Straight answers to the questions teams ask — and ask AI assistants — about autonomous AI sales agents: what they are, how they differ from chatbots, whether they really book meetings, what’s legal, and how Zian works. Where a claim isn’t ours, it links to the third-party study or regulator it comes from.
At a glance
- Direct answers first, sources linked inline — Harvard Business Review, G2, Deepgram, PNAS, ACMA and others.
- Covers the technology, the evidence, compliance, deployment options and Zian’s agent line-up.
- Zian is currently in an invite-only beta — apply for partnership for access.
The technology
What are autonomous AI sales agents?
Autonomous AI sales agents are software agents that carry out real sales work — calling, texting, emailing, qualifying, following up and booking meetings — end-to-end, without a human driving each step. Unlike automation that fires a fixed sequence, an autonomous agent decides message, channel and timing per prospect and adapts to replies. Full explainer: what are autonomous AI sales agents?
How are AI sales agents different from chatbots?
A chatbot waits on your website and answers questions; a sales agent works a pipeline. The agent initiates outbound contact across phone, SMS, email and WhatsApp, pursues a goal (a booked, confirmed meeting), and follows up over days and weeks. The chatbot’s job ends at the conversation; the agent’s job ends at the outcome. Honest comparison: AI sales agents vs chatbots.
Can AI agents really book sales appointments automatically?
Yes — this is the most proven use case, because it plays to the machine’s strengths: instant response and unlimited persistence. The evidence on speed is one-sided: the Lead Response Management study found the odds of contacting a lead fall roughly 100x when response slips from 5 to 30 minutes, and Harvard Business Review’s audit of 2,241 companies found firms responding within an hour were nearly 7x more likely to qualify the lead. An AI agent responds in seconds, every time. On Zian, the appointment-setting agent books 40+ meetings a week for many teams — how it works: AI appointment setting.
Do AI voice agents work for real outbound sales calls?
Yes, within honest limits. In Deepgram and Opus Research’s State of Voice AI survey of 400 business leaders, 80% of organisations reported using some form of voice technology (including legacy IVR) — adoption is mainstream. Modern voice agents handle structured sales calls — qualification, booking, reminders, reactivation — well, and Zian’s speak 30+ languages with voice cloning supported. Two honest caveats: speech recognition still degrades on heavy accents and noisy lines (a PNAS study of five major commercial systems documented uneven error rates), and emotionally loaded calls should route to a human. Platform comparison: best AI voice agents for outbound calls, and AI voice agents vs call centres. For Australia-specific picks and compliance, see the best AI voice agents for sales calls in Australia.
How fast should an AI voice agent respond on a phone call?
Inside a second — and the closer to human pace, the better. Across languages, human conversation runs on average response gaps of about 200 milliseconds, with the most common gap close to zero (Stivers et al., PNAS 2009). Phone-call research finds trouble starts well before the one-second mark: listeners rate a speaker as noticeably less willing as response gaps stretch past roughly 600–800 milliseconds (Roberts & Francis 2013, JASA Express Letters). The network eats part of that budget before the AI does any thinking at all — ITU-T G.114 recommends keeping one-way transmission delay under 150 ms, with 400 ms as the outer planning limit. A production voice agent has to fit listening, reasoning and speaking into what’s left. How the full latency budget breaks down: why voice AI needs sub-second responses.
Do customers prefer being contacted in their own language?
Yes, and the preference is measured. CSA Research’s “Can’t Read, Won’t Buy” study of 8,709 consumers in 29 countries found 76% prefer to buy products with information in their native language, 40% will never buy from websites in other languages, and 75% are more likely to buy the same brand again if customer care is in their language. Zian’s agents operate in 30+ languages across phone, SMS, email and WhatsApp — how that scales: AI agents in 30+ languages.
What’s the difference between an AI phone agent and a predictive dialler?
A predictive dialler automates the dialling — it places calls in bulk and hands answered ones to human reps, with pacing tightly regulated (in the US, the FTC’s Telemarketing Sales Rule caps abandoned calls at 3% of answered calls per 30-day period). An AI phone agent holds the conversation itself — qualifying, answering objections and booking — with no human on the line. Full taxonomy: AI phone agents vs predictive diallers.
Should we use an AI SDR or human SDRs?
The strongest teams run both: AI for instant response, high-volume outreach and follow-up persistence; humans for judgement calls, complex discovery and closing. AI agents make 28x more contact attempts than typical human cadences on Zian, which is the part of the job humans reliably under-execute. The full trade-off analysis: AI SDR vs human SDR and hybrid AI + human SDR pods.
Why does follow-up pacing matter so much?
Because most deals die from silence, not rejection — and because the research above shows reachability decays in minutes while most teams take hours. Zian’s SmartReach AI™ orchestrates message, channel and timing per prospect with intelligent follow-up pacing; teams on the platform see a 926% increase in follow-ups and a 2,736% increase in lead contact rates. The mechanics: AI follow-up pacing.
Why are cold email reply rates falling?
Because AI made sending nearly free while inboxes became harder to reach. Instantly’s 2026 Cold Email Benchmark Report, drawn from billions of interactions on its own platform during 2025, puts the average reply rate at 3.43% while top performers exceed 10% — and Google’s bulk-sender rules now enforce authentication and a hard spam-rate ceiling. More volume makes it worse; tighter targeting, disciplined pacing and multi-channel orchestration are what still work. The full analysis: why reply rates fall as AI volume rises.
How fast do we need to respond to inbound leads?
Faster than almost any human team manages. Harvard Business Review’s classic lead-response study found firms contacting a lead within an hour were nearly 7x as likely to qualify it as those waiting even an hour longer — and over 60x as likely as those waiting 24 hours. Artemis GTM’s 2026 benchmark still puts average B2B response time around 42 hours, with lead-to-opportunity conversion at 21% for sub-5-minute responders versus 2.3% after a day. AI agents answer in seconds, around the clock. The full picture: speed to lead with AI agents.
What do independent 2026 AI SDR numbers actually show?
Mainstream adoption, nuanced results. Digital Applied’s 2026 compilation (citing Salesforce and Outreach) reports 41% of enterprise B2B teams now run an AI SDR in production, while its matched 100,000-email analysis shows AI reply rates of 4.1% versus 5.2% for humans. Salesmotion, citing Dashly, found human-booked meetings still show up more often (71% vs 52%). The consistent pattern across sources: hybrid teams win. Every figure, sourced and verified: the 2026 AI SDR numbers that matter.
Why are there no independent AI SDR benchmarks?
Because the ingredients of a real benchmark don’t exist in this category: there are no shared definitions of “reply rate” or “meeting booked”, vendor-published numbers are drawn from self-selected samples of the accounts that stayed, and no independent body audits anyone’s results — unlike information retrieval, where NIST’s TREC programme has provided shared test sets and pooled, judged evaluation since 1992, or ML systems, where MLCommons maintains the MLPerf benchmark suites. The practical substitute is buyer-run: agree metric definitions in writing, pilot on your own list with a holdout comparison, and verify outcomes in your own CRM and calendar rather than the vendor’s dashboard. Why the published numbers mislead, and the full evaluation playbook: why there are no trustworthy AI SDR benchmarks.
Do visitors from AI search convert better than search-engine visitors?
Yes, on every credible dataset we could verify. Ahrefs’ first-party data (June 2025) found AI-search visitors were about 0.5% of its traffic but 12.1% of signups — roughly 23x the organic conversion rate — and Similarweb’s April–May 2026 panel ranks ChatGPT referrals (~7.1% conversion) above every channel except paid search. The volume is still small; the intent is not. The full data story: do AI-search visitors convert better?
Is ChatGPT still where most AI referral traffic comes from?
Yes, but its lead is shrinking fast. Goodie’s 2026 AI Search Market Share report measured ChatGPT at 89.1% of B2B AI referrals across 41 brand sites in May–August 2025; by its March–April 2026 wave, ChatGPT’s brand-averaged share had fallen to 62.6%, with Claude at 18.5%, Gemini at 10.6% and Perplexity at 7.3%. The practical consequence: an AI-visibility strategy tuned to a single engine now misses more than a third of the traffic. What’s driving the shift and what to do about it: ChatGPT’s shrinking share of AI referrals.
Do half of B2B buyers really start their research in AI chatbots?
The figure is real, but it needs its comparator. G2’s 2026 AI Search Insight Report — a March 2026 survey of 1,076 B2B decision makers across North America, EMEA and APAC — found 51% of B2B software buyers “start their research with an AI chatbot more often than Google”. That is a relative-frequency comparison between two starting doors, not evidence that half of all buying journeys begin in a chatbot — though the trend is steep: the same measure was 29% in G2’s April 2025 survey. What the number actually says, and what it changes for a vendor: half of B2B buyers now start in an AI chatbot.
What is zero-click AI search, and can a brand still win from it?
Zero-click means the answer ends the journey: SparkToro’s 2026 analysis of Similarweb panel data found 68.01% of US Google searches ended without a click in the first four months of 2026, and Ahrefs measured all AI chatbots combined at about 0.28% of total web traffic in March 2026 — so most of the value of appearing in an AI answer is the recommendation itself, not the visit. A brand wins by being named and cited inside the answer. How to do that deliberately: zero-click AI answers.
