in Annex III of the AI Act, whose high-risk obligations Regulation (EU) 2026/1744 deferred to 2 December 2027. Screening is higher-stakes than a sales call, so design the agent to gather structured answers and hand ranking to a human. Detail: AI candidate screening compliance and recruitment screening agents.
Can an AI agent take a customer’s card number over the phone to fix a failed payment?
No — and a well-built one will refuse to. The moment card data enters a call, your recordings, transcripts and storage fall inside PCI DSS scope. The PCI Security Standards Council’s information supplement Protecting Telephone-based Payment Card Data states that “It is a violation of PCI DSS Requirement 3.2 to store any sensitive authentication data, including card validation codes and values, after authorization even if encrypted”, and its call-centre guidance includes “Ensuring that payment card information is never sent over an unencrypted, end-user messaging medium such as chat, SMS (Simple Messaging System)/text or e-mail, or other non-encrypted communication channels” — which rules out the SMS fallback an agent might otherwise reach for. Note what that document is: the Council says “the information provided here does not replace or supersede PCI DSS requirements”. The safe pattern is that the agent never asks for, repeats or stores a number — it identifies itself, explains the failure, and sends the customer to the payment provider’s own hosted update page. How that fits a recovery sequence: voice and SMS failed-payment recovery.
How many times can we retry a declined card, and who sets the limit?
Two different parties set two different limits and they are routinely confused. The card network sets the outer bound: Adyen’s mapping of raw responses to Visa system integrity fee categories documents four Visa decline categories, and for category 1 — “Issuer will not approve” — it says “Do not retry the transaction. Visa charges an excessive retry fee if you retry the transaction”, while for categories 2, 3 and 4 “You can retry the transaction up to 15 times in a 30-day period.” Your processor then sets a tighter default: Stripe’s automate payment retries documentation says “The recommended default setting is 8 tries within 2 weeks”, and a custom schedule allows “up to three retries”. Two caveats. Adyen’s own help-centre article describes the same Visa rule differently — that “the 16th and consecutive retries in a 30-day rolling period will be assessed the excessive retry fee” — and publishes the charge by region (EU, US, CA, APAC, CEMEA and LATAM rows, with a separate cross-border rate). And Visa’s underlying bulletin is not published publicly, so confirm the count with your own acquirer rather than a blog. An AI agent should follow the schedule your processor already runs, not invent one. Sequence design: dunning by voice and SMS.
Can we call someone who abandoned our signup form?
Only on a contact detail they typed in themselves, and only with a lawful basis you can point to. Under APP 7.2, the OAIC’s APP 7 guidelines permit direct marketing where the organisation collected the information from the individual, “the individual would reasonably expect the organisation to use or disclose the personal information for that purpose”, the organisation provides a simple way to opt out, and the individual has not opted out. The OAIC adds that the reasonably-expect test “is an objective test that has regard to what a reasonable person, who is properly informed, would expect in the circumstances” and that “It is the responsibility of the organisation to be able to justify its conduct.” The ACMA sets the bar lower again: its statement of expectations on consent says do not add contact details to marketing databases without consent, “for example, if a consumer visits a website or sends an email to a business it is unlikely to constitute consent to inclusion on a marketing list or in a marketing database”. Working rule: one attempt per abandonment event, on the detail they entered, referencing the thing they started — and screen the number against the Do Not Call Register first. The full sequence: signup abandonment recovery.
Can we contact a customer who has already cancelled?
Yes, but a win-back is a marketing message and is regulated as one. The ACMA’s telemarketing and e-marketing common issues page is explicit: “We have had complaints about alleged e-marketing messages sent by businesses attempting to regain customers who have cancelled subscription services (retention messages). These messages are commercial and must comply with the Spam Act.” Its statement of expectations then closes the two doors people try: rely on inferred consent “only where there is a clear, current or ongoing relationship with the individual and the goods or services being marketed are directly related to that relationship”, and do not lean on stale permission — its example is “consent to receive telemarketing that is more than 3 months old becomes stale unless a consumer has agreed to a longer period under terms and conditions”. It also says do not re-contact people who unsubscribed to encourage them to resubscribe. Read that document for what it is: the ACMA states “This statement is not legal advice nor is it a definitive compliance guide to the Rules. It is an outcome-focused guide to better practice”. Designing around it: win-back sequences for churned subscribers.
What should an onboarding agent never ask a new user for?
Credentials of any kind — a password, a one-time code, or a live API key. Route the user to your own settings screen or an OAuth flow instead. Stripe’s API keys documentation explains why: “Only publishable keys are safe to expose outside your application’s back end”, and its handling rules include “Don’t put keys in source code or configuration files checked into version control” and “Don’t share keys over email, chat or other unencrypted channels” — a chat thread or a call transcript is exactly such a channel, and unlike a person it is retained and indexed. The second thing to get right is disclosure: the European Commission’s Article 50 FAQ says the unless-obvious exception is to be interpreted restrictively, so an onboarding agent should say it is AI rather than assume a new user has worked it out. What the agent should chase instead — first value, not form fields: onboarding and activation agents.
Does my AI receptionist have to support 911?
Usually not directly. The duties in 47 CFR §9.16 — direct 911 dialling, on-site notification and dispatchable location — bind the multi-line telephone system and whoever manufactures, imports, sells, leases, installs, manages or operates it, not an inbound AI answering layer. Kari’s Law reaches systems installed or first sold after 16 February 2020; the location deadlines are 6 January 2021 and 6 January 2022. Where an AI layer pulls you into scope: AI receptionists and 911 obligations.
How do I scrub a calling list against the US National Do Not Call Registry?
Dial only from a registry snapshot obtained no more than 31 days before the call — that is the safe harbour in 16 CFR §310.4(b)(3)(iv). Access is priced per area code: the FTC set FY 2027 fees at US$85 per area code and US$23,425 for all of them, first five free, effective 1 October 2026. Federal DNC is one of at least four lists. Full setup: scrubbing lists for AI diallers.
Why was my A2P 10DLC campaign rejected?
Almost always on the fields you filed, not the message your AI writes. The Campaign Registry says it does not review, approve or reject campaigns — connectivity providers and their upstream partners do, so raise the rejection with your provider. Twilio’s own registration guide now prints two different windows on one page: a warning that “Due to an increase in campaign submissions, campaign reviews are currently taking 10–15 days”, and, further down the same page, an approval-process paragraph saying the manual campaign vetting “can take between two to three weeks to complete” (Twilio, direct Standard and Low-Volume Standard registration guide, read 20 September 2026). Brand review is a third number again on the same page: a Brand held IN_REVIEW is under manual third-party review and “Manual reviews take seven business days or more”. AWS documents campaign registration at up to 4 weeks for US and international companies alike (read 20 September 2026). Plan against the longest figure your own provider publishes, not the banner. Rejection-reason map and how to register an agent that writes each message fresh: why A2P 10DLC campaigns get rejected.
My business number shows as Scam Likely — what do I do?
The label names the company to approach. USTelecom’s call-labelling contact list attributes Scam Likely to T-Mobile via First Orion, Spam Risk and Fraud Risk to AT&T via Hiya, and Potential Spam to Verizon via TNS. File redress with the analytics provider as well as the carrier: USTelecom’s published best practice is an initial status update within 24 hours and a conclusion on at least 95% of qualifying requests within 1 to 2 business days. Rotating numbers does not fix it: Scam Likely remediation.
What consent wording do I need before an AI agent calls a US number?
Today the wording still has to authorise calls using an automatic telephone dialing system or an artificial or prerecorded voice: 47 CFR §64.1200(f) requires a clear and conspicuous disclosure to that effect, plus a statement that signing is not a condition of purchase. The FCC’s AI-call rules in CG Docket 23-362 were still only a proposed rule as at 8 September 2026, so adding an explicit AI reference now is cheap insurance. What to record per consent: consent language and records for AI calls.
How long does it take to launch an AI voice agent in the US?
Carrier registration is the long pole, not prompt engineering. Twilio documents Customer Profile approval at 72 hours or more and warns that A2P 10DLC campaign reviews are currently taking 10–15 days; AWS publishes up to 4 weeks for US campaign registration and up to 10 days for the 10DLC number itself. Voice-only can go live in days; adding the SMS leg costs weeks. Critical-path table: the US go-live timeline.
How quickly do we have to action an unsubscribe request?
It depends who you are sending to. Yahoo’s sender best practices tell senders to “Honor unsubscribes within 2 days” and say opt-out requests “should be processed within 2 days”. Google’s email sender guidelines require one-click unsubscribe and a clearly visible unsubscribe link for senders above roughly 5,000 messages a day, and Google’s sender guidelines FAQ recommends that you “fulfill unsubscribe requests within 48 hours” and lists unsubscribe requests not honoured within 48 hours among the issues for which delivery support or mitigations are unavailable (Yahoo read 12 September 2026, Google re-read 30 September 2026). In Australia the Spam Act 2003 gives you five working days for email and SMS. Take the shortest rule that applies to the address you are sending to. The full picture: the 2026 Gmail and Outlook bulk-sender rules.
Is the FCC’s position on AI voices a proposal, or has it already decided?
Both, on two different questions. The coverage question is decided: Declaratory Ruling FCC 24-17 in CG Docket No. 23-362, adopted 2 February 2024 and released 8 February 2024, confirms that the TCPA’s restrictions on the use of “artificial or prerecorded voice” encompass current AI technologies that generate human voices, so such calls “require the prior express consent of the called party” absent an emergency purpose or exemption. What remains only proposed is a separate duty to announce that a call is AI-generated, in NPRM 24-84. Deciding coverage is not the same as mandating disclosure. Analysis: what NPRM 24-84 would change.
What is the fine if we get the EU AI Act’s transparency duty wrong?
Up to EUR 15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Article 99(4) of Regulation (EU) 2024/1689 sets that band for a list of breaches, and subparagraph (g) is “transparency obligations for providers and deployers pursuant to Article 50” — the article that requires telling people they are interacting with an AI system. Subparagraph (e) puts deployer obligations under Article 26 in the same band. The heavier EUR 35,000,000 or 7% tier in Article 99(3) is reserved for the prohibited practices in Article 5. The checklist: EU AI Act Article 50 compliance.
Are we the provider or the deployer of an AI sales agent?
Almost certainly the deployer, and the distinction decides which duties land on you. Article 3(4) of the EU AI Act defines a deployer as “a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity”. Licensing a platform and pointing it at your prospect list is using it under your authority. The provider is whoever develops the system and places it on the market or puts it into service under its own name or trademark. Deployer duties sit in Article 26. What that means when the agent screens people: deployer obligations for AI screening tools.
Does the EU AI Act reach an Australian company that contacts EU customers?
It can, and establishment in Australia is not the test. Article 2(1)(c) applies the Regulation to “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union”. An Australian team running an AI agent that phones or emails people in the EU is producing output used in the Union. Article 50’s transparency obligations have applied since 2 August 2026. What changed on that date, and for whom: the EU AI Act and AI sales agents.
Who is allowed to be the human overseeing a high-risk AI system?
Not simply whoever is free. Article 26(2) of the EU AI Act says deployers “shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support” — four separate requirements, and authority is the one organisations forget, because a reviewer who cannot actually stop the system is not oversight. Article 26(1) also requires deployers to use the system in accordance with the instructions for use, and Article 26(5) to monitor its operation and inform the provider where a risk arises. Designing that layer: human-in-the-loop AI sales agents.
Is an AI sales agent a high-risk system under the EU AI Act?
Usually not for selling — but the same platform can be high-risk for recruiting. Annex III lists eight high-risk areas: biometrics, critical infrastructure, education, employment, essential private and public services, law enforcement, migration, and administration of justice. Sales and marketing is not among them. Point 4 covers systems “intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates”, and point 5(b) covers evaluating creditworthiness. So an agent booking demos sits outside Annex III while the same agent screening applicants sits inside it. Classification follows use, not product: EU AI Act deployer obligations.
How long can we keep AI call recordings in Australia?
Only as long as you genuinely need them. The OAIC’s APP Guidelines, chapter 11 state that where an APP entity no longer needs personal information for any purpose for which it may be used or disclosed under the APPs, it must take reasonable steps to destroy the information or ensure it is de-identified — except where the information is part of a Commonwealth record, or an Australian law or a court or tribunal order requires it to be retained. Recordings and transcripts of sales calls are personal information, so “keep everything forever” is a decision you have to justify, not a neutral default. What to log, and for how long: AI agent observability.
Can an AI agent handle enquiries for an Australian mortgage broker?
For the enquiry layer yes, for the recommendation no. ASIC’s Regulatory Guide 273, issued 24 June 2020, explains what ASIC looks for when assessing compliance with the best interests obligations in Part 3-5A of the National Consumer Credit Protection Act 2009 — a duty the broker owes the consumer personally. An agent can answer questions around the clock, collect documents, chase a missing payslip and book the appointment. It cannot form the view that a particular credit product is in a particular person’s best interests. Where to draw the line before go-live: AI agents for Australian mortgage and finance brokers.
Can an AI agent take intake calls for an NDIS provider?
Yes, provided the conduct rules bind the agent exactly as they bind a worker. The NDIS Code of Conduct requires people who deliver NDIS supports and services to act with respect for individual rights to freedom of expression, self-determination and decision-making, to respect the privacy of people with disability, to provide supports and services in a safe and competent manner with care and skill, and to act with integrity, honesty and transparency. An automated first responder has to satisfy all four, which in practice means disclosing that it is automated and escalating anything clinical to a person. How to scope it: AI call intake for NDIS providers.
Would the FCC’s proposed AI-call disclosure have to include a tone or a badge on the handset?
Nothing of the kind is proposed; the Commission only asked. In NPRM 24-84 it “seek[s] comment on whether the proposed disclosure at the beginning of an AI-generated voice call should include a special tone, icon, badging, or other indication that is visual, auditory, or otherwise to the called party”, and in the same paragraph asks “Should we require that callers provide consumers the option to opt out of AI-generated voice calls if a consumer wishes to continue receiving non-AI robocalls from a caller?” (FCC 24-84, paragraph 18, read 20 September 2026). Seeking comment is weaker than proposing, and proposing is not yet binding. An AI calling programme should design the opt-out path anyway, because it is cheap now and retrofitted badly later. Where the rulemaking actually stands: FCC NPRM 24-84 and AI call disclosure.
How long do we have to action a TCPA revocation, and which words count as one?
