top of page

Meta Muse Calling Feature Lands as Instinct Adds Its Own Concierge

2 hours ago
13 min read

Meta activated the Meta Muse calling feature just as rival Instinct introduced Concierge, giving two competing AI agents the ability to phone businesses. Both announcements arrived on September 16, turning a missing capability into a new battleground almost overnight.

These agents can now pursue tasks that websites and apps cannot finish. Instinct says Concierge can contact restaurants without online booking, join a dentist’s cancellation list, or dispute a cable bill. Muse can place outbound calls to businesses across the United States.

The simultaneous releases create a sharper conflict than a standard feature race. Instinct has attracted users by acting like a responsive personal operator. Meta enters with established consumer platforms, a dedicated cloud environment, and a much larger potential distribution network.

Making a phone call sounds like an incremental upgrade. It actually pushes personal agents across an important boundary. They are no longer limited to reading information or clicking through websites. They can represent a person in conversations where requests, commitments, and misunderstandings can carry real consequences.

What Instinct and Muse Actually Shipped

Calling gives personal AI agents access to businesses that still operate through people, hold queues, and telephone menus.

Instinct founder Noah Shinn announced Instinct Concierge as an early-access service for requests that require more personal handling. According to the calling feature, availability will initially be limited before expanding to more users.

The examples reveal the intended market. Concierge can pursue a reservation when a restaurant lacks online booking. It can ask a dentist to notify someone about an opening. It can also work through a service dispute that would otherwise require a customer to wait on hold.

These are not simply voice versions of search queries. Each task requires the agent to communicate a goal, interpret a response, and decide what to do next. It might need to offer alternative dates or ask whether a fee applies.

That difference makes Instinct Concierge calls more consequential than automated appointment reminders. Traditional voice bots usually follow scripts written by the organization making the call. A personal agent instead represents the consumer and must navigate an unpredictable conversation.

Meta enabled a similar capability for Muse on the same day. Ryan Fox, a Meta product leader, said the beta had expanded to outbound calls involving U.S. businesses. Meta prioritized people who had previously asked Muse for the feature.

That rollout method doubles as demand collection. When users request an unavailable ability, Meta can treat those prompts as feature signals. People who already demonstrated interest then become early participants when the function becomes available.

Muse itself launched in the United States on September 8, only eight days before the calling expansion. It operates through a dedicated app, WhatsApp, and a web interface. Meta says it will also come to AI glasses.

The company presents Muse as a personal agent rather than a conversational chatbot. A chatbot mainly responds with information or generated content. An agent can take multiple steps, use external services, and continue working after its user leaves.

Meta says Muse can open a browser, complete forms, send emails, book travel, and make purchases. The agent asks for approval before certain sensitive actions, according to the company’s Muse introduction.

Phone access extends that operating model beyond software interfaces. A restaurant may not expose reservation inventory through an application programming interface, or API. A local clinic may only manage cancellations through its reception desk.

The telephone becomes a general-purpose connection to those businesses. An agent does not need a custom integration for every dentist, contractor, gym, or neighborhood restaurant. It only needs a reliable way to participate in an ordinary call.

That flexibility explains why AI agents making calls became a competitive marker. Smaller assistants, including Wajo, had promoted telephone execution as an advantage. Instinct and Meta have now reduced that distinction.

The releases do not establish that both products perform equally well. Neither announcement provides comparable completion rates, error rates, or call recordings across standardized tasks. Feature availability establishes parity on a checklist, not parity in practice.

The more important change is strategic. Two closely watched assistants now agree that useful consumer agents must handle offline bottlenecks. The browser alone is not enough.

Why the Meta Muse Calling Feature Raises the Stakes

The Meta Muse calling feature pressures every personal assistant to show that it can finish tasks, not merely recommend the next step.

Consumer AI products have spent years improving answers. Agents shift the measure of value from response quality toward completed work. A reservation either appears on the calendar, or it does not.

Phone calls intensify that shift because they cover frustrating tasks that users already understand. People know the inconvenience of waiting for a cable representative or repeatedly checking for an appointment. Saving that time creates a benefit that needs little explanation.

Instinct reached this contest with significant momentum. The startup, operated by Spear Street Technology, raised a reported Series B round led by Benchmark and Index Ventures. The deal brought its total funding to $350 million and valued it at $2.5 billion, according to funding details.