Why does a brand appear in one AI answer and vanish from the next?
Because AI answers are drawn fresh each time, not read from a fixed list. seoClarity’s tracking found ChatGPT citation volumes fell 86–94% across five markets between February and April 2026, then rebounded in May, and Profound measured only 11.0% overlap between the domains ChatGPT and Perplexity cite for identical prompts. The practical response is breadth (many citable pages) and repeated measurement rather than one hero page and one snapshot. The full mechanics: AI answer volatility.
Which websites do AI engines actually cite most?
Citations concentrate hard on a small set of trusted surfaces. 5W’s AI Platform Citation Source Index 2026 — an aggregation of six citation studies covering 680M+ citations — puts Reddit first across every major engine (~40% frequency) and finds the top 15 domains capture about 68% of consolidated citation share, while Profound’s own data has Wikipedia at 7.8% of ChatGPT’s total citations. Peec AI’s separate 30M-source analysis independently finds Reddit the #1 or #2 most-cited source on every engine it tested. For a SaaS brand that means presence on trusted third-party surfaces matters alongside owned content. Full analysis: the few sites AI engines trust, and the Reddit playbook.
How often do AI answers actually cite a source?
Rarely — but four times more often than a year ago. Similarweb’s AI search data shows citations appeared in roughly 1.6% of US ChatGPT prompts in June 2025, rising to about 6.8% by May 2026 — so even after quadrupling, more than 93% of prompts produce answers that cite nobody. The rate varies sharply by category: about 23% for travel and hospitality prompts, under 4% for professional services. Citations concentrate in retrieval modes — long, question-shaped, freshness-sensitive and comparison prompts — which is where citable pages should aim. The base rates and what they mean for AEO targets: how often AI answers actually cite a source.
Where on a page do AI engines quote from?
Mostly the top. CXL’s March 2026 analysis of 100 Google AI Overview citations found “55% of citations came from the first 30% of content, while only 21% came from the bottom 40%” — with one structural exception: a meaningful share of bottom-of-page citations came from FAQ blocks, because each question-and-answer pair works as a self-contained unit. It is a small, single-engine sample, so treat it as direction rather than law: put the answer in the first 150–200 words and open each section with its conclusion. The mechanism the engine owners document, and the fixes: front-loading for AI citation.
How do you measure AI referral traffic in GA4?
Mostly, you can’t by default — much AI-driven traffic arrives with no referrer or gets bucketed under generic Referral/Direct. Google’s default channel group now includes an “AI Assistants” channel (sources such as ChatGPT, Gemini, Deepseek, Copilot and Grok), but it does not include Perplexity and cannot see zero-referrer visits. The practical stack is three layers: GA4’s native channel, a custom channel group with a regex on session source, and server logs counting on-demand AI fetchers (ChatGPT-User, OAI-SearchBot, PerplexityBot) as a leading indicator. Step-by-step: how to actually measure AI-driven visits.
Does Google Search Console show AI search performance?
Yes — since 3 June 2026. Google’s Search Central announcement introduced dedicated Search Generative AI performance reports in Search Console, showing impressions, pages, countries, devices and dates for your URLs inside generative AI features — AI Overviews and AI Mode in Search, plus generative AI features in Discover. On rollout, the Search Console help page carries two statements side by side, and both are printed here because Google prints both: “As of August 31, 2026, we’ve rolled out these insights to all websites worldwide” and “Not all properties have access to the report, as we’re rolling out over time” (checked 4 September 2026). Two further limits: the data covers Google’s own AI surfaces only — ChatGPT, Claude and Perplexity visibility still needs log-file and referral measurement — and no dimension splits AI Mode from AI Overviews. What the report answers, what it can’t, and how to fold it into an AEO routine: Search Console’s generative-AI reports, explained.
Should we block AI crawlers in robots.txt?
Block by function, not wholesale. The owners separate training crawlers from search crawlers and user-driven fetchers, and blocking each costs something different. OpenAI’s crawler documentation says disallowing GPTBot opts a site out of training generative AI foundation models, while sites opted out of OAI-SearchBot “will not be shown in ChatGPT search answers”. Google’s crawler documentation likewise states Google-Extended controls use of content for Gemini training and grounding and “does not impact a site’s inclusion in Google Search”. A blanket block therefore trades away AI-answer visibility, not just training. The decision framework: the AI crawler allowlist for B2B SaaS; the full bot taxonomy: training bots vs on-demand fetchers.
How do I verify an AI crawler is really who it claims to be?
Never trust the user-agent string alone — scanners routinely spoof AI bot names to borrow their welcome. The major operators publish machine-readable verification data: OpenAI’s bot documentation lists published IP addresses for each of its bots (openai.com/gptbot.json, searchbot.json, chatgpt-user.json), and Google’s verification guide documents both reverse-DNS lookup and published IP ranges for its crawlers and fetchers. The two-step check: reverse-DNS the requesting IP or match it against the published JSON ranges, and treat any “GPTBot” or “ChatGPT-User” arriving from an unlisted network as an impostor. The per-vendor walkthrough: verifying AI bot traffic with rDNS and IP ranges.
What is “share of model” in AI search?
Share of model is how often — and how favourably — a brand appears in AI assistants’ answers across a set of buyer prompts, measured by repeatedly running the same prompts and logging mentions, citations and recommendations. The term entered the vocabulary via Jellyfish’s trademarked Share of Model™ platform in 2024, and rank-position thinking doesn’t transfer: SE Ranking found repeat runs of the same 10,000 queries in Google’s AI Mode shared on average just 9.2% of cited URLs, so visibility is a sampled rate, not a fixed position. How to measure it, including with no tooling budget: share of model, explained.
What is entity consistency and why does it matter for AI search?
Entity consistency means keeping the facts about your brand — name, what you do, who it’s for, key claims — identical everywhere AI systems read them: your own site, directories and third-party mentions. HubSpot’s 2026 AEO trends article lists it among the year’s answer-engine-optimisation trends, warning that inconsistent facts across your site, directory listings and third-party mentions make your authority questionable and can reduce citation likelihood. Answer engines reconcile what they read about an entity before naming it in an answer, so a description that drifts from page to page is a citation handicap. How to audit and fix yours: entity consistency for AI search.
How do I structure content so AI buying agents can parse it?
Lead with the answer, then make everything extractable: an answer-first capsule near the top, question-shaped headings in a clean sequential hierarchy, tables for comparable facts, entity facts kept identical on every page, Article and FAQPage schema, and no important content locked behind client-side JavaScript — agents extract answers rather than rank pages, so a page they can’t parse is a page they can’t cite. The llms.txt proposal standardises a single /llms.txt file to help agents use a website — cheap to serve, though no major engine documents reading it. Every pattern, practised as it’s described: writing for agentic parsing.
Do AI engines actually read llms.txt?
No engine says so. None of the four companies whose engines dominate AI answers — OpenAI, Anthropic, Google or Perplexity — documents consuming llms.txt from third-party websites; their crawler docs name exactly one control file, robots.txt. Google’s AI features documentation is explicit: “You don’t need to create new machine readable files, AI text files, or markup to appear in these features.” The AI labs do publish llms.txt for their own docs sites, but producing a courtesy file is not consuming yours. Serving one is cheap; treat claims that it drives AI citations as unproven. The owner-by-owner evidence: does any AI engine actually read llms.txt?
Does a B2B website need an MCP server?
For most marketing sites, not yet. The Model Context Protocol is a real open standard for connecting AI applications to external systems — now governed under the Linux Foundation’s Agentic AI Foundation — but it is authenticated, developer-driven infrastructure, and AI buying agents don’t crawl the web looking for MCP endpoints on brand sites. What moves the needle for a marketing site today is schema and parseable answer-shaped content; pilot an MCP server if your product is an API or platform. The full assessment: does your site need MCP for AI buying agents?
How do I prepare my website for AI buying agents that browse and fill forms?
Work three fronts. Forms: standard HTML inputs with proper labels and autocomplete attributes, so an agent completing a buyer’s details can parse the fields the way a browser’s autofill does. Entry points: schema and answer-shaped pages that state plainly what you sell and how to start. Bot-blocking: rethink the blanket wall — OpenAI’s bot documentation distinguishes its crawlers (GPTBot, OAI-SearchBot) from ChatGPT-User, a fetcher that is “not used for crawling the web in an automatic fashion” but visits a page when a person asks — so a CAPTCHA or bot-wall that stops everything non-human also turns away an agent acting for a real buyer. That trade-off deserves a decision, not a default. The full readiness audit: preparing your site and funnel for agentic buyers.
Can I buy products inside ChatGPT?