Ten business days, and many more words than “stop”. The rule provides that a called party may revoke prior express consent “by using any reasonable method to clearly express a desire not to receive further calls or text messages from the caller or sender”, and that a request made using an automated, interactive voice or key press-activated opt-out mechanism on a call, or using the words “stop,” “quit,” “end,” “revoke,” “opt out,” “cancel,” or “unsubscribe” sent in reply to an incoming text message, or made through a website or telephone number designated by the caller to process opt-out requests, “constitutes a reasonable means per se to revoke consent”. Other words still bind you “if a reasonable person would understand those words to have conveyed a request to revoke consent”. All requests made in any reasonable manner “must be honored within a reasonable time not to exceed ten business days from receipt of such request”, and callers “may not designate an exclusive means to request revocation of consent” (47 CFR 64.1200(a)(10), read 20 September 2026). An AI voice agent therefore needs an in-call opt-out path, not only an SMS keyword list. What a defensible consent chain contains: purchased lead lists and the TCPA consent chain.
Do we have to run a fundamental rights impact assessment before an AI agent screens job applicants?
Usually not, because Article 27 is scoped by who the deployer is rather than by which Annex III heading the system falls under. Article 27(1) requires the assessment of “deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III”, and carves out systems “intended to be used in the area listed in point 2 of Annex III”. Recruitment and candidate evaluation sit at point 4, and points 5(b) and (c) are creditworthiness and life and health insurance risk assessment, so an ordinary private-sector employer falls outside Article 27 even though the screening system is high risk (Regulation (EU) 2024/1689, Article 27, Official Journal text read 20 September 2026). A public body, or a private entity providing public services, is inside it, and Article 26 applies to everyone either way. The deployer duties that do land on you: EU AI Act deployer obligations for AI screening.
If we load our existing CRM list into an AI sales agent, is that a new use under the Privacy Act?
Quite possibly, and the OAIC frames it as a secondary-use question rather than a tooling question. Its guidance says that where personal information is being input into an AI system, “APP 6 requires entities to only use or disclose the information for the primary purpose for which it was collected, unless they have consent or can establish the secondary use would be reasonably expected by the individual, and is related (or directly related, for sensitive information) to the primary purpose”, adding that a secondary use “may be within an individual’s reasonable expectations if it was expressly outlined in a notice at the time of collection and in your business’s privacy policy”. The same guidance treats the agent’s output as collection: “If AI systems are used to generate or infer personal information, including images, this is a collection of personal information and must comply with APP 3.” And it recommends “as a matter of best practice” that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools (OAIC, guidance on privacy and the use of commercially available AI products, published 21 October 2024, updated 17 January 2025, read 20 September 2026). What actually governs an AI sales agent here: Australia has no AI Act.
Does registering our numbers with the Free Caller Registry remove a Scam Likely label?
No, and its own terms say so three times. A submission sends your numbers to the three call-protection providers behind the labels, First Orion, Hiya and TNS, but the terms you accept state that “The registration of phone numbers does not guarantee redress based on analysis that each call protection provider does independently”, that the registry “is not to be used as a replacement for caller reputation monitoring services”, and that “multiple submissions of the same telephone number provide no additional value or redress functionality”. Two limits catch AI calling programmes in particular: the registry “is for businesses that make calls on their own behalf”, and you must certify that you are “not a service provider, BPO, or third party registering numbers on another business’s behalf”, so numbers rented from a platform are not yours to register. The same terms note that neither the providers nor their carrier partners use the data to deliver Caller ID Name (Free Caller Registry, terms read 20 September 2026). The redress route that does work, and who owns each label: Scam Likely remediation.
Is a working unsubscribe link a requirement or a recommendation for Outlook high-volume senders?
A recommendation, unlike Gmail, which is not the same as optional. Microsoft splits its announcement in two: the “What’s Changing?” section makes SPF, DKIM and DMARC mandatory for domains sending more than 5,000 emails per day, while “Functional Unsubscribe Links” sits under “Additional Email Hygiene Recommendations” alongside compliant primary sender addresses, list hygiene and bounce management, and transparent mailing practices. The same post then reserves the right to act on either: “Outlook reserves the right to take negative action, including filtering or blocking—against non‐compliant senders, especially for critical breaches of authentication or hygiene” (Microsoft Tech Community, Outlook’s new requirements for high-volume senders, read 20 September 2026). Authentication is what gets a message rejected outright; hygiene is what gets a sender filtered. Google’s one-click unsubscribe requirement is separate and is mandatory above roughly 5,000 messages a day. Both rule sets side by side: the 2026 Gmail and Outlook bulk-sender rules.
Is AI cold calling legal in the UK?
Yes, but not automatically on the terms of a human call. Under PECR, a live marketing call under regulation 21 needs no consent for most subjects if the number is screened against the TPS and CTPS and has not objected. An automated call carrying recorded matter needs specific prior consent under PECR regulation 19, and the ICO’s telephone marketing guidance does not say which side AI speech falls on. The defensive course treats AI marketing calls as regulation 19 calls: the Live-Speech Test for UK AI calls.
Am I a carriage service provider if I resell AI voice agents in Australia?
Probably not, if your client holds the numbers in their own telco account and nobody pays you for arranging the phone service. Under section 87 of the Telecommunications Act 1997, you become one by supplying a listed carriage service to the public yourself, or by arranging it for reward as an intermediary when all four limbs of section 87(5) are met. The ACMA says CSPs do not need a licence but must still follow the rules. The reseller threshold table: carriage service provider rules for AI voice resellers.
What should I do in the first 24 hours after Twilio suspends my account?
Read the status badge beside your account name in the Twilio Console. Active means something narrower stopped, such as one A2P 10DLC campaign under error 30990. Suspended with a negative balance: pay, and Twilio says reactivation typically takes 5 to 10 minutes. Otherwise Twilio’s Engage: Contact Twilio Support page says to contact Support within 24 hours to start review and reactivation. Your numbers keep billing meanwhile. The triage plan: the next 24 hours after a Twilio suspension.
Is ringless voicemail legal if an AI agent leaves the message?
To a US mobile, only with the recipient’s consent, outside emergencies and narrow exemptions. In FCC 22-85, released 21 November 2022, the FCC found that ringless voicemail to wireless phones requires consumer consent because it is a call made using an artificial or prerecorded voice. FCC 24-17 confirms that those restrictions encompass current AI technologies that resemble human voices. For telemarketing, 47 CFR 64.1200(a)(2) requires prior express written consent; prior express consent suffices for a tax-exempt nonprofit or a HIPAA health-care message. More: ringless voicemail rules for AI agents.
Do Ofcom’s silent and abandoned call rules apply to AI voice agents?
Yes. Both limbs of misuse in section 128(5) of the Communications Act 2003 turn on effect: your use of the network, or conduct you engage in through it, causing another person unnecessarily to suffer annoyance, inconvenience or anxiety. Neither names a technology. Ofcom’s 2016 persistent misuse statement calls the view that a 3% abandoned call rate was a safe harbour incorrect. Penalties reach £2,000,000 under section 130. The detail: Ofcom silent and abandoned call rules for AI agents.
What happens when OpenAI deprecates the realtime model my voice agent runs on?
Nothing breaks on the day of the notice. OpenAI’s deprecations page says that on 20 July 2026 it notified developers using legacy audio, realtime and transcription models of their removal from the API on 20 January 2027, and names gpt-realtime-2.1 as the replacement for gpt-realtime. Generally available models get at least 6 months’ notice, and dedicated capacity after shutdown is possible only in some cases, through sales. Budget for re-tuning the prompt: a migration plan for a deprecated voice model.
Which US states require all-party consent to record a call made by an AI agent?
On statute text read on 28 September 2026, nine: California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania and Washington, several only where the recording is secret or the call private. Five more are split or contested. The federal baseline in 18 U.S.C. 2511(2)(d) is one-party consent. California adds a second test: Penal Code 631 reaches anyone who, without all parties’ consent, learns a call’s contents in transit, a question for any AI vendor hearing the call live. The map: two-party consent states for AI call recording.
Is AI cold calling legal in Canada?
Yes, on the CRTC’s terms, and for AI voice the key term is consent. The CRTC’s Unsolicited Telecommunications Rules define an automatic dialing-announcing device as equipment that conveys a pre-recorded or synthesised voice message, and Part IV bars telemarketing calls made that way without express consent. Whether a conversational AI agent counts is undecided. Under section 72.01 of the Telecommunications Act, a corporation faces a penalty of up to $15,000 per violation. The detail: AI cold calling rules in Canada.
How many emails a day can an AI email agent send from Gmail or Outlook?
A paid Google Workspace user can send 2,000 messages a day, 500 on a trial, over a rolling 24 hours, per Google’s Gmail sending limits. An Exchange Online mailbox can send to 10,000 recipients a day under Microsoft’s Exchange Online limits, but Microsoft’s tenant outbound limit announcement adds a daily cap on external recipients shared by every mailbox in the tenant, 10,000 for a single licence. Treat these as ceilings, not targets. The mailbox maths: Gmail and Outlook sending limits for AI email agents.
What does Twilio error 30007 mean for an AI SMS agent?
Twilio’s error 30007 page says the message was filtered (blocked) by Twilio or by the carrier: by Twilio for breaching its Messaging Policy or Acceptable Use Policy, with spam, phishing and fraud as examples, or by a wireless carrier under its own rules or regulations. With an AI agent, first check whether its messages have drifted from your registered A2P 10DLC samples: public link shorteners, emoji, no brand name, or opt-out wording without STOP. The diagnosis: why AI SMS messages are not delivered.
What should we do in the first 24 hours when our emails suddenly go to spam?
Hold cold sends on the affected domain only, read the bounce codes, and check the headers of one message. One seed message in spam is not yet an incident; Gmail 4.7.2x, 4.7.3x, 5.7.2x or 5.7.30 codes, Outlook 550 5.7.515, a spam rate of 0.3% or more, or invoices in spam too, are. Google’s sender guidelines FAQ says bulk senders become eligible for mitigation again when their spam rate stays below 0.3% for 7 consecutive days. The hour-by-hour triage: our emails are suddenly going to spam.
How long does implied consent last under Canada’s anti-spam law?
Under section 10(10) of Canada’s Anti-Spam Legislation, consent implied by an existing business relationship lasts two years from a purchase or lease, for example, and six months from an inquiry or application. A published business address counts only if its owner conspicuously published it, or had it conspicuously published, without a statement refusing unsolicited messages, and the message is relevant to their business role or duties. Unsubscribes must take effect without delay and within 10 business days. The per-send test: CASL implied consent for AI email and SMS agents.
Is AI cold calling legal in Germany?
It is not banned, but section 7(2) of the German Act against Unfair Competition (UWG) requires prior express consent for sales calls to consumers, at least presumed consent for calls to businesses, and prior express consent from everyone for calls by an automatic calling machine. As at 30 September 2026 we found no German court or regulator text saying whether an AI voice agent is such a machine, so plan on express consent. The Bundesnetzagentur enforces the consumer rules. The full rules: is AI cold calling legal in Germany.
Choosing a vendor
How do we run a fair head-to-head trial of AI voice agent vendors?
Same list, same offer, same calling hours, same definition of success — then compare booked and held meetings, not call minutes. Split the list randomly rather than handing each vendor a different segment, run both through at least two full follow-up cycles, and log escalations, hang-ups and compliance stops alongside the wins. Decide the metric before the pilot starts: measurement is a distinct function in NIST’s AI Risk Management Framework, which is organised into Govern, Map, Measure and Manage and is explicitly intended for voluntary use. Pricing models differ enough to distort a naive comparison, so normalise on cost per held meeting. A vendor demo tests sales engineering, not your data. Criteria first: best AI sales agent platforms in 2026.
What does a vendor actually mean when it says it has proprietary AI?
Usually the layer around the model rather than the model itself. Ask which foundation model answers the call and you will often find a third-party one: Retell AI’s API reference documents a model parameter whose selectable values are GPT, Claude and Gemini variants, defaulting to gpt-4.1, and Vapi’s data-flow documentation lists OpenAI, Anthropic, Azure OpenAI, Google Gemini and Groq among the language-model providers it routes to. That is not dishonest — orchestration, routing, telephony handling and optimisation logic are real engineering — but it is a different claim from owning the weights. Make the vendor name which part is theirs, then evaluate that part.
Will our call data be used to train the vendor’s models?
Ask about the whole chain, not just the vendor. Most platforms sit on foundation-model APIs whose defaults are already restrictive: OpenAI’s data-controls documentation states that data sent to the OpenAI API is not used to train or improve OpenAI models unless you explicitly opt in, and Anthropic’s privacy centre states that by default it will not use inputs or outputs from its commercial products to train its models. The open question is the layer in between — your vendor’s own recordings, transcripts and evaluation sets. Get retention periods, deletion rights and any training opt-out written into the contract rather than confirmed in a sales email.
Is the vendor’s learning scoped to our account or shared across customers?
It matters more than it sounds. If a platform improves by training on pooled customer conversations, your objection handling and prospect data become part of a shared asset — and models can memorise. Carlini and colleagues, in Extracting Training Data from Large Language Models, extracted hundreds of verbatim text sequences from GPT-2, which makes cross-account training a governance question rather than a theoretical one. Ask three things: is optimisation per-tenant, does any of our data cross the account boundary, and can we opt out. On Zian, PrecisionPitch AI™ split-tests against your own success outcomes, and private model deployment is available where the boundary has to be physical.
Where do our call recordings physically live?
Two separate answers: where the recording is stored, and where the audio was processed on the way. Vapi documents that recordings, transcripts and call logs sit on its infrastructure by default, with an option to upload them to your own S3, Google Cloud Storage, Cloudflare R2, Supabase or Azure bucket. Telephony adds a second region: Twilio lets you select a Region — US, Ireland or Australia — but its own documentation warns that during the initial rollout it does not guarantee all data will remain within your selected Region. For Australian entities, sending it offshore engages APP 8, and under section 16C of the Privacy Act you stay accountable for the overseas recipient.
Is fine-tuning, prompt engineering or RAG the right way to make an agent sound like us?
Start with the cheapest thing that works. OpenAI’s model-optimisation guide says the prompt engineering process may be all you need for a use case, and positions fine-tuning for consistent formatting, handling novel inputs, and training a smaller, cheaper, faster model to excel at a particular task. Retrieval is the third route: Lewis and colleagues introduced retrieval-augmented generation in 2020 as combining pre-trained parametric and non-parametric memory for language generation — in sales terms, looking facts up at call time instead of baking them into weights. Because product details and availability change weekly, retrieval usually beats fine-tuning for accuracy. Zian’s agents query the web and your knowledge base mid-conversation: features and integrations.