TechCrunch subsequently reported that Instinct was discussing another financing at a much higher valuation. Those talks remain reported negotiations rather than a completed transaction. Even so, the investor interest reflects expectations that personal agents could become a major consumer software category.

Instinct’s appeal comes partly from its conversational presentation. Users communicate with the assistant through familiar messaging channels instead of configuring a complex automation system. The agent then works across services on their behalf.

The startup also recently gave agents their own email addresses. That addition lets them manage account registrations and communications more independently. A trusted-network feature allows one user’s assistant to coordinate certain tasks with another person’s assistant.

Taken together, email, messaging, browser access, and telephone calls form a broader execution layer. Each channel closes gaps left by the others. The assistant can research online, email a business, call when nobody replies, and return with a result.

Meta brings a different advantage. Muse is available through WhatsApp, which already gives the company an established communication surface. Meta also controls major social platforms that can supply context, subject to permissions and product rules.

Muse registered more than 730,000 U.S. downloads during its first five days, according to Sensor Tower data cited by TechCrunch. The Meta AI app recorded 707,000 downloads during its own first five days. Muse also reached second place in U.S. app rankings at one point.

Those early figures measure acquisition, not durable use. Download totals do not reveal how many people connected accounts, completed tasks, or returned after the first session. Still, they show that Meta can introduce an unfamiliar agent to a large audience quickly.

The competitive pressure therefore runs in both directions. Instinct must maintain a clear product advantage before Meta distributes similar capabilities at scale. Meta must prove that its reach can translate into trust and reliable execution.

Other assistants also lose a straightforward point of differentiation. A product cannot rely on telephone access alone once leading rivals offer it. Competitors will need better reliability, narrower specialization, stronger privacy, or access to distinct services.

This race also pressures established assistants from OpenAI, Google, and other large providers. Users will increasingly compare them by the errands they complete across different channels. Strong general reasoning remains important, but it becomes only one component.

For business buyers, the change creates another decision. Companies can expose structured agent interfaces, or they can receive calls from consumer agents through existing support lines. The second path requires no integration, but it can create operational uncertainty.

Businesses may struggle to identify whether a caller represents a real customer. They may also need policies for consent, recording, authentication, and disputed instructions. A convincing synthetic voice does not establish legitimate authority.

The Meta Muse calling feature therefore does more than expand Muse. It signals that phone-based action is becoming part of the expected agent package. Every competitor must now decide how much real-world authority its software should receive.

Instinct Versus Meta Is a Race for Delegated Action

Instinct and Meta are competing to become the software layer users trust to act as them, not simply assist them.

That distinction defines the primary contest. An assistant provides information that helps a person decide. A delegated agent receives a goal and takes actions that advance it.

Telephone access makes delegation unusually visible. When an agent speaks to a restaurant host, it occupies the user’s place in the interaction. The business may make decisions based on what the agent says.

Consider a reservation request. The agent needs the preferred date, party size, location, and dietary constraints. If the ideal time is unavailable, it must know which alternatives are acceptable.

A strict agent might stop and request approval for every variation. A more autonomous agent might choose a nearby time based on prior behavior. The second approach saves time but increases the chance of an unwanted commitment.

That balance separates the products more meaningfully than whether both can dial a number. Users will judge how well each agent handles ambiguity, escalates uncertainty, and documents the final outcome.

Instinct’s position resembles a focused startup trying to define a new interface. It can release features quickly and shape the experience around personal delegation. Early users may tolerate rough edges in exchange for capabilities that feel new.

Meta can integrate more infrastructure around the same concept. Muse runs inside Muse Secure VM, a persistent virtual machine with its own browser. A virtual machine is an isolated software computer operating inside cloud infrastructure.

Meta says a separate Sentinel agent reviews outbound activity and blocks actions that violate its controls. The company also says Muse stores credentials where the primary agent cannot read them.

For purchases, Muse can use a one-time card through Stripe’s Link service. The system is intended to prevent the merchant or agent from seeing the user’s actual card number. Eligible transactions also receive specified purchase protections.

These design choices support a broader promise: give the agent enough context to act while limiting what it can expose or misuse. Meta outlines that approach in its agent safety design.

However, those safeguards remain company claims until outside researchers can test them across realistic scenarios. A secure architecture can reduce risk without eliminating judgment errors. The agent can protect a credential and still reserve the wrong table.

Instinct faces the same problem with fewer publicly described controls. Its usefulness depends on access to messages, accounts, and personal preferences. Every additional permission can improve execution while increasing the impact of a mistake.