Mostly not any more — checkout has moved back to the merchant. OpenAI’s Instant Checkout launched in September 2025, letting US users buy from US Etsy sellers inside the chat; in March 2026 OpenAI announced the initial version “did not offer the level of flexibility” it aspired to and shifted merchants to their own checkout experiences while ChatGPT focuses on product discovery. The underlying Agentic Commerce Protocol (developed with Stripe, specification public on GitHub) survives, and OpenAI’s commerce documentation now centres on product feeds that let ChatGPT index catalogues — the discovery data outlived the transaction plumbing. What that arc teaches B2B SaaS teams, where the “checkout” is a demo booking: the Agentic Commerce Protocol for B2B SaaS.
Should an AI agent connect to a CRM natively, through Zapier or via API?
Match the pattern to the load. Middleware such as Zapier is quick to stand up, but Zapier’s own documentation puts polling intervals at 1 to 15 minutes depending on plan — fine for prototyping, too slow for an agent that needs mid-call CRM lookups. Native connectors handle standard objects well; direct API integrations (webhook-driven) are what real-time write-back and custom objects usually demand. Autonomous agents stress integrations harder than form-fill tools because every conversation writes activity history, and a failed write-back corrupts follow-up pacing. Decision framework: native vs Zapier vs API.
Do the Gmail bulk-sender rules apply if we send fewer than 5,000 emails a day?
Yes, in a lighter form. Google’s email sender guidelines set requirements for all senders: SPF or DKIM authentication on the sending domain, valid forward and reverse DNS (PTR) records for the sending domain or IP, TLS for transmission, RFC 5322 message formatting, and spam rates in Postmaster Tools kept below 0.3%. Full DMARC is only required above roughly 5,000 messages a day — and there, Google states the enforcement policy “can be set to none”. The outbound checklist: the 2026 bulk-sender rules.
How do I verify Perplexity and Claude bot traffic, not just OpenAI and Google?
Both publish IP lists, so the same two-step check works. Perplexity’s bot documentation names PerplexityBot (indexing) and Perplexity-User (user-initiated fetches) and publishes ranges at perplexity.ai/perplexitybot.json and perplexity-user.json. Anthropic’s crawler article names ClaudeBot, Claude-User and Claude-SearchBot and links a published IP list, stating that “If a crawler has a source IP address on this list, it indicates that the crawler is coming from Anthropic”. Match the IP first, then believe the user-agent: verifying AI bot traffic.
What is Web Bot Auth, and will AI agents start proving their identity cryptographically?
It is the cryptographic alternative to IP allowlists. Cloudflare’s Web Bot Auth documentation describes using “cryptographic signatures in HTTP messages” to verify a request comes from an automated bot: the agent publishes Ed25519 keys at /.well-known/http-message-signatures-directory and attaches Signature, Signature-Input and Signature-Agent headers. It rests on IETF drafts (draft-meunier-web-bot-auth-architecture, draft-meunier-http-message-signatures-directory), so it is standards work in progress — but it is where agent identity is heading.
Does a hit from ChatGPT-User mean our page was cited in an answer?
No. OpenAI’s crawler documentation says ChatGPT-User fires when a user asks ChatGPT or a CustomGPT a question and it visits a web page, and for GPT Actions — and it states that “ChatGPT-User is not used to determine whether content may appear in Search”. So a fetch proves your page was opened inside someone’s session, not that it was quoted, and not that you rank. Count citations separately from crawls: training bots vs on-demand fetchers.
Does a B2B SaaS need a product feed for ChatGPT?
Almost certainly not. OpenAI’s product feed specification is built for retail catalogues — product identifiers, variants, weights, shipping methods and return windows — fields a software subscription cannot honestly populate. For B2B software the discovery surface is still crawlable pages, clear capability and packaging explanations, and consistent structured data. Read the agentic-commerce arc before building anything: the Agentic Commerce Protocol for B2B SaaS.
What should an AI sales agent write back to the CRM after every conversation?
Six things, minimum: the outcome (booked, callback, not interested, wrong number), a timestamped summary or transcript, the consent and disclosure state, the channel and identifier used, objections raised, and the next scheduled touch. Autonomous agents pace their own follow-up from that record, so a silent write-back failure does not merely dent reporting — it corrupts the sequence. Integration patterns: AI agent CRM integration and native vs Zapier vs API.
Why do AI answer engines cite pages that don’t rank in Google’s top 10?
Because the engine is not answering your query — it is answering several. Google’s own AI features documentation states that both AI Overviews and AI Mode may use a “query fan-out” technique — “issuing multiple related searches across subtopics and data sources — to develop a response” — so the pages that win are often the ones ranking on the sub-queries. Ahrefs has measured the gap twice. Its 11 August 2025 study of a 15,000-prompt dataset found that “only 12% of links cited by ChatGPT, Gemini, and Copilot appear in Google’s top 10 results for the same prompt”, with Perplexity the outlier at 28.6%. Its 2 March 2026 update, across “863K keyword SERPs, and a grand total of 4M AI Overview URLs”, found “37.9% of URLs cited in AI Overviews also appeared within the first 10 blocks” — down from roughly 76% in its July 2025 run. Both are single-vendor samples from one tool’s index, so read them as direction, not law. What to do with the gap: rank versus AI citation overlap.
Our AI crawler traffic spiked — is that a good sign?
Not until you split it by status code. A 200 means you actually served a fresh copy; RFC 9110, section 15.4.5 defines 304 as indicating “that a conditional GET or HEAD request has been received and would have resulted in a 200 (OK) response if it were not for the fact that the condition evaluated to false” — the bot already held a valid copy and was only revalidating. A spike made mostly of 304s is a re-check loop, not new interest, and it costs you almost no bandwidth. Then check the requester is who it claims: OpenAI’s crawler documentation publishes per-bot IP lists (openai.com/gptbot.json, searchbot.json and chatgpt-user.json), and user-agent strings are trivially spoofed. Finally, remember a fetch is not a citation. The full log-reading method: AI crawler logs and 304 revalidation.
Trust, compliance and deployment
Is AI cold calling legal?
Yes, where it follows the same rules as human calling — the AI gets no exemption. In Australia that means ACMA’s telemarketing rules (permitted hours, caller identification, honouring opt-outs) and the Do Not Call Register; in the US, the TCPA imposes stricter consent requirements for automated calls. Reputable operators announce recording up front and act on every opt-out immediately. Build compliance into the agent’s rules, not the rep’s memory.
Does Australia’s Do Not Call Register apply to AI voice agents?
Yes — by definition, not by analogy. Section 4 of the Do Not Call Register Act 2006 defines a voice call to include “a call that involves a recorded or synthetic voice”, and section 5 makes a voice call with a sales purpose a telemarketing call — so an AI agent calling Australian numbers is a telemarketer, with no AI carve-out. Practically: wash every list against the Register within the 30 days before calling, keep to permitted hours, identify the caller and act on every termination request. What ACMA enforcement actually looks like, with the penalty maths: the Do Not Call Register and AI voice agents.
Do we need to register our SMS sender ID in Australia?
If you send SMS under a brand name, yes. From 1 July 2026, ACMA’s SMS Sender ID Register requires branded (alphanumeric) sender IDs to be registered, and SMS sent using unregistered sender IDs are now being labelled “Unverified” by carriers — a credibility hit no legitimate outreach programme wants. Any AI outreach that texts under your brand should be registered before its next campaign. Australian channel picks: best AI voice agents for sales calls in Australia. The registration steps, timeline and what the register means for AI-driven SMS outreach: Australia’s SMS Sender ID Register, explained.
Do we have to tell people they’re talking to an AI?
Increasingly, yes. In the US, the FCC ruled in February 2024 that AI-generated voices in robocalls count as “artificial” voices under the TCPA, which means prior express consent rules apply. In the EU, Article 50 of the AI Act requires telling people they are interacting with an AI system unless it is obvious, with general application from 2 August 2026. Beyond the law, upfront disclosure measurably protects trust. Jurisdiction by jurisdiction: outreach compliance for AI agents.
Does US law require disclosing that a sales call uses AI?
Not yet as a stand-alone duty — but AI voice calls are already regulated today. The FCC’s February 2024 declaratory ruling means AI-generated and cloned voices count as “artificial” voices under the TCPA, so the existing rules — prior express consent and caller identification — apply to AI sales calls right now. A dedicated duty to disclose that a call uses AI is, as of August 2026, only proposed: the FCC adopted NPRM 24-84 in August 2024, which would require disclosure at the start of a call, but the rule has not been finalised. What’s in force versus what’s still pending: FCC NPRM 24-84 and AI call disclosure, explained.
Does Colorado require telling consumers they’re talking to an AI?
Not under its AI Act. The original Colorado AI Act’s AI-interaction disclosure duty (SB 24-205) never took effect — the law was repealed and re-enacted on 14 May 2026 as SB 26-189, a narrower automated-decision-making framework effective 1 January 2027 with no general AI-interaction disclosure duty. A separate Chatbot Safety Act (HB 26-1263) does require operators of publicly available conversational AI services to maintain a protocol informing users they’re interacting with AI, with operator duties from 1 January 2027; the Attorney General’s proposed rules (filed 11 August 2026) are expected to sharpen its scope. What survived, what didn’t and what sales teams should do: Colorado’s rewritten AI Act.
