
7 Safe AI Agents That Can Talk to Your Customers in 2026
Seven AI agent platforms let you put safety controls in front of a customer conversation rather than behind it: Lumi by Userlens, Salesforce Agentforce 360, Fin, Microsoft Dynamics 365, Ada, Zendesk AI Agents and HubSpot's Customer Agent. Lumi and Dynamics stop a message before it sends, using contact rules, frequency caps and time-zone-aware quiet hours. Fin, Ada, Zendesk and HubSpot check the answer instead. Fin is the only one publishing a price, at $0.99 per resolution. Note that Salesforce agreed on 15 June 2026 to acquire Fin for roughly $3.6 billion, so Agentforce and Fin are a pending single-owner pair rather than two independent options.
This article is for informational purposes only and does not constitute financial, tax, or legal advice. Consult a qualified professional for guidance specific to your situation.
Reviewed for financial accuracy by the Startup Finance Guide editorial team. Our editors cross-reference all claims against platform documentation, pricing pages, and primary regulatory sources. Last reviewed: September 20, 2026.
Seven AI agent platforms let you put safety controls in front of a customer conversation rather than behind it: Lumi by Userlens, Salesforce Agentforce 360, Fin, Microsoft Dynamics 365, Ada, Zendesk AI Agents and HubSpot's Customer Agent. They split into two camps. Lumi and Dynamics stop a message before it sends, using contact rules, frequency caps and time-zone-aware quiet hours. Fin, Ada, Zendesk and HubSpot check the answer instead, either grounding it in approved content or verifying it before delivery. One thing to know before you compare rows two and three: Salesforce agreed on 15 June 2026 to acquire Fin for roughly $3.6 billion, so Agentforce and Fin are a pending single-owner pair rather than two independent options.
Handing customer conversations to an AI still makes teams nervous, and the nervousness is well placed. One wrong reply, one piece of account data shown to the wrong person, and trust you spent years earning takes a hit.
Most "AI safety" claims are marketing copy. A smaller number describe something the vendor actually enforces in the product. This article separates the two across seven platforms, says plainly where a vendor's own documentation does not support the claim commonly made about it, and gives prices where they are public.
Key takeaways
- A safe agent is not one feature. It is layered controls: rules that block a bad message before it sends, access limits that scope what the agent can see, and logs that prove what happened afterwards.
- Timing is the real differentiator. Pre-send controls prevent damage. Audit-and-review controls catch it after the customer has already seen the message. Pick based on which of those two failures would hurt you more.
- Salesforce is acquiring Fin. The deal was announced 15 June 2026 at roughly $3.6 billion and is expected to close by the end of January 2027. Agentforce and Fin appear separately below, but they will not be independent vendors for long.
- Vendor safety language outruns vendor documentation more often than not. Several widely repeated claims in this category, including "zero-trust" input filtering and entity-level CRM access, do not appear in the vendors' own material.
- Pricing is published for only some of these. Fin charges $0.99 per resolution under an outcome-based model. Most of the rest quote.
How to judge whether an agent is actually safe
Five mechanisms matter, and each one fails differently.
- Pre-send validation. Rules check a message against contact limits, quiet hours and exclusion lists before it leaves the system.
- Scoped access control. The agent reads only the records and fields it needs.
- Confidence-based escalation. When the agent is unsure, it hands off rather than guessing.
- Output verification. Generated replies are checked against approved sources or policy before delivery.
- Audit logging. Decisions, data access and escalations are recorded so a dispute can be reconstructed.