What should we ask an AI calling vendor in a regulated industry?
Regulated buyers inherit their vendor’s failures, so borrow the regulator’s question list. APRA’s Prudential Standard CPS 230, in force from 1 July 2026 for Australian banking, insurance and superannuation entities, requires them to identify material service providers and keep a register of them, run due diligence before entering a material arrangement, and hold a legally binding agreement covering service levels, data ownership, audit access and termination, with APRA able to access documentation. Those map cleanly onto AI voice: who are the sub-processors, where is our audit right, what happens on exit, and can we get the data back. Long form: the AI voice vendor security questionnaire.
Do vendor-published comparison pages tell us anything useful?
They tell you what that vendor believes it wins on. The axes are chosen by the party being compared, the rival’s feature set is usually a snapshot taken months ago, and pricing tables go stale fastest. That does not make them worthless — read them for the criteria, then verify every row against the competitor’s own documentation. Comparative claims are not a free-for-all either: the ACCC states that any information or claim a business provides about its products or services must be accurate, truthful and based on reasonable grounds, and that it makes no difference whether a business intends to mislead. That applies to our pages too. Treat any vendor comparison as a hypothesis and test it on your own list.
What documentation does Texas TRAIGA expect, and where does NIST AI RMF fit?
Texas HB 149, the Texas Responsible Artificial Intelligence Governance Act, was signed on 22 June 2025 and took effect on 1 January 2026. The part buyers care about is section 552.105(e), which makes a defence available where the defendant substantially complies with the most recent version of NIST’s Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, or another nationally or internationally recognised AI risk management framework, together with an internal review process. That turns a voluntary framework into evidence worth keeping — so keep the artefacts, not just the intention. Documentation checklist: TRAIGA and the NIST AI RMF.
What do government buyers ask about AI agents in procurement?
More than security. Australian non-corporate Commonwealth entities operate under the Digital Transformation Agency’s Policy for the responsible use of AI in government, version 2.0, effective 15 December 2025, with mandatory requirements covering accountable officials, transparency statements, a strategic approach to AI adoption, use-case accountability, internal use-case registers, staff training and use-case impact assessment. The Standard for AI transparency statements then requires agencies to publish, on a public-facing site, why they use AI, a classification of where the public may interact with or be significantly impacted by AI without human review, and how effectiveness is monitored. A vendor who cannot supply that detail leaves the buyer with the gap. Our question list: government AI agent procurement.
What happens to our AI agent when the model behind it is retired?
It stops working on a date the model provider picked, so ask your vendor which model answers the call and what notice it passes on. The providers publish their own clocks. Anthropic’s model deprecations page says it notifies customers with active deployments, “providing at least 60 days’ notice before model retirement for publicly released models”, that “Requests to models past the retirement date will fail”, and — the detail buyers miss — that partner-operated platforms such as Amazon Bedrock and Google Cloud “set their own retirement schedules, so a model’s lifecycle status and dates can differ”. Microsoft’s Foundry model lifecycle documentation gives generally available models a retirement date “set programmatically at launch to 18 months out”, a GA retirement notice “At least 60 days before retirement” and a preview notice at 30 days — while reserving the right to “invoke an emergency retirement with shortened notice” for compliance or security issues. OpenAI’s deprecations page publishes a tiered clock instead: “At least 6 months” for generally available models, “At least 3 months” for specialised variants such as chat and Codex builds, and much less for preview models — with the caveat that if “safety or compliance concerns require us to retire a model sooner, we will provide as much notice as reasonably possible”. So the notice you get depends on which provider and which tier your vendor is standing on: ask, in writing, for the model name. How to de-risk it: model deprecation risk for AI agents.
Does a vendor’s SOC 2 cover the AI models it calls?
No. A SOC 2 reports on the controls of the organisation that was audited, not on everyone in its supply chain. The AWS shared responsibility model draws the line plainly, calling the split “Security “of” the Cloud versus Security “in” the Cloud”, listing “Inherited Controls” as “Controls which a customer fully inherits from AWS”, and telling customers to “Review third-party audit attestation documents to determine inherited controls and what required controls may be remaining for you to implement in your environment.” Vendors that handle this honestly keep the two apart: Twilio’s sub-processor page says it “imposes obligations on its sub-processors to implement appropriate technical and organizational measures ensuring that the sub-processing of personal data is protected to the standards required by applicable data protection laws”, then points to each sub-processor’s own security documentation by external link rather than folding them into its own attestation. Ask for the vendor’s report, the model host’s attestation, and the boundary between them. And to be unambiguous about our own position: Zian has published no security certification, and nothing on this page should be read as one. The wider checklist: auditing an AI vendor’s technical claims.
How can I check whether a vendor actually built the model it runs on?
Read the sub-processor list before the marketing page — it is a contractual disclosure and it names names. Twilio’s published list carries an “Anthropic” row scoped to “All AI Products” with the purpose “Vendor for AI functionality in product”, plus a separate “Amazon Bedrock” row described as “Claude by Anthropic in Amazon Bedrock” — that is a model supply chain, stated by the vendor rather than inferred by you. Stripe’s sub-processor list works the same way, defining sub-processors as “service providers who have or potentially will have access to or process personal data that Stripe processes for, and on behalf of, Stripe’s Business Users”, and giving business users 30 days to object in writing to a newly added one. Cross-check the list against the trust centre and the data-flow docs. If a vendor publishes no list at all, or will not name the model host without an NDA, record that as “not published” — an absence you can quote is still a finding. More tests: the AI vendor technical-claims checklist.
Why is my AI voice agent bill higher than minutes times the rate?
Because minutes times rate is not the formula vendors bill on. Retell publishes a prompt-token multiplier that bills a 60-second call as 72 seconds when the call uses 4,800 tokens, and a 10-second minimum charge on calls with dynamic opening messages; its concurrency burst adds US$0.10 per minute across the entire call, not just the overage. Carrier legs round up separately. Worked reconciliation: why the bill beats minutes times rate.
Do I get charged for AI calls nobody answers?
Mostly no, but the exceptions are where outbound campaigns leak money. Twilio’s Call resource documentation says a completed call can mean a person, an IVR menu or a voicemail, and that completed calls are charged against your project balance regardless of outcome — so voicemail pickups bill. Retell adds a 10-second minimum on calls with dynamic opening messages. Measure cost per conversation, not per minute: what unanswered AI calls cost.
Can a vendor be certified against the NIST AI Risk Management Framework?
No. NIST describes the AI RMF as “intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems”, and neither the framework page nor the AI RMF entry in NIST’s Trustworthy and Responsible AI Resource Center offers a certification, accreditation or conformity-assessment scheme for it; the only accreditation linked from the framework page is NIST’s unrelated laboratory programme, NVLAP, in the site navigation, checked 20 September 2026 (NIST, AI Risk Management Framework). So “NIST AI RMF certified” is not a status a vendor can hold; what exists is evidence of practice mapped to the framework’s four functions, plus the separate Generative AI Profile, NIST-AI-600-1, released 26 July 2024. One moving part belongs in the same question, because the same page says “The AI RMF 1.0 is being revised as part of the White House AI Action Plan”, so ask which version a vendor’s artefacts were written against. Where framework evidence does carry legal weight is Texas. The buyer-side list: the enterprise readiness checklist.
Is the WhatsApp message after an AI call still free?
Not from 1 October 2026. Meta’s pricing update says that from that date it charges for utility messages sent in response to users within an open 24-hour customer service window, unbilled since 1 July 2025, and for service messages, the free-form replies. Under Meta’s calling pricing, a call also starts or refreshes that window, so the confirmation an agent sends straight after the call becomes a billed line. Worked costs for Australia: WhatsApp calling and follow-up pricing.
How many calls does it take to know an AI sales script change actually worked?
Count outcomes, not calls. The two-proportion formula in Hae-Young Kim’s 2016 statistical note needs about 13,791 leads per arm to tell a 2% booking rate from 2.5% at 95% confidence and 80% power, and the verdict rests on roughly 276 booked meetings in the control arm. At 2% against 3% it falls to 3,819 per arm. Fix the sample size before the test starts and do not stop early: why call volume alone won’t improve an AI sales agent.
How long does a voice AI pilot take from contract to a go/no-go decision?
The pre-live build, plus as long as your call volume takes to give a readable result. Using as a placeholder the four weeks of build in one vendor’s plan, Assort Health’s inbound healthcare timeline, confirming a lift from a 2% to a 4% booking rate on a 50/50 split needs 2,274 leads, 1,137 per arm by the formula in Hae-Young Kim’s 2016 statistical note. At 200 eligible leads a day, decide around day 44; at 50 a day, about day 79. The clock: how long a voice AI pilot takes from contract to go-live.
What should I check before choosing a white label AI voice agent platform?
Seven things: a branded client login, tenant isolation, a provisioning API, client billing, per-client concurrency, phone-number ownership and exit terms. Read each on the vendor’s own current pages. Synthflow’s reselling migration guide records that in-product reselling through Stripe was removed on 15 September 2026, and Vapi’s FAQ says white-labelling runs through its API, with multi-tenancy handled by your application. Put number release terms in the client contract at signing. The checklist: white label AI voice agent platform checks.
Is the Gemini Live API or the OpenAI Realtime API better for a phone voice agent?
On the telephony seam, OpenAI. OpenAI’s telephony guide says GPT-Live supports raw G.711 μ-law at 8 kHz and can take calls through a SIP trunk, and its Realtime conversations guide shows audio/pcmu output and caps a session at 60 minutes. Google’s Live API capabilities guide says Gemini audio is raw 16-bit PCM and output always uses 24kHz, so you run the transcoding bridge, and a Gemini Live connection lasts around 10 minutes. Costs and trade-offs: Gemini Live vs OpenAI Realtime for phone agents.
Should I choose LiveKit Agents or Pipecat for a voice agent?
Choose on transport, not integration count: speech-path integrations are near parity, and the two are not mutually exclusive, because Pipecat’s README lists LiveKit (WebRTC) among its transports. Both licences are permissive, BSD 2-Clause for Pipecat and Apache 2.0 for LiveKit Agents, but LiveKit’s turn-detection models ship under a separate LiveKit Model License that bars using them standalone or with any other framework. Side by side: LiveKit Agents vs Pipecat.
Is Twilio or Telnyx cheaper for an AI voice agent?
On US list rates read on 28 September 2026, Telnyx, for our worked scenario: 100,000 minutes a month, 60% outbound, WebSocket media streaming and 20 local numbers came to US$998 on Telnyx and US$1,643 on Twilio. Twilio’s US voice pricing lists local outbound calls at $0.0140 a minute; Telnyx’s Voice API pricing charges $0.002 a minute on top of the SIP trunk, whose outbound rate is a starting figure. Check your own destinations. The full bill: Twilio vs Telnyx for AI voice agents.
Should I choose Ada or Lorikeet for AI customer service?
Choose Ada if you need published language breadth or a PCI DSS attestation: Ada’s documentation lists 60 languages on messaging and email and its voice page lists 42, with quote-only pricing. Choose Lorikeet if you want published per-resolution rates: Lorikeet’s pricing page lists US$0.90 to US$0.99 per chat, email or SMS resolution on a US$2,100 or US$5,100 monthly plan paid annually, and it publishes ISO 27001. Both as at 30 September 2026. The full comparison: Ada vs Lorikeet for AI customer service.
Which voice AI platforms can cold call Australians from a local caller ID?
Of 10 platforms whose documentation we read on 30 September 2026, six supply an Australian number themselves: Synthflow (sold for testing), Voxworks, AiDial, Twilio, Telnyx and Vonage. Vapi, Retell AI, Bland and ElevenLabs Agents need a +61 number you bring from a carrier. Either way, the calls must keep to the calling hours and caller ID rules in the Telecommunications (Telemarketing and Research Calls) Industry Standard 2017. The vendor table and the 4R test: voice AI for Australian cold calls with a local caller ID.
Which services let an AI phone agent take PCI compliant card payments in Australia?
Five named services can take the card so the AI never receives the digits: Twilio Pay (keypad only), PCI Pal, Sycurio (formerly Semafone), Westpac PayWay Phone and a Stripe payment link sent by SMS. Pick by the route your AI stack supports: redirect to an IVR, transfer, in-line keypad masking or a link. The PCI Security Standards Council telephone payments guidance covers both the masking and the IVR routes. The comparison: PCI voice payment options for AI phone agents.
Using Zian
What results do teams see on Zian?
The platform counters, straight from live usage: 50,769+ qualified sales appointments set, a 926% increase in follow-ups, 28x more contact attempts, a 2,736% increase in lead contact rates and 3,102% more sales appointments. Results vary by list quality, offer and market — which is why the platform split-tests continuously: PrecisionPitch AI™ tests scripts and approaches against real outcomes, not opens. See AI sales script split-testing.
How do we choose between the AI sales platforms out there?
Evaluate on four axes: autonomy (does it decide, or just fire sequences?), channel depth (real phone calls or just email?), outcome optimisation (does it learn from booked meetings or from opens?), and deployment control. Our honest read of the field, criteria first: best AI sales agent platforms in 2026.
Which US states require an AI voice agent to tell people it is AI?
There is no single US rule — it is a state patchwork, and much of what circulates online is wrong. Utah is currently the strictest live duty: Utah Code §13-77-103 requires a supplier using generative AI to disclose that fact when a person clearly and unambiguously asks, and it covers audio explicitly. Maine (10 M.R.S. §1500-DD) reaches aural communications too, while California’s BOT Act applies to online interactions rather than phone calls. Texas SB 140 is widely and wrongly described as an AI-disclosure law — it is a telemarketing statute that says nothing about AI. Our verified state-by-state map: the US state AI call-disclosure patchwork.
Does a lead vendor’s “TCPA-compliant” badge protect me if I call the list with an AI agent?
No. Under the TCPA the burden of proving prior express consent sits with the caller, not the list seller — the FCC stated this directly at paragraph 33 of its 2012 TCPA Order (FCC 12-21). A vendor’s badge is a commercial assurance, not a legal defence, and it does not put the capture record in your hands. Because the FCC has ruled that AI-generated voices are “artificial” under the TCPA, an AI voice agent needs consent for every call regardless of content. What a defensible consent chain has to contain: purchased lead lists and the TCPA consent chain.
