Article

October 9, 2026

Inside the Detection of Meta Muse: Two AI Voices, One New Security Challenge

Muse's AI voices are just the latest to join Pindrop's AI Voice Consortium, which helps contact centers identify AI agents during live calls.

Muse's Brett and Hailey are already calling your contact center

The #1 question I've been asked this week: does Pindrop detect Muse? What about other personal AI agents? The answer is yes, Pindrop BotStopper™ detects personal AI agents, checking AI voices that call your contact center against 5000+ AI voices in Pindrop's AI Voice Consortium. This means Muse's AI voices are already in the consortium, and already easily identified.

What is Pindrop seeing in Muse calls?

Two distinct Muse voices are already appearing in contact centers across multiple industries. The first call we matched to Brett or Hailey arrived on September 9, a full week before their outbound call beta announcement on September 16, and Muse has been calling financial institutions, healthcare organizations and retailers ever since.

  • Week-over-week analysis: by its fourth week, weekly Muse call volume was 8x the first week's.
  • Two voices: Hailey carries more of the calls, but both voices are active every week.
  • Across industries: financial institutions see the most Muse calls, followed by healthcare and retail.
  • Why it matters: adoption is happening before most enterprises have a policy for it.
Weekly calls carrying Muse's two voices, Brett and Hailey, from September 9 to October 6, 2026.

How does Pindrop detect Meta's Muse specifically?

Pindrop liveness detection analyzes call audio in real time to detect synthetic, replayed, or modulated speech. Once an AI voice is detected, the technology goes one step further. Muse's calling feature has two AI voices (Brett and Hailey). Pindrop captured their unique voice characteristics and registered them in the AI Voice Consortium.

Now anytime Brett or Hailey call into a contact center defended by Pindrop, they're identified by voice. Every Muse call in this analysis was matched to one of those two registered voices, so a contact center doesn't just know a bot is on the line, it knows it's Muse.

Interestingly, we've also observed that some customers flag Muse calls as fraudulent, while others classify them as legitimate. As more AI agents come online, businesses need to look beyond detection. That's why Pindrop is focusing on the next layer: agent authentication and authorization—establishing who an agent is, whom it represents, and what it is permitted to do.

700K+ AI agent calls in just 2 months

Pindrop identified 727K confirmed AI agent interactions in two months. 94% of those were labeled as "good AI agents" and 6% were "bad AI agents."

From there, Pindrop identified 19 distinct bot types and use cases.

Type Action
Payer bots Prior authorization, claims, enrollment
IVR / whisper bots IVR and machine audio
Nuisance bots Robocalls and harassment
Retail fraud bots Item not received, empty package, refund request
Benign bots Feedback, personal assistant, voicemail
Reconnaissance fraud bots Account balance, recent transactions
Account takeover bots Change address, change phone number

What does a Muse call look like?

Median time in each phase for Muse calls that reach a live agent.
  • It works the phone menu: 47% of Muse calls press keypad digits to navigate the IVR.
  • It reaches people: 64% of calls get through to a human agent. On those calls, a typical Muse call spends 2 min 01 s in the phone menu and then 2 min 18 s with the human operator.

Consumer AI agents change who's on the other end of the line

How have AI agents evolved?

As with most sophisticated tools, Pindrop researchers first saw fraudsters adopting AI agents, bots, and synthetic voices to launch attacks against contact centers. Retail fraud, for instance, is generally categorized by low-cost returns. With automation, however, AI callers request hundreds of these fraudulent returns on behalf of bad actors—a tactic that quickly adds up.

Legitimate automation has since followed. Healthcare providers are now using agents for routine tasks, like verifying claim status or coverage. This was a clear sign that not every bot on the line is a threat.

Now, personal AI agents like Meta Muse and OpenAI Dots have taken the industry by storm. Their quick adoption is already raising questions about the workflows we've relied on for decades, including in the contact center. Meta's current beta testing of advanced outbound calling features with Muse signals that the mass adoption of routine call automation is on its way. While other agents have been capable of providing these services, Meta's audience of nearly 3.6 billion daily users has propelled personal AI calling agents to the forefront.

This has massive implications for how contact centers operate. With Muse and other personal AI agents now available to consumers, everyday customers can send an agent to call on their behalf.

  • Impact on customer interactions: This changes how customers engage with enterprises. Tasks like checking a balance, disputing a charge, or rescheduling an appointment could be handled by an agent.
  • Big picture: The contact center is going to look very different from what we're used to.

And Muse isn't the only agent that can pick up the phone:

Agent or service What it can do What it means for your contact center
Meta Muse Calls businesses on a user's behalf An agent may speak for a customer. Verify the customer and the scope of delegation before sharing account details or making changes.
Instinct Uses a phone and computer for tasks like bill disputes and scheduling Expect delegated negotiation and follow-up. Confirm instructions and escalate decisions to the customer.
Google Search agentic calling Calls local businesses about availability and discounts Separate public-information requests from requests that need account access.
Gemini Call for Me Handles inquiries, bookings, phone menus and hold time; the user can take over A call can switch from agent to customer mid-call. Keep context through the handoff and authenticate the person who takes over.
Hippocratic AI provider agents Provider–payer calls on eligibility, claims, prior authorization and referrals These agents represent an organization, not a consumer. Verify the organization and its permitted access.

The personal agent protocol conversation is missing a layer

This week, Meta, Walmart, Stripe, and a handful of other companies announced the Personal Agent Protocol, an open standard for how AI agents interact with businesses.

This protocol is a stepping stone. But it doesn't emphasize the security and authentication layer the voice channel needs: it focuses on how agents connect and act. When an agent dials a contact center, three questions remain open:

  • Who authorized this agent? A phone call doesn't arrive with a verified session attached.
  • Is the human behind it who they claim to be? Recognizing an AI voice doesn't establish the identity of the customer it represents.
  • What is the agent allowed to do? Checking a balance and changing a payout address carry very different risk.

Conclusion: what you can do about it

  • The old model: A human customer talking to an IVR (interactive voice response) system or a human agent.
  • The new model: Two customers. One is the bot calling on behalf of your customer, and the other is the real human customer behind it.
  • The call to action: This requires a reevaluation of authenticity (is this a real human, or a known agent?) and authorization (is this agent allowed to act for this person?) in your voice contact center.

Talk to a real human about AI agent calls

About the data

Don't assume. Verify.

Take the first step toward a safer, more secure future for your business.