Is it legal to use a cloned voice on business calls?
Yes, with layered consent — and unconsented cloned-voice robocalling is unlawful. The FCC’s February 2024 declaratory ruling confirmed AI-generated and cloned voices count as “artificial or prerecorded voice” under the TCPA, so US calls need prior express consent (written consent for telemarketing), caller identification and opt-out. In Australia, voice calls fall under the Do Not Call Register Act 2006 and the telemarketing Industry Standard rather than the Spam Act. You also need the voice owner’s licence to clone their voice. Full breakdown: voice cloning for business calls.
When do Australia’s automated decision-making disclosure rules start?
From 10 December 2026, organisations covered by the Privacy Act must state in their privacy policy the kinds of personal information used in — and the kinds of decisions made using — automated decision-making that could significantly affect individuals’ rights or interests, under the Privacy and Other Legislation Amendment Act 2024. It is a disclosure duty, not a prohibition; the OAIC ran a consultation in May–June 2026 and states it intends to release final guidance by September 2026. Step-by-step preparation: writing an ADM transparency statement; what else the Privacy Act review has queued for outbound teams: the Privacy Act review, mapped; the broader picture: AI agent data sovereignty in Australia.
What happens when an AI agent says something wrong?
Plan for it contractually and technically — the liability is established: in Moffatt v Air Canada (2024), a Canadian tribunal held the airline liable for a policy its chatbot invented. The mitigations: hard boundaries (agents never invent pricing or terms), instant human handoff on sensitive conversations, and complete conversation logs so every interaction is auditable.
Do autonomous sales agents need a human approving every message?
No — but they need defined gates. The 2026 operating consensus is human-in-the-loop: agents run routine outreach autonomously inside written guardrails and escalate to a person when confidence drops or stakes rise (pricing, legal terms, sensitive accounts). Article 14 of the EU AI Act requires that high-risk AI systems be designed for effective human oversight — sales outreach generally isn’t classed high-risk, but the same architecture (override authority, escalation, audit logs) is what buyers now expect. The full playbook: human-in-the-loop controls for autonomous sales agents; the when-to-escalate mechanics: confidence thresholds.
What guardrails should an autonomous AI sales agent have?
Three layers at minimum: written permissions and prohibitions (what the agent may do, and what it must never do — invent pricing, make legal claims, contact opted-out prospects), explicit escalation triggers that hand the conversation to a human, and an audit trail recording every action the agent takes. On the engineering side, OWASP’s guidance on Excessive Agency says what security teams have always said: grant the agent the least privilege its task needs, and require human approval for high-impact actions. Australia’s Voluntary AI Safety Standard makes meaningful human oversight Guardrail 5. How to write each layer, with worked examples: how to write guardrails for autonomous AI agents.
What observability should an AI agent platform expose?
Three layers: reasoning or decision traces (why the agent chose an action), tool-use and action logs (what it actually did — calls, messages, CRM writes), and outcome attribution (which conversations produced booked meetings or revenue). Add conversation transcripts and guardrail-trigger logs and you have both a debugging surface and audit evidence. OpenTelemetry’s generative-AI semantic conventions — still marked “Development” — are emerging as the vendor-neutral way to capture agent traces. The full buyer’s checklist: AI agent observability.
Can a prospect trick an AI sales agent with prompt injection?
It’s a real risk class. Sales agents read untrusted input all day — email replies, live speech, web pages — and OWASP ranks prompt injection the #1 risk for LLM applications. The UK National Cyber Security Centre cautions the problem may never be totally mitigated, so ask vendors about layered defences — least-privilege tool access, human approval gates for sensitive actions, input and output filtering, and logging — rather than accepting claims it has been solved. The buyer’s question list: prompt injection and the OWASP risks.
When should an AI sales agent escalate to a human?
When the cost of a wrong action outweighs the cost of a pause — not simply when a confidence score dips. Production teams combine signals: an explicit request for a person, sentiment degradation, out-of-scope or compliance-sensitive topics, and actions that are hard to reverse. Australia’s Voluntary AI Safety Standard makes “enable human control or intervention in an AI system to achieve meaningful human oversight” one of its ten guardrails. Escalation design in full: confidence thresholds for AI sales agents.
Can Zian’s agents run on our own infrastructure?
Yes — Zian supports private model deployment on customer infrastructure for organisations that can’t send conversation data to shared clouds (banking, government, healthcare-adjacent). Integrations cover HubSpot, Salesforce, HighLevel and Zapier either way. Details: private AI deployment for sales agents.
Does this only work for sales teams?
No — the same agent architecture runs beyond sales. Zian’s digital team includes a 24/7 multilingual customer support agent (30+ languages), plus niched agents for recruitment screening, government and council surveys, university admissions, construction project coordination, IT support and bank KYC onboarding.
What integrations does Zian support?
Native CRM integrations for HubSpot, Salesforce and HighLevel, plus Zapier and a full API for everything else — agents read and write to your existing pipeline rather than creating a parallel one. The full matrix: features and integrations; setup patterns and what to sync: CRM integrations for AI agents.
What can the agents actually do on a call or in a conversation?
Live phone, SMS, email and WhatsApp outreach in 30+ languages (voice cloning supported), with the ability to research prospects and query the web and your knowledge base mid-conversation — so answers come from your data, not generic patter. Capabilities in detail: features and integrations.
How long has the technology behind Zian been around?
The platform’s conversational-AI lineage runs back to 2018, through multi-channel expansion, private enterprise deployments and a select enterprise rollout in 2025 — this is a productisation of years of deployed agent work, not a wrapper built last quarter. The history, year by year: 2018 foundation and 2025 enterprise rollout.
Is there a free plan?
Yes — the Intel + Widgets tier is free forever, and paid tiers scale up from there. During the current beta, access to all tiers is gated through the partner application.
Did the EU AI Act’s high-risk obligations start on 2 August 2026?
No. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), published in the Official Journal on 24 July 2026, deferred the Annex III high-risk obligations to 2 December 2027 and Annex I product-embedded obligations to 2 August 2028. What did apply from 2 August 2026 is the Article 50 transparency duty — people interacting with an AI system must be told it’s AI unless that’s obvious — alongside the earlier prohibitions and GPAI rules. Full breakdown: what actually applies under the EU AI Act as of August 2026.
What does Article 50 of the EU AI Act require from AI sales and support teams?
Two duties, both applying from 2 August 2026: people interacting with an AI system must be told it’s AI unless that’s obvious, and AI-generated (synthetic) content must be marked in a machine-readable format and detectable as artificially generated. The European Commission’s Article 50 FAQ says the unless-obvious exception is to be interpreted restrictively — the test is whether an average person, reasonably well-informed and observant, would realise they’re talking to AI — so a convincing voice or chat agent should disclose rather than rely on it. The recent deferral didn’t touch this duty: Regulation (EU) 2026/1744 pushed the Annex III high-risk obligations to 2 December 2027, but Article 50 transparency applies now. The team-by-team checklist: the Article 50 compliance checklist.
What are the Gmail and Outlook bulk-sender rules for outbound email?
Since February 2024, Google’s email sender guidelines require senders of around 5,000+ daily messages to Gmail to authenticate with SPF, DKIM and DMARC, offer one-click unsubscribe, and keep spam-complaint rates below 0.3% (Google recommends under 0.1%) — with enforcement ramping up from November 2025. Microsoft applied matching authentication requirements to outlook.com, hotmail.com and live.com from May 2025, rejecting mail that fails them with error 550 5.7.515. The rules and an AI-outbound checklist: the 2026 bulk-sender crackdown.
What should an AI-to-human handoff include?
A handoff packet, not a transcript dump: who the prospect is, consent and disclosure state, a short conversation summary, objections already raised, and the next-step commitment — written back to the CRM so the human picks up where the AI left off. Zendesk’s 2026 CX Trends research (11,000+ respondents, 22 countries) found 74% of consumers get frustrated when they have to repeat information. Design guide: the AI-to-human handoff.
Do AI sales agents have to say they’re AI on a phone call?
In many places, yes — and the list is growing. In the US, the FCC’s February 2024 declaratory ruling treats AI-generated voices as “artificial voice” calls under the TCPA (consent and identification duties apply), and NPRM 24-84 — which would require explicit AI disclosure at the start of a call — remains a proposal as of August 2026. State law adds more: Maine’s 10 M.R.S. §1500-DD requires clear and conspicuous notification when an AI chatbot could mislead a consumer into thinking it’s human, Utah requires disclosure on request (proactively in regulated high-risk interactions), and California’s PUC §2874 covers artificial-voice announcements. In the EU, Article 50 of the AI Act applies from 2 August 2026. Scripts and a full jurisdiction table: AI-call disclosure scripts.
What hours can an AI agent make telemarketing calls in Australia?
The same hours as any telemarketer: under the Telemarketing and Research Calls Industry Standard, ACMA’s permitted hours for telemarketing calls are 9:00am–8:00pm weekdays and 9:00am–5:00pm Saturdays, with no calls on Sundays or national public holidays (research calls have slightly wider windows). Calling line identification must be enabled, and numbers must be washed against the Do Not Call Register. The full picture — number types, CLI rules and caller-ID reputation — is in our guide to getting an Australian number for your AI voice agent.