What happens when a consumer’s AI assistant phones my business?
It is already happening. Google operates a service that places automated calls to businesses on a customer’s behalf to ask about pricing, availability and bookings, and Google publishes the opener those calls use — they identify themselves as an automated service and state that the call is recorded (Google Business Profile Help), along with routes for a business to opt out. The practical consequence is that your phone line now has machine callers as well as human ones, and deep IVR menus and hold queues serve them badly. Our readiness guide: preparing your phone lines for inbound AI callers.
Can we use a published AI-visibility benchmark rate as our target?
Not safely. Published AEO/GEO benchmarks measure a non-deterministic system, and almost none disclose the things that would make their number comparable to yours: the prompt list, samples per prompt, the exact date window, the named engines and modes, the locale, and what they actually counted as a “citation”. Conductor’s 2026 AEO/GEO Benchmarks Report, for example, states plainly that its figures are US-only averages, and it does not publish its prompt set. Treat published averages as direction and track your own trend instead: how to read a 2026 AEO benchmark report.
What is the difference between an AI sales agent platform and an AI voice agent platform?
Scope. A voice agent platform sells you the call layer: speech, turn-taking, telephony, transfer and barge-in handling — you still supply the pipeline logic and the follow-up. A sales agent platform owns the outcome across channels: who to contact, on which channel, when to try again, and booking the meeting, with voice as one component. Compare on that axis before comparing features: best AI sales agent platforms 2026 and best AI voice agents for outbound calls 2026.
How do we get access to Zian?
Zian is currently in partnership-application beta. Apply for partnership and you’ll be onboarded as capacity opens — early access prioritises teams with an existing lead flow or database to work.
Does Zian have a free trial or self-serve signup?
No self-serve signup, and no time-limited free trial. Zian is in partnership-application beta, so every tier — including the free-forever Intel + Widgets tier — is gated behind the partner application rather than a credit-card form, and there is no published price list to compare line by line. That is a real trade-off to weigh when you are evaluating vendors: you get a scoped pilot with engineering support instead of a sandbox you can sign into on a Sunday. Enterprise arrangements cover custom private models and local data residency. If the fit looks right, apply for partnership and we will scope a pilot against your list.
Does Australia have an AI Act?
No. A title search of the Federal Register of Legislation for “Artificial Intelligence” on 2 September 2026 returns two instruments, both grant-programme funding rules, and no regulatory statute. An outbound AI sales agent is instead governed by the Do Not Call Register Act 2006, the Spam Act 2003 for SMS and email, the Privacy Act 1988 and the Australian Consumer Law. The ten mandatory guardrails proposed in September 2024 are not enacted, and the National AI Plan does not use the word “guardrail” at all. Full map in Australia has no AI Act.
Does any Australian law require an AI caller to disclose that it is AI?
No. The Telemarketing and Research Calls Industry Standard 2017 contains no occurrence of “artificial”, “automated” or “AI”. Its section 9(2)(a) actually removes the duty to give a caller’s given name where a recorded or synthetic voice is used. But section 12, headed “Calls that involve a recorded or synthetic voice”, imposes a duty of its own: you must provide a mechanism during the call for the recipient to request your contact and complaint details. So a synthetic-voice agent is excused one identification duty and handed another. Source: F2017L00323.
Can I record a phone call anywhere in Australia if I am a party to it?
No — the “one-party consent” rule of thumb breaks in Western Australia. Under section 5(1)(b) of the Surveillance Devices Act 1998 (WA), a party may not record a private conversation unless every principal party consents (s 5(3)(c)), or one consents and the recording is reasonably necessary to protect that party’s lawful interests (s 5(3)(d)); the penalty is A$5,000 or 12 months for an individual and A$50,000 for a body corporate. Victoria (Surveillance Devices Act 1999, s 6(1)) and Queensland (Invasion of Privacy Act 1971, s 43) do permit a party to record. Victoria s 11 and Queensland s 45 separately restrict communicating or publishing a recording: lawfully recorded does not mean freely shareable. NSW and SA are now verified. Section 7(1)(b) of the Surveillance Devices Act 2007 (NSW) bars a party from recording a private conversation unless s 7(3) applies — all principal parties consent, or one consents and the recording is reasonably necessary for the protection of that principal party’s lawful interests, or it is not made for the purpose of communicating or publishing the conversation to persons who are not parties — with a maximum penalty of 500 penalty units for a corporation, or 100 penalty units or 5 years imprisonment for anyone else. Section 4(1)(b) of the Surveillance Devices Act 2016 (SA) bars the same conduct, but with only the consent and lawful-interests limbs and no not-for-publication limb, at A$75,000 for a body corporate or A$15,000 or 3 years for a natural person. Both registers still refuse automated retrieval and both returned HTTP 403 again on 14 September 2026, so both Acts were read in the registers’ own published documents through the Internet Archive id_ raw-capture route on 14 September 2026: the NSW whole-Act page as captured on 12 March 2026, which is the most recent capture the archive holds, and the SA authorised PDF marked Version 21.9.2023, taken from the register’s own current path as captured on 23 March 2026. The nine-row statutory table, jurisdiction by jurisdiction: call recording laws in Australia for AI agents. Worked through for an industry that records constantly: AI call handling for Australian real estate agencies.
What are the TCPA statutory damages for an AI call in 2026?
Unchanged: US$500 per violation under 47 U.S.C. 227(b)(3)(B), which a court may treble to US$1,500 for a wilful or knowing violation. The FCC’s February 2024 Declaratory Ruling classified AI-generated voices as “artificial” under the TCPA, so AI calls to mobiles need prior express consent. Checked 4 September 2026. Detail in TCPA 2026 AI calling settlements.
Is in-call AI disclosure federally required in the United States?
Not as at 2 September 2026. FCC 24-84 proposes to define an “AI-generated call” and require disclosure, but it remains a Notice of Proposed Rulemaking in CG Docket 23-362 — a Federal Register check returns one proposed rule dated 10 September 2024 and no final rule. Several secondary sources assert the requirement is already in force; it is not. Individual US states do impose disclosure duties, covered in US state AI call disclosure laws.
Does a TCPA settlement mean the company broke the law?
No. Both 2026 funds we traced to primary court records — Gen Digital’s US$9,950,000, finally approved 14 July 2026, and Hy Cite Enterprises’ US$4,750,000, preliminarily approved 24 March 2026 with a fairness hearing set for 6 October 2026 — contain express denials of liability, and the Gen Digital order records that the court “does not make any determination as to the merits”. Notably, neither settlement order mentions AI at all: both are wrong-number classes turning on the statutory phrase “artificial or prerecorded voice”.
How accurate is speech recognition on Australian accents?
No major speech-to-text vendor publishes an Australian-English word error rate — that absence is the finding. The widely repeated “30-50% WER for accented speech versus 2-8% for native speakers” traces to an AAAI-24 undergraduate paper measuring Indic-accented English, whose native-side figure comes from wav2vec 2.0 results on LibriSpeech audiobooks. It compares lecture audio to audiobooks across different models and corpora. A benchmark holding corpus and model set constant (WildASR, March 2026) reports 2.2-6.8% on accented English, with Australian speakers 12.1% of that set, against a 4.7% human error rate. See Australian accents and word error rate.
Why does headline word error rate understate a failed booking?
Because errors are not evenly distributed across words. AssemblyAI’s own analysis reports missed-entity rates far above its headline WER — roughly 13.1% for names and 19.6% for phone numbers on real-world customer audio. On an Australian booking call the payload is proper nouns: suburb names, street names and spelled-out surnames. A 5% WER concentrated in those fails more appointments than a 12% WER spread across filler words. Always ask for the test conditions: a WER number without its corpus and audio conditions is not a measurement.
How much latency does a mid-call knowledge lookup add?
ElevenLabs documents around 250 ms of added latency for the RAG step in its agents platform, with no methodology attached. Retell AI exposes a knowledge_base latency percentile, but only on calls that actually use its knowledge base. Pinecone’s own latency guidance publishes no millisecond figure at all, and Cohere’s Rerank overview does not use the word latency. Zian publishes no latency figure. Most “live” lookups could have been pre-fetched before the call. See retrieval latency mid-call.
How many concurrent lines does 10,000 calls a day need?
Concurrency, not daily volume, is the binding constraint. Ten thousand dial attempts at an assumed 67.5 seconds of line time each, across an 11-hour window, is 675,000 seconds of line time divided by 39,600 seconds — about 17 lines on average, and roughly 34 at an assumed 2x peak. Both inputs are assumptions you should replace with your own measured figures; only the arithmetic is ours. For scale, Vapi includes 10 concurrent slots by default and Retell AI 20 on pay-as-you-go. Working through it: scaling AI calling.
What does an AI receptionist cost in Australia?
Australian services that publish a price start at A$99/month (Hey Jodie, which marks currency and notes “Prices exclude applicable taxes”) and run to “$1,299/month” for Valory Enterprise — a figure Valory’s page prints with an unmarked “$”, AUD appearing only in that page’s schema.org markup, checked 4 September 2026. What actually decides the comparison is the pricing model, not the technology: a pay-as-you-go human service (OfficeHQ, “$33* per month + $3.89* per call”, the asterisk resolving to “Plus GST”) stays cheaper than flat-rate AI below about 17 answered calls a month, while metered AI pushes the crossover past 50. No vendor on the pages we opened publishes a cost per booked appointment, which is the number that actually matters. Zian publishes no price during beta. Method in how to read the pricing pages and AI receptionist vs virtual receptionist.
How many times should I poll an AI engine before a change means anything?
More than once, and more than most teams do. A University of St Gallen study (arXiv, 8 April 2026) ran eight prompts across four verticals and four engines daily for two months, plus up to ten same-day repeat runs, and recommends at least seven to eight runs before treating a reading as stable. Single-poll movement is noise. Track per-prompt history and a consecutive-hold rate rather than a headline percentage, and never compare across a changed denominator. Method in building an AEO poll harness.
What is Google’s Preferred Sources button, and does it lift rankings?
An embeddable button, shipped 20 August 2026, that lets a reader add your site to their preferred sources list. Google’s Search Central guide scopes every effect to that reader: a “preferred” badge in Top Stories, AI Mode and AI Overviews “for users who have selected your site as a preferred source”. It sits under search appearance, not among the ranking systems, and Google says of its promotion methods “It’s not required to do them in order to appear as a preferred source”. Full read: Preferred Sources as an AEO lever.
How many sites have readers marked as Google preferred sources?
Google has published four counts in nine months, all of sources readers selected — not publishers who installed the button. On blog.google: “nearly 90,000 unique sources” (10 December 2025), “over 200,000 unique sites” (30 April 2026), “more than 345,000 unique sources” (27 May 2026) and “more than 600,000 unique sources” (20 August 2026). Google’s separate claim that readers are “twice as likely to click through to a site after marking it as a Preferred Source” carries no published sample, window or control group, checked 4 September 2026.
When did Google AI Mode launch in Australia?
8 October 2025. Google’s Australian blog announced it in English, describing AI Mode as “built right into Search” and running on “a custom version of our advanced Gemini models”. Because it lives on google.com it produces no distinct referrer, so it is not a traffic source you can report. For an Australian B2B vendor the exposure is absence from a synthesised comparison, not lost informational clicks: what AI Mode in Australia changed for B2B.
Can we see Google AI Mode traffic separately in GA4?
No. GA4’s channel definitions put arrivals “via non-ad links in organic-search results, including Google’s AI Overviews and AI Mode” under Organic Search, while the separate AI Assistant channel — ChatGPT, Gemini, Deepseek, Copilot, Grok — expressly “excludes Google’s AI Overviews and AI Mode”, checked 4 September 2026. Search Console pools the same two surfaces, and its generative-AI report offers only Pages, Countries, Dates and Devices. Trend the impressions line; poll prompts for presence.
Why do the 2026 studies of AI click loss disagree?
Different populations, denominators and counterfactuals. A pre-registered randomised Chrome experiment on over 1,000 users (Agarwal, ISB; Sen, CMU) found AI Overviews “reduced users’ organic clicks to third-party sites by 39.8 percent”, conditional on one appearing (ProMarket). Ahrefs’ 58%, from its 4 February 2026 update, is a position-one click-through-rate gap across 300,000 keywords — a rate comparison, not sessions lost, and not interchangeable with the field experiment’s click reduction. The ABC’s “one down by 35 per cent” is one unnamed Australian news site in Similarweb data — and the rival Ipsos Iris panel, in the same article, pointed the other way. None forecasts a B2B site: the full comparison.
What is inferred consent under the Spam Act, and who has to prove it?
Schedule 2, clause 2 of the Spam Act 2003 (Cth) defines consent as express consent, or consent “that can reasonably be inferred from” the conduct and the business and other relationships of the person concerned. Clause 4(1) closes the shortcut: consent “may not be inferred from the mere fact that the relevant electronic address has been published”. Section 16(5) puts an evidential burden on whoever relies on it, and the ACMA says “it’s up to you to prove that you have a person’s consent”. Detail: inferred consent and AI agents.
Does a Do Not Call Register registration expire?
No. Section 17(1)(b) of the Do Not Call Register Act 2006 says a registration, unless sooner removed under a subsection 18(1) determination, “remains in force indefinitely”. The three-year term many calling teams still plan around existed from 2010 and was repealed by Schedule 3 of the Telecommunications Legislation Amendment (Deregulation) Act 2015. A number that washes dirty stays dirty until the account-holder removes it; the only clock you get is the 30-day washing cycle in s 11(3).
If someone opts out mid-call, does the Spam Act’s five-day rule apply to the call?
No — the Spam Act does not reach the phone leg at all. Section 5(5) provides that a message sent “by way of a voice call made using a standard telephone service” is not an electronic message for the purposes of the Act, so section 18 never touches the call. What applies is s 13(1)(b) of the Telemarketing and Research Calls Industry Standard 2017: terminate immediately. Schedule 2 clause 6’s five business days governs SMS and email only. Full sequence: what an agent must do after a mid-call opt-out.
Does the Privacy Act cover a small dental or medical practice?
Yes, at any size. Section 6D(1) of the Privacy Act 1988 (Cth) exempts businesses turning over A$3,000,000 or less, but s 6D(4)(b) switches that exemption off for an entity that “provides a health service to another individual and holds any health information except in an employee record”. Health information is sensitive information under s 6(1), so APP 3.3 governs what an AI phone agent may collect on a booking call. A two-chair practice is inside: AI receptionist privacy rules for Australian practices.