This is why consumer agents differ from earlier smart speakers. A speaker might set a timer or answer a factual question. These new systems can browse accounts, exchange messages, spend money, and negotiate with businesses.

The winning product will need an effective authority model. That model defines what the agent can do independently, what requires approval, and what remains prohibited.

Calls introduce actions that are difficult to reverse. Joining a cancellation list is usually low risk. Canceling an existing reservation or subscription can trigger penalties, lost access, or limited recovery options.

The agent must also preserve evidence. A user should be able to review the number called, the identity presented, the request made, and the response received. Summaries alone may omit the detail needed to resolve a dispute.

Meta says Muse provides an audit trail of completed and planned actions. That is a useful foundation, but phone interactions require further clarity. Users need to know whether calls are recorded, transcribed, summarized, or retained.

Businesses also require disclosure. A person answering the telephone should know when they are speaking with an automated system. Applicable consent requirements can vary by location and by whether recording occurs.

Neither product’s announcement fully resolves these operational questions. The releases establish capability before establishing a shared etiquette for agent-to-human calls.

That sequencing is familiar in consumer technology. Adoption often precedes stable norms. The difference here is that the software acts with personal authority from the beginning.

For users, the practical comparison should focus on controlled execution. Which agent pauses at the right moment? Which one recovers from a misunderstanding? Which one produces a useful record?

Those questions matter more than personality or conversational fluency. A charming agent that completes the wrong action creates more work than a dull one that asks for confirmation.

The Real Test Is Permission, Not Voice

The hardest problem is not producing natural speech, but deciding when an agent has enough authority to make a commitment.

Recent Instinct experiences show why that distinction matters. An Atlantic writer reported that the assistant successfully found providers, contacted cleaning companies, and arranged a book pickup. Those examples demonstrate the convenience of delegated research and outreach.

The same account documented more troubling outcomes reported by other testers. One user said the agent canceled a flight prematurely and caused a loss exceeding $200. Another said Instinct booked a restaurant carrying a $200 cancellation fee without approval.

A separate user reportedly lost temporary access to Resy after the agent repeatedly sent reservation requests. Instinct founder Noah Shinn did not respond to the publication’s request for comment about those incidents.

These cases remain individual reports, not a controlled measurement of Instinct’s overall reliability. They cannot establish how frequently errors occur. They do illustrate the types of failure that become possible when an assistant receives operational authority.

The reported agent errors also expose a difficult product tension. Users want the system to remove friction. Repeated confirmation prompts return that friction to the user.

Yet autonomy without checkpoints can turn a request for information into an unintended transaction. “Check the cancellation terms” is different from “cancel the booking.” A reliable agent must preserve that distinction across long, messy interactions.

Phone calls add another layer of ambiguity. A business employee may offer a substitute product, a different appointment, or a cancellation with conditions. The agent must recognize when the conversation has moved beyond its original authority.

Natural language models can generate plausible responses without maintaining perfect alignment with every constraint. Long conversations also create opportunities for instructions to conflict or drift.

Prompt injection presents a related threat. It occurs when untrusted content tries to redirect an AI agent away from its user’s instructions. An agent with access to email, websites, and calls encounters many possible sources of such content.

Meta acknowledges that agents require stronger containment than ordinary chatbots. Its Sentinel system is designed to inspect actions separately from the Muse model. Meta also says users approve sensitive steps, including sending emails and making purchases.

Those controls sound sensible, but calling creates categories that do not fit neatly into existing approval rules. Does agreeing to a restaurant’s cancellation policy count as a purchase? Does confirming an appointment create a binding commitment?

Product teams will need more precise policies than “ask before sensitive actions.” Sensitivity depends on the context, cost, reversibility, and information disclosed.

Privacy presents another challenge. A call may require an address, birth date, account number, or medical scheduling detail. The agent must reveal enough information to complete the task without exposing unrelated data.

Meta says Muse conversations and virtual-machine data do not feed its advertising systems. It also allows users to opt out of having interactions used for AI training, according to the company.

The Associated Press noted that Meta is emphasizing privacy as it introduces a product requiring extensive digital access. Its launch coverage framed consumer trust as a central question for Muse.

Instinct has faced sharper scrutiny over permissions and data terms. The company’s policies have raised questions about connected-service data and model training. Users should review the current settings and terms before linking sensitive accounts.