When does Australia’s Telemarketing Standard sunset, and what should AI callers do?
The Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 — the instrument behind Australia’s permitted calling hours, caller-identification and call-termination rules — is scheduled for automatic repeal on 1 April 2027: the Federal Register of Legislation records the sunset under section 50 of the Legislation Act 2003. Before then the ACMA must remake, replace or let it lapse; as at August 2026 no replacement consultation has opened, so any claim about a successor’s content is speculation. The practical position: comply fully with the 2017 Standard now — it binds until at least 1 April 2027 — and watch ACMA’s consultations page, because a remake drafted in the AI era could revisit how synthetic-voice callers identify themselves. The three possible outcomes and a preparation checklist: the Telemarketing Standard sunset, explained.
What is STIR/SHAKEN and does Australia use it?
STIR/SHAKEN is the US caller-ID authentication framework: the originating voice provider cryptographically signs each call with an A, B or C attestation level asserting how confident it is in the caller’s right to the number, and the terminating provider verifies the signature before the phone rings. Australia has no STIR/SHAKEN mandate — instead, ACMA has registered the C661:2022 Reducing Scam Calls and Scam SMs industry code, which requires telcos to identify, trace and block scam calls and SMS. For AI voice agents the practical advice is the same in both countries: call from numbers you control, ask your carrier how your calls are attested, and treat number reputation as an asset. The full comparison: STIR/SHAKEN and what Australia has instead.
What is branded calling (Rich Call Data) and does it work in Australia?
Branded calling puts your business name, logo and call reason on the recipient’s screen — technically, Rich Call Data (RCD) carried with the call and tied to its STIR/SHAKEN attestation, standardised in RFC 9795 and RFC 9796 (July 2025). The US has a live ecosystem: CTIA’s Branded Calling ID programme delivers vetted name, logo and call reason over cryptographically signed calls. Australia has neither STIR/SHAKEN nor an RCD ecosystem — caller-ID trust rests on the C661:2022 Reducing Scam Calls and Scam SMs industry code, which requires telcos to identify, trace and block scam traffic — so for Australian AI voice campaigns the practical play is number hygiene: consistent caller line identification, numbers you control and a reputation you protect. What exists, what’s marketing and what to do in each country: branded calling for AI voice agents.
What should an enterprise check before buying an AI sales agent platform?
Four tiers: identity and access (SAML SSO, SCIM provisioning, role-based access control), data protection (encryption, contractual data residency, sub-processor transparency), governance (immutable audit logs, third-party attestations — a SOC 2 report is an AICPA-defined examination of a service organisation’s controls, so ask for the report and its scope rather than the badge), and operational maturity (SLAs, incident history, observability of what the agent actually did). Private model deployment on your own infrastructure is an architectural alternative to certificate-led assurance. The line-by-line version with vendor questions: the enterprise readiness checklist.
Does the EU AI Act’s Article 50 disclosure duty apply to B2B calls?
Yes. The European Commission’s Article 50 FAQ frames the duty around interaction with natural persons — whether consumers, professionals or other users — so ringing a procurement manager carries the same obligation as ringing a consumer. There is no business-to-business carve-out. The only exception is where it would be obvious to a reasonably well-informed, observant person that they are dealing with AI, and the Commission reads that narrowly. Checklist: the Article 50 compliance checklist.
How do we mark AI-generated content as machine-readable under Article 50?
Article 50(2) requires synthetic output to be marked in a machine-readable format and detectable as artificially generated. Rather than invent your own scheme, the ready-made route is the European Commission’s Code of Practice on Transparency of AI-generated Content, published on 10 June 2026: the Commission and the AI Board confirmed it is “an adequate voluntary tool to demonstrate compliance with the AI Act transparency obligations”, and the Commission reports roughly 190 organisations had signed it by the end of July 2026.
Has the FCC finalised its AI call-disclosure rules?
No — as at 26 August 2026 they remain a proposal. FCC 24-84, adopted on 7 August 2024 in CG Docket No. 23-362, is a Notice of Proposed Rulemaking in which the Commission says it will “propose to define AI-generated calls and propose new rules that would require callers disclose to consumers when they receive an AI-generated call”. Proposing is not binding. What binds now is the February 2024 declaratory ruling treating AI voices as artificial under the TCPA. Full analysis: what NPRM 24-84 would change.
What must a US artificial-voice call say at the start, even without new AI rules?
Identity first, contact number second. 47 CFR §64.1200(b) requires all artificial or prerecorded voice messages to state clearly, at the beginning of the message, the identity of the business responsible for initiating the call — under its registered business name — and to state a contact telephone number during or after the message, one that lets a person make a do-not-call request in business hours. Telemarketing messages also need an automated opt-out mechanism. Wording that satisfies this: AI-agent disclosure scripts.
Can an AI agent screen job candidates lawfully?
Only with the local rules built in. New York City’s Local Law 144 requires an automated employment decision tool to have been subject to a bias audit within one year of the use of the tool, requires information about that audit to be publicly available, and requires notice to candidates — the Department of Consumer and Worker Protection began enforcing the law and rule on 5 July 2023. In the EU, employment-related systems sit in Annex III of the AI Act, whose high-risk obligations Regulation (EU) 2026/1744 deferred to 2 December 2027. Screening is higher-stakes than a sales call, so design the agent to gather structured answers and hand ranking to a human. Detail: AI candidate screening compliance and recruitment screening agents.
Can an AI agent take a customer’s card number over the phone to fix a failed payment?
No — and a well-built one will refuse to. The moment card data enters a call, your recordings, transcripts and storage fall inside PCI DSS scope. The PCI Security Standards Council’s information supplement Protecting Telephone-based Payment Card Data states that “It is a violation of PCI DSS Requirement 3.2 to store any sensitive authentication data, including card validation codes and values, after authorization even if encrypted”, and its call-centre guidance includes “Ensuring that payment card information is never sent over an unencrypted, end-user messaging medium such as chat, SMS (Simple Messaging System)/text or e-mail, or other non-encrypted communication channels” — which rules out the SMS fallback an agent might otherwise reach for. Note what that document is: the Council says “the information provided here does not replace or supersede PCI DSS requirements”. The safe pattern is that the agent never asks for, repeats or stores a number — it identifies itself, explains the failure, and sends the customer to the payment provider’s own hosted update page. How that fits a recovery sequence: voice and SMS failed-payment recovery.
How many times can we retry a declined card, and who sets the limit?
Two different parties set two different limits and they are routinely confused. The card network sets the outer bound: Adyen’s mapping of raw responses to Visa system integrity fee categories documents four Visa decline categories, and for category 1 — “Issuer will not approve” — it says “Do not retry the transaction. Visa charges an excessive retry fee if you retry the transaction”, while for categories 2, 3 and 4 “You can retry the transaction up to 15 times in a 30-day period.” Your processor then sets a tighter default: Stripe’s automate payment retries documentation says “The recommended default setting is 8 tries within 2 weeks”, and a custom schedule allows “up to three retries”. Two caveats. Adyen’s own help-centre article describes the same Visa rule differently — that “the 16th and consecutive retries in a 30-day rolling period will be assessed the excessive retry fee” — and publishes the charge by region (EU, US, CA, APAC, CEMEA and LATAM rows, with a separate cross-border rate). And Visa’s underlying bulletin is not published publicly, so confirm the count with your own acquirer rather than a blog. An AI agent should follow the schedule your processor already runs, not invent one. Sequence design: dunning by voice and SMS.
Can we call someone who abandoned our signup form?
Only on a contact detail they typed in themselves, and only with a lawful basis you can point to. Under APP 7.2, the OAIC’s APP 7 guidelines permit direct marketing where the organisation collected the information from the individual, “the individual would reasonably expect the organisation to use or disclose the personal information for that purpose”, the organisation provides a simple way to opt out, and the individual has not opted out. The OAIC adds that the reasonably-expect test “is an objective test that has regard to what a reasonable person, who is properly informed, would expect in the circumstances” and that “It is the responsibility of the organisation to be able to justify its conduct.” The ACMA sets the bar lower again: its statement of expectations on consent says do not add contact details to marketing databases without consent, “for example, if a consumer visits a website or sends an email to a business it is unlikely to constitute consent to inclusion on a marketing list or in a marketing database”. Working rule: one attempt per abandonment event, on the detail they entered, referencing the thing they started — and screen the number against the Do Not Call Register first. The full sequence: signup abandonment recovery.
Can we contact a customer who has already cancelled?