Does “hosted in Australia” mean the AI model runs in Australia?
No. The phrase usually describes storage at rest, not inference. Google’s own documentation warns that “Endpoints don’t guarantee data residency or in-region ML processing”, and AWS cross-Region inference profiles route “within the geography” — geographies “such as US, EU, and APAC”, which is not Australia. Audit six layers separately: storage, application processing, model inference, support access, backups and telemetry, each with a region code and a dated artefact. Checklist: how to audit an Australian-hosted claim.
Where does the “62% of calls go unanswered” figure come from?
A 2016 study by a United States marketing agency. 411 Locals published it on 18 January 2016: “We monitored the phone calls of 85 businesses, operating in 58 industries, for a period of 30 days… While 37.8% of calls do get answered, another 37.8% get forwarded to voicemail and 24.3% don’t get any response.” The 62% is voicemail plus no-answer combined, so a call that reached voicemail counts as unanswered. There is no published Australian equivalent — use your own call detail records: what a 7pm enquiry actually costs.
Should we quote Spam Act or Do Not Call penalties in dollars?
No — cite penalty units. Section 4AA(8) of the Crimes Act 1914 says an indexed penalty unit “only applies to offences committed on or after the indexation day”, and the note to s 5 of the Crimes (Amount of a Penalty Unit) Instrument 2026 repeats that its A$364 figure “only applies to offences committed on or after 1 July 2026”. Spam Act and Do Not Call breaches are civil penalty provisions, not offences, and s 4AA(1) still reads A$330. Across a 10,000-unit cap those two multipliers are A$340,000 apart.
Can an AI agent run the KYC checks when a bank or fintech onboards a customer?
It can do the collecting; it cannot take the liability. Under Australia’s Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (compilation in force 1 July 2026), s 28(1) provides that a “reporting entity must not commence to provide a designated service to a customer if the reporting entity has not established on reasonable grounds each of the matters in subsection (2)” — the customer’s identity, any beneficial owners, anyone acting on their behalf, politically-exposed-person and sanctions status, and “the nature and purpose of the business relationship or occasional transaction”. Section 28(3)(d) then requires the entity to “verify, using reliable and independent data” the KYC information appropriate to that customer’s ML/TF risk. Section 37 does let an agent do the collection and verification — and its note is the sentence to put in front of a vendor: “The reporting entity (and not its agent) will be liable to civil penalties for contraventions of this Part”. So an onboarding agent can chase documents, explain requirements and route exceptions, while the reporting entity keeps the breach. Design it that way: onboarding agents and first value.
Can an AI agent coordinate a construction project’s payment paperwork?
It can chase and prepare, but the clocks are statutory and counted in business days. Building Commission NSW’s summary of the deadlines in the Building and Construction Industry Security of Payment Act 1999 (NSW) sets payment by a principal to a head contractor at “15 days after claim is made” (s 11(1A)(a)), head contractor to a non-residential subcontractor at “20 days” (s 11(1B)(a)), and a payment schedule — the response a respondent must give if it does not intend to pay the full amount — at “10 days after claim is made” (s 14(4)(ii)). The same page states that these “refer to the number of business days”, and warns that they “are only the maximum time frames provided by the Act if your contract does not specifically set out deadlines. Your contract can specify shorter deadlines, so you should always check your contract first.” A coordination agent therefore needs the contract’s own dates, a business-day calendar carrying the right state public holidays, and a hard escalation to a named human before a date lapses — not a generic weekly reminder. Other states and territories have their own Acts with different numbers; do not port one schedule across borders.
What does an AI agent platform mean when it says it runs on our own infrastructure?
Three different things, so make the vendor pick one in writing. The cloud providers’ own documentation shows how much room the phrase has: Microsoft’s Foundry deployment-type documentation states that “Data stored at rest remains in the designated Azure geography”, while inference is a separate question — Global deployment types “May be processed in any Azure region”, Data Zone types process data “only within the Microsoft-specified data zone (US, EU, or Asia Pacific (APAC))”, and Microsoft “can add regions to either data zone without prior notice”. None of that is your infrastructure; it is a region promise inside someone else’s. The same page also draws the line that matters for self-hosting: those deployment types cover the serverless API, and “Open-source and custom models that use managed compute don’t use these types” — running open-weight models on compute you control is a different path with different guarantees and different accuracy. Ask three questions: whose cloud account the compute bills to, whether the model weights sit on hardware you control, and which of storage, inference, support access and telemetry each has a named region. How we deploy: private AI deployment for sales agents; how to audit the claim: the vendor technical-claims checklist.
What makes an AI customer support agent genuinely multilingual?
Per-channel model coverage, not the headline language count. Deepgram’s own model and language table is the clearest illustration: its general model nova-3 is listed as “Multilingual (English, Spanish, French, German, Hindi, Russian, Portuguese, Japanese, Italian, and Dutch)” plus dozens of further languages, while the telephony-tuned nova-2-phonecall lists “English: en, en-US” only — the model tuned for your channel can be the monolingual one. The same page adds that “All models default to language=en unless otherwise specified via the language parameter”, so an unset parameter quietly transcribes a Vietnamese or Arabic caller as English rather than failing loudly. Ask a vendor for accuracy per language on your channel, what happens when language detection changes mid-conversation, and what the agent does when confidence drops — then test with your own recordings. How we run it: AI agents in 30+ languages.
What should we check before buying AI appointment-setting software?
The calendar layer, because that is where these deployments actually break. Google’s Calendar API quota documentation sets “Per minute per project 10,000 requests” and “Per minute per user per project 600 requests”, plus a daily threshold of “Per day per project 1,000,000 requests”, and states that if either quota is exceeded “you’re rate limited and receive a 403 usageLimits status code or a 429 usageLimits status code”, to be handled with “truncated exponential backoff”. Its Calendar MCP toolset table also prices agent tool calls unevenly — delete_event costs 10 query units where create_event, list_events and suggest_time cost 1 — so a reschedule-heavy agent burns quota roughly an order of magnitude faster than a booking-only one. The page adds that “Full billing details will be shared later in 2026 with at least 90 days’ notice before any changes take effect”. So ask: what does the agent say to a prospect when the calendar write returns a 429 mid-call, is double-booking prevented server-side or in the agent’s head, and who absorbs calendar API costs at your volume. Criteria first: best AI appointment-setting software in 2026.
Is there an Australian standard for governing AI agents, given there is no AI Act?
Yes — voluntary, and increasingly asked for in procurement. The National AI Centre published the Voluntary AI Safety Standard on 5 September 2024 (page updated 2 December 2025), built on “10 voluntary guardrails that apply to all organisations throughout the AI supply chain”. That page now carries a note that “On 21 October 2025, we published the Guidance for AI Adoption, which outlines 6 essential practices for safe and responsible AI governance. This updated and simplified guidance for industry evolves the Voluntary AI Safety Standard.” For anyone deploying sales or support agents, the operative document is the implementation guidance, whose sixth practice asks organisations to “Implement mechanisms to enable human control and intervention during the operation of the AI system” and to plan for decommissioning — including a process to inform employees, customers and upstream or downstream parties “within a reasonable timeframe of the retirement or shutdown of an AI model or system”. None of it binds you by itself; existing law does. What actually applies in Australia: AI regulation for sales agents in Australia.
Does the Privacy Act’s employee records exemption cover job applicants an AI agent screens?
No, on the exemption’s own words. Section 7B(3) of the Privacy Act 1988 exempts an act by an organisation “that is or was an employer of an individual” only where that act “is directly related to: (a) a current or former employment relationship between the employer and the individual; and (b) an employee record held by the organisation and relating to the individual”, and the Act defines an employee record as “a record of personal information relating to the employment of the employee”. A candidate you have never employed has neither a current nor a former employment relationship with you, so the exemption does not reach the screening data. Treat applicant information as ordinary personal information under the Australian Privacy Principles: a collection notice that says an AI system is involved, purpose limitation, and a retention rule for the people you do not hire. The bias-audit and notice rules that apply overseas are separate again: AI candidate screening compliance.
How do we verify a vendor’s claim that its sales agent is autonomous?
Start from a definition someone else owns, then test the dial. The National AI Centre’s Voluntary AI Safety Standard glossary adopts the OECD definition of an AI system — “A machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.” Autonomy is a level, not a badge, so test where the level sits: hand the agent a lead that does not fit the script and see whether it changes channel or simply advances to the next step; ask whether retry timing is learned from outcomes or configured by a human; ask what it does after N attempts with no reply. Then ask the opposite question, because a genuinely autonomous system needs a bigger brake — the same body’s implementation guidance asks deployers to “Implement mechanisms to enable human control and intervention during the operation of the AI system”. Our criteria-first read of the field: best AI sales agent platforms in 2026.
Should we run a production voice agent on a preview model?
Not unless you can migrate inside a fortnight. OpenAI’s deprecations documentation states that preview models, “identified by preview in the model name, may be retired with much shorter notice, such as 2 weeks”, and says so in as many words: “We don’t recommend using preview models for business-critical production workloads unless you can migrate on short notice.” The same page explains that deprecation is immediate on announcement — “When we announce that a model or endpoint is being deprecated, it immediately becomes deprecated” — and that every deprecated model gets a shut-down date after which it is no longer accessible. Preview models are where new voice and realtime capabilities land first, so the trade is real: run them behind a flag, keep a tested fallback on a generally available model, and never let a preview model be the only thing that can answer a customer’s call. The wider risk and how to price it: model deprecation risk for AI agents.
How many test runs does an AI voice agent need before go-live?
More than one, and the number is arithmetic rather than judgement. If a fault fires on about 1 call in 20, a single clean scenario run proves very little: reaching 95% confidence that you would have seen it takes 59 runs of that scenario. Layer the testing as well, because each layer is structurally blind to the faults the next one catches. LiveKit documents a behavioural test framework that runs in pytest or Vitest and asserts on messages, tool calls and arguments turn by turn, agent simulations that run whole conversations, and it points at partner services for end-to-end behaviour through the full audio pipeline (LiveKit testing and evaluation docs, read 10 September 2026). A pass in text mode says nothing about what the speech recogniser would have heard. The four-layer ladder and what a run costs at each rung: how to test an AI voice agent before go-live.
Can we point our own SIP trunk at an AI voice agent?
Yes, and it is four settings rather than a project: origination pointed at the platform SIP host, the platform signalling IP addresses allowlisted on your side, a media port range opened, and one authentication mode chosen. The media rule is the one that bites. RTP is a separate flow from signalling and needs its own firewall rule, so signalling can complete perfectly and the call still carry no audio, which is the most common shape of a first failed call. Vapi publishes its media range as UDP 40000 to 60000 in both its US and EU regions and notes that US media has no static IP addresses to allowlist (Vapi SIP networking and firewall docs, read 10 September 2026). Twilio requires a minimum of either an IP access control list or credentials on termination. Interop matrix across Retell, Vapi, LiveKit and Twilio: how to connect an AI agent to your SIP trunk.
Which layer of a voice agent should we build failover for first?
The trunk, then the transcriber, then the voice, then the model, in that order, because a perfect model fallback is worthless if the call never arrives. Two of those four fail loudly and two fail silently, so the real design question is what the caller hears while the switch is thrown. Know the published defaults before you configure anything: Twilio fails over to the next origination SIP URI after 4 seconds with no SIP response, but will not fail over on ten listed responses including 404, 486 and any 6xx (Twilio SIP trunking docs, read 10 September 2026), and the fallback adapters shipped in LiveKit Agents v1.8.0 default to a 10.0 second attempt timeout for speech to text and 5.0 seconds for the language model. The build sequence and a test for each layer: how to build failover into an AI voice agent.
How long does it take to build a voice AI agent in-house?
Far longer than the quickstart suggests, and the vendor documentation quietly says so. The LiveKit voice AI quickstart promises a simple voice assistant in less than 10 minutes, while the same documentation index states 223 pages for Build Agents, 41 for Telephony and 28 for Manage and Deploy, which is 292 entries describing the work that comes after the quickstart (LiveKit documentation index, read 10 September 2026). Deduplicated by URL those 292 entries are 261 distinct pages, because one index re-lists 26 model plugin pages under a second heading. Our estimate for a team doing it for the first time is roughly 22 engineer-days for one inbound line and roughly 83 for outbound at volume. The method, priced stage by stage: how long to build a voice AI agent in-house.
How do we wash a calling list against the Australian Do Not Call Register automatically, and what does it cost?
There are four washing channels and only two of them can be driven by a machine. The register publishes them as website upload, quick wash upload, an automated washing service over SFTP, and real time access over SOAP, all charged at the same rate and all requiring an active subscription with credit (Do Not Call Register washing process overview, read 10 September 2026). Cost runs on a credit schedule the ACMA approved on 27 September 2021: eight subscription types, from Type A at 500 wash credits for no fee up to Type H at 100,000,000 credits for A$142,271, each valid 12 months, with unused credits forfeited if a subscription lapses. For an always-on agent the 30 day wash rule stops being a pre-campaign chore and becomes a scheduler invariant. Channels, file format and the three ways an agent loses the safe harbour it thinks it has: Do Not Call Register washing for AI diallers.
What actually transfers when we move to a different AI voice platform?
More than most teams expect, and the cost sits in request count rather than in access. Agent configuration, prompts, tools, knowledge base files, phone numbers, transcripts, recordings and test cases all have a documented export route on both Vapi and Retell AI. What differs is shape. Retell documents that its v3 list-calls endpoint deliberately omits transcript, transcript_object, transcript_with_tool_calls and recording_url to keep responses lean, and directs you to call get-call per call id to fetch them (Retell API reference for list-calls, read 10 September 2026), so a 40,000 call export costs roughly one request per call there against paged list requests on Vapi. A field-for-field copy is never the job, because the objects are shaped differently on each side. Object by object portability matrix, every endpoint linked: switching AI voice platforms, what transfers.
Our tool call returns in 200 ms but the caller hears seconds of silence. Where does that time go?
Usually not in the API. A tool turn is a chain of waits, and the two steps that most often dominate emit no log line anywhere: the model serialising the tool call arguments, and the framework buffering the reply before a speech engine can start streaming it. In livekit/agents issue 5826, open since 24 May 2026, a builder measured roughly 590 to 1000 ms of dead air per tool turn inside the streaming layer, on models that speak before they call a tool, measured end to end against live streaming speech synthesis. That is why blaming the CRM is such a durable misdiagnosis: the silence a caller hears and the duration your API reports are different measurements, and on tool turns they routinely disagree by a factor of five or more. The three-clock test that names the layer: why your AI voice agent goes silent on tool calls.
