← Back to blog
NewsAbout 6 min read

Your AI Agent Is Now Calling Customer Support, and Businesses Have to Answer

Published Oct 4, 2026
Your AI Agent Is Now Calling Customer Support, and Businesses Have to Answer

At its Decagon Dialogues event on 1 October, Decagon shipped four products aimed at a problem most companies have not started planning for: what happens when the caller on the other end is not a person, but someone else's AI agent.

The four releases were Voice 3 with a new speech model called Chord, a Personal Agent Gateway with a companion authorisation protocol, Agent Modules, and a beta called Duet Apprentice. The first two matter most, because together they describe both sides of a conversation that is becoming routine.

The voice model cleared a human bar

Chord is Decagon's first in-house voice model, post-trained specifically for customer conversations rather than general speech. The company ran a blind test across three pairs of recordings, each pairing a real person with the same voice run through Chord. On average, roughly 90 per cent of listeners could not identify which was human.

A studio condenser microphone inside a dark soundproofed recording booth

Two details in how Chord works are worth more than the headline number. The model shapes speech phrase by phrase, slowing down for phone numbers and confirmation codes before returning to conversational pace. And it runs on a duplex architecture with two layers operating in parallel: a low-latency model handles listening and speaking, while a heavier model manages reasoning, tool calling, and guardrails behind the conversation.

The design shows up in the behaviour. The agent processes incoming audio while it is still speaking, so it can talk through a casual "mhm" and then yield on a genuine interruption, instead of either talking over the caller or going silent. It can narrate progress during a long task and take a follow-up question mid-flight rather than putting the caller on hold.

Decagon says Chord is trained on licensed data and consented voice talent, and never on customer-owned data. Voice 3 supports more than 70 languages, detects the caller's language, and switches automatically even when a caller moves between languages mid-sentence, with each language validated by native speakers before release.

The harder problem is the other agent

A good synthetic voice is table stakes by now. The more interesting release is the Personal Agent Gateway, and the reason Decagon built it is spelled out in its own announcement: in the month before the event, Meta launched Muse, OpenAI introduced dots, and Instinct started placing phone calls for users. Those are personal agents that book, buy, cancel, and negotiate on their owner's behalf, and they are already contacting customer support.

That breaks an assumption every support stack is built on. The party asking for something is not necessarily the party who owns the account, and may not be the party authorised to approve the change.

The gateway addresses this with two pieces. Personal agent detection flags likely personal agents across chat and voice, using signals from the business and from the platform, and each business decides what happens next and what those agents can access. Then a dedicated personal agent channel sits alongside chat, email, and voice, with separate Agent Operating Procedures, so the same request follows a different workflow depending on whether a person or an agent is asking.

Permissions live inside those procedures. A business defines which scopes an agent can request and which sections of a workflow require each scope, and a section is never exposed to an agent that lacks the matching permission. Decagon's example is an airline: a traveller's personal agent asks permission to view and rebook a flight, and the traveller approves viewing only. The agent gets the itinerary and not the ability to change it.

That protocol is what Decagon calls PACT, and its purpose is narrow but load-bearing. It lets a business verify who an agent represents and what that person actually authorised, which is the question a support system has to answer before it does anything on someone's behalf.

Why this lands on support first

Decagon's customers started by using its agents to resolve support tickets, and the company says those same agents now qualify leads, onboard customers, collect payments, and grow relationships. That expansion is the reason the personal agent problem is urgent rather than theoretical. The same agent that answers a question can also change an order, and the risk profile of those two actions is not the same.

Christian Niedworok, who leads digital service communication at Deutsche Telekom, put the Voice 3 experience in plain terms in the company's announcement: the voice sounds like it is listening, and it keeps the conversation moving instead of going quiet while it works. That is a description of latency and turn-taking, which is exactly what made older voice agents feel robotic.

The other two releases point the same way

The Agent Modules and the Duet Apprentice beta fill in the operational side. Modules package defined capabilities that a business can switch on for a specific job, which is the difference between a general assistant and something you can point at a queue. Duet Apprentice learns from a company's own wikis and from past escalations, and keeps that knowledge inside the customer's workspace, so an agent improves on the organisation's own material rather than on a shared pool.

Neither release is as vivid as the voice demo. Both matter for the same reason the gateway does. The companies deploying agents at scale are moving past the question of what a model can do, and toward the question of what a specific agent is allowed to know, say, and change inside a real workflow.

Why the voice bar was the easy part

Worth noting how quickly the 90 per cent figure stops being the story. A synthetic voice indistinguishable from a human is now a solved problem for a narrow, well-defined task like a support call, and the vendors that have not shipped one will ship one soon.

The bar that is still moving is authorisation. Decagon's own framing makes the point: personal agents that book, buy, cancel, and negotiate are already contacting support, and the businesses receiving those calls have no established way to check who the agent represents. A perfect voice on an unauthorised request is worse than a clumsy voice on a verified one.

That is why the gateway, not the voice model, is the release that will shape the next year of support tooling. It is also why the PACT protocol matters more than its modest scope suggests. Somebody has to define what proof of authorisation looks like when the requesting party is software, and the first credible definition tends to become the default.

What businesses should be deciding now

The uncomfortable part of this shift is that it forces a decision most companies have deferred: what an automated caller is allowed to do, and how you prove it was authorised.

Three questions are worth answering before the requests arrive. Can your systems tell an agent from a person, and does it matter for each workflow? What is the smallest set of permissions a personal agent needs for your most common request? And when an agent acts on someone's behalf, what record do you keep of the authorisation, and who can inspect it?

None of those are model questions. They are policy questions, and they are the ones that will determine whether your support stack treats an incoming agent as a customer, a threat, or something the system has no category for. Decagon has shipped the plumbing. The definitions are still up to the businesses on the other end.

Related articles