Here is how the seven compare. Cells read "Not publicly documented" where the vendor's own site does not support the capability, including for the client whose product leads the list.
| Platform | Pre-send control | Access control | Escalation logic | Audit logging | Published price |
|---|---|---|---|---|---|
| Lumi by Userlens | Contact rules, quiet hours, frequency caps, uncertainty rules | Campaign-level human approval of goal, audience, tone and guardrails | Uncertainty rules hold the send | Not publicly documented | Quoted |
| Salesforce Agentforce 360 | Input screening of data sent to the agent | Standard Salesforce permissions model | Human handoff on ambiguous requests | Records agent actions and decision paths | Quoted |
| Fin | Answers grounded in your published content | Scoped to connected knowledge base | Hands off with full conversation context | Source citations per answer | $0.99 per resolution, outcome-based |
| Microsoft Dynamics 365 | Time-zone-aware quiet times, from Customer Insights Journeys, not Copilot | Role-based CRM access | Falls back to the journey time zone when data is missing | Journey and rule-level logs | Quoted |
| Ada | Responses verified against approved sources before sending | Not publicly documented | Non-compliant responses blocked automatically | Not publicly documented | Quoted |
| Zendesk AI Agents | Automated QA on interactions | Plan and add-on dependent | Standard ticket escalation rules | Redaction and access logs via the ADPP add-on | Add-on, Enterprise plans |
| HubSpot Customer Agent | Knowledge-base grounded responses | CRM-scoped by hub and permission | Escalates with full context | Resolution-rate reporting | Per-resolution plus credits |
Disclosure: rows two and three are a pending single-owner pair. Salesforce agreed to acquire Fin on 15 June 2026.
1. Lumi by Userlens
Lumi is a customer adoption agent for B2B SaaS and product-led growth teams. Its core idea is that a human approves the campaign, not each individual message, and a rule engine then enforces those boundaries on every send.
- Contact rules and exclusions. Userlens describes defining who Lumi may contact and who it must leave alone, as a standing rule rather than a per-send decision.
- Frequency caps, quiet hours and uncertainty rules. All three are documented product behaviour. Note that Userlens calls the third "uncertainty rules"; you will sometimes see it written up as "skip-if-unsure logic", which is a description rather than a feature name.
- Grounded in product usage. Outreach is built from how a customer actually uses the product rather than a generic lifecycle stage, which is the same data problem covered in unifying product usage data for customer success.
Best for: B2B SaaS and PLG teams that want automated adoption nudges without losing control of who gets contacted and when.
What to consider: two things. Lumi is purpose-built for SaaS product adoption, so ecommerce and high-volume consumer support teams will find better channel coverage elsewhere. And unlike Salesforce, Zendesk and Fin, Userlens does not publish documentation of an audit log or send-level enforcement record, so if you need to hand a compliance team a verifiable trail, ask for that in writing before you buy. Pricing is quoted rather than published.
2. Salesforce Agentforce 360
Agentforce is Salesforce's agentic platform, launched at Dreamforce in September 2024 and rebranded to Agentforce 360 in October 2025. A common shorthand has it that Agentforce is Einstein Copilot renamed; that is not quite right. What was renamed, in January 2025, was the specific agent type "Einstein Copilot for Salesforce", which became "Agentforce (Default)" with no functionality change. The platform itself was new.
- Input screening. Salesforce documents screening and verifying the data sent to an agent so that harmful, misleading or unexpected inputs do not influence its decisions.
- Decision-path recording. Salesforce documents recording an agent's actions and decision paths to trace behaviour and investigate incidents, which is the strongest audit story among the seven.
- Access follows your existing permissions model. An agent is bound by the Salesforce permissions already in place. Worth flagging: the frequently repeated claim that Agentforce enforces "entity-level rather than table-level" access, with permissions shifting automatically as roles change, does not appear in Salesforce's security documentation. Treat it as a question for your account team, not a guarantee.
Best for: enterprises already standardised on Salesforce that want an agent bound by the same access rules as a human rep.
What to consider: the safety architecture is coupled to the Salesforce ecosystem, so the guarantees do not travel outside it. Salesforce also frames autonomy as an administrative responsibility, noting that the more freedom an agent has, the more carefully you need to manage its behaviour. That is advice to you, not an enforced platform behaviour, and reading it as the latter is a common mistake.