Why do keypresses not register with our AI voice agent?
Because a digit can travel three ways and both ends have to agree on which. It can go in band as audio tones mixed into the call, out of band as RFC 4733 telephone-event packets carried beside the audio, or as SIP INFO messages. RFC 4733, which obsoleted RFC 2833 in December 2006, gives the reason the out of band format exists: low-rate voice codecs cannot be guaranteed to reproduce tone signals accurately enough for automatic recognition. Support is not universal. Twilio states that out of band RFC 2833 is supported, that out of band SIP INFO is not currently supported, and that in band tones inside a G.711 stream are passed through untouched (Twilio support article on DTMF types, updated 23 May 2025, read 10 September 2026). Check the INVITE SDP for a telephone-event rtpmap line before you change a single prompt. Packet-level tests per platform: AI voice agent DTMF not working.
The call happened but nothing reached our CRM. How do we find the fault?
Prove which of three ledgers is missing the call before you touch any code: the carrier record, the platform call record, and your own web server or load balancer access log. Three of the four faults that produce this one symptom are invisible in your application log. Delivery contracts differ, so know the one you are on. Retell AI gives your endpoint a 10 second timeout and retries up to 3 times if no 2xx status arrives, which means your consumer has to be idempotent (Retell webhook overview, read 10 September 2026), while Vapi fixes the assistant-request webhook at 7.5 seconds end to end and states that the limit is not configurable (Vapi server events docs, read 10 September 2026). Return 2xx as soon as the payload is safely queued and do the heavy work afterwards. The full triage order: AI voice agent webhook not firing.
Our AI agent told a customer something untrue. What do we do in the first hour?
Freeze before you fix. The most expensive mistake is editing the prompt, because on most platforms the configuration that spoke to your customer is the configuration you are about to overwrite. Pause the agent or route that intent to a human, write down the call id and the exact start time with its UTC offset, then export the audio, the transcript, the tool call log and the prompt revision that was live to storage you control. Retention clocks are shorter than people assume: Vapi documents pay-as-you-go retention of up to 30 days for chats and 14 days for calls, with configurable policies only on enterprise plans (Vapi call recording docs, read 10 September 2026). Then call your lawyer early, because whether the promise binds you is a contract question rather than an engineering one. The six-step first hour and the evidence hold: our AI agent told a customer something untrue.
Whose local time do Australian telemarketing calling hours use?
The person answering, not your server and not the number prefix. The permitted windows are national: 9:00am to 8:00pm on weekdays and 9:00am to 5:00pm on Saturdays for telemarketing calls, none on Sundays or national public holidays, and the register adds that they apply unless the consumer has consented to being called at that time (Do Not Call Register industry standards page, read 10 September 2026). The trap is that Australia spans three standard offsets and only some states observe daylight saving. During daylight saving the only weekday window that is inside the rules everywhere on the mainland at once is 01:00 to 09:00 UTC, which is 9am to 5pm in Perth: eight hours, not eleven. Triage for a call that landed late, and the scheduler fix: our AI agent called someone at 9pm in Perth.
Does a speech-to-speech model cost more per minute than a speech, language and synthesis pipeline?
Yes, and the gap is architectural rather than a rate card difference. There is also no single per-minute number to look up. OpenAI states that Realtime API costs accrue when a Response is created and are charged on input and output token counts, and that the entire conversation is sent to the model for each Response, so turns later in a session cost more than earlier ones (OpenAI voice agent latency and cost guide, read 12 September 2026). That design fact is why prompt caching decides the bill: the published audio rates are 32.00 per 1M input tokens against 0.40 per 1M for cached input, a factor of 80, and the pricing page prints no currency code beside them (read 10 September 2026). On our worked ten minute example that is a 7.4 times spread on identical audio, and a cascade of separate recognition, language and synthesis services comes in lower again. Full arithmetic: voice AI cost per minute, realtime versus pipeline.
What does A2P 10DLC cost for a two-way AI SMS agent?
More than a blast calculator suggests, because in a real exchange half the segments travel towards you and inbound segments can be billed too: Twilio notes that T-Mobile, including Sprint, applies fees to inbound SMS and MMS as well as outbound. The registration layer is separate and lands before a single message moves. On the Twilio fee schedule a Sole Proprietor or Low Volume Standard brand is US$4.50 one time and a Standard brand is US$46, campaign use case registration carries a US$15 vetting fee, and a campaign then costs US$2, US$10 or US$1.50 a month depending on its type (Twilio pricing and fees for A2P 10DLC, article updated 15 June 2026, read 10 September 2026). Priced per conversation rather than per send, with the carrier fees added: A2P 10DLC costs for two-way AI SMS agents.
Which text-to-speech engine is fastest for a voice agent?
The published figures cannot be ranked against each other, because none of them measures the same thing. ElevenLabs lists Flash v2.5 at about 75ms and footnotes that figure as excluding application and network latency (ElevenLabs models page, read 10 September 2026). Rime publishes Mist v3 at 37ms time to first audio at the median and 56ms at P90, but its own benchmark table states those were measured on a single Lambda H100 SXM machine, and the same page notes that going through the cloud API adds a network round trip of typically 25 to 50ms from most of the continental United States (Rime latency docs, read 10 September 2026). Two latency numbers are comparable only when metric, transport, concurrency and network position all match. What each vendor figure leaves out: fastest TTS for voice agents, latency compared.
What does one-click unsubscribe actually require in an outbound email?
Two headers, a working endpoint and a visible link, and every part of it is specified. Google requires senders above roughly 5,000 messages a day to support one-click unsubscribe in marketing and subscribed messages and to include a clearly visible unsubscribe link in the body, set through a List-Unsubscribe-Post header and a List-Unsubscribe header (Google email sender guidelines, read 10 September 2026). RFC 8058, published January 2017, sets the rest: the List-Unsubscribe header must carry an HTTPS URI, the List-Unsubscribe-Post header must carry the single pair List-Unsubscribe=One-Click, the message must have a DKIM signature covering both headers, the POST that arrives must not include cookies or HTTP authorisation, and the sender must not answer it with a redirect. The URI has to identify recipient and list on its own, because one-click cannot ask a follow-up question. Where this sits in the wider rules: the 2026 Gmail and Outlook bulk-sender rules.
How long should a page section be for an AI system to retrieve it?
Short enough to survive being read on its own. Retrieval pipelines split a page into chunks and hand only the matching chunks to the model that writes the answer, so a passage that leans on the paragraph above it arrives without that paragraph. OpenAI documents the default for its vector stores as 800 tokens per chunk with 400 tokens of overlap, adjustable between 100 and 4096 tokens (OpenAI retrieval guide, read 10 September 2026). Roughly 600 words is a sensible working ceiling for a self-contained section: front-load the definition, keep the heading literal, name the entity instead of writing it or the company, and keep the source link inside the same block as the claim it supports. How chunking changes the way a page should be written: chunk-aware writing for 800 token retrieval.
Can an AI agent work in university admissions?
For the operational layer, yes: answering applicant enquiries around the clock in the language the applicant uses, pre-checking documents against published criteria, triaging so that complete files reach assessors sooner, and booking interviews with persistent follow-up. The decision itself should stay human, and every accept, reject or conditional offer should remain a judgement your admissions team makes. The pressure behind the question is documented rather than anecdotal: WICHE projects in Knocking at the College Door, 11th edition, that the total number of United States high school graduates peaks in 2025 and then declines steadily through 2041, a fall of about 13% from the peak (WICHE, read 10 September 2026). Fewer applicants means more competition for each one, and speed of reply is the part a machine reliably wins. Where agents fit across the funnel: AI admissions agents for universities.
Are our generative AI impressions in Search Console counted on top of our normal Search impressions?
No — they are a filtered view of numbers the main report already contains. Google states that the generative AI performance report “includes data from the Web search type in the Performance report (Search results)”, so an impression earned inside AI Overviews or AI Mode is already inside your web-search total and adding the two together double counts (Search Console Help, generative AI performance report, read 14 September 2026). The same page confirms the report covers AI Overviews and AI Mode only, that as of 31 August 2026 Google had rolled the insights out to “all websites worldwide”, and that chart and table totals can legitimately differ because the chart aggregates by property while a page-grouped table aggregates by page. What the report answers and what it withholds: the Search Console generative AI performance report.
Can we pull the Search Console generative AI data through the API?
Not as at 14 September 2026, and the two places such a parameter would live both say otherwise. The Search Analytics API reference documents a type parameter accepting only discover, googleNews, news, image, video and web, with web defined as the combined All tab in Google Search and no generative AI value offered (Search Console API, searchanalytics.query, read 14 September 2026), and the help page for the report itself documents an export button for the chart and table data and no endpoint (read 14 September 2026). Automation today therefore means a scheduled export, not a query. How to baseline and trend it anyway: the generative AI performance report for AEO.
How do we stop our pages appearing in AI Overviews and AI Mode without leaving Google Search?
There is a dedicated switch, and Google says it is not a ranking signal. The Search generative AI control sits under Settings, then Search generative AI, in Search Console, and offers three values: include, exclude, or inherit from the parent property. Google states that the control “only affects whether your content can appear in certain Search generative AI features; this control isn’t used as a ranking or inclusion signal affecting other parts of Search”, that content is excluded within 1 to 2 days of the change going live, and that it does not affect AI training, for which Google-Extended remains the separate lever (Search Console Help, Search generative AI control, read 14 September 2026). Read the trade honestly: an excluded site receives no impressions and no traffic from those features at all, and content from other sites still appears there.
What user-reported spam rate should an outbound email programme stay under?
Below 0.1%, and never at or above 0.3%. Google’s sender guidelines FAQ says senders “should keep their spam rate below 0.1% and should prevent spam rates from ever reaching 0.3% or higher”, adds that rates above 0.1% already damage inbox delivery for bulk senders, and states that since June 2024 a bulk sender above 0.3% is ineligible for mitigation, regaining eligibility only once the rate stays below 0.3% for 7 consecutive days (Google Workspace Admin Help, email sender guidelines FAQ, read 14 September 2026). Spam rate is calculated daily in Postmaster Tools, so one bad send is visible tomorrow and the recovery window is a week. The full rule set: the 2026 Gmail and Outlook bulk-sender rules.
What happens if our sending domain fails the Outlook high-volume sender requirements?
The message is rejected outright with a named code. Microsoft documents the bounce as “550 5.7.515 Access denied” and explains that it means the domain in your 5322.From address did not pass the required authentication level for senders of large volumes, which it defines as 5,000 or more messages a day to Microsoft consumer email services such as Outlook.com, Hotmail and Live.com (Microsoft Support, NDR 550 5.7.515, read 14 September 2026). Microsoft’s announcement is worth reading carefully, because it carries an April 29th update saying the action was changed to rejection while the paragraph beneath it still describes routing to Junk from 5 May 2025 with rejection at a date to be announced; both texts remain on the page (Microsoft Tech Community, read 14 September 2026). The DMARC bar is low — p=none is enough — but it must align with SPF or DKIM.
What is the difference between the Agentic Commerce Protocol and Google AP2?
They solve different halves of an agent purchase. The Agentic Commerce Protocol describes itself as “an interaction model and open standard for connecting buyers, their AI agents, and businesses to complete purchases seamlessly”, is maintained by OpenAI and Stripe, is published under the Apache 2.0 licence, and is marked on its own repository as currently in beta, with separate checkout and delegate-payment specifications (Agentic Commerce Protocol repository, read 14 September 2026). Google’s Agent Payments Protocol answers authorisation rather than plumbing: an open extension to the Agent2Agent protocol that wraps each step in verifiable digital credentials — a Checkout Mandate shared with the merchant and a Payment Mandate shared with the credential provider and networks, each in an open and a closed form — to give a non-repudiable cryptographic audit trail for every transaction (AP2 protocol documentation, read 14 September 2026). ACP standardises how the merchant gets called; AP2 standardises proof that a human authorised it. What either means for B2B SaaS, where the checkout is a booked demo: the Agentic Commerce Protocol for B2B SaaS.
The FCC one-to-one consent rule was vacated. Can an AI agent call shared or co-registration leads now?
The rule is gone; the consent requirement is not. In Insurance Marketing Coalition Limited v Federal Communications Commission, No. 24-10277, filed 24 January 2025, the Eleventh Circuit agreed that the FCC “exceeded its statutory authority under the TCPA” and wrote that it would “grant IMC’s petition for review, vacate Part III.D of the 2023 Order, and remand for further proceedings” (Eleventh Circuit opinion, read 14 September 2026). The same opinion restates the baseline that survives: to give prior express consent a person “need only ‘clearly and unmistakably’ state, before receiving the robocall, that he is willing to receive the robocall”. So a shared or co-registration lead is not automatically callable. You still have to produce, per record, an unmistakable prior consent, and the burden of proving it sits with the caller rather than the list seller. What a defensible chain of custody contains: purchased lead lists and the TCPA consent chain.
Is ISO/IEC 27001 the same thing as SOC 2?
No. One is a certifiable standard, the other is an audit report, and a vendor can hold either without the other. ISO/IEC 27001:2022 “specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system”, is written to be “applicable to all organizations, regardless of type, size or nature”, and states that “Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document” (IEC Webstore, ISO/IEC 27001:2022, read 14 September 2026). SOC 2 is the AICPA reporting framework for “Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy” (AICPA, read 14 September 2026), and the auditor reports on the controls the vendor itself scoped and described. Always read the scope section and the trust services criteria actually covered, not the badge. The rest of the review: the enterprise AI sales agent readiness checklist.
What happens to a fine-tuned model when its base model retires?
It retires with the base model, and the dates are published. OpenAI states that inference on fine-tuned models “will continue to be available until the base models are deprecated”, and its deprecations page then lists the fine-tuned versions ft-gpt-3.5-turbo, ft-gpt-4, ft-gpt-4.1-nano-2025-04-14, ft-babbage-002 and ft-davinci-002 as all shutting down on 23 October 2026. The self-serve fine-tuning platform is itself winding down on a stated clock: from 2 July 2026 new fine-tuning jobs stopped being available to organisations that had not run inference on a fine-tuned model in the previous 60 days, and from 6 January 2027 active existing customers can no longer create new fine-tuning jobs at all (OpenAI deprecations page, read 14 September 2026). Treat a base-model retirement as a revalidation project with a test set, not a configuration change. How to build so a swap is boring: model deprecation risk for AI agents.