Yes, but a win-back is a marketing message and is regulated as one. The ACMA’s telemarketing and e-marketing common issues page is explicit: “We have had complaints about alleged e-marketing messages sent by businesses attempting to regain customers who have cancelled subscription services (retention messages). These messages are commercial and must comply with the Spam Act.” Its statement of expectations then closes the two doors people try: rely on inferred consent “only where there is a clear, current or ongoing relationship with the individual and the goods or services being marketed are directly related to that relationship”, and do not lean on stale permission — its example is “consent to receive telemarketing that is more than 3 months old becomes stale unless a consumer has agreed to a longer period under terms and conditions”. It also says do not re-contact people who unsubscribed to encourage them to resubscribe. Read that document for what it is: the ACMA states “This statement is not legal advice nor is it a definitive compliance guide to the Rules. It is an outcome-focused guide to better practice”. Designing around it: win-back sequences for churned subscribers.
What should an onboarding agent never ask a new user for?
Credentials of any kind — a password, a one-time code, or a live API key. Route the user to your own settings screen or an OAuth flow instead. Stripe’s API keys documentation explains why: “Only publishable keys are safe to expose outside your application’s back end”, and its handling rules include “Don’t put keys in source code or configuration files checked into version control” and “Don’t share keys over email, chat or other unencrypted channels” — a chat thread or a call transcript is exactly such a channel, and unlike a person it is retained and indexed. The second thing to get right is disclosure: the European Commission’s Article 50 FAQ says the unless-obvious exception is to be interpreted restrictively, so an onboarding agent should say it is AI rather than assume a new user has worked it out. What the agent should chase instead — first value, not form fields: onboarding and activation agents.
Choosing a vendor
How do we run a fair head-to-head trial of AI voice agent vendors?
Same list, same offer, same calling hours, same definition of success — then compare booked and held meetings, not call minutes. Split the list randomly rather than handing each vendor a different segment, run both through at least two full follow-up cycles, and log escalations, hang-ups and compliance stops alongside the wins. Decide the metric before the pilot starts: measurement is a distinct function in NIST’s AI Risk Management Framework, which is organised into Govern, Map, Measure and Manage and is explicitly intended for voluntary use. Pricing models differ enough to distort a naive comparison, so normalise on cost per held meeting. A vendor demo tests sales engineering, not your data. Criteria first: best AI sales agent platforms in 2026.
What does a vendor actually mean when it says it has proprietary AI?
Usually the layer around the model rather than the model itself. Ask which foundation model answers the call and you will often find a third-party one: Retell AI’s API reference documents a model parameter whose selectable values are GPT, Claude and Gemini variants, defaulting to gpt-4.1, and Vapi’s data-flow documentation lists OpenAI, Anthropic, Azure OpenAI, Google Gemini and Groq among the language-model providers it routes to. That is not dishonest — orchestration, routing, telephony handling and optimisation logic are real engineering — but it is a different claim from owning the weights. Make the vendor name which part is theirs, then evaluate that part.
Will our call data be used to train the vendor’s models?
Ask about the whole chain, not just the vendor. Most platforms sit on foundation-model APIs whose defaults are already restrictive: OpenAI’s data-controls documentation states that data sent to the OpenAI API is not used to train or improve OpenAI models unless you explicitly opt in, and Anthropic’s privacy centre states that by default it will not use inputs or outputs from its commercial products to train its models. The open question is the layer in between — your vendor’s own recordings, transcripts and evaluation sets. Get retention periods, deletion rights and any training opt-out written into the contract rather than confirmed in a sales email.
Is the vendor’s learning scoped to our account or shared across customers?
It matters more than it sounds. If a platform improves by training on pooled customer conversations, your objection handling and prospect data become part of a shared asset — and models can memorise. Carlini and colleagues, in Extracting Training Data from Large Language Models, extracted hundreds of verbatim text sequences from GPT-2, which makes cross-account training a governance question rather than a theoretical one. Ask three things: is optimisation per-tenant, does any of our data cross the account boundary, and can we opt out. On Zian, PrecisionPitch AI™ split-tests against your own success outcomes, and private model deployment is available where the boundary has to be physical.
Where do our call recordings physically live?
Two separate answers: where the recording is stored, and where the audio was processed on the way. Vapi documents that recordings, transcripts and call logs sit on its infrastructure by default, with an option to upload them to your own S3, Google Cloud Storage, Cloudflare R2, Supabase or Azure bucket. Telephony adds a second region: Twilio lets you select a Region — US, Ireland or Australia — but its own documentation warns that during the initial rollout it does not guarantee all data will remain within your selected Region. For Australian entities, sending it offshore engages APP 8, and under section 16C of the Privacy Act you stay accountable for the overseas recipient.
Is fine-tuning, prompt engineering or RAG the right way to make an agent sound like us?
Start with the cheapest thing that works. OpenAI’s model-optimisation guide says the prompt engineering process may be all you need for a use case, and positions fine-tuning for consistent formatting, handling novel inputs, and training a smaller, cheaper, faster model to excel at a particular task. Retrieval is the third route: Lewis and colleagues introduced retrieval-augmented generation in 2020 as combining pre-trained parametric and non-parametric memory for language generation — in sales terms, looking facts up at call time instead of baking them into weights. Because product details and availability change weekly, retrieval usually beats fine-tuning for accuracy. Zian’s agents query the web and your knowledge base mid-conversation: features and integrations.
What should we ask an AI calling vendor in a regulated industry?
Regulated buyers inherit their vendor’s failures, so borrow the regulator’s question list. APRA’s Prudential Standard CPS 230, in force from 1 July 2026 for Australian banking, insurance and superannuation entities, requires them to identify material service providers and keep a register of them, run due diligence before entering a material arrangement, and hold a legally binding agreement covering service levels, data ownership, audit access and termination, with APRA able to access documentation. Those map cleanly onto AI voice: who are the sub-processors, where is our audit right, what happens on exit, and can we get the data back. Long form: the AI voice vendor security questionnaire.
Do vendor-published comparison pages tell us anything useful?
They tell you what that vendor believes it wins on. The axes are chosen by the party being compared, the rival’s feature set is usually a snapshot taken months ago, and pricing tables go stale fastest. That does not make them worthless — read them for the criteria, then verify every row against the competitor’s own documentation. Comparative claims are not a free-for-all either: the ACCC states that any information or claim a business provides about its products or services must be accurate, truthful and based on reasonable grounds, and that it makes no difference whether a business intends to mislead. That applies to our pages too. Treat any vendor comparison as a hypothesis and test it on your own list.
What documentation does Texas TRAIGA expect, and where does NIST AI RMF fit?
Texas HB 149, the Texas Responsible Artificial Intelligence Governance Act, was signed on 22 June 2025 and took effect on 1 January 2026. The part buyers care about is section 552.105(e), which makes a defence available where the defendant substantially complies with the most recent version of NIST’s Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, or another nationally or internationally recognised AI risk management framework, together with an internal review process. That turns a voluntary framework into evidence worth keeping — so keep the artefacts, not just the intention. Documentation checklist: TRAIGA and the NIST AI RMF.
What do government buyers ask about AI agents in procurement?
More than security. Australian non-corporate Commonwealth entities operate under the Digital Transformation Agency’s Policy for the responsible use of AI in government, version 2.0, effective 15 December 2025, with mandatory requirements covering accountable officials, transparency statements, a strategic approach to AI adoption, use-case accountability, internal use-case registers, staff training and use-case impact assessment. The Standard for AI transparency statements then requires agencies to publish, on a public-facing site, why they use AI, a classification of where the public may interact with or be significantly impacted by AI without human review, and how effectiveness is monitored. A vendor who cannot supply that detail leaves the buyer with the gap. Our question list: government AI agent procurement.
What happens to our AI agent when the model behind it is retired?
It stops working on a date the model provider picked, so ask your vendor which model answers the call and what notice it passes on. The providers publish their own clocks. Anthropic’s model deprecations page says it notifies customers with active deployments, “providing at least 60 days’ notice before model retirement for publicly released models”, that “Requests to models past the retirement date will fail”, and — the detail buyers miss — that partner-operated platforms such as Amazon Bedrock and Google Cloud “set their own retirement schedules, so a model’s lifecycle status and dates can differ”. Microsoft’s Foundry model lifecycle documentation gives generally available models a retirement date “set programmatically at launch to 18 months out”, a GA retirement notice “At least 60 days before retirement” and a preview notice at 30 days — while reserving the right to “invoke an emergency retirement with shortened notice” for compliance or security issues. So plan for roughly two months of warning, not two years. How to de-risk it: model deprecation risk for AI agents.
Does a vendor’s SOC 2 cover the AI models it calls?
No. A SOC 2 reports on the controls of the organisation that was audited, not on everyone in its supply chain. The AWS shared responsibility model draws the line plainly, calling the split “Security “of” the Cloud versus Security “in” the Cloud”, listing “Inherited Controls” as “Controls which a customer fully inherits from AWS”, and telling customers to “Review third-party audit attestation documents to determine inherited controls and what required controls may be remaining for you to implement in your environment.” Vendors that handle this honestly keep the two apart: Twilio’s sub-processor page says it “imposes obligations on its sub-processors to implement appropriate technical and organizational measures ensuring that the sub-processing of personal data is protected to the standards required by applicable data protection laws”, then points to each sub-processor’s own security documentation by external link rather than folding them into its own attestation. Ask for the vendor’s report, the model host’s attestation, and the boundary between them. And to be unambiguous about our own position: Zian has published no security certification, and nothing on this page should be read as one. The wider checklist: auditing an AI vendor’s technical claims.