3. Fin
Fin only answers what it can ground in your published support content. When it cannot find a confident match it says so and hands the conversation to a person with the full history attached.
Some naming history, because it causes confusion. On 12 May 2026 Intercom changed its company name to Fin. Intercom was not retired; it continues as the name of the customer-service software platform, with Fin as its AI agent.
- Grounded answers with citations. Replies are generated from your knowledge base with source citations, which is what keeps it from inventing policy or pricing.
- Outcome-based pricing at $0.99 per resolution. A resolution is defined as no further help being requested after Fin's last answer. You are not charged when a conversation is simply passed to your team without an outcome. Note the nuance: this is an outcome-based model of which resolution is one type, not a flat pay-per-resolution tariff.
- Full-context handoff. The human agent receives the entire conversation rather than starting from zero.
Best for: support teams wanting fast self-serve deflection without a hallucinated answer reaching a customer.
What to consider: the ownership change. Salesforce announced a definitive agreement to acquire Fin for approximately $3.6 billion on 15 June 2026, with closing expected in the fourth quarter of Salesforce's fiscal 2027, which ends 31 January 2027. Salesforce describes Fin's packaged agents as complementing the customisable Agentforce platform with multiple deployment options rather than being absorbed into it, but any multi-year commitment should account for a roadmap that will be set by a different company.
4. Microsoft Dynamics 365
Sending a promotional message at 3 a.m. local time is not only annoying, it can breach rules: the US TCPA restricts telemarketing calls and texts to 8 a.m. to 9 p.m. in the recipient's local time, and India's TRAI regulations bar commercial communication between 9 p.m. and 9 a.m. for registered preferences.
Dynamics handles this with quiet-time rules. One important correction to how this is usually written up: the quiet-time controls are a feature of Customer Insights Journeys, Microsoft's real-time marketing module, and they are a deterministic rules engine. They are not a Copilot capability and not AI behaviour. Microsoft's current agent naming is Copilot in Dynamics 365 Customer Service, Copilot Studio, and individually named agents such as the Sales Qualification Agent; there is no product called "Dynamics 365 Copilot".
- Commercial and transactional messages follow separate rules. Microsoft's documentation notes that teams may want transactional messages such as order confirmations or password resets sent immediately regardless of the time.
- Channel-specific windows. You can set stricter quiet times for text messages while allowing emails across a broader range of hours.
- Defined fallback. If no time-zone field is set under the audience configuration, quiet times use the journey time zone rather than guessing.
Best for: marketing and lifecycle teams sending across multiple time zones and regulatory regimes.
What to consider: this is scheduling discipline, not answer safety. It does nothing about content accuracy or hallucination, so treat it as one layer rather than the whole stack. It also earns its place here on a rules engine rather than on anything the AI does, which is worth knowing if you are specifically shopping for agent safety.
5. Ada
Ada's safety story is output-side. Its own material describes agents verifying responses against approved sources and blocking non-compliant answers, with every response checked for compliance, tone and relevance before it reaches the customer.
- Verification against approved sources. Non-compliant responses are blocked automatically before delivery.
- Compliance certifications that are actually published. SOC 2 Type II, GDPR and HIPAA, with annual third-party penetration tests and LLM evaluations. Ada also displays PCI DSS, CCPA/CPRA, PIPEDA and AIUC-1.
- Built for regulated volume. Financial services, travel and insurance are the natural fits, where a certification matters more than an internal policy document.
Best for: enterprises in regulated or high-volume industries that need certifications they can hand to an auditor.
What to consider: Ada is frequently described as "zero-trust by default", with input filtering that catches prompt injection and output scoring against safety thresholds. None of that language appears in Ada's own documentation, which describes source verification and compliance checking on the output side. The capability is directionally real; the input-side and zero-trust framing is not the vendor's. Expect an enterprise sales cycle and implementation timeline, and pricing on quote.
6. Zendesk AI Agents
Zendesk's contribution is the after-the-fact record, and specifically redaction.