Do calls to Australian business numbers escape the Do Not Call Register?
The Register does not cover them, but the rules governing the call still do, and that is the half teams miss. The Do Not Call Register states that “Business telephone numbers are not eligible for registration” and that only business numbers used primarily for faxes may be listed, so washing a purely B2B list removes nothing (Do Not Call Register, register your numbers, read 14 September 2026). The Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 is separate and broader: the regulator says the standards apply to any individual or organisation that makes or arranges telemarketing or research calls to Australian numbers, “even those not on the register”, and that a body exempt from the Act “must still meet the requirements contained in the industry standards”, with enforcement options running “from formal warnings to penalties of up to $250,000” (Do Not Call Register, industry standards, read 14 September 2026). Permitted hours, caller identification and termination requests therefore all apply on a B2B dial. What enforcement looks like: the Do Not Call Register and AI voice agents.
Does the FCC AI-disclosure proposal cover text messages as well as calls?
Partly, and the split is the useful detail. In NPRM 24-84 the Commission proposes requiring “callers making autodialed text messages that include AI-generated content to provide clear and conspicuous disclosure that the consumer’s consent to receive such messages may include consent to receive AI-generated content”, and separately proposes a disclosure at the beginning of each AI-generated voice call. Footnote 36 then draws the line: “the on-call disclosure proposed herein would apply to only voice calls and not text messages”, pointing at 47 CFR 64.1200(b) (FCC 24-84, read 14 September 2026). The Notice also records that it uses the word call to include text messages, “consistent with Commission and judicial precedent”. Consent-time disclosure would reach your SMS leg; the in-message identification duty would not. Status and what already binds today: FCC NPRM 24-84 and AI call disclosure.
How do we stop an AI agent creating duplicate CRM records?
Give it a unique key and make every write an upsert rather than a create. HubSpot documentation says the email address “is the primary unique identifier to avoid duplicate contacts in HubSpot” and publishes a batch upsert endpoint at /crm/v3/objects/contacts/batch/upsert that takes an idProperty of either email or a custom unique identifier property, so that “if the contacts already exist, they’ll be updated and if the contacts don’t exist, they’ll be created” (HubSpot contacts API reference, read 14 September 2026). One trap sits on the same page: “Partial upserts are not supported when using email as the idProperty for contacts”, so an agent that wants to update a subset of fields has to key on a custom unique identifier property instead. Resolve identity before the write, never after. The field-level blueprint: AI agent CRM integration.
Why does our voice agent pass every eval and still get it wrong on real calls?
Because a green suite is a claim about the artefacts your harness produced, and by default those artefacts are text rather than audio. One documented case sits in the Pipecat tracker: issue 5664, opened on 8 September 2026 and closed as at 16 September 2026, records that the simulation judge reads the bot tool calls by name and arguments only, never the values those tools returned, and that this is deliberate, because a simulation judges the conversation from the caller side and the caller cannot see your backend either (pipecat-ai/pipecat issue 5664, read 16 September 2026). A success criterion written to catch a reply that contradicted a tool result will therefore pass anyway. The nine default blind spots ranked by how often they are switched on without anyone choosing them, and the one-variable replay that names which one is yours: why voice agent evals pass but real calls fail.
Did ChatGPT change how it searches the web in August 2026?
Two named datasets disagree, so the honest answer depends on which measurement you mean. Promptwatch reports that the share of ChatGPT fan-out queries containing the site: operator jumped from about 0.37% to 16.8% on 8 August 2026, roughly a 46 times increase, with average searches per response moving from about 1.08 to 1.83 (Promptwatch, read 16 September 2026). DEJAN AI, capturing 196,692 OpenAI fan-out queries, measured the site: share at 0.14% across August and found 0 of 371 fan-outs on 8 August itself containing the operator (DEJAN AI, read 16 September 2026). What neither party contests is the separate citation measurement: Promptwatch puts reddit.com at an average 3.83% of ChatGPT Search citations from 18 July to 7 August 2026 and 0.52% from 14 to 17 August. Three methods lined up side by side, plus our own poll registry across the same window: did ChatGPT change how it searches in August 2026.
How do we get voice agent traces into Langfuse or Datadog without writing a custom exporter?
You do not write one. LiveKit Agents 1.8.0, released on 5 September 2026, moved its spans, metrics and logs onto the OpenTelemetry GenAI semantic conventions so that Langfuse, Datadog Agent Observability and other GenAI-aware backends read LiveKit traces natively (LiveKit Agents 1.8.0 release notes, read 16 September 2026). Langfuse accepts standard OTLP on its /api/public/otel endpoint, configured with two environment variables and no custom code (Langfuse OpenTelemetry integration, read 16 September 2026). The catch is in the same release: five GenAI content events became attributes, so a dashboard still reading the old events goes silent rather than erroring. Day one setup, the breaking changes and the voice spans the convention does not define: OpenTelemetry spans for voice agents.
What can an AI voice agent hear before the call is answered?
Whatever the far end chooses to put in the early media window: a carrier announcement, a disconnected-number recording, or a switchboard talking while the phone rings. RFC 3960 defines early media as media exchanged before a particular session is accepted by the called user, occurring from the moment the initial INVITE is sent until the receiving user agent generates a final response, and it states plainly that SIP provides no early media indicator, so no signalling flag tells you whether audio is arriving (RFC 3960, read 16 September 2026). The same document says early media sessions terminate when a final response is sent, and that a 200 OK simply transitions that stream into a regular media session. Why a bare 180 Ringing is not early media, and the three-gate test for whether any of it reaches your agent: early media and what your agent hears before answer.
How do we stop an AI agent mispronouncing Australian place names?
Fix it in the lexicon layer rather than the prompt, and build the name list before writing a single phoneme. The Australian Government Style Manual is the authority on the string you feed the engine: official place names use a standard 26 character alphabet, do not use diacritical marks, are not possessive and do not generally carry punctuation, and hyphens or apostrophes appear only where they were part of the name of the person commemorated (Style Manual, Australian place names, read 16 September 2026). That matters because a respelling which adds an accent to force a vowel is no longer the official name sitting in your CRM. The four places you can intervene, and a coverage test showing how little of this vocabulary the standard pronouncing dictionaries actually hold: fixing AI agent pronunciation of Australian names.
Can we point our own SBC straight at a model provider SIP endpoint instead of using Twilio?
Yes for inbound calls, and the targets are published. The OpenAI telephony guide says to point the trunk at the OpenAI SIP endpoint, built from your project ID as the user part of the URI and sip.api.openai.com as the host, with transport set to tls, or sip-eu.api.openai.com for European data residency; to allow outbound TCP and TLS to the DNS-resolved addresses on port 5061; and to open bidirectional UDP for SRTP traffic to four CIDR blocks: 13.79.45.80/28, 23.98.140.64/28, 40.67.149.176/28 and 40.83.204.240/28 (OpenAI voice and SIP guide, read 16 September 2026). Create the webhook first, because an incoming call fires a realtime.call.incoming event to it rather than waiting for you. What the removed intermediary was quietly doing, and the five checks to run before moving traffic: direct SIP to a model provider without Twilio.
How many messages a day can our AI SMS agent send on a 10DLC number?
Two separate ceilings apply, and the daily one is not set per number. Twilio documents that T-Mobile assigns a daily message cap based on your Trust Score, applied at the Brand level per EIN and shared across every A2P Brand and campaign registered under that EIN, including registrations made on other messaging platforms; businesses in the Russell 3000 Index receive a default total of 200,000 SMS segments and MMS per day, exceeding the cap returns error 30023, and the counter resets at midnight Pacific time (Twilio, T-Mobile daily message limits for A2P 10DLC, article updated 18 June 2026, read 16 September 2026). Sending rate is the other ceiling, measured in message segments per second and set by Brand type, campaign use case and Trust Score, with Sole Proprietor and Low Volume Brands not put through secondary vetting and fixed to their use case rate (Twilio, message throughput and Trust Scores, article updated 9 September 2026, read 16 September 2026). Costed per conversation rather than per send: A2P 10DLC costs for two-way AI SMS agents.
Can we slow an AI crawler down with a crawl-delay line in robots.txt?
Not reliably, because crawl-delay is not part of the standard. RFC 9309, the IETF Robots Exclusion Protocol, defines user-agent, allow and disallow records and contains no crawl-delay field anywhere; it says only that crawlers may interpret other records and may be lenient about them, which is permission rather than obligation (RFC 9309, read 16 September 2026). Google states the position directly: it supports user-agent, allow, disallow and sitemap, and other fields such as crawl-delay are not supported (Google robots.txt specification, read 16 September 2026). The OpenAI crawlers page documents per-bot allow and disallow tags plus published IP ranges, and as at 16 September 2026 documents no crawl-delay directive of any kind; it also notes a robots.txt change can take around 24 hours to take effect for search (OpenAI crawlers overview, read 16 September 2026). Rate limiting therefore belongs on your own server. How to confirm a crawler is genuine before you throttle it: verifying AI bot traffic by rDNS and IP ranges.
How do we know an AI agent transfer actually connected rather than the agent just hanging up?
Read the NOTIFY stream, not the call log. A SIP transfer uses the REFER method defined in RFC 3515, which creates an implicit subscription inside the same dialog, and the RFC requires that every NOTIFY in that subscription carry a message/sipfrag body beginning with a SIP response status line whose response class indicates the status of the referred action (RFC 3515, read 16 September 2026). That status line is the evidence: a 200 class means the referred request succeeded, anything else names the failure, and the body is described as a complete statement of the status rather than a delta. The same RFC warns that terminating the subscription, by unsubscribing or by rejecting a NOTIFY, is not an indication that the referred request should be withdrawn or abandoned, so a transfer can still complete after your side stopped listening. The fault tree, ordered by frequency: why AI agent warm transfers fail.
Will buying more HubSpot API capacity make our AI agent write faster?
Only if the app is privately distributed, and that is the trap. HubSpot documents that an app distributed through its marketplace using OAuth is limited to 110 requests every 10 seconds for each account that installs it, excluding the CRM Search API, and states that the API limit increase add-on does not raise the limit for those apps (HubSpot API usage guidelines and limits, read 16 September 2026). A privately distributed app sits on a different table: 100 requests per 10 seconds per app on Free and Starter and 190 on Professional and Enterprise, against daily ceilings of 250,000, 625,000 and 1,000,000 per account, where the burst limit is per app but the daily limit is shared across every app in the account, and at most two limit increases can be purchased. Check the distribution setting before you buy anything. Field-level integration patterns for an agent writing mid-call: AI agent CRM integration.
What would the FCC count as an AI-generated call?
Considerably more than a cloned voice, and the proposed wording lives in the rule text rather than the summary. In the appendix to NPRM 24-84 the Commission proposes adding to its rules that an AI-generated call means a call that uses any technology or tool to generate an artificial or prerecorded voice or a text using computational technology or other machine learning, including predictive algorithms, and large language models, to process natural language and produce voice or text content to communicate with a called party over an outbound telephone call (FCC 24-84, read 16 September 2026). Two boundaries follow. It is scoped to outbound calls, and the same Notice asks whether the definition is necessary at all, given the TCPA already covers artificial or prerecorded voice and the Commission has already determined that voice cloning qualifies under that phrase. Status as at today and what already binds: FCC NPRM 24-84 and AI call disclosure.
Do we have to tell staff before an AI agent screens them?
In the EU the duty is explicit, and it sits on the employer rather than the vendor. Article 26(7) of the AI Act provides that before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers representatives and the affected workers that they will be subject to the use of that system, and that the information shall be provided, where applicable, in accordance with the rules and procedures laid down in Union and national law and practice on information of workers and their representatives (Regulation (EU) 2024/1689, Article 26(7), text read 16 September 2026 from the Official Journal capture, because EUR-Lex blocks automated fetches). Read the boundary carefully: the paragraph requires notification, not consent and not an opt-out, and it reaches representatives as well as the individuals screened. When the obligation attaches and the rest of the deployer list: EU AI Act deployer obligations for AI screening.
Our Search Console generative AI report is empty. Does that mean we never appear in AI Overviews?
Not necessarily, and Google lists three different causes before visibility is one of them: that “Not all properties have access to the report, as we’re rolling out over time”, that “Your site hasn’t received enough impressions in generative AI features on Google Search”, and that you may have excluded your site from Search generative AI features. Read the first of those against the note Google now prints at the top of the same page, “As of August 31, 2026, we’ve rolled out these insights to all websites worldwide”, and the rollout explanation is superseded by Google’s own banner even though both sentences are still published; treat impressions and exclusion as the live causes (Search Console Help, generative AI performance report, read 20 September 2026). The same page adds two limits worth knowing before you conclude anything: the report covers AI Overviews and AI Mode only, and Search Console does not include data from experiments in Search Labs because those remain in active development. An empty report is a measurement question first. How to baseline and trend it anyway: the Search Console generative AI performance report for AEO.
Why is our text-to-speech slower from Australia than the vendor latency numbers suggest?
Because the published figure usually measures one component while your caller experiences all of them. Deepgram sets the breakdown out as total latency equals network plus time to first byte plus audio synthesis, and works an example where a 745 millisecond total contains a 616 millisecond time to first byte, of which 339 milliseconds is the SSL handshake alone (Deepgram, text to speech latency, read 16 September 2026). The same page states that Deepgram servers are exclusively in the United States and that API requests made from another country will incur relatively higher network latency than requests from the USA. An Australian deployment therefore pays a geography cost that no engine comparison table records. Which engines are fastest, and what to measure instead of the headline number: fastest TTS for voice agents, latency compared.
Why does our AI agent cut callers off mid sentence on Deepgram Flux?
Read the trigger field on the EndOfTurn event before you change anything else. Deepgram documents that trigger is present on every EndOfTurn event and only there, and that it carries one of three values: model when the native end of turn detection decided, manual when you sent a ForceEndTurn message, and timeout when eot_timeout_ms elapsed (Deepgram, Force End Turn, read 18 September 2026). The configuration page puts the eot_timeout_ms default at 5000 ms across a valid range of 500 to 60000, and states that setting eot_threshold to 1.0 suppresses natural end of turn detection while the eot_timeout_ms backstop still applies, so a silence timeout can end a turn no matter how uncertain the model was. The diagnosis in full, including what to log: why a Deepgram Flux agent cuts callers off, read from the trigger field.
Our p95 latency looks fine but callers say the agent is slow after a transfer. What are we missing?