How can I check whether a vendor actually built the model it runs on?
Read the sub-processor list before the marketing page — it is a contractual disclosure and it names names. Twilio’s published list carries an “Anthropic” row scoped to “All AI Products” with the purpose “Vendor for AI functionality in product”, plus a separate “Amazon Bedrock” row described as “Claude by Anthropic in Amazon Bedrock” — that is a model supply chain, stated by the vendor rather than inferred by you. Stripe’s sub-processor list works the same way, defining sub-processors as “service providers who have or potentially will have access to or process personal data that Stripe processes for, and on behalf of, Stripe’s Business Users”, and giving business users 30 days to object in writing to a newly added one. Cross-check the list against the trust centre and the data-flow docs. If a vendor publishes no list at all, or will not name the model host without an NDA, record that as “not published” — an absence you can quote is still a finding. More tests: the AI vendor technical-claims checklist.
Using Zian
What results do teams see on Zian?
The platform counters, straight from live usage: 50,769+ qualified sales appointments set, a 926% increase in follow-ups, 28x more contact attempts, a 2,736% increase in lead contact rates and 3,102% more sales appointments. Results vary by list quality, offer and market — which is why the platform split-tests continuously: PrecisionPitch AI™ tests scripts and approaches against real outcomes, not opens. See AI sales script split-testing.
How do we choose between the AI sales platforms out there?
Evaluate on four axes: autonomy (does it decide, or just fire sequences?), channel depth (real phone calls or just email?), outcome optimisation (does it learn from booked meetings or from opens?), and deployment control. Our honest read of the field, criteria first: best AI sales agent platforms in 2026.
Which US states require an AI voice agent to tell people it is AI?
There is no single US rule — it is a state patchwork, and much of what circulates online is wrong. Utah is currently the strictest live duty: Utah Code §13-77-103 requires a supplier using generative AI to disclose that fact when a person clearly and unambiguously asks, and it covers audio explicitly. Maine (10 M.R.S. §1500-DD) reaches aural communications too, while California’s BOT Act applies to online interactions rather than phone calls. Texas SB 140 is widely and wrongly described as an AI-disclosure law — it is a telemarketing statute that says nothing about AI. Our verified state-by-state map: the US state AI call-disclosure patchwork.
Does a lead vendor’s “TCPA-compliant” badge protect me if I call the list with an AI agent?
No. Under the TCPA the burden of proving prior express consent sits with the caller, not the list seller — the FCC stated this directly at paragraph 33 of its 2012 TCPA Order (FCC 12-21). A vendor’s badge is a commercial assurance, not a legal defence, and it does not put the capture record in your hands. Because the FCC has ruled that AI-generated voices are “artificial” under the TCPA, an AI voice agent needs consent for every call regardless of content. What a defensible consent chain has to contain: purchased lead lists and the TCPA consent chain.
What happens when a consumer’s AI assistant phones my business?
It is already happening. Google operates a service that places automated calls to businesses on a customer’s behalf to ask about pricing, availability and bookings, and Google publishes the opener those calls use — they identify themselves as an automated service and state that the call is recorded (Google Business Profile Help), along with routes for a business to opt out. The practical consequence is that your phone line now has machine callers as well as human ones, and deep IVR menus and hold queues serve them badly. Our readiness guide: preparing your phone lines for inbound AI callers.
Can we use a published AI-visibility benchmark rate as our target?
Not safely. Published AEO/GEO benchmarks measure a non-deterministic system, and almost none disclose the things that would make their number comparable to yours: the prompt list, samples per prompt, the exact date window, the named engines and modes, the locale, and what they actually counted as a “citation”. Conductor’s 2026 AEO/GEO Benchmarks Report, for example, states plainly that its figures are US-only averages, and it does not publish its prompt set. Treat published averages as direction and track your own trend instead: how to read a 2026 AEO benchmark report.
What is the difference between an AI sales agent platform and an AI voice agent platform?
Scope. A voice agent platform sells you the call layer: speech, turn-taking, telephony, transfer and barge-in handling — you still supply the pipeline logic and the follow-up. A sales agent platform owns the outcome across channels: who to contact, on which channel, when to try again, and booking the meeting, with voice as one component. Compare on that axis before comparing features: best AI sales agent platforms 2026 and best AI voice agents for outbound calls 2026.
How do we get access to Zian?
Zian is currently in an invite-only beta. Apply for partnership and you’ll be onboarded as capacity opens — early access prioritises teams with an existing lead flow or database to work.
Does Zian have a free trial or self-serve signup?
No self-serve signup, and no time-limited free trial. Zian is in invite-only beta, so every tier — including the free-forever Intel + Widgets tier — is gated behind the partner application rather than a credit-card form, and there is no published price list to compare line by line. That is a real trade-off to weigh when you are evaluating vendors: you get a scoped pilot with engineering support instead of a sandbox you can sign into on a Sunday. Enterprise arrangements cover custom private models and local data residency. If the fit looks right, apply for partnership and we will scope a pilot against your list.
Does Australia have an AI Act?
No. A title search of the Federal Register of Legislation for “Artificial Intelligence” on 2 September 2026 returns two instruments, both grant-programme funding rules, and no regulatory statute. An outbound AI sales agent is instead governed by the Do Not Call Register Act 2006, the Spam Act 2003 for SMS and email, the Privacy Act 1988 and the Australian Consumer Law. The ten mandatory guardrails proposed in September 2024 are not enacted, and the National AI Plan does not use the word “guardrail” at all. Full map in Australia has no AI Act.
Does any Australian law require an AI caller to disclose that it is AI?
No. The Telemarketing and Research Calls Industry Standard 2017 contains no occurrence of “artificial”, “automated” or “AI”. Its section 9(2)(a) actually removes the duty to give a caller’s given name where a recorded or synthetic voice is used. But section 12, headed “Calls that involve a recorded or synthetic voice”, imposes a duty of its own: you must provide a mechanism during the call for the recipient to request your contact and complaint details. So a synthetic-voice agent is excused one identification duty and handed another. Source: F2017L00323.
Can I record a phone call anywhere in Australia if I am a party to it?
No — the “one-party consent” rule of thumb breaks in Western Australia. Under section 5(1)(b) of the Surveillance Devices Act 1998 (WA), a party may not record a private conversation unless every principal party consents (s 5(3)(c)), or one consents and the recording is reasonably necessary to protect that party’s lawful interests (s 5(3)(d)); the penalty is A$5,000 or 12 months for an individual and A$50,000 for a body corporate. Victoria (Surveillance Devices Act 1999, s 6(1)) and Queensland (Invasion of Privacy Act 1971, s 43) do permit a party to record. Victoria s 11 and Queensland s 45 separately restrict communicating or publishing a recording: lawfully recorded does not mean freely shareable. NSW and SA we could not verify — legislation.nsw.gov.au, legislation.sa.gov.au and AustLII all returned HTTP 403 on 4 September 2026, so treat any national one-party-consent table as unverified. Worked through for an industry that records constantly: AI call handling for Australian real estate agencies.
What are the TCPA statutory damages for an AI call in 2026?
Unchanged: US$500 per violation under 47 U.S.C. 227(b)(3)(B), which a court may treble to US$1,500 for a wilful or knowing violation. The FCC’s February 2024 Declaratory Ruling classified AI-generated voices as “artificial” under the TCPA, so AI calls to mobiles need prior express consent. Checked 4 September 2026. Detail in TCPA 2026 AI calling settlements.
Is in-call AI disclosure federally required in the United States?
Not as at 2 September 2026. FCC 24-84 proposes to define an “AI-generated call” and require disclosure, but it remains a Notice of Proposed Rulemaking in CG Docket 23-362 — a Federal Register check returns one proposed rule dated 10 September 2024 and no final rule. Several secondary sources assert the requirement is already in force; it is not. Individual US states do impose disclosure duties, covered in US state AI call disclosure laws.
Does a TCPA settlement mean the company broke the law?
No. Both 2026 funds we traced to primary court records — Gen Digital’s US$9,950,000, finally approved 14 July 2026, and Hy Cite Enterprises’ US$4,750,000, preliminarily approved 24 March 2026 with a fairness hearing set for 6 October 2026 — contain express denials of liability, and the Gen Digital order records that the court “does not make any determination as to the merits”. Notably, neither settlement order mentions AI at all: both are wrong-number classes turning on the statutory phrase “artificial or prerecorded voice”.
How accurate is speech recognition on Australian accents?
No major speech-to-text vendor publishes an Australian-English word error rate — that absence is the finding. The widely repeated “30-50% WER for accented speech versus 2-8% for native speakers” traces to an AAAI-24 undergraduate paper measuring Indic-accented English, whose native-side figure comes from wav2vec 2.0 results on LibriSpeech audiobooks. It compares lecture audio to audiobooks across different models and corpora. A benchmark holding corpus and model set constant (WildASR, March 2026) reports 2.2-6.8% on accented English, with Australian speakers 12.1% of that set, against a 4.7% human error rate. See Australian accents and word error rate.
