Everyone publishes the ceiling. This is the floor.
A supplier who cannot tell you what they refuse to automate has not thought about the failure cases. Which means you will find them instead, on a real call, with a real customer. Here is our list, with the reason under each item rather than a shrug.
This page is the short version. The longer argument, with the public record behind each boundary and the questions that let you test any supplier rather than just this one, is in what AI should not handle on business calls.
Six things the agent is built to refuse
Each one has a destination behind it. A boundary with nowhere to send the caller is a dead end, not a policy.
Advice that needs a licence
Clinical, legal and financial advice. The agent takes the request, records it accurately and routes it to the person qualified to answer. It never answers it. Not because a model could not produce something plausible, but precisely because it could, and a plausible wrong answer in those three domains is the one that ends up in a file somewhere.
A caller who is distressed
Bereavement, an emergency, someone in evident crisis, someone calling a third time about the same thing. What matters is not how gracefully the agent copes, because coping is the wrong goal. What matters is how few turns pass before it stops trying.
Anything that cannot be undone
Money out, a cancellation, a refund, a change to a prescription, the release of a record. Everything the agent can do gets sorted into three buckets before launch, and the shortest bucket is the one holding the actions nobody can take back. Those are prepared in full and held, never committed.
Inventing an exception to a policy
Applying a rule is arithmetic. Writing one is a judgement about a particular person on a particular day, and that judgement has an owner who is not the software. Asked for something the policy does not cover, the agent names the person who will decide and captures the request in their words.
Passing as a person
The agent says what it is when asked, and increasingly is expected to say so before anyone asks. Article 50 of the EU AI Act requires that people be informed they are interacting with an AI system unless that is obvious, and it has applied since 2 August 2026. A product built to fool the caller is one rule change away from being unusable.
Calling people who never agreed to it
Consent is decided before any technology touches it, and it is the one boundary where the answer arrives from outside the building. If nobody can describe where the list came from, there is no call to design. That is not a legal reflex, it is that an unexplainable list is also a list that does not convert.
The decision underneath the purchase
A buyer comparing voice agents thinks they are choosing a capability set. They are actually choosing a set of defaults for the moments when the script runs out. Those moments are rare as a percentage and they are the whole reputational surface of the system, because they are the calls a customer tells someone else about.
The failure is not that the model breaks. The failure is that it does not break. Asked something outside its knowledge, a language model produces an answer shaped exactly like a correct one, delivered at the same speed and in the same tone as everything else on the call. There is no stammer, no pause, no signal to the listener that anything has changed. In April 2025 an AI support agent at a developer tools company told users, through the company's own support address, that their subscription was limited to one device. No such policy existed. The company's cofounder said so publicly, refunded the developer who raised it, and by then the invented rule had already reached the community forums. Nothing malfunctioned. The system worked exactly as built, and what it was built to do was answer.
That is why the useful boundaries are structural rather than instructional. Telling an agent to be careful is not a control. Removing its ability to commit an irreversible action, and giving every refusal a named destination, is. Article 22 of the GDPR points in the same direction from the legal side: a person has the right not to be subject to a decision based solely on automated processing which produces legal effects concerning them or similarly significantly affects them, and where such a decision is permitted on the grounds the Article allows, the controller must provide safeguards that include the right to obtain human intervention and to contest the decision. Whether any particular call reaches that threshold is a question for your own counsel. The design point is narrower and holds either way: a path with no human in it anywhere cannot produce human intervention after the fact.
The reliability engineering that keeps an agent inside those boundaries turn after turn is a separate discipline, covered on encoded policy versus prompt instructions and in how an agent gets verified before it speaks to anyone.
What gets written down before the agent refuses anything
The refusal list, in writing
Written before anything is configured, from your policies rather than a template. Every item names the situation, what the caller hears, and why the boundary is there.
A destination for every refusal
Not "a human". A named queue, a named rota, a callback with a committed window, or an honest statement that nobody is available until Monday. Vague handovers are where callers get lost.
What can commit, what only proposes
Every action the agent can take is sorted into read, reversible write and irreversible write. The third list is the short one, and it needs a person on it before anything moves.
Where the agent is allowed to write at all is bounded by what it is connected to, which is the subject of the system of record page. Where the audio and the transcript end up is on the call data path page, and the surrounding controls are on security. Nothing here is legal advice, and the two statutory boundaries below are descriptions of published law rather than a view on your situation.
The two boundaries that are not ours to set
Two of the six sit outside commercial preference. Whether the agent discloses that it is an AI system is governed by Article 50 of the EU AI Act, which requires that people be informed they are interacting with an AI system unless that is obvious to a reasonably well informed and observant person, and which has applied since 2 August 2026. The country by country picture, including markets where the duty is broader or narrower, is on the multi-country page.
Whether a particular person may be called at all is consent law, decided before the technology is involved and treated separately on our country guide to AI calling in Europe. We will not run an outbound programme against a list whose origin nobody can describe. That is not caution about the law, it is that a list nobody can explain is also a list that does not convert.
Nothing on this page is legal advice, and it is not intended as a substitute for your own counsel. It is a description of where we draw lines and what we read when drawing them.
Two questions, and what the answers tell you
Ask them to name three things their agent is built to refuse, and to tell you what the caller actually hears in each case. Then ask which actions it can complete alone and which need a person before they commit.
Two answers, two minutes, no contract required. What you are listening for is whether the specifics arrive without a pause, because a refusal list is not something anyone can improvise; it either exists in writing or it does not. The longer version of the test, with the public record behind each boundary, is in the vendor evaluation checklist.
Frequently Asked Questions
Does refusing work mean the agent is less capable?
It means the boundaries were decided in advance instead of on a live call. A system with no stated boundaries has the same failure modes, it just has not written them down. The practical difference shows up in the exceptions, which are the calls that matter most and the ones a feature list never covers.
How fast should an agent hand a distressed caller to a person?
Immediately, and without making the person explain themselves twice. The measurable version is how many turns of conversation pass before the handover begins, and whether the human who picks up already has the context. A handover that dumps the caller back at the beginning is technically a transfer and practically a second failure.
Who decides where the boundaries sit, you or us?
You do, on your own policies. The six on this page are the floor rather than the whole list, and the rest comes out of the situations your front desk already handles badly on a bad day. What we bring is the set of questions that surface those situations before launch instead of after it, and the discipline of writing the answer down while nobody is on hold.
Founder & CEO, AInora
Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.
View all articlesA working session, not a demo
Forty-five minutes on your actual call flow. We take the policies your front desk already follows, push on them until the edge cases fall out, and you keep the written version at the end whether or not anything else happens.
If it goes further, the first piece of work is one workflow: missed calls and after hours, roughly two weeks, before anything else moves.
Talk it through