- Redaction, scoped correctly. Redaction suggestions cover ticket comments and PDF attachments. PCI redaction covers card numbers, expiration dates and CVV codes from call transcripts. This is narrower than the "redacts names, addresses and card numbers from all conversation logs" description that circulates, and worth checking against your actual data types.
- Access logs and retention controls. The Advanced Data Privacy and Protection add-on adds access logs, custom data retention, automatic redaction and advanced encryption.
- Inside the existing ticketing workflow. Compliance controls live in the tool support teams already use.
Best for: support operations in regulated industries that need to answer a dispute with a record rather than a recollection.
What to consider: the honest caveat is bigger than "some features are an add-on". Almost everything above belongs to the ADPP add-on on Enterprise plans, not to Zendesk AI Agents. Zendesk's AI Agents page itself advertises automated QA to audit outcomes and does not mention PII redaction or decision-path audit trails at all. If audit logging of the agent specifically is what you are buying, confirm which product line delivers it.
7. HubSpot Customer Agent
HubSpot announced Agent Hub and Agent Builder on 23 July 2026, and the customer-facing agent now sits inside it. Two naming notes: HubSpot's own knowledge base labels Agent Hub as beta rather than generally available, and "Breeze", the former umbrella brand for HubSpot's AI, is being retired, with the product now presented simply as Customer Agent.
- CRM-grounded answers. Because the agent sits on HubSpot's customer data, replies draw on the same records your reps see, which reduces the chance of an answer contradicting what someone just told the customer.
- Resolution-rate reporting. HubSpot publishes a 70% average resolution rate for the agent and reports on resolution rates in-product.
- Full-context human handoff. Confirmed in HubSpot's own product documentation.
Best for: teams already on HubSpot that want agent performance tied to CRM data rather than to ticket volume.
What to consider: three things. Agent Hub is in beta, so treat the roadmap as unsettled. The sentiment analytics and qualified-lead dashboards often attributed to this product are not advertised on HubSpot's page, so verify them in a demo rather than assuming. And the analytics are only as good as the CRM data feeding them, which is a real constraint if your records are patchy. Pricing works on resolutions plus credits rather than a flat seat fee, which is worth modelling alongside your other CRM automation costs.
Choosing based on where your risk actually sits
- Outbound timing and contact frequency (lifecycle email, adoption nudges): pre-send rule engines. Lumi, or Dynamics 365 quiet times.
- A wrong answer reaching a customer: grounding and output verification. Fin or Ada.
- Data exposure inside a CRM: Salesforce Agentforce, on the understanding that you are inheriting the Salesforce permissions model rather than buying a new one.
- Proving what happened after a dispute: Zendesk with the ADPP add-on.
- Spend on outreach that does not work: HubSpot's resolution reporting, or usage-based measurement of the kind covered in revenue intelligence tools that track consumption.
Most teams end up with two: one for the customer-facing layer and one for the data or compliance layer underneath.
Limitations and evidence gaps
- Every capability above was checked against the vendor's own public documentation. Where documentation is silent, the table says so rather than inferring. Absence of documentation is not proof a capability is missing, only that you cannot verify it before a sales call.
- Pricing is published only for Fin. Everything else is quoted and varies by volume, plan and region.
- The Salesforce acquisition of Fin had not closed at the time of writing. Closing dates and integration plans change.
- Agent Hub is in beta and HubSpot's AI branding is mid-transition, so product names in that section are the likeliest to date.
- Nothing here is legal advice on the EU AI Act, TCPA, TRAI or any other regime mentioned. Rules differ by jurisdiction and by how you deploy.
Conclusion
None of these platforms makes an AI agent risk-free, and no vendor claim should be read that way. What they do is move risk from "we hope this works" to "the system enforces this, and we can show you the record".
Before you sign, ask for one demonstration: deliberately violate a rule and watch what happens. Does the message get blocked, or flagged after it has already gone out? That single question separates safety architecture from a policy document, and it is also the fastest way to find out which of the claims above the vendor will stand behind in writing.
