Customers now ask AI to act for them. Designing a task-completing service agent
Customers now have AI act for them. How to scope a service agent that updates accounts, books and takes documents, with verification, disclosure and escalation.

The short answer
A task-completing service agent should start with a short list of actions sorted by risk: read-only lookups, reversible changes such as rebooking or address updates, document intake, and irreversible actions that always stop for a person. Match verification to the risk of each action, disclose that the customer is talking to AI, and hand over with full context.
Key takeaways
- Sort every task by what happens if the agent gets it wrong: read-only, reversible, document intake, or irreversible.
- Verification should rise with the risk of the action, and never rest on details the customer typed into the chat.
- In KPMG's survey of 314 US leaders at $1bn+ firms (July–August 2026), 49% defined high-risk uses barred from autonomous decisions.
- Irreversible actions such as refunds above a limit, cancellations and contract changes should end in a draft a person approves.
- Plan for the customer's own AI assistant arriving on your channel, and confirm consequential changes on a registered channel.
In this article
Why answering is no longer enough
Customers increasingly expect AI to complete the task, not describe how to do it. A service agent that explains your address-change form while the customer could have had it done elsewhere is now the slower option.
Gartner's survey of business and consumer customers, published in July 2026, looked at how often people turn to third-party generative AI tools instead of company chatbots for service, and whether they let AI act on their behalf.1 The Next Web's write-up of the same survey covers the split between business and consumer buyers and what senior leaders reported about returns.2 We summarised the main finding in our note on customers choosing ChatGPT over company chatbots.
Our view: the gap is not tone or model quality. Third-party assistants feel useful because they try to finish things. A company agent that can actually change a booking, with your data and your rules, can do what a general assistant cannot. That is the reason to build one.
Scope the tasks by what happens when it goes wrong
Scope a task-completing agent by the cost of a mistake, not by the volume of requests. Four tiers cover most service work, and each gets different controls.
Read-only lookups come first: order status, balance, appointment time, policy details. A wrong answer is annoying but nothing changes in your systems. Reversible changes come next: rebooking, updating a delivery slot, changing contact preferences. A mistake can be undone, at some cost.
Document intake sits in its own tier: proof of address, claim photos, invoices. The agent receives and files the document; a person or a rules check decides what it means. The agent can still save a round trip by checking the basics on upload: the right document type, a readable file, a date inside the allowed window. Telling the customer at once that a bank statement is three pages short beats a rejection email a week later. Irreversible actions come last: refunds above a limit, cancellations with penalties, contract and credit changes. These end in a draft a person approves.
| Tier | Examples | Agent may |
|---|---|---|
| Read-only | Order status, balance, opening hours | Answer after basic verification |
| Reversible | Rebook, change slot, update preferences | Act, confirm, log |
| Document intake | Proof of address, claim photos | Receive, check type, file for review |
| Irreversible | Large refunds, cancellations, contract changes | Draft only; a person approves |
Illustrative. Our default tiers; your own limits decide where each task sits.
Buyers already think this way. In KPMG's AI Quarterly Pulse, a survey of 314 US leaders at companies with $1 billion or more in revenue (24 July–25 August 2026), 49% said they define high-risk uses barred from autonomous decisions.3 The tier table is how that list becomes configuration.
How should the agent verify who it is talking to?
Verification should rise with the tier. A read-only lookup may need only a logged-in session or an order number plus a postcode. A change to an account needs a one-time code sent to the phone or email already on file. An irreversible action needs that code and a person's approval.
Never verify on information the customer typed into the conversation alone. Names, dates of birth and order numbers are easy to find or guess, and an agent that accepts them is easier to talk into a change than a trained person would be. Step up to a registered channel whenever the action changes something.
The agent's own access matters as much as the customer's. Give it a dedicated service account that can do exactly the tier-one and tier-two actions and nothing more. Our guide to least privilege for agents on ERP and CRM covers how to set those permissions. If you buy a platform rather than build, our due-diligence questions for agent platforms cover data, logs and exit terms.
A reversible change, end to end
- Request
- Disclose AI
- Verify on a registered channel
- Act in the system
- Confirm and log
Disclosure and the customer's own AI
Tell customers they are dealing with an AI agent at the start, in plain words. As of October 2026, Article 50 of the EU AI Act has applied since 2 August 2026. A Cloud Security Alliance research note reads it as requiring providers of conversational systems to make sure users know they are dealing with AI, unless that is obvious from the context.4 This is not legal advice. A clear opening line and a logged record that it was shown cost almost nothing, wherever you operate.
The newer design problem runs the other way. If customers have AI act for them, some requests to your agent will come from the customer's own assistant. That assistant may phrase things perfectly and still lack the authority it claims.
Our view: treat a request from another AI like any request from an unverified party. Read-only answers are fine at the usual level. Anything that changes an account is confirmed on the customer's registered channel, so a person approves it on their side. This keeps your controls the same whoever, or whatever, is typing.
Escalation that does not start from zero
Escalation is part of the task design, not a fallback. Every tier needs a defined point where the agent stops and passes the case to a person, with the conversation, the verification state, the documents received and what the agent was about to do.
Escalate on signals as well as tiers. Repeated failed verification, a customer asking twice for a person, words that suggest distress or a complaint, and any request outside the agreed task list should all hand over at once, whatever the tier.
The worst handoff makes the customer repeat everything. The second worst passes a transcript with no summary. Design the handoff as a structured note a person can act on within a minute. Our guide to escalation design for support agents sets out the triggers and the note, and our piece on exception queues covers who works them.
Where to start
Start with one reversible action that customers request often and your team finds tedious, such as rescheduling an appointment or changing a delivery slot. Ship the read-only lookups around it first, then add the action with verification on a registered channel and a full log.
Measure three things from the first week: the share of requests the agent completes, the share it escalates, and every case where a change had to be undone. Add the next action only when those numbers are stable. Agent adoption is moving quickly: in the same KPMG survey, 62% of US leaders said they were building or deploying agents, up from 53% in the second quarter of 2026.3 Speed of adoption is no reason to skip the tiers.
Our AI automation page describes how we build one workflow at a time on the systems you already run, with acceptance criteria agreed before the build.
Sources
- Gartner, survey of B2B and B2C customers on third-party GenAI and company chatbots for service (Jul 2026)
- The Next Web, customers prefer third-party GenAI to company chatbots (Jul 2026)
- KPMG, AI Quarterly Pulse Q3 2026: 314 US leaders at $1bn+ firms, 24 Jul–25 Aug 2026 (Sep 2026)
- Cloud Security Alliance, research note on EU AI Act Article 50 transparency (Jul 2026)