Why does headline word error rate understate a failed booking?
Because errors are not evenly distributed across words. AssemblyAI’s own analysis reports missed-entity rates far above its headline WER — roughly 13.1% for names and 19.6% for phone numbers on real-world customer audio. On an Australian booking call the payload is proper nouns: suburb names, street names and spelled-out surnames. A 5% WER concentrated in those fails more appointments than a 12% WER spread across filler words. Always ask for the test conditions: a WER number without its corpus and audio conditions is not a measurement.
How much latency does a mid-call knowledge lookup add?
ElevenLabs documents around 250 ms of added latency for the RAG step in its agents platform, with no methodology attached. Retell AI exposes a knowledge_base latency percentile, but only on calls that actually use its knowledge base. Pinecone’s own latency guidance publishes no millisecond figure at all, and Cohere’s Rerank overview does not use the word latency. Zian publishes no latency figure. Most “live” lookups could have been pre-fetched before the call. See retrieval latency mid-call.
How many concurrent lines does 10,000 calls a day need?
Concurrency, not daily volume, is the binding constraint. Ten thousand dial attempts at an assumed 67.5 seconds of line time each, across an 11-hour window, is 675,000 seconds of line time divided by 39,600 seconds — about 17 lines on average, and roughly 34 at an assumed 2x peak. Both inputs are assumptions you should replace with your own measured figures; only the arithmetic is ours. For scale, Vapi includes 10 concurrent slots by default and Retell AI 20 on pay-as-you-go. Working through it: scaling AI calling.
What does an AI receptionist cost in Australia?
Australian services that publish a price start at A$99/month (Hey Jodie, which marks currency and notes “Prices exclude applicable taxes”) and run to “$1,299/month” for Valory Enterprise — a figure Valory’s page prints with an unmarked “$”, AUD appearing only in that page’s schema.org markup, checked 4 September 2026. What actually decides the comparison is the pricing model, not the technology: a pay-as-you-go human service (OfficeHQ, “$33* per month + $3.89* per call”, the asterisk resolving to “Plus GST”) stays cheaper than flat-rate AI below about 17 answered calls a month, while metered AI pushes the crossover past 50. No vendor on the pages we opened publishes a cost per booked appointment, which is the number that actually matters. Zian publishes no price during beta. Method in how to read the pricing pages and AI receptionist vs virtual receptionist.
How many times should I poll an AI engine before a change means anything?
More than once, and more than most teams do. A University of St Gallen study (arXiv, 8 April 2026) ran eight prompts across four verticals and four engines daily for two months, plus up to ten same-day repeat runs, and recommends at least seven to eight runs before treating a reading as stable. Single-poll movement is noise. Track per-prompt history and a consecutive-hold rate rather than a headline percentage, and never compare across a changed denominator. Method in building an AEO poll harness.
What is Google’s Preferred Sources button, and does it lift rankings?
An embeddable button, shipped 20 August 2026, that lets a reader add your site to their preferred sources list. Google’s Search Central guide scopes every effect to that reader: a “preferred” badge in Top Stories, AI Mode and AI Overviews “for users who have selected your site as a preferred source”. It sits under search appearance, not among the ranking systems, and Google says of its promotion methods “It’s not required to do them in order to appear as a preferred source”. Full read: Preferred Sources as an AEO lever.
How many sites have readers marked as Google preferred sources?
Google has published four counts in nine months, all of sources readers selected — not publishers who installed the button. On blog.google: “nearly 90,000 unique sources” (10 December 2025), “over 200,000 unique sites” (30 April 2026), “more than 345,000 unique sources” (27 May 2026) and “more than 600,000 unique sources” (20 August 2026). Google’s separate claim that readers are “twice as likely to click through to a site after marking it as a Preferred Source” carries no published sample, window or control group, checked 4 September 2026.
When did Google AI Mode launch in Australia?
8 October 2025. Google’s Australian blog announced it in English, describing AI Mode as “built right into Search” and running on “a custom version of our advanced Gemini models”. Because it lives on google.com it produces no distinct referrer, so it is not a traffic source you can report. For an Australian B2B vendor the exposure is absence from a synthesised comparison, not lost informational clicks: what AI Mode in Australia changed for B2B.
Can we see Google AI Mode traffic separately in GA4?
No. GA4’s channel definitions put arrivals “via non-ad links in organic-search results, including Google’s AI Overviews and AI Mode” under Organic Search, while the separate AI Assistant channel — ChatGPT, Gemini, Deepseek, Copilot, Grok — expressly “excludes Google’s AI Overviews and AI Mode”, checked 4 September 2026. Search Console pools the same two surfaces, and its generative-AI report offers only Pages, Countries, Dates and Devices. Trend the impressions line; poll prompts for presence.
Why do the 2026 studies of AI click loss disagree?
Different populations, denominators and counterfactuals. A pre-registered randomised Chrome experiment on over 1,000 users (Agarwal, ISB; Sen, CMU) found AI Overviews “reduced users’ organic clicks to third-party sites by 39.8 percent”, conditional on one appearing (ProMarket). Ahrefs’ 58% is a position-one click-through-rate gap across 300,000 keywords, not sessions lost. The ABC’s “one down by 35 per cent” is one unnamed Australian news site in Similarweb data — and the rival Ipsos Iris panel, in the same article, pointed the other way. None forecasts a B2B site: the full comparison.
What is inferred consent under the Spam Act, and who has to prove it?
Schedule 2, clause 2 of the Spam Act 2003 (Cth) defines consent as express consent, or consent “that can reasonably be inferred from” the conduct and the business and other relationships of the person concerned. Clause 4(1) closes the shortcut: consent “may not be inferred from the mere fact that the relevant electronic address has been published”. Section 16(5) puts an evidential burden on whoever relies on it, and the ACMA says “it’s up to you to prove that you have a person’s consent”. Detail: inferred consent and AI agents.
Does a Do Not Call Register registration expire?
No. Section 17(1)(b) of the Do Not Call Register Act 2006 says a registration, unless sooner removed under a subsection 18(1) determination, “remains in force indefinitely”. The three-year term many calling teams still plan around existed from 2010 and was repealed by Schedule 3 of the Telecommunications Legislation Amendment (Deregulation) Act 2015. A number that washes dirty stays dirty until the account-holder removes it; the only clock you get is the 30-day washing cycle in s 11(3).
If someone opts out mid-call, does the Spam Act’s five-day rule apply to the call?
No — the Spam Act does not reach the phone leg at all. Section 5(5) provides that a message sent “by way of a voice call made using a standard telephone service” is not an electronic message for the purposes of the Act, so section 18 never touches the call. What applies is s 13(1)(b) of the Telemarketing and Research Calls Industry Standard 2017: terminate immediately. Schedule 2 clause 6’s five business days governs SMS and email only. Full sequence: what an agent must do after a mid-call opt-out.
Does the Privacy Act cover a small dental or medical practice?
Yes, at any size. Section 6D(1) of the Privacy Act 1988 (Cth) exempts businesses turning over A$3,000,000 or less, but s 6D(4)(b) switches that exemption off for an entity that “provides a health service to another individual and holds any health information except in an employee record”. Health information is sensitive information under s 6(1), so APP 3.3 governs what an AI phone agent may collect on a booking call. A two-chair practice is inside: AI receptionist privacy rules for Australian practices.
Does “hosted in Australia” mean the AI model runs in Australia?
No. The phrase usually describes storage at rest, not inference. Google’s own documentation warns that “Endpoints don’t guarantee data residency or in-region ML processing”, and AWS cross-Region inference profiles route “within the geography” — geographies “such as US, EU, and APAC”, which is not Australia. Audit six layers separately: storage, application processing, model inference, support access, backups and telemetry, each with a region code and a dated artefact. Checklist: how to audit an Australian-hosted claim.
Where does the “62% of calls go unanswered” figure come from?
A 2016 study by a United States marketing agency. 411 Locals published it on 18 January 2016: “We monitored the phone calls of 85 businesses, operating in 58 industries, for a period of 30 days… While 37.8% of calls do get answered, another 37.8% get forwarded to voicemail and 24.3% don’t get any response.” The 62% is voicemail plus no-answer combined, so a call that reached voicemail counts as unanswered. There is no published Australian equivalent — use your own call detail records: what a 7pm enquiry actually costs.
Should we quote Spam Act or Do Not Call penalties in dollars?
No — cite penalty units. Section 4AA(8) of the Crimes Act 1914 says an indexed penalty unit “only applies to offences committed on or after the indexation day”, and the note to s 5 of the Crimes (Amount of a Penalty Unit) Instrument 2026 repeats that its A$364 figure “only applies to offences committed on or after 1 July 2026”. Spam Act and Do Not Call breaches are civil penalty provisions, not offences, and s 4AA(1) still reads A$330. Across a 10,000-unit cap those two multipliers are A$340,000 apart.
Last updated: 4 September 2026. Answers on this page are refreshed as the underlying studies and regulations change.