Recommended Free Tools
AI agents can give customers false or biased answers, expose sensitive information, enable security breaches, or take the wrong action—such as issuing a refund or changing an account. The risk rises when an agent has more autonomy, access to customer data, or permission to act without confirmation. Businesses need to limit that authority, monitor outcomes, and make human help and meaningful redress accessible.
What “AI agent” means for customer support
A support chatbot that drafts a response for an employee is not equivalent to an agent that reads customer records, decides what policy applies, and processes a refund. The key difference is authority: what the system can access, decide, and do without a person stepping in.
The UK Competition and Markets Authority (CMA) describes agents as being used to progress multi-step tasks, including customer service requests, refunds, and transactions. Its analysis portrays deployments as primarily bounded and controlled: consumer-facing authority remains limited, and escalation to people is common. That is a more accurate baseline than assuming fully autonomous customer-service agents are already the norm.
The following is a risk framework, not a claim that every organization uses these exact deployment levels:
#1 Best Overall
| Deployment level | What the system can do | What to scrutinize |
|---|---|---|
| Answer or draft | Provide information or suggest a reply, without changing an account. | Whether the answer is accurate, appropriately qualified, and checked before it is sent. |
| Workflow support | Look up information or prepare a proposed action for a person to review. | Which records it can see, what evidence supports its recommendation, and whether approval is meaningful. |
| Action-enabled agent | Make permitted account or transaction changes, potentially without case-by-case human review. | Permission limits, authentication, customer confirmation, reversibility, monitoring, and a way to challenge the result. |
A system marketed as an “agent” may fit any of these patterns. Assess its actual permissions and behavior, not the label.
What can go wrong
Incorrect or fabricated answers can become costly actions
Language models can produce plausible but incorrect answers, including claims that a policy allows something when it does not. NIST’s July 31, 2025 initial public draft on an internal-use chatbot identifies hallucinations as a challenge. The CMA also warns that agent errors may have costly consequences, especially when they affect financial decisions, contractual changes, or service continuity.
The impact depends on what happens next. A mistaken answer that an employee catches is different from an agent using that answer to issue a refund, cancel a service, or change an account. Clearly defined action limits and appropriate confirmation can prevent an unverified answer from becoming an irreversible decision.
Rank #2
Customer information may be exposed or used in unexpected ways
Support conversations can include personal, financial, health, or other sensitive details. The US Federal Trade Commission (FTC) warns that AI providers may receive sensitive or confidential customer and business information, and that a provider’s incentives to gather data may conflict with data-protection commitments.
Before connecting a support agent to customer data, establish what information reaches the provider, how long it is retained, who can access it, and whether it may be used to train or improve models. Check that the provider’s actual practices match the organization’s privacy statements and customer-facing promises. Telling customers that AI is involved does not, by itself, control where their information goes or how it is used.
The FTC material concerns US privacy and confidentiality commitments; legal obligations vary by jurisdiction and sector.
Rank #3
Weak security can expose records or permit unauthorized actions
NIST’s July 31, 2025 draft identifies prompt injection, data exposure, and unauthorized access among the challenges considered for its internal chatbot prototype. In customer support, untrusted text in a message or document could attempt to influence an agent’s behavior. The relevant question is not only whether the model recognizes suspicious text, but whether that text can cause the agent to access records or use connected tools improperly.
Review what the agent can read and change, how users and connected systems are authenticated, and how access is limited. NIST’s prototype documents safeguards including local deployment, access controls, and validation filters, but the draft explicitly is not general implementation guidance. Those examples are not a guarantee that a particular customer-support system is secure.
Bias and opaque decisions can leave customers without a fair remedy
An agent may reproduce or amplify bias in its data or decision-making. If it gives different customers different outcomes, or applies a rule without explaining the reason in understandable terms, customers may struggle to identify or challenge unfair treatment. Complex, opaque decisions can make that problem harder to detect.
Rank #4
Organizations need to examine patterns in complaints and outcomes, explain decisions clearly, and provide a route to contest consequential decisions with a person. A single plausible-sounding response is not evidence that customers are being treated consistently.