Frequently asked questions
Do EU rules require telling a customer they are talking to an AI?
Yes, where the Act applies. Article 50 of the EU AI Act took effect on 2 August 2026 and requires that people be told they are interacting with an AI system. The reach is not unlimited though: it applies where a system is placed on the EU market or its output is used in the EU, not to every company everywhere. Standard support chatbots fall under the limited-risk transparency rules. Penalties under Article 99 for breaching Article 50 run to €15 million or 3% of total worldwide annual turnover, whichever is higher. One timing detail worth knowing: the separate Article 50(2) duty to mark synthetic content in a machine-readable way was pushed back to 2 December 2026 under the Digital Omnibus agreement, while the disclosure duty stayed on its original date.
What does it mean for an AI agent to be safe when talking to customers?
A safe agent has privacy, access control and behavioural limits built into the message pipeline rather than layered on afterwards. In practice that means it does not expose data the recipient should not see, it respects boundaries such as quiet hours and frequency caps, it declines or escalates rather than guessing, and it leaves a record. The important distinction is preventive versus reactive: a control that fires before the send prevents the incident, while one that fires after only documents it.
Do safety guardrails slow an agent's response down?
It depends on the design, and claims that the overhead is always negligible are worth treating sceptically. Checks that run alongside generation add very little. A verification pass that makes a second model call before delivery does not, and can add a noticeable delay. The larger time cost is usually escalation itself, since a handoff to a person is slower than any automated reply. Ask the vendor for measured latency with guardrails on, not a general reassurance.
Do you still need human staff after deploying a safe agent?
Yes. Every platform here is designed to escalate uncertain or sensitive conversations to a person rather than remove the need for one. What changes is the shape of the work: fewer routine conversations, more of the hard escalated subset, plus new work reviewing logs and tuning rules that did not exist before.
What kinds of AI agents talk to customers on a company's behalf?
Salesforce's own security material treats customer service agents, which resolve tickets across channels, and ecommerce agents, which guide purchases and recommendations, as the two customer-facing categories. SDR agents that qualify leads and book meetings are filed separately, as agents supporting sales and marketing decisions rather than talking to customers on the company's behalf. Each carries a different risk profile and therefore needs different controls.
How do you verify a vendor's safety claims before buying?
Ask for a live demonstration of a deliberately violated rule. Request compliance certifications as documents rather than accepting marketing language. Ask whether audit logs are available to you as the customer or only to the vendor internally, which is a surprisingly common gap. And check every capability claim against the vendor's own documentation, because a meaningful share of what gets repeated about these products in comparison articles, this category's "zero-trust input filtering" and "entity-level access" among them, is not language the vendors themselves use.
How much of B2B churn is decided during onboarding?
The widely quoted figure is that roughly 70% of customer churn happens in the first 90 days, which HubSpot attributes to OnRamp's 2026 State of Onboarding report. Treat it as directional rather than settled: it comes from a vendor survey of 161 respondents, not from an independent study. The underlying point, that early-lifecycle messaging carries disproportionate weight, holds up better than the specific number.
This article reflects publicly available information as of September 2026 and does not endorse any specific platform. Vendor capabilities, pricing, and product names in this category change frequently. Verify current terms directly with each provider.
Last verified: 2026-09-20
Sources
- Userlens | Lumi customer adoption agent
- Salesforce | Signs definitive agreement to acquire Fin
- Salesforce | AI agent security
- Intercom | Today Intercom becomes Fin
- Fin | Pricing
- Microsoft Learn | Set up quiet times in Customer Insights Journeys
- Ada | Trust and security
- Zendesk | About the Advanced Data Privacy and Protection add-on
- HubSpot | Meet Agent Hub and Agent Builder
- European Commission | Guidelines on AI transparency obligations
- EU Artificial Intelligence Act | Article 99, penalties