🍽️ An AI calls a Tokyo restaurant to book a table. The restaurant never signed up for the service, doesn't take phone bookings from strangers, and has asked, more than once, to be removed. The AI keeps calling anyway. Sometimes for tens of minutes, until someone picks up. This is the "AutoReserve problem," and it previews a question the whole AI-agent industry hasn't answered: when a bot acts on your behalf, who on the other end agreed to deal with it?
The service that phones restaurants for you
AutoReserve, run by Tokyo-based Hello, Inc., launched in 2018 and has passed five million registered users. Its pitch is genuinely useful, especially in Japan. Only a small share of Japanese restaurants take online reservations; plenty of well-loved places, from small izakaya to old soba shops and counter sushi bars, still book by phone and only in Japanese. For a foreign visitor, or anyone who dreads phone calls, that's a wall. AutoReserve knocks it down: you tap a time in the app, and for restaurants that only answer the phone, its AI places the call and books the table for you. It works in English, Chinese and Korean. On paper, it's exactly the kind of chore an AI agent should take off your hands.
The trouble is what happens on the other end of the line.
When the phone won't stop ringing
Since users started piling in around 2020, restaurants have reported a growing list of problems, and Japanese food-industry press and TV have covered them repeatedly. AutoReserve lists restaurants it has no relationship with, scraping details from the public web the way a map or review site does. Owners find themselves listed as "bookable" without ever having agreed, sometimes with the wrong hours, the wrong closing days, or a reservation confirmed for a day the shop is shut. Because the caller is an AI reading from a script, staff can't relay the things a phone booking is actually for: allergies, food likes and dislikes, a regular's usual order.
And the calls don't stop. A person calling a busy restaurant hangs up after two or three rings and tries again later. AutoReserve's system, several outlets report, redials until someone answers, sometimes for tens of minutes on end, right through the dinner rush. Restaurants have taken to blocking the number and posting public notices: chains including Global Dining, Mango Tree Cafe and Stamina Taro, along with countless independents, now tell customers plainly that they do not accept AutoReserve bookings.
When restaurants ask to be delisted, the company holds firm. Its position is that it only aggregates information already public, like other review sites, blogs and map services, so it won't take the pages down. Asked by Japanese media, the operator has said there's no legal problem, and that isn't obviously wrong: Japanese courts have declined to force gourmet sites to remove restaurants that didn't want to be listed. The CEO has apologized for the friction, blaming poor communication rather than the design.
There's a commercial edge to this, too. Hello also sells a restaurant-management suite called Respo, covering the reservation ledger, POS and mobile ordering. Restaurants that adopt it integrate cleanly with AutoReserve; those that don't get the cold AI call. The relentless phone booking, in other words, doubles as a nudge toward signing up.
Google already had this fight — in 2018
If this feels familiar, it should. In May 2018, Google demoed Duplex at its I/O conference: an assistant that phoned a hair salon and a restaurant and booked appointments in a voice so human it threw in "um" and "uh." The room applauded. The internet did not. Critics zeroed in on the deception, since only the caller knew a machine was on the line, and one prominent researcher called the demo horrifying, arguing Silicon Valley had learned nothing about ethics.
Google's answer was disclosure. By the time Duplex reached real calls, it opened with a line identifying itself as Google's automated booking service and noting that the call was recorded. That was partly an ethics fix and partly a legal one, since a dozen US states require both parties to consent before a call is taped. Just as important, and less remembered: Google limited Duplex to businesses it had partnered with. The bot didn't cold-call whichever restaurant it liked.
Put those two responses next to AutoReserve and the contrast is sharp. Duplex ended up telling the other party it was a robot, and only calling places that had opted in. AutoReserve does neither reliably. Which points at the part the 2018 debate never really settled.
Disclosure was the easy part
The Duplex outrage was mostly about honesty: should a bot admit it's a bot? That's a real question, and it has a clean answer: yes, and say so up front. But AutoReserve exposes a harder one that a disclosure banner doesn't touch. Imagine the AI announced itself perfectly on every call: "Hello, I'm an automated booking assistant." The restaurant that never wanted to be in the system, that has asked to leave, that is blocking the number, still gets called. Being honest about what is calling does nothing about whether it should be calling at all.
That gap is about to get much wider. The current wave of AI agents, from OpenAI's Operator (now folded into ChatGPT's agent mode) to Anthropic's computer use and Google's Project Mariner, are all built to take actions in the real world on your behalf: filling forms, placing orders, working through multi-step tasks. Every one of them ships with guardrails, and they're thoughtful ones. Agents pause and hand control back to the human before logins, payments, or anything with, in the developers' words, meaningful real-world consequences.
But look closely at who those guardrails protect. They protect you, the user, from your own agent, from it spending your money or agreeing to terms you didn't read. What almost none of them address is the person on the receiving end: the shop, the front desk, the support line, the human whose afternoon the agent is about to occupy. Every consent framework in agentic AI so far governs the relationship between a user and their bot. The party the bot acts upon isn't in the room. Nobody asks the restaurant.
Scale is what turns this from a nuisance into a structural problem. A world with a few Duplex testers is fine. A world where millions of people delegate their calls, their bookings and their complaints to tireless agents is different in kind, because the one thing agents don't do is get tired, or embarrassed, or take the hint. Human friction used to be a natural rate limit: a person gives up. An agent redials. "This information is public and I'm legally allowed to call you" is a defensible sentence for one call. Multiplied by every agent acting on every scraped listing, it starts to look like a slow denial-of-service on human attention.
Who gets to say no?
AutoReserve isn't a uniquely villainous company; in some ways it's just early. It built an agent that acts on public data, stayed inside the law, and ran into a question the law and the AI industry are both behind on: there's a real difference between displaying public information and acting on it. A map listing sits there. An agent picks up the phone. The moment scraping turns into autonomous action against a human who wants out, "it's all public anyway" stops being a complete answer.
The fix restaurants are asking for is almost boringly simple: an opt-out that actually works, a promise that a shop which says "stop" gets to stop. That it's this hard to get is the tell. We've poured real care into agents that are careful about what they'll do for us. We've barely started on what they're allowed to do to everyone else.
In Japan, the pressure is coming from restaurant owners with a phone that won't stop buzzing. Has an automated system ever called a business you run, or reached a number you'd rather it hadn't, and did anyone ever ask whether that was okay?
Global Discussion
0 comments