Personalization can become pressure or manipulation
Tailoring a conversation to a customer’s circumstances can be helpful, but the same capability can steer people toward outcomes that benefit the business instead of resolving their problem. The CMA highlights risks from harmful choice architecture and dark patterns, particularly when agents are optimized for engagement or commercial objectives.
Review what the agent is rewarded for achieving. If it is designed to maximize retention or conversion, consider whether it can make cancellation or another legitimate customer choice harder, apply pressure, or divert a customer from a fair resolution.
Best Value
Customers can lose control when escalation fails
Customers may trust an automated answer too readily or find it difficult to reach a person when the answer is wrong. An escalation route is not effective if it is hidden, repeatedly sends the customer back to the agent, or fails to carry the relevant conversation and case details to the employee who takes over.
The CMA states: “A central principle remains unchanged: businesses are responsible for how they engage with consumers, regardless of whether that is through people or AI systems.” Using a provider or delegating tasks to an agent does not remove the organization’s responsibility for its customer interactions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to review a customer-support agent before deployment
Use these checks to judge a proposed deployment against its actual authority and data access. The CMA recommends careful scoping as autonomy increases, monitoring real-world outcomes, accessible escalation, and rapid refinement when problems arise.
1. Set boundaries on tasks and permissions
- List which requests the agent may answer, which records it may access, and which actions it may take.
- Require customer confirmation or employee approval where an action could affect money, a contract, access to a service, or an account.
- Decide in advance which cases must go to a person, such as disputed, sensitive, unusual, or consequential requests.
2. Test more than routine questions
- Test ambiguous requests, policy exceptions, and cases where the available information is incomplete or contradictory.
- Check whether the agent can be induced to disclose data or take an unsafe action through untrusted text.
- Confirm that uncertain answers and disputed decisions reach an appropriate person rather than being presented as settled facts.
3. Map data flows and provider terms
- Identify the information collected, sent to a provider, retained, shared, or used for model training or improvement.
- Compare those practices with customer notices and the organization’s privacy and confidentiality commitments.
- Review provider access and retention arrangements, not just the wording shown to customers.
4. Check security around connected systems
- Limit access to the records and tools needed for the agent’s specific tasks.
- Review authentication, authorization, and the boundaries between customer messages and trusted system instructions.
- Validate that connected actions and outputs are checked before consequential changes occur.
5. Keep escalation, investigation, and accountability workable
- Give customers a clear way to reach a person, especially when they dispute an outcome.
- Preserve enough information to investigate what the agent saw, said, and did in a case.
- Assign a responsible business owner who can review complaints and outcomes and act quickly when monitoring finds a problem.
What to compare when choosing an approach
The label “AI agent” is less useful than the controls around it. When comparing deployment options, assess the same dimensions for each one:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall- Autonomy: What decisions and actions can it make without approval?
- Data access: What customer information can it read, and how sensitive is that information?
- Testing and monitoring: Can the organization test realistic cases and detect errors, bias, complaints, and unintended outcomes after launch?
- Escalation and redress: Can a customer reach a person and challenge a decision without being trapped in an automated loop?
- Security and authorization: How are users, records, and connected actions protected from unauthorized access or influence?
- Accountability: Who reviews incidents, can correct outcomes, and is responsible for improving the system?
There is no directly applicable published statistic in the cited official material that quantifies how often AI customer-support agents fail or harm customers. A general AI adoption figure would not answer that question. Organizations should therefore evaluate the specific system, tasks, and safeguards they plan to use rather than treating an unestablished industry-wide failure rate as a measure of safety.
Where the cited guidance applies
The CMA material is UK consumer-protection and competition analysis, not a universal statement of law. The FTC material addresses US privacy and confidentiality commitments in the context of AI service providers. NIST’s chatbot publication is an initial public draft dated July 31, 2025, about an internal-use prototype—not a customer-support deployment guide. NIST’s AI Agent Standards Initiative page was updated August 14, 2026. Legal duties and appropriate safeguards depend on jurisdiction, sector, and the system’s actual use.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

