Applied AI

The Phone Is About to Be Answered by AI, and That Cuts Both Ways

By Ed Richards,

Realtime voice models and a half billion dollar raise for ElevenLabs have made convincing AI phone agents ordinary this year. That is useful for your enquiry line and dangerous for your finance team.

Voice went from novelty to infrastructure this year

Back in May, OpenAI launched three new Realtime API voice models in one go, including one built for reasoning-level conversation and another handling translation across more than seventy languages. The same month, ElevenLabs closed a $500m Series D at an $11bn valuation to expand its enterprise voice-agent platform. Neither of those was a demo. Both were infrastructure moves, the kind vendors make when they expect the thing to be used constantly, at scale, by businesses that are not tech companies.

Events is one of those businesses. A venue enquiry line, an agency's out-of-hours delegate helpline, a supplier's order desk, all of them are phone-shaped problems that a convincing voice agent can now plausibly take on. That is worth being specific about, because "AI can answer the phone now" covers a genuinely useful capability and a genuinely dangerous one, and they look identical from the outside.

Half one: what a voice agent is actually good for

An enquiry line or a delegate helpline spends most of its time on a small number of repeatable jobs: taking down the basics of an enquiry, checking availability against a known calendar, answering the same handful of FAQs, and booking a callback with a human when the question is bigger than that. A voice agent that sounds natural is genuinely good at exactly that list.

  • Capture. Name, date, headcount, budget range, the shape of the enquiry, taken down accurately so a human is not starting cold on the callback.
  • Qualification. A first pass at whether the enquiry fits what you actually do, so the human callback is a conversation with someone worth having a conversation with.
  • FAQs. Opening hours, parking, accessibility, what is and is not included, the questions your team answers identically forty times a week.
  • Translation. At a multilingual conference or exhibition, a voice agent that can hold a competent conversation in a delegate's own language, at 11pm when nobody bilingual is on shift, is a real improvement on a hold message.

All four of those share a property: getting them slightly wrong is annoying, not dangerous. A misheard headcount gets corrected on the callback. A slightly clunky translation still gets the delegate to the right answer eventually.

What never to hand to a voice agent

Two categories are worth ruling out entirely, not softening, ruling out.

  • Anything with money. Taking a payment, confirming a refund, changing an invoice, agreeing a price outside a published rate card. A voice agent should capture the request and route it to a human, never complete it.
  • A distressed delegate. Someone who is lost, unwell, anxious, or dealing with an emergency at your event needs a person on the line within a small number of seconds, not a competent-sounding agent working through a script. Build the escalation trigger for distress in early and test it, do not assume the agent will recognise it on its own.

Half two: the same technology, pointed the other way

Back in January, a Swiss businessman was reported to have transferred several million Swiss francs after a series of calls from what he believed was a trusted business partner. It was an AI voice clone. Not a single suspicious call, a series of them, convincing enough across multiple conversations to move real money.

That story is not really about Switzerland or about millionaires. It is about the fact that voice cloning good enough to sustain a conversation, not just a ten second clip, is now ordinary infrastructure, available to the same degree to anyone with bad intentions as it is to a legitimate business building a helpline. Agencies that move large supplier payments fast, which is most of them during peak event season, are a natural target. "The MD, on the phone, asking finance to pay the new supplier account today, it's urgent, I'm in a meeting and can't email" is no longer a hypothetical. It is a phone call a cloned voice can now make convincingly.

An events agency in the south east already treats this as a live risk rather than a theoretical one. Its finance lead has a standing rule that no supplier detail changes on a phone call alone, full stop, regardless of how senior the caller sounds or how urgent the request feels. That rule predates most of the voice AI news above. It is simply more obviously necessary now than it was a year ago.

The callback-and-codeword rule

The fix does not need new software. It needs a rule that survives urgency, because urgency is the entire attack.

  • Any request to pay a new supplier, change existing bank details, or move a payment outside the normal approval chain, made by phone, gets a callback to a known number before it happens, never a number given during the call itself.
  • Agree a codeword or a simple verification question in advance with anyone senior enough to plausibly make an urgent payment request by phone, something a voice clone working from public information would not know.
  • Make the rule apply to everyone, including the MD, especially the MD. The whole point of the attack is impersonating authority to bypass a process. A rule with an exception for authority has no rule in it.

A prompt to build the escalation rules

If you are speccing a voice agent for an enquiry line or helpline, this is a useful first pass at the escalation logic before you brief a vendor. Paste it into your AI assistant with a description of your line's current volume and typical calls, and expect back a draft set of rules for what the agent handles, what it escalates immediately, and what phrasing it should never use to imply it is human.

I am briefing an AI voice agent for our events business phone line (describe: venue enquiry line, agency delegate helpline, supplier order desk). Help me draft the escalation rules before I brief a vendor.

Here is what the line currently handles:
[describe typical call volume, the most common enquiry types, and roughly how many calls a human currently takes out of hours]

Draft me:
1. A list of call types the agent can handle end to end (capture, qualify, answer FAQ, book callback).
2. A list of call types that must escalate to a human immediately, including anything involving payment, account changes, or a caller who sounds distressed or confused.
3. Wording the agent should use at the start of the call to make clear it is automated, in plain language, not buried in a disclaimer.
4. A short brief for the vendor on what "escalate immediately" should trigger technically, phrased so a non-technical person could check the vendor has actually built it.

Keep this to one page, practical, no jargon.

This week

Two separate jobs, both small. If your enquiry line already runs or is about to run a voice agent, check the four things above are what it actually does, and that anything involving money or a distressed caller routes to a person. Separately, whether or not you touch voice AI at all, put the callback-and-codeword rule in front of your finance team this week. It costs nothing and it closes a door that is now easier to walk through than it used to be. I will be talking through more of this at CHS Manchester later this month, but the rule itself does not need to wait until then.

More insights