No architecture can remove every risk when an agent operates across independent services. A restaurant employee can misunderstand the agent. A call can disconnect. A user can provide incomplete instructions.

Reliability therefore needs transparent measurement. Companies should report task completion rates, unauthorized-action rates, reversal outcomes, and the frequency of human intervention. Curated demonstrations do not answer those questions.

Users also need clear recovery paths. A useful agent should identify its error, preserve the interaction history, and help reverse the action. It should not leave the user to reconstruct what happened.

The industry’s near-term challenge is to make delegation inspectable. Every meaningful step should connect to a user instruction, a permission rule, and an audit record.

This standard will feel slower than unrestricted autonomy. It is also more likely to earn durable trust. Consumers will not keep delegating important tasks if they must supervise the agent afterward.

Three Signals Will Show Whether Calling Agents Last

The next phase will be decided by adoption quality, visible safeguards, and how quickly competitors respond.

The first signal is repeat use of Instinct Concierge calls and the Meta Muse calling feature. Initial downloads and feature requests establish curiosity. They do not prove that users will delegate calls every week.

The important metrics are completed tasks and returning users. Companies should reveal how often calls achieve the requested outcome without correction. They should also distinguish simple inquiries from commitments involving money or account changes.

Watch which categories attract sustained demand. Restaurant reservations offer a familiar demonstration, but they may not support frequent use for most people. Healthcare scheduling, home services, billing disputes, and subscription cancellation provide broader tests.

Each category also carries different risks. A restaurant can involve cancellation fees. A medical call can expose sensitive information. A subscription dispute can change ongoing charges or access.

If calling becomes a routine behavior across several categories, the case for personal agents grows stronger. If use remains concentrated in demonstrations and novelty tasks, the current excitement weakens.

The second signal is whether Meta and Instinct publish clearer permission and audit controls. Users need more than a promise that approval occurs when necessary. They need to understand what the product considers necessary.

Useful controls would include spending limits, prohibited task categories, approved contacts, and confirmation rules for irreversible actions. Call histories should explain what the agent requested and what the business agreed to provide.

Error reporting will matter just as much. A company that discloses failure categories can show how its controls improve over time. Silence leaves users dependent on scattered anecdotes and promotional examples.

Independent security testing would strengthen Meta’s claims around Muse Secure VM and Sentinel. Similar disclosure from Instinct would help users compare the products on more than convenience.

If both companies add granular controls and publish meaningful reliability data, calling agents will look more like a dependable service. If they rely on broad assurances, trust will remain a barrier.

The third signal is the competitive response. Wajo and other smaller agents already use calling as part of their positioning. They must now demonstrate specialization or better execution rather than simple feature access.

OpenAI, Google, and other platform providers also face a strategic choice. They can add direct outbound calling, partner with voice infrastructure providers, or leave the channel to specialized services.

Business platforms may respond from the other side. Reservation systems, healthcare portals, and customer-service vendors can create interfaces specifically for authorized agents. Structured access could reduce misunderstandings compared with open-ended calls.

However, businesses may also introduce restrictions. They could block suspected automated callers, require explicit disclosure, or limit high-frequency requests. Resy-style rate controls offer an early indication of that friction.

Regulators will eventually influence these interactions. Disclosure, consent, recording, impersonation, and consumer-protection rules were not designed around personal agents negotiating routine transactions. Enforcement or guidance could change how the products operate.

For now, users should test calling agents with bounded, reversible tasks. A request for available appointment times carries less risk than authorizing a cancellation. Clear constraints make the result easier to evaluate.

People should also separate research from execution when the consequences are significant. An agent can gather options first, then request approval before committing. That workflow preserves much of the time benefit while limiting surprises.

Teams studying agent behavior should keep their own records. A searchable AI workflow can help capture requests, outcomes, and failures across repeated tests. Evidence matters when product claims move faster than published benchmarks.

The Meta Muse calling feature and Instinct Concierge calls mark a real expansion of consumer agents. They connect AI software to businesses that still depend on conversation rather than structured digital systems.

Their lasting value will not depend on whether synthetic voices sound human. It will depend on whether the agents understand limits, ask at the right moment, and recover when something goes wrong.

Would you let an agent wait on hold for you today? That seems like an easy choice. The harder question is whether you would let it accept a fee, change an account, or disclose personal information. Start with a reversible task, inspect the record, and decide how much authority the result has earned.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page