The slowest turn in the call was probably never measured. The livekit-agents 1.8.1 release, published on 10 September 2026, carries the changelog line fix(voice): report e2e_latency for the first reply after a handoff, landed as pull request 7167 (LiveKit Agents 1.8.1 release notes, read 18 September 2026). On any earlier version the first agent turn after a handoff contributes nothing to the percentile, so the dashboard is summarising only the turns that were already fast. What to measure instead, and how to fix the turn rather than the chart: why a voice agent is slow after a transfer when p95 looks fine.
How do we version control an AI agent prompt and promote it from staging to production?
Export the running configuration to files, commit those files unchanged, then promote with a pipeline rather than by copying between dashboards. Only the logical half of an agent travels between environments: the prompt, the tool definitions, the model and voice identifiers and the evaluation fixtures. Credentials, phone numbers and resource identifiers are rebound per environment, and there is now a deadline on the alternative, because OpenAI documents that on 30 November 2026 the v1/prompts API and reusable prompt objects are scheduled to shut down and that migrating means moving reusable prompt content into your application code (OpenAI deprecations, read 18 September 2026). The full promotion sequence: version control and promote AI agent config.
Is a caller phone number in our logs personal information under the Privacy Act?
Almost always yes, and which field it sits in changes nothing. The OAIC Australian Privacy Principles guidelines define personal information as information or an opinion about an identified individual, or an individual who is reasonably identifiable, and list a telephone number among the common examples alongside name, address and date of birth (OAIC, APP guidelines chapter B, key concepts, paragraphs B.88 and B.89, read 18 September 2026). On an agentic voice stack the number is rarely in one place: it is copied into room names, span attributes and call statistics lines that a retention policy was never written to reach. Where the boundary actually sits, and the conditions that move a field across it: is a phone number in a log personal information.
What does an AI voice agent have to produce before it can triage tickets on an MSP helpdesk?
A ticket your PSA will accept, which is a shorter list than it sounds. The Autotask REST reference for the Tickets entity lists 74 fields in its fields table, marks 6 of them as required, and marks one of those 6, id, as read-only, so five values must come from the agent: companyID, dueDateTime, priority, status and title (Autotask REST API, Tickets entity, counted from that page on 18 September 2026). Build that payload and prove your PSA accepts it before you give the agent a phone number. The rest of the sequence, including what the agent must never do on a call: AI voice triage on an MSP helpdesk.
Our AI receptionist gave a caller medical advice. Is there a 24 hour deadline to report it?
In an ordinary Australian private practice there is no 24 hour statutory clock. Where a mandatory notification is required at all, the Health Practitioner Regulation National Law provides that the practitioner must notify as soon as practicable after forming the reasonable belief, and Ahpra states that a notification should be made as soon as practicable, with practicable carrying its ordinary meaning of feasible or possible (Ahpra, mandatory notifications, read 18 September 2026). What is genuinely urgent is evidence: preserve the audio and the transcript before anyone edits the agent configuration, because changing the prompt destroys the record of what produced the answer. The 24 hour and then 7 day sequence: what to do after an AI receptionist gives clinical advice.
A customer says we recorded them without consent. What do we do first?
Preserve the audio, find what the greeting actually said on that call, and compare the timestamp at which recording started with the timestamp at which the disclosure was spoken. There is more room than it feels: the OAIC tells complainants to raise the matter with the organisation first and to give it at least 30 days to respond, and says 30 days is what it considers a reasonable time before the complaint comes to the Commissioner (OAIC, complain to an organisation or agency, read 18 September 2026). The gap is usually mechanical rather than careless, because recording is commonly started by a call event while the disclosure is spoken by the agent a moment later. The full response path: responding to a recording consent complaint.
Who signs the business associate agreement in a HIPAA voice agent stack?
However many of the layers you contract with directly, which is usually fewer than the five that touch the audio. The HIPAA Privacy Rule provides that a covered entity may disclose protected health information to a business associate if it obtains satisfactory assurance that the business associate will appropriately safeguard the information, that a covered entity is not required to obtain such assurances from a business associate that is a subcontractor, and that the assurances must be documented through a written contract or other written agreement (45 CFR 164.502(e) on the eCFR, read 18 September 2026). Your platform vendor contracts down its own chain; you contract with the parties you actually buy from. Which vendors publish what, layer by layer: who signs the BAA in a HIPAA voice stack.
At what call volume should we move from a managed voice platform to a framework?
Not at the 10,000 minutes a month the circulating comparison tables repeat. Compared on published infrastructure prices alone a framework is cheaper from roughly 600 minutes a month; count an amortised build plus evaluation maintenance and on call time, and the crossover moves out to between 90,000 and 183,000 minutes a month. The headline rates mislead because they measure different things: the Vapi pricing page prices hosting at US$0.05 a minute with model components billed at the listed price of the provider and no markup, so that rate excludes the language model, speech to text and text to speech, while a bundled per minute rate includes all three (Vapi pricing, read 18 September 2026). The worked calculation with every input stated and substitutable: the platform versus framework cost crossover.
What can an AI phone agent do on an Australian childcare enrolment enquiry line?
It can answer what the centre already publishes, capture a waitlist enquiry, book a tour and write a structured note for a human to read. It should stop before enrolment record content, because regulations 160 to 162 of the Education and Care Services National Regulations set what that record must contain and who may authorise what, which makes the boundary written down rather than a judgement call. One fact such a line is asked constantly: the Department of Education states that all Child Care Subsidy eligible families are guaranteed at least 72 hours of subsidised care a fortnight, or 3 days a week, regardless of activity levels, and that this started on 5 January 2026 and replaces the previous activity test (Department of Education, 3 Day Guarantee, read 18 September 2026). Where the line sits: where an AI agent must stop on a childcare enquiry call.
How long do we have to keep the logs our AI system generates under the EU AI Act?
At least six months if you are the deployer of a high risk system, and the duty attaches to the logs the system generates automatically. Article 26(6) of Regulation (EU) 2024/1689 provides that deployers of high risk AI systems shall keep the logs automatically generated by that system, to the extent such logs are under their control, for a period appropriate to the intended purpose of the system, of at least six months, unless provided otherwise in applicable Union or national law and in particular in Union law on the protection of personal data (Regulation (EU) 2024/1689, Article 26(6), Official Journal text read 18 September 2026 from an archived capture, because EUR-Lex blocks automated fetches). Read the two limits inside that sentence: the duty reaches only logs under your control, and data protection law can shorten the period as well as extend it. The rest of the deployer list: EU AI Act deployer obligations for AI screening.
Can we charge AI crawlers for access instead of blocking them in robots.txt?
At the network edge, yes, and the mechanism is a status code. Cloudflare documents that pay per crawl lets a site owner set a price per zone, and that on each request an AI crawler either presents payment intent in request headers and receives an HTTP 200, or receives an HTTP 402 Payment Required response carrying the price, with Cloudflare acting as merchant of record (Cloudflare, what is pay per crawl, read 18 September 2026). The same page carries the trap: if you have already blocked a crawler in the WAF or in Bot Management, those rulesets override the charge setting and the crawler gets no access at all, paid or unpaid. Whether the economics work for a site your size: pay per crawl economics for AI crawlers.
Our AI SMS agent has two use cases. Do we need two 10DLC campaigns?
Probably, and how many you are allowed depends on your Brand type rather than on how many numbers you own. Twilio documents that a Sole Proprietor Brand may register one campaign per Brand, while a Low Volume Standard Brand and a Standard Brand may each register up to five campaigns unless a clear and valid business reason is provided for exceeding that limit, and that each tax identifier may be used to register up to five Standard or Low Volume Standard Brands (Twilio, A2P 10DLC, read 18 September 2026). The same page sets daily volume by Brand type as well: 1,000 SMS segments and MMS a day to T-Mobile for a Sole Proprietor, up to 2,000 for a Low Volume Standard Brand, and from 2,000 upward by Trust Score for a Standard Brand. What the registration layer costs before a single message moves: A2P 10DLC costs for two way AI SMS agents.
Why do the chart and the table in our generative AI performance report show different totals?
Because they aggregate differently, and Google says so on the report documentation. Chart data is aggregated by property, so if two results from the same site appear in one generative AI feature they count as a single impression, whereas table data grouped by page is aggregated by page, and the help page names that difference as the usual cause of a chart total not matching a table total (Search Console Help, generative AI performance report, read 18 September 2026). Two further limits belong on the same checklist: the 1,000 row limit that applies to the Search performance report applies here too, and the newest data can be preliminary and is drawn as a dotted line while it is still being collected. How to baseline and trend the report anyway: the Search Console generative AI performance report for AEO.
Does blocking AI crawlers stop my site appearing in Google?
Since 15 September 2026 it can, because one setting changed meaning rather than changing state. Cloudflare announced that Block and Block on pages with ads now apply to mixed-use crawlers, including Applebot, Bingbot and Googlebot, so either setting affects search as well as training (Cloudflare, accountable mixed-use AI crawlers, read 22 September 2026). The setting that refuses training while keeping search is the new Disallow AI Training, named for the Disallow directive it publishes in robots.txt. Nothing flipped by default: Cloudflare states that current settings carry over on their own, so the exposure is an old Block rule that now reaches further than it did. What that looks like in Search Console: why blocked AI crawlers dropped a site out of Google.
Will the new Australian privacy bill require consent to send marketing SMS?
On the current draft, no, and the Spam Act still decides that question today. The exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 opened on 31 August 2026 and closed to submissions on 18 September 2026 (Attorney-General’s Department, privacy reform consultation, read 22 September 2026). Its replacement Australian Privacy Principle 7 would require a simple way to opt out of direct marketing and clear information about how to use it, not consent to send; proposed APP 4.2 is where consent appears, providing that an organisation must not trade personal information unless the individual has consented to the trading. Keep every statement about it conditional: the document is watermarked EXPOSURE DRAFT and its commencement table is entirely blank. What binds you now is section 16 of the Spam Act 2003, which prohibits sending a commercial electronic message that has an Australian link and is not a designated commercial electronic message under Schedule 1, with consent an exception the sender carries the evidential burden to establish. Where the draft would and would not change practice: marketing consent under the 2026 Australian privacy bill.
What does an ACMA telemarketing or spam breach actually cost?
More than any single matter suggests, because the regulator publishes the running total. ACMA stated in July 2026 that “Businesses have paid more than $12 million in penalties for spam and telemarketing breaches over the past 18 months” (ACMA, telemarketing and spam breaches, read 22 September 2026). That is money actually paid, which is a different figure from a statutory maximum; maximums still belong in penalty units rather than dollars. The same page restates the four duties that generate those penalties: do not contact numbers on the Do Not Call Register without consent, call only during permitted hours, identify yourself clearly, and do not send marketing messages to people who have unsubscribed. An AI agent changes none of the four. How the register and enforcement work in practice: the Do Not Call Register and ACMA enforcement for AI voice agents.
Do I have to file in the FCC’s Robocall Mitigation Database?
Almost certainly not, because the filing duty sits with your voice service provider. Most businesses running an AI voice agent are end users rather than voice service providers, and the Commission put that in writing in its September 2026 rulemaking: “Although end users are not required to file in the RMD, and we do not condone voice service providers compelling their end users to submit RMD filings” (Federal Register, 91 FR 57454, read 22 September 2026). Read that document as position plus proposals rather than settled rules: it is a Further Notice of Proposed Rulemaking with comments due 9 October 2026. One budgeting detail sits in the same text: the $100 application fee adopted in the earlier RMD Order is, in the words of the Commission, not yet effective. Who files, who does not, and what to ask your carrier: the Robocall Mitigation Database and AI voice agents.
Can my AI agent use the caller’s voice as an identity factor?
Not as an authentication factor, if you are working to the current NIST baseline. Revision 4 of NIST SP 800-63B states, within its presentation attack detection requirements, that “Biometric comparison based on voice SHALL NOT be used” (NIST SP 800-63B, read 22 September 2026). The change log for the revision records the same decision, noting that section 3.2.3.2 prohibits biometric comparison based on voice. Scope matters and is often misquoted: the publication binds United States federal agencies and the credential service providers acting for them, so for an Australian operator it is a benchmark rather than a legal duty. Use it as the reason to rank knowledge and possession factors above voice: the identity verification ladder for AI agents.
Does a vendor claim of 45+ languages mean the agent works in all of them?
No. A raw language count tells you the model can generate text in a language; it does not tell you the agent resolves the task with the same accuracy, latency and compliance behaviour it manages in English. There is a published way to think in tiers rather than totals: Unicode CLDR defines four main coverage levels, Core, Basic, Moderate and Modern, and ships a coverageLevels.txt data file per release listing which locales sit at each level (Unicode CLDR, coverage levels, read 22 September 2026). Borrow the method rather than the labels: grade each language you actually sell into on task completion, handoff rate, latency and disclosure wording, and treat anything ungraded as unsupported. A test you can run in an afternoon: a language parity test for multilingual AI agents.
Why does my SMS send go out late in November and December?
Because the large messaging providers throttle deliberately through the peak retail weeks. Twilio announced on 17 September 2026 that it will run a Heightened Awareness Period from Thursday 19 November 2026 to Monday 4 January 2027, during which message sending rates to United States destinations are monitored and may be limited at the account level for toll-free, short code and 10DLC numbers (Twilio changelog, read 22 September 2026). Accounts sending high volumes from short codes or toll-free numbers may be moved temporarily to Market Throughput, while 10DLC numbers stay on account based throughput. Nothing is thrown away: Twilio documents that message requests are queued for delivery in the order it receives them (Twilio, rate limits and message queues, read 22 September 2026), so the business consequence is a late send rather than a lost message. How to plan the calendar around it: an SMS throughput plan for Black Friday and peak season.
Why does my AI call drop when the caller presses hold?
Because hold is a renegotiation, and a stack that answers it from cache sends an invalid answer. Pressing hold sends an in-dialog re-INVITE whose SDP sets the media direction to a=sendonly. RFC 3264 section 6.1 is unambiguous about what has to come back: if a stream is offered as sendonly, the corresponding stream MUST be marked as recvonly or inactive in the answer (RFC 3264, the SDP offer/answer model, read 22 September 2026). An agent that replays a cached a=sendrecv answer is therefore non-compliant, and the carrier ends the dialog rather than carrying a stream that both ends claim to be sending. Reproduce it, then fix it: why a caller hold re-INVITE drops an AI call.
Last updated: 30 September 2026. Answers on this page are refreshed as the underlying studies and regulations change.